* [PATCH 7.1 000/438] 7.1.8-rc1 review
@ 2026-08-07 14:33 Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 001/438] net: mpls: initialize rtm_tos in mpls_getroute() Greg Kroah-Hartman
` (451 more replies)
0 siblings, 452 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
This is the start of the stable review cycle for the 7.1.8 release.
There are 438 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.8-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 7.1.8-rc1
Andrei Kuchynski <akuchynski@chromium.org>
usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
Leo Li <sunpeng.li@amd.com>
drm/amd/display: Exit idle optimizations before programming
Leo Li <sunpeng.li@amd.com>
drm/amd/display: check GRPH_FLIP status before sending event
Jackson Lee <jackson.lee@chipsnmedia.com>
media: chips-media: wave5: Support CBP profile
Matthew Brost <matthew.brost@intel.com>
drm/xe: Wait on external BO kernel fences in exec IOCTL
Thomas Hellström <thomas.hellstrom@linux.intel.com>
drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
Matthew Brost <matthew.brost@intel.com>
drm/xe: Set TTM device beneficial_order to 9 (2M)
Michal Wajdeczko <michal.wajdeczko@intel.com>
drm/xe: Separate early xe_device initialization
Michal Wajdeczko <michal.wajdeczko@intel.com>
drm/xe: Move xe->info.devid|revid initialization
Michal Wajdeczko <michal.wajdeczko@intel.com>
drm/xe: Move xe->info.force_execlist initialization
Michal Wajdeczko <michal.wajdeczko@intel.com>
drm/xe: Drop unused param from xe_device_create()
Andrei Kuchynski <akuchynski@chromium.org>
usb: typec: ucsi: Fix race condition and ordering in port unregistration
Sergey Senozhatsky <senozhatsky@chromium.org>
usb: typec: ucsi: split connector lock classes
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: Ensure locking/ref counting for OA whitelists
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: Generalize whitelist_apply_to_hwe
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: Keep track of non-OA nonpriv slots
Ashutosh Dixit <ashutosh.dixit@intel.com>
drm/xe/rtp: Maintain OA whitelists separately
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: validate external BO copy bounds for both stride paths
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: use check_add_overflow for shader size+offset bound
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: enforce cursor size limits for MOB cursors
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: bound DMA command body size against suffix pointer
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: clamp dirty-page range with min, not max
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: reject DX_BIND_QUERY without a DX context
Zack Rusin <zack.rusin@broadcom.com>
drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
William Palacek <William.Palacek@amd.com>
drm/amdkfd: hold event_mutex while checkpointing CRIU events
David Francis <David.Francis@amd.com>
drm/amdkfd: Handle invalid event type in CRIU event restore
William Palacek <William.Palacek@amd.com>
drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
drm/amdkfd: fix QID bit leak in pqm_create_queue()
Gang Ba <Gang.Ba@amd.com>
drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
Jiri Slaby (SUSE) <jirislaby@kernel.org>
drm/amd/display: use proper context for logging
Alan Swanson <reiver@improbability.net>
drm/amd/display: Silence link_dpms I2C retimer failures
Ray Wu <ray.wu@amd.com>
drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
George Zhang <george.zhang@amd.com>
drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
Alex Deucher <alexander.deucher@amd.com>
drm/amd/display: check if dml21_add_phantom_plane() is successful
Yang Wang <kevinyang.wang@amd.com>
drm/amd/pm: use milliwatts for GPU power sensors
Yang Wang <kevinyang.wang@amd.com>
drm/amd/pm: hide pp_table sysfs on APUs
Yang Wang <kevinyang.wang@amd.com>
drm/amd/pm: fix pptable use-after-free
Yang Wang <kevinyang.wang@amd.com>
drm/amd/pm: fix torn gpu metrics reads
Harkirat Gill <harkirat.gill@amd.com>
drm/amdgpu: cap GTT size to physical RAM on APUs
Candice Li <candice.li@amd.com>
drm/amdgpu: restore UMD profile pstate after runtime resume
Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
Myeonghun Pak <mhun512@gmail.com>
drm/mediatek: ovl_adaptor: balance component registrations
Guangshuo Li <lgs201920130244@gmail.com>
drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2
Osama Abdelkader <osama.abdelkader@gmail.com>
drm/panthor: validate firmware interface structure sizes
Osama Abdelkader <osama.abdelkader@gmail.com>
drm/panthor: reject firmware sections with oversized data
Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
drm/bridge: display-connector: Fix I2C adapter resource leak
Maíra Canal <mcanal@igalia.com>
drm/vc4: Zero the tile state data array before each BIN job
Jose Maria Casanova Crespo <jmcasanova@igalia.com>
drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
Alexander Kaplan <alexander.kaplan@sms-medipool.de>
drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
Avi Weiss <thnkslprpt@gmail.com>
can: ctucanfd: mark error-active controller status valid
Avi Weiss <thnkslprpt@gmail.com>
can: ctucanfd: handle bus error interrupts
Avi Weiss <thnkslprpt@gmail.com>
can: ctucanfd: unmap BAR0 using base address
Avi Weiss <thnkslprpt@gmail.com>
can: ctucanfd: use self-test mode for PRESUME_ACK
Pengpeng Hou <pengpeng@iscas.ac.cn>
can: ctucanfd: add missing MODULE_DEVICE_TABLE()
Pengpeng Hou <pengpeng@iscas.ac.cn>
can: peak_usb: validate uCAN receive record lengths
Maoyi Xie <maoyixie.tju@gmail.com>
can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
James Gao <jamesgao5@outlook.com>
can: peak_usb: add bounds check for USB channel index
Pengpeng Hou <pengpeng@iscas.ac.cn>
can: softing: fw_parse(): validate firmware record spans
Tu Nguyen <tu.nguyen.xg@renesas.com>
can: rcar_canfd: change the initializing flow for clocks and resets
Pengpeng Hou <pengpeng@iscas.ac.cn>
can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
Abdun Nihaal <nihaal@cse.iitm.ac.in>
can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
Oleksij Rempel <o.rempel@pengutronix.de>
can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
Oliver Hartkopp <socketcan@hartkopp.net>
can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
Marc Kleine-Budde <mkl@pengutronix.de>
can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
Guangshuo Li <lgs201920130244@gmail.com>
can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
Pengpeng Hou <pengpeng@iscas.ac.cn>
can: ems_usb: validate CPC message lengths
Lucas Martins Alves <lucas.alves@lumal21.com.br>
can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
Liem <liem16213@gmail.com>
i2c: imx: Cancel hrtimer before clearing slave pointer
Liem <liem16213@gmail.com>
i2c: imx: Fix slave registration race and error handling
Carlos Song <carlos.song@nxp.com>
i2c: imx: mark I2C adapter when hardware is powered down
Jonas Gorski <jonas.gorski@bisdn.de>
i2c: iproc: reset bus after timeout if START_BUSY is stuck
H. Nikolaus Schaller <hns@goldelico.com>
i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>
i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
Linmao Li <lilinmao@kylinos.cn>
i2c: spacemit: request IRQ after controller initialization
Dawei Feng <dawei.feng@seu.edu.cn>
ice: fix memory leak in ice_lbtest_prepare_rings()
Dawid Osuchowski <dawid.osuchowski@linux.intel.com>
ice: fix VF interrupts cleanup
Aaron Ma <aaron.ma@canonical.com>
ice: wait for reset completion in ice_resume()
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: fix skb leak on flow key update failure during ct
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: fix skb leak on flow key update failure during recirculation
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: fix potential UAF on meter attach failure
Nava kishore Manne <nava.kishore.manne@amd.com>
phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
Nava kishore Manne <nava.kishore.manne@amd.com>
phy: zynqmp: use read-modify-write for SERDES scrambler bypass
Nava kishore Manne <nava.kishore.manne@amd.com>
phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
Holger Dengler <dengler@linux.ibm.com>
s390/zcrypt: Validate length for CCA ECC private key requests
Holger Dengler <dengler@linux.ibm.com>
s390/zcrypt: Validate length for CCA AES cipher key requests
Harald Freudenberger <freude@linux.ibm.com>
s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
Harald Freudenberger <freude@linux.ibm.com>
s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
Harald Freudenberger <freude@linux.ibm.com>
s390/zcrypt: Close speculative mem read possibility
Harald Freudenberger <freude@linux.ibm.com>
s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
Stefan Haberland <sth@linux.ibm.com>
s390/dasd: Fix undersized format-check buffer
Jan Höppner <hoeppner@linux.ibm.com>
s390/dasd: Fix potential NULL pointer dereference
Aswin Karuvally <aswin@linux.ibm.com>
s390/qeth: Check CAP_NET_ADMIN for private ioctls
Niklas Schnelle <schnelle@linux.ibm.com>
s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
Jianing Li <m13940358460@163.com>
power: supply: max17040: handle missing status supplier
Sasha Finkelstein <k@chaosmail.tech>
power: supply: macsmc: Support macOS 27 SMC firmware
Xu Rao <raoxu@uniontech.com>
power: supply: bq25890: fix the -10 C NTC lookup entry
Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
Abdun Nihaal <nihaal@cse.iitm.ac.in>
cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
Christian Loehle <christian.loehle@arm.com>
cpufreq: cppc: Sanitize lockless policy limit snapshots
Frank Sorenson <sorenson@redhat.com>
cifs: add fscache_resize_cookie() to cifs_setsize()
Junjie Cao <junjie.cao@intel.com>
gpio: pch: use raw_spinlock_t for the register lock
bui duc phuc <phucduc.bui@gmail.com>
gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
Daniel Golle <daniel@makrotopia.org>
gpiolib: tolerate gpio-hogs lacking a hogging state
Hardik Prakash <hardikprakash.official@gmail.com>
i2c: designware: defer probe if child GpioInt controllers are not bound
Myeonghun Pak <mhun512@gmail.com>
i2c: amd-mp2: Unregister callback on adapter add failure
Vincent Jardin <vjardin@free.fr>
hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
Hongyan Xu <getshell@seu.edu.cn>
hwmon: (npcm750-pwm-fan): stop fan timer on device detach
Asim Viladi Oglu Manizada <manizada@pm.me>
sctp: prevent peer transport count overflow
Yuxiang Yang <yangyx22@mails.tsinghua.edu.cn>
sctp: reject stale cookies with mismatched verification tags
Shawn Guo <shengchao.guo@oss.qualcomm.com>
scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc
Ibrahim Hashimov <security@auditcode.ai>
scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
Damien Le Moal <dlemoal@kernel.org>
scsi: libsas: terminate deferred commands on time out
Chris Gellermann <christian.gellermann@codasip.com>
selftests/clone3: fix wild pointer access of getline due to missing init
Chris Gellermann <christian.gellermann@codasip.com>
selftests/mm: fix potential wild pointer access of getline due to missing init
Vijaya Krishna Nivarthi <vijaya.nivarthi@oss.qualcomm.com>
spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
Stanislaw Pal <kuncy7@gmail.com>
spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/filters: Fix false positive match in regex_match_full()
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing: Check return value of __register_event() in trace_module_add_events()
Ming Lei <tom.leiming@gmail.com>
ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
Eric Dumazet <edumazet@google.com>
vxlan: use pskb_network_may_pull() in route_shortcircuit()
Eric Dumazet <edumazet@google.com>
vxlan: use pskb_network_may_pull() for transmit path header pulls
Eric Dumazet <edumazet@google.com>
vxlan: use neigh_ha_snapshot() in route_shortcircuit()
Eric Dumazet <edumazet@google.com>
vxlan: unclone skb head before modifying eth header in route_shortcircuit()
Eric Dumazet <edumazet@google.com>
vxlan: re-fetch eth header after route_shortcircuit()
Matt Fleming <mfleming@cloudflare.com>
veth: convert frag_list skbs before running XDP
Breno Leitao <leitao@debian.org>
uprobes: Fix NULL pointer dereference in hprobe_expire()
Michael Bommarito <michael.bommarito@gmail.com>
um: vector: fix use-after-free in vector_mmsg_rx()
Thorsten Blum <thorsten.blum@linux.dev>
powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
Jiakai Xu <xujiakai2025@iscas.ac.cn>
riscv/mm: use physical alignment for vmemmap_start_pfn
Chengfeng Ye <nicoyip.dev@gmail.com>
net: pktgen: fix proc entry use-after-free
Zhiling Zou <zhilinz@nebusec.ai>
net: ipv6: clear suppressed fib6 rule result
Zhiling Zou <zhilinz@nebusec.ai>
net: bridge: stop fast-leave after deleting a port group
Breno Leitao <leitao@debian.org>
mm: memcg: initialize *locked in memcg1_oom_prepare() stub
Link Lin <linkl@google.com>
mm/page_reporting: use system_freezable_wq to fix UAF during suspend
Kiryl Shutsemau (Meta) <kas@kernel.org>
mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
Kyumin Lee <fyonglkm@gmail.com>
io_uring: preserve task restrictions across exec
Jens Axboe <axboe@kernel.dk>
io_uring/net: initialize mshot_len for send
Christian Brauner <brauner@kernel.org>
binfmt_misc: don't leak the user namespace when the mount fails
Christian Brauner <brauner@kernel.org>
binfmt_misc: don't let an 'F' entry pin its own instance
Christian Brauner <brauner@kernel.org>
binfmt_misc: reject a flag character as the field delimiter
Christian Brauner <brauner@kernel.org>
binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
Christian Brauner <brauner@kernel.org>
binfmt_misc: restore write access when removing an entry
Zhao Li <enderaoelyther@gmail.com>
wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
Zhao Li <enderaoelyther@gmail.com>
wifi: mac80211: fix tid_tx use-after-free on BA session stop
Pratik Vishwakarma <Pratik.Vishwakarma@amd.com>
x86/CPU/AMD: Carve out a Zen5 models range
Zihan Xi <zihanx@nebusec.ai>
tipc: avoid use-after-free in poll trace queue dumps
Soeren Moch <smoch@web.de>
PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug
Carlo Caione <ccaione@baylibre.com>
of/address: Fix NULL bus dereference in of_pci_range_parser_one()
David Lee <david.lee@trailofbits.com>
netfilter: ipset: do not update comments from kernel-side hash adds
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
net/smc: fix socket use-after-free during link group termination
Wei Liu <wei.liu@kernel.org>
mshv: fix hv_input_get_system_property struct
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: reject repeated SMB2 NEGOTIATE requests
Zhiling Zou <roxy520tt@gmail.com>
ipvs: do not propagate one-packet flag to synced conns
David Carlier <devnexen@gmail.com>
igc: remove napi_synchronize() in igc_down()
Matt Vollrath <tactii@gmail.com>
igbvf: Fix leak in TX DMA error cleanup
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
fou: Fix use-after-free in fou_create()
Dawei Feng <dawei.feng@seu.edu.cn>
e1000: fix memory leak in e1000_probe()
Md Sadre Alam <md.alam@oss.qualcomm.com>
dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
Sonali Pradhan <sonalipradhan@google.com>
ALSA: usb-audio: Clamp frame size in implicit-feedback mode
Sonali Pradhan <sonalipradhan@google.com>
ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
Baul Lee <baul.lee@xbow.com>
ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
Baul Lee <baul.lee@xbow.com>
ALSA: usb-audio: fix stack info leak in RME Digiface status
Baul Lee <baul.lee@xbow.com>
ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
Damien Le Moal <dlemoal@kernel.org>
ata: libata-scsi: schedule deferred atapi command
Damien Le Moal <dlemoal@kernel.org>
ata: libata-scsi: terminate deferred commands on time out
Niklas Cassel <cassel@kernel.org>
ata: libata-sata: fix ata_scsi_lpm_supported() iteration
Matt Vollrath <tactii@gmail.com>
ata: libata-eh: Increase STANDBY IMMEDIATE timeout
Haidar Lee <haidar.lee@adlinktech.com>
ASoC: tas2562: fix broken entries in the volume lookup table
Haidar Lee <haidar.lee@adlinktech.com>
ASoC: tas2562: fix DVC coefficient write order
Shengjiu Wang <shengjiu.wang@nxp.com>
ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
Shengjiu Wang <shengjiu.wang@nxp.com>
ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
Baul Lee <baul.lee@xbow.com>
ALSA: ump: fix double free of out_cvts on rawmidi error
Norbert Szetei <norbert@doyensec.com>
ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
Norbert Szetei <norbert@doyensec.com>
ALSA: seq: Fix division by zero in initialize_timer()
Norbert Szetei <norbert@doyensec.com>
ALSA: pcm: wake linked drain waiters on unlink
Xu Rao <raoxu@uniontech.com>
ALSA: lx6464es: fix period byte count for 16-bit streams
Eckhart Mohr <e.mohr@tuxedocomputers.com>
ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
Takashi Iwai <tiwai@suse.de>
ALSA: 6fire: Fix UAF at error handling during probe
David Howells <dhowells@redhat.com>
afs: Fix UAF when sending a message
David Howells <dhowells@redhat.com>
afs: Fix afs_fs_fetch_data() to subtract transferred from len
David Howells <dhowells@redhat.com>
afs: Fix afs_fs_fetch_data() to set call->async
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
bpf: lwt: Fix dst reference leak on reroute failure
Sangho Lee <kudo3228@gmail.com>
Bluetooth: HIDP: validate numbered report payloads
Sangho Lee <kudo3228@gmail.com>
Bluetooth: HIDP: reject frames without a transaction header
Chengfeng Ye <nicoyip.dev@gmail.com>
Bluetooth: hci_sync: Fix advertising data UAFs
Zihan Xi <xizh2024@lzu.edu.cn>
Bluetooth: mgmt: fix UAF in pair command cancellation
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: SCO: give the socket its own sco_conn reference
Zihan Xi <zihanx@nebusec.ai>
Bluetooth: mgmt: fix pending command UAF in EIR updates
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
Luxiao Xu <rakukuip@gmail.com>
audit: fix potential use-after-free in audit_del_rule()
Zhan Xusheng <zhanxusheng1024@gmail.com>
audit: fix potential integer overflow in audit_log_n_string()
Charles Vosburgh <trilobyte777@gmail.com>
sctp: validate Adaptation Indication parameter length
Hidayath Khan <hidayath@linux.ibm.com>
dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Fix resource leak on IRQ registration failure
Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Fix missing error codes and memory unaccounting
Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
Sean Christopherson <seanjc@google.com>
KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
Paolo Bonzini <pbonzini@redhat.com>
KVM: VMX: add memory clobber to asm for VMX instructions
Raushan Patel <raushan.jhon@gmail.com>
tracing/fprobe: Roll back on enable_trace_fprobe() failure
Raushan Patel <raushan.jhon@gmail.com>
tracing/probes: Reject $arg0 in meta argument expansion
Weiming Shi <bestswngs@gmail.com>
KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
Gregory Price <gourry@gourry.net>
mm/vmstat: fold stranded per-cpu node stats when a node comes online
Usama Arif <usama.arif@linux.dev>
userfaultfd: wait on source PMD during UFFDIO_MOVE
Xiangfeng Cai <caixiangfeng@bytedance.com>
mm/hugetlb: fix list corruption in allocate_file_region_entries()
Zi Yan <ziy@nvidia.com>
mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
Kiryl Shutsemau (Meta) <kas@kernel.org>
fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
Kiryl Shutsemau (Meta) <kas@kernel.org>
fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
Jori Koolstra <jkoolstra@xs4all.nl>
selftest: fix headers in fclog.c
Aboorva Devarajan <aboorvad@linux.ibm.com>
mm/util: don't read __page_2 for order-1 folios in snapshot_page()
Kefeng Wang <wangkefeng.wang@huawei.com>
mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
Joseph Qi <joseph.qi@linux.alibaba.com>
ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset
Guanghui Yang <3497809730@qq.com>
btrfs: zoned: fix missing chunk metadata reservation
Stanislav Kinsburskii <skinsburskii@gmail.com>
lib: test_hmm: use device devt for coherent device range selection
Nathan Chancellor <nathan@kernel.org>
fortify: Disable -Wstringop-overread in tests
Benjamin Boortz <bennib@mailbox.org>
pinctrl: bm1880: add missing select GENERIC_PINCONF
Michael Bommarito <michael.bommarito@gmail.com>
erofs: cap LZMA stream pool size
Mykola Lysenko <nickolay.lysenko@gmail.com>
btrfs: raid56: fix scrub read assembly submitting no reads
Karl Mehltretter <kmehltretter@gmail.com>
pinctrl: devicetree: don't free uninitialized dev_name on error path
Benjamin Boortz <bennib@mailbox.org>
pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
Kiryl Shutsemau (Meta) <kas@kernel.org>
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
Qi Zheng <qi.zheng@linux.dev>
mm: mglru: fix stale batch updates after memcg reparenting
Christian Loehle <christian.loehle@arm.com>
ACPI: CPPC: Check all controls for fast switching
Nicolas Schier <n.schier@fritz.com>
kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos
Peiyang He <peiyang_he@smail.nju.edu.cn>
iommu/iommufd: Fix IOPF group ownership UAF
Peiyang He <peiyang_he@smail.nju.edu.cn>
iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
Peiyang He <peiyang_he@smail.nju.edu.cn>
iommufd: Reject DMABUF pages from the access pin path
Nicolin Chen <nicolinc@nvidia.com>
iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
Nicolin Chen <nicolinc@nvidia.com>
iommufd/viommu: Release the igroup lock on the vdevice_size error path
Masami Hiramatsu (Google) <mhiramat@kernel.org>
ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Publish VP to pt_vp_array before installing the file descriptor
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Order pt_vp_array publish against irqfd assertion path
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Fix missing error code on VP allocation failure
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Fix level-triggered check on uninitialized data
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Fix race in mshv_irqfd_deassign
Christoph Hellwig <hch@lst.de>
iomap: add a separate bio_set for iomap_split_ioend
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: use memcmp() to compare ClientGUIDs
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix use-after-free in __close_file_table_ids()
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: return success for deferred final close
Jerome Tollet <jerome.tollet@gmail.com>
drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
Denis V. Lunev <den@openvz.org>
qede: sync udp_tunnel ports outside qede_lock in the recovery path
Haibo Chen <haibo.chen@nxp.com>
spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
Gabriele Monaco <gmonaco@redhat.com>
sched/deadline: Use revised wakeup rule only for running dl_server
Suman Ghosh <sumang@marvell.com>
octeontx2-pf: Set correct sequence for carrier off and tx queue stop
Jiawen Wu <jiawenwu@trustnetic.com>
net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
Wei Fang <wei.fang@nxp.com>
ptp: netc: fix potential interrupt storm caused by incorrect unbind order
Aditya Garg <gargaditya@linux.microsoft.com>
net: mana: Return error code from mana_create_rxq()
Long Li <longli@microsoft.com>
net: mana: Create separate EQs for each vPort
Nazim Amirul <muhammad.nazim.amirul.nazle.asmade@altera.com>
net: stmmac: Fix E2E delay mechanism
Daniel Golle <daniel@makrotopia.org>
net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
Daniel Golle <daniel@makrotopia.org>
net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling
Daniel Golle <daniel@makrotopia.org>
net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
riscv: vdso: Only try to install vDSO when present
Shuangpeng Bai <shuangpeng.kernel@gmail.com>
ipv6: release fib6_null_entry on subtree failure
Vincent Donnefort <vdonnefort@google.com>
ring-buffer: Fix reader page read offset for remote buffers
Karl Mehltretter <kmehltretter@gmail.com>
riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
Muhammad Bilal <meatuni001@gmail.com>
accel/qaic: use sizeof(*trans_hdr) for transaction length check
Anirudh Srinivasan <asrinivasan@oss.tenstorrent.com>
riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
Masami Hiramatsu (Google) <mhiramat@kernel.org>
fprobe: Fix module reference count leak on error in register_fprobe()
Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
drm/xe/pt: check no-DMA huge-pte cases before DMA segment test
Alexander Kaplan <alexander.kaplan@sms-medipool.de>
drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
Minhong He <heminhong@kylinos.cn>
can: isotp: check register_netdevice_notifier() error in module init
Chenguang Zhao <zhaochenguang@kylinos.cn>
net: sxgbe: check descriptor ring allocation failures
Chenguang Zhao <zhaochenguang@kylinos.cn>
net: sxgbe: free TX rings on RX allocation failure
Ao Sun <ao.sun@transsion.com>
scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
Chandrakanth Patil <chandrakanth.patil@broadcom.com>
scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
Hariprasad Kelam <hkelam@marvell.com>
octeontx2-af: Block VFs from clobbering special CGX PKIND state
Ratheesh Kannoth <rkannoth@marvell.com>
octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle
Leon Romanovsky <leon@kernel.org>
scsi: target: Clear cmd_cnt when initial counter enrollment fails
Benjamin Block <bblock@linux.ibm.com>
scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
Bart Van Assche <bvanassche@acm.org>
scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
Guangshuo Li <lgs201920130244@gmail.com>
scsi: ufs: core: Cancel RTC work in active-active suspend
TanZheng <tanzheng@kylinos.cn>
scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
Christian Marangi <ansuelsmth@gmail.com>
net: phylink: put link_gpio if phylink_create fails
Mauricio Faria de Oliveira <mfo@igalia.com>
x86/boot: Add volatile, clobbers and zero-length test in memcmp()
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_sync: hold conn in hci_past_sync() callback
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
Pauli Virtanen <pav@iki.fi>
Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btintel: Validate length before parsing diagnostics TLV
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: fix refcounting of iso_conn
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: ensure no dangling hcon references in iso_conn
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: fix leaking sk after socket release
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: hold sk properly in iso_conn_ready
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: lock sk in iso_connect_ind
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: lock sk in iso_sock_getname
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
Jiale Yao <yaojiale02@163.com>
Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
Pauli Virtanen <pav@iki.fi>
Bluetooth: ISO: clear iso_data always when detaching conn from hcon
Przemyslaw Korba <przemyslaw.korba@intel.com>
ice: suppress DPLL errors during reset recovery
Yuho Choi <dbgh9129@gmail.com>
idpf: Fix mailbox IRQ name leak on request failure
Joshua Hay <joshua.a.hay@intel.com>
idpf: adjust TxQ ring count minimum
Michael Bommarito <michael.bommarito@gmail.com>
idpf: bound interrupt-vector register fill to the allocated array
Guenter Roeck <linux@roeck-us.net>
hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
Chenguang Zhao <zhaochenguang@kylinos.cn>
net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
David Howells <dhowells@redhat.com>
netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
Yichong Chen <chenyichong@uniontech.com>
netfs: release readahead folios on iterator preparation failure
Yichong Chen <chenyichong@uniontech.com>
netfs: handle single writeback rolling buffer allocation failure
Yichong Chen <chenyichong@uniontech.com>
netfs: clear PG_private_2 on copy-to-cache append failure
Zhao Li <enderaoelyther@gmail.com>
wifi: mac80211: validate individual TWT params before driver setup
Eric Dumazet <edumazet@google.com>
net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
Cen Zhang (Microsoft) <blbllhy@gmail.com>
net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
Thorsten Blum <thorsten.blum@linux.dev>
powerpc/boot: Fix treeboot-akebono CPU node lookup check
Thorsten Blum <thorsten.blum@linux.dev>
powerpc/boot: Fix treeboot-currituck CPU node lookup check
Thorsten Blum <thorsten.blum@linux.dev>
powerpc/boot: Fix simpleboot CPU node lookup check
Eric Joyner <eric.joyner@amd.com>
ethtool: Embed FEC hist ranges as buffer in struct
Yun Lu <luyun@kylinos.cn>
rtase: fix double free of multi-frag skb on DMA map failure
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix PWM auto temp state array and bounds check
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Use cached PWM frequency value
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix cache updated before hardware write on I2C error
Luiz Angelo Daros de Luca <luizluca@gmail.com>
hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
Chenguang Zhao <zhaochenguang@kylinos.cn>
forcedeth: fix UAF of txrx_stats in nv_remove
Surendra Singh Chouhan <kr494167@gmail.com>
ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set()
David Corvaglia <david@corvaglia.dev>
net: bridge: mrp: fix Option TLV length in MRP_Test frames
Guenter Roeck <linux@roeck-us.net>
hwmon: (nct6775-core) Prevent access to unsupported weight registers
Eric Dumazet <edumazet@google.com>
net: do not send ICMP/NDISC Redirects when peer allocation fails
Guenter Roeck <linux@roeck-us.net>
hwmon: (nzxt-smart2) DMA-align output buffer
Guenter Roeck <linux@roeck-us.net>
hwmon: (lm90) Only report alarms if driver is ready
Guenter Roeck <linux@roeck-us.net>
hwmon: (sht3x) Fix unaligned accesses
Guenter Roeck <linux@roeck-us.net>
hwmon: (ltc4282) Fix reading the minimum alarm voltage
Guenter Roeck <linux@roeck-us.net>
hwmon: (ina2xx) Fix various overflow issues
Guenter Roeck <linux@roeck-us.net>
hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
Srikanth Boyapally <srikanth.boyapally@amd.com>
spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
wangdicheng <wangdicheng@kylinos.cn>
ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
Baochen Qiang <baochen.qiang@oss.qualcomm.com>
wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()
Christian Loehle <christian.loehle@arm.com>
ACPI: CPPC: Skip writes to unsupported performance controls
Alex Tran <alex.tran@oss.qualcomm.com>
gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper
Gao Xiang <xiang@kernel.org>
erofs: ensure valid f_path for page cache sharing
Gao Xiang <xiang@kernel.org>
erofs: remove fscache backend entirely
Gao Xiang <xiang@kernel.org>
erofs: clean up erofs_ishare_fill_inode()
Dawei Feng <dawei.feng@seu.edu.cn>
smb: client: fix buffer leaks in SMB1 read and write
Xingui Yang <yangxingui@huawei.com>
scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
HyeongJun An <sammiee5311@gmail.com>
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
HyeongJun An <sammiee5311@gmail.com>
scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
Mario Limonciello <mario.limonciello@amd.com>
pinctrl-amd: Don't clear S4 wake bits at probe
Jonas Köppeler <j.koeppeler@tu-berlin.de>
net/sched: sch_cake: skip clearing unused tins during rate adjustment
Maciej Fijalkowski <maciej.fijalkowski@intel.com>
xsk: reclaim invalid Tx descriptors in ZC batch path
Maciej Fijalkowski <maciej.fijalkowski@intel.com>
xsk: provide sufficient space in pool->tx_descs
Jason Xing <kerneljasonxing@gmail.com>
xsk: drain continuation descs after overflow in xsk_build_skb()
Jason Xing <kerneljasonxing@gmail.com>
xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
John Ericson <mail@johnericson.me>
selftests/net/af_unix: test listen() rejects wrong socket states
John Ericson <mail@johnericson.me>
af_unix: fix listen() succeeding on sockets in the wrong state
Xiang Mei (Microsoft) <xmei5@asu.edu>
nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
Xiang Mei (Microsoft) <xmei5@asu.edu>
nexthop: take nh->lock for f6i_list walks in replace check and notify
Xiang Mei <xmei5@asu.edu>
rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: SDCA: Ensure that Control Range is large enough for header
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: SDCA: Make UMP message size check more robust
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: SDCA: Always free firmware in FDL path
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: SDCA: Correct pointer passed to devm_acpi_table_put
Xiang Mei (Microsoft) <xmei5@asu.edu>
netfilter: nft_payload: fix mask build for partial field offload
Julian Anastasov <ja@ssi.bg>
ipvs: clear the nfct flag under lock
Julian Anastasov <ja@ssi.bg>
ipvs: do not mangle ICMP replies for non-first fragments
Julian Anastasov <ja@ssi.bg>
ipvs: fix places with wrong packet offsets
Julian Anastasov <ja@ssi.bg>
ipvs: fix the checksum validations
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: nf_tables: make nft_object rhltable per table
Julian Anastasov <ja@ssi.bg>
ipvs: adjust double hashing when fwd method changes
Michael Bommarito <michael.bommarito@gmail.com>
assoc_array: trim the final shortcut word using the current chunk end
Michael Bommarito <michael.bommarito@gmail.com>
keys: make keyring key-chunk byte order agree with keyring_diff_objects()
Michael Bommarito <michael.bommarito@gmail.com>
keys: fix out-of-bounds read in keyring_get_key_chunk()
Fabrice Derepas <fabrice.derepas@canonical.com>
KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
Alexandru Elisei <alexandru.elisei@arm.com>
KVM: arm64: Reject guest_memfd memslots when the VM has MTE
Vincent Donnefort <vdonnefort@google.com>
KVM: arm64: Add missing hyp_enter when trapping sysreg
Vincent Donnefort <vdonnefort@google.com>
KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load()
Vincent Donnefort <vdonnefort@google.com>
KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing
Vincent Donnefort <vdonnefort@google.com>
KVM: arm64: Fix hyp_trace clock disabling
Carlos López <clopez@suse.de>
KVM: arm64: vgic: Mitigate potential LPI registration failure
Carlos López <clopez@suse.de>
KVM: arm64: vgic: Fix race between LPI release and re-registration
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Fix sleeping under spinlock in mshv_portid_alloc
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
mshv: Fix duplicate GSI detection for GSI 0
Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
Yi Xie <xieyi@kylinos.cn>
mshv_vtl: fix fd leak in mshv_ioctl_create_vtl()
Ruoyu Wang <ruoyuw560@gmail.com>
drm/mediatek: Check CRTC state before freeing
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
Lorenzo Bianconi <lorenzo@kernel.org>
selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests
Xiang Mei <xmei5@asu.edu>
netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
phy: zynqmp: fix runtime PM leak on probe allocation failure
Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
Tomas Glozar <tglozar@redhat.com>
rtla/timerlat_top: Fix on-threshold actions firing on signal
Namjae Jeon <linkinjeon@kernel.org>
ntfs: drop stale page-cache when shrinking a non-resident attr
Namjae Jeon <linkinjeon@kernel.org>
ntfs: harden runlist realloc size calculations
Johannes Thumshirn <johannes.thumshirn@wdc.com>
btrfs: zoned: skip fully truncated ordered extents at zone finish
Qu Wenruo <wqu@suse.com>
btrfs: raid56: fix an incorrect csum skip during scrub
Dongjiang Zhu <zhudongjiang@fnnas.com>
btrfs: skip global block reserve accounting for rescue mounts
Qu Wenruo <wqu@suse.com>
btrfs: warn about extent buffer that can not be released
Johannes Thumshirn <johannes.thumshirn@wdc.com>
btrfs: zoned: reset meta_write_pointer on zone reset
Johannes Thumshirn <johannes.thumshirn@wdc.com>
btrfs: zoned: fix deadlock between metadata writeback and transaction commit
Qu Wenruo <wqu@suse.com>
btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
Sang-Heon Jeon <ekffu200098@gmail.com>
of: reserved_mem: prevent OOB when too many dynamic regions are defined
Uday Khare <udaykhare77@gmail.com>
ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
Uday Khare <udaykhare77@gmail.com>
ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
phy: qcom: m31-eusb2: Fix return value of init call
Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
Rosen Penev <rosenp@gmail.com>
ata: sata_mv: accept 1 or 2 resources in platform probe
Namjae Jeon <linkinjeon@kernel.org>
ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points
Kuan-Ying Lee <kuan-ying.lee@canonical.com>
selftests/seccomp: Fix pointer type mismatch build error
Haofeng Li <lihaofeng@kylinos.cn>
selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
Abdun Nihaal <nihaal@cse.iitm.ac.in>
gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
Nicolin Chen <nicolinc@nvidia.com>
iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
Yuho Choi <dbgh9129@gmail.com>
dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
Yuho Choi <dbgh9129@gmail.com>
dmaengine: idxd: fix double free of wq, engine, and group structs
Hongling Zeng <zenghongling@kylinos.cn>
dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
Sneh Mankad <sneh.mankad@oss.qualcomm.com>
pinctrl: qcom: Unconditionally mark gpio as wakeup enable
David Carlier <devnexen@gmail.com>
dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold
D Scott Phillips <scott@os.amperecomputing.com>
KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
Michael Bommarito <michael.bommarito@gmail.com>
thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
Michael Diesen <michael.diesen@posteo.de>
ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
Harry Yoo (Oracle) <harry@kernel.org>
mm/slab: prevent unbounded recursion in free path with new kmalloc type
Harry Yoo (Oracle) <harry@kernel.org>
lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
Harry Yoo (Oracle) <harry@kernel.org>
mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
net: mpls: initialize rtm_tos in mpls_getroute()
-------------
Diffstat:
Documentation/arch/arm64/silicon-errata.rst | 4 +
.../bindings/ufs/qcom,sa8255p-ufshc.yaml | 9 +-
Documentation/filesystems/erofs.rst | 9 +-
Documentation/networking/af_xdp.rst | 54 +-
Documentation/virt/kvm/api.rst | 6 +
Makefile | 12 +-
arch/arm64/include/asm/kvm_hypevents.h | 1 +
arch/arm64/kvm/arm.c | 25 +-
arch/arm64/kvm/hyp/nvhe/hyp-main.c | 1 +
arch/arm64/kvm/hyp_trace.c | 36 +-
arch/arm64/kvm/mmu.c | 4 +
arch/arm64/kvm/vgic/vgic-its.c | 25 +-
arch/arm64/kvm/vgic/vgic-v3.c | 8 +-
arch/arm64/kvm/vgic/vgic.c | 18 +-
arch/powerpc/boot/simpleboot.c | 2 +-
arch/powerpc/boot/treeboot-akebono.c | 2 +-
arch/powerpc/boot/treeboot-currituck.c | 2 +-
arch/powerpc/platforms/ps3/mm.c | 1 +
arch/riscv/Makefile | 2 +-
arch/riscv/kernel/unaligned_access_speed.c | 4 +-
arch/riscv/mm/init.c | 7 +-
arch/s390/kvm/pci.c | 107 +++-
arch/s390/kvm/pci.h | 2 +
arch/s390/pci/pci_mmio.c | 1 +
arch/um/drivers/vector_kern.c | 3 +
arch/x86/boot/string.c | 11 +-
arch/x86/kernel/cpu/amd.c | 4 +-
arch/x86/kvm/svm/avic.c | 8 -
arch/x86/kvm/vmx/vmx_ops.h | 8 +-
arch/x86/kvm/x86.c | 6 +
drivers/accel/qaic/qaic_control.c | 2 +-
drivers/acpi/cppc_acpi.c | 29 +-
drivers/ata/ahci_ceva.c | 18 +-
drivers/ata/libata-eh.c | 37 +-
drivers/ata/libata-sata.c | 2 +-
drivers/ata/libata-scsi.c | 119 +++-
drivers/ata/libata.h | 3 +-
drivers/ata/sata_mv.c | 2 +-
drivers/block/ublk_drv.c | 9 +
drivers/bluetooth/btintel.c | 3 +
drivers/bluetooth/btmtk.c | 86 ++-
drivers/bluetooth/btusb.c | 30 +-
drivers/cpufreq/cppc_cpufreq.c | 35 +-
drivers/cpufreq/powernow-k8.c | 1 +
drivers/dibs/dibs_loopback.c | 47 +-
drivers/dma/idxd/cdev.c | 4 +-
drivers/dma/idxd/init.c | 36 +-
drivers/dma/sun6i-dma.c | 11 +-
drivers/dma/switchtec_dma.c | 2 +-
drivers/gpio/gpio-by-pinctrl.c | 18 +-
drivers/gpio/gpio-pca953x.c | 15 +-
drivers/gpio/gpio-pch.c | 28 +-
drivers/gpio/gpio-sloppy-logic-analyzer.c | 10 +
drivers/gpio/gpiolib.c | 13 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c | 39 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 9 +
drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c | 15 +
drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c | 3 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c | 4 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c | 12 +
drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 10 +-
drivers/gpu/drm/amd/amdkfd/kfd_events.c | 23 +-
.../gpu/drm/amd/amdkfd/kfd_process_queue_manager.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_queue.c | 2 +-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 243 ++++++--
drivers/gpu/drm/amd/display/dc/core/dc.c | 45 ++
drivers/gpu/drm/amd/display/dc/dc.h | 1 +
.../gpu/drm/amd/display/dc/dce/dce_clock_source.c | 20 +-
.../drm/amd/display/dc/dml2_0/dml21/dml21_utils.c | 15 +-
.../dml21/src/dml2_core/dml2_core_dcn4_calcs.c | 31 +-
.../drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c | 16 +-
drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 16 +-
drivers/gpu/drm/amd/include/kgd_pp_interface.h | 6 +-
drivers/gpu/drm/amd/pm/amdgpu_dpm.c | 39 +-
drivers/gpu/drm/amd/pm/amdgpu_pm.c | 29 +-
drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h | 6 +-
.../gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c | 4 +-
.../gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c | 4 +-
.../gpu/drm/amd/pm/powerplay/hwmgr/vega12_hwmgr.c | 2 +-
.../gpu/drm/amd/pm/powerplay/hwmgr/vega20_hwmgr.c | 5 +-
drivers/gpu/drm/amd/pm/powerplay/inc/hwmgr.h | 5 +
drivers/gpu/drm/amd/pm/swsmu/smu11/arcturus_ppt.c | 2 +-
.../drm/amd/pm/swsmu/smu11/cyan_skillfish_ppt.c | 6 +-
drivers/gpu/drm/amd/pm/swsmu/smu11/navi10_ppt.c | 8 +-
.../drm/amd/pm/swsmu/smu11/sienna_cichlid_ppt.c | 7 +-
drivers/gpu/drm/amd/pm/swsmu/smu11/vangogh_ppt.c | 9 +-
drivers/gpu/drm/amd/pm/swsmu/smu12/renoir_ppt.c | 5 +-
drivers/gpu/drm/amd/pm/swsmu/smu13/aldebaran_ppt.c | 3 +-
.../gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_0_ppt.c | 2 +-
.../gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_12_ppt.c | 3 +-
.../gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_4_ppt.c | 4 +-
.../gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_5_ppt.c | 2 +-
.../gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_6_ppt.c | 3 +-
.../gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_7_ppt.c | 2 +-
.../gpu/drm/amd/pm/swsmu/smu13/yellow_carp_ppt.c | 2 +-
.../gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_0_ppt.c | 3 +-
.../gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_2_ppt.c | 2 +-
.../gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_0_ppt.c | 3 +-
.../gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_8_ppt.c | 3 +-
drivers/gpu/drm/bridge/display-connector.c | 11 +-
drivers/gpu/drm/display/drm_dp_helper.c | 12 +
drivers/gpu/drm/drm_exec.c | 6 +-
drivers/gpu/drm/drm_gpuvm.c | 3 +-
drivers/gpu/drm/i915/display/intel_ddi.c | 2 +
drivers/gpu/drm/i915/display/intel_dp.c | 9 +-
drivers/gpu/drm/i915/display/intel_hdmi.c | 26 +
drivers/gpu/drm/i915/display/intel_hdmi.h | 2 +
drivers/gpu/drm/mediatek/mtk_crtc.c | 6 +-
drivers/gpu/drm/mediatek/mtk_disp_ovl_adaptor.c | 7 +-
drivers/gpu/drm/mediatek/mtk_hdmi_v2.c | 8 -
drivers/gpu/drm/panthor/panthor_fw.c | 47 +-
drivers/gpu/drm/vc4/vc4_irq.c | 2 +-
drivers/gpu/drm/vc4/vc4_validate.c | 29 +-
drivers/gpu/drm/vmwgfx/ttm_object.c | 7 +-
drivers/gpu/drm/vmwgfx/vmwgfx_blit.c | 39 +-
drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c | 49 +-
drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 20 +-
drivers/gpu/drm/vmwgfx/vmwgfx_fence.c | 13 +-
drivers/gpu/drm/vmwgfx/vmwgfx_page_dirty.c | 4 +-
drivers/gpu/drm/vmwgfx/vmwgfx_resource.c | 4 +-
drivers/gpu/drm/vmwgfx/vmwgfx_shader.c | 13 +-
drivers/gpu/drm/vmwgfx/vmwgfx_vkms.c | 17 +-
drivers/gpu/drm/xe/tests/xe_pci.c | 6 +
drivers/gpu/drm/xe/xe_device.c | 56 +-
drivers/gpu/drm/xe/xe_device.h | 4 +-
drivers/gpu/drm/xe/xe_exec.c | 22 +-
drivers/gpu/drm/xe/xe_gt_debugfs.c | 4 +-
drivers/gpu/drm/xe/xe_hw_engine.c | 2 +
drivers/gpu/drm/xe/xe_hw_engine_types.h | 8 +
drivers/gpu/drm/xe/xe_oa.c | 7 +
drivers/gpu/drm/xe/xe_oa_types.h | 3 +
drivers/gpu/drm/xe/xe_pci.c | 15 +-
drivers/gpu/drm/xe/xe_pt.c | 13 +-
drivers/gpu/drm/xe/xe_reg_whitelist.c | 87 ++-
drivers/gpu/drm/xe/xe_reg_whitelist.h | 4 +
drivers/gpu/drm/xe/xe_vm.c | 3 +-
drivers/hv/mshv_eventfd.c | 41 +-
drivers/hv/mshv_irq.c | 2 +-
drivers/hv/mshv_portid_table.c | 6 +-
drivers/hv/mshv_root_main.c | 41 +-
drivers/hv/mshv_vtl_main.c | 1 +
drivers/hv/vmbus_drv.c | 13 +-
drivers/hwmon/adt7470.c | 131 ++--
drivers/hwmon/ina2xx.c | 61 +-
drivers/hwmon/lm90.c | 4 +-
drivers/hwmon/ltc4282.c | 4 +-
drivers/hwmon/nct6775-core.c | 20 +-
drivers/hwmon/npcm750-pwm-fan.c | 11 +
drivers/hwmon/nzxt-smart2.c | 2 +-
drivers/hwmon/pmbus/pmbus_core.c | 7 +-
drivers/hwmon/sht3x.c | 9 +-
drivers/i2c/busses/i2c-amd-mp2-plat.c | 4 +-
drivers/i2c/busses/i2c-bcm-iproc.c | 11 +
drivers/i2c/busses/i2c-designware-platdrv.c | 80 +++
drivers/i2c/busses/i2c-imx.c | 54 +-
drivers/i2c/busses/i2c-jz4780.c | 5 +-
drivers/i2c/busses/i2c-k1.c | 10 +-
drivers/i2c/busses/i2c-qcom-cci.c | 18 +-
drivers/infiniband/hw/mana/main.c | 40 +-
drivers/infiniband/hw/mana/mana_ib.h | 14 +
drivers/infiniband/hw/mana/qp.c | 68 ++-
.../iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 15 +
drivers/iommu/io-pgfault.c | 24 +-
drivers/iommu/iommufd/device.c | 2 +-
drivers/iommu/iommufd/eventq.c | 2 +
drivers/iommu/iommufd/pages.c | 3 +
drivers/iommu/iommufd/viommu.c | 22 +-
.../media/platform/chips-media/wave5/wave5-hw.c | 3 +
.../platform/chips-media/wave5/wave5-vpu-enc.c | 5 +-
.../platform/chips-media/wave5/wave5-vpuapi.h | 1 +
drivers/net/can/c_can/c_can_main.c | 8 +-
drivers/net/can/ctucanfd/ctucanfd_base.c | 14 +-
drivers/net/can/ctucanfd/ctucanfd_pci.c | 3 +-
drivers/net/can/rcar/rcar_canfd.c | 32 +-
drivers/net/can/softing/softing_fw.c | 46 +-
drivers/net/can/usb/ems_usb.c | 43 ++
drivers/net/can/usb/etas_es58x/es58x_core.c | 1 -
drivers/net/can/usb/gs_usb.c | 4 +-
drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c | 1 +
drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c | 13 +-
drivers/net/can/usb/peak_usb/pcan_usb_core.c | 1 -
drivers/net/can/usb/peak_usb/pcan_usb_fd.c | 40 +-
drivers/net/can/usb/peak_usb/pcan_usb_pro.c | 20 +-
drivers/net/dsa/mt7530-mdio.c | 11 +-
drivers/net/dsa/mt7530.c | 86 ++-
drivers/net/ethernet/intel/e1000/e1000_main.c | 2 +-
drivers/net/ethernet/intel/ice/ice_dpll.c | 19 +-
drivers/net/ethernet/intel/ice/ice_ethtool.c | 10 +-
drivers/net/ethernet/intel/ice/ice_main.c | 10 +
drivers/net/ethernet/intel/ice/ice_vf_lib.c | 27 +
.../net/ethernet/intel/ice/ice_vf_lib_private.h | 1 +
drivers/net/ethernet/intel/ice/virt/queues.c | 21 +
drivers/net/ethernet/intel/idpf/idpf_dev.c | 2 +-
drivers/net/ethernet/intel/idpf/idpf_lib.c | 2 +-
drivers/net/ethernet/intel/idpf/idpf_txrx.c | 5 +-
drivers/net/ethernet/intel/idpf/idpf_txrx.h | 2 +-
drivers/net/ethernet/intel/idpf/idpf_vf_dev.c | 2 +-
drivers/net/ethernet/intel/idpf/idpf_virtchnl.c | 5 +-
drivers/net/ethernet/intel/idpf/idpf_virtchnl.h | 2 +-
drivers/net/ethernet/intel/igbvf/netdev.c | 2 -
drivers/net/ethernet/intel/igc/igc_main.c | 3 +-
drivers/net/ethernet/marvell/octeontx2/af/cgx.c | 12 +
drivers/net/ethernet/marvell/octeontx2/af/cgx.h | 1 +
drivers/net/ethernet/marvell/octeontx2/af/mbox.h | 1 +
drivers/net/ethernet/marvell/octeontx2/af/rvu.h | 2 +
.../net/ethernet/marvell/octeontx2/af/rvu_cgx.c | 79 +++
.../net/ethernet/marvell/octeontx2/af/rvu_nix.c | 97 ++-
.../net/ethernet/marvell/octeontx2/af/rvu_npc.c | 49 +-
.../net/ethernet/marvell/octeontx2/nic/otx2_pf.c | 8 +-
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 2 +-
drivers/net/ethernet/mellanox/mlx5/core/en.h | 1 -
drivers/net/ethernet/mellanox/mlx5/core/en_main.c | 7 -
drivers/net/ethernet/mellanox/mlx5/core/en_stats.c | 19 +-
drivers/net/ethernet/microsoft/mana/mana_en.c | 143 +++--
drivers/net/ethernet/microsoft/mana/mana_ethtool.c | 23 +-
drivers/net/ethernet/nvidia/forcedeth.c | 4 +-
drivers/net/ethernet/qlogic/qede/qede_main.c | 44 +-
drivers/net/ethernet/realtek/rtase/rtase_main.c | 3 +
drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c | 14 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 3 +-
drivers/net/ethernet/wangxun/libwx/wx_lib.c | 2 +
drivers/net/phy/phylink.c | 29 +-
drivers/net/veth.c | 4 +-
drivers/net/vxlan/vxlan_core.c | 21 +-
drivers/net/vxlan/vxlan_mdb.c | 4 +-
drivers/net/wireless/ath/ath12k/mac.c | 5 +-
.../net/wireless/marvell/mwifiex/11n_rxreorder.c | 2 +-
drivers/of/address.c | 22 +-
drivers/of/of_reserved_mem.c | 14 +-
drivers/pci/controller/dwc/pci-imx6.c | 9 +-
drivers/phy/qualcomm/phy-qcom-m31-eusb2.c | 2 +-
drivers/phy/xilinx/phy-zynqmp.c | 62 +-
drivers/pinctrl/Kconfig | 2 +
drivers/pinctrl/devicetree.c | 4 +
drivers/pinctrl/pinctrl-amd.c | 3 +-
drivers/pinctrl/qcom/pinctrl-msm.c | 8 +-
drivers/pinctrl/qcom/pinctrl-sc8280xp.c | 21 +-
drivers/power/supply/bq25890_charger.c | 2 +-
drivers/power/supply/macsmc-power.c | 52 +-
drivers/power/supply/max17040_battery.c | 6 +-
drivers/ptp/ptp_netc.c | 15 +-
drivers/s390/block/dasd_eckd.c | 11 +-
drivers/s390/block/dasd_ioctl.c | 2 +-
drivers/s390/crypto/pkey_cca.c | 15 +-
drivers/s390/crypto/zcrypt_api.c | 4 +-
drivers/s390/crypto/zcrypt_ccamisc.c | 89 ++-
drivers/s390/crypto/zcrypt_ccamisc.h | 6 +-
drivers/s390/net/qeth_core_main.c | 3 +
drivers/s390/scsi/zfcp_aux.c | 1 +
drivers/scsi/hisi_sas/hisi_sas_v3_hw.c | 10 +-
drivers/scsi/libiscsi.c | 2 +-
drivers/scsi/libiscsi_tcp.c | 8 +-
drivers/scsi/libsas/sas_init.c | 37 +-
drivers/scsi/libsas/sas_scsi_host.c | 15 +
drivers/scsi/mpi3mr/mpi3mr_fw.c | 9 +-
drivers/scsi/scsi_debug.c | 8 +-
drivers/spi/spi-cadence.c | 26 +-
drivers/spi/spi-nxp-fspi.c | 83 ++-
drivers/spi/spi-qcom-qspi.c | 3 +-
drivers/spi/spi-qpic-snand.c | 22 +-
drivers/target/target_core_iblock.c | 6 +-
drivers/target/target_core_transport.c | 12 +-
drivers/thunderbolt/xdomain.c | 40 +-
drivers/ufs/core/ufs-rpmb.c | 2 -
drivers/ufs/core/ufshcd.c | 46 +-
drivers/usb/typec/ucsi/ucsi.c | 88 +--
drivers/usb/typec/ucsi/ucsi.h | 1 +
fs/afs/fsclient.c | 5 +-
fs/afs/internal.h | 3 +-
fs/binfmt_misc.c | 54 +-
fs/btrfs/block-group.c | 34 +-
fs/btrfs/block-rsv.c | 19 +-
fs/btrfs/disk-io.c | 58 +-
fs/btrfs/extent_io.c | 6 -
fs/btrfs/extent_io.h | 6 +
fs/btrfs/fs.h | 9 +
fs/btrfs/raid56.c | 15 +-
fs/btrfs/super.c | 8 +-
fs/btrfs/zoned.c | 27 +-
fs/erofs/Kconfig | 36 +-
fs/erofs/Makefile | 1 -
fs/erofs/data.c | 4 +-
fs/erofs/decompressor_lzma.c | 3 +-
fs/erofs/fscache.c | 664 ---------------------
fs/erofs/inode.c | 2 +-
fs/erofs/internal.h | 76 +--
fs/erofs/ishare.c | 101 ++--
fs/erofs/super.c | 94 +--
fs/erofs/zdata.c | 6 -
fs/iomap/ioend.c | 21 +-
fs/netfs/buffered_read.c | 10 +-
fs/netfs/internal.h | 1 +
fs/netfs/main.c | 7 +
fs/netfs/objects.c | 30 +-
fs/netfs/read_pgpriv2.c | 3 +-
fs/netfs/rolling_buffer.c | 22 +-
fs/netfs/write_issue.c | 15 +-
fs/ntfs/attrib.c | 10 +
fs/ntfs/namei.c | 3 +-
fs/ntfs/runlist.c | 50 +-
fs/ocfs2/dir.c | 5 +-
fs/proc/task_mmu.c | 34 +-
fs/smb/client/cifssmb.c | 12 +-
fs/smb/client/inode.c | 1 +
fs/smb/server/connection.h | 5 +
fs/smb/server/smb2pdu.c | 14 +-
fs/smb/server/smb_common.c | 37 +-
fs/smb/server/vfs_cache.c | 6 +-
include/acpi/cppc_acpi.h | 5 +-
include/drm/drm_exec.h | 20 +-
include/hyperv/hvhdk_mini.h | 3 +-
include/kvm/arm_vgic.h | 3 -
include/linux/alloc_tag.h | 3 +
include/linux/dma/qcom_bam_dma.h | 21 +-
include/linux/ethtool.h | 1 +
include/linux/iommu.h | 5 +
include/linux/libata.h | 6 +-
include/linux/memcontrol.h | 25 +
include/linux/netfilter/nf_conntrack_sip.h | 2 +-
include/linux/netfs.h | 1 +
include/linux/rolling_buffer.h | 6 +-
include/linux/slab.h | 19 +-
include/linux/thunderbolt.h | 3 +
include/net/bluetooth/hci_core.h | 4 +-
include/net/ip_vs.h | 45 +-
include/net/mana/mana.h | 15 +-
include/net/netfilter/nf_conntrack_expect.h | 3 +
include/net/netfilter/nf_tables.h | 4 +-
include/net/xdp_sock.h | 1 +
include/net/xsk_buff_pool.h | 9 +-
include/scsi/libsas.h | 3 +-
io_uring/cancel.c | 2 +-
io_uring/net.c | 1 +
io_uring/tctx.c | 7 +-
io_uring/tctx.h | 1 +
kernel/audit.c | 11 +-
kernel/auditfilter.c | 6 +-
kernel/events/uprobes.c | 2 +-
kernel/sched/cpufreq_schedutil.c | 11 +
kernel/sched/deadline.c | 3 +-
kernel/trace/fprobe.c | 6 +-
kernel/trace/ring_buffer.c | 2 +
kernel/trace/trace_events.c | 4 +-
kernel/trace/trace_events_filter.c | 3 +
kernel/trace/trace_fprobe.c | 12 +-
kernel/trace/trace_mmiotrace.c | 13 +-
kernel/trace/trace_probe.c | 6 +-
lib/alloc_tag.c | 9 +
lib/assoc_array.c | 3 +-
lib/test_fortify/Makefile | 1 +
lib/test_hmm.c | 2 +-
mm/huge_memory.c | 14 +-
mm/hugetlb.c | 12 +-
mm/memcontrol-v1.h | 6 +-
mm/migrate_device.c | 5 +-
mm/mm_init.c | 15 +-
mm/page_reporting.c | 6 +-
mm/percpu-km.c | 2 +-
mm/slab.h | 28 +-
mm/slab_common.c | 13 +
mm/slub.c | 97 ++-
mm/util.c | 2 +-
mm/vmscan.c | 11 +-
net/bluetooth/hci_conn.c | 14 +-
net/bluetooth/hci_sync.c | 220 ++++---
net/bluetooth/hidp/core.c | 30 +-
net/bluetooth/iso.c | 273 ++++++---
net/bluetooth/l2cap_core.c | 5 +
net/bluetooth/mgmt.c | 84 ++-
net/bluetooth/sco.c | 22 +-
net/bridge/br_mrp.c | 2 +-
net/bridge/br_multicast.c | 1 +
net/can/isotp.c | 334 ++++++++---
net/can/j1939/bus.c | 2 +
net/can/j1939/j1939-priv.h | 3 +
net/can/j1939/main.c | 8 +-
net/can/j1939/transport.c | 4 +-
net/core/lwt_bpf.c | 4 +-
net/core/pktgen.c | 4 +-
net/core/skbuff.c | 18 +-
net/ipv4/fou_core.c | 2 +-
net/ipv4/netfilter/nf_nat_h323.c | 22 +-
net/ipv4/nexthop.c | 25 +-
net/ipv4/route.c | 2 -
net/ipv4/udp_tunnel_nic.c | 32 +-
net/ipv6/fib6_rules.c | 1 +
net/ipv6/ip6_fib.c | 1 +
net/ipv6/ip6_output.c | 2 +-
net/ipv6/ndisc.c | 2 +
net/mac80211/agg-tx.c | 4 +-
net/mac80211/s1g.c | 4 +
net/mpls/af_mpls.c | 1 +
net/netfilter/ipset/ip_set_hash_gen.h | 2 +-
net/netfilter/ipvs/ip_vs_app.c | 4 +-
net/netfilter/ipvs/ip_vs_conn.c | 192 ++++--
net/netfilter/ipvs/ip_vs_core.c | 190 +++---
net/netfilter/ipvs/ip_vs_proto_sctp.c | 19 +-
net/netfilter/ipvs/ip_vs_proto_tcp.c | 48 +-
net/netfilter/ipvs/ip_vs_proto_udp.c | 54 +-
net/netfilter/ipvs/ip_vs_xmit.c | 42 +-
net/netfilter/nf_conntrack_expect.c | 35 +-
net/netfilter/nf_conntrack_sip.c | 2 +-
net/netfilter/nf_nat_sip.c | 22 +-
net/netfilter/nf_tables_api.c | 34 +-
net/netfilter/nft_payload.c | 12 +-
net/netfilter/xt_hashlimit.c | 16 +-
net/openvswitch/actions.c | 12 +-
net/openvswitch/meter.c | 33 +-
net/rds/tcp.c | 8 +-
net/sched/cls_u32.c | 7 +
net/sched/sch_cake.c | 8 +-
net/sctp/associola.c | 3 +
net/sctp/sm_make_chunk.c | 17 +-
net/smc/smc_core.c | 2 +-
net/tipc/socket.c | 2 +-
net/unix/af_unix.c | 1 +
net/xdp/xsk.c | 257 +++++++-
net/xdp/xsk_buff_pool.c | 13 +-
net/xdp/xsk_queue.h | 65 +-
security/keys/keyring.c | 14 +-
security/keys/trusted-keys/trusted_dcp.c | 15 +-
sound/core/pcm_native.c | 7 +
sound/core/seq/seq_timer.c | 9 +-
sound/core/timer.c | 2 +
sound/core/ump.c | 1 +
sound/hda/codecs/realtek/alc269.c | 4 +-
sound/pci/lx6464es/lx6464es.c | 5 +-
sound/pci/lx6464es/lx_core.c | 5 +-
sound/soc/codecs/max98090.c | 5 +-
sound/soc/codecs/max98095.c | 5 +-
sound/soc/codecs/tas2562.c | 30 +-
sound/soc/codecs/tas2781-i2c.c | 4 +-
sound/soc/fsl/fsl_asrc.c | 2 +-
sound/soc/fsl/fsl_easrc.c | 2 +-
sound/soc/sdca/sdca_device.c | 2 +-
sound/soc/sdca/sdca_fdl.c | 5 +-
sound/soc/sdca/sdca_functions.c | 2 +
sound/soc/sdca/sdca_ump.c | 4 +-
sound/soc/sophgo/cv1800b-sound-adc.c | 10 +-
sound/usb/6fire/chip.c | 4 +
sound/usb/endpoint.c | 14 +-
sound/usb/midi.c | 2 +
sound/usb/midi2.c | 4 +-
sound/usb/mixer_quirks.c | 2 +-
tools/testing/selftests/clone3/clone3_set_tid.c | 2 +-
tools/testing/selftests/filesystems/fclog.c | 4 +-
tools/testing/selftests/lkdtm/tests.txt | 2 +-
tools/testing/selftests/mm/mlock-random-test.c | 2 +-
tools/testing/selftests/mm/pagemap_ioctl.c | 56 +-
tools/testing/selftests/net/af_unix/.gitignore | 1 +
tools/testing/selftests/net/af_unix/Makefile | 1 +
tools/testing/selftests/net/af_unix/unix_listen.c | 187 ++++++
.../selftests/net/netfilter/nft_flowtable.sh | 14 +-
tools/testing/selftests/seccomp/seccomp_bpf.c | 3 +-
tools/tracing/rtla/src/timerlat_top.c | 2 +-
455 files changed, 6043 insertions(+), 3365 deletions(-)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 001/438] net: mpls: initialize rtm_tos in mpls_getroute()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 002/438] mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT Greg Kroah-Hartman
` (450 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Paolo Abeni,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 295dd295e2137e10e9a5b1891d97e0f08de76f03 ]
mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE
request by filling a struct rtmsg allocated from an skb whose data
area is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every
field of the header except rtm_tos:
r = nlmsg_data(nlh);
r->rtm_family = AF_MPLS;
r->rtm_dst_len = 20;
r->rtm_src_len = 0;
r->rtm_table = RT_TABLE_MAIN;
r->rtm_type = RTN_UNICAST;
r->rtm_scope = RT_SCOPE_UNIVERSE;
r->rtm_protocol = rt->rt_protocol;
r->rtm_flags = 0;
struct rtmsg has no padding, so the one uninitialised byte rtm_tos
(offset 3) is copied straight to user space on recvmsg(), leaking a
byte of uninitialised heap memory. This is in contrast to
mpls_dump_route(), which fills the very same header and does set
rtm_tos = 0.
Initialize rtm_tos to 0, matching mpls_dump_route().
Reproduced with KMSAN by adding an MPLS route and issuing a
non-RTM_F_FIB_MATCH RTM_GETROUTE for its label:
BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0
_copy_to_iter+0x36c/0x33f0
__skb_datagram_iter+0x196/0x12c0
skb_copy_datagram_iter+0x5b/0x210
netlink_recvmsg+0x37b/0xef0
...
Uninit was created at:
__alloc_skb+0x8ca/0x10e0
mpls_getroute+0x1280/0x3a40
rtnetlink_rcv_msg+0x1138/0x15a0
...
Byte 19 of 64 is uninitialized
(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)
Fixes: 397fc9e5cefe ("mpls: route get support")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260723010830.289917-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mpls/af_mpls.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/mpls/af_mpls.c b/net/mpls/af_mpls.c
index 35069183f59c..1ad5a2d9b6cd 100644
--- a/net/mpls/af_mpls.c
+++ b/net/mpls/af_mpls.c
@@ -2541,6 +2541,7 @@ static int mpls_getroute(struct sk_buff *in_skb, struct nlmsghdr *in_nlh,
r->rtm_family = AF_MPLS;
r->rtm_dst_len = 20;
r->rtm_src_len = 0;
+ r->rtm_tos = 0;
r->rtm_table = RT_TABLE_MAIN;
r->rtm_type = RTN_UNICAST;
r->rtm_scope = RT_SCOPE_UNIVERSE;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 002/438] mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 001/438] net: mpls: initialize rtm_tos in mpls_getroute() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 003/438] lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() Greg Kroah-Hartman
` (449 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlastimil Babka (SUSE),
Harry Yoo (Oracle), Suren Baghdasaryan, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harry Yoo (Oracle) <harry@kernel.org>
commit 982e31382d9a1a3c8c4e6a13702a53711f4efe9f upstream.
Bootstrap caches are created with SLAB_NO_OBJ_EXT to disallow sheaves
and obj_exts.
To allow disabling obj_exts while allowing sheaves, decouple
SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT. Bootstrap caches now have both
SLAB_NO_SHEAVES and SLAB_NO_OBJ_EXT.
No functional change intended.
Reviewed-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Signed-off-by: Harry Yoo (Oracle) <harry@kernel.org>
Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Link: https://patch.msgid.link/20260713-kmalloc-no-objext-v3-2-47c7bd138de7@kernel.org
Signed-off-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Signed-off-by: Harry Yoo <harry@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/slab.h | 13 +++++++++++--
mm/slub.c | 10 ++++++----
2 files changed, 17 insertions(+), 6 deletions(-)
diff --git a/include/linux/slab.h b/include/linux/slab.h
index 1a69255bb87f..fda7e24a762b 100644
--- a/include/linux/slab.h
+++ b/include/linux/slab.h
@@ -58,10 +58,13 @@ enum _slab_flag_bits {
#endif
_SLAB_OBJECT_POISON,
_SLAB_CMPXCHG_DOUBLE,
+#ifdef CONFIG_SLAB_OBJ_EXT
_SLAB_NO_OBJ_EXT,
-#if defined(CONFIG_SLAB_OBJ_EXT) && defined(CONFIG_64BIT)
+#ifdef CONFIG_64BIT
_SLAB_OBJ_EXT_IN_OBJ,
#endif
+#endif
+ _SLAB_NO_SHEAVES,
_SLAB_FLAGS_LAST_BIT
};
@@ -239,8 +242,14 @@ enum _slab_flag_bits {
#endif
#define SLAB_TEMPORARY SLAB_RECLAIM_ACCOUNT /* Objects are short-lived */
-/* Slab created using create_boot_cache */
+/* Slab caches without obj_exts array */
+#ifdef CONFIG_SLAB_OBJ_EXT
#define SLAB_NO_OBJ_EXT __SLAB_FLAG_BIT(_SLAB_NO_OBJ_EXT)
+#else
+#define SLAB_NO_OBJ_EXT __SLAB_FLAG_UNUSED
+#endif
+
+#define SLAB_NO_SHEAVES __SLAB_FLAG_BIT(_SLAB_NO_SHEAVES)
#if defined(CONFIG_SLAB_OBJ_EXT) && defined(CONFIG_64BIT)
#define SLAB_OBJ_EXT_IN_OBJ __SLAB_FLAG_BIT(_SLAB_OBJ_EXT_IN_OBJ)
diff --git a/mm/slub.c b/mm/slub.c
index 12ace2932927..b0e8c4ae2f37 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -7724,12 +7724,12 @@ static unsigned int calculate_sheaf_capacity(struct kmem_cache *s,
return 0;
/*
- * Bootstrap caches can't have sheaves for now (SLAB_NO_OBJ_EXT).
+ * Bootstrap caches can't have sheaves for now (SLAB_NO_SHEAVES).
* SLAB_NOLEAKTRACE caches (e.g., kmemleak's object_cache) must not
* have sheaves to avoid recursion when sheaf allocation triggers
* kmemleak tracking.
*/
- if (s->flags & (SLAB_NO_OBJ_EXT | SLAB_NOLEAKTRACE))
+ if (s->flags & (SLAB_NO_SHEAVES | SLAB_NOLEAKTRACE))
return 0;
/*
@@ -8511,7 +8511,8 @@ void __init kmem_cache_init(void)
create_boot_cache(kmem_cache_node, "kmem_cache_node",
sizeof(struct kmem_cache_node),
- SLAB_HWCACHE_ALIGN | SLAB_NO_OBJ_EXT, 0, 0);
+ SLAB_HWCACHE_ALIGN | SLAB_NO_SHEAVES | SLAB_NO_OBJ_EXT,
+ 0, 0);
hotplug_node_notifier(slab_memory_callback, SLAB_CALLBACK_PRI);
@@ -8521,7 +8522,8 @@ void __init kmem_cache_init(void)
create_boot_cache(kmem_cache, "kmem_cache",
offsetof(struct kmem_cache, per_node) +
nr_node_ids * sizeof(struct kmem_cache_per_node_ptrs),
- SLAB_HWCACHE_ALIGN | SLAB_NO_OBJ_EXT, 0, 0);
+ SLAB_HWCACHE_ALIGN | SLAB_NO_SHEAVES | SLAB_NO_OBJ_EXT,
+ 0, 0);
kmem_cache = bootstrap(&boot_kmem_cache);
kmem_cache_node = bootstrap(&boot_kmem_cache_node);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 003/438] lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 001/438] net: mpls: initialize rtm_tos in mpls_getroute() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 002/438] mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 004/438] mm/slab: prevent unbounded recursion in free path with new kmalloc type Greg Kroah-Hartman
` (448 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Harry Yoo (Oracle),
Suren Baghdasaryan, Vlastimil Babka (SUSE), Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harry Yoo (Oracle) <harry@kernel.org>
commit a37b0066a10aabf3c968b4566706fb866eaf9a85 upstream.
mem_alloc_profiling_enabled() tells whether memalloc profiling is
currently enabled. However, even when this function returns false,
it can be enabled later.
However, this is not enough. Some optimizations can be applied only when
memalloc profiling is permanently disabled. For example, to skip the
creation of KMALLOC_NO_OBJ_EXT caches at boot time, mem_profiling must
be set to "never", "0" w/ debugging on, or have been shutdown so that
it can no longer be enabled.
Introduce mem_alloc_profiling_permanently_disabled() for this purpose.
Signed-off-by: Harry Yoo (Oracle) <harry@kernel.org>
Acked-by: Suren Baghdasaryan <surenb@google.com>
Link: https://patch.msgid.link/20260713-kmalloc-no-objext-v3-3-47c7bd138de7@kernel.org
Signed-off-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Signed-off-by: Harry Yoo <harry@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/alloc_tag.h | 3 +++
lib/alloc_tag.c | 9 +++++++++
2 files changed, 12 insertions(+)
diff --git a/include/linux/alloc_tag.h b/include/linux/alloc_tag.h
index 02de2ede560f..7e7cdc7612be 100644
--- a/include/linux/alloc_tag.h
+++ b/include/linux/alloc_tag.h
@@ -134,6 +134,8 @@ static inline bool mem_alloc_profiling_enabled(void)
&mem_alloc_profiling_key);
}
+bool mem_alloc_profiling_permanently_disabled(void);
+
static inline struct alloc_tag_counters alloc_tag_read(struct alloc_tag *tag)
{
struct alloc_tag_counters v = { 0, 0 };
@@ -239,6 +241,7 @@ static inline bool alloc_tag_is_inaccurate(struct alloc_tag *tag)
#define DEFINE_ALLOC_TAG(_alloc_tag)
static inline bool mem_alloc_profiling_enabled(void) { return false; }
+static inline bool mem_alloc_profiling_permanently_disabled(void) { return true; }
static inline void alloc_tag_add(union codetag_ref *ref, struct alloc_tag *tag,
size_t bytes) {}
static inline void alloc_tag_sub(union codetag_ref *ref, size_t bytes) {}
diff --git a/lib/alloc_tag.c b/lib/alloc_tag.c
index a9ab88f416b9..e3a923594604 100644
--- a/lib/alloc_tag.c
+++ b/lib/alloc_tag.c
@@ -26,6 +26,15 @@ static bool mem_profiling_support = true;
static bool mem_profiling_support;
#endif
+/*
+ * Memory allocation profiling is permanently disabled and cannot be enabled.
+ * Must be called after setup_early_mem_profiling().
+ */
+bool mem_alloc_profiling_permanently_disabled(void)
+{
+ return !mem_profiling_support;
+}
+
static struct codetag_type *alloc_tag_cttype;
#ifdef CONFIG_ARCH_MODULE_NEEDS_WEAK_PER_CPU
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 004/438] mm/slab: prevent unbounded recursion in free path with new kmalloc type
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 003/438] lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 005/438] ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05) Greg Kroah-Hartman
` (447 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Danielle Costantino, Shakeel Butt,
Harry Yoo (Oracle), Suren Baghdasaryan, Vlastimil Babka (SUSE),
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harry Yoo (Oracle) <harry@kernel.org>
commit d9e6a7623938968e3752b67e37eaff097e559a54 upstream.
Commit 280ea9c3154b ("mm/slab: avoid allocating slabobj_ext array from
its own slab") avoided recursive allocation of obj_exts from kmalloc
caches of the same size, by bumping the obj_exts array's allocation
size whenever the array size equals the size of the object being
allocated.
However, as reported by Danielle Costantino and Shakeel Butt,
even slabs from kmalloc caches of different sizes can form a cycle
by allocating obj_exts arrays from each other [1]:
What happened: a KMALLOC_NORMAL slab's obj_exts array (used by
allocation profiling / memcg accounting) is itself kmalloc()'d from a
KMALLOC_NORMAL cache, so the "slab holds another slab's obj_exts array"
relation can form cycles. With sizeof(struct slabobj_ext) == 16 and
the host's geometry:
- kmalloc-512 has 64 objects/slab -> array is 64*16 == 1024 bytes,
served from kmalloc-1k;
- kmalloc-1k has 32 objects/slab -> array is 32*16 == 512 bytes,
served from kmalloc-512.
A kmalloc-512 slab and a kmalloc-1k slab therefore hold each other's
obj_exts array. Discarding one frees the other's array, which empties
and discards that slab, which frees the first's array, and so on:
__free_slab() -> free_slab_obj_exts() -> kfree() -> discard_slab() ->
__free_slab() recurses along the cycle until the stack is exhausted.
With memory allocation profiling, this allows unbounded recursion
in the free path and led to a stack overflow on a production host in
the Meta fleet [1]:
BUG: TASK stack guard page was hit
Oops: stack guard page
RIP: 0010:kfree+0x8/0x5d0
Call Trace:
__free_slab+0x66/0xc0
kfree+0x3f0/0x5d0
... ( ~125x __free_slab <-> kfree ) ...
<kernel driver freeing a resource>
do_syscall_64
It is proposed [1] to resolve this issue by always serving the obj_exts
array allocation from kmalloc caches (or large kmalloc) of sizes larger
than the object size. However, as pointed out by Vlastimil Babka [2],
this can waste an excessive amount of memory as slabs from large
kmalloc sizes (e.g. kmalloc-8k) generally need obj_exts arrays much
smaller than the object size.
Therefore, rather than bumping the size, let us take a different
approach; disallow formation of cycles between kmalloc types when
allocating obj_exts arrays. Currently, all obj_exts arrays are served
from normal kmalloc caches. Cycles cannot be created if obj_exts arrays
of normal kmalloc caches are served from a special kmalloc type that can
never have obj_exts arrays.
To achieve this, create a new kmalloc type called KMALLOC_NO_OBJ_EXT.
KMALLOC_NO_OBJ_EXT caches are created with SLAB_NO_OBJ_EXT flag when
either 1) memory allocation profiling is not permanently disabled,
or 2) kmalloc types with a priority higher than KMALLOC_CGROUP are
aliased with KMALLOC_NORMAL.
Sheaf bootstrapping for KMALLOC_NO_OBJ_EXT caches now must be deferred
because allocation of a barn can trigger obj_exts array allocation of
normal kmalloc caches when the KMALLOC_NO_OBJ_EXT cache for that size
is not ready yet. For simplicity, perform bootstrapping of sheaves for
all kmalloc caches later.
Introduce a new slab alloc flag, SLAB_ALLOC_NO_OBJ_EXT, to prevent
allocation of obj_exts arrays, and let kmalloc_slab() override the type
to KMALLOC_NO_OBJ_EXT when specified. Note that kmalloc_type() remains
unchanged because kmalloc_flags() bypasses the kmalloc fastpath.
Do not pass SLAB_ALLOC_NO_RECURSE to kmalloc_flags() in
alloc_slab_obj_exts() and instead use SLAB_ALLOC_NO_OBJ_EXT only when
the objects are allocated from normal kmalloc caches. While this
prevents unbounded recursive allocation of obj_exts, it allows
KMALLOC_NO_OBJ_EXT caches to have sheaves.
Since sheaf allocations specify SLAB_ALLOC_NO_RECURSE that prevents
allocation of both sheaves and obj_exts arrays, the recursion depth
is bounded.
obj_exts arrays for non-kmalloc-normal caches can now have a valid tag.
Do not call mark_obj_codetag_empty() when freeing an obj_exts array to
avoid false warnings. KMALLOC_NO_OBJ_EXT don't need this as they never
allocate those arrays.
Reported-by: Danielle Costantino <dcostantino@meta.com>
Reported-by: Shakeel Butt <shakeel.butt@linux.dev>
Closes: https://lore.kernel.org/linux-mm/20260625230029.703750-1-shakeel.butt@linux.dev [1]
Fixes: 4b8736964640 ("mm/slab: add allocation accounting into slab allocation and free paths")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/linux-mm/c5c4208d-a6f0-413e-bad9-49be12f12d55@kernel.org [2]
Signed-off-by: Harry Yoo (Oracle) <harry@kernel.org>
Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Link: https://patch.msgid.link/20260713-kmalloc-no-objext-v3-4-47c7bd138de7@kernel.org
Signed-off-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
[harry@kernel.org: Backport notes:
- Fix a minor conflict due to missing partitioned
kmalloc caches in 7.1.
- Use __GFP_NO_OBJ_EXT instead of SLAB_ALLOC_NO_OBJ_EXT
since slab's internal alloc_flags do not exist in 7.1.
- Since there is no way to distinguish between no obj_exts vs.
no recursion in 7.1 due to lack of SLAB_ALLOC_* flags, sheaves for
normal kmalloc caches are allocated from kmalloc-no-objext-* unlike
upstream.
Also, allocations from kmalloc-no-objext cannot allocate sheaves and
may observe slightly higher contention. Only 7.1 has this problem as
kmalloc caches don't have sheaves in LTS kernels.
- Apply the __GFP_NO_OBJ_EXT flag to the !allow_spin path in
alloc_slab_obj_exts(). ]
Signed-off-by: Harry Yoo <harry@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/slab.h | 6 +++
mm/slab.h | 28 +++++++++++++-
mm/slab_common.c | 13 +++++++
mm/slub.c | 87 +++++++++++++++-----------------------------
4 files changed, 75 insertions(+), 59 deletions(-)
diff --git a/include/linux/slab.h b/include/linux/slab.h
index fda7e24a762b..739f474c5d92 100644
--- a/include/linux/slab.h
+++ b/include/linux/slab.h
@@ -642,6 +642,9 @@ enum kmalloc_cache_type {
#endif
#ifndef CONFIG_MEMCG
KMALLOC_CGROUP = KMALLOC_NORMAL,
+#endif
+#ifndef CONFIG_SLAB_OBJ_EXT
+ KMALLOC_NO_OBJ_EXT = KMALLOC_NORMAL,
#endif
KMALLOC_RANDOM_START = KMALLOC_NORMAL,
KMALLOC_RANDOM_END = KMALLOC_RANDOM_START + RANDOM_KMALLOC_CACHES_NR,
@@ -655,6 +658,9 @@ enum kmalloc_cache_type {
#endif
#ifdef CONFIG_MEMCG
KMALLOC_CGROUP,
+#endif
+#ifdef CONFIG_SLAB_OBJ_EXT
+ KMALLOC_NO_OBJ_EXT,
#endif
NR_KMALLOC_TYPES
};
diff --git a/mm/slab.h b/mm/slab.h
index bf2f87acf5e3..50414bd2b919 100644
--- a/mm/slab.h
+++ b/mm/slab.h
@@ -365,9 +365,13 @@ static inline struct kmem_cache *
kmalloc_slab(size_t size, kmem_buckets *b, gfp_t flags, unsigned long caller)
{
unsigned int index;
+ enum kmalloc_cache_type type = kmalloc_type(flags, caller);
+
+ if (flags & __GFP_NO_OBJ_EXT)
+ type = KMALLOC_NO_OBJ_EXT;
if (!b)
- b = &kmalloc_caches[kmalloc_type(flags, caller)];
+ b = &kmalloc_caches[type];
if (size <= 192)
index = kmalloc_size_index[size_index_elem(size)];
else
@@ -402,7 +406,8 @@ static inline bool is_kmalloc_normal(struct kmem_cache *s)
{
if (!is_kmalloc_cache(s))
return false;
- return !(s->flags & (SLAB_CACHE_DMA|SLAB_ACCOUNT|SLAB_RECLAIM_ACCOUNT));
+
+ return !(s->flags & (SLAB_CACHE_DMA|SLAB_ACCOUNT|SLAB_RECLAIM_ACCOUNT|SLAB_NO_OBJ_EXT));
}
bool __kfree_rcu_sheaf(struct kmem_cache *s, void *obj);
@@ -505,6 +510,25 @@ static inline void metadata_access_disable(void)
kasan_enable_current();
}
+/*
+ * Return true if KMALLOC_NORMAL caches may need obj_exts arrays.
+ *
+ * Memory allocation profiling requires obj_exts for all caches.
+ * Memcg usually doesn't need them for normal kmalloc caches, but kmalloc types
+ * with a priority higher than KMALLOC_CGROUP can be aliased with KMALLOC_NORMAL.
+ */
+static inline bool need_kmalloc_no_objext(void)
+{
+ if (!mem_alloc_profiling_permanently_disabled())
+ return true;
+
+ if (!mem_cgroup_kmem_disabled() &&
+ (KMALLOC_NORMAL == KMALLOC_RECLAIM))
+ return true;
+
+ return false;
+}
+
#ifdef CONFIG_SLAB_OBJ_EXT
/*
diff --git a/mm/slab_common.c b/mm/slab_common.c
index 8b661fff5eed..214374233fb8 100644
--- a/mm/slab_common.c
+++ b/mm/slab_common.c
@@ -843,6 +843,12 @@ EXPORT_SYMBOL(kmalloc_size_roundup);
#define KMALLOC_RANDOM_NAME(N, sz)
#endif
+#ifdef CONFIG_SLAB_OBJ_EXT
+#define KMALLOC_NO_OBJ_EXT_NAME(sz) .name[KMALLOC_NO_OBJ_EXT] = "kmalloc-no-objext-" #sz,
+#else
+#define KMALLOC_NO_OBJ_EXT_NAME(sz)
+#endif
+
#define INIT_KMALLOC_INFO(__size, __short_size) \
{ \
.name[KMALLOC_NORMAL] = "kmalloc-" #__short_size, \
@@ -850,6 +856,7 @@ EXPORT_SYMBOL(kmalloc_size_roundup);
KMALLOC_CGROUP_NAME(__short_size) \
KMALLOC_DMA_NAME(__short_size) \
KMALLOC_RANDOM_NAME(RANDOM_KMALLOC_CACHES_NR, __short_size) \
+ KMALLOC_NO_OBJ_EXT_NAME(__short_size) \
.size = __size, \
}
@@ -957,6 +964,12 @@ new_kmalloc_cache(int idx, enum kmalloc_cache_type type)
return;
}
flags |= SLAB_ACCOUNT;
+ } else if (IS_ENABLED(CONFIG_SLAB_OBJ_EXT) && type == KMALLOC_NO_OBJ_EXT) {
+ if (!need_kmalloc_no_objext()) {
+ kmalloc_caches[type][idx] = kmalloc_caches[KMALLOC_NORMAL][idx];
+ return;
+ }
+ flags |= SLAB_NO_OBJ_EXT | SLAB_NO_MERGE;
} else if (IS_ENABLED(CONFIG_ZONE_DMA) && (type == KMALLOC_DMA)) {
flags |= SLAB_CACHE_DMA;
}
diff --git a/mm/slub.c b/mm/slub.c
index b0e8c4ae2f37..b2fdb10b6b65 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -2106,42 +2106,6 @@ static inline void init_slab_obj_exts(struct slab *slab)
slab->obj_exts = 0;
}
-/*
- * Calculate the allocation size for slabobj_ext array.
- *
- * When memory allocation profiling is enabled, the obj_exts array
- * could be allocated from the same slab cache it's being allocated for.
- * This would prevent the slab from ever being freed because it would
- * always contain at least one allocated object (its own obj_exts array).
- *
- * To avoid this, increase the allocation size when we detect the array
- * may come from the same cache, forcing it to use a different cache.
- */
-static inline size_t obj_exts_alloc_size(struct kmem_cache *s,
- struct slab *slab, gfp_t gfp)
-{
- size_t sz = sizeof(struct slabobj_ext) * slab->objects;
- struct kmem_cache *obj_exts_cache;
-
- if (sz > KMALLOC_MAX_CACHE_SIZE)
- return sz;
-
- if (!is_kmalloc_normal(s))
- return sz;
-
- obj_exts_cache = kmalloc_slab(sz, NULL, gfp, 0);
- /*
- * We can't simply compare s with obj_exts_cache, because random kmalloc
- * caches have multiple caches per size, selected by caller address.
- * Since caller address may differ between kmalloc_slab() and actual
- * allocation, bump size when sizes are equal.
- */
- if (s->object_size == obj_exts_cache->object_size)
- return obj_exts_cache->object_size + 1;
-
- return sz;
-}
-
int alloc_slab_obj_exts(struct slab *slab, struct kmem_cache *s,
gfp_t gfp, bool new_slab)
{
@@ -2150,13 +2114,17 @@ int alloc_slab_obj_exts(struct slab *slab, struct kmem_cache *s,
unsigned long new_exts;
unsigned long old_exts;
struct slabobj_ext *vec;
- size_t sz;
+ size_t sz = sizeof(struct slabobj_ext) * slab->objects;
gfp &= ~OBJCGS_CLEAR_MASK;
- /* Prevent recursive extension vector allocation */
- gfp |= __GFP_NO_OBJ_EXT;
- sz = obj_exts_alloc_size(s, slab, gfp);
+ /*
+ * In most cases, obj_exts arrays are allocated from normal kmalloc.
+ * However, normal kmalloc caches must allocate them from
+ * KMALLOC_NO_OBJ_EXT caches to prevent recursion.
+ */
+ if (is_kmalloc_normal(s))
+ gfp |= __GFP_NO_OBJ_EXT;
/*
* Note that allow_spin may be false during early boot and its
@@ -2165,10 +2133,11 @@ int alloc_slab_obj_exts(struct slab *slab, struct kmem_cache *s,
* very early allocations on those.
*/
if (unlikely(!allow_spin))
- vec = kmalloc_nolock(sz, __GFP_ZERO | __GFP_NO_OBJ_EXT,
+ vec = kmalloc_nolock(sz, __GFP_ZERO | (gfp & __GFP_NO_OBJ_EXT),
slab_nid(slab));
else
- vec = kmalloc_node(sz, gfp | __GFP_ZERO, slab_nid(slab));
+ vec = kmalloc_node(sz, gfp | __GFP_ZERO,
+ slab_nid(slab));
if (!vec) {
/*
@@ -2183,8 +2152,21 @@ int alloc_slab_obj_exts(struct slab *slab, struct kmem_cache *s,
return -ENOMEM;
}
- VM_WARN_ON_ONCE(virt_to_slab(vec) != NULL &&
- virt_to_slab(vec)->slab_cache == s);
+ if (IS_ENABLED(CONFIG_DEBUG_VM)) {
+ struct kmem_cache *exts_cache;
+ struct slab *exts_slab;
+
+ exts_slab = virt_to_slab(vec);
+ if (exts_slab) {
+ /*
+ * The vector must be allocated from either normal or
+ * KMALLOC_NO_OBJ_EXT kmalloc caches to avoid cycles.
+ */
+ exts_cache = exts_slab->slab_cache;
+ WARN_ON_ONCE(!is_kmalloc_normal(exts_cache) &&
+ !(exts_cache->flags & SLAB_NO_OBJ_EXT));
+ }
+ }
new_exts = (unsigned long)vec;
#ifdef CONFIG_MEMCG
@@ -2207,7 +2189,6 @@ int alloc_slab_obj_exts(struct slab *slab, struct kmem_cache *s,
* assign slabobj_exts in parallel. In this case the existing
* objcg vector should be reused.
*/
- mark_obj_codetag_empty(vec);
if (unlikely(!allow_spin))
kfree_nolock(vec);
else
@@ -2243,14 +2224,6 @@ static inline void free_slab_obj_exts(struct slab *slab, bool allow_spin)
return;
}
- /*
- * obj_exts was created with __GFP_NO_OBJ_EXT flag, therefore its
- * corresponding extension will be NULL. alloc_tag_sub() will throw a
- * warning if slab has extensions but the extension of an object is
- * NULL, therefore replace NULL with CODETAG_EMPTY to indicate that
- * the extension for obj_exts is expected to be NULL.
- */
- mark_obj_codetag_empty(obj_exts);
if (allow_spin)
kfree(obj_exts);
else
@@ -7904,10 +7877,10 @@ static int calculate_sizes(struct kmem_cache_args *args, struct kmem_cache *s)
s->allocflags |= __GFP_RECLAIMABLE;
/*
- * For KMALLOC_NORMAL caches we enable sheaves later by
- * bootstrap_kmalloc_sheaves() to avoid recursion
+ * For kmalloc caches we enable sheaves later by
+ * bootstrap_kmalloc_sheaves() to avoid recursion.
*/
- if (!is_kmalloc_normal(s))
+ if (!is_kmalloc_cache(s))
s->sheaf_capacity = calculate_sheaf_capacity(s, args);
/*
@@ -8473,7 +8446,7 @@ static void __init bootstrap_kmalloc_sheaves(void)
{
enum kmalloc_cache_type type;
- for (type = KMALLOC_NORMAL; type <= KMALLOC_RANDOM_END; type++) {
+ for (type = KMALLOC_NORMAL; type < NR_KMALLOC_TYPES; type++) {
for (int idx = 0; idx < KMALLOC_SHIFT_HIGH + 1; idx++) {
struct kmem_cache *s = kmalloc_caches[type][idx];
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 005/438] ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 004/438] mm/slab: prevent unbounded recursion in free path with new kmalloc type Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 006/438] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect Greg Kroah-Hartman
` (446 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Diesen, Takashi Iwai,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Diesen <michael.diesen@posteo.de>
[ Upstream commit bed0c8084044364f5ac3f3e89e1bbad423f6b0d4 ]
The HP Dragonfly Folio G3 2-in-1 also ships with PCI SSID 103c:8a05.
On this unit the ALC245 codec reports subsystem id 103c:8a06 - the SSID
that is already covered by commit 0a10faad5ca5 ("ALSA: hda/realtek: add
quirk for HP Dragonfly Folio G3 2-in-1") - while the PCI SSID that
SND_PCI_QUIRK matches against is 103c:8a05:
snd_hda_codec_alc269 ehdaudio0D0: ALC245: picked fixup for PCI SSID 103c:8a05
cs35l41-hda spi1-CSC3551:00-cs35l41-hda.0: CS35L41 Bound - SSID: 103C8A06
The existing entry therefore never applies here, the four CS35L41
amplifiers on SPI are not registered and the internal speakers stay
silent.
Add the same fixup that the 8a06 entry uses: the four amplifiers bind
and the speaker mute LED (codec GPIO 0x04) works.
Signed-off-by: Michael Diesen <michael.diesen@posteo.de>
Link: https://patch.msgid.link/20260727091920.4634-1-michael.diesen@posteo.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/hda/codecs/realtek/alc269.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/hda/codecs/realtek/alc269.c b/sound/hda/codecs/realtek/alc269.c
index 427caf08145d..cfc313f49381 100644
--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -7086,6 +7086,7 @@ static const struct hda_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x103c, 0x89d3, "HP EliteBook 645 G9 (MB 89D2)", ALC236_FIXUP_HP_MUTE_LED_MICMUTE_VREF),
SND_PCI_QUIRK(0x103c, 0x89da, "HP Spectre x360 14t-ea100", ALC245_FIXUP_HP_SPECTRE_X360_EU0XXX),
SND_PCI_QUIRK(0x103c, 0x89e7, "HP Elite x2 G9", ALC245_FIXUP_CS35L41_SPI_2_HP_GPIO_LED),
+ SND_PCI_QUIRK(0x103c, 0x8a05, "HP Dragonfly Folio G3 2-in-1", ALC245_FIXUP_CS35L41_SPI_4_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8a06, "HP Dragonfly Folio G3 2-in-1", ALC245_FIXUP_CS35L41_SPI_4_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8a0f, "HP Pavilion 14-ec1xxx", ALC287_FIXUP_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8a1f, "HP Laptop 14s-dr5xxx", ALC236_FIXUP_HP_MUTE_LED_COEFBIT2),
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 006/438] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 005/438] ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05) Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 007/438] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context Greg Kroah-Hartman
` (445 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Mika Westerberg,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 2c5d2d3c3f70cde2565d7b279b544893a2035842 ]
tb_xdp_handle_request() runs on system_wq and queues
xd->state_work via queue_delayed_work() in three request handlers:
PROPERTIES_CHANGED_REQUEST, UUID_REQUEST (via start_handshake),
and LINK_STATE_CHANGE_REQUEST. Similarly, update_xdomain() queues
xd->properties_changed_work when local properties change.
Concurrently, tb_xdomain_remove() calls stop_handshake() which does
cancel_delayed_work_sync() on both delayed works. Later,
tb_xdomain_unregister() calls device_unregister() which eventually
frees the xdomain. Since commit 559c1e1e0134 ("thunderbolt: Run
tb_xdp_handle_request() in system workqueue") moved the request
handler off tb->wq, the handler and the remove path are no longer
serialized. If queue_delayed_work() executes after
cancel_delayed_work_sync() but before the xdomain is freed, the
delayed work fires on a freed object.
Add xd->removing that tb_xdomain_remove() sets under xd->lock
before calling stop_handshake(). Each external queue site holds
the same lock and checks removing before calling
queue_delayed_work(). This provides the mutual exclusion needed:
either the queue site acquires the lock first and queues work that
the subsequent cancel will see, or the remove path acquires the
lock first and the queue site observes removing == true and skips
the queue.
Fixes: 559c1e1e0134 ("thunderbolt: Run tb_xdp_handle_request() in system workqueue")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thunderbolt/xdomain.c | 40 ++++++++++++++++++++++++++---------
include/linux/thunderbolt.h | 3 +++
2 files changed, 33 insertions(+), 10 deletions(-)
diff --git a/drivers/thunderbolt/xdomain.c b/drivers/thunderbolt/xdomain.c
index 1fd1cf4295a2a..55f91ead8f13b 100644
--- a/drivers/thunderbolt/xdomain.c
+++ b/drivers/thunderbolt/xdomain.c
@@ -785,9 +785,13 @@ static void tb_xdp_handle_request(struct work_struct *work)
* the xdomain related to this connection as well in
* case there is a change in services it offers.
*/
- if (xd && device_is_registered(&xd->dev))
- queue_delayed_work(tb->wq, &xd->state_work,
- msecs_to_jiffies(XDOMAIN_SHORT_TIMEOUT));
+ if (xd) {
+ mutex_lock(&xd->lock);
+ if (!xd->removing && device_is_registered(&xd->dev))
+ queue_delayed_work(tb->wq, &xd->state_work,
+ msecs_to_jiffies(XDOMAIN_SHORT_TIMEOUT));
+ mutex_unlock(&xd->lock);
+ }
break;
case UUID_REQUEST_OLD:
@@ -800,8 +804,12 @@ static void tb_xdp_handle_request(struct work_struct *work)
* received UUID request from the remote host.
*/
if (!ret && xd && xd->state == XDOMAIN_STATE_ERROR) {
- dev_dbg(&xd->dev, "restarting handshake\n");
- start_handshake(xd);
+ mutex_lock(&xd->lock);
+ if (!xd->removing) {
+ dev_dbg(&xd->dev, "restarting handshake\n");
+ start_handshake(xd);
+ }
+ mutex_unlock(&xd->lock);
}
break;
@@ -829,9 +837,13 @@ static void tb_xdp_handle_request(struct work_struct *work)
ret = tb_xdp_link_state_change_response(ctl, route,
sequence, 0);
- xd->target_link_width = lsc->tlw;
- queue_delayed_work(tb->wq, &xd->state_work,
- msecs_to_jiffies(XDOMAIN_SHORT_TIMEOUT));
+ mutex_lock(&xd->lock);
+ if (!xd->removing) {
+ xd->target_link_width = lsc->tlw;
+ queue_delayed_work(tb->wq, &xd->state_work,
+ msecs_to_jiffies(XDOMAIN_SHORT_TIMEOUT));
+ }
+ mutex_unlock(&xd->lock);
} else {
tb_xdp_error_response(ctl, route, sequence,
ERROR_NOT_READY);
@@ -2074,6 +2086,10 @@ void tb_xdomain_remove(struct tb_xdomain *xd)
{
tb_xdomain_debugfs_remove(xd);
+ mutex_lock(&xd->lock);
+ xd->removing = true;
+ mutex_unlock(&xd->lock);
+
stop_handshake(xd);
device_for_each_child_reverse(&xd->dev, xd, unregister_service);
@@ -2484,8 +2500,12 @@ static int update_xdomain(struct device *dev, void *data)
xd = tb_to_xdomain(dev);
if (xd) {
- queue_delayed_work(xd->tb->wq, &xd->properties_changed_work,
- msecs_to_jiffies(50));
+ mutex_lock(&xd->lock);
+ if (!xd->removing)
+ queue_delayed_work(xd->tb->wq,
+ &xd->properties_changed_work,
+ msecs_to_jiffies(50));
+ mutex_unlock(&xd->lock);
}
return 0;
diff --git a/include/linux/thunderbolt.h b/include/linux/thunderbolt.h
index 0ba112175bb39..7204586c10c3e 100644
--- a/include/linux/thunderbolt.h
+++ b/include/linux/thunderbolt.h
@@ -209,6 +209,8 @@ enum tb_link_width {
* @link_width: Width of the downstream facing link
* @link_usb4: Downstream link is USB4
* @is_unplugged: The XDomain is unplugged
+ * @removing: Set by tb_xdomain_remove() under @lock to prevent
+ * concurrent delayed work queueing
* @needs_uuid: If the XDomain does not have @remote_uuid it will be
* queried first
* @service_ids: Used to generate IDs for the services
@@ -257,6 +259,7 @@ struct tb_xdomain {
enum tb_link_width link_width;
bool link_usb4;
bool is_unplugged;
+ bool removing;
bool needs_uuid;
struct ida service_ids;
struct ida in_hopids;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 007/438] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 006/438] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 008/438] dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold Greg Kroah-Hartman
` (444 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, D Scott Phillips, Marc Zyngier
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: D Scott Phillips <scott@os.amperecomputing.com>
commit 8a570b19b4b16a8a3b5ffa2b332bd5613110b2d8 upstream.
In the nested state, the physical interrupt has already been
deactivated through the HW bit in the LR. The extra deactivation
would be harmless but can hit an errata case on AmpereOne, so
avoid it here.
On AmpereOne, deactivating a physical interrupt through
ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not
active, but is the highest priority pending interrupt causes the
cpu to lose the interrupt pending state and also prevents the
delivery of future interrupts.
Fixes: 6dd333c8942b2 ("KVM: arm64: GICv3: nv: Plug L1 LR sync into deactivation primitive")
Signed-off-by: D Scott Phillips <scott@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/linux-arm-kernel/20260710222128.416581-1-scott@os.amperecomputing.com/
Link: https://patch.msgid.link/20260714231158.496808-1-scott@os.amperecomputing.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Documentation/arch/arm64/silicon-errata.rst | 4 ++++
arch/arm64/kvm/vgic/vgic-v3.c | 8 +++++++-
2 files changed, 11 insertions(+), 1 deletion(-)
--- a/Documentation/arch/arm64/silicon-errata.rst
+++ b/Documentation/arch/arm64/silicon-errata.rst
@@ -55,10 +55,14 @@ stable kernels.
+----------------+-----------------+-----------------+-----------------------------+
| Ampere | AmpereOne | AC03_CPU_38 | AMPERE_ERRATUM_AC03_CPU_38 |
+----------------+-----------------+-----------------+-----------------------------+
+| Ampere | AmpereOne | AC03_CPU_57 | N/A |
++----------------+-----------------+-----------------+-----------------------------+
| Ampere | AmpereOne AC04 | AC04_CPU_10 | AMPERE_ERRATUM_AC03_CPU_38 |
+----------------+-----------------+-----------------+-----------------------------+
| Ampere | AmpereOne AC04 | AC04_CPU_23 | AMPERE_ERRATUM_AC04_CPU_23 |
+----------------+-----------------+-----------------+-----------------------------+
+| Ampere | AmpereOne AC04 | AC04_CPU_29 | N/A |
++----------------+-----------------+-----------------+-----------------------------+
+----------------+-----------------+-----------------+-----------------------------+
| ARM | Cortex-A510 | #2457168 | ARM64_ERRATUM_2457168 |
+----------------+-----------------+-----------------+-----------------------------+
--- a/arch/arm64/kvm/vgic/vgic-v3.c
+++ b/arch/arm64/kvm/vgic/vgic-v3.c
@@ -275,7 +275,13 @@ void vgic_v3_deactivate(struct kvm_vcpu
lr = vgic_v3_compute_lr(vcpu, irq) & ~ICH_LR_ACTIVE_BIT;
}
- if (lr & ICH_LR_HW)
+ /*
+ * In the nested state, the irq has already been deactivated via the HW
+ * bit in the LR. Deactivating again would be harmless except AmpereOne
+ * errata AC03_CPU_57, AC04_CPU_29 could cause irq delivery to break if
+ * the deactivation hits the highest priority pending irq.
+ */
+ if ((lr & ICH_LR_HW) && !vgic_state_is_nested(vcpu))
vgic_v3_deactivate_phys(FIELD_GET(ICH_LR_PHYS_ID_MASK, lr));
vgic_v3_fold_lr(vcpu, lr);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 008/438] dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 007/438] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 009/438] pinctrl: qcom: Unconditionally mark gpio as wakeup enable Greg Kroah-Hartman
` (443 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Carlier, Frank Li, Vinod Koul,
Sasha Levin, Logan Gunthorpe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Carlier <devnexen@gmail.com>
[ Upstream commit 9d12eb98582fec2578d17e025b13740dcfb57d8e ]
FIELD_GET(SE_THRESH_MASK, thresh) extracts bits [31:23] from thresh and
right-shifts them, which is the inverse of the intended operation. Since
thresh is derived from se_buf_len / 2 (at most 255), bits [31:23] are
always zero, so the SE threshold is never actually programmed into the
register.
Use FIELD_PREP() instead to correctly left-shift thresh into bits [31:23]
of the valid_en_se register, consistent with the FIELD_PREP usage for
the perf tuner config just above.
Fixes: 30eba9df76ad ("dmaengine: switchtec-dma: Implement hardware initialization and cleanup")
Signed-off-by: David Carlier <devnexen@gmail.com>
Review-by: Logan Gunthorpe <logang@deltatee.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260317083252.13224-1-devnexen@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/switchtec_dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/switchtec_dma.c b/drivers/dma/switchtec_dma.c
index 3ef9286406159..71d9868ce613e 100644
--- a/drivers/dma/switchtec_dma.c
+++ b/drivers/dma/switchtec_dma.c
@@ -1099,7 +1099,7 @@ static int switchtec_dma_chan_init(struct switchtec_dma_dev *swdma_dev,
dev_dbg(&pdev->dev, "Channel %d: SE buffer count %d\n", i, se_buf_len);
thresh = se_buf_len / 2;
- valid_en_se |= FIELD_GET(SE_THRESH_MASK, thresh);
+ valid_en_se |= FIELD_PREP(SE_THRESH_MASK, thresh);
writel(valid_en_se, &swdma_chan->mmio_chan_fw->valid_en_se);
/* request irqs */
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 009/438] pinctrl: qcom: Unconditionally mark gpio as wakeup enable
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 008/438] dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 010/438] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 Greg Kroah-Hartman
` (442 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sneh Mankad, Maulik Shah,
Linus Walleij, Konrad Dybcio, Bartosz Golaszewski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sneh Mankad <sneh.mankad@oss.qualcomm.com>
[ Upstream commit 859e02a369ab328a77dfcabf59562100e55f9c5c ]
GPIO interrupts that are wakeup capable need to be forwarded to wakeup
capable parent irqchip. This is done via writing to it's wakeup_enable bit.
Currently the bit is set only for PDC irqchip by checking skip_wake_irqs.
skip_wake_irqs is set to differentiate between parent irqchips MPM and
PDC. It is set when the parent irqchip is PDC to inform pinctrl about
skipping the IRQ setting up at TLMM.
However, the functionality to forward GPIO interrupts during SoC low
power mode is needed regardless of which parent irqchip it is.
Without the functionality it is impossible for MPM irqchip to detect the
GPIO interrupt during SoC low power mode since for MPM irqchip the
skip_wake_irqs is always false.
Remove skip_wake_irqs condition when setting wakeup enable bit to allow
forwarding GPIO interrupts for SoCs using MPM irqchip too.
Fixes: 76b446f5b86e ("pinctrl: qcom: handle intr_target_reg wakeup_present/enable bits")
Signed-off-by: Sneh Mankad <sneh.mankad@oss.qualcomm.com>
Reviewed-by: Maulik Shah <maulik.shah@oss.qualcomm.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://patch.msgid.link/20260616-enable_wakeup_capable_gpios-v3-1-fb59647d89cb@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/qcom/pinctrl-msm.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/pinctrl/qcom/pinctrl-msm.c b/drivers/pinctrl/qcom/pinctrl-msm.c
index 45b3a2763eb85..6a24f9b5e4a97 100644
--- a/drivers/pinctrl/qcom/pinctrl-msm.c
+++ b/drivers/pinctrl/qcom/pinctrl-msm.c
@@ -1242,12 +1242,12 @@ static int msm_gpio_irq_reqres(struct irq_data *d)
/*
* If the wakeup_enable bit is present and marked as available for the
* requested GPIO, it should be enabled when the GPIO is marked as
- * wake irq in order to allow the interrupt event to be transfered to
- * the PDC HW.
+ * wake irq in order to allow the interrupt event to be transferred to
+ * the PDC/MPM HW.
* While the name implies only the wakeup event, it's also required for
* the interrupt event.
*/
- if (test_bit(d->hwirq, pctrl->skip_wake_irqs) && g->intr_wakeup_present_bit) {
+ if (g->intr_wakeup_present_bit) {
u32 intr_cfg;
raw_spin_lock_irqsave(&pctrl->lock, flags);
@@ -1275,7 +1275,7 @@ static void msm_gpio_irq_relres(struct irq_data *d)
unsigned long flags;
/* Disable the wakeup_enable bit if it has been set in msm_gpio_irq_reqres() */
- if (test_bit(d->hwirq, pctrl->skip_wake_irqs) && g->intr_wakeup_present_bit) {
+ if (g->intr_wakeup_present_bit) {
u32 intr_cfg;
raw_spin_lock_irqsave(&pctrl->lock, flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 010/438] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 009/438] pinctrl: qcom: Unconditionally mark gpio as wakeup enable Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 011/438] dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA Greg Kroah-Hartman
` (441 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Bartosz Golaszewski,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 437a8d2aa1aa442c4a176fdf4700a9b3bb0c8794 ]
Pins 143 and 151 were not included in the PDC wakeup map. They are
normally used for PCIe2A and PCIe3a PERST# respectively, so they're
unlikely to be excercised in practice, but still add them for the sake
of completeness.
Fixes: c0e4c71a9e7c ("pinctrl: qcom: Introduce sc8280xp TLMM driver")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://patch.msgid.link/20260626-topic-8280_pinctrl_wakeup-v1-1-2ccb267148f5@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/qcom/pinctrl-sc8280xp.c | 21 +++++++++++----------
1 file changed, 11 insertions(+), 10 deletions(-)
diff --git a/drivers/pinctrl/qcom/pinctrl-sc8280xp.c b/drivers/pinctrl/qcom/pinctrl-sc8280xp.c
index 4056b9fa32f8c..e018bd11626ca 100644
--- a/drivers/pinctrl/qcom/pinctrl-sc8280xp.c
+++ b/drivers/pinctrl/qcom/pinctrl-sc8280xp.c
@@ -1881,16 +1881,17 @@ static const struct msm_gpio_wakeirq_map sc8280xp_pdc_map[] = {
{ 126, 200 }, { 127, 225 }, { 128, 262 }, { 129, 201 },
{ 130, 209 }, { 131, 173 }, { 132, 202 }, { 136, 210 },
{ 138, 171 }, { 139, 226 }, { 140, 227 }, { 142, 228 },
- { 144, 229 }, { 145, 230 }, { 146, 231 }, { 148, 232 },
- { 149, 233 }, { 150, 234 }, { 152, 235 }, { 154, 212 },
- { 157, 213 }, { 161, 219 }, { 170, 236 }, { 171, 221 },
- { 174, 222 }, { 175, 237 }, { 176, 223 }, { 177, 170 },
- { 180, 238 }, { 181, 239 }, { 182, 240 }, { 183, 241 },
- { 184, 242 }, { 185, 243 }, { 190, 178 }, { 193, 184 },
- { 196, 185 }, { 198, 186 }, { 200, 174 }, { 201, 175 },
- { 205, 176 }, { 206, 177 }, { 208, 187 }, { 210, 198 },
- { 211, 199 }, { 212, 204 }, { 215, 205 }, { 220, 188 },
- { 221, 194 }, { 223, 195 }, { 225, 196 }, { 227, 197 },
+ { 143, 261 }, { 144, 229 }, { 145, 230 }, { 146, 231 },
+ { 148, 232 }, { 149, 233 }, { 150, 234 }, { 151, 264 },
+ { 152, 235 }, { 154, 212 }, { 157, 213 }, { 161, 219 },
+ { 170, 236 }, { 171, 221 }, { 174, 222 }, { 175, 237 },
+ { 176, 223 }, { 177, 170 }, { 180, 238 }, { 181, 239 },
+ { 182, 240 }, { 183, 241 }, { 184, 242 }, { 185, 243 },
+ { 190, 178 }, { 193, 184 }, { 196, 185 }, { 198, 186 },
+ { 200, 174 }, { 201, 175 }, { 205, 176 }, { 206, 177 },
+ { 208, 187 }, { 210, 198 }, { 211, 199 }, { 212, 204 },
+ { 215, 205 }, { 220, 188 }, { 221, 194 }, { 223, 195 },
+ { 225, 196 }, { 227, 197 },
};
static struct msm_pinctrl_soc_data sc8280xp_pinctrl = {
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 011/438] dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 010/438] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 012/438] dmaengine: idxd: fix double free of wq, engine, and group structs Greg Kroah-Hartman
` (440 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Jernej Skrabec,
Frank Li, Frank Li, Vinod Koul, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongling Zeng <zenghongling@kylinos.cn>
[ Upstream commit ab1150115e68a46b687eb38c1ab92782018c9f2c ]
When terminating DMA transfers, active descriptors are not properly
reclaimed. Only cyclic descriptors were handled, leaving non-cyclic
descriptors and their LLI chains to be permanently leaked.
Fix by using vchan_terminate_vdesc() which handles both cyclic and
non-cyclic descriptors by adding them to desc_terminated queue for
proper cleanup.
Add pchan->desc != pchan->done check to prevent double-adding completed
descriptors, which would corrupt the list.
Fixes: 555859308723 ("dmaengine: sun6i: Add driver for the Allwinner A31 DMA controller")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Acked-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Suggested-by: Frank Li <Frank.li@oss.nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260701045733.33654-1-zenghongling@kylinos.cn
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/sun6i-dma.c | 11 ++++-------
1 file changed, 4 insertions(+), 7 deletions(-)
diff --git a/drivers/dma/sun6i-dma.c b/drivers/dma/sun6i-dma.c
index a9a254dbf8cb9..f47a326dd7ffa 100644
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -945,16 +945,13 @@ static int sun6i_dma_terminate_all(struct dma_chan *chan)
spin_lock_irqsave(&vchan->vc.lock, flags);
- if (vchan->cyclic) {
- vchan->cyclic = false;
- if (pchan && pchan->desc) {
- struct virt_dma_desc *vd = &pchan->desc->vd;
- struct virt_dma_chan *vc = &vchan->vc;
+ if (pchan && pchan->desc && pchan->desc != pchan->done) {
+ struct virt_dma_desc *vd = &pchan->desc->vd;
- list_add_tail(&vd->node, &vc->desc_completed);
- }
+ vchan_terminate_vdesc(vd);
}
+ vchan->cyclic = false;
vchan_get_all_descriptors(&vchan->vc, &head);
if (pchan) {
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 012/438] dmaengine: idxd: fix double free of wq, engine, and group structs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 011/438] dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 013/438] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() Greg Kroah-Hartman
` (439 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Vinicius Costa Gomes,
Frank Li, Vinod Koul, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit ec2d428b2e32dd157de8f86a86dd85c5b2c8f45c ]
The release callbacks for wq, engine, and group devices
(idxd_conf_wq_release, idxd_conf_engine_release,
idxd_conf_group_release) each call kfree() on the enclosing struct.
The setup error paths and cleanup functions also call kfree()
explicitly after put_device(), producing a double free whenever
put_device() drops the reference count to zero and fires the release.
In the setup functions, device_initialize() is called before
device_add(), so the reference count is exactly 1 at the error sites.
put_device() unconditionally fires the release, which frees the struct;
the subsequent explicit kfree() then operates on freed memory.
For idxd_setup_wqs(), the wq release callback also owns opcap_bmap
and wqcfg. The error unwind additionally freed those fields explicitly
before calling put_device(), causing further double frees on both.
Remove the redundant explicit kfree() calls from all setup error paths
and cleanup functions for wq, engine, and group structs, delegating
sole ownership of those allocations to the release callbacks.
Fixes: 7c5dd23e57c1 ("dmaengine: idxd: fix wq conf_dev 'struct device' lifetime")
Fixes: 75b911309060 ("dmaengine: idxd: fix engine conf_dev lifetime")
Fixes: defe49f96012 ("dmaengine: idxd: fix group conf_dev lifetime")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Acked-by: Vinicius Costa Gomes <vinicius.gomes@intel.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260415205452.67155-1-dbgh9129@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/idxd/init.c | 36 +++++-------------------------------
1 file changed, 5 insertions(+), 31 deletions(-)
diff --git a/drivers/dma/idxd/init.c b/drivers/dma/idxd/init.c
index f1cfc7790d950..4b827a3297564 100644
--- a/drivers/dma/idxd/init.c
+++ b/drivers/dma/idxd/init.c
@@ -159,18 +159,12 @@ static void idxd_cleanup_interrupts(struct idxd_device *idxd)
static void idxd_clean_wqs(struct idxd_device *idxd)
{
- struct idxd_wq *wq;
struct device *conf_dev;
int i;
for (i = 0; i < idxd->max_wqs; i++) {
- wq = idxd->wqs[i];
- if (idxd->hw.wq_cap.op_config)
- bitmap_free(wq->opcap_bmap);
- kfree(wq->wqcfg);
- conf_dev = wq_confdev(wq);
+ conf_dev = wq_confdev(idxd->wqs[i]);
put_device(conf_dev);
- kfree(wq);
}
bitmap_free(idxd->wq_enable_map);
kfree(idxd->wqs);
@@ -212,7 +206,6 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
rc = dev_set_name(conf_dev, "wq%d.%d", idxd->id, wq->id);
if (rc < 0) {
put_device(conf_dev);
- kfree(wq);
goto err_unwind;
}
@@ -227,7 +220,6 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
wq->wqcfg = kzalloc_node(idxd->wqcfg_size, GFP_KERNEL, dev_to_node(dev));
if (!wq->wqcfg) {
put_device(conf_dev);
- kfree(wq);
rc = -ENOMEM;
goto err_unwind;
}
@@ -235,9 +227,7 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
if (idxd->hw.wq_cap.op_config) {
wq->opcap_bmap = bitmap_zalloc(IDXD_MAX_OPCAP_BITS, GFP_KERNEL);
if (!wq->opcap_bmap) {
- kfree(wq->wqcfg);
put_device(conf_dev);
- kfree(wq);
rc = -ENOMEM;
goto err_unwind;
}
@@ -252,13 +242,8 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
err_unwind:
while (--i >= 0) {
- wq = idxd->wqs[i];
- if (idxd->hw.wq_cap.op_config)
- bitmap_free(wq->opcap_bmap);
- kfree(wq->wqcfg);
- conf_dev = wq_confdev(wq);
+ conf_dev = wq_confdev(idxd->wqs[i]);
put_device(conf_dev);
- kfree(wq);
}
bitmap_free(idxd->wq_enable_map);
@@ -270,15 +255,12 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
static void idxd_clean_engines(struct idxd_device *idxd)
{
- struct idxd_engine *engine;
struct device *conf_dev;
int i;
for (i = 0; i < idxd->max_engines; i++) {
- engine = idxd->engines[i];
- conf_dev = engine_confdev(engine);
+ conf_dev = engine_confdev(idxd->engines[i]);
put_device(conf_dev);
- kfree(engine);
}
kfree(idxd->engines);
}
@@ -313,7 +295,6 @@ static int idxd_setup_engines(struct idxd_device *idxd)
rc = dev_set_name(conf_dev, "engine%d.%d", idxd->id, engine->id);
if (rc < 0) {
put_device(conf_dev);
- kfree(engine);
goto err;
}
@@ -324,10 +305,8 @@ static int idxd_setup_engines(struct idxd_device *idxd)
err:
while (--i >= 0) {
- engine = idxd->engines[i];
- conf_dev = engine_confdev(engine);
+ conf_dev = engine_confdev(idxd->engines[i]);
put_device(conf_dev);
- kfree(engine);
}
kfree(idxd->engines);
@@ -336,13 +315,10 @@ static int idxd_setup_engines(struct idxd_device *idxd)
static void idxd_clean_groups(struct idxd_device *idxd)
{
- struct idxd_group *group;
int i;
for (i = 0; i < idxd->max_groups; i++) {
- group = idxd->groups[i];
- put_device(group_confdev(group));
- kfree(group);
+ put_device(group_confdev(idxd->groups[i]));
}
kfree(idxd->groups);
}
@@ -377,7 +353,6 @@ static int idxd_setup_groups(struct idxd_device *idxd)
rc = dev_set_name(conf_dev, "group%d.%d", idxd->id, group->id);
if (rc < 0) {
put_device(conf_dev);
- kfree(group);
goto err;
}
@@ -402,7 +377,6 @@ static int idxd_setup_groups(struct idxd_device *idxd)
while (--i >= 0) {
group = idxd->groups[i];
put_device(group_confdev(group));
- kfree(group);
}
kfree(idxd->groups);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 013/438] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 012/438] dmaengine: idxd: fix double free of wq, engine, and group structs Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 014/438] iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE Greg Kroah-Hartman
` (438 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Dave Jiang,
Vinicius Costa Gomes, Vinod Koul, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit ee1d7274102285d78a53161fc705a8d8cd40b066 ]
The failed_dev_add and failed_dev_name paths drop the file-device
reference while wq->wq_lock is still held. If put_device(fdev) drops the
last reference, idxd_file_dev_release() runs synchronously and tries to
take wq->wq_lock again, deadlocking.
Those paths also fall through into the later ctx cleanup labels even
though idxd_file_dev_release() owns that cleanup and frees ctx. This can
make idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context.
Move idxd_wq_get() before file-device setup can fail, since the release
callback always calls idxd_wq_put(). Then unlock wq->wq_lock before
put_device(fdev) and return directly from the file-device setup failure
path, leaving ctx cleanup to the release callback.
Fixes: e6fd6d7e5f0fe ("dmaengine: idxd: add a device to represent the file opened")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Acked-by: Vinicius Costa Gomes <vinicius.gomes@intel.com>
Link: https://patch.msgid.link/20260525141550.1385581-1-dbgh9129@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/idxd/cdev.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/idxd/cdev.c b/drivers/dma/idxd/cdev.c
index 0366c7cf35020..82b07cf942ef8 100644
--- a/drivers/dma/idxd/cdev.c
+++ b/drivers/dma/idxd/cdev.c
@@ -288,6 +288,7 @@ static int idxd_cdev_open(struct inode *inode, struct file *filp)
fdev->parent = cdev_dev(idxd_cdev);
fdev->bus = &dsa_bus_type;
fdev->type = &idxd_cdev_file_type;
+ idxd_wq_get(wq);
rc = dev_set_name(fdev, "file%d", ctx->id);
if (rc < 0) {
@@ -301,13 +302,14 @@ static int idxd_cdev_open(struct inode *inode, struct file *filp)
goto failed_dev_add;
}
- idxd_wq_get(wq);
mutex_unlock(&wq->wq_lock);
return 0;
failed_dev_add:
failed_dev_name:
+ mutex_unlock(&wq->wq_lock);
put_device(fdev);
+ return rc;
failed_ida:
failed_set_pasid:
if (device_user_pasid_enabled(idxd))
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 014/438] iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 013/438] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 015/438] gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() Greg Kroah-Hartman
` (437 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kevin Tian, Pranjal Shrivastava,
Nicolin Chen, Jason Gunthorpe, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit c3b8ee84a965058b41275069d4696f37a8b14bf6 ]
arm_vsmmu_vsid_to_sid() maps a guest's vSID to a single physical Stream ID
taken from master->streams[0], assuming a device has exactly one stream. A
device with several streams gets only its first one mapped, so a guest vSID
invalidation cannot reach the others' ATC and IOTLB entries; a device with
none makes master->streams a ZERO_SIZE_PTR, read out of bounds.
Add an arm_vsmmu_vdevice_init() op to reject the vDEVICE with -EOPNOTSUPP
when master->num_streams is not one, rather than mapping it silently.
Fixes: d68beb276ba26 ("iommu/arm-smmu-v3: Support IOMMU_HWPT_INVALIDATE using a VIOMMU object")
Link: https://patch.msgid.link/r/b15f2b73520f389f3f57881da2f040e7bdc18876.1783311134.git.nicolinc@nvidia.com
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Pranjal Shrivastava <praan@google.com>
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c
index ddae0b07c76b5..b7a4a1b5eddd5 100644
--- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c
+++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c
@@ -297,6 +297,20 @@ static int arm_vsmmu_vsid_to_sid(struct arm_vsmmu *vsmmu, u32 vsid, u32 *sid)
return ret;
}
+static int arm_vsmmu_vdevice_init(struct iommufd_vdevice *vdev)
+{
+ struct device *dev = iommufd_vdevice_to_device(vdev);
+ struct arm_smmu_master *master = dev_iommu_priv_get(dev);
+
+ /*
+ * arm_vsmmu_vsid_to_sid() maps a vSID to master->streams[0] alone, so
+ * more streams would leave the rest stale and none reads out of bounds.
+ */
+ if (master->num_streams != 1)
+ return -EOPNOTSUPP;
+ return 0;
+}
+
/* This is basically iommu_viommu_arm_smmuv3_invalidate in u64 for conversion */
struct arm_vsmmu_invalidation_cmd {
union {
@@ -403,6 +417,7 @@ int arm_vsmmu_cache_invalidate(struct iommufd_viommu *viommu,
static const struct iommufd_viommu_ops arm_vsmmu_ops = {
.alloc_domain_nested = arm_vsmmu_alloc_domain_nested,
.cache_invalidate = arm_vsmmu_cache_invalidate,
+ .vdevice_init = arm_vsmmu_vdevice_init,
};
size_t arm_smmu_get_viommu_size(struct device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 015/438] gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 014/438] iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 016/438] selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE Greg Kroah-Hartman
` (436 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Wolfram Sang,
Bartosz Golaszewski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
[ Upstream commit 7a7baebd9f23ba4f24796775472b2fd00dcd95d9 ]
The memory allocated for priv->blob.data is not freed in the error paths
that follow the fops_buf_size_set() call in gpio_la_poll_probe(), as
well as in the remove function. Fix that by using device managed action
to free the memory on remove.
Fixes: 7828b7bbbf20 ("gpio: add sloppy logic analyzer using polling")
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Link: https://patch.msgid.link/20260715075311.527753-1-nihaal@cse.iitm.ac.in
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-sloppy-logic-analyzer.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/gpio/gpio-sloppy-logic-analyzer.c b/drivers/gpio/gpio-sloppy-logic-analyzer.c
index 969dddd3d6faf..0f4a6228a7488 100644
--- a/drivers/gpio/gpio-sloppy-logic-analyzer.c
+++ b/drivers/gpio/gpio-sloppy-logic-analyzer.c
@@ -161,6 +161,13 @@ static int fops_buf_size_get(void *data, u64 *val)
return 0;
}
+static void fops_buf_release(void *data)
+{
+ struct gpio_la_poll_priv *priv = data;
+
+ vfree(priv->blob.data);
+}
+
static int fops_buf_size_set(void *data, u64 val)
{
struct gpio_la_poll_priv *priv = data;
@@ -239,6 +246,9 @@ static int gpio_la_poll_probe(struct platform_device *pdev)
return ret;
fops_buf_size_set(priv, GPIO_LA_DEFAULT_BUF_SIZE);
+ ret = devm_add_action_or_reset(dev, fops_buf_release, priv);
+ if (ret)
+ return ret;
priv->descs = devm_gpiod_get_array(dev, "probe", GPIOD_IN);
if (IS_ERR(priv->descs))
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 016/438] selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 015/438] gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 017/438] selftests/seccomp: Fix pointer type mismatch build error Greg Kroah-Hartman
` (435 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Haofeng Li, Kees Cook, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haofeng Li <lihaofeng@kylinos.cn>
[ Upstream commit b3a7aa9c0020ae549a0d4964867ff66d2bd61709 ]
Commit 57fbad15c2ee ("stackleak: Rename STACKLEAK to KSTACK_ERASE")
renamed the LKDTM crash type and selftest configuration but missed the
entry in tests.txt.
As a result, the selftest generates STACKLEAK_ERASING.sh, which run.sh
skips because the LKDTM DIRECT trigger only exposes KSTACK_ERASE. Rename
the test entry so the generated runner uses the registered crash type.
Fixes: 57fbad15c2ee ("stackleak: Rename STACKLEAK to KSTACK_ERASE")
Signed-off-by: Haofeng Li <lihaofeng@kylinos.cn>
Link: https://patch.msgid.link/tencent_CD80B5F746B6AABD68AF3F1097AD02C96F05@qq.com
Signed-off-by: Kees Cook <kees@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/lkdtm/tests.txt | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/lkdtm/tests.txt b/tools/testing/selftests/lkdtm/tests.txt
index 3245032db34d3..444040ca51689 100644
--- a/tools/testing/selftests/lkdtm/tests.txt
+++ b/tools/testing/selftests/lkdtm/tests.txt
@@ -78,7 +78,7 @@ USERCOPY_STACK_FRAME_TO
USERCOPY_STACK_FRAME_FROM
USERCOPY_STACK_BEYOND
USERCOPY_KERNEL
-STACKLEAK_ERASING OK: the rest of the thread stack is properly erased
+KSTACK_ERASE OK: the rest of the thread stack is properly erased
CFI_FORWARD_PROTO
CFI_BACKWARD call trace:|ok: control flow unchanged
FORTIFY_STRSCPY detected buffer overflow
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 017/438] selftests/seccomp: Fix pointer type mismatch build error
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 016/438] selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 018/438] ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points Greg Kroah-Hartman
` (434 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuan-Ying Lee, Jiri Olsa, Kees Cook,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuan-Ying Lee <kuan-ying.lee@canonical.com>
[ Upstream commit 3421b9b056a6576d0ebac1030eafb48ad0544092 ]
We hit the following build error while running the seccomp selftests in
our testing.
CC seccomp_bpf
seccomp_bpf.c: In function ‘UPROBE_setup’:
seccomp_bpf.c:5175:74: error: pointer type mismatch in conditional expression [-Wincompatible-pointer-types]
5175 | offset = get_uprobe_offset(variant->uretprobe ? probed_uretprobe : probed_uprobe);
| ^
seccomp_bpf.c:5175:57: note: first expression has type ‘int (*)(void)’
5175 | offset = get_uprobe_offset(variant->uretprobe ? probed_uretprobe : probed_uprobe);
| ^~~~~~~~~~~~~~~~
seccomp_bpf.c:5175:76: note: second expression has type ‘int (__attribute__((nocf_check)) *)(void)’
5175 | offset = get_uprobe_offset(variant->uretprobe ? probed_uretprobe : probed_uprobe);
| ^~~~~~~~~~~~~
get_uprobe_offset() takes a 'const void *' argument, so cast both
operands to 'void *'.
Fixes: 9ffc7a635c35 ("selftests/seccomp: validate uprobe syscall passes through seccomp")
Signed-off-by: Kuan-Ying Lee <kuan-ying.lee@canonical.com>
Acked-by: Jiri Olsa <jolsa@kernel.org>
Link: https://patch.msgid.link/20260715053559.28535-1-kuan-ying.lee@canonical.com
Signed-off-by: Kees Cook <kees@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/seccomp/seccomp_bpf.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/seccomp/seccomp_bpf.c b/tools/testing/selftests/seccomp/seccomp_bpf.c
index 358b6c65e120e..0622bc2acad40 100644
--- a/tools/testing/selftests/seccomp/seccomp_bpf.c
+++ b/tools/testing/selftests/seccomp/seccomp_bpf.c
@@ -5178,7 +5178,8 @@ FIXTURE_SETUP(UPROBE)
ASSERT_GE(bit, 0);
}
- offset = get_uprobe_offset(variant->uretprobe ? probed_uretprobe : probed_uprobe);
+ offset = get_uprobe_offset(variant->uretprobe ? (void *)probed_uretprobe
+ : (void *)probed_uprobe);
ASSERT_GE(offset, 0);
if (variant->uretprobe)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 018/438] ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 017/438] selftests/seccomp: Fix pointer type mismatch build error Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 019/438] ata: sata_mv: accept 1 or 2 resources in platform probe Greg Kroah-Hartman
` (433 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 523307b8516fc740895238af8473aa0630b3e088 ]
When creating a WSL special file (socket, fifo, character or block
device), __ntfs_create() sets FILE_ATTRIBUTE_RECALL_ON_OPEN in ni->flags
as valid_reparse_data() requires for these tags. This flag is
intentionally absent from $FILE_NAME, so the subsequent reload
ni->flags = fn->file_attributes;
drops it from ni->flags, the authoritative copy written back to
$STANDARD_INFORMATION. The on-disk file_attributes becomes 0x00000404
instead of 0x00040404, and after a remount valid_reparse_data() rejects
the reparse point while fsck reports "$REPARSE_POINT data is corrupted".
Preserve the RECALL_ON_OPEN bit across the reload. Symlinks do not set
that bit, so they are unaffected.
Fixes: af0db57d4293 ("ntfs: update inode operations")
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/namei.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/ntfs/namei.c b/fs/ntfs/namei.c
index a20ef06087368..712c9ccc8b254 100644
--- a/fs/ntfs/namei.c
+++ b/fs/ntfs/namei.c
@@ -683,7 +683,8 @@ static struct ntfs_inode *__ntfs_create(struct mnt_idmap *idmap, struct inode *d
mutex_unlock(&dir_ni->mrec_lock);
mutex_unlock(&ni->mrec_lock);
- ni->flags = fn->file_attributes;
+ ni->flags = fn->file_attributes |
+ (ni->flags & FILE_ATTRIBUTE_RECALL_ON_OPEN);
/* Set the sequence number. */
vi->i_generation = ni->seq_no;
set_nlink(vi, 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 019/438] ata: sata_mv: accept 1 or 2 resources in platform probe
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 018/438] ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 020/438] ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() Greg Kroah-Hartman
` (432 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev, Damien Le Moal,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit ef19a9cf037957fe3a35df8355c76ff0a63a0436 ]
Board files in arch/arm/plat-orion, arch/arm/mach-dove,
arch/arm/mach-mv78xx0 and arch/arm/mach-orion5x still register the
"sata_mv" device with two resources (IORESOURCE_MEM plus IORESOURCE_IRQ).
Those devices are rejected with -EINVAL, so SATA no longer probes on
legacy Marvell Orion/Kirkwood-style boards.
Accept both 1 resource (DT, IRQ fetched via platform_get_irq()) and 2
resources (legacy, IRQ supplied as a second resource) so both probing
paths work.
Fixes: b3b2bec9646e ("ata: sata_mv: Fixes expected number of resources now IRQs are gone")
Assisted-by: opencode:big-pickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ata/sata_mv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/ata/sata_mv.c b/drivers/ata/sata_mv.c
index ffb396f61731f..1d8ca95fb7328 100644
--- a/drivers/ata/sata_mv.c
+++ b/drivers/ata/sata_mv.c
@@ -4026,7 +4026,7 @@ static int mv_platform_probe(struct platform_device *pdev)
/*
* Simple resource validation ..
*/
- if (unlikely(pdev->num_resources != 1)) {
+ if (unlikely(pdev->num_resources != 1 && pdev->num_resources != 2)) {
dev_err(&pdev->dev, "invalid number of resources\n");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 020/438] ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 019/438] ata: sata_mv: accept 1 or 2 resources in platform probe Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 021/438] phy: qcom: m31-eusb2: Fix return value of init call Greg Kroah-Hartman
` (431 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Radhey Shyam Pandey, Damien Le Moal,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
[ Upstream commit 4d99a91574c420decab56cc880fad0dc15b8a7a3 ]
On phy_init() failure the error path fallsthrough to disable_rsts, which
deasserts the controller reset and then enters disable_phys calling
phy_power_off() on PHYs that were never powered on. That corrupts the PHY
power_count and triggers an extra runtime PM put.
Use a separate exit_phys path that unwinds with phy_exit() only and falls
through to disable_clks while the controller remains in reset. Reserve
phy_power_off() for the phy_power_on() failure path only, and skip
masked-out ports in both unwind loops.
On phy_power_on() failure re-assert the controller reset before disabling
clocks and regulators, matching the teardown order used by
ahci_platform_enable_resources() and ahci_platform_disable_resources().
Fixes: 26c8404e162b ("ata: ahci_ceva: fix error handling for Xilinx GT PHY support")
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ata/ahci_ceva.c | 18 ++++++++++++++----
1 file changed, 14 insertions(+), 4 deletions(-)
diff --git a/drivers/ata/ahci_ceva.c b/drivers/ata/ahci_ceva.c
index 2d6a08c23d6ad..2961e53288f42 100644
--- a/drivers/ata/ahci_ceva.c
+++ b/drivers/ata/ahci_ceva.c
@@ -211,7 +211,7 @@ static int ceva_ahci_platform_enable_resources(struct ahci_host_priv *hpriv)
rc = phy_init(hpriv->phys[i]);
if (rc)
- goto disable_rsts;
+ goto exit_phys;
}
/* De-assert the controller reset */
@@ -230,14 +230,24 @@ static int ceva_ahci_platform_enable_resources(struct ahci_host_priv *hpriv)
return 0;
-disable_rsts:
- ahci_platform_deassert_rsts(hpriv);
-
disable_phys:
while (--i >= 0) {
+ if (ahci_ignore_port(hpriv, i))
+ continue;
+
phy_power_off(hpriv->phys[i]);
phy_exit(hpriv->phys[i]);
}
+ ahci_platform_assert_rsts(hpriv);
+ goto disable_clks;
+
+exit_phys:
+ while (--i >= 0) {
+ if (ahci_ignore_port(hpriv, i))
+ continue;
+
+ phy_exit(hpriv->phys[i]);
+ }
disable_clks:
ahci_platform_disable_clks(hpriv);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 021/438] phy: qcom: m31-eusb2: Fix return value of init call
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 020/438] ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 022/438] ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup Greg Kroah-Hartman
` (430 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Krishna Kurapati, Vinod Koul,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
[ Upstream commit 361f533a2dce2c2841fe4dc0c9d85a67117edf95 ]
The init call currently returns success irrespective of any failures
during repeater init or clock enablement. Return appropriate error value
in the init call failure path.
Fixes: 9c8504861cc4 ("phy: qcom: Add M31 based eUSB2 PHY driver")
Signed-off-by: Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
Link: https://patch.msgid.link/20260718-m31-eusb2-fix-v1-1-8588a1b94d76@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-m31-eusb2.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/phy/qualcomm/phy-qcom-m31-eusb2.c b/drivers/phy/qualcomm/phy-qcom-m31-eusb2.c
index 68f1ba8fec4ad..9434bd22ef32d 100644
--- a/drivers/phy/qualcomm/phy-qcom-m31-eusb2.c
+++ b/drivers/phy/qualcomm/phy-qcom-m31-eusb2.c
@@ -221,7 +221,7 @@ static int m31eusb2_phy_init(struct phy *uphy)
disable_vreg:
regulator_bulk_disable(M31_EUSB_NUM_VREGS, phy->vregs);
- return 0;
+ return ret;
}
static int m31eusb2_phy_exit(struct phy *uphy)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 022/438] ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 021/438] phy: qcom: m31-eusb2: Fix return value of init call Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 023/438] ASoC: max98090: " Greg Kroah-Hartman
` (429 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Uday Khare, Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uday Khare <udaykhare77@gmail.com>
[ Upstream commit 317e21532e6ffa1de026bdbce5ba98e1b70ca5c6 ]
In max98095_probe(), the -EPROBE_DEFER check after devm_clk_get() is
broken due to a missing IS_ERR() guard.
The code intends to return -EPROBE_DEFER only when the clock lookup
fails with that specific error. However, without IS_ERR() the check:
if (PTR_ERR(max98095->mclk) == -EPROBE_DEFER)
is called unconditionally, including when devm_clk_get() succeeds and
returns a valid pointer. Calling PTR_ERR() on a valid pointer
reinterprets its address as a signed long; the result is arbitrary
and is almost never equal to -EPROBE_DEFER, so the check silently
does nothing in the success case. When devm_clk_get() fails with
any error other than -EPROBE_DEFER the check is also skipped, leaving
max98095->mclk holding an error pointer with no indication to the caller.
This means a deferred probe will never actually be triggered for this
device, and any non-EPROBE_DEFER clock error is silently swallowed with
the error pointer left in the mclk field.
Fix this by adding the missing IS_ERR() guard around the PTR_ERR() call,
matching the pattern already used in the sibling max98088 and wm8960
drivers.
Fixes: e3048c3d2be5 ("ASoC: max98095: Add master clock handling")
Signed-off-by: Uday Khare <udaykhare77@gmail.com>
Link: https://patch.msgid.link/20260720103950.14474-1-udaykhare77@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/max98095.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/sound/soc/codecs/max98095.c b/sound/soc/codecs/max98095.c
index aae6423156e16..207374e451810 100644
--- a/sound/soc/codecs/max98095.c
+++ b/sound/soc/codecs/max98095.c
@@ -1987,8 +1987,9 @@ static int max98095_probe(struct snd_soc_component *component)
int ret = 0;
max98095->mclk = devm_clk_get(component->dev, "mclk");
- if (PTR_ERR(max98095->mclk) == -EPROBE_DEFER)
- return -EPROBE_DEFER;
+ if (IS_ERR(max98095->mclk))
+ if (PTR_ERR(max98095->mclk) == -EPROBE_DEFER)
+ return -EPROBE_DEFER;
/* reset the codec, the DSP core, and disable all interrupts */
max98095_reset(component);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 023/438] ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 022/438] ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 024/438] of: reserved_mem: prevent OOB when too many dynamic regions are defined Greg Kroah-Hartman
` (428 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Uday Khare, Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uday Khare <udaykhare77@gmail.com>
[ Upstream commit a792ce0fad61a70793ec565743f11d6ca534de59 ]
In max98090_probe(), the -EPROBE_DEFER check after devm_clk_get() is
broken due to a missing IS_ERR() guard.
The code intends to return -EPROBE_DEFER only when the clock lookup
fails with that specific error. However, without IS_ERR() the check:
if (PTR_ERR(max98090->mclk) == -EPROBE_DEFER)
is called unconditionally, including when devm_clk_get() succeeds and
returns a valid pointer. Calling PTR_ERR() on a valid pointer
reinterprets its address as a signed long; the result is arbitrary
and is almost never equal to -EPROBE_DEFER, so the check silently
does nothing in the success case. When devm_clk_get() fails with
any error other than -EPROBE_DEFER the check is also skipped, leaving
max98090->mclk holding an error pointer with no indication to the caller.
This means a deferred probe will never actually be triggered for this
device, and any non-EPROBE_DEFER clock error is silently swallowed with
the error pointer left in the mclk field.
Fix this by adding the missing IS_ERR() guard around the PTR_ERR() call,
matching the pattern already used in the sibling max98088 and wm8960
drivers.
Fixes: b10ab7b838bd ("ASoC: max98090: Add master clock handling")
Signed-off-by: Uday Khare <udaykhare77@gmail.com>
Link: https://patch.msgid.link/20260720104254.14948-1-udaykhare77@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/max98090.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/sound/soc/codecs/max98090.c b/sound/soc/codecs/max98090.c
index 13a15459040fc..595efd84b62b3 100644
--- a/sound/soc/codecs/max98090.c
+++ b/sound/soc/codecs/max98090.c
@@ -2424,8 +2424,9 @@ static int max98090_probe(struct snd_soc_component *component)
dev_dbg(component->dev, "max98090_probe\n");
max98090->mclk = devm_clk_get(component->dev, "mclk");
- if (PTR_ERR(max98090->mclk) == -EPROBE_DEFER)
- return -EPROBE_DEFER;
+ if (IS_ERR(max98090->mclk))
+ if (PTR_ERR(max98090->mclk) == -EPROBE_DEFER)
+ return -EPROBE_DEFER;
max98090->component = component;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 024/438] of: reserved_mem: prevent OOB when too many dynamic regions are defined
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 023/438] ASoC: max98090: " Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 025/438] btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag Greg Kroah-Hartman
` (427 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sang-Heon Jeon, Rob Herring (Arm),
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sang-Heon Jeon <ekffu200098@gmail.com>
[ Upstream commit db3dbdfea1b8f38774419c5c2c14e4b81c48708d ]
On boot, fdt_scan_reserved_mem() saves each dynamically-placed
/reserved-memory subnode into a local array of size
MAX_RESERVED_REGIONS.
If the device tree defines more than MAX_RESERVED_REGIONS
dynamically-placed regions, fdt_scan_reserved_mem() writes past the
end of the local array.
Add a bounds check that logs an error and skips the excess regions,
restoring the original behavior.
Fixes: 8a6e02d0c00e ("of: reserved_mem: Restructure how the reserved memory regions are processed")
Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com>
Link: https://patch.msgid.link/20260614133807.2165124-2-ekffu200098@gmail.com
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/of/of_reserved_mem.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/drivers/of/of_reserved_mem.c b/drivers/of/of_reserved_mem.c
index deaea58c74f2a..47041d195dff8 100644
--- a/drivers/of/of_reserved_mem.c
+++ b/drivers/of/of_reserved_mem.c
@@ -351,6 +351,7 @@ int __init fdt_scan_reserved_mem(void)
err = __reserved_mem_reserve_reg(child, uname);
if (!err)
count++;
+
/*
* Save the nodes for the dynamically-placed regions
* into an array which will be used for allocation right
@@ -358,10 +359,17 @@ int __init fdt_scan_reserved_mem(void)
* or marked as no-map. This is done to avoid dynamically
* allocating from one of the statically-placed regions.
*/
- if (err == -ENOENT && of_get_flat_dt_prop(child, "size", NULL)) {
- dynamic_nodes[dynamic_nodes_cnt] = child;
- dynamic_nodes_cnt++;
+ if (err != -ENOENT || !of_get_flat_dt_prop(child, "size", NULL))
+ continue;
+
+ if (dynamic_nodes_cnt == MAX_RESERVED_REGIONS) {
+ pr_err("too many defined dynamic regions, skip '%s'\n",
+ uname);
+ continue;
}
+
+ dynamic_nodes[dynamic_nodes_cnt] = child;
+ dynamic_nodes_cnt++;
}
for (int i = 0; i < dynamic_nodes_cnt; i++) {
const char *uname;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 025/438] btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 024/438] of: reserved_mem: prevent OOB when too many dynamic regions are defined Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 026/438] btrfs: zoned: fix deadlock between metadata writeback and transaction commit Greg Kroah-Hartman
` (426 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Thumshirn, Qu Wenruo,
David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qu Wenruo <wqu@suse.com>
[ Upstream commit 6881f45d0eb541f2cee8c37c84b3860a23823bb3 ]
[BUG]
The following script can lead to unexpected qgroup rescan failure:
# mkfs.btrfs -f -O quota $dev
# mount $dev $mnt
# mount -o remount,rescue=ibadroots $mnt
^^^^^ This above command is expected to fail
# btrfs quota rescan -w $mnt
^^^^^ The above qgroup rescan is not expected to fail
# btrfs qgroup show $mnt
WARNING: qgroup data inconsistent, rescan recommended
Qgroupid Referenced Exclusive Path
-------- ---------- --------- ----
0/5 16.00KiB 16.00KiB <toplevel>
The above short script will be converted to a proper fstests case.
[CAUSE]
Inside btrfs_reconfigure(), if either btrfs_check_options() or
btrfs_check_features() failed, we will always have
BTRFS_FS_STATE_REMOUNTING set for the fs until the next successful
remount.
That BTRFS_FS_STATE_REMOUNTING flag will interrupt several operations,
including:
- Qgroup rescan
- Auto defrag
- Space reclaim
[FIX]
Change the error handling of btrfs_check_options() and
btrfs_check_features() to goto restore label.
Fixes: eddb1a433f26 ("btrfs: add reconfigure callback for fs_context")
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/super.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/fs/btrfs/super.c b/fs/btrfs/super.c
index ba70d727622e8..ba0b31e5816b6 100644
--- a/fs/btrfs/super.c
+++ b/fs/btrfs/super.c
@@ -1518,12 +1518,14 @@ static int btrfs_reconfigure(struct fs_context *fc)
sync_filesystem(sb);
set_bit(BTRFS_FS_STATE_REMOUNTING, &fs_info->fs_state);
- if (!btrfs_check_options(fs_info, &ctx->mount_opt, fc->sb_flags))
- return -EINVAL;
+ if (!btrfs_check_options(fs_info, &ctx->mount_opt, fc->sb_flags)) {
+ ret = -EINVAL;
+ goto restore;
+ }
ret = btrfs_check_features(fs_info, !(fc->sb_flags & SB_RDONLY));
if (ret < 0)
- return ret;
+ goto restore;
btrfs_ctx_to_info(fs_info, ctx);
btrfs_remount_begin(fs_info, old_ctx.mount_opt, fc->sb_flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 026/438] btrfs: zoned: fix deadlock between metadata writeback and transaction commit
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 025/438] btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 027/438] btrfs: zoned: reset meta_write_pointer on zone reset Greg Kroah-Hartman
` (425 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Naohiro Aota, Johannes Thumshirn,
David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Thumshirn <johannes.thumshirn@wdc.com>
[ Upstream commit 1ebe51c29fa9755d5b2fea28727c051117907cf8 ]
When writing out metadata extent buffers in a zoned filesystem,
btree_writepages() holds fs_info->zoned_meta_io_lock across the whole
writeback loop, including the call to btrfs_check_meta_write_pointer() ->
check_bg_is_active().
For the tree-log block group, check_bg_is_active() may fail to activate
the zone and fall back to btrfs_zone_finish_one_bg() to free an active
zone. That path waits for the running transaction to commit while still
holding zoned_meta_io_lock, but the committer needs that same lock to
write out the tree extents, so the two tasks deadlock:
Task A (kworker, metadata writeback) Task B (fsstress, transaction commit)
------------------------------------ -------------------------------------
wb_workfn() btrfs_commit_transaction(T)
btree_writepages() btrfs_write_and_wait_transaction()
btrfs_zoned_meta_io_lock() btrfs_write_marked_extents()
btrfs_check_meta_write_pointer() btree_writepages()
check_bg_is_active() [treelog_bg] btrfs_zoned_meta_io_lock()
btrfs_zone_finish_one_bg() <blocks on zoned_meta_io_lock,
btrfs_zone_finish() held by Task A>
do_zone_finish()
btrfs_inc_block_group_ro()
btrfs_wait_for_commit()
<blocks waiting for commit
of transaction T, done by
Task B>
The sibling branch in check_bg_is_active() already drops zoned_meta_io_lock
around do_zone_finish() for this exact reason. Do the same in the tree-log
branch: release the lock around btrfs_zone_finish_one_bg() and re-acquire
it afterwards. The lock only protects fs_info->active_{meta,system}_bg,
which this branch does not touch, and ctx->zoned_bg keeps a reference to
the block group across the unlock, so nothing is lost while the lock
is dropped.
This hang occasionally reproduces with fstests generic/475 on a zoned
btrfs filesystem.
Fixes: 13bb483d32ab ("btrfs: zoned: activate metadata block group on write time")
Reviewed-by: Naohiro Aota <naohiro.aota@wdc.com>
Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/zoned.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
index 0d590e81f3259..a85fc150c97b5 100644
--- a/fs/btrfs/zoned.c
+++ b/fs/btrfs/zoned.c
@@ -2188,7 +2188,11 @@ static bool check_bg_is_active(struct btrfs_eb_write_context *ctx,
if (fs_info->treelog_bg == block_group->start) {
if (!btrfs_zone_activate(block_group)) {
- int ret_fin = btrfs_zone_finish_one_bg(fs_info);
+ int ret_fin;
+
+ btrfs_zoned_meta_io_unlock(fs_info);
+ ret_fin = btrfs_zone_finish_one_bg(fs_info);
+ btrfs_zoned_meta_io_lock(fs_info);
if (ret_fin != 1 || !btrfs_zone_activate(block_group))
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 027/438] btrfs: zoned: reset meta_write_pointer on zone reset
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 026/438] btrfs: zoned: fix deadlock between metadata writeback and transaction commit Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 028/438] btrfs: warn about extent buffer that can not be released Greg Kroah-Hartman
` (424 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Naohiro Aota, Johannes Thumshirn,
David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Thumshirn <johannes.thumshirn@wdc.com>
[ Upstream commit 5fabb1cf25d723274009d7b759545fd59f230c9d ]
btrfs_reset_unused_block_groups() resets a block group's zone and sets
alloc_offset back to 0 so the space can be reused, but it leaves
meta_write_pointer pointing at the previous end of the zone.
Once the block group is reactivated and reused for metadata, newly
allocated tree blocks live before that stale write pointer.
btrfs_check_meta_write_pointer() then sees them behind the write pointer,
so they can never be written out in sequential order: the dirty extent
buffers are stranded and pin their btree_inode folios until unmount.
Reset meta_write_pointer back to the start of the block group for
metadata and system block groups.
Fixes: 453a73c3069a ("btrfs: zoned: reclaim unused zone by zone resetting")
Reviewed-by: Naohiro Aota <naohiro.aota@wdc.com>
Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/zoned.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
index a85fc150c97b5..6963e9068a565 100644
--- a/fs/btrfs/zoned.c
+++ b/fs/btrfs/zoned.c
@@ -3196,6 +3196,17 @@ int btrfs_reset_unused_block_groups(struct btrfs_space_info *space_info, u64 num
reclaimed = bg->alloc_offset;
bg->zone_unusable = bg->length - bg->zone_capacity;
bg->alloc_offset = 0;
+ /*
+ * The zone was just reset to empty, so alloc_offset went back to
+ * the start of the zone. For metadata/system block groups the
+ * write pointer must follow it back to the start of the zone;
+ * otherwise it stays stale at the previous (finished) zone end,
+ * and metadata written into the reused zone would sit behind the
+ * write pointer, could never be written out in sequential order,
+ * and would be stranded (pinning its folio) until unmount.
+ */
+ if (bg->flags & (BTRFS_BLOCK_GROUP_METADATA | BTRFS_BLOCK_GROUP_SYSTEM))
+ bg->meta_write_pointer = bg->start;
/*
* This holds because we currently reset fully used then freed
* block group.
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 028/438] btrfs: warn about extent buffer that can not be released
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 027/438] btrfs: zoned: reset meta_write_pointer on zone reset Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 029/438] btrfs: skip global block reserve accounting for rescue mounts Greg Kroah-Hartman
` (423 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AHN SEOK-YOUNG, Teng Liu,
Filipe Manana, Qu Wenruo, David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qu Wenruo <wqu@suse.com>
[ Upstream commit 83f7e52b7ed1c3e03b79123e20b6f6adf8d886bb ]
When we unmount the fs or during mount failures, btrfs will call
invalidate_inode_pages() to release all btree inode folios.
However that function can return -EBUSY if any folios can not be
invalidated.
This can be caused by:
- Some extent buffers are still held by btrfs
This is a logic error, as we should release all tree root nodes
during unmount and mount failure handling.
- Some extent buffers are under readahead and haven't yet finished
These are much rarer but valid cases.
In that case we should wait for those extent buffers.
Introduce a new helper invalidate_and_check_btree_folios() which will:
- Call invalidate_inode_pages2() and catch its return value
If it returned 0 as expected, that's great and we can call it a day.
- Otherwise go through each extent buffer in buffer_tree
Increase the ref by one first for the eb we're checking.
This is to ensure the eb won't be freed after the readahead is
finished.
For ebs that still have EXTENT_BUFFER_READING flag, wait for them to
finish first.
After waiting for the readahead, check the refs of the eb and if it's
still dirty.
If the eb ref count is greater than 2 (one for the buffer tree, one
held by us), it means we are still holding the extent buffer somewhere
else, which is a code bug.
If the eb is still dirty, it means a bug in transaction handling, e.g.
the bug fixed by patch "btrfs: only release the dirty pages io tree
after successful writes".
For either case, show a warning message about the eb, including its
bytenr, owner, refs and flags.
And if it's a debug build, also trigger WARN_ON_ONCE() so that fstests
can properly catch such situation.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221270
Reported-by: AHN SEOK-YOUNG <iamsyahn@gmail.com>
CC: Teng Liu <27rabbitlt@gmail.com>
Tested-by: Teng Liu <27rabbitlt@gmail.com>
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Stable-dep-of: 51a0e8399858 ("btrfs: skip global block reserve accounting for rescue mounts")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/disk-io.c | 53 ++++++++++++++++++++++++++++++++++++++++++--
fs/btrfs/extent_io.c | 6 -----
fs/btrfs/extent_io.h | 6 +++++
3 files changed, 57 insertions(+), 8 deletions(-)
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index ab92b35fa3cc1..833965b06f90e 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -3276,6 +3276,55 @@ static bool fs_is_full_ro(const struct btrfs_fs_info *fs_info)
return false;
}
+/*
+ * Try to wait for any metadata readahead, and invalidate all btree folios.
+ *
+ * If the invalidation failed, report any dirty/held extent buffers.
+ */
+static void invalidate_and_check_btree_folios(struct btrfs_fs_info *fs_info)
+{
+ unsigned long index = 0;
+ struct extent_buffer *eb;
+ int ret;
+
+ ret = invalidate_inode_pages2(fs_info->btree_inode->i_mapping);
+ if (likely(ret == 0))
+ return;
+
+ /*
+ * Some btree pages can not be invalidated, this happens when some tree
+ * blocks are still held (either by readahead or some task is holding a ref).
+ */
+ rcu_read_lock();
+ xa_for_each(&fs_info->buffer_tree, index, eb) {
+ /* Increase the ref so that the eb won't disappear. */
+ if (!refcount_inc_not_zero(&eb->refs))
+ continue;
+ rcu_read_unlock();
+
+ /* Wait for any readahead first. */
+ if (test_bit(EXTENT_BUFFER_READING, &eb->bflags))
+ wait_on_bit_io(&eb->bflags, EXTENT_BUFFER_READING,
+ TASK_UNINTERRUPTIBLE);
+ /*
+ * The refs threshold is 2, one held by us at the beginning
+ * of the loop, one for the ownership in the buffer tree.
+ */
+ if (unlikely(refcount_read(&eb->refs) > 2 || extent_buffer_under_io(eb))) {
+ WARN_ON_ONCE(IS_ENABLED(CONFIG_BTRFS_DEBUG));
+ btrfs_warn(fs_info,
+ "unable to release extent buffer %llu owner %llu gen %llu refs %u flags 0x%lx",
+ eb->start, btrfs_header_owner(eb),
+ btrfs_header_generation(eb),
+ refcount_read(&eb->refs), eb->bflags);
+ }
+ free_extent_buffer(eb);
+ rcu_read_lock();
+ }
+ rcu_read_unlock();
+ invalidate_inode_pages2(fs_info->btree_inode->i_mapping);
+}
+
int __cold open_ctree(struct super_block *sb, struct btrfs_fs_devices *fs_devices)
{
u32 sectorsize;
@@ -3706,7 +3755,7 @@ int __cold open_ctree(struct super_block *sb, struct btrfs_fs_devices *fs_device
if (fs_info->data_reloc_root)
btrfs_drop_and_free_fs_root(fs_info, fs_info->data_reloc_root);
free_root_pointers(fs_info, true);
- invalidate_inode_pages2(fs_info->btree_inode->i_mapping);
+ invalidate_and_check_btree_folios(fs_info);
fail_sb_buffer:
btrfs_stop_all_workers(fs_info);
@@ -4445,7 +4494,7 @@ void __cold close_ctree(struct btrfs_fs_info *fs_info)
* We must make sure there is not any read request to
* submit after we stop all workers.
*/
- invalidate_inode_pages2(fs_info->btree_inode->i_mapping);
+ invalidate_and_check_btree_folios(fs_info);
btrfs_stop_all_workers(fs_info);
/*
diff --git a/fs/btrfs/extent_io.c b/fs/btrfs/extent_io.c
index f0bfa8a6218a7..741fd1d4ab2ea 100644
--- a/fs/btrfs/extent_io.c
+++ b/fs/btrfs/extent_io.c
@@ -2877,12 +2877,6 @@ bool try_release_extent_mapping(struct folio *folio, gfp_t mask)
return try_release_extent_state(io_tree, folio);
}
-static int extent_buffer_under_io(const struct extent_buffer *eb)
-{
- return (test_bit(EXTENT_BUFFER_WRITEBACK, &eb->bflags) ||
- test_bit(EXTENT_BUFFER_DIRTY, &eb->bflags));
-}
-
static bool folio_range_has_eb(struct folio *folio)
{
struct btrfs_folio_state *bfs;
diff --git a/fs/btrfs/extent_io.h b/fs/btrfs/extent_io.h
index b310a5145cf69..7b4152387d886 100644
--- a/fs/btrfs/extent_io.h
+++ b/fs/btrfs/extent_io.h
@@ -327,6 +327,12 @@ static inline bool extent_buffer_uptodate(const struct extent_buffer *eb)
return test_bit(EXTENT_BUFFER_UPTODATE, &eb->bflags);
}
+static inline bool extent_buffer_under_io(const struct extent_buffer *eb)
+{
+ return (test_bit(EXTENT_BUFFER_WRITEBACK, &eb->bflags) ||
+ test_bit(EXTENT_BUFFER_DIRTY, &eb->bflags));
+}
+
int memcmp_extent_buffer(const struct extent_buffer *eb, const void *ptrv,
unsigned long start, unsigned long len);
void read_extent_buffer(const struct extent_buffer *eb, void *dst,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 029/438] btrfs: skip global block reserve accounting for rescue mounts
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 028/438] btrfs: warn about extent buffer that can not be released Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 030/438] btrfs: raid56: fix an incorrect csum skip during scrub Greg Kroah-Hartman
` (422 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Dongjiang Zhu,
David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dongjiang Zhu <zhudongjiang@fnnas.com>
[ Upstream commit 51a0e8399858621442807a26057bcd1cd3ced046 ]
[BUG]
Mounting with rescue=ibadroots after corrupting the block group tree
root triggers a NULL pointer dereference:
BUG: kernel NULL pointer dereference, address: 0000000000000100
RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs]
Call Trace:
fill_dummy_bgs+0xd4/0x120 [btrfs]
open_ctree+0xc6e/0x1ca0 [btrfs]
btrfs_get_tree+0x50d/0xa40 [btrfs]
The same crash occurs with a corrupted raid stripe tree root, via
btrfs_read_block_groups() instead of fill_dummy_bgs().
[CAUSE]
With rescue=ibadroots, btrfs_read_roots() allows the mount to continue
when either root cannot be read, leaving the corresponding root pointer
NULL while its on-disk feature bit remains set.
btrfs_update_global_block_rsv() then dereferences the missing root based
on the feature bit alone.
[FIX]
Rescue mounts are fully read-only and cannot start transactions, so the
global reserve is never consumed. Under btrfs_is_full_ro(), mark the
reserve as full and return before performing the accounting.
And since we need to check if the fs is mount fully RO, export
fs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.
Fixes: 8dbfc14fc736 ("btrfs: account block group tree when calculating global reserve size")
Fixes: 515020900d44 ("btrfs: read raid stripe tree from disk")
Suggested-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Dongjiang Zhu <zhudongjiang@fnnas.com>
[ Squash the fs_is_full_ro() export commit into this one. ]
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/block-rsv.c | 19 +++++++++++++++++--
fs/btrfs/disk-io.c | 11 +----------
fs/btrfs/fs.h | 9 +++++++++
3 files changed, 27 insertions(+), 12 deletions(-)
diff --git a/fs/btrfs/block-rsv.c b/fs/btrfs/block-rsv.c
index 9efb3016ef116..c68a8f4b7d19c 100644
--- a/fs/btrfs/block-rsv.c
+++ b/fs/btrfs/block-rsv.c
@@ -322,10 +322,25 @@ void btrfs_block_rsv_add_bytes(struct btrfs_block_rsv *block_rsv,
void btrfs_update_global_block_rsv(struct btrfs_fs_info *fs_info)
{
struct btrfs_block_rsv *block_rsv = &fs_info->global_block_rsv;
- struct btrfs_space_info *sinfo = block_rsv->space_info;
+ struct btrfs_space_info *sinfo;
struct btrfs_root *root, *tmp;
- u64 num_bytes = btrfs_root_used(&fs_info->tree_root->root_item);
unsigned int min_items = 1;
+ u64 num_bytes;
+
+ /*
+ * A full read-only mount (rescue options) cannot start transactions,
+ * so the global reserve is never consumed. Mark it as full and skip
+ * the accounting.
+ */
+ if (btrfs_is_full_ro(fs_info)) {
+ spin_lock(&block_rsv->lock);
+ block_rsv->full = true;
+ spin_unlock(&block_rsv->lock);
+ return;
+ }
+
+ sinfo = block_rsv->space_info;
+ num_bytes = btrfs_root_used(&fs_info->tree_root->root_item);
/*
* The global block rsv is based on the size of the extent tree, the
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index 833965b06f90e..7ca64f79451cb 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -3267,15 +3267,6 @@ int btrfs_check_features(struct btrfs_fs_info *fs_info, bool is_rw_mount)
return 0;
}
-static bool fs_is_full_ro(const struct btrfs_fs_info *fs_info)
-{
- if (!sb_rdonly(fs_info->sb))
- return false;
- if (unlikely(fs_info->mount_opt & BTRFS_MOUNT_FULL_RO_MASK))
- return true;
- return false;
-}
-
/*
* Try to wait for any metadata readahead, and invalidate all btree folios.
*
@@ -3432,7 +3423,7 @@ int __cold open_ctree(struct super_block *sb, struct btrfs_fs_devices *fs_device
WRITE_ONCE(fs_info->fs_error, -EUCLEAN);
/* If the fs has any rescue options, no transaction is allowed. */
- if (fs_is_full_ro(fs_info))
+ if (btrfs_is_full_ro(fs_info))
WRITE_ONCE(fs_info->fs_error, -EROFS);
/* Set up fs_info before parsing mount options */
diff --git a/fs/btrfs/fs.h b/fs/btrfs/fs.h
index a8aa086a4df86..0292246db614d 100644
--- a/fs/btrfs/fs.h
+++ b/fs/btrfs/fs.h
@@ -1146,6 +1146,15 @@ void __btrfs_clear_fs_compat_ro(struct btrfs_fs_info *fs_info, u64 flag,
#define btrfs_test_opt(fs_info, opt) ((fs_info)->mount_opt & \
BTRFS_MOUNT_##opt)
+static inline bool btrfs_is_full_ro(const struct btrfs_fs_info *fs_info)
+{
+ if (!sb_rdonly(fs_info->sb))
+ return false;
+ if (unlikely(fs_info->mount_opt & BTRFS_MOUNT_FULL_RO_MASK))
+ return true;
+ return false;
+}
+
static inline bool btrfs_fs_closing(const struct btrfs_fs_info *fs_info)
{
return unlikely(test_bit(BTRFS_FS_CLOSING_START, &fs_info->flags));
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 030/438] btrfs: raid56: fix an incorrect csum skip during scrub
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 029/438] btrfs: skip global block reserve accounting for rescue mounts Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 031/438] btrfs: zoned: skip fully truncated ordered extents at zone finish Greg Kroah-Hartman
` (421 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Vacek, Qu Wenruo,
David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qu Wenruo <wqu@suse.com>
[ Upstream commit 330dcc553f282e8dc0b88c9495b4c296465364e1 ]
Commit 7425a2894019 ("btrfs: introduce btrfs_bio_for_each_block_all()
helper") uses the new helper to replace the nested loop inside
verify_bio_data_sectors(), which simplifies the code.
However that also changed the behavior of "continue" when a block has no
data checksum.
Previously the "continue" would skip the old for() loop, which would also
increase @total_sector_nr.
Now the "continue" will skip the new btrfs_bio_for_each_block_all()
loop, which doesn't update @total_sector_nr.
This means if we hit a block that has no data checksum, we will skip all
the remaining blocks no matter if they have data checksum.
As @total_sector_nr will never be updated, and that test_bit() will
always return false.
Fix it by increasing @total_sector_nr before calling "continue".
Fixes: 7425a2894019 ("btrfs: introduce btrfs_bio_for_each_block_all() helper")
Reviewed-by: Daniel Vacek <neelx@suse.com>
Signed-off-by: Qu Wenruo <wqu@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/raid56.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/raid56.c b/fs/btrfs/raid56.c
index 08ee8f316d96d..515ffa4b02114 100644
--- a/fs/btrfs/raid56.c
+++ b/fs/btrfs/raid56.c
@@ -1679,8 +1679,10 @@ static void verify_bio_data_sectors(struct btrfs_raid_bio *rbio,
continue;
/* No csum for this sector, skip to the next sector. */
- if (!test_bit(total_sector_nr, rbio->csum_bitmap))
+ if (!test_bit(total_sector_nr, rbio->csum_bitmap)) {
+ total_sector_nr++;
continue;
+ }
expected_csum = rbio->csum_buf + total_sector_nr * fs_info->csum_size;
btrfs_calculate_block_csum_pages(fs_info, paddrs, csum_buf);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 031/438] btrfs: zoned: skip fully truncated ordered extents at zone finish
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 030/438] btrfs: raid56: fix an incorrect csum skip during scrub Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 032/438] ntfs: harden runlist realloc size calculations Greg Kroah-Hartman
` (420 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Johannes Thumshirn,
David Sterba, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Thumshirn <johannes.thumshirn@wdc.com>
[ Upstream commit ab602da96a915d42dcb1b0b322e8daea0f71b51f ]
A fully truncated ordered extent (truncated_len == 0) wrote no data, so its
->csum_list is empty and btrfs_finish_ordered_zoned() trips:
assertion failed: !list_empty(&ordered->csum_list), in fs/btrfs/zoned.c:2141
Since commit 66ff4d366e7e a short or cancelled direct IO write finishes the
unsubmitted ordered extent as truncated with uptodate = true instead of
setting BTRFS_ORDERED_IOERR, so it now reaches btrfs_finish_ordered_zoned()
rather than being skipped by the IOERR check in btrfs_finish_ordered_io().
generic/208 hits this on a zoned filesystem.
Return early for these, like the BTRFS_ORDERED_PREALLOC case; there is no
zone append result to record and btrfs_finish_one_ordered() skips them too.
Fixes: 66ff4d366e7e ("btrfs: fix false IO failure after falling back to buffered write")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/zoned.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
index 6963e9068a565..e9d72401d328f 100644
--- a/fs/btrfs/zoned.c
+++ b/fs/btrfs/zoned.c
@@ -2136,6 +2136,16 @@ void btrfs_finish_ordered_zoned(struct btrfs_ordered_extent *ordered)
if (test_bit(BTRFS_ORDERED_PREALLOC, &ordered->flags))
return;
+ /*
+ * A fully truncated ordered extent wrote no data and so has
+ * no zone append result to record.
+ */
+ if (test_bit(BTRFS_ORDERED_TRUNCATED, &ordered->flags) &&
+ ordered->truncated_len == 0) {
+ ASSERT(list_empty(&ordered->csum_list));
+ return;
+ }
+
ASSERT(!list_empty(&ordered->csum_list));
sum = list_first_entry(&ordered->csum_list, struct btrfs_ordered_sum, list);
logical = sum->logical;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 032/438] ntfs: harden runlist realloc size calculations
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 031/438] btrfs: zoned: skip fully truncated ordered extents at zone finish Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 033/438] ntfs: drop stale page-cache when shrinking a non-resident attr Greg Kroah-Hartman
` (419 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alper Mudar, Namjae Jeon,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 8bed376124ab4505b70083a2b91f2c7ef6d51e24 ]
Add a shared helper to safely convert runlist element counts to byte sizes
using overflow checks, and use it in both ntfs_rl_realloc() and
ntfs_rl_realloc_nofail().
Fixes: 11ccc9107dc4 ("ntfs: update runlist handling and cluster allocator")
Co-developed-by: Alper Mudar <kommandant_alper@proton.me>
Signed-off-by: Alper Mudar <kommandant_alper@proton.me>
Tested-by: Alper Mudar <kommandant_alper@proton.me>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/runlist.c | 50 +++++++++++++++++++++++++----------------------
1 file changed, 27 insertions(+), 23 deletions(-)
diff --git a/fs/ntfs/runlist.c b/fs/ntfs/runlist.c
index 15f1ae530ae13..8d2740cfddd73 100644
--- a/fs/ntfs/runlist.c
+++ b/fs/ntfs/runlist.c
@@ -71,29 +71,46 @@ static inline void ntfs_rl_mc(struct runlist_element *dstbase, int dst,
* On success, return a pointer to the newly allocated, or recycled, memory.
* On error, return -errno.
*/
-struct runlist_element *ntfs_rl_realloc(struct runlist_element *rl,
- int old_size, int new_size)
+static inline struct runlist_element *ntfs_rl_realloc_gfp(struct runlist_element *rl,
+ int old_size, int new_size, gfp_t gfp)
{
struct runlist_element *new_rl;
+ size_t new_bytes;
+
+ if (old_size < 0 || new_size < 0)
+ return ERR_PTR(-EINVAL);
- old_size = old_size * sizeof(*rl);
- new_size = new_size * sizeof(*rl);
if (old_size == new_size)
return rl;
- new_rl = kvzalloc(new_size, GFP_NOFS);
+ if (check_mul_overflow(new_size, sizeof(*rl), &new_bytes))
+ return ERR_PTR(-EINVAL);
+
+ new_rl = kvzalloc(new_bytes, gfp);
if (unlikely(!new_rl))
return ERR_PTR(-ENOMEM);
if (likely(rl != NULL)) {
- if (unlikely(old_size > new_size))
- old_size = new_size;
- memcpy(new_rl, rl, old_size);
+ size_t old_bytes;
+
+ if (check_mul_overflow(old_size, sizeof(*rl), &old_bytes)) {
+ kvfree(new_rl);
+ return ERR_PTR(-EINVAL);
+ }
+ if (unlikely(old_bytes > new_bytes))
+ old_bytes = new_bytes;
+ memcpy(new_rl, rl, old_bytes);
kvfree(rl);
}
return new_rl;
}
+struct runlist_element *ntfs_rl_realloc(struct runlist_element *rl,
+ int old_size, int new_size)
+{
+ return ntfs_rl_realloc_gfp(rl, old_size, new_size, GFP_NOFS);
+}
+
/*
* ntfs_rl_realloc_nofail - Reallocate memory for runlists
* @rl: original runlist
@@ -118,21 +135,8 @@ struct runlist_element *ntfs_rl_realloc(struct runlist_element *rl,
static inline struct runlist_element *ntfs_rl_realloc_nofail(struct runlist_element *rl,
int old_size, int new_size)
{
- struct runlist_element *new_rl;
-
- old_size = old_size * sizeof(*rl);
- new_size = new_size * sizeof(*rl);
- if (old_size == new_size)
- return rl;
-
- new_rl = kvmalloc(new_size, GFP_NOFS | __GFP_NOFAIL);
- if (likely(rl != NULL)) {
- if (unlikely(old_size > new_size))
- old_size = new_size;
- memcpy(new_rl, rl, old_size);
- kvfree(rl);
- }
- return new_rl;
+ return ntfs_rl_realloc_gfp(rl, old_size, new_size,
+ GFP_NOFS | __GFP_NOFAIL);
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 033/438] ntfs: drop stale page-cache when shrinking a non-resident attr
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 032/438] ntfs: harden runlist realloc size calculations Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 034/438] rtla/timerlat_top: Fix on-threshold actions firing on signal Greg Kroah-Hartman
` (418 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 4e646ecd44759e552b0b9ccd995f3f608daab414 ]
ntfs_non_resident_attr_shrink() shrinks attribute sizes but fails to
trim the page cache. This leaves orphaned dirty folios beyond the new
end of the attribute, leading to writeback failures (-ENOENT), data
loss, and $EA chain corruption.
Fix this by truncating the page cache to the new size immediately after
updating the sizes, preventing writeback from flushing out-of-range folios.
Fixes: 495e90fa3348 ("ntfs: update attrib operations")
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/attrib.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index 0f1d0b54cfb52..22338ad541279 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -4292,6 +4292,16 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
ni->initialized_size = newsize;
ctx->attr->data.non_resident.initialized_size = cpu_to_le64(newsize);
}
+
+ /*
+ * Drop any page-cache folios that now lie beyond the shrunk
+ * attribute. The clusters backing them have just been freed and the
+ * runlist truncated, so leaving stale dirty folios around makes a
+ * later writeback map a vcn past the new allocation, which fails with
+ * -ENOENT and loses the write.
+ */
+ truncate_inode_pages(VFS_I(ni)->i_mapping, newsize);
+
/* Update data size in the index. */
if (ni->type == AT_DATA && ni->name == AT_UNNAMED)
NInoSetFileNameDirty(ni);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 034/438] rtla/timerlat_top: Fix on-threshold actions firing on signal
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 033/438] ntfs: drop stale page-cache when shrinking a non-resident attr Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 035/438] phy: zynqmp: fix clock error handling in xpsgtr_phy_init() Greg Kroah-Hartman
` (417 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Attila Fazekas, Wander Lairson Costa,
Tomas Glozar, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tomas Glozar <tglozar@redhat.com>
[ Upstream commit fafb66e5903c2bcfc7b7e259042a8282f18a6faa ]
A bug was reported when rtla-timerlat-top tool performs on-threshold
actions, even though no threshold was hit. This is reproduced even if no
threshold is set at all:
$ rtla timerlat top -q -c 0 --on-threshold shell,command='echo BAD'
BAD
Timer Latency
...
The bug is due to incorrect logic in timerlat_top_bpf_main_loop().
The loop uses timerlat_bpf_wait(), the return values of which are:
- > 0 (number of ringbuffer entries): at least 1 CPU hit threshold
- = 0: time out
- < 0: wait was interrupted by a signal
Commit 3138df6f0cd0 ("rtla/timerlat: Exit top main loop on any non-zero
wait_retval") changed the condition for "threshold hit" from
"wait_reval == 1" (exactly 1 CPU hit threshold) to "wait_retval != 0",
to fix a race where multiple CPUs hit the threshold at the same time.
That also made it incorrectly include a signal (< 0), coming from either
duration expired (SIGALRM) or user interrupt (SIGINT).
Check for wait_retval greater than zero in the if condition to cover all
return values correctly.
Fixes: 3138df6f0cd0 ("rtla/timerlat: Exit top main loop on any non-zero wait_retval")
Reported-by: Attila Fazekas <afazekas@redhat.com>
Reviewed-by: Wander Lairson Costa <wander@redhat.com>
Link: https://lore.kernel.org/r/20260713141047.687877-1-tglozar@redhat.com
Signed-off-by: Tomas Glozar <tglozar@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/tracing/rtla/src/timerlat_top.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/tracing/rtla/src/timerlat_top.c b/tools/tracing/rtla/src/timerlat_top.c
index 035abf01dbe63..d625b76a31679 100644
--- a/tools/tracing/rtla/src/timerlat_top.c
+++ b/tools/tracing/rtla/src/timerlat_top.c
@@ -821,7 +821,7 @@ timerlat_top_bpf_main_loop(struct osnoise_tool *tool)
if (!params->quiet)
timerlat_print_stats(tool);
- if (wait_retval != 0) {
+ if (wait_retval > 0) {
/* Stopping requested by tracer */
retval = common_threshold_handler(tool);
if (retval)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 035/438] phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 034/438] rtla/timerlat_top: Fix on-threshold actions firing on signal Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 036/438] phy: zynqmp: fix runtime PM leak on probe allocation failure Greg Kroah-Hartman
` (416 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Radhey Shyam Pandey, Michal Simek,
Vinod Koul, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
[ Upstream commit e4779e2a16d600892aaf743438f6ce8cc4eb3c4c ]
Propagate clk_prepare_enable() failures to the caller instead of
returning success, and disable the reference clock on initialization
error paths to avoid leaking clock references when phy_exit() is not
called.
Fixes: 25d700833513 ("phy: xilinx: phy-zynqmp: dynamic clock support for power-save")
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Reviewed-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260720153832.1130006-2-radhey.shyam.pandey@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/xilinx/phy-zynqmp.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/phy/xilinx/phy-zynqmp.c b/drivers/phy/xilinx/phy-zynqmp.c
index fe6b4925d1662..c8230f2bda629 100644
--- a/drivers/phy/xilinx/phy-zynqmp.c
+++ b/drivers/phy/xilinx/phy-zynqmp.c
@@ -658,12 +658,13 @@ static int xpsgtr_phy_init(struct phy *phy)
{
struct xpsgtr_phy *gtr_phy = phy_get_drvdata(phy);
struct xpsgtr_dev *gtr_dev = gtr_phy->dev;
- int ret = 0;
+ int ret;
mutex_lock(>r_dev->gtr_mutex);
/* Configure and enable the clock when peripheral phy_init call */
- if (clk_prepare_enable(gtr_dev->clk[gtr_phy->refclk]))
+ ret = clk_prepare_enable(gtr_dev->clk[gtr_phy->refclk]);
+ if (ret)
goto out;
/* Skip initialization if not required. */
@@ -673,7 +674,7 @@ static int xpsgtr_phy_init(struct phy *phy)
if (gtr_dev->tx_term_fix) {
ret = xpsgtr_phy_tx_term_fix(gtr_phy);
if (ret < 0)
- goto out;
+ goto out_disable_clk;
gtr_dev->tx_term_fix = false;
}
@@ -687,7 +688,7 @@ static int xpsgtr_phy_init(struct phy *phy)
*/
ret = xpsgtr_configure_pll(gtr_phy);
if (ret)
- goto out;
+ goto out_disable_clk;
xpsgtr_lane_set_protocol(gtr_phy);
@@ -705,6 +706,10 @@ static int xpsgtr_phy_init(struct phy *phy)
break;
}
+ goto out;
+
+out_disable_clk:
+ clk_disable_unprepare(gtr_dev->clk[gtr_phy->refclk]);
out:
mutex_unlock(>r_dev->gtr_mutex);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 036/438] phy: zynqmp: fix runtime PM leak on probe allocation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 035/438] phy: zynqmp: fix clock error handling in xpsgtr_phy_init() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 037/438] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() Greg Kroah-Hartman
` (415 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Radhey Shyam Pandey, Michal Simek,
Vinod Koul, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
[ Upstream commit f3506e15cf72e94f62d5f2d173e5b7008f644cde ]
Allocate saved_regs before pm_runtime_resume_and_get() so a
devm_kmalloc() failure does not leave an unreleased runtime PM usage
counter.
Fixes: 5af9b304bc60 ("phy: xilinx: phy-zynqmp: Fix SGMII linkup failure on resume")
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Reviewed-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260720153832.1130006-3-radhey.shyam.pandey@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/xilinx/phy-zynqmp.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/phy/xilinx/phy-zynqmp.c b/drivers/phy/xilinx/phy-zynqmp.c
index c8230f2bda629..2138f5399821a 100644
--- a/drivers/phy/xilinx/phy-zynqmp.c
+++ b/drivers/phy/xilinx/phy-zynqmp.c
@@ -1044,6 +1044,12 @@ static int xpsgtr_probe(struct platform_device *pdev)
return PTR_ERR(provider);
}
+ gtr_dev->saved_regs = devm_kmalloc(gtr_dev->dev,
+ sizeof(save_reg_address),
+ GFP_KERNEL);
+ if (!gtr_dev->saved_regs)
+ return -ENOMEM;
+
pm_runtime_set_active(gtr_dev->dev);
pm_runtime_enable(gtr_dev->dev);
@@ -1053,12 +1059,6 @@ static int xpsgtr_probe(struct platform_device *pdev)
return ret;
}
- gtr_dev->saved_regs = devm_kmalloc(gtr_dev->dev,
- sizeof(save_reg_address),
- GFP_KERNEL);
- if (!gtr_dev->saved_regs)
- return -ENOMEM;
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 037/438] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 036/438] phy: zynqmp: fix runtime PM leak on probe allocation failure Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 038/438] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests Greg Kroah-Hartman
` (414 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei,
Pablo Neira Ayuso, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5 ]
sip_help_tcp() stores the size change of each NAT-rewritten SIP message
in s16 diff and accumulates it in s16 tdiff, but a single message can
grow by more than S16_MAX while the packet stays under the 65535
enlarge_skb() limit: nf_nat_sip() rewrites every matching URI, and a long
Contact list expands the message by tens of kilobytes. diff then wraps,
and "datalen = datalen + diff - msglen" yields a huge unsigned datalen,
so the next iteration's ct_sip_get_header() reads past the linearized skb
tail.
Widen diff, tdiff and the seq_adjust hook to s32. Both are bounded by the
65535 byte packet limit, and the seqadj core is already s32
(nf_ct_seqadj_set() takes s32), so no previously accepted input is
rejected.
BUG: KASAN: use-after-free in ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)
Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25
ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)
sip_help_tcp (net/netfilter/nf_conntrack_sip.c:1694)
nf_confirm (net/netfilter/nf_conntrack_proto.c:183)
nf_hook_slow (net/netfilter/core.c:619)
ip6_output (net/ipv6/ip6_output.c:246)
ip6_forward (net/ipv6/ip6_output.c:690)
ipv6_rcv (net/ipv6/ip6_input.c:351)
__netif_receive_skb_one_core (net/core/dev.c:6212)
process_backlog (net/core/dev.c:6676)
__napi_poll (net/core/dev.c:7735)
net_rx_action (net/core/dev.c:7955)
handle_softirqs (kernel/softirq.c:622)
run_ksoftirqd (kernel/softirq.c:1076)
...
Fixes: f5b321bd37fb ("netfilter: nf_conntrack_sip: add TCP support")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/netfilter-devel/20260712234201.3213635-1-xmei5@asu.edu
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/netfilter/nf_conntrack_sip.h | 2 +-
net/netfilter/nf_conntrack_sip.c | 2 +-
net/netfilter/nf_nat_sip.c | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/include/linux/netfilter/nf_conntrack_sip.h b/include/linux/netfilter/nf_conntrack_sip.h
index dbc614dfe0d56..aafa0c04f917e 100644
--- a/include/linux/netfilter/nf_conntrack_sip.h
+++ b/include/linux/netfilter/nf_conntrack_sip.h
@@ -115,7 +115,7 @@ struct nf_nat_sip_hooks {
unsigned int *datalen);
void (*seq_adjust)(struct sk_buff *skb,
- unsigned int protoff, s16 off);
+ unsigned int protoff, s32 off);
unsigned int (*expect)(struct sk_buff *skb,
unsigned int protoff,
diff --git a/net/netfilter/nf_conntrack_sip.c b/net/netfilter/nf_conntrack_sip.c
index f3f90a8663389..e4a70d1d77b0b 100644
--- a/net/netfilter/nf_conntrack_sip.c
+++ b/net/netfilter/nf_conntrack_sip.c
@@ -1663,7 +1663,7 @@ static int sip_help_tcp(struct sk_buff *skb, unsigned int protoff,
unsigned int matchoff, matchlen;
unsigned int msglen, origlen;
const char *dptr, *end;
- s16 diff, tdiff = 0;
+ s32 diff, tdiff = 0;
int ret = NF_ACCEPT;
unsigned long clen;
bool term;
diff --git a/net/netfilter/nf_nat_sip.c b/net/netfilter/nf_nat_sip.c
index aea02f6aff092..a93eaf0f7d305 100644
--- a/net/netfilter/nf_nat_sip.c
+++ b/net/netfilter/nf_nat_sip.c
@@ -321,7 +321,7 @@ static unsigned int nf_nat_sip(struct sk_buff *skb, unsigned int protoff,
}
static void nf_nat_sip_seq_adjust(struct sk_buff *skb, unsigned int protoff,
- s16 off)
+ s32 off)
{
enum ip_conntrack_info ctinfo;
struct nf_conn *ct = nf_ct_get(skb, &ctinfo);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 038/438] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 037/438] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 039/438] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() Greg Kroah-Hartman
` (413 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo@kernel.org>
[ Upstream commit 1d6123f87eebb5148844cd43045c6e598799720b ]
The IPIP and IP6IP6 tunnel tests call check_counters() to verify
flowtable offloading occurred, but the flow-add rule only matches
meta oif "veth1". When traffic is routed through a tunnel device,
oif is the tunnel interface (tun0, tun6, etc.), not veth1, so
the flow-add rule never fires, no flowtable entry is created,
and counters stay at zero — producing a silent false pass.
Fix by adding tunnel-specific flow-add rules for each tunnel
interface. These match TCP dport 12345 traffic before the bare
accept rule, set ct mark, add the flow to the flowtable, and
increment routed_orig. The existing routed_repl rule on veth0
already handles the reply direction since decapsulated reply
packets exit through the physical interface.
Also add check_counters() for the IP6IP6 non-VLAN and
IP6IP6-over-VLAN tests which previously used a bare PASS message.
Fixes: fe8313316eaf ("selftests: netfilter: nft_flowtable.sh: Add IPIP flowtable selftest")
Fixes: 5e5180352193 ("selftests: netfilter: nft_flowtable.sh: Add IP6IP6 flowtable selftest")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../selftests/net/netfilter/nft_flowtable.sh | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/net/netfilter/nft_flowtable.sh b/tools/testing/selftests/net/netfilter/nft_flowtable.sh
index 08ad07500e8a7..d9a21ca8ed2cb 100755
--- a/tools/testing/selftests/net/netfilter/nft_flowtable.sh
+++ b/tools/testing/selftests/net/netfilter/nft_flowtable.sh
@@ -617,7 +617,11 @@ ip -6 -net "$nsr2" route add default via fee1:3::1
ip -net "$ns2" route add default via 10.0.2.1
ip -6 -net "$ns2" route add default via dead:2::1
+ip netns exec "$nsr1" nft -a insert rule inet filter forward \
+ 'meta oif tun0 tcp dport 12345 ct mark set 1 flow add @f1 counter name routed_orig accept'
ip netns exec "$nsr1" nft -a insert rule inet filter forward 'meta oif tun0 accept'
+ip netns exec "$nsr1" nft -a insert rule inet filter forward \
+ 'meta oif tun6 tcp dport 12345 ct mark set 1 flow add @f1 counter name routed_orig accept'
ip netns exec "$nsr1" nft -a insert rule inet filter forward 'meta oif tun6 accept'
ip netns exec "$nsr1" nft -a insert rule inet filter forward \
'meta oif "veth0" tcp sport 12345 ct mark set 1 flow add @f1 counter name routed_repl accept'
@@ -629,7 +633,7 @@ if ! test_tcp_forwarding_nat "$ns1" "$ns2" 1 "IPIP tunnel"; then
fi
if test_tcp_forwarding "$ns1" "$ns2" 1 6 "[dead:2::99]" 12345; then
- echo "PASS: flow offload for ns1/ns2 IP6IP6 tunnel"
+ check_counters "flow offload for ns1/ns2 IP6IP6 tunnel"
else
echo "FAIL: flow offload for ns1/ns2 with IP6IP6 tunnel" 1>&2
ip netns exec "$nsr1" nft list ruleset
@@ -642,6 +646,8 @@ ip -net "$nsr1" link set veth1.10 up
ip -net "$nsr1" addr add 192.168.20.1/24 dev veth1.10
ip -net "$nsr1" addr add fee1:4::1/64 dev veth1.10 nodad
ip netns exec "$nsr1" sysctl net.ipv4.conf.veth1/10.forwarding=1 > /dev/null
+ip netns exec "$nsr1" nft -a insert rule inet filter forward \
+ 'meta oif veth1.10 tcp dport 12345 ct mark set 1 flow add @f1 counter name routed_orig accept'
ip netns exec "$nsr1" nft -a insert rule inet filter forward 'meta oif veth1.10 accept'
ip -net "$nsr1" link add name tun0.10 type ipip local 192.168.20.1 remote 192.168.20.2
@@ -649,6 +655,8 @@ ip -net "$nsr1" link set tun0.10 up
ip -net "$nsr1" addr add 192.168.200.1/24 dev tun0.10
ip -net "$nsr1" route change default via 192.168.200.2
ip netns exec "$nsr1" sysctl net.ipv4.conf.tun0/10.forwarding=1 > /dev/null
+ip netns exec "$nsr1" nft -a insert rule inet filter forward \
+ 'meta oif tun0.10 tcp dport 12345 ct mark set 1 flow add @f1 counter name routed_orig accept'
ip netns exec "$nsr1" nft -a insert rule inet filter forward 'meta oif tun0.10 accept'
ip -net "$nsr1" link add name tun6.10 type ip6tnl local fee1:4::1 remote fee1:4::2 encaplimit none
@@ -656,6 +664,8 @@ ip -net "$nsr1" link set tun6.10 up
ip -net "$nsr1" addr add fee1:5::1/64 dev tun6.10 nodad
ip -6 -net "$nsr1" route delete default
ip -6 -net "$nsr1" route add default via fee1:5::2
+ip netns exec "$nsr1" nft -a insert rule inet filter forward \
+ 'meta oif tun6.10 tcp dport 12345 ct mark set 1 flow add @f1 counter name routed_orig accept'
ip netns exec "$nsr1" nft -a insert rule inet filter forward 'meta oif tun6.10 accept'
ip -net "$nsr2" link add link veth0 name veth0.10 type vlan id 10
@@ -683,7 +693,7 @@ if ! test_tcp_forwarding_nat "$ns1" "$ns2" 1 "IPIP tunnel over vlan"; then
fi
if test_tcp_forwarding "$ns1" "$ns2" 1 6 "[dead:2::99]" 12345; then
- echo "PASS: flow offload for ns1/ns2 IP6IP6 tunnel over vlan"
+ check_counters "flow offload for ns1/ns2 IP6IP6 tunnel over vlan"
else
echo "FAIL: flow offload for ns1/ns2 with IP6IP6 tunnel over vlan" 1>&2
ip netns exec "$nsr1" nft list ruleset
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 039/438] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 038/438] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 040/438] drm/mediatek: Check CRTC state before freeing Greg Kroah-Hartman
` (412 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jaeyeong Lee, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit 4aa63842fc92de1bce59d4709a0d32e718890bb2 ]
Add a new function to insert a pair of expectations, this is required by
the SIP and H323 NAT helpers. The spinlock is held to check if there is
a slot for both expectations, in such case, insert them.
This removes the need for nf_ct_unexpect_related() inside the loop to
find a pair of consecutive ports, otherwise inserting expectations whose
dead flag is already set on can happen.
Bump master_help->expecting for the expectation class after checking if
the expectation fits in the master expectation list, which is needed for
this new _pair() function variant to run the eviction routine including
the preallocated slot for the first expectation in the pair.
Fixes: b8b09dc2bf35 ("netfilter: nf_conntrack_expect: use conntrack GC to reap expectations")
Reported-by: Jaeyeong Lee <iostreampy@proton.me>
Link: https://patch.msgid.link/178377968720.33756.12204817361601593230@proton.me/
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/netfilter/nf_conntrack_expect.h | 3 ++
net/ipv4/netfilter/nf_nat_h323.c | 22 +++++--------
net/netfilter/nf_conntrack_expect.c | 35 ++++++++++++++++++++-
net/netfilter/nf_nat_sip.c | 20 ++++--------
4 files changed, 50 insertions(+), 30 deletions(-)
diff --git a/include/net/netfilter/nf_conntrack_expect.h b/include/net/netfilter/nf_conntrack_expect.h
index c024345c9bd86..26d6babd92fcd 100644
--- a/include/net/netfilter/nf_conntrack_expect.h
+++ b/include/net/netfilter/nf_conntrack_expect.h
@@ -161,6 +161,9 @@ static inline int nf_ct_expect_related(struct nf_conntrack_expect *expect,
return nf_ct_expect_related_report(expect, 0, 0, flags);
}
+int nf_ct_expect_related_pair(struct nf_conntrack_expect *expect[],
+ unsigned int flag);
+
struct nf_conn_help;
void nf_ct_expectation_gc(struct nf_conn_help *master_help);
diff --git a/net/ipv4/netfilter/nf_nat_h323.c b/net/ipv4/netfilter/nf_nat_h323.c
index 183e8a3ff2bab..6bcd6734769b5 100644
--- a/net/ipv4/netfilter/nf_nat_h323.c
+++ b/net/ipv4/netfilter/nf_nat_h323.c
@@ -182,6 +182,7 @@ static int nat_rtp_rtcp(struct sk_buff *skb, struct nf_conn *ct,
struct nf_conntrack_expect *rtp_exp,
struct nf_conntrack_expect *rtcp_exp)
{
+ struct nf_conntrack_expect *rtp_pair[2] = { rtp_exp, rtcp_exp };
struct nf_ct_h323_master *info = nfct_help_data(ct);
int dir = CTINFO2DIR(ctinfo);
int i;
@@ -227,22 +228,13 @@ static int nat_rtp_rtcp(struct sk_buff *skb, struct nf_conn *ct,
int ret;
rtp_exp->tuple.dst.u.udp.port = htons(nated_port);
- ret = nf_ct_expect_related(rtp_exp, 0);
+ rtcp_exp->tuple.dst.u.udp.port = htons(nated_port + 1);
+ ret = nf_ct_expect_related_pair(rtp_pair, 0);
if (ret == 0) {
- rtcp_exp->tuple.dst.u.udp.port =
- htons(nated_port + 1);
- ret = nf_ct_expect_related(rtcp_exp, 0);
- if (ret == 0)
- break;
- else if (ret == -EBUSY) {
- nf_ct_unexpect_related(rtp_exp);
- continue;
- } else if (ret < 0) {
- nf_ct_unexpect_related(rtp_exp);
- nated_port = 0;
- break;
- }
- } else if (ret != -EBUSY) {
+ break;
+ } else if (ret == -EBUSY) {
+ continue;
+ } else if (ret < 0) {
nated_port = 0;
break;
}
diff --git a/net/netfilter/nf_conntrack_expect.c b/net/netfilter/nf_conntrack_expect.c
index 38630c5e006f0..16520a41fe5f0 100644
--- a/net/netfilter/nf_conntrack_expect.c
+++ b/net/netfilter/nf_conntrack_expect.c
@@ -426,7 +426,6 @@ static void nf_ct_expect_insert(struct nf_conntrack_expect *exp,
exp->timeout += helper->expect_policy[exp->class].timeout * HZ;
hlist_add_head_rcu(&exp->lnode, &master_help->expectations);
- master_help->expecting[exp->class]++;
hlist_add_head_rcu(&exp->hnode, &nf_ct_expect_hash[h]);
cnet = nf_ct_pernet(net);
@@ -533,6 +532,7 @@ int nf_ct_expect_related_report(struct nf_conntrack_expect *expect,
if (ret < 0)
goto out;
+ master_help->expecting[expect->class]++;
nf_ct_expect_insert(expect, master_help);
nf_ct_expect_event_report(IPEXP_NEW, expect, portid, report);
@@ -545,6 +545,39 @@ int nf_ct_expect_related_report(struct nf_conntrack_expect *expect,
}
EXPORT_SYMBOL_GPL(nf_ct_expect_related_report);
+int nf_ct_expect_related_pair(struct nf_conntrack_expect *expect[],
+ unsigned int flags)
+{
+ struct nf_conn_help *master_help;
+ int i, ret;
+
+ spin_lock_bh(&nf_conntrack_expect_lock);
+ master_help = nfct_help(expect[0]->master);
+ if (!master_help || master_help != nfct_help(expect[1]->master)) {
+ ret = -EINVAL;
+ goto out;
+ }
+
+ for (i = 0; i < 2; i++) {
+ ret = __nf_ct_expect_check(expect[i], master_help, flags);
+ if (ret < 0) {
+ if (i == 1)
+ master_help->expecting[expect[0]->class]--;
+ goto out;
+ }
+ master_help->expecting[expect[i]->class]++;
+ }
+
+ for (i = 0; i < 2; i++) {
+ nf_ct_expect_insert(expect[i], master_help);
+ nf_ct_expect_event_report(IPEXP_NEW, expect[i], 0, 0);
+ }
+out:
+ spin_unlock_bh(&nf_conntrack_expect_lock);
+ return ret;
+}
+EXPORT_SYMBOL_GPL(nf_ct_expect_related_pair);
+
void nf_ct_expect_iterate_destroy(bool (*iter)(struct nf_conntrack_expect *e, void *data),
void *data)
{
diff --git a/net/netfilter/nf_nat_sip.c b/net/netfilter/nf_nat_sip.c
index a93eaf0f7d305..133bd713fe0c2 100644
--- a/net/netfilter/nf_nat_sip.c
+++ b/net/netfilter/nf_nat_sip.c
@@ -592,6 +592,7 @@ static unsigned int nf_nat_sdp_media(struct sk_buff *skb, unsigned int protoff,
unsigned int medialen,
union nf_inet_addr *rtp_addr)
{
+ struct nf_conntrack_expect *rtp_pair[2] = { rtp_exp, rtcp_exp };
enum ip_conntrack_info ctinfo;
struct nf_conn *ct = nf_ct_get(skb, &ctinfo);
enum ip_conntrack_dir dir = CTINFO2DIR(ctinfo);
@@ -622,24 +623,15 @@ static unsigned int nf_nat_sdp_media(struct sk_buff *skb, unsigned int protoff,
int ret;
rtp_exp->tuple.dst.u.udp.port = htons(port);
- ret = nf_ct_expect_related(rtp_exp,
- NF_CT_EXP_F_SKIP_MASTER);
- if (ret == -EBUSY)
- continue;
- else if (ret < 0) {
- port = 0;
- break;
- }
rtcp_exp->tuple.dst.u.udp.port = htons(port + 1);
- ret = nf_ct_expect_related(rtcp_exp,
- NF_CT_EXP_F_SKIP_MASTER);
+
+ ret = nf_ct_expect_related_pair(rtp_pair,
+ NF_CT_EXP_F_SKIP_MASTER);
if (ret == 0)
break;
- else if (ret == -EBUSY) {
- nf_ct_unexpect_related(rtp_exp);
+ else if (ret == -EBUSY)
continue;
- } else if (ret < 0) {
- nf_ct_unexpect_related(rtp_exp);
+ else if (ret < 0) {
port = 0;
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 040/438] drm/mediatek: Check CRTC state before freeing
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 039/438] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 041/438] mshv_vtl: fix fd leak in mshv_ioctl_create_vtl() Greg Kroah-Hartman
` (411 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, CK Hu, Chun-Kuang Hu,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 233a4d3a39fc1585f5e271b2adab43c6af025ae0 ]
mtk_crtc_reset() destroys the current CRTC state only when crtc->state
is non-NULL, but it always converts crtc->state to struct mtk_crtc_state
and passes the result to kfree().
When reset is called without an existing state, container_of(NULL, ...)
does not produce NULL. Keep the mtk state free in the same crtc->state
guard as the helper state destruction.
This issue was found by a static analysis checker and confirmed by
manual source review.
Fixes: 2d267b81898e ("drm/mtk: Use __drm_atomic_helper_crtc_reset")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: CK Hu <ck.hu@mediatek.com>
Link: https://patchwork.kernel.org/project/linux-mediatek/patch/20260707150528.2270739-1-ruoyuw560@gmail.com/
Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/mediatek/mtk_crtc.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/mediatek/mtk_crtc.c b/drivers/gpu/drm/mediatek/mtk_crtc.c
index fcb16f3f7b23b..b01162a7df7fa 100644
--- a/drivers/gpu/drm/mediatek/mtk_crtc.c
+++ b/drivers/gpu/drm/mediatek/mtk_crtc.c
@@ -153,10 +153,10 @@ static void mtk_crtc_reset(struct drm_crtc *crtc)
{
struct mtk_crtc_state *state;
- if (crtc->state)
+ if (crtc->state) {
__drm_atomic_helper_crtc_destroy_state(crtc->state);
-
- kfree(to_mtk_crtc_state(crtc->state));
+ kfree(to_mtk_crtc_state(crtc->state));
+ }
crtc->state = NULL;
state = kzalloc_obj(*state);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 041/438] mshv_vtl: fix fd leak in mshv_ioctl_create_vtl()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 040/438] drm/mediatek: Check CRTC state before freeing Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 042/438] Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation Greg Kroah-Hartman
` (410 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yi Xie, Hamza Mahfooz, Wei Liu,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yi Xie <xieyi@kylinos.cn>
[ Upstream commit ec08dd5b9ffa52980908805bdc8a55a8f1bc6667 ]
put_unused_fd() if anon_inode_getfile() fails.
Fixes: 7bfe3b8ea6e30 ("Drivers: hv: Introduce mshv_vtl driver")
Signed-off-by: Yi Xie <xieyi@kylinos.cn>
Reviewed-by: Hamza Mahfooz <hamzamahfooz@linux.microsoft.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_vtl_main.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/hv/mshv_vtl_main.c b/drivers/hv/mshv_vtl_main.c
index c194007014678..3ce4b4d6c11eb 100644
--- a/drivers/hv/mshv_vtl_main.c
+++ b/drivers/hv/mshv_vtl_main.c
@@ -129,6 +129,7 @@ mshv_ioctl_create_vtl(void __user *user_arg, struct device *module_dev)
file = anon_inode_getfile("mshv_vtl", &mshv_vtl_fops,
vtl, O_RDWR);
if (IS_ERR(file)) {
+ put_unused_fd(fd);
kfree(vtl);
return PTR_ERR(file);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 042/438] Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 041/438] mshv_vtl: fix fd leak in mshv_ioctl_create_vtl() Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 043/438] mshv: Fix duplicate GSI detection for GSI 0 Greg Kroah-Hartman
` (409 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sebastian Andrzej Siewior,
Michael Kelley, Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
[ Upstream commit 8c7ab779c8850f4dab8473463cca9a7d52fdaecc ]
lockdep_hardirq_threaded() is supposed to be used within IRQ core code
and not within drivers. It is not obvious from within the driver, that
this is the only interrupt service routing and that it is not shared
handler.
Replace lockdep_hardirq_threaded() with a lockdep annotation limiting
threaded context on PREEMPT_RT to __vmbus_isr().
Fixes: f8e6343b7a89c ("Drivers: hv: vmbus: Use kthread for vmbus interrupts on PREEMPT_RT")
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Reviewed-by: Michael Kelley <mhklinux@outlook.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/vmbus_drv.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/drivers/hv/vmbus_drv.c b/drivers/hv/vmbus_drv.c
index 23206640c6139..44877664d9d08 100644
--- a/drivers/hv/vmbus_drv.c
+++ b/drivers/hv/vmbus_drv.c
@@ -1384,8 +1384,19 @@ void vmbus_isr(void)
if (IS_ENABLED(CONFIG_PREEMPT_RT)) {
vmbus_irqd_wake();
} else {
- lockdep_hardirq_threaded();
+ static DEFINE_WAIT_OVERRIDE_MAP(vmbus_map, LD_WAIT_CONFIG);
+
+ /*
+ * vmbus_isr is never force-threaded and always invoked at hard
+ * IRQ level. __vmbus_isr() below can acquire a spinlock_t
+ * which becomes a sleeping lock and must not be acquired in
+ * this context. Therefore on PREEMPT_RT this will be threaded
+ * via vmbus_irqd_wake(). On non-PREEMPT the annotation lets
+ * lockdep know that acquiring a spinlock_t is not an issue.
+ */
+ lock_map_acquire_try(&vmbus_map);
__vmbus_isr();
+ lock_map_release(&vmbus_map);
}
}
EXPORT_SYMBOL_FOR_MODULES(vmbus_isr, "mshv_vtl");
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 043/438] mshv: Fix duplicate GSI detection for GSI 0
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 042/438] Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation Greg Kroah-Hartman
@ 2026-08-07 14:33 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 044/438] mshv: Fix sleeping under spinlock in mshv_portid_alloc Greg Kroah-Hartman
` (408 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:33 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit 649dd135491945afa544351e3e6d4a727de87020 ]
The duplicate routing entry check in mshv_update_routing_table() uses
guest_irq_num != 0 to detect whether a GSI slot is already occupied.
This fails for GSI 0 because its guest_irq_num is 0 both when the slot
is unused (zero-initialized) and when legitimately assigned. As a
result, duplicate entries for GSI 0 are silently accepted, with the
second entry overwriting the first — corrupting the routing table
without any error reported to userspace.
While GSI 0 (legacy timer) is unlikely to appear in MSI-based routing
in practice, the check is semantically wrong — it conflates
"uninitialized" with "GSI number 0." Use girq_entry_valid instead,
which is explicitly set to true when an entry is populated and remains
zero for unused slots regardless of the GSI number.
Fixes: 621191d709b14 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_irq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hv/mshv_irq.c b/drivers/hv/mshv_irq.c
index b3142c84dcbc2..65a4ffc82d566 100644
--- a/drivers/hv/mshv_irq.c
+++ b/drivers/hv/mshv_irq.c
@@ -51,7 +51,7 @@ int mshv_update_routing_table(struct mshv_partition *partition,
/*
* Allow only one to one mapping between GSI and MSI routing.
*/
- if (girq->guest_irq_num != 0) {
+ if (girq->girq_entry_valid) {
r = -EINVAL;
goto out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 044/438] mshv: Fix sleeping under spinlock in mshv_portid_alloc
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-08-07 14:33 ` [PATCH 7.1 043/438] mshv: Fix duplicate GSI detection for GSI 0 Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 045/438] KVM: arm64: vgic: Fix race between LPI release and re-registration Greg Kroah-Hartman
` (407 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit a9708e550d11a53b22d932cdbfaa10c26346a2d0 ]
idr_alloc() is called with GFP_KERNEL inside idr_lock(), which holds a
spinlock. GFP_KERNEL allows the allocator to sleep, triggering a
sleeping-while-atomic bug.
Fix by using idr_preload(GFP_KERNEL) before taking the lock to
pre-allocate memory in a sleepable context, then idr_alloc() with
GFP_NOWAIT inside the spinlock-protected section.
Fixes: 621191d709b1 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_portid_table.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/hv/mshv_portid_table.c b/drivers/hv/mshv_portid_table.c
index c349af1f0aaac..6f59b3e376247 100644
--- a/drivers/hv/mshv_portid_table.c
+++ b/drivers/hv/mshv_portid_table.c
@@ -40,12 +40,14 @@ mshv_port_table_fini(void)
int
mshv_portid_alloc(struct port_table_info *info)
{
- int ret = 0;
+ int ret;
+ idr_preload(GFP_KERNEL);
idr_lock(&port_table_idr);
ret = idr_alloc(&port_table_idr, info, PORTID_MIN,
- PORTID_MAX, GFP_KERNEL);
+ PORTID_MAX, GFP_NOWAIT);
idr_unlock(&port_table_idr);
+ idr_preload_end();
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 045/438] KVM: arm64: vgic: Fix race between LPI release and re-registration
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 044/438] mshv: Fix sleeping under spinlock in mshv_portid_alloc Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 046/438] KVM: arm64: vgic: Mitigate potential LPI registration failure Greg Kroah-Hartman
` (406 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Carlos López, Marc Zyngier,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carlos López <clopez@suse.de>
[ Upstream commit cbfe2b24a1ea9de35032dbdd100fdc700f5be92d ]
Fix a potential race between decrementing an LPI's reference count and
evicting that structure from the LPI xarray.
LPI structures are maintained in the VGIC LPI xarray (dist->lpi_xa).
When the reference count of an LPI structure drops to zero,
vgic_release_lpi_locked() removes the structure from the xarray and
frees it under the xarray lock.
However, the release of an LPI can race with a concurrent LPI
re-registration with the same INTID via vgic_add_lpi() on another CPU,
since the reference count drop and the xarray eviction are not performed
in a single atomic step. This can happen e.g. if the guest issues a
DISCARD while the LPI is still referenced from a vCPU's active-pending
list (ap_list), and the same INTID is re-mapped via MAPTI.
Particularly, vgic_release_lpi_locked() is called from two distinct
paths: direct release via vgic_put_irq(), and deferred release via
vgic_release_deleted_lpis(). During direct release, the issue can result
in deleting a newly registered LPI from the xarray:
CPU0 (Releasing LPI) CPU1 (Adding new LPI)
==================== =====================
vgic_put_irq()
__vgic_put_irq()
refcount_dec_and_test()
vgic_add_lpi()
xa_lock_irqsave()
old_irq = xa_load(.., intid)
vgic_try_get_irq_ref(old_irq) == false
new IRQ inserted --> __xa_store(.., intid, ..)
xa_unlock_irqrestore()
xa_lock_irqsave();
vgic_release_lpi_locked()
__xa_erase(.., irq->intid) <-- BUG: new IRQ is erased
kfree_rcu(old_irq)
During the deferred release path, the old IRQ can be leaked:
CPU0 (Releasing LPI) CPU1 (Adding new LPI)
==================== =====================
vgic_put_irq_norelease()
__vgic_put_irq()
refcount_dec_and_test()
irq->pending_release = true
vgic_add_lpi()
xa_lock_irqsave()
old_irq = xa_load(.., intid)
vgic_try_get_irq_ref(oldirq) == false
BUG: old IRQ overwritten --> __xa_store(.., intid, ..)
xa_unlock_irqrestore()
vgic_release_deleted_lpis()
xa_lock_irqsave()
xa_for_each() { .. } <-- old IRQ with pending_release = true
is gone, so it cannot be released
To fix the direct release path, move the reference count drop inside
the xarray lock, making sure that vgic_add_lpi() never encounters the
to-be-released LPI.
In the deferred release path, the refcount drop must happen under a raw
spinlock, so the xarray lock cannot be grabbed, and the same solution
does not work. Instead, update vgic_add_lpi(), so that if it evicts
an LPI from the xarray, it takes on the responsibility of freeing it.
Consequently, an LPI may now be freed concurrently after a deferred
release drops the refcount, so accessing the pending_release field is no
longer safe from use-after-free. Delete all uses of the flag, and update
vgic_release_deleted_lpis() to identify orphaned LPIs purely based on
their refcount.
Reported-by: Claude:claude-opus-4-6
Fixes: 3a08a6ca7c37 ("KVM: arm64: vgic-v3: Use bare refcount for VGIC LPIs")
Fixes: d54594accf73 ("KVM: arm64: vgic-v3: Erase LPIs from xarray outside of raw spinlocks")
Signed-off-by: Carlos López <clopez@suse.de>
Link: https://patch.msgid.link/20260715105137.3973823-4-clopez@suse.de
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/vgic/vgic-its.c | 24 ++++++++++++++++--------
arch/arm64/kvm/vgic/vgic.c | 18 ++++++++----------
include/kvm/arm_vgic.h | 3 ---
3 files changed, 24 insertions(+), 21 deletions(-)
diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c
index 7abb685c65465..e9ef7686a9524 100644
--- a/arch/arm64/kvm/vgic/vgic-its.c
+++ b/arch/arm64/kvm/vgic/vgic-its.c
@@ -116,18 +116,26 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
kfree(irq);
irq = oldirq;
} else {
- ret = xa_err(__xa_store(&dist->lpi_xa, intid, irq, 0));
- }
-
- xa_unlock_irqrestore(&dist->lpi_xa, flags);
+ /*
+ * The entry is either empty or contains a dead LPI (refcount=0)
+ * from the deferred release path, pending cleanup by
+ * vgic_release_deleted_lpis(). Evict and free it if present.
+ */
+ oldirq = __xa_store(&dist->lpi_xa, intid, irq, 0);
+ ret = xa_err(oldirq);
+ if (ret) {
+ xa_unlock_irqrestore(&dist->lpi_xa, flags);
+ kfree(irq);
- if (ret) {
- xa_release(&dist->lpi_xa, intid);
- kfree(irq);
+ return ERR_PTR(ret);
+ }
- return ERR_PTR(ret);
+ if (oldirq && !WARN_ON_ONCE(refcount_read(&oldirq->refcount)))
+ kfree_rcu(oldirq, rcu);
}
+ xa_unlock_irqrestore(&dist->lpi_xa, flags);
+
/*
* We "cache" the configuration table entries in our struct vgic_irq's.
* However we only have those structs for mapped IRQs, so we read in
diff --git a/arch/arm64/kvm/vgic/vgic.c b/arch/arm64/kvm/vgic/vgic.c
index 4cd818ce90933..7fb9057fdd7ee 100644
--- a/arch/arm64/kvm/vgic/vgic.c
+++ b/arch/arm64/kvm/vgic/vgic.c
@@ -147,11 +147,7 @@ static __must_check bool __vgic_put_irq(struct kvm *kvm, struct vgic_irq *irq)
static __must_check bool vgic_put_irq_norelease(struct kvm *kvm, struct vgic_irq *irq)
{
- if (!__vgic_put_irq(kvm, irq))
- return false;
-
- irq->pending_release = true;
- return true;
+ return __vgic_put_irq(kvm, irq);
}
void vgic_put_irq(struct kvm *kvm, struct vgic_irq *irq)
@@ -168,12 +164,14 @@ void vgic_put_irq(struct kvm *kvm, struct vgic_irq *irq)
guard(spinlock_irqsave)(&dist->lpi_xa.xa_lock);
}
- if (!__vgic_put_irq(kvm, irq))
+ if (!irq_is_lpi(kvm, irq->intid))
return;
- xa_lock_irqsave(&dist->lpi_xa, flags);
- vgic_release_lpi_locked(dist, irq);
- xa_unlock_irqrestore(&dist->lpi_xa, flags);
+ if (refcount_dec_and_lock_irqsave(&irq->refcount,
+ &dist->lpi_xa.xa_lock, &flags)) {
+ vgic_release_lpi_locked(dist, irq);
+ xa_unlock_irqrestore(&dist->lpi_xa, flags);
+ }
}
static void vgic_release_deleted_lpis(struct kvm *kvm)
@@ -185,7 +183,7 @@ static void vgic_release_deleted_lpis(struct kvm *kvm)
xa_lock_irqsave(&dist->lpi_xa, flags);
xa_for_each(&dist->lpi_xa, intid, irq) {
- if (irq->pending_release)
+ if (!refcount_read(&irq->refcount))
vgic_release_lpi_locked(dist, irq);
}
diff --git a/include/kvm/arm_vgic.h b/include/kvm/arm_vgic.h
index 1388dc6028a9a..700d6c519d133 100644
--- a/include/kvm/arm_vgic.h
+++ b/include/kvm/arm_vgic.h
@@ -242,9 +242,6 @@ struct vgic_irq {
* affinity reg (v3).
*/
- bool pending_release:1; /* Used for LPIs only, unreferenced IRQ
- * pending a release */
-
bool pending_latch:1; /* The pending latch state used to calculate
* the pending state for both level
* and edge triggered IRQs. */
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 046/438] KVM: arm64: vgic: Mitigate potential LPI registration failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 045/438] KVM: arm64: vgic: Fix race between LPI release and re-registration Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 047/438] KVM: arm64: Fix hyp_trace clock disabling Greg Kroah-Hartman
` (405 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Carlos López,
Marc Zyngier, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carlos López <clopez@suse.de>
[ Upstream commit 21f12496fdd357ad4e1fcdd07dc80ab7378f7d24 ]
Mitigate a potential failure when inserting a new LPI into the VGIC LPI
xarray.
When vgic_add_lpi() is preparing to register a new LPI, it pre-allocates
an xarray entry using xa_reserve_irq(), so that it can later perform the
insertion under the xarray lock without allocating.
However, since xa_reserve_irq() is called before acquiring such lock,
there is a potential race where xa_reserve_irq() observes a populated
entry, thus not performing the allocation, and another CPU removes that
entry before the xarray lock is grabbed to perform the insertion.
CPU0 (Adding new LPI) CPU1 (Releasing LPI)
===================== ===================
vgic_add_lpi()
/* Entry populated, does not allocate */
xa_reserve_irq(.., intid, ..)
vgic_release_deleted_lpis()
xa_lock_irqsave()
vgic_release_lpi_locked()
xarray node freed --> __xa_erase(.., intid)
xa_unlock_irqrestore()
xa_lock_irqsave()
xa_load(.., intid) == NULL
vgic_try_get_irq_ref(NULL) == false
__xa_store(.., intid, irq, 0) <-- xarray node was freed, gfp=0
cannot allocate, returns -ENOMEM
This can happen e.g. if the guest issues a DISCARD while the LPI is
still referenced from a vCPU's active-pending list (ap_list), and the
same INTID is re-mapped via MAPTI.
Mitigate this by passing GFP_NOWAIT to __xa_store(), so that the
allocation can happen under the lock in the rare case that this
condition is hit. Add __GFP_ACCOUNT as well to match xa_reserve_irq()'s
flags.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 1d6f83f60f79 ("KVM: arm64: vgic: Store LPIs in an xarray")
Signed-off-by: Carlos López <clopez@suse.de>
Link: https://patch.msgid.link/20260715105137.3973823-5-clopez@suse.de
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/vgic/vgic-its.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c
index e9ef7686a9524..c15f1867adc20 100644
--- a/arch/arm64/kvm/vgic/vgic-its.c
+++ b/arch/arm64/kvm/vgic/vgic-its.c
@@ -121,7 +121,8 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
* from the deferred release path, pending cleanup by
* vgic_release_deleted_lpis(). Evict and free it if present.
*/
- oldirq = __xa_store(&dist->lpi_xa, intid, irq, 0);
+ oldirq = __xa_store(&dist->lpi_xa, intid, irq,
+ GFP_NOWAIT | __GFP_ACCOUNT);
ret = xa_err(oldirq);
if (ret) {
xa_unlock_irqrestore(&dist->lpi_xa, flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 047/438] KVM: arm64: Fix hyp_trace clock disabling
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 046/438] KVM: arm64: vgic: Mitigate potential LPI registration failure Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 048/438] KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing Greg Kroah-Hartman
` (404 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vincent Donnefort, Marc Zyngier,
Sasha Levin, Fuad Tabba
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Donnefort <vdonnefort@google.com>
[ Upstream commit bbece712cfc7f286b2908ac120dcf700279d87eb ]
Fix the disable path in hyp_trace_clock_enable(), which fell through to
re-initialize and reschedule the clock after cancelling the work. Return
early instead.
While at it, cleanup hyp_trace_clock::lock which is unused and
hyp_trace_clock::running which is redundant: the trace_remote framework
already serializes calls to the callback enable_tracing.
Fixes: b22888917fa4 ("KVM: arm64: Sync boot clock with the nVHE/pKVM hyp")
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Reviewed-by: Fuad Tabba <fuad.tabba@linux.dev> (✓ DKIM/linux.dev)
Link: https://patch.msgid.link/20260715105100.3178255-1-vdonnefort@google.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp_trace.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/arm64/kvm/hyp_trace.c b/arch/arm64/kvm/hyp_trace.c
index c4b3ee5521313..ac6a2db317323 100644
--- a/arch/arm64/kvm/hyp_trace.c
+++ b/arch/arm64/kvm/hyp_trace.c
@@ -37,8 +37,6 @@ static struct hyp_trace_clock {
u32 shift;
struct delayed_work work;
struct completion ready;
- struct mutex lock;
- bool running;
} hyp_clock;
static void __hyp_clock_work(struct work_struct *work)
@@ -110,12 +108,9 @@ static void hyp_trace_clock_enable(struct hyp_trace_clock *hyp_clock, bool enabl
{
struct system_time_snapshot snap;
- if (hyp_clock->running == enable)
- return;
-
if (!enable) {
cancel_delayed_work_sync(&hyp_clock->work);
- hyp_clock->running = false;
+ return;
}
ktime_get_snapshot(&snap);
@@ -128,7 +123,6 @@ static void hyp_trace_clock_enable(struct hyp_trace_clock *hyp_clock, bool enabl
INIT_DELAYED_WORK(&hyp_clock->work, __hyp_clock_work);
schedule_delayed_work(&hyp_clock->work, msecs_to_jiffies(CLOCK_INIT_MS));
wait_for_completion(&hyp_clock->ready);
- hyp_clock->running = true;
}
/* Access to this struct within the trace_remote_callbacks are protected by the trace_remote lock */
@@ -304,9 +298,15 @@ static void hyp_trace_unload(struct trace_buffer_desc *desc, void *priv)
static int hyp_trace_enable_tracing(bool enable, void *priv)
{
+ int ret;
+
hyp_trace_clock_enable(&hyp_clock, enable);
- return kvm_call_hyp_nvhe(__tracing_enable, enable);
+ ret = kvm_call_hyp_nvhe(__tracing_enable, enable);
+ if (ret)
+ hyp_trace_clock_enable(&hyp_clock, !enable);
+
+ return ret;
}
static int hyp_trace_swap_reader_page(unsigned int cpu, void *priv)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 048/438] KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 047/438] KVM: arm64: Fix hyp_trace clock disabling Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 049/438] KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load() Greg Kroah-Hartman
` (403 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Fuad Tabba,
Vincent Donnefort, Marc Zyngier, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Donnefort <vdonnefort@google.com>
[ Upstream commit df7a9d376f7a388ecfacf8dfe0b5819ddfba6972 ]
In the very unlikely event of a failure in __map_hyp, the allocated
backing pages are leaked in hyp_trace_buffer_alloc_bpages_backing(). Fix
this by freeing the pages on error.
Fixes: 3aed038aac8d ("KVM: arm64: Add trace remote for the nVHE/pKVM hyp")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Reviewed-by: Fuad Tabba <fuad.tabba@linux.dev>
Tested-by: Fuad Tabba <fuad.tabba@linux.dev>
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Link: https://patch.msgid.link/20260710114819.2689386-2-vdonnefort@google.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp_trace.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/hyp_trace.c b/arch/arm64/kvm/hyp_trace.c
index ac6a2db317323..73c1731392c74 100644
--- a/arch/arm64/kvm/hyp_trace.c
+++ b/arch/arm64/kvm/hyp_trace.c
@@ -154,6 +154,7 @@ static int hyp_trace_buffer_alloc_bpages_backing(struct hyp_trace_buffer *trace_
int nr_bpages = (PAGE_ALIGN(size) / PAGE_SIZE) + 1;
size_t backing_size;
void *start;
+ int ret;
backing_size = PAGE_ALIGN(sizeof(struct simple_buffer_page) * nr_bpages *
num_possible_cpus());
@@ -162,10 +163,16 @@ static int hyp_trace_buffer_alloc_bpages_backing(struct hyp_trace_buffer *trace_
if (!start)
return -ENOMEM;
+ ret = __map_hyp(start, backing_size);
+ if (ret) {
+ free_pages_exact(start, backing_size);
+ return ret;
+ }
+
trace_buffer->desc->bpages_backing_start = (unsigned long)start;
trace_buffer->desc->bpages_backing_size = backing_size;
- return __map_hyp(start, backing_size);
+ return ret;
}
static void hyp_trace_buffer_free_bpages_backing(struct hyp_trace_buffer *trace_buffer)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 049/438] KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 048/438] KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 050/438] KVM: arm64: Add missing hyp_enter when trapping sysreg Greg Kroah-Hartman
` (402 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Vincent Donnefort,
Fuad Tabba, Marc Zyngier, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Donnefort <vdonnefort@google.com>
[ Upstream commit ca28278d10ec234592989ad370d58294b9d43e0f ]
The footprint calculated for struct hyp_trace_desc sizes only
trace_buffer_desc and do not take into account the other fields. It
worked so far thanks to the follow-up PAGE_ALIGN().
Fix the descriptor size and while at it, enforce an overflow check after
PAGE_ALIGN().
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 3aed038aac8d ("KVM: arm64: Add trace remote for the nVHE/pKVM hyp")
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Reviewed-by: Fuad Tabba <fuad.tabba@linux.dev>
Tested-by: Fuad Tabba <fuad.tabba@linux.dev>
Link: https://patch.msgid.link/20260710114819.2689386-3-vdonnefort@google.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp_trace.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/arch/arm64/kvm/hyp_trace.c b/arch/arm64/kvm/hyp_trace.c
index 73c1731392c74..3f4ba2034a155 100644
--- a/arch/arm64/kvm/hyp_trace.c
+++ b/arch/arm64/kvm/hyp_trace.c
@@ -229,18 +229,22 @@ static int hyp_trace_buffer_share_hyp(struct hyp_trace_buffer *trace_buffer)
static struct trace_buffer_desc *hyp_trace_load(unsigned long size, void *priv)
{
struct hyp_trace_buffer *trace_buffer = priv;
+ size_t desc_size, tb_desc_size;
struct hyp_trace_desc *desc;
- size_t desc_size;
int ret;
if (WARN_ON(trace_buffer->desc))
return ERR_PTR(-EINVAL);
- desc_size = trace_buffer_desc_size(size, num_possible_cpus());
+ tb_desc_size = trace_buffer_desc_size(size, num_possible_cpus());
+ desc_size = size_add(tb_desc_size, offsetof(struct hyp_trace_desc, trace_buffer_desc));
if (desc_size == SIZE_MAX)
return ERR_PTR(-E2BIG);
desc_size = PAGE_ALIGN(desc_size);
+ if (!desc_size)
+ return ERR_PTR(-E2BIG);
+
desc = (struct hyp_trace_desc *)alloc_pages_exact(desc_size, GFP_KERNEL);
if (!desc)
return ERR_PTR(-ENOMEM);
@@ -256,7 +260,7 @@ static struct trace_buffer_desc *hyp_trace_load(unsigned long size, void *priv)
if (ret)
goto err_free_desc;
- ret = trace_remote_alloc_buffer(&desc->trace_buffer_desc, desc_size, size,
+ ret = trace_remote_alloc_buffer(&desc->trace_buffer_desc, tb_desc_size, size,
cpu_possible_mask);
if (ret)
goto err_free_backing;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 050/438] KVM: arm64: Add missing hyp_enter when trapping sysreg
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 049/438] KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 051/438] KVM: arm64: Reject guest_memfd memslots when the VM has MTE Greg Kroah-Hartman
` (401 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vincent Donnefort, Fuad Tabba,
Marc Zyngier, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Donnefort <vdonnefort@google.com>
[ Upstream commit e7821048e8d72a94b1fb7422f8b45aa374ff076f ]
Add a missing hypervisor event call for hyp_enter on sysreg trapping,
causing an unbalanced hyp_enter/hyp_exit.
The enum hyp_enter_exit_reason is not ABI, so we can keep the ERET
reasons at the end for clarity.
Fixes: 696dfec22b8e ("KVM: arm64: Add hyp_enter/hyp_exit events to nVHE/pKVM hyp")
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Reviewed-by: Fuad Tabba <tabba@google.com>
Tested-by: Fuad Tabba <tabba@google.com>
Link: https://patch.msgid.link/20260617095238.1530121-1-vdonnefort@google.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/include/asm/kvm_hypevents.h | 1 +
arch/arm64/kvm/hyp/nvhe/hyp-main.c | 1 +
arch/arm64/kvm/hyp_trace.c | 1 +
3 files changed, 3 insertions(+)
diff --git a/arch/arm64/include/asm/kvm_hypevents.h b/arch/arm64/include/asm/kvm_hypevents.h
index 743c49bd878f7..5f6e6789d1211 100644
--- a/arch/arm64/include/asm/kvm_hypevents.h
+++ b/arch/arm64/include/asm/kvm_hypevents.h
@@ -12,6 +12,7 @@
enum hyp_enter_exit_reason {
HYP_REASON_SMC,
HYP_REASON_HVC,
+ HYP_REASON_SYS,
HYP_REASON_PSCI,
HYP_REASON_HOST_ABORT,
HYP_REASON_GUEST_EXIT,
diff --git a/arch/arm64/kvm/hyp/nvhe/hyp-main.c b/arch/arm64/kvm/hyp/nvhe/hyp-main.c
index a0da08caa6c27..4cd321c27d042 100644
--- a/arch/arm64/kvm/hyp/nvhe/hyp-main.c
+++ b/arch/arm64/kvm/hyp/nvhe/hyp-main.c
@@ -925,6 +925,7 @@ void handle_trap(struct kvm_cpu_context *host_ctxt)
handle_host_mem_abort(host_ctxt);
break;
case ESR_ELx_EC_SYS64:
+ trace_hyp_enter(host_ctxt, HYP_REASON_SYS);
if (handle_host_mte(esr))
break;
fallthrough;
diff --git a/arch/arm64/kvm/hyp_trace.c b/arch/arm64/kvm/hyp_trace.c
index 3f4ba2034a155..210807edacf7f 100644
--- a/arch/arm64/kvm/hyp_trace.c
+++ b/arch/arm64/kvm/hyp_trace.c
@@ -409,6 +409,7 @@ static const char *__hyp_enter_exit_reason_str(u8 reason)
static const char strs[][12] = {
"smc",
"hvc",
+ "sys",
"psci",
"host_abort",
"guest_exit",
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 051/438] KVM: arm64: Reject guest_memfd memslots when the VM has MTE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 050/438] KVM: arm64: Add missing hyp_enter when trapping sysreg Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 052/438] KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type Greg Kroah-Hartman
` (400 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Alexandru Elisei,
Marc Zyngier, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexandru Elisei <alexandru.elisei@arm.com>
[ Upstream commit 679d7201c1f09e37fa1c12ce28d84079c17fc87f ]
The user cannot use MTE on VMAs created by mapping a guest_memfd file,
as arch_calc_vm_flag_bits() does not set VM_MTE_ALLOWED.
When creating a guest_memfd backed memslot,
kvm_arch_prepare_memory_region() rejects the memslot if MTE is enabled for
the VM and if guest_memfd has been mapped in a VMA that intersects the
memslot.
However, the documentation for KVM_SET_USER_MEMORY_REGION2 explicitly
states that the only condition for userspace_addr is for it to be a legal
userspace address, but the mapping is not required to be valid nor
populated at memslot creation.
If userspace sets userspace_addr to an address that hasn't been mapped, or
if userspace_addr belongs to a VMA that isn't backed by the guest_memfd
file, or if the VMA doesn't intersect the memslot, memslot creation is
successful and KVM ends up with a VM with MTE and guest_memfd-backed
memslots.
The same happens if the order is reversed: when userspace enables MTE, KVM
does not check if memslots backed by guest_memfd are already present.
Fix both issues by rejecting guest_memfd-backed memslots when MTE is
enabled, and by rejecting MTE when guest_memfd-backed memslots are already
present.
Fixes: 32e200bd6e44 ("KVM: arm64: Enable support for guest_memfd backed memory")
Tested-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Fuad Tabba <fuad.tabba@linux.dev>
Signed-off-by: Alexandru Elisei <alexandru.elisei@arm.com>
Link: https://patch.msgid.link/20260722090354.94245-1-alexandru.elisei@arm.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/virt/kvm/api.rst | 6 ++++++
arch/arm64/kvm/arm.c | 25 +++++++++++++++++++------
arch/arm64/kvm/mmu.c | 4 ++++
3 files changed, 29 insertions(+), 6 deletions(-)
diff --git a/Documentation/virt/kvm/api.rst b/Documentation/virt/kvm/api.rst
index 52bbbb553ce10..934ec29093e36 100644
--- a/Documentation/virt/kvm/api.rst
+++ b/Documentation/virt/kvm/api.rst
@@ -8401,6 +8401,12 @@ When this capability is enabled all memory in memslots must be mapped as
attempts to create a memslot with an invalid mmap will result in an
-EINVAL return.
+``guest_memfd``, even though it is an anonymous file, is not supported with MTE.
+Attempting to create a memslot backed by ``guest_memfd`` when the MTE capability
+is enabled, or attempting to enable the MTE capability after
+``guest_memfd``-backed memslots have been created, will result in an -EINVAL
+return.
+
When enabled the VMM may make use of the ``KVM_ARM_MTE_COPY_TAGS`` ioctl to
perform a bulk copy of tags to/from the guest.
diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index 9ffd5d4079e6c..00df8783c30df 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -148,14 +148,27 @@ int kvm_vm_ioctl_enable_cap(struct kvm *kvm,
set_bit(KVM_ARCH_FLAG_RETURN_NISV_IO_ABORT_TO_USER,
&kvm->arch.flags);
break;
- case KVM_CAP_ARM_MTE:
- mutex_lock(&kvm->lock);
- if (system_supports_mte() && !kvm->created_vcpus) {
- r = 0;
- set_bit(KVM_ARCH_FLAG_MTE_ENABLED, &kvm->arch.flags);
+ case KVM_CAP_ARM_MTE: {
+ struct kvm_memory_slot *memslot;
+ int bkt;
+
+ guard(mutex)(&kvm->lock);
+ if (!system_supports_mte() || kvm->created_vcpus)
+ break;
+
+ r = 0;
+ guard(mutex)(&kvm->slots_lock);
+ kvm_for_each_memslot(memslot, bkt, kvm_memslots(kvm)) {
+ if (kvm_slot_has_gmem(memslot)) {
+ r = -EINVAL;
+ break;
+ }
}
- mutex_unlock(&kvm->lock);
+ if (r == 0)
+ set_bit(KVM_ARCH_FLAG_MTE_ENABLED, &kvm->arch.flags);
break;
+
+ }
case KVM_CAP_ARM_SYSTEM_SUSPEND:
r = 0;
set_bit(KVM_ARCH_FLAG_SYSTEM_SUSPEND_ENABLED, &kvm->arch.flags);
diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c
index 6e95514d5a76e..726827c85c732 100644
--- a/arch/arm64/kvm/mmu.c
+++ b/arch/arm64/kvm/mmu.c
@@ -2625,6 +2625,10 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
if (kvm_slot_has_gmem(new) && !kvm_memslot_is_gmem_only(new))
return -EINVAL;
+ /* guest_memfd is incompatible with MTE. */
+ if (kvm_slot_has_gmem(new) && kvm_has_mte(kvm))
+ return -EINVAL;
+
hva = new->userspace_addr;
reg_end = hva + (new->npages << PAGE_SHIFT);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 052/438] KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 051/438] KVM: arm64: Reject guest_memfd memslots when the VM has MTE Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 053/438] keys: fix out-of-bounds read in keyring_get_key_chunk() Greg Kroah-Hartman
` (399 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fabrice Derepas, David Gstir,
Richard Weinberger, Jarkko Sakkinen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fabrice Derepas <fabrice.derepas@canonical.com>
[ Upstream commit 35d661c98fe4733490f20b4311616a3c2c30abc0 ]
Two correctness and type-hygiene issues exist in the DCP trusted keys
implementation.
First, trusted_dcp_unseal() reads p->key_len from a user-supplied blob
without checking if it exceeds MAX_KEY_SIZE. If a crafted blob provides a
payload_len larger than 128, the subsequent do_aead_crypto() call writes
past the end of the p->key array into the adjacent p->blob buffer within
the same struct trusted_key_payload -- the caller's own input, not
unrelated kernel memory. While not exploitable, this violates strict array
bounds and triggers static analyzers. Fix this by adding a validation
check against MIN_KEY_SIZE and MAX_KEY_SIZE immediately after reading the
length, matching the checks already done in trusted_core.c.
Second, calc_blob_len() calculates a sum in size_t that truncates to
unsigned int on 64-bit platforms. Because the DCP hardware is only present
on 32-bit i.MX SoC platforms, size_t and unsigned int are functionally
equivalent in production, making this truncation harmless in practice.
Nevertheless, updating the return type to size_t (and subsequently updating
'blen' in the seal/unseal paths) resolves type-narrowing warnings and
improves overall code hygiene.
Fixes: 2e8a0f40a39c ("KEYS: trusted: Introduce NXP DCP-backed trusted keys")
Signed-off-by: Fabrice Derepas <fabrice.derepas@canonical.com>
Reviewed-by: David Gstir <david@sigma-star.at>
Reviewed-by: Richard Weinberger <richard@nod.at>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260719163939.3624767-1-fabrice.derepas@canonical.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/trusted-keys/trusted_dcp.c | 15 +++++++++++----
1 file changed, 11 insertions(+), 4 deletions(-)
diff --git a/security/keys/trusted-keys/trusted_dcp.c b/security/keys/trusted-keys/trusted_dcp.c
index 7b6eb655df0cb..c078adebe190e 100644
--- a/security/keys/trusted-keys/trusted_dcp.c
+++ b/security/keys/trusted-keys/trusted_dcp.c
@@ -69,7 +69,7 @@ static bool skip_zk_test;
module_param_named(dcp_skip_zk_test, skip_zk_test, bool, 0);
MODULE_PARM_DESC(dcp_skip_zk_test, "Don't test whether device keys are zero'ed");
-static unsigned int calc_blob_len(unsigned int payload_len)
+static size_t calc_blob_len(unsigned int payload_len)
{
return sizeof(struct dcp_blob_fmt) + payload_len + DCP_BLOB_AUTHLEN;
}
@@ -200,7 +200,8 @@ static int encrypt_blob_key(u8 *plain_key, u8 *encrypted_key)
static int trusted_dcp_seal(struct trusted_key_payload *p, char *datablob)
{
struct dcp_blob_fmt *b = (struct dcp_blob_fmt *)p->blob;
- int blen, ret;
+ size_t blen;
+ int ret;
u8 *plain_blob_key;
blen = calc_blob_len(p->key_len);
@@ -242,7 +243,8 @@ static int trusted_dcp_seal(struct trusted_key_payload *p, char *datablob)
static int trusted_dcp_unseal(struct trusted_key_payload *p, char *datablob)
{
struct dcp_blob_fmt *b = (struct dcp_blob_fmt *)p->blob;
- int blen, ret;
+ size_t blen;
+ int ret;
u8 *plain_blob_key = NULL;
if (b->fmt_version != DCP_BLOB_VERSION) {
@@ -253,9 +255,14 @@ static int trusted_dcp_unseal(struct trusted_key_payload *p, char *datablob)
}
p->key_len = le32_to_cpu(b->payload_len);
+ if (p->key_len < MIN_KEY_SIZE || p->key_len > MAX_KEY_SIZE) {
+ ret = -EINVAL;
+ goto out;
+ }
+
blen = calc_blob_len(p->key_len);
if (blen != p->blob_len) {
- pr_err("DCP blob has bad length: %i != %i\n", blen,
+ pr_err("DCP blob has bad length: %zu != %u\n", blen,
p->blob_len);
ret = -EINVAL;
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 053/438] keys: fix out-of-bounds read in keyring_get_key_chunk()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 052/438] KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 054/438] keys: make keyring key-chunk byte order agree with keyring_diff_objects() Greg Kroah-Hartman
` (398 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Jarkko Sakkinen,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 63918731f9ae25b5deb022f118e941e6dddfcef4 ]
For description-level chunks keyring_get_key_chunk() advances the read
pointer by level * sizeof(long) past the inline prefix but only
bounds-checks the prefix, so a long enough key description is read past
its kmemdup(desc, desc_len + 1) allocation. Compute the full byte
offset and bounds-check the description against it before reading.
The walk only reaches a description-level chunk when two keys collide
through the hash, x, type and domain_tag chunks, so this is reached from
an unprivileged add_key(2) with a crafted pair of same-type keys whose
index hashes collide; KASAN reports a slab-out-of-bounds read.
Fixes: f771fde82051 ("keys: Simplify key description management")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260719161505.2423935-2-michael.bommarito@gmail.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/keyring.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/security/keys/keyring.c b/security/keys/keyring.c
index 7a2ee0ded7c93..085f7a743354c 100644
--- a/security/keys/keyring.c
+++ b/security/keys/keyring.c
@@ -271,6 +271,7 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
unsigned long chunk = 0;
const u8 *d;
int desc_len = index_key->desc_len, n = sizeof(chunk);
+ unsigned int offset;
level /= ASSOC_ARRAY_KEY_CHUNK_SIZE;
switch (level) {
@@ -284,12 +285,12 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
return (unsigned long)index_key->domain_tag;
default:
level -= 4;
- if (desc_len <= sizeof(index_key->desc))
+ offset = sizeof(index_key->desc) + level * sizeof(long);
+ if (desc_len <= offset)
return 0;
- d = index_key->description + sizeof(index_key->desc);
- d += level * sizeof(long);
- desc_len -= sizeof(index_key->desc);
+ d = index_key->description + offset;
+ desc_len -= offset;
if (desc_len > n)
desc_len = n;
do {
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 054/438] keys: make keyring key-chunk byte order agree with keyring_diff_objects()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 053/438] keys: fix out-of-bounds read in keyring_get_key_chunk() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 055/438] assoc_array: trim the final shortcut word using the current chunk end Greg Kroah-Hartman
` (397 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Jarkko Sakkinen,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 58565eef0f8d861aae92abfb7658458d661cee17 ]
keyring_get_key_chunk() loads description bytes into the index chunk low
address first, while keyring_diff_objects() numbers the first differing
bit from the low end and folds the absolute byte index into the level
without removing the inline-prefix offset the level already carries.
The two disagree on byte order and bit position, so the array can be
told two keys first differ at a bit that does not differ in the chunk
the walker uses, letting crafted descriptions collide into one node.
Load the chunk in the order keyring_diff_objects() assumes and drop the
inline-prefix length when folding the byte index into the level. This
only changes the in-memory ordering used to place keys within a keyring;
add, search and read of non-colliding keys are unaffected.
Fixes: f771fde82051 ("keys: Simplify key description management")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260719161505.2423935-3-michael.bommarito@gmail.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/keyring.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/security/keys/keyring.c b/security/keys/keyring.c
index 085f7a743354c..15bf4af8f2821 100644
--- a/security/keys/keyring.c
+++ b/security/keys/keyring.c
@@ -293,9 +293,10 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
desc_len -= offset;
if (desc_len > n)
desc_len = n;
+ d += desc_len;
do {
chunk <<= 8;
- chunk |= *d++;
+ chunk |= *--d;
} while (--desc_len > 0);
return chunk;
}
@@ -376,7 +377,7 @@ static int keyring_diff_objects(const void *object, const void *data)
return -1;
differ_plus_i:
- level += i;
+ level += i - (int)sizeof(a->desc);
differ:
i = level * 8 + __ffs(seg_a ^ seg_b);
return i;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 055/438] assoc_array: trim the final shortcut word using the current chunk end
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 054/438] keys: make keyring key-chunk byte order agree with keyring_diff_objects() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 056/438] ipvs: adjust double hashing when fwd method changes Greg Kroah-Hartman
` (396 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Jarkko Sakkinen,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit a82c8a05e86f3f84e09698f65b4515b5d04633f6 ]
assoc_array_walk() masks off the bits past shortcut->skip_to_level in the
word that contains skip_to_level, gated on
round_up(sc_level, ASSOC_ARRAY_KEY_CHUNK_SIZE) > skip_to_level.
That guard is wrong in two opposite ways:
- When sc_level is word-aligned (every word after the first) round_up()
is a no-op, so the guard is sc_level > skip_to_level and never fires for
the word that holds skip_to_level. A shortcut that spans more than one
word and ends in the middle of its last word leaves that word untrimmed,
and its stale high bits leak into the dissimilarity word and can steer
the walk down the wrong descendant.
- When sc_level is unaligned (the first word) and skip_to_level sits on
the next chunk boundary, sc_level + CHUNK would exceed skip_to_level and
fire the trim with shift = skip_to_level & CHUNK_MASK == 0, which clears
the whole dissimilarity word and makes a differing shortcut compare
equal.
Use the end of the chunk that contains sc_level instead:
skip_to_level < round_down(sc_level, CHUNK) + CHUNK
For an aligned sc_level whose word holds skip_to_level this now fires (the
first bug); for an unaligned sc_level with skip_to_level on the following
boundary it does not, so shift is never 0 when the branch runs and the trim
never clears the whole word.
Fixes: 3cb989501c26 ("Add a generic associative array implementation.")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260719161505.2423935-4-michael.bommarito@gmail.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
lib/assoc_array.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/lib/assoc_array.c b/lib/assoc_array.c
index bcc6e0a013eb8..b6c9723e12ced 100644
--- a/lib/assoc_array.c
+++ b/lib/assoc_array.c
@@ -255,7 +255,8 @@ assoc_array_walk(const struct assoc_array *array,
sc_segments = shortcut->index_key[sc_level >> ASSOC_ARRAY_KEY_CHUNK_SHIFT];
dissimilarity = segments ^ sc_segments;
- if (round_up(sc_level, ASSOC_ARRAY_KEY_CHUNK_SIZE) > shortcut->skip_to_level) {
+ if (shortcut->skip_to_level < round_down(sc_level,
+ ASSOC_ARRAY_KEY_CHUNK_SIZE) + ASSOC_ARRAY_KEY_CHUNK_SIZE) {
/* Trim segments that are beyond the shortcut */
int shift = shortcut->skip_to_level & ASSOC_ARRAY_KEY_CHUNK_MASK;
dissimilarity &= ~(ULONG_MAX << shift);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 056/438] ipvs: adjust double hashing when fwd method changes
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 055/438] assoc_array: trim the final shortcut word using the current chunk end Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 057/438] netfilter: nf_tables: make nft_object rhltable per table Greg Kroah-Hartman
` (395 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhiling Zou, Julian Anastasov,
Pablo Neira Ayuso, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit 712d2993bea555f1f09cd53cbdb25714f28e85db ]
Synced conns can be created with one forwarding method
and later updated with different one after the dest
server is configured. This needs adjusting the hashing
for node hn1 because only MASQ supports double hashing.
Modify conn_tab_lock() to support seeking for hash node
hn0 together with adding for hn1. By this way we can
safely modify the forwarding method and hn1.hash_key
under bucket lock for the first node hn0. The forwarding
method is also protected by cp->lock as it is part of
cp->flags.
Fix the usage of stale idx/idx2 values in conn_tab_lock
after jumping to the retry label. Instead, use idx/idx2
values just to order the locking for the old/new tables.
Reported-by: Zhiling Zou <roxy520tt@gmail.com>
Link: https://patch.msgid.link/1b914f41d725bc064c9ba9830dc8169329737270.1782540466.git.roxy520tt@gmail.com/
Link: https://sashiko.dev/#/patchset/CALMqdkR704S2BG_QD_bgHTFp2%2B1QCi7n0T4zoZyTo8mDZevYSA%40mail.gmail.com
Fixes: f20c73b0460d ("ipvs: use more keys for connection hashing")
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/ipvs/ip_vs_conn.c | 189 +++++++++++++++++++++++++-------
1 file changed, 147 insertions(+), 42 deletions(-)
diff --git a/net/netfilter/ipvs/ip_vs_conn.c b/net/netfilter/ipvs/ip_vs_conn.c
index b457dd2f6bc89..26f2233b34b04 100644
--- a/net/netfilter/ipvs/ip_vs_conn.c
+++ b/net/netfilter/ipvs/ip_vs_conn.c
@@ -70,25 +70,45 @@ static struct kmem_cache *ip_vs_conn_cachep __read_mostly;
* bucket or hash table
* - hash table resize works like rehash but always rehashes into new table
* - bit lock on bucket serializes all operations that modify the chain
+ * - on resize, bucket from the old table is locked before bucket from the
+ * new table
* - cp->lock protects conn fields like cp->flags, cp->dest
*/
-/* Lock conn_tab bucket for conn hash/unhash, not for rehash */
+/**
+ * conn_tab_lock - Lock conn_tab buckets for conn hash/unhash, not for rehash
+ * @t: hash table for hn0, new_tbl when new_hash=true
+ * @t2: hash table for hn1, new_tbl when new_hash2=true
+ * @cp: connection
+ * @hash_key: hash key for hn0
+ * @hash_key2: hash key for hn1
+ * @use2: using hn1 (double hashing) based on the forwarding method
+ * @new_hash: mode for hn0, hash node (true) or seek node (false)
+ * @new_hash2: mode for hn1, hash node (true) or seek node (false)
+ * @head_ret: returned head for hn0
+ * @head2_ret: returned head for hn1
+ *
+ * We support 3 modes:
+ * - seek mode for both nodes, used for unhashing
+ * - hash mode for both nodes, used for hashing
+ * - seek hn0 and hash hn1, used when forwarding method is changed
+ */
static __always_inline void
-conn_tab_lock(struct ip_vs_rht *t, struct ip_vs_conn *cp, u32 hash_key,
- u32 hash_key2, bool use2, bool new_hash,
- struct hlist_bl_head **head_ret, struct hlist_bl_head **head2_ret)
+conn_tab_lock(struct ip_vs_rht *t, struct ip_vs_rht *t2, struct ip_vs_conn *cp,
+ u32 hash_key, u32 hash_key2, bool use2, bool new_hash,
+ bool new_hash2, struct hlist_bl_head **head_ret,
+ struct hlist_bl_head **head2_ret)
{
struct hlist_bl_head *head, *head2;
u32 hash_key_new, hash_key_new2;
- struct ip_vs_rht *t2 = t;
- u32 idx, idx2;
+ int idx = 0, idx2 = 0;
+
+ /* Advance idx2 when new_hash is not set but hash_key2
+ * is for new table
+ */
+ if (new_hash2 && use2 && t != t2)
+ idx2++;
- idx = hash_key & t->mask;
- if (use2)
- idx2 = hash_key2 & t->mask;
- else
- idx2 = idx;
if (!new_hash) {
/* We need to lock the bucket in the right table */
@@ -100,46 +120,45 @@ conn_tab_lock(struct ip_vs_rht *t, struct ip_vs_conn *cp, u32 hash_key,
* both nodes in different tables, use idx/idx2
* for proper lock ordering for heads.
*/
- idx = hash_key & t->mask;
- idx |= IP_VS_RHT_TABLE_ID_MASK;
- }
- if (use2) {
- if (!ip_vs_rht_same_table(t2, hash_key2)) {
- /* It is already moved to new table */
- t2 = rcu_dereference(t2->new_tbl);
- idx2 = hash_key2 & t2->mask;
- idx2 |= IP_VS_RHT_TABLE_ID_MASK;
- }
- } else {
- idx2 = idx;
+ idx++;
}
}
+ if (use2 && !new_hash2 && !ip_vs_rht_same_table(t2, hash_key2)) {
+ /* It is already moved to new table */
+ t2 = rcu_dereference(t2->new_tbl);
+ idx2++;
+ }
+ if (!use2)
+ idx2 = idx;
head = t->buckets + (hash_key & t->mask);
head2 = use2 ? t2->buckets + (hash_key2 & t2->mask) : head;
- local_bh_disable();
- /* Do not touch seqcount, this is a safe operation */
-
- if (idx <= idx2) {
+ if (idx > idx2 || (head > head2 && idx == idx2)) {
+ hlist_bl_lock(head2);
hlist_bl_lock(head);
- if (head != head2)
- hlist_bl_lock(head2);
} else {
- hlist_bl_lock(head2);
hlist_bl_lock(head);
+ if (head != head2)
+ hlist_bl_lock(head2);
}
if (!new_hash) {
+ bool changed;
+
/* Ensure hash_key is read under lock */
hash_key_new = READ_ONCE(cp->hn0.hash_key);
- hash_key_new2 = READ_ONCE(cp->hn1.hash_key);
+ changed = hash_key != hash_key_new;
+ if (use2 && !new_hash2) {
+ hash_key_new2 = READ_ONCE(cp->hn1.hash_key);
+ changed |= hash_key2 != hash_key_new2;
+ } else {
+ hash_key_new2 = hash_key2;
+ }
/* Hash changed ? */
- if (hash_key != hash_key_new ||
- (hash_key2 != hash_key_new2 && use2)) {
+ if (changed) {
if (head != head2)
hlist_bl_unlock(head2);
hlist_bl_unlock(head);
- local_bh_enable();
hash_key = hash_key_new;
hash_key2 = hash_key_new2;
goto retry;
@@ -155,7 +174,6 @@ static inline void conn_tab_unlock(struct hlist_bl_head *head,
if (head != head2)
hlist_bl_unlock(head2);
hlist_bl_unlock(head);
- local_bh_enable();
}
static void ip_vs_conn_expire(struct timer_list *t);
@@ -268,8 +286,9 @@ static inline int ip_vs_conn_hash(struct ip_vs_conn *cp)
use2 = false;
}
- conn_tab_lock(t, cp, hash_key, hash_key2, use2, true /* new_hash */,
- &head, &head2);
+ local_bh_disable();
+ conn_tab_lock(t, t, cp, hash_key, hash_key2, use2, true /* new_hash */,
+ true /* new_hash2 */, &head, &head2);
cp->flags |= IP_VS_CONN_F_HASHED;
WRITE_ONCE(cp->hn0.hash_key, hash_key);
@@ -280,6 +299,7 @@ static inline int ip_vs_conn_hash(struct ip_vs_conn *cp)
hlist_bl_add_head_rcu(&cp->hn1.node, head2);
conn_tab_unlock(head, head2);
+ local_bh_enable();
ret = 1;
/* Schedule resizing if load increases */
@@ -306,18 +326,20 @@ static inline bool ip_vs_conn_unlink(struct ip_vs_conn *cp)
return refcount_dec_if_one(&cp->refcnt);
rcu_read_lock();
+ local_bh_disable();
t = rcu_dereference(ipvs->conn_tab);
hash_key = READ_ONCE(cp->hn0.hash_key);
hash_key2 = READ_ONCE(cp->hn1.hash_key);
use2 = ip_vs_conn_use_hash2(cp);
- conn_tab_lock(t, cp, hash_key, hash_key2, use2, false /* new_hash */,
- &head, &head2);
+ conn_tab_lock(t, t, cp, hash_key, hash_key2, use2, false /* new_hash */,
+ false /* new_hash2 */, &head, &head2);
if (cp->flags & IP_VS_CONN_F_HASHED) {
/* Decrease refcnt and unlink conn only if we are last user */
- if (refcount_dec_if_one(&cp->refcnt)) {
+ if (use2 == ip_vs_conn_use_hash2(cp) &&
+ refcount_dec_if_one(&cp->refcnt)) {
hlist_bl_del_rcu(&cp->hn0.node);
if (use2)
hlist_bl_del_rcu(&cp->hn1.node);
@@ -328,6 +350,7 @@ static inline bool ip_vs_conn_unlink(struct ip_vs_conn *cp)
conn_tab_unlock(head, head2);
+ local_bh_enable();
rcu_read_unlock();
return ret;
@@ -632,6 +655,7 @@ void ip_vs_conn_fill_cport(struct ip_vs_conn *cp, __be16 cport)
int ntbl;
int dir;
+restart:
/* No packets from inside, so we can do it in 2 steps. */
dir = use2 ? 1 : 0;
@@ -686,6 +710,23 @@ void ip_vs_conn_fill_cport(struct ip_vs_conn *cp, __be16 cport)
/* Protect the cp->flags modification */
spin_lock_bh(&cp->lock);
+ /* Recheck the forwarding method under lock */
+ if (use2 != ip_vs_conn_use_hash2(cp)) {
+ use2 = !use2;
+ if (use2) {
+ spin_unlock_bh(&cp->lock);
+ /* Restart with new use2 value */
+ goto restart;
+ }
+ if (dir) {
+ /* Not started yet, so just skip dir 1 */
+ spin_unlock_bh(&cp->lock);
+ dir--;
+ goto next_dir;
+ }
+ /* Just finish dir 0 */
+ }
+
/* Lock seqcount only for the old bucket, even if we are on new table
* because it affects the del operation, not the adding.
*/
@@ -752,6 +793,61 @@ void ip_vs_conn_fill_cport(struct ip_vs_conn *cp, __be16 cport)
goto next_dir;
}
+/* Change forwarding method for hashed conn */
+static void ip_vs_conn_change_fwd_mask(struct ip_vs_conn *cp, u32 new_flags)
+{
+ struct netns_ipvs *ipvs = cp->ipvs;
+ struct hlist_bl_head *head, *head2;
+ u32 hash2, hash_key, hash_key2;
+ struct ip_vs_rht *t, *t2;
+
+ /* See ip_vs_conn_use_hash2() for reference */
+ if ((cp->flags & IP_VS_CONN_F_TEMPLATE) ||
+ /* No change in double hashing ? */
+ (IP_VS_FWD_METHOD(cp) == IP_VS_CONN_F_MASQ) ==
+ ((new_flags & IP_VS_CONN_F_FWD_MASK) == IP_VS_CONN_F_MASQ)) {
+ cp->flags = new_flags;
+ return;
+ }
+ t = rcu_dereference(ipvs->conn_tab);
+ if (ip_vs_conn_use_hash2(cp)) {
+ /* Stop double hashing */
+ hash_key = READ_ONCE(cp->hn0.hash_key);
+ hash_key2 = READ_ONCE(cp->hn1.hash_key);
+
+ conn_tab_lock(t, t, cp, hash_key, hash_key2, true /* use2 */,
+ false /* new_hash */, false /* new_hash2 */,
+ &head, &head2);
+
+ /* Keep both hash keys in same table */
+ hash_key = READ_ONCE(cp->hn0.hash_key);
+ WRITE_ONCE(cp->hn1.hash_key, hash_key);
+ hlist_bl_del_rcu(&cp->hn1.node);
+ cp->flags = new_flags;
+
+ conn_tab_unlock(head, head2);
+ } else {
+ /* Start double hashing */
+
+ hash_key = READ_ONCE(cp->hn0.hash_key);
+
+ t2 = rcu_dereference(t->new_tbl);
+ hash2 = ip_vs_conn_hashkey_conn(t2, cp, true);
+ hash_key2 = ip_vs_rht_build_hash_key(t2, hash2);
+
+ /* Change the forwarding method under locked hn0 */
+ conn_tab_lock(t, t2, cp, hash_key, hash_key2, true /* use2 */,
+ false /* new_hash */, true /* new_hash2 */,
+ &head, &head2);
+
+ WRITE_ONCE(cp->hn1.hash_key, hash_key2);
+ cp->flags = new_flags;
+ hlist_bl_add_head_rcu(&cp->hn1.node, head2);
+
+ conn_tab_unlock(head, head2);
+ }
+}
+
/* Get default load factor to map conn_count/u_thresh to t->size */
static int ip_vs_conn_default_load_factor(struct netns_ipvs *ipvs)
{
@@ -1021,9 +1117,18 @@ ip_vs_bind_dest(struct ip_vs_conn *cp, struct ip_vs_dest *dest)
conn_flags &= ~IP_VS_CONN_F_INACTIVE;
/* connections inherit forwarding method from dest */
flags &= ~(IP_VS_CONN_F_FWD_MASK | IP_VS_CONN_F_NOOUTPUT);
+ flags |= conn_flags;
+ /* Changing forwarding method for hashed conn can
+ * happen only under locks
+ */
+ if (cp->flags & IP_VS_CONN_F_HASHED)
+ ip_vs_conn_change_fwd_mask(cp, flags);
+ else
+ cp->flags = flags;
+ } else {
+ flags |= conn_flags;
+ cp->flags = flags;
}
- flags |= conn_flags;
- cp->flags = flags;
cp->dest = dest;
IP_VS_DBG_BUF(7, "Bind-dest %s c:%s:%d v:%s:%d "
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 057/438] netfilter: nf_tables: make nft_object rhltable per table
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 056/438] ipvs: adjust double hashing when fwd method changes Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 058/438] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH Greg Kroah-Hartman
` (394 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Westphal, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit f4f699790590bd0896c48a71e9232a65198f92f0 ]
The nft_object rhltable is global, this allows for accessing objects
that are being dismangled from lookup path by other existing netns.
Given the nft_obj_destroy() releases the object inmediately, this might
lead to use-after-free of these objects that are being released.
Make the existing rhltable per table to address this issue to deal with
with the nft_rcv_nl_event() path too.
Update nft_obj_lookup() to take the table as non-const, otherwise,
compiler complains when passing the objname_ht to rhltable_lookup().
Fixes: 4d44175aa5bb ("netfilter: nf_tables: handle nft_object lookups via rhltable")
Suggested-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/netfilter/nf_tables.h | 4 +++-
net/netfilter/nf_tables_api.c | 34 +++++++++++++++----------------
2 files changed, 19 insertions(+), 19 deletions(-)
diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h
index 9d844354c4d95..3be612145c130 100644
--- a/include/net/netfilter/nf_tables.h
+++ b/include/net/netfilter/nf_tables.h
@@ -1294,6 +1294,7 @@ static inline void nft_use_inc_restore(u32 *use)
* @sets: sets in the table
* @objects: stateful objects in the table
* @flowtables: flow tables in the table
+ * @objname_ht: hashtable for objects lookup by name
* @hgenerator: handle generator state
* @handle: table handle
* @use: number of chain references to this table
@@ -1313,6 +1314,7 @@ struct nft_table {
struct list_head sets;
struct list_head objects;
struct list_head flowtables;
+ struct rhltable objname_ht;
u64 hgenerator;
u64 handle;
u32 use;
@@ -1400,7 +1402,7 @@ static inline void *nft_obj_data(const struct nft_object *obj)
#define nft_expr_obj(expr) *((struct nft_object **)nft_expr_priv(expr))
struct nft_object *nft_obj_lookup(const struct net *net,
- const struct nft_table *table,
+ struct nft_table *table,
const struct nlattr *nla, u32 objtype,
u8 genmask);
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index e1db3e678656d..c89e55ffc77d1 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -45,8 +45,6 @@ enum {
NFT_VALIDATE_DO,
};
-static struct rhltable nft_objname_ht;
-
static u32 nft_chain_hash(const void *data, u32 len, u32 seed);
static u32 nft_chain_hash_obj(const void *data, u32 len, u32 seed);
static int nft_chain_hash_cmp(struct rhashtable_compare_arg *, const void *);
@@ -1635,6 +1633,10 @@ static int nf_tables_newtable(struct sk_buff *skb, const struct nfnl_info *info,
if (err)
goto err_chain_ht;
+ err = rhltable_init(&table->objname_ht, &nft_objname_ht_params);
+ if (err < 0)
+ goto err_obj_ht;
+
INIT_LIST_HEAD(&table->chains);
INIT_LIST_HEAD(&table->sets);
INIT_LIST_HEAD(&table->objects);
@@ -1653,6 +1655,8 @@ static int nf_tables_newtable(struct sk_buff *skb, const struct nfnl_info *info,
list_add_tail_rcu(&table->list, &nft_net->tables);
return 0;
err_trans:
+ rhltable_destroy(&table->objname_ht);
+err_obj_ht:
rhltable_destroy(&table->chains_ht);
err_chain_ht:
kfree(table->udata);
@@ -1819,6 +1823,7 @@ static void nf_tables_table_destroy(struct nft_table *table)
return;
rhltable_destroy(&table->chains_ht);
+ rhltable_destroy(&table->objname_ht);
kfree(table->name);
kfree(table->udata);
kfree(table);
@@ -8082,7 +8087,7 @@ void nft_unregister_obj(struct nft_object_type *obj_type)
EXPORT_SYMBOL_GPL(nft_unregister_obj);
struct nft_object *nft_obj_lookup(const struct net *net,
- const struct nft_table *table,
+ struct nft_table *table,
const struct nlattr *nla, u32 objtype,
u8 genmask)
{
@@ -8098,7 +8103,7 @@ struct nft_object *nft_obj_lookup(const struct net *net,
!lockdep_commit_lock_is_held(net));
rcu_read_lock();
- list = rhltable_lookup(&nft_objname_ht, &k, nft_objname_ht_params);
+ list = rhltable_lookup(&table->objname_ht, &k, nft_objname_ht_params);
if (!list)
goto out;
@@ -8376,7 +8381,7 @@ static int nf_tables_newobj(struct sk_buff *skb, const struct nfnl_info *info,
if (err < 0)
goto err_trans;
- err = rhltable_insert(&nft_objname_ht, &obj->rhlhead,
+ err = rhltable_insert(&table->objname_ht, &obj->rhlhead,
nft_objname_ht_params);
if (err < 0)
goto err_obj_ht;
@@ -8561,8 +8566,8 @@ nf_tables_getobj_single(u32 portid, const struct nfnl_info *info,
struct netlink_ext_ack *extack = info->extack;
u8 genmask = nft_genmask_cur(info->net);
u8 family = info->nfmsg->nfgen_family;
- const struct nft_table *table;
struct net *net = info->net;
+ struct nft_table *table;
struct nft_object *obj;
struct sk_buff *skb2;
u32 objtype;
@@ -10423,9 +10428,9 @@ static void nf_tables_commit_chain(struct net *net, struct nft_chain *chain)
nf_tables_commit_chain_free_rules_old(g0);
}
-static void nft_obj_del(struct nft_object *obj)
+static void nft_obj_del(struct nft_table *table, struct nft_object *obj)
{
- rhltable_remove(&nft_objname_ht, &obj->rhlhead, nft_objname_ht_params);
+ rhltable_remove(&table->objname_ht, &obj->rhlhead, nft_objname_ht_params);
list_del_rcu(&obj->list);
}
@@ -11110,7 +11115,7 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
break;
case NFT_MSG_DELOBJ:
case NFT_MSG_DESTROYOBJ:
- nft_obj_del(nft_trans_obj(trans));
+ nft_obj_del(table, nft_trans_obj(trans));
nf_tables_obj_notify(&ctx, nft_trans_obj(trans),
trans->msg_type);
break;
@@ -11402,7 +11407,7 @@ static int __nf_tables_abort(struct net *net, enum nfnl_abort_action action)
nft_trans_destroy(trans);
} else {
nft_use_dec_restore(&table->use);
- nft_obj_del(nft_trans_obj(trans));
+ nft_obj_del(table, nft_trans_obj(trans));
}
break;
case NFT_MSG_DELOBJ:
@@ -12025,7 +12030,7 @@ static void __nft_release_table(struct net *net, struct nft_table *table)
nft_set_destroy(&ctx, set);
}
list_for_each_entry_safe(obj, ne, &table->objects, list) {
- nft_obj_del(obj);
+ nft_obj_del(table, obj);
nft_use_dec(&table->use);
nft_obj_destroy(&ctx, obj);
}
@@ -12207,10 +12212,6 @@ static int __init nf_tables_module_init(void)
if (err < 0)
goto err_netdev_notifier;
- err = rhltable_init(&nft_objname_ht, &nft_objname_ht_params);
- if (err < 0)
- goto err_rht_objname;
-
err = nft_offload_init();
if (err < 0)
goto err_offload;
@@ -12233,8 +12234,6 @@ static int __init nf_tables_module_init(void)
err_netlink_notifier:
nft_offload_exit();
err_offload:
- rhltable_destroy(&nft_objname_ht);
-err_rht_objname:
unregister_netdevice_notifier(&nf_tables_flowtable_notifier);
err_netdev_notifier:
nf_tables_core_module_exit();
@@ -12256,7 +12255,6 @@ static void __exit nf_tables_module_exit(void)
unregister_pernet_subsys(&nf_tables_net_ops);
cancel_work_sync(&trans_gc_work);
rcu_barrier();
- rhltable_destroy(&nft_objname_ht);
nf_tables_core_module_exit();
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 058/438] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 057/438] netfilter: nf_tables: make nft_object rhltable per table Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 059/438] ipvs: fix the checksum validations Greg Kroah-Hartman
` (393 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin,
Talha Berk Arslan
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit 305b63e1402267459fdabb183af4527f6799eebf ]
The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the
dsthash_ent structure which represents an entry in the hashtable. There
is a union area which uses a different layout to express the rate match
mode.
Update .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode
flag is requested by two or more different rules that refer to the same
hashtable. Otherwise, uninitialized access to the burst field in the
union is possible.
Reject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by
revision less than 3 too.
Fixes: bea74641e378 ("netfilter: xt_hashlimit: add rate match mode")
Reported-and-tested-by: Talha Berk Arslan <talha.anything.info@gmail.com>
Link: https://patch.msgid.link/20260721074629.668-1-talha.anything.info@gmail.com/
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/xt_hashlimit.c | 16 +++++++++++++++-
1 file changed, 15 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/xt_hashlimit.c b/net/netfilter/xt_hashlimit.c
index 2704b4b60d1e0..9af0fa895f730 100644
--- a/net/netfilter/xt_hashlimit.c
+++ b/net/netfilter/xt_hashlimit.c
@@ -117,6 +117,7 @@ struct xt_hashlimit_htable {
refcount_t use;
u_int8_t family;
bool rnd_initialized;
+ bool ratematch;
struct hashlimit_cfg3 cfg; /* config */
@@ -323,6 +324,7 @@ static int htable_create(struct net *net, struct hashlimit_cfg3 *cfg,
kvfree(hinfo);
return -ENOMEM;
}
+ hinfo->ratematch = !!(cfg->mode & XT_HASHLIMIT_RATE_MATCH);
spin_lock_init(&hinfo->lock);
switch (revision) {
@@ -872,7 +874,10 @@ static int hashlimit_mt_check_common(const struct xt_mtchk_param *par,
}
/* Check for overflow. */
- if (revision >= 3 && cfg->mode & XT_HASHLIMIT_RATE_MATCH) {
+ if (cfg->mode & XT_HASHLIMIT_RATE_MATCH) {
+ if (revision < 3)
+ return -EINVAL;
+
if (cfg->avg == 0 || cfg->avg > U32_MAX) {
pr_info_ratelimited("invalid rate\n");
return -ERANGE;
@@ -905,6 +910,15 @@ static int hashlimit_mt_check_common(const struct xt_mtchk_param *par,
mutex_unlock(&hashlimit_mutex);
return ret;
}
+ } else {
+ if ((cfg->mode & XT_HASHLIMIT_RATE_MATCH &&
+ !(*hinfo)->ratematch) ||
+ (!(cfg->mode & XT_HASHLIMIT_RATE_MATCH) &&
+ (*hinfo)->ratematch)) {
+ mutex_unlock(&hashlimit_mutex);
+ htable_put(*hinfo);
+ return -EINVAL;
+ }
}
mutex_unlock(&hashlimit_mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 059/438] ipvs: fix the checksum validations
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 058/438] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 060/438] ipvs: fix places with wrong packet offsets Greg Kroah-Hartman
` (392 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Anastasov, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit e876b75b9020a97bbdc79721e7fc749024891c65 ]
ip_vs_in_icmp_v6() is missing checksum validation for ICMPv6
packets from clients. In fact, as for TCP/UDP we should
validate the checksum for ICMP packets only when we
mangle the packets on MASQ or on reply for tunnel.
Also, Sashiko points out that handle_response_icmp() being
common for IPv4 and IPv6 is missing the pseudo-header
calculation while validating ICMPv6 messages from real
servers which is a problem if checksum is not validated
by the hardware.
Fix the problems by creating ip_vs_checksum_common_check()
helper and use it for TCP/UDP/ICMP both for IPv4 and IPv6.
Rely on the nf_checksum() for validating the ICMP messages
but use it also for TCP and UDP.
Use correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.
IPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum
validation on LOCAL_OUT (local clients or local real
servers) and on FORWARD (traffic from servers on LAN).
Do it only on LOCAL_IN, in case nf_checksum() is not
called on PRE_ROUTING.
Also, ip_vs_checksum_complete() can be marked static.
Fixes: 2a3b791e6e11 ("IPVS: Add/adjust Netfilter hook functions and helpers for v6")
Link: https://sashiko.dev/#/patchset/20260708180315.77413-1-ja%40ssi.bg
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip_vs.h | 31 +++++++++++++++--
net/netfilter/ipvs/ip_vs_core.c | 20 +++++++++--
net/netfilter/ipvs/ip_vs_proto_sctp.c | 15 ++++----
net/netfilter/ipvs/ip_vs_proto_tcp.c | 44 +++++------------------
net/netfilter/ipvs/ip_vs_proto_udp.c | 50 ++++++---------------------
5 files changed, 74 insertions(+), 86 deletions(-)
diff --git a/include/net/ip_vs.h b/include/net/ip_vs.h
index 62433e48b1f9a..591bf5b4b894f 100644
--- a/include/net/ip_vs.h
+++ b/include/net/ip_vs.h
@@ -25,7 +25,9 @@
#include <linux/netfilter.h> /* for union nf_inet_addr */
#include <linux/ip.h>
#include <linux/ipv6.h> /* for struct ipv6hdr */
+#include <net/route.h>
#include <net/ipv6.h>
+#include <net/ip6_fib.h>
#if IS_ENABLED(CONFIG_NF_CONNTRACK)
#include <net/netfilter/nf_conntrack.h>
#endif
@@ -2044,8 +2046,6 @@ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
struct ip_vs_conn *cp, int dir);
#endif
-__sum16 ip_vs_checksum_complete(struct sk_buff *skb, int offset);
-
static inline __wsum ip_vs_check_diff4(__be32 old, __be32 new, __wsum oldsum)
{
__be32 diff[2] = { ~old, new };
@@ -2071,6 +2071,33 @@ static inline __wsum ip_vs_check_diff2(__be16 old, __be16 new, __wsum oldsum)
return csum_partial(diff, sizeof(diff), oldsum);
}
+static inline bool ip_vs_checksum_needed(struct sk_buff *skb, int af)
+{
+ /* Checksum unnecessary or already validated? */
+ if (skb_csum_unnecessary(skb))
+ return false;
+ /* LOCAL_OUT ? */
+ if (!skb->dev || skb->dev->flags & IFF_LOOPBACK)
+ return false;
+ /* !LOCAL_IN (FORWARD) ? */
+ if (af == AF_INET6) {
+ if (!(dst_rt6_info(skb_dst(skb))->rt6i_flags & RTF_LOCAL))
+ return false;
+ } else {
+ if (!(skb_rtable(skb)->rt_flags & RTCF_LOCAL))
+ return false;
+ }
+ return true;
+}
+
+static inline bool ip_vs_checksum_common_check(struct sk_buff *skb,
+ int offset, int proto, int af)
+{
+ if (!ip_vs_checksum_needed(skb, af))
+ return true;
+ return !nf_checksum(skb, NF_INET_LOCAL_IN, offset, proto, af);
+}
+
/* Forget current conntrack (unconfirmed) and attach notrack entry */
static inline void ip_vs_notrack(struct sk_buff *skb)
{
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index bafab93451d03..c8b512725e6e0 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -867,7 +867,7 @@ static int sysctl_nat_icmp_send(struct netns_ipvs *ipvs) { return 0; }
#endif
-__sum16 ip_vs_checksum_complete(struct sk_buff *skb, int offset)
+static __sum16 ip_vs_checksum_complete(struct sk_buff *skb, int offset)
{
return csum_fold(skb_checksum(skb, offset, skb->len - offset, 0));
}
@@ -1038,13 +1038,14 @@ static int handle_response_icmp(int af, struct sk_buff *skb,
unsigned int offset, unsigned int ihl,
unsigned int hooknum)
{
+ int iproto = af == AF_INET6 ? IPPROTO_ICMPV6 : IPPROTO_ICMP;
unsigned int verdict = NF_DROP;
if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ)
goto after_nat;
/* Ensure the checksum is correct */
- if (!skb_csum_unnecessary(skb) && ip_vs_checksum_complete(skb, ihl)) {
+ if (!ip_vs_checksum_common_check(skb, ihl, iproto, af)) {
/* Failed checksum! */
IP_VS_DBG_BUF(1, "Forward ICMP: failed checksum from %s!\n",
IP_VS_DBG_ADDR(af, snet));
@@ -1898,7 +1899,8 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
verdict = NF_DROP;
/* Ensure the checksum is correct */
- if (!skb_csum_unnecessary(skb) && ip_vs_checksum_complete(skb, ihl)) {
+ if ((IP_VS_FWD_METHOD(cp) == IP_VS_CONN_F_MASQ || tunnel) &&
+ !ip_vs_checksum_common_check(skb, ihl, IPPROTO_ICMP, AF_INET)) {
/* Failed checksum! */
IP_VS_DBG(1, "Incoming ICMP: failed checksum from %pI4!\n",
&iph->saddr);
@@ -2064,6 +2066,18 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
goto out;
}
+ verdict = NF_DROP;
+
+ /* Ensure the checksum is correct */
+ if (IP_VS_FWD_METHOD(cp) == IP_VS_CONN_F_MASQ &&
+ !ip_vs_checksum_common_check(skb, iph->len, IPPROTO_ICMPV6,
+ AF_INET6)) {
+ /* Failed checksum! */
+ IP_VS_DBG(1, "Incoming ICMPv6: failed checksum from %pI6c!\n",
+ &iph->saddr);
+ goto out;
+ }
+
/* do the statistics and put it back */
ip_vs_in_stats(cp, skb);
diff --git a/net/netfilter/ipvs/ip_vs_proto_sctp.c b/net/netfilter/ipvs/ip_vs_proto_sctp.c
index c67317be17dfa..f6f732b7dfa86 100644
--- a/net/netfilter/ipvs/ip_vs_proto_sctp.c
+++ b/net/netfilter/ipvs/ip_vs_proto_sctp.c
@@ -11,7 +11,7 @@
static int
sctp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
- unsigned int sctphoff);
+ struct ip_vs_iphdr *iph);
static int
sctp_conn_schedule(struct netns_ipvs *ipvs, int af, struct sk_buff *skb,
@@ -109,7 +109,7 @@ sctp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
int ret;
/* Some checks before mangling */
- if (!sctp_csum_check(cp->af, skb, pp, sctphoff))
+ if (!sctp_csum_check(cp->af, skb, pp, iph))
return 0;
/* Call application helper if needed */
@@ -157,7 +157,7 @@ sctp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
int ret;
/* Some checks before mangling */
- if (!sctp_csum_check(cp->af, skb, pp, sctphoff))
+ if (!sctp_csum_check(cp->af, skb, pp, iph))
return 0;
/* Call application helper if needed */
@@ -187,19 +187,22 @@ sctp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
static int
sctp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
- unsigned int sctphoff)
+ struct ip_vs_iphdr *iph)
{
+ unsigned int sctphoff = iph->len;
struct sctphdr *sh;
__le32 cmp, val;
+ if (!ip_vs_checksum_needed(skb, af))
+ return 1;
sh = (struct sctphdr *)(skb->data + sctphoff);
cmp = sh->checksum;
val = sctp_compute_cksum(skb, sctphoff);
if (val != cmp) {
/* CRC failure, dump it. */
- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
- "Failed checksum for");
+ IP_VS_DBG_RL_PKT(0, af, pp, skb, iph->off,
+ "Failed checksum for");
return 0;
}
return 1;
diff --git a/net/netfilter/ipvs/ip_vs_proto_tcp.c b/net/netfilter/ipvs/ip_vs_proto_tcp.c
index f86b763efcc4d..533fce3e5e4e4 100644
--- a/net/netfilter/ipvs/ip_vs_proto_tcp.c
+++ b/net/netfilter/ipvs/ip_vs_proto_tcp.c
@@ -29,7 +29,7 @@
static int
tcp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
- unsigned int tcphoff);
+ struct ip_vs_iphdr *iph);
static int
tcp_conn_schedule(struct netns_ipvs *ipvs, int af, struct sk_buff *skb,
@@ -166,7 +166,7 @@ tcp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
int ret;
/* Some checks before mangling */
- if (!tcp_csum_check(cp->af, skb, pp, tcphoff))
+ if (!tcp_csum_check(cp->af, skb, pp, iph))
return 0;
/* Call application helper if needed */
@@ -244,7 +244,7 @@ tcp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
int ret;
/* Some checks before mangling */
- if (!tcp_csum_check(cp->af, skb, pp, tcphoff))
+ if (!tcp_csum_check(cp->af, skb, pp, iph))
return 0;
/*
@@ -302,41 +302,13 @@ tcp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
static int
tcp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
- unsigned int tcphoff)
+ struct ip_vs_iphdr *iph)
{
- switch (skb->ip_summed) {
- case CHECKSUM_NONE:
- skb->csum = skb_checksum(skb, tcphoff, skb->len - tcphoff, 0);
- fallthrough;
- case CHECKSUM_COMPLETE:
-#ifdef CONFIG_IP_VS_IPV6
- if (af == AF_INET6) {
- if (csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
- &ipv6_hdr(skb)->daddr,
- skb->len - tcphoff,
- IPPROTO_TCP,
- skb->csum)) {
- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
- "Failed checksum for");
- return 0;
- }
- } else
-#endif
- if (csum_tcpudp_magic(ip_hdr(skb)->saddr,
- ip_hdr(skb)->daddr,
- skb->len - tcphoff,
- ip_hdr(skb)->protocol,
- skb->csum)) {
- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
- "Failed checksum for");
- return 0;
- }
- break;
- default:
- /* No need to checksum. */
- break;
+ if (!ip_vs_checksum_common_check(skb, iph->len, IPPROTO_TCP, af)) {
+ IP_VS_DBG_RL_PKT(0, af, pp, skb, iph->off,
+ "Failed checksum for");
+ return 0;
}
-
return 1;
}
diff --git a/net/netfilter/ipvs/ip_vs_proto_udp.c b/net/netfilter/ipvs/ip_vs_proto_udp.c
index 58f9e255927e2..de3597347542e 100644
--- a/net/netfilter/ipvs/ip_vs_proto_udp.c
+++ b/net/netfilter/ipvs/ip_vs_proto_udp.c
@@ -25,7 +25,7 @@
static int
udp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
- unsigned int udphoff);
+ struct ip_vs_iphdr *iph);
static int
udp_conn_schedule(struct netns_ipvs *ipvs, int af, struct sk_buff *skb,
@@ -155,7 +155,7 @@ udp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
int ret;
/* Some checks before mangling */
- if (!udp_csum_check(cp->af, skb, pp, udphoff))
+ if (!udp_csum_check(cp->af, skb, pp, iph))
return 0;
/*
@@ -238,7 +238,7 @@ udp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
int ret;
/* Some checks before mangling */
- if (!udp_csum_check(cp->af, skb, pp, udphoff))
+ if (!udp_csum_check(cp->af, skb, pp, iph))
return 0;
/*
@@ -298,48 +298,20 @@ udp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
static int
udp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
- unsigned int udphoff)
+ struct ip_vs_iphdr *iph)
{
struct udphdr _udph, *uh;
- uh = skb_header_pointer(skb, udphoff, sizeof(_udph), &_udph);
+ uh = skb_header_pointer(skb, iph->len, sizeof(_udph), &_udph);
if (uh == NULL)
return 0;
- if (uh->check != 0) {
- switch (skb->ip_summed) {
- case CHECKSUM_NONE:
- skb->csum = skb_checksum(skb, udphoff,
- skb->len - udphoff, 0);
- fallthrough;
- case CHECKSUM_COMPLETE:
-#ifdef CONFIG_IP_VS_IPV6
- if (af == AF_INET6) {
- if (csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
- &ipv6_hdr(skb)->daddr,
- skb->len - udphoff,
- IPPROTO_UDP,
- skb->csum)) {
- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
- "Failed checksum for");
- return 0;
- }
- } else
-#endif
- if (csum_tcpudp_magic(ip_hdr(skb)->saddr,
- ip_hdr(skb)->daddr,
- skb->len - udphoff,
- ip_hdr(skb)->protocol,
- skb->csum)) {
- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
- "Failed checksum for");
- return 0;
- }
- break;
- default:
- /* No need to checksum. */
- break;
- }
+ if (!uh->check)
+ return 1;
+ if (!ip_vs_checksum_common_check(skb, iph->len, IPPROTO_UDP, af)) {
+ IP_VS_DBG_RL_PKT(0, af, pp, skb, iph->off,
+ "Failed checksum for");
+ return 0;
}
return 1;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 060/438] ipvs: fix places with wrong packet offsets
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 059/438] ipvs: fix the checksum validations Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 061/438] ipvs: do not mangle ICMP replies for non-first fragments Greg Kroah-Hartman
` (391 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Anastasov, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit 15cab31a3730e05f0767b922a7450e5d784b2607 ]
The offsets we use to packet headers and payloads should be
based on skb->data. We even already respect non-zero
network offset in ip_vs_fill_iph_skb() but some places
do it wrongly and support only zero offset which is expected
for the IP layer where IPVS has hooks.
Change all places that instead of skb->data use offsets based
on the network header (skb_network_header, ip_hdr, etc) because
this doubles the network offset as noted by Sashiko.
For ip_vs_nat_icmp_v6() we can even rely on the IPv6 header
parsing done by the caller.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Link: https://sashiko.dev/#/patchset/20260710143733.29741-2-fw%40strlen.de
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip_vs.h | 15 +--
net/netfilter/ipvs/ip_vs_app.c | 4 +-
net/netfilter/ipvs/ip_vs_core.c | 133 +++++++++++++-------------
net/netfilter/ipvs/ip_vs_proto_sctp.c | 4 +-
net/netfilter/ipvs/ip_vs_proto_tcp.c | 4 +-
net/netfilter/ipvs/ip_vs_proto_udp.c | 4 +-
net/netfilter/ipvs/ip_vs_xmit.c | 26 ++---
7 files changed, 97 insertions(+), 93 deletions(-)
diff --git a/include/net/ip_vs.h b/include/net/ip_vs.h
index 591bf5b4b894f..7b556ce03602e 100644
--- a/include/net/ip_vs.h
+++ b/include/net/ip_vs.h
@@ -1952,8 +1952,9 @@ int ip_vs_tunnel_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
int ip_vs_dr_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, struct ip_vs_iphdr *iph);
int ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
- struct ip_vs_protocol *pp, int offset,
- unsigned int hooknum, struct ip_vs_iphdr *iph);
+ struct ip_vs_protocol *pp, unsigned int toff,
+ unsigned int wlen, unsigned int hooknum,
+ struct ip_vs_iphdr *ciph);
void ip_vs_dest_dst_rcu_free(struct rcu_head *head);
#ifdef CONFIG_IP_VS_IPV6
@@ -1966,8 +1967,9 @@ int ip_vs_tunnel_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
int ip_vs_dr_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, struct ip_vs_iphdr *iph);
int ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
- struct ip_vs_protocol *pp, int offset,
- unsigned int hooknum, struct ip_vs_iphdr *iph);
+ struct ip_vs_protocol *pp, unsigned int toff,
+ unsigned int wlen, unsigned int hooknum,
+ struct ip_vs_iphdr *ciph);
#endif
#ifdef CONFIG_SYSCTL
@@ -2039,11 +2041,12 @@ static inline bool ip_vs_conn_use_hash2(struct ip_vs_conn *cp)
}
void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
- struct ip_vs_conn *cp, int dir);
+ struct ip_vs_conn *cp, int dir, unsigned int toff);
#ifdef CONFIG_IP_VS_IPV6
void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
- struct ip_vs_conn *cp, int dir);
+ struct ip_vs_conn *cp, int dir, unsigned int toff,
+ struct ip_vs_iphdr *ciph);
#endif
static inline __wsum ip_vs_check_diff4(__be32 old, __be32 new, __wsum oldsum)
diff --git a/net/netfilter/ipvs/ip_vs_app.c b/net/netfilter/ipvs/ip_vs_app.c
index b0e00be85cb12..11cbdbaf561da 100644
--- a/net/netfilter/ipvs/ip_vs_app.c
+++ b/net/netfilter/ipvs/ip_vs_app.c
@@ -367,7 +367,7 @@ static inline int app_tcp_pkt_out(struct ip_vs_conn *cp, struct sk_buff *skb,
if (skb_ensure_writable(skb, ipvsh->len + sizeof(*th)))
return 0;
- th = (struct tcphdr *)(skb_network_header(skb) + ipvsh->len);
+ th = (struct tcphdr *)(skb->data + ipvsh->len);
/*
* Remember seq number in case this pkt gets resized
@@ -443,7 +443,7 @@ static inline int app_tcp_pkt_in(struct ip_vs_conn *cp, struct sk_buff *skb,
if (skb_ensure_writable(skb, ipvsh->len + sizeof(*th)))
return 0;
- th = (struct tcphdr *)(skb_network_header(skb) + ipvsh->len);
+ th = (struct tcphdr *)(skb->data + ipvsh->len);
/*
* Remember seq number in case this pkt gets resized
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index c8b512725e6e0..cd5eb71543ec8 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -924,13 +924,12 @@ static int ip_vs_route_me_harder(struct netns_ipvs *ipvs, int af,
* - inout: 1=in->out, 0=out->in
*/
void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
- struct ip_vs_conn *cp, int inout)
+ struct ip_vs_conn *cp, int inout, unsigned int toff)
{
struct iphdr *iph = ip_hdr(skb);
- unsigned int icmp_offset = iph->ihl*4;
- struct icmphdr *icmph = (struct icmphdr *)(skb_network_header(skb) +
- icmp_offset);
+ struct icmphdr *icmph = (struct icmphdr *)(skb->data + toff);
struct iphdr *ciph = (struct iphdr *)(icmph + 1);
+ unsigned int coff __maybe_unused = toff + sizeof(struct icmphdr);
if (inout) {
iph->saddr = cp->vaddr.ip;
@@ -957,48 +956,45 @@ void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
/* And finally the ICMP checksum */
icmph->checksum = 0;
- icmph->checksum = ip_vs_checksum_complete(skb, icmp_offset);
+ icmph->checksum = ip_vs_checksum_complete(skb, toff);
skb->ip_summed = CHECKSUM_UNNECESSARY;
if (inout)
- IP_VS_DBG_PKT(11, AF_INET, pp, skb, (void *)ciph - (void *)iph,
- "Forwarding altered outgoing ICMP");
+ IP_VS_DBG_PKT(11, AF_INET, pp, skb, coff,
+ "Forwarding altered outgoing ICMP");
else
- IP_VS_DBG_PKT(11, AF_INET, pp, skb, (void *)ciph - (void *)iph,
- "Forwarding altered incoming ICMP");
+ IP_VS_DBG_PKT(11, AF_INET, pp, skb, coff,
+ "Forwarding altered incoming ICMP");
}
#ifdef CONFIG_IP_VS_IPV6
void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
- struct ip_vs_conn *cp, int inout)
+ struct ip_vs_conn *cp, int inout, unsigned int toff,
+ struct ip_vs_iphdr *ciph)
{
struct ipv6hdr *iph = ipv6_hdr(skb);
- unsigned int icmp_offset = 0;
- unsigned int offs = 0; /* header offset*/
int protocol;
struct icmp6hdr *icmph;
- struct ipv6hdr *ciph;
- unsigned short fragoffs;
+ struct ipv6hdr *cih;
- ipv6_find_hdr(skb, &icmp_offset, IPPROTO_ICMPV6, &fragoffs, NULL);
- icmph = (struct icmp6hdr *)(skb_network_header(skb) + icmp_offset);
- offs = icmp_offset + sizeof(struct icmp6hdr);
- ciph = (struct ipv6hdr *)(skb_network_header(skb) + offs);
+ icmph = (struct icmp6hdr *)(skb->data + toff);
+ cih = (struct ipv6hdr *)(skb->data + ciph->off);
- protocol = ipv6_find_hdr(skb, &offs, -1, &fragoffs, NULL);
+ protocol = ciph->protocol;
if (inout) {
iph->saddr = cp->vaddr.in6;
- ciph->daddr = cp->vaddr.in6;
+ cih->daddr = cp->vaddr.in6;
} else {
iph->daddr = cp->daddr.in6;
- ciph->saddr = cp->daddr.in6;
+ cih->saddr = cp->daddr.in6;
}
/* the TCP/UDP/SCTP port */
- if (!fragoffs && (IPPROTO_TCP == protocol || IPPROTO_UDP == protocol ||
- IPPROTO_SCTP == protocol)) {
- __be16 *ports = (void *)(skb_network_header(skb) + offs);
+ if (!ciph->fragoffs &&
+ (protocol == IPPROTO_TCP || protocol == IPPROTO_UDP ||
+ protocol == IPPROTO_SCTP)) {
+ __be16 *ports = (void *)(skb->data + ciph->len);
IP_VS_DBG(11, "%s() changed port %d to %d\n", __func__,
ntohs(inout ? ports[1] : ports[0]),
@@ -1011,19 +1007,17 @@ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
/* And finally the ICMP checksum */
icmph->icmp6_cksum = ~csum_ipv6_magic(&iph->saddr, &iph->daddr,
- skb->len - icmp_offset,
+ skb->len - toff,
IPPROTO_ICMPV6, 0);
- skb->csum_start = skb_network_header(skb) - skb->head + icmp_offset;
+ skb->csum_start = skb_headroom(skb) + toff;
skb->csum_offset = offsetof(struct icmp6hdr, icmp6_cksum);
skb->ip_summed = CHECKSUM_PARTIAL;
if (inout)
- IP_VS_DBG_PKT(11, AF_INET6, pp, skb,
- (void *)ciph - (void *)iph,
+ IP_VS_DBG_PKT(11, AF_INET6, pp, skb, ciph->off,
"Forwarding altered outgoing ICMPv6");
else
- IP_VS_DBG_PKT(11, AF_INET6, pp, skb,
- (void *)ciph - (void *)iph,
+ IP_VS_DBG_PKT(11, AF_INET6, pp, skb, ciph->off,
"Forwarding altered incoming ICMPv6");
}
#endif
@@ -1033,37 +1027,38 @@ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
*/
static int handle_response_icmp(int af, struct sk_buff *skb,
union nf_inet_addr *snet,
- __u8 protocol, struct ip_vs_conn *cp,
+ struct ip_vs_conn *cp,
struct ip_vs_protocol *pp,
- unsigned int offset, unsigned int ihl,
- unsigned int hooknum)
+ struct ip_vs_iphdr *ciph,
+ unsigned int toff, unsigned int hooknum)
{
int iproto = af == AF_INET6 ? IPPROTO_ICMPV6 : IPPROTO_ICMP;
unsigned int verdict = NF_DROP;
+ unsigned int ctoff = ciph->len;
if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ)
goto after_nat;
/* Ensure the checksum is correct */
- if (!ip_vs_checksum_common_check(skb, ihl, iproto, af)) {
+ if (!ip_vs_checksum_common_check(skb, toff, iproto, af)) {
/* Failed checksum! */
IP_VS_DBG_BUF(1, "Forward ICMP: failed checksum from %s!\n",
IP_VS_DBG_ADDR(af, snet));
goto out;
}
- if (IPPROTO_TCP == protocol || IPPROTO_UDP == protocol ||
- IPPROTO_SCTP == protocol)
- offset += 2 * sizeof(__u16);
- if (skb_ensure_writable(skb, offset))
+ if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
+ ciph->protocol == IPPROTO_SCTP)
+ ctoff += 2 * sizeof(__u16);
+ if (skb_ensure_writable(skb, ctoff))
goto out;
#ifdef CONFIG_IP_VS_IPV6
if (af == AF_INET6)
- ip_vs_nat_icmp_v6(skb, pp, cp, 1);
+ ip_vs_nat_icmp_v6(skb, pp, cp, 1, toff, ciph);
else
#endif
- ip_vs_nat_icmp(skb, pp, cp, 1);
+ ip_vs_nat_icmp(skb, pp, cp, 1, toff);
if (ip_vs_route_me_harder(cp->ipvs, af, skb, hooknum))
goto out;
@@ -1091,9 +1086,9 @@ static int handle_response_icmp(int af, struct sk_buff *skb,
* Currently handles error types - unreachable, quench, ttl exceeded.
*/
static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
- int *related, unsigned int hooknum)
+ int *related, unsigned int hooknum,
+ struct ip_vs_iphdr *ipvsh)
{
- struct iphdr *iph;
struct icmphdr _icmph, *ic;
struct iphdr _ciph, *cih; /* The ip header contained within the ICMP */
struct ip_vs_iphdr ciph;
@@ -1108,17 +1103,19 @@ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
if (ip_is_fragment(ip_hdr(skb))) {
if (ip_vs_gather_frags(ipvs, skb, ip_vs_defrag_user(hooknum)))
return NF_STOLEN;
+ if (!ip_vs_fill_iph_skb(AF_INET, skb, false, ipvsh))
+ return NF_ACCEPT;
}
- iph = ip_hdr(skb);
- offset = ihl = iph->ihl * 4;
+ ihl = ipvsh->len;
+ offset = ipvsh->len;
ic = skb_header_pointer(skb, offset, sizeof(_icmph), &_icmph);
if (ic == NULL)
return NF_DROP;
IP_VS_DBG(12, "Outgoing ICMP (%d,%d) %pI4->%pI4\n",
ic->type, ntohs(icmp_id(ic)),
- &iph->saddr, &iph->daddr);
+ &ipvsh->saddr.ip, &ipvsh->daddr.ip);
/*
* Work through seeing if this is for us.
@@ -1137,7 +1134,7 @@ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
/* Now find the contained IP header */
offset += sizeof(_icmph);
cih = skb_header_pointer(skb, offset, sizeof(_ciph), &_ciph);
- if (cih == NULL)
+ if (!(cih && cih->version == 4 && cih->ihl >= 5))
return NF_ACCEPT; /* The packet looks wrong, ignore */
pp = ip_vs_proto_get(cih->protocol);
@@ -1160,9 +1157,9 @@ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
if (!cp)
return NF_ACCEPT;
- snet.ip = iph->saddr;
- return handle_response_icmp(AF_INET, skb, &snet, cih->protocol, cp,
- pp, ciph.len, ihl, hooknum);
+ snet.ip = ipvsh->saddr.ip;
+ return handle_response_icmp(AF_INET, skb, &snet, cp, pp, &ciph, ihl,
+ hooknum);
}
#ifdef CONFIG_IP_VS_IPV6
@@ -1175,7 +1172,6 @@ static int ip_vs_out_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
struct ip_vs_conn *cp;
struct ip_vs_protocol *pp;
union nf_inet_addr snet;
- unsigned int offset;
*related = 1;
ic = frag_safe_skb_hp(skb, ipvsh->len, sizeof(_icmph), &_icmph);
@@ -1218,9 +1214,8 @@ static int ip_vs_out_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
return NF_ACCEPT;
snet.in6 = ciph.saddr.in6;
- offset = ciph.len;
- return handle_response_icmp(AF_INET6, skb, &snet, ciph.protocol, cp,
- pp, offset, ipvsh->len, hooknum);
+ return handle_response_icmp(AF_INET6, skb, &snet, cp, pp, &ciph,
+ ipvsh->len, hooknum);
}
#endif
@@ -1546,7 +1541,8 @@ ip_vs_out_hook(void *priv, struct sk_buff *skb, const struct nf_hook_state *stat
#endif
if (unlikely(iph.protocol == IPPROTO_ICMP)) {
int related;
- int verdict = ip_vs_out_icmp(ipvs, skb, &related, hooknum);
+ int verdict = ip_vs_out_icmp(ipvs, skb, &related,
+ hooknum, &iph);
if (related)
return verdict;
@@ -1754,9 +1750,8 @@ static int ipvs_gre_decap(struct netns_ipvs *ipvs, struct sk_buff *skb,
*/
static int
ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
- unsigned int hooknum)
+ unsigned int hooknum, struct ip_vs_iphdr *iph)
{
- struct iphdr *iph;
struct icmphdr _icmph, *ic;
struct iphdr _ciph, *cih; /* The ip header contained within the ICMP */
struct ip_vs_iphdr ciph;
@@ -1766,7 +1761,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
unsigned int offset, offset2, ihl, verdict;
bool tunnel, new_cp = false;
union nf_inet_addr *raddr;
- char *outer_proto = "IPIP";
+ char *outer_proto __maybe_unused = "IPIP";
unsigned int hlen_ipip;
int ulen = 0;
@@ -1776,17 +1771,19 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
if (ip_is_fragment(ip_hdr(skb))) {
if (ip_vs_gather_frags(ipvs, skb, ip_vs_defrag_user(hooknum)))
return NF_STOLEN;
+ if (!ip_vs_fill_iph_skb(AF_INET, skb, false, iph))
+ return NF_ACCEPT;
}
- iph = ip_hdr(skb);
- offset = ihl = iph->ihl * 4;
+ ihl = iph->len;
+ offset = iph->len;
ic = skb_header_pointer(skb, offset, sizeof(_icmph), &_icmph);
if (ic == NULL)
return NF_DROP;
IP_VS_DBG(12, "Incoming ICMP (%d,%d) %pI4->%pI4\n",
ic->type, ntohs(icmp_id(ic)),
- &iph->saddr, &iph->daddr);
+ &iph->saddr.ip, &iph->daddr.ip);
/*
* Work through seeing if this is for us.
@@ -1903,7 +1900,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
!ip_vs_checksum_common_check(skb, ihl, IPPROTO_ICMP, AF_INET)) {
/* Failed checksum! */
IP_VS_DBG(1, "Incoming ICMP: failed checksum from %pI4!\n",
- &iph->saddr);
+ &iph->saddr.ip);
goto out;
}
@@ -1974,7 +1971,8 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
if (IPPROTO_TCP == cih->protocol || IPPROTO_UDP == cih->protocol ||
IPPROTO_SCTP == cih->protocol)
offset += 2 * sizeof(__u16);
- verdict = ip_vs_icmp_xmit(skb, cp, pp, offset, hooknum, &ciph);
+ verdict = ip_vs_icmp_xmit(skb, cp, pp, iph->len, offset, hooknum,
+ &ciph);
out:
if (likely(!new_cp))
@@ -2087,7 +2085,8 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
IPPROTO_SCTP == ciph.protocol)
offset += 2 * sizeof(__u16); /* Also mangle ports */
- verdict = ip_vs_icmp_xmit_v6(skb, cp, pp, offset, hooknum, &ciph);
+ verdict = ip_vs_icmp_xmit_v6(skb, cp, pp, iph->len, offset, hooknum,
+ &ciph);
out:
if (likely(!new_cp))
@@ -2166,7 +2165,7 @@ ip_vs_in_hook(void *priv, struct sk_buff *skb, const struct nf_hook_state *state
if (unlikely(iph.protocol == IPPROTO_ICMP)) {
int related;
int verdict = ip_vs_in_icmp(ipvs, skb, &related,
- hooknum);
+ hooknum, &iph);
if (related)
return verdict;
@@ -2302,6 +2301,7 @@ ip_vs_forward_icmp(void *priv, struct sk_buff *skb,
const struct nf_hook_state *state)
{
struct netns_ipvs *ipvs = net_ipvs(state->net);
+ struct ip_vs_iphdr iphdr;
int r;
/* ipvs enabled in this netns ? */
@@ -2311,10 +2311,9 @@ ip_vs_forward_icmp(void *priv, struct sk_buff *skb,
if (state->pf == NFPROTO_IPV4) {
if (ip_hdr(skb)->protocol != IPPROTO_ICMP)
return NF_ACCEPT;
+ ip_vs_fill_iph_skb(AF_INET, skb, false, &iphdr);
#ifdef CONFIG_IP_VS_IPV6
} else {
- struct ip_vs_iphdr iphdr;
-
ip_vs_fill_iph_skb(AF_INET6, skb, false, &iphdr);
if (iphdr.protocol != IPPROTO_ICMPV6)
@@ -2324,7 +2323,7 @@ ip_vs_forward_icmp(void *priv, struct sk_buff *skb,
#endif
}
- return ip_vs_in_icmp(ipvs, skb, &r, state->hook);
+ return ip_vs_in_icmp(ipvs, skb, &r, state->hook, &iphdr);
}
static const struct nf_hook_ops ip_vs_ops4[] = {
diff --git a/net/netfilter/ipvs/ip_vs_proto_sctp.c b/net/netfilter/ipvs/ip_vs_proto_sctp.c
index f6f732b7dfa86..3dbd3096e1637 100644
--- a/net/netfilter/ipvs/ip_vs_proto_sctp.c
+++ b/net/netfilter/ipvs/ip_vs_proto_sctp.c
@@ -121,7 +121,7 @@ sctp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
payload_csum = true;
}
- sctph = (void *) skb_network_header(skb) + sctphoff;
+ sctph = (void *)skb->data + sctphoff;
/* Only update csum if we really have to */
if (sctph->source != cp->vport || payload_csum ||
@@ -169,7 +169,7 @@ sctp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
payload_csum = true;
}
- sctph = (void *) skb_network_header(skb) + sctphoff;
+ sctph = (void *)skb->data + sctphoff;
/* Only update csum if we really have to */
if (sctph->dest != cp->dport || payload_csum ||
diff --git a/net/netfilter/ipvs/ip_vs_proto_tcp.c b/net/netfilter/ipvs/ip_vs_proto_tcp.c
index 533fce3e5e4e4..99a286fdc90c6 100644
--- a/net/netfilter/ipvs/ip_vs_proto_tcp.c
+++ b/net/netfilter/ipvs/ip_vs_proto_tcp.c
@@ -179,7 +179,7 @@ tcp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
payload_csum = true;
}
- tcph = (void *)skb_network_header(skb) + tcphoff;
+ tcph = (void *)skb->data + tcphoff;
tcph->source = cp->vport;
/* Adjust TCP checksums */
@@ -260,7 +260,7 @@ tcp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
payload_csum = true;
}
- tcph = (void *)skb_network_header(skb) + tcphoff;
+ tcph = (void *)skb->data + tcphoff;
tcph->dest = cp->dport;
/*
diff --git a/net/netfilter/ipvs/ip_vs_proto_udp.c b/net/netfilter/ipvs/ip_vs_proto_udp.c
index de3597347542e..f32785682402d 100644
--- a/net/netfilter/ipvs/ip_vs_proto_udp.c
+++ b/net/netfilter/ipvs/ip_vs_proto_udp.c
@@ -170,7 +170,7 @@ udp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
payload_csum = true;
}
- udph = (void *)skb_network_header(skb) + udphoff;
+ udph = (void *)skb->data + udphoff;
udph->source = cp->vport;
/*
@@ -254,7 +254,7 @@ udp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
payload_csum = true;
}
- udph = (void *)skb_network_header(skb) + udphoff;
+ udph = (void *)skb->data + udphoff;
udph->dest = cp->dport;
/*
diff --git a/net/netfilter/ipvs/ip_vs_xmit.c b/net/netfilter/ipvs/ip_vs_xmit.c
index 9fef4335da13f..c23401c789de3 100644
--- a/net/netfilter/ipvs/ip_vs_xmit.c
+++ b/net/netfilter/ipvs/ip_vs_xmit.c
@@ -1502,8 +1502,9 @@ ip_vs_dr_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
*/
int
ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
- struct ip_vs_protocol *pp, int offset, unsigned int hooknum,
- struct ip_vs_iphdr *iph)
+ struct ip_vs_protocol *pp, unsigned int toff,
+ unsigned int wlen, unsigned int hooknum,
+ struct ip_vs_iphdr *ciph)
{
struct rtable *rt; /* Route to the other host */
int rc;
@@ -1515,7 +1516,7 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
translate address/port back */
if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ) {
if (cp->packet_xmit)
- rc = cp->packet_xmit(skb, cp, pp, iph);
+ rc = cp->packet_xmit(skb, cp, pp, ciph);
else
rc = NF_ACCEPT;
/* do not touch skb anymore */
@@ -1533,7 +1534,7 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
IP_VS_RT_MODE_LOCAL | IP_VS_RT_MODE_NON_LOCAL |
IP_VS_RT_MODE_RDR : IP_VS_RT_MODE_NON_LOCAL;
local = __ip_vs_get_out_rt(cp->ipvs, cp->af, skb, cp->dest, cp->daddr.ip, rt_mode,
- NULL, iph);
+ NULL, ciph);
if (local < 0)
goto tx_error;
rt = skb_rtable(skb);
@@ -1565,13 +1566,13 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
}
/* copy-on-write the packet before mangling it */
- if (skb_ensure_writable(skb, offset))
+ if (skb_ensure_writable(skb, wlen))
goto tx_error;
if (skb_cow(skb, rt->dst.dev->hard_header_len))
goto tx_error;
- ip_vs_nat_icmp(skb, pp, cp, 0);
+ ip_vs_nat_icmp(skb, pp, cp, 0, toff);
/* Another hack: avoid icmp_send in ip_fragment */
skb->ignore_df = 1;
@@ -1587,8 +1588,9 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
#ifdef CONFIG_IP_VS_IPV6
int
ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
- struct ip_vs_protocol *pp, int offset, unsigned int hooknum,
- struct ip_vs_iphdr *ipvsh)
+ struct ip_vs_protocol *pp, unsigned int toff,
+ unsigned int wlen, unsigned int hooknum,
+ struct ip_vs_iphdr *ciph)
{
struct rt6_info *rt; /* Route to the other host */
int rc;
@@ -1600,7 +1602,7 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
translate address/port back */
if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ) {
if (cp->packet_xmit)
- rc = cp->packet_xmit(skb, cp, pp, ipvsh);
+ rc = cp->packet_xmit(skb, cp, pp, ciph);
else
rc = NF_ACCEPT;
/* do not touch skb anymore */
@@ -1617,7 +1619,7 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
IP_VS_RT_MODE_LOCAL | IP_VS_RT_MODE_NON_LOCAL |
IP_VS_RT_MODE_RDR : IP_VS_RT_MODE_NON_LOCAL;
local = __ip_vs_get_out_rt_v6(cp->ipvs, cp->af, skb, cp->dest,
- &cp->daddr.in6, NULL, ipvsh, 0, rt_mode);
+ &cp->daddr.in6, NULL, ciph, 0, rt_mode);
if (local < 0)
goto tx_error;
rt = dst_rt6_info(skb_dst(skb));
@@ -1649,13 +1651,13 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
}
/* copy-on-write the packet before mangling it */
- if (skb_ensure_writable(skb, offset))
+ if (skb_ensure_writable(skb, wlen))
goto tx_error;
if (skb_cow(skb, rt->dst.dev->hard_header_len))
goto tx_error;
- ip_vs_nat_icmp_v6(skb, pp, cp, 0);
+ ip_vs_nat_icmp_v6(skb, pp, cp, 0, toff, ciph);
/* Another hack: avoid icmp_send in ip_fragment */
skb->ignore_df = 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 061/438] ipvs: do not mangle ICMP replies for non-first fragments
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 060/438] ipvs: fix places with wrong packet offsets Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 062/438] ipvs: clear the nfct flag under lock Greg Kroah-Hartman
` (390 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Anastasov, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit 342e24a339b90e8e339a0f8c151ca479b8565661 ]
Sashiko warns that ip_vs_nat_icmp() unconditionally mangles the
payload for embedded non-first IPv4 fragments. The problem is
in the very old inverted pp->dont_defrag check which should not
continue when embedded is a non-first TCP/UDP/SCTP fragment.
Check for embedded non-first fragment is also missing from
ip_vs_out_icmp_v6(), it is needed before any connection
lookups that expect ports after the network headers.
Drop the blocking code from ip_vs_in_icmp_v6() which prevents
ICMPv6 from local clients to use non-MASQ forwarding.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Link: https://sashiko.dev/#/patchset/20260720201122.79882-1-ja%40ssi.bg
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip_vs.h | 11 +++---
net/netfilter/ipvs/ip_vs_core.c | 61 ++++++++++++---------------------
net/netfilter/ipvs/ip_vs_xmit.c | 28 +++++++++++----
3 files changed, 48 insertions(+), 52 deletions(-)
diff --git a/include/net/ip_vs.h b/include/net/ip_vs.h
index 7b556ce03602e..8d98f7e0a9fb2 100644
--- a/include/net/ip_vs.h
+++ b/include/net/ip_vs.h
@@ -1953,8 +1953,7 @@ int ip_vs_dr_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, struct ip_vs_iphdr *iph);
int ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, unsigned int toff,
- unsigned int wlen, unsigned int hooknum,
- struct ip_vs_iphdr *ciph);
+ unsigned int hooknum, struct ip_vs_iphdr *ciph);
void ip_vs_dest_dst_rcu_free(struct rcu_head *head);
#ifdef CONFIG_IP_VS_IPV6
@@ -1968,8 +1967,7 @@ int ip_vs_dr_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, struct ip_vs_iphdr *iph);
int ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, unsigned int toff,
- unsigned int wlen, unsigned int hooknum,
- struct ip_vs_iphdr *ciph);
+ unsigned int hooknum, struct ip_vs_iphdr *ciph);
#endif
#ifdef CONFIG_SYSCTL
@@ -2041,12 +2039,13 @@ static inline bool ip_vs_conn_use_hash2(struct ip_vs_conn *cp)
}
void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
- struct ip_vs_conn *cp, int dir, unsigned int toff);
+ struct ip_vs_conn *cp, int dir, unsigned int toff,
+ bool has_ports);
#ifdef CONFIG_IP_VS_IPV6
void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
struct ip_vs_conn *cp, int dir, unsigned int toff,
- struct ip_vs_iphdr *ciph);
+ bool has_ports, struct ip_vs_iphdr *ciph);
#endif
static inline __wsum ip_vs_check_diff4(__be32 old, __be32 new, __wsum oldsum)
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index cd5eb71543ec8..7efa209a517b1 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -924,7 +924,8 @@ static int ip_vs_route_me_harder(struct netns_ipvs *ipvs, int af,
* - inout: 1=in->out, 0=out->in
*/
void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
- struct ip_vs_conn *cp, int inout, unsigned int toff)
+ struct ip_vs_conn *cp, int inout, unsigned int toff,
+ bool has_ports)
{
struct iphdr *iph = ip_hdr(skb);
struct icmphdr *icmph = (struct icmphdr *)(skb->data + toff);
@@ -944,8 +945,7 @@ void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
}
/* the TCP/UDP/SCTP port */
- if (IPPROTO_TCP == ciph->protocol || IPPROTO_UDP == ciph->protocol ||
- IPPROTO_SCTP == ciph->protocol) {
+ if (has_ports) {
__be16 *ports = (void *)ciph + ciph->ihl*4;
if (inout)
@@ -970,18 +970,15 @@ void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
#ifdef CONFIG_IP_VS_IPV6
void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
struct ip_vs_conn *cp, int inout, unsigned int toff,
- struct ip_vs_iphdr *ciph)
+ bool has_ports, struct ip_vs_iphdr *ciph)
{
struct ipv6hdr *iph = ipv6_hdr(skb);
- int protocol;
struct icmp6hdr *icmph;
struct ipv6hdr *cih;
icmph = (struct icmp6hdr *)(skb->data + toff);
cih = (struct ipv6hdr *)(skb->data + ciph->off);
- protocol = ciph->protocol;
-
if (inout) {
iph->saddr = cp->vaddr.in6;
cih->daddr = cp->vaddr.in6;
@@ -991,9 +988,7 @@ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
}
/* the TCP/UDP/SCTP port */
- if (!ciph->fragoffs &&
- (protocol == IPPROTO_TCP || protocol == IPPROTO_UDP ||
- protocol == IPPROTO_SCTP)) {
+ if (has_ports) {
__be16 *ports = (void *)(skb->data + ciph->len);
IP_VS_DBG(11, "%s() changed port %d to %d\n", __func__,
@@ -1035,6 +1030,7 @@ static int handle_response_icmp(int af, struct sk_buff *skb,
int iproto = af == AF_INET6 ? IPPROTO_ICMPV6 : IPPROTO_ICMP;
unsigned int verdict = NF_DROP;
unsigned int ctoff = ciph->len;
+ bool has_ports = false;
if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ)
goto after_nat;
@@ -1048,17 +1044,19 @@ static int handle_response_icmp(int af, struct sk_buff *skb,
}
if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
- ciph->protocol == IPPROTO_SCTP)
+ ciph->protocol == IPPROTO_SCTP) {
ctoff += 2 * sizeof(__u16);
+ has_ports = true;
+ }
if (skb_ensure_writable(skb, ctoff))
goto out;
#ifdef CONFIG_IP_VS_IPV6
if (af == AF_INET6)
- ip_vs_nat_icmp_v6(skb, pp, cp, 1, toff, ciph);
+ ip_vs_nat_icmp_v6(skb, pp, cp, 1, toff, has_ports, ciph);
else
#endif
- ip_vs_nat_icmp(skb, pp, cp, 1, toff);
+ ip_vs_nat_icmp(skb, pp, cp, 1, toff, has_ports);
if (ip_vs_route_me_harder(cp->ipvs, af, skb, hooknum))
goto out;
@@ -1142,8 +1140,7 @@ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
return NF_ACCEPT;
/* Is the embedded protocol header present? */
- if (unlikely(cih->frag_off & htons(IP_OFFSET) &&
- pp->dont_defrag))
+ if (unlikely(cih->frag_off & htons(IP_OFFSET) && !pp->dont_defrag))
return NF_ACCEPT;
IP_VS_DBG_PKT(11, AF_INET, pp, skb, offset,
@@ -1207,6 +1204,10 @@ static int ip_vs_out_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
if (!pp)
return NF_ACCEPT;
+ /* Is the embedded protocol header present? */
+ if (unlikely(ciph.fragoffs && !pp->dont_defrag))
+ return NF_ACCEPT;
+
/* The embedded headers contain source and dest in reverse order */
cp = INDIRECT_CALL_1(pp->conn_out_get, ip_vs_conn_out_get_proto,
ipvs, AF_INET6, skb, &ciph);
@@ -1865,8 +1866,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
pp = pd->pp;
/* Is the embedded protocol header present? */
- if (unlikely(cih->frag_off & htons(IP_OFFSET) &&
- pp->dont_defrag))
+ if (unlikely(cih->frag_off & htons(IP_OFFSET) && !pp->dont_defrag))
return NF_ACCEPT;
IP_VS_DBG_PKT(11, AF_INET, pp, skb, offset,
@@ -1874,7 +1874,6 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
offset2 = offset;
ip_vs_fill_iph_skb_icmp(AF_INET, skb, offset, !tunnel, &ciph);
- offset = ciph.len;
/* The embedded headers contain source and dest in reverse order.
* For IPIP/UDP/GRE tunnel this is error for request, not for reply.
@@ -1968,11 +1967,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
/* do the statistics and put it back */
ip_vs_in_stats(cp, skb);
- if (IPPROTO_TCP == cih->protocol || IPPROTO_UDP == cih->protocol ||
- IPPROTO_SCTP == cih->protocol)
- offset += 2 * sizeof(__u16);
- verdict = ip_vs_icmp_xmit(skb, cp, pp, iph->len, offset, hooknum,
- &ciph);
+ verdict = ip_vs_icmp_xmit(skb, cp, pp, iph->len, hooknum, &ciph);
out:
if (likely(!new_cp))
@@ -2032,8 +2027,8 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
return NF_ACCEPT;
pp = pd->pp;
- /* Cannot handle fragmented embedded protocol */
- if (ciph.fragoffs)
+ /* Is the embedded protocol header present? */
+ if (ciph.fragoffs && !pp->dont_defrag)
return NF_ACCEPT;
IP_VS_DBG_PKT(11, AF_INET6, pp, skb, offset,
@@ -2057,13 +2052,6 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
new_cp = true;
}
- /* VS/TUN, VS/DR and LOCALNODE just let it go */
- if ((hooknum == NF_INET_LOCAL_OUT) &&
- (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ)) {
- verdict = NF_ACCEPT;
- goto out;
- }
-
verdict = NF_DROP;
/* Ensure the checksum is correct */
@@ -2079,14 +2067,7 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
/* do the statistics and put it back */
ip_vs_in_stats(cp, skb);
- /* Need to mangle contained IPv6 header in ICMPv6 packet */
- offset = ciph.len;
- if (IPPROTO_TCP == ciph.protocol || IPPROTO_UDP == ciph.protocol ||
- IPPROTO_SCTP == ciph.protocol)
- offset += 2 * sizeof(__u16); /* Also mangle ports */
-
- verdict = ip_vs_icmp_xmit_v6(skb, cp, pp, iph->len, offset, hooknum,
- &ciph);
+ verdict = ip_vs_icmp_xmit_v6(skb, cp, pp, iph->len, hooknum, &ciph);
out:
if (likely(!new_cp))
diff --git a/net/netfilter/ipvs/ip_vs_xmit.c b/net/netfilter/ipvs/ip_vs_xmit.c
index c23401c789de3..0b0c5304993a9 100644
--- a/net/netfilter/ipvs/ip_vs_xmit.c
+++ b/net/netfilter/ipvs/ip_vs_xmit.c
@@ -1503,13 +1503,14 @@ ip_vs_dr_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
int
ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, unsigned int toff,
- unsigned int wlen, unsigned int hooknum,
- struct ip_vs_iphdr *ciph)
+ unsigned int hooknum, struct ip_vs_iphdr *ciph)
{
struct rtable *rt; /* Route to the other host */
int rc;
int local;
int rt_mode, was_input;
+ bool has_ports = false;
+ unsigned int wlen;
/* The ICMP packet for VS/TUN, VS/DR and LOCALNODE will be
forwarded directly here, because there is no need to
@@ -1565,6 +1566,13 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
goto tx_error;
}
+ wlen = ciph->len;
+ if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
+ ciph->protocol == IPPROTO_SCTP) {
+ wlen += 2 * sizeof(__u16); /* Also mangle ports */
+ has_ports = true;
+ }
+
/* copy-on-write the packet before mangling it */
if (skb_ensure_writable(skb, wlen))
goto tx_error;
@@ -1572,7 +1580,7 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
if (skb_cow(skb, rt->dst.dev->hard_header_len))
goto tx_error;
- ip_vs_nat_icmp(skb, pp, cp, 0, toff);
+ ip_vs_nat_icmp(skb, pp, cp, 0, toff, has_ports);
/* Another hack: avoid icmp_send in ip_fragment */
skb->ignore_df = 1;
@@ -1589,10 +1597,11 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
int
ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
struct ip_vs_protocol *pp, unsigned int toff,
- unsigned int wlen, unsigned int hooknum,
- struct ip_vs_iphdr *ciph)
+ unsigned int hooknum, struct ip_vs_iphdr *ciph)
{
+ bool has_ports = false;
struct rt6_info *rt; /* Route to the other host */
+ unsigned int wlen;
int rc;
int local;
int rt_mode;
@@ -1650,6 +1659,13 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
goto tx_error;
}
+ wlen = ciph->len;
+ if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
+ ciph->protocol == IPPROTO_SCTP) {
+ wlen += 2 * sizeof(__u16); /* Also mangle ports */
+ has_ports = true;
+ }
+
/* copy-on-write the packet before mangling it */
if (skb_ensure_writable(skb, wlen))
goto tx_error;
@@ -1657,7 +1673,7 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
if (skb_cow(skb, rt->dst.dev->hard_header_len))
goto tx_error;
- ip_vs_nat_icmp_v6(skb, pp, cp, 0, toff, ciph);
+ ip_vs_nat_icmp_v6(skb, pp, cp, 0, toff, has_ports, ciph);
/* Another hack: avoid icmp_send in ip_fragment */
skb->ignore_df = 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 062/438] ipvs: clear the nfct flag under lock
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 061/438] ipvs: do not mangle ICMP replies for non-first fragments Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 063/438] netfilter: nft_payload: fix mask build for partial field offload Greg Kroah-Hartman
` (389 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Anastasov, Pablo Neira Ayuso,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit da7d894c41d5910daae2b8ffa024c52ff0a4df6a ]
Sashiko warns that cp->flags should be changed under cp->lock
Fixes: 35dfb013149f ("ipvs: queue delayed work to expire no destination connections if expire_nodest_conn=1")
Fixes: f0a5e4d7a594 ("ipvs: allow connection reuse for unconfirmed conntrack")
Link: https://sashiko.dev/#/patchset/CALMqdkR704S2BG_QD_bgHTFp2%2B1QCi7n0T4zoZyTo8mDZevYSA%40mail.gmail.com
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/ipvs/ip_vs_core.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index 7efa209a517b1..6b79e0c4d9e28 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -2194,8 +2194,11 @@ ip_vs_in_hook(void *priv, struct sk_buff *skb, const struct nf_hook_state *state
}
if (resched) {
- if (!old_ct)
+ if (!old_ct) {
+ spin_lock_bh(&cp->lock);
cp->flags &= ~IP_VS_CONN_F_NFCT;
+ spin_unlock_bh(&cp->lock);
+ }
if (!atomic_read(&cp->n_control))
ip_vs_conn_expire_now(cp);
__ip_vs_conn_put(cp);
@@ -2211,8 +2214,11 @@ ip_vs_in_hook(void *priv, struct sk_buff *skb, const struct nf_hook_state *state
if (sysctl_expire_nodest_conn(ipvs)) {
bool old_ct = ip_vs_conn_uses_old_conntrack(cp, skb);
- if (!old_ct)
+ if (!old_ct) {
+ spin_lock_bh(&cp->lock);
cp->flags &= ~IP_VS_CONN_F_NFCT;
+ spin_unlock_bh(&cp->lock);
+ }
ip_vs_conn_expire_now(cp);
__ip_vs_conn_put(cp);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 063/438] netfilter: nft_payload: fix mask build for partial field offload
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 062/438] ipvs: clear the nfct flag under lock Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 064/438] ASoC: SDCA: Correct pointer passed to devm_acpi_table_put Greg Kroah-Hartman
` (388 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AutonomousCodeSecurity,
Xiang Mei (Microsoft), Pablo Neira Ayuso, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei (Microsoft) <xmei5@asu.edu>
[ Upstream commit 39e88f28fb32bf02bd4b525c24c842c9cff5663d ]
nft_payload_offload_mask() builds the offload match mask for a payload
expression that covers only part of a header field. For a partial IPv6
address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which
is undefined on the 32-bit int operand. It also trims only one word, so
the remaining words stay 0xffffffff (and when priv_len is a multiple of 4
the trim is skipped entirely), leaving the mask covering more bytes than
the rule matches.
UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20
shift exponent 120 is too large for 32-bit type 'int'
...
The match is byte-granular and struct nft_data is zero-initialised, so the
correct mask is simply the first priv_len bytes set to 0xff. Set those
bytes directly and drop the word/shift trimming; this removes the undefined
shift and no longer over-masks the trailing bytes.
Fixes: a5d45bc0dc50 ("netfilter: nftables_offload: build mask based from the matching bytes")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_payload.c | 12 +-----------
1 file changed, 1 insertion(+), 11 deletions(-)
diff --git a/net/netfilter/nft_payload.c b/net/netfilter/nft_payload.c
index 4438d05f8018c..8ffa864a2195a 100644
--- a/net/netfilter/nft_payload.c
+++ b/net/netfilter/nft_payload.c
@@ -259,9 +259,7 @@ static int nft_payload_dump(struct sk_buff *skb,
static bool nft_payload_offload_mask(struct nft_offload_reg *reg,
u32 priv_len, u32 field_len)
{
- unsigned int remainder, delta, k;
struct nft_data mask = {};
- __be32 remainder_mask;
if (priv_len == field_len) {
memset(®->mask, 0xff, priv_len);
@@ -270,15 +268,7 @@ static bool nft_payload_offload_mask(struct nft_offload_reg *reg,
return false;
}
- memset(&mask, 0xff, field_len);
- remainder = priv_len % sizeof(u32);
- if (remainder) {
- k = priv_len / sizeof(u32);
- delta = field_len - priv_len;
- remainder_mask = htonl(~((1 << (delta * BITS_PER_BYTE)) - 1));
- mask.data[k] = (__force u32)remainder_mask;
- }
-
+ memset(&mask, 0xff, priv_len);
memcpy(®->mask, &mask, field_len);
return true;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 064/438] ASoC: SDCA: Correct pointer passed to devm_acpi_table_put
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 063/438] netfilter: nft_payload: fix mask build for partial field offload Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 065/438] ASoC: SDCA: Always free firmware in FDL path Greg Kroah-Hartman
` (387 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Charles Keepax, Pierre-Louis Bossart,
Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 6a50332e194f58b562d396ab772c34e8c9890c0f ]
devm_acpi_table_put() takes a struct acpi_table_header * but the value
passed in is struct acpi_table_header ** so the value passed to
acpi_put_table() is actually the pointer not the table itself.
Remove the extra reference to correct the passed value.
Fixes: c4d096c3ca42 ("ASoC: SDCA: Add SDCA FDL data parsing")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260722103500.872714-2-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sdca/sdca_device.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/sdca/sdca_device.c b/sound/soc/sdca/sdca_device.c
index 405e80b979de8..4bcd8d1fdff82 100644
--- a/sound/soc/sdca/sdca_device.c
+++ b/sound/soc/sdca/sdca_device.c
@@ -43,7 +43,7 @@ void sdca_lookup_swft(struct sdw_slave *slave)
dev_info(&slave->dev, "SWFT not available\n");
else
devm_add_action_or_reset(&slave->dev, devm_acpi_table_put,
- &slave->sdca_data.swft);
+ slave->sdca_data.swft);
}
EXPORT_SYMBOL_NS(sdca_lookup_swft, "SND_SOC_SDCA");
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 065/438] ASoC: SDCA: Always free firmware in FDL path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 064/438] ASoC: SDCA: Correct pointer passed to devm_acpi_table_put Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 066/438] ASoC: SDCA: Make UMP message size check more robust Greg Kroah-Hartman
` (386 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Charles Keepax, Pierre-Louis Bossart,
Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 7f64ccc374b2fe1f6a169182e95ab8e104cae406 ]
In the case a disk firmware exists but is invalid and no SWFT firmware
exists fdl_load_file() will return without calling release_firmware().
Update the code to call this to ensure the firmware is released on the
error path.
Fixes: 71f7990a34cd ("ASoC: SDCA: Add FDL library for XU entities")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260722103500.872714-3-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sdca/sdca_fdl.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/sound/soc/sdca/sdca_fdl.c b/sound/soc/sdca/sdca_fdl.c
index 994821a6df617..60fdd406220d4 100644
--- a/sound/soc/sdca/sdca_fdl.c
+++ b/sound/soc/sdca/sdca_fdl.c
@@ -258,7 +258,8 @@ static int fdl_load_file(struct sdca_interrupt *interrupt,
if (!swf) {
dev_err(dev, "failed to locate SWF\n");
- return -ENOENT;
+ ret = -ENOENT;
+ goto error;
}
dev_info(dev, "loading SWF: %x-%x-%x\n",
@@ -270,6 +271,8 @@ static int fdl_load_file(struct sdca_interrupt *interrupt,
SDCA_CTL_XU_FDL_MESSAGEOFFSET, fdl_file->fdl_offset,
SDCA_CTL_XU_FDL_MESSAGELENGTH, swf->data,
swf->file_length - offsetof(struct acpi_sw_file, data));
+
+error:
release_firmware(firmware);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 066/438] ASoC: SDCA: Make UMP message size check more robust
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 065/438] ASoC: SDCA: Always free firmware in FDL path Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 067/438] ASoC: SDCA: Ensure that Control Range is large enough for header Greg Kroah-Hartman
` (385 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Charles Keepax, Pierre-Louis Bossart,
Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 556d872e7c2a0b570c5b0974813847ef0d0cd637 ]
If message offset was larger than the buffer length the size
check will pass incorrectly. Refactor the check such that it is
more robust to invalid sizes.
Fixes: daab108504be ("ASoC: SDCA: Add UMP buffer helper functions")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260722103500.872714-4-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sdca/sdca_ump.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/soc/sdca/sdca_ump.c b/sound/soc/sdca/sdca_ump.c
index a86bb28c6d0ad..82a8bf75bbca5 100644
--- a/sound/soc/sdca/sdca_ump.c
+++ b/sound/soc/sdca/sdca_ump.c
@@ -141,7 +141,7 @@ int sdca_ump_read_message(struct device *dev,
return ret;
}
- if (msg_len > buf_len - msg_offset) {
+ if (msg_offset + msg_len > buf_len) {
dev_err(dev, "%s: message too big for UMP buffer: %d\n",
entity->label, msg_len);
return -EINVAL;
@@ -207,7 +207,7 @@ int sdca_ump_write_message(struct device *dev,
buf_len = sdca_range(range, SDCA_MESSAGEOFFSET_BUFFER_LENGTH, 0);
ump_mode = sdca_range(range, SDCA_MESSAGEOFFSET_UMP_MODE, 0);
- if (msg_len > buf_len - msg_offset) {
+ if (msg_offset + msg_len > buf_len) {
dev_err(dev, "%s: message too big for UMP buffer: %d\n",
entity->label, msg_len);
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 067/438] ASoC: SDCA: Ensure that Control Range is large enough for header
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 066/438] ASoC: SDCA: Make UMP message size check more robust Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 068/438] rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() Greg Kroah-Hartman
` (384 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Charles Keepax, Pierre-Louis Bossart,
Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 951e921b039b793bef7050eaf5c5fb1a4a5341d1 ]
When reading the Ranges structure from an SDCA Control, ensure that the
read data is large enough to encompass the required header before
accessing it.
Fixes: 64fb5af1d1bb ("ASoC: SDCA: Add parsing for Control range structures")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260722103500.872714-5-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sdca/sdca_functions.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/soc/sdca/sdca_functions.c b/sound/soc/sdca/sdca_functions.c
index 196bade11ab5d..ecc372a397573 100644
--- a/sound/soc/sdca/sdca_functions.c
+++ b/sound/soc/sdca/sdca_functions.c
@@ -847,6 +847,8 @@ static int find_sdca_control_range(struct device *dev,
return 0;
else if (num_range < 0)
return num_range;
+ else if (num_range < 2 * sizeof(*limits))
+ return -EINVAL;
range_list = devm_kcalloc(dev, num_range, sizeof(*range_list), GFP_KERNEL);
if (!range_list)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 068/438] rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 067/438] ASoC: SDCA: Ensure that Control Range is large enough for header Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 069/438] nexthop: take nh->lock for f6i_list walks in replace check and notify Greg Kroah-Hartman
` (383 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei,
Allison Henderson, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 78f75d632f74b8de0f081a128588f7c37d0d1164 ]
rds_tcp_laddr_check() looks up a scoped IPv6 interface with
dev_get_by_index_rcu(), drops the RCU read-side lock, and only then
passes the bare struct net_device * into ipv6_chk_addr().
dev_get_by_index_rcu() only keeps the device alive within the same RCU
read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can
free the net_device; ipv6_chk_addr() then dereferences the stale pointer
in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading
freed memory.
Keep the RCU read-side lock held across the ipv6_chk_addr() call instead
of dropping it right after the lookup, so the device cannot be freed
while it is in use.
BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
Read of size 8 at addr ffff8880106ec000 by task exploit/153
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
__ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)
rds_tcp_laddr_check (net/rds/tcp.c:370)
rds_bind (net/rds/bind.c:248)
__sys_bind (net/socket.c:1920)
__x64_sys_bind (net/socket.c:1956)
do_syscall_64 (arch/x86/entry/syscall_64.c:63)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Fixes: eee2fa6ab322 ("rds: Changing IP address internal representation to struct in6_addr")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260722210203.565803-1-xmei5@asu.edu
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/tcp.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/net/rds/tcp.c b/net/rds/tcp.c
index 76f441cbf50e6..c20dc6d5ca65d 100644
--- a/net/rds/tcp.c
+++ b/net/rds/tcp.c
@@ -336,23 +336,25 @@ int rds_tcp_laddr_check(struct net *net, const struct in6_addr *addr,
/* If the scope_id is specified, check only those addresses
* hosted on the specified interface.
*/
+ rcu_read_lock();
if (scope_id != 0) {
- rcu_read_lock();
dev = dev_get_by_index_rcu(net, scope_id);
/* scope_id is not valid... */
if (!dev) {
rcu_read_unlock();
return -EADDRNOTAVAIL;
}
- rcu_read_unlock();
}
#if IS_ENABLED(CONFIG_IPV6)
if (ipv6_mod_enabled()) {
ret = ipv6_chk_addr(net, addr, dev, 0);
- if (ret)
+ if (ret) {
+ rcu_read_unlock();
return 0;
+ }
}
#endif
+ rcu_read_unlock();
return -EADDRNOTAVAIL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 069/438] nexthop: take nh->lock for f6i_list walks in replace check and notify
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 068/438] rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 070/438] nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush Greg Kroah-Hartman
` (382 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AutonomousCodeSecurity,
Xiang Mei (Microsoft), Ido Schimmel, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei (Microsoft) <xmei5@asu.edu>
[ Upstream commit 072cd1f21819dedd2252e704d255de3b0cfc61a7 ]
fib6_check_nh_list() and __nexthop_replace_notify() walk nh->f6i_list
during an RTNL-serialized nexthop replace without holding nh->lock. IPv6
RTM_NEWROUTE/RTM_DELROUTE run without RTNL and mutate that list under
nh->lock (fib6_add_rt2node_nh(), fib6_purge_rt()), so both walks race a
concurrent route delete that unlinks and frees a fib6_info:
BUG: KASAN: slab-use-after-free in rt6_fill_node.isra.0 (net/ipv6/route.c:5799)
Read of size 4 at addr ffff888014607e64 by task exploit/143
rt6_fill_node.isra.0 (net/ipv6/route.c:5799)
fib6_rt_update (net/ipv6/route.c:6412)
__nexthop_replace_notify (net/ipv4/nexthop.c:2542)
rtm_new_nexthop (net/ipv4/nexthop.c:2554)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
BUG: KASAN: slab-use-after-free in fib6_check_nh_list (net/ipv4/nexthop.c:1605)
Read of size 8 at addr ffff888014a7d068 by task exploit/142
fib6_check_nh_list (net/ipv4/nexthop.c:1605)
rtm_new_nexthop (net/ipv4/nexthop.c:2575)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
Both walks only read the entries and take no tb6_lock, so protect them
with nh->lock; fib6_rt_update() uses gfp_any(), which returns GFP_ATOMIC
under the lock.
Fixes: 081efd18326e ("ipv6: Protect nh->f6i_list with spinlock and flag.")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260722002951.2614721-1-xmei5@asu.edu
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/nexthop.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c
index dc95a3d6e899e..8b1f3382a998a 100644
--- a/net/ipv4/nexthop.c
+++ b/net/ipv4/nexthop.c
@@ -1597,14 +1597,21 @@ static int fib6_check_nh_list(struct nexthop *old, struct nexthop *new,
struct netlink_ext_ack *extack)
{
struct fib6_info *f6i;
+ int err = 0;
if (list_empty(&old->f6i_list))
return 0;
+ spin_lock_bh(&old->lock);
list_for_each_entry(f6i, &old->f6i_list, nh_list) {
- if (check_src_addr(&f6i->fib6_src.addr, extack) < 0)
- return -EINVAL;
+ err = check_src_addr(&f6i->fib6_src.addr, extack);
+ if (err)
+ break;
}
+ spin_unlock_bh(&old->lock);
+
+ if (err)
+ return err;
return fib6_check_nexthop(new, NULL, extack);
}
@@ -2521,8 +2528,10 @@ static void __nexthop_replace_notify(struct net *net, struct nexthop *nh,
fi->nh_updated = false;
}
+ spin_lock_bh(&nh->lock);
list_for_each_entry(f6i, &nh->f6i_list, nh_list)
fib6_rt_update(net, f6i, info);
+ spin_unlock_bh(&nh->lock);
}
/* send RTM_NEWROUTE with REPLACE flag set for all FIB entries
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 070/438] nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 069/438] nexthop: take nh->lock for f6i_list walks in replace check and notify Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 071/438] af_unix: fix listen() succeeding on sockets in the wrong state Greg Kroah-Hartman
` (381 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AutonomousCodeSecurity,
Xiang Mei (Microsoft), Ido Schimmel, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei (Microsoft) <xmei5@asu.edu>
[ Upstream commit 4787a6d2629b4e8c0b6bacab1f75c1660eca44d9 ]
nh_rt_cache_flush() walks nh->f6i_list during an RTNL-serialized nexthop
replace without holding nh->lock, racing the unlocked IPv6 route
add/delete that mutate the list under nh->lock and free fib6_info
entries (nh_rt_cache_flush() is inlined into rtm_new_nexthop()):
BUG: KASAN: slab-use-after-free in nh_rt_cache_flush (net/ipv4/nexthop.c:2243)
Read of size 8 at addr ffff888012953e18 by task exploit/146
nh_rt_cache_flush (net/ipv4/nexthop.c:2243)
replace_nexthop (net/ipv4/nexthop.c:2610)
rtm_new_nexthop (net/ipv4/nexthop.c:3323)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
Unlike the other f6i_list walks, this one bumps each route's sernum via
fib6_update_sernum_upto_root(), which needs tb6_lock; taking nh->lock
around it would invert the established tb6_lock -> nh->lock order and
deadlock. As the only purpose is to invalidate cached dsts, bump the
IPv6 sernum for the whole netns with rt_genid_bump_ipv6() instead,
mirroring the rt_cache_flush() already done for IPv4 just above.
Fixes: 081efd18326e ("ipv6: Protect nh->f6i_list with spinlock and flag.")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260722002951.2614721-2-xmei5@asu.edu
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/nexthop.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c
index 8b1f3382a998a..1bfc429fc9607 100644
--- a/net/ipv4/nexthop.c
+++ b/net/ipv4/nexthop.c
@@ -2223,18 +2223,18 @@ static void remove_nexthop(struct net *net, struct nexthop *nh,
static void nh_rt_cache_flush(struct net *net, struct nexthop *nh,
struct nexthop *replaced_nh)
{
- struct fib6_info *f6i;
struct nh_group *nhg;
+ bool have_f6i;
int i;
if (!list_empty(&nh->fi_list))
rt_cache_flush(net);
- list_for_each_entry(f6i, &nh->f6i_list, nh_list) {
- spin_lock_bh(&f6i->fib6_table->tb6_lock);
- fib6_update_sernum_upto_root(net, f6i);
- spin_unlock_bh(&f6i->fib6_table->tb6_lock);
- }
+ spin_lock_bh(&nh->lock);
+ have_f6i = !list_empty(&nh->f6i_list);
+ spin_unlock_bh(&nh->lock);
+ if (have_f6i)
+ rt_genid_bump_ipv6(net);
/* if an IPv6 group was replaced, we have to release all old
* dsts to make sure all refcounts are released
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 071/438] af_unix: fix listen() succeeding on sockets in the wrong state
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 070/438] nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 072/438] selftests/net/af_unix: test listen() rejects wrong socket states Greg Kroah-Hartman
` (380 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Ericson, Jakub Kicinski,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ericson <mail@johnericson.me>
[ Upstream commit f0d9c3ffc2b5fc2ffacb56b3036155ce7a940a12 ]
Commit fd0a109a0f6b ("net, pidfs: prepare for handing out pidfds for
reaped sk->sk_peer_pid") inserted a prepare_peercred() call between err
= -EINVAL and the socket-state check in unix_listen(). Since
prepare_peercred() leaves err at 0 on success, listen() on an AF_UNIX
socket that is not in TCP_CLOSE or TCP_LISTEN state (e.g. one that is
already connected) now silently returns success without doing anything,
instead of failing with EINVAL as it did before.
Fixes: fd0a109a0f6b ("net, pidfs: prepare for handing out pidfds for reaped sk->sk_peer_pid")
Signed-off-by: John Ericson <mail@johnericson.me>
Link: https://patch.msgid.link/20260718182903.2295560-1-John.Ericson@Obsidian.Systems
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/unix/af_unix.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 0d9cd977c7b78..bb01d5371dc85 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -823,6 +823,7 @@ static int unix_listen(struct socket *sock, int backlog)
if (err)
goto out;
unix_state_lock(sk);
+ err = -EINVAL;
if (sk->sk_state != TCP_CLOSE && sk->sk_state != TCP_LISTEN)
goto out_unlock;
if (backlog > sk->sk_max_ack_backlog)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 072/438] selftests/net/af_unix: test listen() rejects wrong socket states
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 071/438] af_unix: fix listen() succeeding on sockets in the wrong state Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 073/438] xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx Greg Kroah-Hartman
` (379 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Ericson, Jakub Kicinski,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ericson <mail@johnericson.me>
[ Upstream commit 7f57c650d08b8793bb551bdb33ad876535ef9fe8 ]
Add a regression test for the unix_listen() state check. The key case is
listen() on a bound socket that has already been connected: it is no
longer in TCP_CLOSE or TCP_LISTEN, so it must fail with EINVAL. A
prepare_peercred() call slipped in ahead of that check once left err at 0
and made listen() silently succeed there instead; this guards against a
repeat.
The neighbouring outcomes are covered too so they cannot regress the same
way: a bound socket in TCP_CLOSE listens fine, calling listen() again on a
socket already in TCP_LISTEN is allowed, and an unbound socket fails with
EINVAL.
Each case runs for both listenable socket types (SOCK_STREAM and
SOCK_SEQPACKET) and both pathname and abstract addresses.
Fixes: fd0a109a0f6b ("net, pidfs: prepare for handing out pidfds for reaped sk->sk_peer_pid")
Signed-off-by: John Ericson <mail@johnericson.me>
Link: https://patch.msgid.link/20260718182903.2295560-2-John.Ericson@Obsidian.Systems
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../testing/selftests/net/af_unix/.gitignore | 1 +
tools/testing/selftests/net/af_unix/Makefile | 1 +
.../selftests/net/af_unix/unix_listen.c | 187 ++++++++++++++++++
3 files changed, 189 insertions(+)
create mode 100644 tools/testing/selftests/net/af_unix/unix_listen.c
diff --git a/tools/testing/selftests/net/af_unix/.gitignore b/tools/testing/selftests/net/af_unix/.gitignore
index 240b26740c9e0..9731766441036 100644
--- a/tools/testing/selftests/net/af_unix/.gitignore
+++ b/tools/testing/selftests/net/af_unix/.gitignore
@@ -6,3 +6,4 @@ scm_rights
so_peek_off
unix_connect
unix_connreset
+unix_listen
diff --git a/tools/testing/selftests/net/af_unix/Makefile b/tools/testing/selftests/net/af_unix/Makefile
index 4c0375e28bbee..57d159803a3ab 100644
--- a/tools/testing/selftests/net/af_unix/Makefile
+++ b/tools/testing/selftests/net/af_unix/Makefile
@@ -14,6 +14,7 @@ TEST_GEN_PROGS := \
so_peek_off \
unix_connect \
unix_connreset \
+ unix_listen \
# end of TEST_GEN_PROGS
include ../../lib.mk
diff --git a/tools/testing/selftests/net/af_unix/unix_listen.c b/tools/testing/selftests/net/af_unix/unix_listen.c
new file mode 100644
index 0000000000000..416fa3e5bfe9b
--- /dev/null
+++ b/tools/testing/selftests/net/af_unix/unix_listen.c
@@ -0,0 +1,187 @@
+// SPDX-License-Identifier: GPL-2.0
+/*
+ * Tests for the state checks in AF_UNIX listen().
+ *
+ * The central case is a regression test: listen() on a bound socket that
+ * is already connected (i.e. not in TCP_CLOSE or TCP_LISTEN state) must
+ * fail with EINVAL. A prior change accidentally let it return success
+ * without doing anything, because a helper called in between reset the
+ * error code to 0. The neighbouring checks (unbound, already listening)
+ * are tested too so they cannot silently regress the same way.
+ *
+ * Every case runs for both listenable socket types (SOCK_STREAM and
+ * SOCK_SEQPACKET) and both pathname and abstract addresses.
+ */
+#define _GNU_SOURCE
+
+#include <errno.h>
+#include <stddef.h>
+#include <stdio.h>
+#include <string.h>
+#include <unistd.h>
+
+#include <sys/socket.h>
+#include <sys/un.h>
+
+#include "kselftest_harness.h"
+
+#define SK_NAME "unix_listen_sk"
+#define SRV_NAME "unix_listen_srv"
+
+FIXTURE(unix_listen)
+{
+ int sk; /* socket under test */
+ int server; /* a listening peer, when a test needs one */
+ struct sockaddr_un addr, srv_addr;
+ socklen_t addrlen, srv_addrlen;
+};
+
+FIXTURE_VARIANT(unix_listen)
+{
+ int type;
+ int abstract;
+};
+
+FIXTURE_VARIANT_ADD(unix_listen, stream_pathname)
+{
+ .type = SOCK_STREAM,
+ .abstract = 0,
+};
+
+FIXTURE_VARIANT_ADD(unix_listen, stream_abstract)
+{
+ .type = SOCK_STREAM,
+ .abstract = 1,
+};
+
+FIXTURE_VARIANT_ADD(unix_listen, seqpacket_pathname)
+{
+ .type = SOCK_SEQPACKET,
+ .abstract = 0,
+};
+
+FIXTURE_VARIANT_ADD(unix_listen, seqpacket_abstract)
+{
+ .type = SOCK_SEQPACKET,
+ .abstract = 1,
+};
+
+/* Fill @addr with a pathname or abstract address named @name. */
+static socklen_t unix_set_addr(struct sockaddr_un *addr, const char *name,
+ int abstract)
+{
+ size_t len = strlen(name);
+
+ memset(addr, 0, sizeof(*addr));
+ addr->sun_family = AF_UNIX;
+ /* An abstract address leads with a NUL and has no filesystem entry. */
+ memcpy(addr->sun_path + (abstract ? 1 : 0), name, len);
+
+ return offsetof(struct sockaddr_un, sun_path) + len + 1;
+}
+
+FIXTURE_SETUP(unix_listen)
+{
+ self->sk = -1;
+ self->server = -1;
+ self->addrlen = unix_set_addr(&self->addr, SK_NAME, variant->abstract);
+ self->srv_addrlen = unix_set_addr(&self->srv_addr, SRV_NAME,
+ variant->abstract);
+}
+
+FIXTURE_TEARDOWN(unix_listen)
+{
+ if (self->sk >= 0)
+ close(self->sk);
+ if (self->server >= 0)
+ close(self->server);
+
+ /* Pathname sockets leave a filesystem entry behind; abstract ones do not. */
+ if (!variant->abstract) {
+ remove(SK_NAME);
+ remove(SRV_NAME);
+ }
+}
+
+/* A bound socket in TCP_CLOSE is the normal, allowed case. */
+TEST_F(unix_listen, bound_is_ok)
+{
+ int err;
+
+ self->sk = socket(AF_UNIX, variant->type, 0);
+ ASSERT_LE(0, self->sk);
+
+ err = bind(self->sk, (struct sockaddr *)&self->addr, self->addrlen);
+ ASSERT_EQ(0, err);
+
+ err = listen(self->sk, 8);
+ EXPECT_EQ(0, err);
+}
+
+/* Listening again on an already-listening socket (TCP_LISTEN) is allowed. */
+TEST_F(unix_listen, relisten_is_ok)
+{
+ int err;
+
+ self->sk = socket(AF_UNIX, variant->type, 0);
+ ASSERT_LE(0, self->sk);
+
+ err = bind(self->sk, (struct sockaddr *)&self->addr, self->addrlen);
+ ASSERT_EQ(0, err);
+
+ err = listen(self->sk, 8);
+ ASSERT_EQ(0, err);
+
+ err = listen(self->sk, 16);
+ EXPECT_EQ(0, err);
+}
+
+/* listen() on an unbound socket fails: there is nothing to listen on. */
+TEST_F(unix_listen, unbound_is_einval)
+{
+ int err;
+
+ self->sk = socket(AF_UNIX, variant->type, 0);
+ ASSERT_LE(0, self->sk);
+
+ err = listen(self->sk, 8);
+ EXPECT_EQ(-1, err);
+ EXPECT_EQ(EINVAL, errno);
+}
+
+/*
+ * The regression: a bound socket that has already been connected is not in
+ * TCP_CLOSE or TCP_LISTEN, so listen() must reject it with EINVAL rather
+ * than quietly succeeding.
+ */
+TEST_F(unix_listen, connected_is_einval)
+{
+ int err;
+
+ self->server = socket(AF_UNIX, variant->type, 0);
+ ASSERT_LE(0, self->server);
+
+ err = bind(self->server, (struct sockaddr *)&self->srv_addr,
+ self->srv_addrlen);
+ ASSERT_EQ(0, err);
+
+ err = listen(self->server, 8);
+ ASSERT_EQ(0, err);
+
+ self->sk = socket(AF_UNIX, variant->type, 0);
+ ASSERT_LE(0, self->sk);
+
+ /* Bind first so the unbound check does not mask the state check. */
+ err = bind(self->sk, (struct sockaddr *)&self->addr, self->addrlen);
+ ASSERT_EQ(0, err);
+
+ err = connect(self->sk, (struct sockaddr *)&self->srv_addr,
+ self->srv_addrlen);
+ ASSERT_EQ(0, err);
+
+ err = listen(self->sk, 8);
+ EXPECT_EQ(-1, err);
+ EXPECT_EQ(EINVAL, errno);
+}
+
+TEST_HARNESS_MAIN
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 073/438] xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 072/438] selftests/net/af_unix: test listen() rejects wrong socket states Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 074/438] xsk: drain continuation descs after overflow in xsk_build_skb() Greg Kroah-Hartman
` (378 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maciej Fijalkowski, Jason Xing,
Stanislav Fomichev, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Xing <kernelxing@tencent.com>
[ Upstream commit a3c8382ebce4780c6b3ace2c09bc342313ac0186 ]
This patch is inspired by the check[1] from sashiko. It says when
overflow happens, the address of cq to be published is invalid.
Actually the severer thing is the whole process of publishing the
address of cq in this particular case is not right: it should truely
publish the address and advance the cached_prod in cq as long as it
reads descriptors from txq.
The following is the full analysis.
xsk_drop_skb() is called in three places, which all discard a partially
built multi-buffer skb:
1) xsk_build_skb() -EOVERFLOW error path: packet exceeds MAX_SKB_FRAGS
2) __xsk_generic_xmit() post-loop cleanup: an invalid descriptor in
the TX ring prevents the partial packet from completing
3) xsk_release(): socket close while xs->skb holds an incomplete packet
In all three cases, the TX descriptors for the already-processed frags
have been consumed from the TX ring (xskq_cons_release), and CQ slots
have been reserved. However, xsk_drop_skb() calls xsk_consume_skb()
which cancels the CQ reservations via xsk_cq_cancel_locked(). Since
the buffer addresses never appear in the completion queue, userspace
permanently loses track of these buffers.
Fix this by letting consume_skb() trigger the existing xsk_destruct_skb
destructor, which already submits buffer addresses to the CQ via
xsk_cq_submit_addr_locked().
Note that cancelling the descriptors back to the TX ring (via
xskq_cons_cancel_n) is not a appropriate option because an oversized
packet that always exceeds MAX_SKB_FRAGS would be retried indefinitely,
which is an obviously deadlock bug in the TX path.
Also move the desc->addr assignment in xsk_build_skb() above the
overflow check so that the current descriptor's address is recorded
before a potential -EOVERFLOW jump to free_err, consistent with the
zerocopy path in xsk_build_skb_zerocopy().
[1]: https://lore.kernel.org/all/20260425041726.85FB3C2BCB2@smtp.kernel.org/
Fixes: cf24f5a5feea ("xsk: add support for AF_XDP multi-buffer on Tx path")
Acked-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Signed-off-by: Jason Xing <kernelxing@tencent.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Link: https://patch.msgid.link/20260719135609.147823-2-maciej.fijalkowski@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xdp/xsk.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/net/xdp/xsk.c b/net/xdp/xsk.c
index f8c8a8c9dfba5..0a6203c425766 100644
--- a/net/xdp/xsk.c
+++ b/net/xdp/xsk.c
@@ -793,8 +793,11 @@ static void xsk_consume_skb(struct sk_buff *skb)
static void xsk_drop_skb(struct sk_buff *skb)
{
- xdp_sk(skb->sk)->tx->invalid_descs += xsk_get_num_desc(skb);
- xsk_consume_skb(skb);
+ struct xdp_sock *xs = xdp_sk(skb->sk);
+
+ xs->tx->invalid_descs += xsk_get_num_desc(skb);
+ consume_skb(skb);
+ xs->skb = NULL;
}
static int xsk_skb_metadata(struct sk_buff *skb, void *buffer,
@@ -876,7 +879,7 @@ static struct sk_buff *xsk_build_skb_zerocopy(struct xdp_sock *xs,
return ERR_PTR(-ENOMEM);
/* in case of -EOVERFLOW that could happen below,
- * xsk_consume_skb() will release this node as whole skb
+ * xsk_drop_skb() will release this node as whole skb
* would be dropped, which implies freeing all list elements
*/
xsk_addr->addrs[xsk_addr->num_descs] = desc->addr;
@@ -968,6 +971,8 @@ static struct sk_buff *xsk_build_skb(struct xdp_sock *xs,
goto free_err;
}
+ xsk_addr->addrs[xsk_addr->num_descs] = desc->addr;
+
if (unlikely(nr_frags == (MAX_SKB_FRAGS - 1) && xp_mb_desc(desc))) {
err = -EOVERFLOW;
goto free_err;
@@ -985,8 +990,6 @@ static struct sk_buff *xsk_build_skb(struct xdp_sock *xs,
skb_add_rx_frag(skb, nr_frags, page, 0, len, PAGE_SIZE);
refcount_add(PAGE_SIZE, &xs->sk.sk_wmem_alloc);
-
- xsk_addr->addrs[xsk_addr->num_descs] = desc->addr;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 074/438] xsk: drain continuation descs after overflow in xsk_build_skb()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 073/438] xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 075/438] xsk: provide sufficient space in pool->tx_descs Greg Kroah-Hartman
` (377 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Xing, Maciej Fijalkowski,
Stanislav Fomichev, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Xing <kernelxing@tencent.com>
[ Upstream commit bd44a6dcd4248883de90f5dad53ae80066e27096 ]
Fix generic xmit path multi-buffer logic when packets are either too big
(count of descriptors exceed MAX_SKB_FRAGS) or an invalid descriptor is
included in fragmented packet. Introduce xdp_sock::drain_cont and act
upon this flag - when it is set, keep on consuming descriptors from
AF_XDP Tx ring and put them directly onto Cq. Previously these
descriptors were silently lost and could never be reached again.
Fixes: cf24f5a5feea ("xsk: add support for AF_XDP multi-buffer on Tx path")
Closes: https://lore.kernel.org/all/20260425041726.85FB3C2BCB2@smtp.kernel.org/
Reviewed-by: Jason Xing <kernelxing@tencent.com>
Co-developed-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com> # wrapped cq addr submission onto routine
Signed-off-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Signed-off-by: Jason Xing <kernelxing@tencent.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Link: https://patch.msgid.link/20260719135609.147823-3-maciej.fijalkowski@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/xdp_sock.h | 1 +
net/xdp/xsk.c | 45 +++++++++++++++++++++++++++++++++++++++---
2 files changed, 43 insertions(+), 3 deletions(-)
diff --git a/include/net/xdp_sock.h b/include/net/xdp_sock.h
index ebac60a3d8a17..8b51876efbed1 100644
--- a/include/net/xdp_sock.h
+++ b/include/net/xdp_sock.h
@@ -80,6 +80,7 @@ struct xdp_sock {
* call of __xsk_generic_xmit().
*/
struct sk_buff *skb;
+ bool drain_cont;
struct list_head map_list;
/* Protects map_list */
diff --git a/net/xdp/xsk.c b/net/xdp/xsk.c
index 0a6203c425766..8dadc39ca81f3 100644
--- a/net/xdp/xsk.c
+++ b/net/xdp/xsk.c
@@ -736,6 +736,19 @@ static void xsk_cq_submit_addr_locked(struct xsk_buff_pool *pool,
spin_unlock_irqrestore(&pool->cq_prod_lock, flags);
}
+static void xsk_cq_submit_addr_single_locked(struct xsk_buff_pool *pool,
+ struct xdp_desc *desc)
+{
+ unsigned long flags;
+ u32 idx;
+
+ spin_lock_irqsave(&pool->cq_prod_lock, flags);
+ idx = xskq_get_prod(pool->cq);
+ xskq_prod_write_addr(pool->cq, idx, desc->addr);
+ xskq_prod_submit_n(pool->cq, 1);
+ spin_unlock_irqrestore(&pool->cq_prod_lock, flags);
+}
+
static void xsk_cq_cancel_locked(struct xsk_buff_pool *pool, u32 n)
{
spin_lock(&pool->cq->cq_cached_prod_lock);
@@ -1027,13 +1040,14 @@ static struct sk_buff *xsk_build_skb(struct xdp_sock *xs,
static int __xsk_generic_xmit(struct sock *sk)
{
struct xdp_sock *xs = xdp_sk(sk);
- bool sent_frame = false;
struct xdp_desc desc;
struct sk_buff *skb;
+ u32 cached_cons;
u32 max_batch;
int err = 0;
mutex_lock(&xs->mutex);
+ cached_cons = xs->tx->cached_cons;
/* Since we dropped the RCU read lock, the socket state might have changed. */
if (unlikely(!xsk_is_bound(xs))) {
@@ -1062,11 +1076,21 @@ static int __xsk_generic_xmit(struct sock *sk)
goto out;
}
+ if (unlikely(xs->drain_cont)) {
+ xsk_cq_submit_addr_single_locked(xs->pool, &desc);
+ xs->tx->invalid_descs++;
+ xskq_cons_release(xs->tx);
+ xs->drain_cont = xp_mb_desc(&desc);
+ continue;
+ }
+
skb = xsk_build_skb(xs, &desc);
if (IS_ERR(skb)) {
err = PTR_ERR(skb);
if (err != -EOVERFLOW)
goto out;
+ if (xp_mb_desc(&desc))
+ xs->drain_cont = true;
err = 0;
continue;
}
@@ -1095,18 +1119,33 @@ static int __xsk_generic_xmit(struct sock *sk)
goto out;
}
- sent_frame = true;
xs->skb = NULL;
}
if (xskq_has_descs(xs->tx)) {
+ bool drain = xs->skb || xs->drain_cont || xp_mb_desc(&desc);
+
+ err = xsk_cq_reserve_locked(xs->pool);
+ if (err) {
+ xs->tx->invalid_descs--;
+ if (xs->skb)
+ xsk_drop_skb(xs->skb);
+ xs->drain_cont = drain;
+ err = -EAGAIN;
+ goto out;
+ }
+
if (xs->skb)
xsk_drop_skb(xs->skb);
+
+ xsk_cq_submit_addr_single_locked(xs->pool, &desc);
+
xskq_cons_release(xs->tx);
+ xs->drain_cont = xp_mb_desc(&desc);
}
out:
- if (sent_frame)
+ if (xs->tx->cached_cons != cached_cons)
__xsk_tx_release(xs);
mutex_unlock(&xs->mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 075/438] xsk: provide sufficient space in pool->tx_descs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 074/438] xsk: drain continuation descs after overflow in xsk_build_skb() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 076/438] xsk: reclaim invalid Tx descriptors in ZC batch path Greg Kroah-Hartman
` (376 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Xing, Maciej Fijalkowski,
Stanislav Fomichev, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
[ Upstream commit 08c9a8e794b4694c100dafcb80e069e29ad81b64 ]
The temporary Tx descriptor array in an XSK buffer pool is currently
sized from the Tx ring of the socket that creates the pool.
This is insufficient for shared-UMEM Tx. A later socket may have a
larger Tx ring and submit a valid multi-buffer packet containing more
descriptors than the first socket's ring, while still remaining within
the device's xdp_zc_max_segs limit.
A packet-framed batch parser bounded by the temporary array cannot reach
the end-of-packet descriptor in that case. It leaves the packet on the
Tx ring and encounters the same packet on every subsequent attempt,
stalling Tx processing for that socket.
Size the temporary descriptor array to the larger of the first Tx ring
and the device's xdp_zc_max_segs capability. This keeps the array large
enough to inspect one maximum-sized valid packet. Larger shared Tx rings
do not require further resizing, as they can be processed over multiple
batches.
Following commit will actually address the data path side.
Fixes: d5581966040f ("xsk: support ZC Tx multi-buffer in batch API")
Reviewed-by: Jason Xing <kernelxing@tencent.com>
Signed-off-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Link: https://patch.msgid.link/20260719135609.147823-4-maciej.fijalkowski@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/xsk_buff_pool.h | 6 ++++--
net/xdp/xsk.c | 10 +++++++---
net/xdp/xsk_buff_pool.c | 12 ++++++++----
3 files changed, 19 insertions(+), 9 deletions(-)
diff --git a/include/net/xsk_buff_pool.h b/include/net/xsk_buff_pool.h
index ccb3b350001f2..f5e737a830559 100644
--- a/include/net/xsk_buff_pool.h
+++ b/include/net/xsk_buff_pool.h
@@ -102,12 +102,14 @@ struct xsk_buff_pool {
/* AF_XDP core. */
struct xsk_buff_pool *xp_create_and_assign_umem(struct xdp_sock *xs,
- struct xdp_umem *umem);
+ struct xdp_umem *umem,
+ u32 max_segs);
int xp_assign_dev(struct xsk_buff_pool *pool, struct net_device *dev,
u16 queue_id, u16 flags);
int xp_assign_dev_shared(struct xsk_buff_pool *pool, struct xdp_sock *umem_xs,
struct net_device *dev, u16 queue_id);
-int xp_alloc_tx_descs(struct xsk_buff_pool *pool, struct xdp_sock *xs);
+int xp_alloc_tx_descs(struct xsk_buff_pool *pool, struct xdp_sock *xs,
+ u32 max_segs);
void xp_destroy(struct xsk_buff_pool *pool);
void xp_get_pool(struct xsk_buff_pool *pool);
bool xp_put_pool(struct xsk_buff_pool *pool);
diff --git a/net/xdp/xsk.c b/net/xdp/xsk.c
index 8dadc39ca81f3..161ec3d47f053 100644
--- a/net/xdp/xsk.c
+++ b/net/xdp/xsk.c
@@ -1524,7 +1524,8 @@ static int xsk_bind(struct socket *sock, struct sockaddr_unsized *addr, int addr
* and/or device.
*/
xs->pool = xp_create_and_assign_umem(xs,
- umem_xs->umem);
+ umem_xs->umem,
+ dev->xdp_zc_max_segs);
if (!xs->pool) {
err = -ENOMEM;
sockfd_put(sock);
@@ -1556,7 +1557,8 @@ static int xsk_bind(struct socket *sock, struct sockaddr_unsized *addr, int addr
* utilizes
*/
if (xs->tx && !xs->pool->tx_descs) {
- err = xp_alloc_tx_descs(xs->pool, xs);
+ err = xp_alloc_tx_descs(xs->pool, xs,
+ dev->xdp_zc_max_segs);
if (err) {
xp_put_pool(xs->pool);
xs->pool = NULL;
@@ -1574,7 +1576,9 @@ static int xsk_bind(struct socket *sock, struct sockaddr_unsized *addr, int addr
goto out_unlock;
} else {
/* This xsk has its own umem. */
- xs->pool = xp_create_and_assign_umem(xs, xs->umem);
+ xs->pool = xp_create_and_assign_umem(xs, xs->umem,
+ dev->xdp_zc_max_segs);
+
if (!xs->pool) {
err = -ENOMEM;
goto out_unlock;
diff --git a/net/xdp/xsk_buff_pool.c b/net/xdp/xsk_buff_pool.c
index d981cfdd85357..419dc0ffbf7ef 100644
--- a/net/xdp/xsk_buff_pool.c
+++ b/net/xdp/xsk_buff_pool.c
@@ -42,9 +42,12 @@ void xp_destroy(struct xsk_buff_pool *pool)
kvfree(pool);
}
-int xp_alloc_tx_descs(struct xsk_buff_pool *pool, struct xdp_sock *xs)
+int xp_alloc_tx_descs(struct xsk_buff_pool *pool, struct xdp_sock *xs,
+ u32 max_segs)
{
- pool->tx_descs = kvzalloc_objs(*pool->tx_descs, xs->tx->nentries);
+ u32 nentries = max(xs->tx->nentries, max_segs);
+
+ pool->tx_descs = kvzalloc_objs(*pool->tx_descs, nentries);
if (!pool->tx_descs)
return -ENOMEM;
@@ -52,7 +55,8 @@ int xp_alloc_tx_descs(struct xsk_buff_pool *pool, struct xdp_sock *xs)
}
struct xsk_buff_pool *xp_create_and_assign_umem(struct xdp_sock *xs,
- struct xdp_umem *umem)
+ struct xdp_umem *umem,
+ u32 max_segs)
{
bool unaligned = umem->flags & XDP_UMEM_UNALIGNED_CHUNK_FLAG;
struct xsk_buff_pool *pool;
@@ -69,7 +73,7 @@ struct xsk_buff_pool *xp_create_and_assign_umem(struct xdp_sock *xs,
goto out;
if (xs->tx)
- if (xp_alloc_tx_descs(pool, xs))
+ if (xp_alloc_tx_descs(pool, xs, max_segs))
goto out;
pool->chunk_mask = ~((u64)umem->chunk_size - 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 076/438] xsk: reclaim invalid Tx descriptors in ZC batch path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 075/438] xsk: provide sufficient space in pool->tx_descs Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 077/438] net/sched: sch_cake: skip clearing unused tins during rate adjustment Greg Kroah-Hartman
` (375 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Xing, Maciej Fijalkowski,
Stanislav Fomichev, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
[ Upstream commit 72f2b4516faf55d4dfac2414649d3cffa5fd2c5e ]
The zero-copy Tx batch parser stops when it encounters an invalid
descriptor. If this happens after one or more continuation descriptors,
the Tx consumer can be advanced past fragments that are neither submitted
to the driver nor returned to userspace through the completion ring.
A similar problem occurs when a packet exceeds xdp_zc_max_segs. The
descriptors consumed up to the limit are released without completion, and
the remaining continuation descriptors can subsequently be interpreted
as the beginning of another packet.
Parse Tx batches in packet units and distinguish descriptors belonging to
complete valid packets from descriptors consumed while draining an
invalid or oversized packet. Return the former to the driver and append
the latter to the CQ address area so userspace can reclaim their UMEM
frames.
Treat a standalone invalid descriptor as a one-descriptor reclaim-only
packet. Advancing the Tx-ring consumer releases the ring slot, but does
not by itself return ownership of the referenced UMEM frame to userspace.
Once draining starts, continue until the packet's end-of-packet
descriptor is consumed. Preserve the drain state on the socket when EOP
has not yet been supplied, so draining can continue during a later call.
Leave incomplete but otherwise valid packets on the Tx ring.
Shared-UMEM pools using multi-buffer Tx also need packet-framed parsing.
Walk their Tx sockets one packet at a time, preserving the existing
per-socket fairness scheme, instead of using the legacy one-descriptor
fallback. Keep that fallback for shared pools that do not use
multi-buffer Tx. Since the drain state is maintained per socket and both
the singular and shared paths can resume an interrupted drain, changing
the socket list from singular to shared requires no special bind-time
transition.
CQ entries are positional, and drivers may complete only part of the Tx
work returned by xsk_tx_peek_release_desc_batch(). Therefore, reclaim-only
entries cannot be published immediately when earlier driver-visible
descriptors are still outstanding.
Track the number of driver-visible CQ entries preceding the reclaim
entries. Let xsk_tx_completed() publish partial hardware Tx completions,
and publish the reclaim entries only after every earlier Tx descriptor
has completed. Complete a reclaim-only batch immediately when there is no
driver-visible work in front of it, and prevent another Tx batch from
being appended while reclaim entries remain pending.
Also cap batch processing by the size of the pool's temporary descriptor
array, as Tx rings belonging to sockets sharing a UMEM may have different
sizes.
This ensures that every invalid Tx descriptor consumed by the ZC batch
path is either submitted to the driver as part of a valid packet or
returned to userspace without violating CQ completion ordering.
Reviewed-by: Jason Xing <kernelxing@tencent.com>
Signed-off-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Fixes: cf24f5a5feea ("xsk: add support for AF_XDP multi-buffer on Tx path")
Link: https://patch.msgid.link/20260719135609.147823-5-maciej.fijalkowski@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/networking/af_xdp.rst | 54 ++++----
include/net/xsk_buff_pool.h | 3 +
net/xdp/xsk.c | 187 +++++++++++++++++++++++++---
net/xdp/xsk_buff_pool.c | 1 +
net/xdp/xsk_queue.h | 65 +++++++---
5 files changed, 248 insertions(+), 62 deletions(-)
diff --git a/Documentation/networking/af_xdp.rst b/Documentation/networking/af_xdp.rst
index 50d92084a49c6..cc3f0d16b28fb 100644
--- a/Documentation/networking/af_xdp.rst
+++ b/Documentation/networking/af_xdp.rst
@@ -43,12 +43,13 @@ UMEM also has two rings: the FILL ring and the COMPLETION ring. The
FILL ring is used by the application to send down addr for the kernel
to fill in with RX packet data. References to these frames will then
appear in the RX ring once each packet has been received. The
-COMPLETION ring, on the other hand, contains frame addr that the
-kernel has transmitted completely and can now be used again by user
-space, for either TX or RX. Thus, the frame addrs appearing in the
-COMPLETION ring are addrs that were previously transmitted using the
-TX ring. In summary, the RX and FILL rings are used for the RX path
-and the TX and COMPLETION rings are used for the TX path.
+COMPLETION ring, on the other hand, contains frame addresses from Tx
+descriptors that the kernel has finished processing and that can now be
+used again by user space, for either Tx or Rx. This includes frames whose
+transmission has completed as well as frames referenced by invalid Tx
+descriptors rejected by the kernel. A completion therefore returns
+ownership of a frame to user space, but does not by itself guarantee that
+the packet was successfully transmitted.
The socket is then finally bound with a bind() call to a device and a
specific queue id on that device, and it is not until bind is
@@ -169,14 +170,15 @@ chunks mode, then the incoming addr will be left untouched.
UMEM Completion Ring
~~~~~~~~~~~~~~~~~~~~
-The COMPLETION Ring is used transfer ownership of UMEM frames from
+The COMPLETION Ring is used to transfer ownership of UMEM frames from
kernel-space to user-space. Just like the FILL ring, UMEM indices are
-used.
-
-Frames passed from the kernel to user-space are frames that has been
-sent (TX ring) and can be used by user-space again.
-
-The user application consumes UMEM addrs from this ring.
+used. Frames passed from the kernel to user-space are frames referenced
+by Tx descriptors that the kernel has finished processing and can be
+used by user-space again. This includes both frames whose transmission
+has completed and frames referenced by invalid Tx descriptors that were
+rejected and reclaimed by the kernel. A completion entry does not
+guarantee successful packet transmission. The user application consumes
+UMEM addrs from this ring.
RX Ring
@@ -504,21 +506,25 @@ will be treated as an invalid descriptor.
These are the semantics for producing packets onto AF_XDP Tx ring
consisting of multiple frames:
-* When an invalid descriptor is found, all the other
- descriptors/frames of this packet are marked as invalid and not
- completed. The next descriptor is treated as the start of a new
- packet, even if this was not the intent (because we cannot guess
- the intent). As before, if your program is producing invalid
- descriptors you have a bug that must be fixed.
+* When an invalid descriptor is found, the complete packet is treated as
+ invalid. The kernel consumes descriptors through the descriptor marking
+ the end of the packet and returns all their frame addresses through the
+ COMPLETION ring. A standalone invalid descriptor is treated as a
+ one-descriptor invalid packet. The descriptor following the end of the
+ invalid packet is treated as the start of a new packet. As before, if
+ your program is producing invalid descriptors you have a bug that must
+ be fixed. Rejected descriptors are reported in the ``tx_invalid_descs``
+ statistic.
* Zero length descriptors are treated as invalid descriptors.
* For copy mode, the maximum supported number of frames in a packet is
- equal to CONFIG_MAX_SKB_FRAGS + 1. If it is exceeded, all
- descriptors accumulated so far are dropped and treated as
- invalid. To produce an application that will work on any system
- regardless of this config setting, limit the number of frags to 18,
- as the minimum value of the config is 17.
+ equal to CONFIG_MAX_SKB_FRAGS + 1. If it is exceeded, all descriptors
+ through the end of the oversized packet are consumed, treated as invalid,
+ and their frame addresses are returned through the COMPLETION ring. To
+ produce an application that will work on any system regardless of this
+ config setting, limit the number of frags to 18, as the minimum value of
+ the config is 17.
* For zero-copy mode, the limit is up to what the NIC HW
supports. Usually at least five on the NICs we have checked. We
diff --git a/include/net/xsk_buff_pool.h b/include/net/xsk_buff_pool.h
index f5e737a830559..2bb1d122b1bc6 100644
--- a/include/net/xsk_buff_pool.h
+++ b/include/net/xsk_buff_pool.h
@@ -78,6 +78,9 @@ struct xsk_buff_pool {
u32 chunk_size;
u32 chunk_shift;
u32 frame_len;
+ u32 tx_descs_nentries;
+ u32 reclaim_descs;
+ u32 tx_zc_pending_descs;
u32 xdp_zc_max_segs;
u8 tx_metadata_len; /* inherited from umem */
u8 cached_need_wakeup;
diff --git a/net/xdp/xsk.c b/net/xdp/xsk.c
index 161ec3d47f053..855fe92358bac 100644
--- a/net/xdp/xsk.c
+++ b/net/xdp/xsk.c
@@ -498,6 +498,23 @@ void __xsk_map_flush(struct list_head *flush_list)
void xsk_tx_completed(struct xsk_buff_pool *pool, u32 nb_entries)
{
+ u32 reclaim_descs = READ_ONCE(pool->reclaim_descs);
+
+ if (unlikely(reclaim_descs)) {
+ u32 pending_descs = READ_ONCE(pool->tx_zc_pending_descs);
+
+ if (nb_entries < pending_descs) {
+ WRITE_ONCE(pool->tx_zc_pending_descs,
+ pending_descs - nb_entries);
+ xskq_prod_submit_n(pool->cq, nb_entries);
+ return;
+ }
+
+ WRITE_ONCE(pool->tx_zc_pending_descs, 0);
+ nb_entries += reclaim_descs;
+ WRITE_ONCE(pool->reclaim_descs, 0);
+ }
+
xskq_prod_submit_n(pool->cq, nb_entries);
}
EXPORT_SYMBOL(xsk_tx_completed);
@@ -573,24 +590,157 @@ static u32 xsk_tx_peek_release_fallback(struct xsk_buff_pool *pool, u32 max_entr
return nb_pkts;
}
+static void xsk_tx_commit_batch(struct xsk_buff_pool *pool,
+ struct xsk_tx_batch *batch)
+{
+ u32 nb_descs = xsk_tx_batch_cq_descs(batch);
+ u32 cq_cached_prod;
+
+ if (!nb_descs)
+ return;
+
+ cq_cached_prod = pool->cq->cached_prod;
+ xskq_prod_write_addr_batch(pool->cq, pool->tx_descs, nb_descs);
+
+ if (unlikely(batch->reclaim_descs)) {
+ u32 cq_pending_descs;
+
+ /* CQ is positional. Descriptors already written but not
+ * submitted must complete before any reclaim-only descriptors
+ * appended below.
+ */
+ cq_pending_descs = cq_cached_prod - xskq_get_prod(pool->cq);
+
+ WRITE_ONCE(pool->tx_zc_pending_descs,
+ batch->tx_descs + cq_pending_descs);
+ WRITE_ONCE(pool->reclaim_descs, batch->reclaim_descs);
+ if (unlikely(!pool->tx_zc_pending_descs))
+ xsk_tx_completed(pool, 0);
+ }
+}
+
+static struct xsk_tx_batch
+__xsk_tx_peek_release_desc_batch(struct xsk_buff_pool *pool, struct xdp_sock *xs,
+ struct xdp_desc *descs, u32 max_descs)
+{
+ struct xsk_tx_batch batch = {};
+ u32 entries;
+
+ entries = xskq_cons_nb_entries(xs->tx, max_descs);
+ if (!entries)
+ return batch;
+
+ batch = xskq_cons_read_desc_batch(xs, pool, descs, max_descs);
+ if (!xsk_tx_batch_cq_descs(&batch)) {
+ xs->tx->queue_empty_descs++;
+ } else {
+ __xskq_cons_release(xs->tx);
+ xs->sk.sk_write_space(&xs->sk);
+ }
+ return batch;
+}
+
+static struct xsk_tx_batch
+xsk_tx_peek_release_shared_desc_batch(struct xsk_buff_pool *pool, u32 max_descs)
+{
+ u32 cq_descs_before, cq_descs_after;
+ struct xsk_tx_batch sum_batch = {};
+ bool budget_exhausted;
+ u32 per_socket_budget;
+ struct xdp_sock *xs;
+
+ /* The fairness quota must allow one maximum-sized valid packet. */
+ per_socket_budget = max_t(u32, MAX_PER_SOCKET_BUDGET,
+ pool->xdp_zc_max_segs);
+
+again:
+ budget_exhausted = false;
+ cq_descs_before = xsk_tx_batch_cq_descs(&sum_batch);
+ list_for_each_entry_rcu(xs, &pool->xsk_tx_list, tx_list) {
+ u32 budget, budget_left, offset, remaining, used;
+ struct xsk_tx_batch curr_batch;
+
+ /* Once reclaim-only descriptors have been appended to the CQ
+ * address area, do not append driver-visible Tx descriptors
+ * from another socket after them. xsk_tx_completed() relies on
+ * all driver-visible descriptors preceding all reclaim-only
+ * descriptors in CQ order.
+ */
+ if (sum_batch.reclaim_descs)
+ break;
+
+ /* be gentle when playing with pool->tx_descs */
+ offset = xsk_tx_batch_cq_descs(&sum_batch);
+ if (offset >= max_descs)
+ break;
+
+ if (xs->tx_budget_spent >= per_socket_budget) {
+ if (xskq_cons_nb_entries(xs->tx, 1))
+ budget_exhausted = true;
+ continue;
+ }
+
+ budget_left = per_socket_budget - xs->tx_budget_spent;
+ remaining = max_descs - offset;
+ budget = min(remaining, budget_left);
+
+ curr_batch = __xsk_tx_peek_release_desc_batch(pool, xs,
+ pool->tx_descs + offset,
+ budget);
+ used = xsk_tx_batch_cq_descs(&curr_batch);
+ if (!used) {
+ if (curr_batch.budget_limited && budget_left < remaining)
+ budget_exhausted = true;
+ continue;
+ }
+
+ xs->tx_budget_spent += used;
+ sum_batch.tx_descs += curr_batch.tx_descs;
+ sum_batch.reclaim_descs = curr_batch.reclaim_descs;
+ }
+
+ cq_descs_after = xsk_tx_batch_cq_descs(&sum_batch);
+
+ if (sum_batch.reclaim_descs || cq_descs_after >= max_descs)
+ return sum_batch;
+
+ /* Continue filling the batch while this pass made progress */
+ if (cq_descs_before != cq_descs_after)
+ goto again;
+
+ if (!budget_exhausted)
+ return sum_batch;
+
+ list_for_each_entry_rcu(xs, &pool->xsk_tx_list, tx_list)
+ xs->tx_budget_spent = 0;
+ goto again;
+}
+
u32 xsk_tx_peek_release_desc_batch(struct xsk_buff_pool *pool, u32 nb_pkts)
{
+ struct xsk_tx_batch batch = {};
struct xdp_sock *xs;
+ bool umem_shared;
rcu_read_lock();
- if (!list_is_singular(&pool->xsk_tx_list)) {
- /* Fallback to the non-batched version */
- rcu_read_unlock();
- return xsk_tx_peek_release_fallback(pool, nb_pkts);
- }
+ if (unlikely(READ_ONCE(pool->reclaim_descs)))
+ goto out;
- xs = list_first_or_null_rcu(&pool->xsk_tx_list, struct xdp_sock, tx_list);
- if (!xs) {
- nb_pkts = 0;
+ xs = list_first_or_null_rcu(&pool->xsk_tx_list, struct xdp_sock,
+ tx_list);
+ if (!xs)
goto out;
- }
- nb_pkts = xskq_cons_nb_entries(xs->tx, nb_pkts);
+ nb_pkts = min(nb_pkts, pool->tx_descs_nentries);
+ if (!nb_pkts)
+ goto out;
+
+ umem_shared = !list_is_singular(&pool->xsk_tx_list);
+
+ if (umem_shared && !(pool->umem->flags & XDP_UMEM_SG_FLAG)) {
+ rcu_read_unlock();
+ return xsk_tx_peek_release_fallback(pool, nb_pkts);
+ }
/* This is the backpressure mechanism for the Tx path. Try to
* reserve space in the completion queue for all packets, but
@@ -602,19 +752,16 @@ u32 xsk_tx_peek_release_desc_batch(struct xsk_buff_pool *pool, u32 nb_pkts)
if (!nb_pkts)
goto out;
- nb_pkts = xskq_cons_read_desc_batch(xs->tx, pool, nb_pkts);
- if (!nb_pkts) {
- xs->tx->queue_empty_descs++;
- goto out;
- }
-
- __xskq_cons_release(xs->tx);
- xskq_prod_write_addr_batch(pool->cq, pool->tx_descs, nb_pkts);
- xs->sk.sk_write_space(&xs->sk);
+ batch = umem_shared ?
+ xsk_tx_peek_release_shared_desc_batch(pool, nb_pkts) :
+ __xsk_tx_peek_release_desc_batch(pool, xs,
+ pool->tx_descs,
+ nb_pkts);
+ xsk_tx_commit_batch(pool, &batch);
out:
rcu_read_unlock();
- return nb_pkts;
+ return batch.tx_descs;
}
EXPORT_SYMBOL(xsk_tx_peek_release_desc_batch);
diff --git a/net/xdp/xsk_buff_pool.c b/net/xdp/xsk_buff_pool.c
index 419dc0ffbf7ef..4538223f44082 100644
--- a/net/xdp/xsk_buff_pool.c
+++ b/net/xdp/xsk_buff_pool.c
@@ -51,6 +51,7 @@ int xp_alloc_tx_descs(struct xsk_buff_pool *pool, struct xdp_sock *xs,
if (!pool->tx_descs)
return -ENOMEM;
+ pool->tx_descs_nentries = nentries;
return 0;
}
diff --git a/net/xdp/xsk_queue.h b/net/xdp/xsk_queue.h
index 3e3fbb73d23e2..1bc42c8902f4b 100644
--- a/net/xdp/xsk_queue.h
+++ b/net/xdp/xsk_queue.h
@@ -58,6 +58,17 @@ struct parsed_desc {
u32 valid;
};
+struct xsk_tx_batch {
+ u32 tx_descs;
+ u32 reclaim_descs;
+ bool budget_limited;
+};
+
+static inline u32 xsk_tx_batch_cq_descs(const struct xsk_tx_batch *batch)
+{
+ return batch->tx_descs + batch->reclaim_descs;
+}
+
/* The structure of the shared state of the rings are a simple
* circular buffer, as outlined in
* Documentation/core-api/circular-buffers.rst. For the Rx and
@@ -263,17 +274,18 @@ static inline void parse_desc(struct xsk_queue *q, struct xsk_buff_pool *pool,
parsed->mb = xp_mb_desc(desc);
}
-static inline
-u32 xskq_cons_read_desc_batch(struct xsk_queue *q, struct xsk_buff_pool *pool,
- u32 max)
+static inline struct xsk_tx_batch
+xskq_cons_read_desc_batch(struct xdp_sock *xs, struct xsk_buff_pool *pool,
+ struct xdp_desc *descs, u32 max)
{
- u32 cached_cons = q->cached_cons, nb_entries = 0;
- struct xdp_desc *descs = pool->tx_descs;
- u32 total_descs = 0, nr_frags = 0;
+ bool drain = READ_ONCE(xs->drain_cont);
+ u32 cached_cons, nb_entries = 0;
+ struct xsk_tx_batch batch = {};
+ struct xsk_queue *q = xs->tx;
+ u32 nr_frags = 0;
+
+ cached_cons = q->cached_cons;
- /* track first entry, if stumble upon *any* invalid descriptor, rewind
- * current packet that consists of frags and stop the processing
- */
while (cached_cons != q->cached_prod && nb_entries < max) {
struct xdp_rxtx_ring *ring = (struct xdp_rxtx_ring *)q->ring;
u32 idx = cached_cons & q->ring_mask;
@@ -283,25 +295,42 @@ u32 xskq_cons_read_desc_batch(struct xsk_queue *q, struct xsk_buff_pool *pool,
cached_cons++;
parse_desc(q, pool, &descs[nb_entries], &parsed);
if (unlikely(!parsed.valid))
- break;
+ drain = true;
+
+ nr_frags++;
+ nb_entries++;
if (likely(!parsed.mb)) {
- total_descs += (nr_frags + 1);
- nr_frags = 0;
- } else {
- nr_frags++;
- if (nr_frags == pool->xdp_zc_max_segs) {
+ if (unlikely(drain)) {
+ batch.reclaim_descs = nr_frags;
+ WRITE_ONCE(xs->drain_cont, false);
nr_frags = 0;
break;
}
+
+ batch.tx_descs += nr_frags;
+ nr_frags = 0;
+ continue;
+ }
+
+ if (nr_frags == pool->xdp_zc_max_segs)
+ drain = true;
+ }
+
+ if (nr_frags) {
+ if (drain) {
+ batch.reclaim_descs = nr_frags;
+ WRITE_ONCE(xs->drain_cont, true);
+ } else {
+ if (nb_entries == max)
+ batch.budget_limited = true;
+ cached_cons -= nr_frags;
}
- nb_entries++;
}
- cached_cons -= nr_frags;
/* Release valid plus any invalid entries */
xskq_cons_release_n(q, cached_cons - q->cached_cons);
- return total_descs;
+ return batch;
}
/* Functions for consumers */
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 077/438] net/sched: sch_cake: skip clearing unused tins during rate adjustment
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 076/438] xsk: reclaim invalid Tx descriptors in ZC batch path Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 078/438] pinctrl-amd: Dont clear S4 wake bits at probe Greg Kroah-Hartman
` (374 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jonas Köppeler, Mike Pham,
Toke Høiland-Jørgensen, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonas Köppeler <j.koeppeler@tu-berlin.de>
[ Upstream commit a3729e0df005a936ceb3c2b0d167f01a2b03f970 ]
When cake_configure_rates() is called from the dequeue path with
rate_adjust=true, it only needs to update the rate parameters. The
loop that clears the unused tins is both unnecessary and harmful in
this path:
- cake_clear_tin() overwrites q->cur_tin and q->cur_flow, which are
actively used by cake_dequeue(), corrupting the dequeue state.
- iterating over the unused tins and their internal queues to purge
packets adds needless overhead to the hot path.
Skip the entire loop when rate_adjust is set, as neither
cake_clear_tin() nor the mtu_time update are needed when only the
rate changes.
The clearing loop runs on every rate adjustment from the dequeue path,
clearing (max_tins - cur_tins) tins each time, so the cost grows the
fewer tins the configured mode actually uses. Testing cake_mq over veth
(8 rx/tx queues, 2 Gbit limit) with flent's [1] rrul and tcp_nup tests and
32 TCP upstreams shows a large drop in loaded latency and a throughput
gain, restoring behaviour to pre-15c2715a5264 levels:
+------------+------+------+-------+-------+---------+
| kernel | mode | test | base | load | tput |
| | | | (ms) | (ms) | (Mbit) |
+------------+------+------+-------+-------+---------+
| net-next | be | rrul | 0.810 | 11.78 | 1469.67 |
| net-next | be | nup | 0.637 | 85.71 | 1243.15 |
| net-next | ds3 | rrul | 0.397 | 15.28 | 1770.06 |
| net-next | ds3 | nup | 0.351 | 15.98 | 1799.39 |
+------------+------+------+-------+-------+---------+
| patched | be | rrul | 0.092 | 0.56 | 1873.40 |
| patched | be | nup | 0.109 | 1.82 | 1869.12 |
| patched | ds3 | rrul | 0.097 | 0.98 | 1866.10 |
| patched | ds3 | nup | 0.101 | 0.51 | 1861.79 |
+------------+------+------+-------+-------+---------+
The same trend holds on real hardware (IPQ8074A, 4 rx/tx queues,
OpenWrt): in besteffort mode the tcp_nup loaded latency drops from
~470 ms to ~4 ms.
[1] https://flent.org
Fixes: 15c2715a5264 ("net/sched: sch_cake: fixup cake_mq rate adjustment for diffserv config")
Signed-off-by: Jonas Köppeler <j.koeppeler@tu-berlin.de>
Tested-by: Mike Pham <mikepham4321@gmail.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/20260720-sch_cake-skip-clearing-tins-v2-1-e6a8b0275c73@tu-berlin.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_cake.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/net/sched/sch_cake.c b/net/sched/sch_cake.c
index b967b7153ad34..8965fe252471c 100644
--- a/net/sched/sch_cake.c
+++ b/net/sched/sch_cake.c
@@ -2609,9 +2609,11 @@ static void cake_configure_rates(struct Qdisc *sch, u64 rate, bool rate_adjust)
break;
}
- for (c = qd->tin_cnt; c < CAKE_MAX_TINS; c++) {
- cake_clear_tin(sch, c);
- qd->tins[c].cparams.mtu_time = qd->tins[ft].cparams.mtu_time;
+ if (!rate_adjust) {
+ for (c = qd->tin_cnt; c < CAKE_MAX_TINS; c++) {
+ cake_clear_tin(sch, c);
+ qd->tins[c].cparams.mtu_time = qd->tins[ft].cparams.mtu_time;
+ }
}
qd->rate_ns = qd->tins[ft].tin_rate_ns;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 078/438] pinctrl-amd: Dont clear S4 wake bits at probe
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 077/438] net/sched: sch_cake: skip clearing unused tins during rate adjustment Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 079/438] scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer Greg Kroah-Hartman
` (373 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello, Linus Walleij,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
[ Upstream commit ffe8a0c6b55285ceaf2f42fc20c3a0594d14f1e9 ]
commit 6bc3462a0f5e ("pinctrl: amd: Mask wake bits on probe again")
introduced a regression where Wake-on-LAN no longer works after suspend
or shutdown on some AMD platforms.
Firmware-programmed S4 wake bits for devices like PCIe NICs using PCI
PME are cleared at probe, but nothing restores them. Unlike S0i3/S3 wake
sources that use enable_irq_wake() -> amd_gpio_irq_set_wake(), PCIe PME
does not use GPIO IRQ infrastructure and relies on firmware configuration.
The original intent of commit 6bc3462a0f5e ("pinctrl: amd: Mask wake
bits on probe again") was to clear spurious wake bits left by firmware
to prevent unwanted wakeups. However, S4 wake bits are used for
hardware-level wake sources like WoL that bypass the kernel's IRQ wake
API.
Fix by preserving S4 wake bits at probe and only clearing S0i3/S3 bits:
- Firmware-configured S4 wake sources (WoL) continue working
- Kernel maintains control of S3/S0i3 wake policy via set_wake()
- S3-only wake sources work correctly per commit f31f33dbb3ba ("pinctrl:
amd: Take suspend type into consideration which pins are non-wake")
The trade-off is that firmware-programmed spurious S4 wake bits remain
set, but this is less problematic than breaking WoL.
Fixes: 6bc3462a0f5e ("pinctrl: amd: Mask wake bits on probe again")
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/pinctrl-amd.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/pinctrl/pinctrl-amd.c b/drivers/pinctrl/pinctrl-amd.c
index e3128b0045d22..15a398bb3be23 100644
--- a/drivers/pinctrl/pinctrl-amd.c
+++ b/drivers/pinctrl/pinctrl-amd.c
@@ -884,8 +884,7 @@ static void amd_gpio_irq_init(struct amd_gpio *gpio_dev)
u32 pin_reg, mask;
int i;
- mask = BIT(WAKE_CNTRL_OFF_S0I3) | BIT(WAKE_CNTRL_OFF_S3) |
- BIT(WAKE_CNTRL_OFF_S4);
+ mask = BIT(WAKE_CNTRL_OFF_S0I3) | BIT(WAKE_CNTRL_OFF_S3);
for (i = 0; i < desc->npins; i++) {
int pin = desc->pins[i].number;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 079/438] scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 078/438] pinctrl-amd: Dont clear S4 wake bits at probe Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 080/438] scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer Greg Kroah-Hartman
` (372 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI, HyeongJun An,
Chris Leech, Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit 98b87885de4b7f605533a2860685f5689fce8e82 ]
iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the
target-supplied data segment. The segment carries a 2-byte sense length
followed by the sense bytes, so it must hold 2 + senselen bytes, but the
bounds check only requires datalen >= senselen:
senselen = get_unaligned_be16(data);
if (datalen < senselen)
goto invalid_datalen;
memcpy(sc->sense_buffer, data + 2,
min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));
A target that returns a SCSI Response whose datalen equals senselen
(with senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data +
2 read up to two bytes past the received data. Those bytes are stale
conn->data contents and end up in the command's sense buffer, which is
returned to userspace.
Account for the 2-byte sense length prefix in the check.
Fixes: 7996a778ff8c ("[SCSI] iscsi: add libiscsi")
Suggested-by: Sashiko AI <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Acked-by: Chris Leech <cleech@redhat.com>
Link: https://patch.msgid.link/20260714104934.1404423-1-sammiee5311@gmail.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/libiscsi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
index 25857d6ed6e84..1b4e6af37c927 100644
--- a/drivers/scsi/libiscsi.c
+++ b/drivers/scsi/libiscsi.c
@@ -918,7 +918,7 @@ static void iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
}
senselen = get_unaligned_be16(data);
- if (datalen < senselen)
+ if (datalen < senselen + 2)
goto invalid_datalen;
memcpy(sc->sense_buffer, data + 2,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 080/438] scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 079/438] scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 081/438] scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race Greg Kroah-Hartman
` (371 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Leech, HyeongJun An,
Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit c1dea15f819cded9b3faf58f8bec72323568b6e6 ]
iscsi_tcp_hdr_dissect() receives the data segment of several PDU types
into the fixed-size conn->data buffer, which is allocated for
ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP,
REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU
whose DataSegmentLength exceeds that buffer.
The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its
data segment (sense/response data) into conn->data via
iscsi_tcp_data_recv_prep(), but it does so without the same check. The
only upstream bound on in.datalen is conn->max_recv_dlength, the
initiator's advertised MaxRecvDataSegmentLength, which is commonly
negotiated well above 8192 (open-iscsi defaults to 262144). A target
that returns a SCSI Response with a DataSegmentLength between 8193 and
max_recv_dlength therefore overflows the 8192-byte conn->data buffer.
Once the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly
like those responses: bound the data segment, receive it into conn->data
when present, and otherwise complete the PDU with no data. Fold the
opcode into that case group rather than duplicating the check.
Fixes: a081c13e39b5 ("[SCSI] iscsi_tcp: split module into lib and lld")
Suggested-by: Chris Leech <cleech@redhat.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Acked-by: Chris Leech <cleech@redhat.com>
Link: https://patch.msgid.link/20260716065848.1653431-1-sammiee5311@gmail.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/libiscsi_tcp.c | 8 +-------
1 file changed, 1 insertion(+), 7 deletions(-)
diff --git a/drivers/scsi/libiscsi_tcp.c b/drivers/scsi/libiscsi_tcp.c
index e90805ba868fb..7223bb18b0480 100644
--- a/drivers/scsi/libiscsi_tcp.c
+++ b/drivers/scsi/libiscsi_tcp.c
@@ -752,13 +752,6 @@ iscsi_tcp_hdr_dissect(struct iscsi_conn *conn, struct iscsi_hdr *hdr)
rc = __iscsi_complete_pdu(conn, hdr, NULL, 0);
spin_unlock(&conn->session->back_lock);
break;
- case ISCSI_OP_SCSI_CMD_RSP:
- if (tcp_conn->in.datalen) {
- iscsi_tcp_data_recv_prep(tcp_conn);
- return 0;
- }
- rc = iscsi_complete_pdu(conn, hdr, NULL, 0);
- break;
case ISCSI_OP_R2T:
if (ahslen) {
rc = ISCSI_ERR_AHSLEN;
@@ -766,6 +759,7 @@ iscsi_tcp_hdr_dissect(struct iscsi_conn *conn, struct iscsi_hdr *hdr)
}
rc = iscsi_tcp_r2t_rsp(conn, hdr);
break;
+ case ISCSI_OP_SCSI_CMD_RSP:
case ISCSI_OP_LOGIN_RSP:
case ISCSI_OP_TEXT_RSP:
case ISCSI_OP_REJECT:
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 081/438] scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 080/438] scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 082/438] smb: client: fix buffer leaks in SMB1 read and write Greg Kroah-Hartman
` (370 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xingui Yang, John Garry,
Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xingui Yang <yangxingui@huawei.com>
[ Upstream commit 3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845 ]
Commit fbefe22811c3 ("scsi: libsas: Don't always drain event workqueue
for HA resume") introduced sas_resume_ha_no_sync() to avoid a deadlock:
the PHYE_RESUME_TIMEOUT handler, running on the HA event workqueue,
calls sas_deform_port() -> sas_destruct_devices(), which removes SCSI
devices and waits for the host to become runtime-active. But the host
cannot resume until sas_resume_ha() -> sas_drain_work() returns, and the
drain is blocked on that very handler.
However skipping the drain reintroduces a race: hisi_sas returns from
resume before all PHY UP work and libsas discovery work finish. The
controller may then autosuspend while disks are still waking up. The
disks issue IO to a suspended controller, the IO fails, and the disks
get disabled.
Fix the deadlock at its source by moving the PHYE_RESUME_TIMEOUT
notification to after sas_drain_work(). By then the host resume is about
to complete, so device removal through device_link no longer blocks on
the resume and the cycle is broken.
With the deadlock gone, restore sas_resume_ha() (the draining variant)
in hisi_sas and remove sas_resume_ha_no_sync().
The reorder is safe for the other libsas consumers (isci, pm8001,
aic94xx, mvsas). During suspend, sas_suspend_devices() calls
sas_notify_lldd_dev_gone() for each device, which sets dev->lldd_dev to
NULL. When scsi_unblock_requests re-enables I/O in resume, any I/O to a
timed-out phy's disk is immediately rejected by the LLDD before reaching
hardware: isci returns SAS_DEVICE_UNKNOWN (mapped to DID_BAD_TARGET),
and pm8001 returns SAS_PHY_DOWN (mapped to DID_NO_CONNECT). Both
complete directly via scsi_done() without entering SCSI EH. This is
identical in both the old and new ordering since lldd_dev_gone runs
during suspend, before resume. The reorder only affects when the
PHYE_RESUME_TIMEOUT handler runs (synchronized by sas_drain_work()
vs. asynchronous after resume returns), not whether I/O can reach the
device. aic94xx and mvsas do not register any PM ops and never reach
this code path.
Fixes: fbefe22811c3 ("scsi: libsas: Don't always drain event workqueue for HA resume")
Signed-off-by: Xingui Yang <yangxingui@huawei.com>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260716081145.3950172-1-yangxingui@huawei.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/hisi_sas/hisi_sas_v3_hw.c | 10 +------
drivers/scsi/libsas/sas_init.c | 37 +++++++++++++-------------
include/scsi/libsas.h | 1 -
3 files changed, 19 insertions(+), 29 deletions(-)
diff --git a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
index 213d5b5dea94f..8a2500993e19d 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
@@ -5261,15 +5261,7 @@ static int _resume_v3_hw(struct device *device)
return rc;
}
phys_init_v3_hw(hisi_hba);
-
- /*
- * If a directly-attached disk is removed during suspend, a deadlock
- * may occur, as the PHYE_RESUME_TIMEOUT processing will require the
- * hisi_hba->device to be active, which can only happen when resume
- * completes. So don't wait for the HA event workqueue to drain upon
- * resume.
- */
- sas_resume_ha_no_sync(sha);
+ sas_resume_ha(sha);
clear_bit(HISI_SAS_RESETTING_BIT, &hisi_hba->flags);
dev_warn(dev, "end of resuming controller\n");
diff --git a/drivers/scsi/libsas/sas_init.c b/drivers/scsi/libsas/sas_init.c
index 0bec236f0fb59..c3f3d05b46dea 100644
--- a/drivers/scsi/libsas/sas_init.c
+++ b/drivers/scsi/libsas/sas_init.c
@@ -410,7 +410,7 @@ static void sas_resume_insert_broadcast_ha(struct sas_ha_struct *ha)
}
}
-static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
+void sas_resume_ha(struct sas_ha_struct *ha)
{
const unsigned long tmo = msecs_to_jiffies(25000);
int i;
@@ -426,6 +426,23 @@ static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
dev_info(ha->dev, "waiting up to 25 seconds for %d phy%s to resume\n",
i, i > 1 ? "s" : "");
wait_event_timeout(ha->eh_wait_q, phys_suspended(ha) == 0, tmo);
+
+ /*
+ * All phys are back up or timed out. Turn on I/O and drain
+ * pending work.
+ */
+ scsi_unblock_requests(ha->shost);
+ sas_drain_work(ha);
+
+ /*
+ * Send PHYE_RESUME_TIMEOUT after sas_drain_work(). The handler
+ * calls sas_deform_port() -> sas_destruct_devices(), which removes
+ * SCSI devices and, for LLDDs using device_link() PM sync, waits
+ * for the host to be runtime-active. Sending it before the drain
+ * would deadlock: the drain waits for the handler, the handler
+ * waits for host resume, and host resume waits for the drain to
+ * finish.
+ */
for (i = 0; i < ha->num_phys; i++) {
struct asd_sas_phy *phy = ha->sas_phy[i];
@@ -436,12 +453,6 @@ static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
}
}
- /* all phys are back up or timed out, turn on i/o so we can
- * flush out disks that did not return
- */
- scsi_unblock_requests(ha->shost);
- if (drain)
- sas_drain_work(ha);
clear_bit(SAS_HA_RESUMING, &ha->state);
sas_queue_deferred_work(ha);
@@ -450,20 +461,8 @@ static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
*/
sas_resume_insert_broadcast_ha(ha);
}
-
-void sas_resume_ha(struct sas_ha_struct *ha)
-{
- _sas_resume_ha(ha, true);
-}
EXPORT_SYMBOL(sas_resume_ha);
-/* A no-sync variant, which does not call sas_drain_ha(). */
-void sas_resume_ha_no_sync(struct sas_ha_struct *ha)
-{
- _sas_resume_ha(ha, false);
-}
-EXPORT_SYMBOL(sas_resume_ha_no_sync);
-
void sas_suspend_ha(struct sas_ha_struct *ha)
{
int i;
diff --git a/include/scsi/libsas.h b/include/scsi/libsas.h
index 163f23c92b411..36d4cb567837c 100644
--- a/include/scsi/libsas.h
+++ b/include/scsi/libsas.h
@@ -680,7 +680,6 @@ extern int sas_register_ha(struct sas_ha_struct *);
extern int sas_unregister_ha(struct sas_ha_struct *);
extern void sas_prep_resume_ha(struct sas_ha_struct *sas_ha);
extern void sas_resume_ha(struct sas_ha_struct *sas_ha);
-extern void sas_resume_ha_no_sync(struct sas_ha_struct *sas_ha);
extern void sas_suspend_ha(struct sas_ha_struct *sas_ha);
int sas_phy_reset(struct sas_phy *phy, int hard_reset);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 082/438] smb: client: fix buffer leaks in SMB1 read and write
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 081/438] scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 083/438] erofs: clean up erofs_ishare_fill_inode() Greg Kroah-Hartman
` (369 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dawei Feng, Steve French,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawei Feng <dawei.feng@seu.edu.cn>
[ Upstream commit 6a3e16d60e81a4aa3056ab15617036cfbea2e07d ]
CIFSSMBRead(), CIFSSMBWrite() and CIFSSMBWrite2() allocate a request
buffer before checking whether tcon->ses->server is NULL. If that
defensive check ever fails, the helper returns -ECONNABORTED without
releasing the request buffer.
Fix these leaks by releasing the allocated request buffer before
returning from these error paths. Use cifs_small_buf_release() for the
buffers allocated by small_smb_init() and cifs_buf_release() for the
buffer allocated by smb_init().
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings.
Runtime validation used a temporary fault-injection hook to force
tcon->ses->server to NULL after request-buffer initialization. On the
unfixed kernel, the harness observed two leaked small request buffers and
one leaked large request buffer, with directed kmemleak dumps confirming
the CIFS buffer allocation stacks. After the fix, no CIFS request-buffer
deltas remained.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Dawei Feng <dawei.feng@seu.edu.cn>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/client/cifssmb.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c
index 9e27bfa7376b1..024c5d462424d 100644
--- a/fs/smb/client/cifssmb.c
+++ b/fs/smb/client/cifssmb.c
@@ -1681,8 +1681,10 @@ CIFSSMBRead(const unsigned int xid, struct cifs_io_parms *io_parms,
pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));
/* tcon and ses pointer are checked in smb_init */
- if (tcon->ses->server == NULL)
+ if (!tcon->ses->server) {
+ cifs_small_buf_release(pSMB);
return -ECONNABORTED;
+ }
pSMB->AndXCommand = 0xFF; /* none */
pSMB->Fid = netfid;
@@ -1796,8 +1798,10 @@ CIFSSMBWrite(const unsigned int xid, struct cifs_io_parms *io_parms,
pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));
/* tcon and ses pointer are checked in smb_init */
- if (tcon->ses->server == NULL)
+ if (!tcon->ses->server) {
+ cifs_buf_release(pSMB);
return -ECONNABORTED;
+ }
pSMB->AndXCommand = 0xFF; /* none */
pSMB->Fid = netfid;
@@ -2077,8 +2081,10 @@ CIFSSMBWrite2(const unsigned int xid, struct cifs_io_parms *io_parms,
pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));
/* tcon and ses pointer are checked in smb_init */
- if (tcon->ses->server == NULL)
+ if (!tcon->ses->server) {
+ cifs_small_buf_release(pSMB);
return -ECONNABORTED;
+ }
pSMB->AndXCommand = 0xFF; /* none */
pSMB->Fid = netfid;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 083/438] erofs: clean up erofs_ishare_fill_inode()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 082/438] smb: client: fix buffer leaks in SMB1 read and write Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 084/438] erofs: remove fscache backend entirely Greg Kroah-Hartman
` (368 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hongbo Li, Chao Yu, Gao Xiang,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gao Xiang <hsiangkao@linux.alibaba.com>
[ Upstream commit 1ccc75909ca7c3b52163b408a3e1eb5453db013f ]
- Use the shorthand `si` to replace the overly long `sharedinode`;
- Introduce erofs_warn() and get rid of barely-used _erofs_printk();
- Get rid of the variable `hash`;
- Simplify error paths.
Reviewed-by: Hongbo Li <lihongbo22@huawei.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Stable-dep-of: 96b2dbbe58a1 ("erofs: ensure valid f_path for page cache sharing")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/erofs/internal.h | 2 ++
fs/erofs/ishare.c | 45 +++++++++++++++++++--------------------------
2 files changed, 21 insertions(+), 26 deletions(-)
diff --git a/fs/erofs/internal.h b/fs/erofs/internal.h
index 4792490161ec9..9e2ae7b619773 100644
--- a/fs/erofs/internal.h
+++ b/fs/erofs/internal.h
@@ -23,6 +23,8 @@
__printf(2, 3) void _erofs_printk(struct super_block *sb, const char *fmt, ...);
#define erofs_err(sb, fmt, ...) \
_erofs_printk(sb, KERN_ERR fmt "\n", ##__VA_ARGS__)
+#define erofs_warn(sb, fmt, ...) \
+ _erofs_printk(sb, KERN_WARNING fmt "\n", ##__VA_ARGS__)
#define erofs_info(sb, fmt, ...) \
_erofs_printk(sb, KERN_INFO fmt "\n", ##__VA_ARGS__)
diff --git a/fs/erofs/ishare.c b/fs/erofs/ishare.c
index 6ed66b17359ba..35cbd0bc04d7d 100644
--- a/fs/erofs/ishare.c
+++ b/fs/erofs/ishare.c
@@ -40,49 +40,42 @@ static int erofs_ishare_iget5_set(struct inode *inode, void *data)
bool erofs_ishare_fill_inode(struct inode *inode)
{
struct erofs_sb_info *sbi = EROFS_SB(inode->i_sb);
- struct erofs_inode *vi = EROFS_I(inode);
const struct address_space_operations *aops;
+ struct erofs_inode *vi = EROFS_I(inode);
struct erofs_inode_fingerprint fp;
- struct inode *sharedinode;
- unsigned long hash;
+ struct inode *si;
aops = erofs_get_aops(inode, true);
if (IS_ERR(aops))
return false;
if (erofs_xattr_fill_inode_fingerprint(&fp, inode, sbi->domain_id))
return false;
- hash = xxh32(fp.opaque, fp.size, 0);
- sharedinode = iget5_locked(erofs_ishare_mnt->mnt_sb, hash,
- erofs_ishare_iget5_eq, erofs_ishare_iget5_set,
- &fp);
- if (!sharedinode) {
- kfree(fp.opaque);
- return false;
- }
- if (inode_state_read_once(sharedinode) & I_NEW) {
- sharedinode->i_mapping->a_ops = aops;
- sharedinode->i_size = vi->vfs_inode.i_size;
- unlock_new_inode(sharedinode);
+ si = iget5_locked(erofs_ishare_mnt->mnt_sb,
+ xxh32(fp.opaque, fp.size, 0),
+ erofs_ishare_iget5_eq, erofs_ishare_iget5_set, &fp);
+ if (si && (inode_state_read_once(si) & I_NEW)) {
+ si->i_mapping->a_ops = aops;
+ si->i_size = inode->i_size;
+ unlock_new_inode(si);
} else {
kfree(fp.opaque);
- if (aops != sharedinode->i_mapping->a_ops) {
- iput(sharedinode);
+ if (!si || aops != si->i_mapping->a_ops) {
+ iput(si);
return false;
}
- if (sharedinode->i_size != vi->vfs_inode.i_size) {
- _erofs_printk(inode->i_sb, KERN_WARNING
- "size(%lld:%lld) not matches for the same fingerprint\n",
- vi->vfs_inode.i_size, sharedinode->i_size);
- iput(sharedinode);
+ if (si->i_size != inode->i_size) {
+ erofs_warn(inode->i_sb, "i_size mismatch (%lld != %lld) for the same fingerprint",
+ inode->i_size, si->i_size);
+ iput(si);
return false;
}
}
- vi->sharedinode = sharedinode;
+ vi->sharedinode = si;
INIT_LIST_HEAD(&vi->ishare_list);
- spin_lock(&EROFS_I(sharedinode)->ishare_lock);
- list_add(&vi->ishare_list, &EROFS_I(sharedinode)->ishare_list);
- spin_unlock(&EROFS_I(sharedinode)->ishare_lock);
+ spin_lock(&EROFS_I(si)->ishare_lock);
+ list_add(&vi->ishare_list, &EROFS_I(si)->ishare_list);
+ spin_unlock(&EROFS_I(si)->ishare_lock);
return true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 084/438] erofs: remove fscache backend entirely
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 083/438] erofs: clean up erofs_ishare_fill_inode() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 085/438] erofs: ensure valid f_path for page cache sharing Greg Kroah-Hartman
` (367 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jingbo Xu, Gao Xiang, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gao Xiang <hsiangkao@linux.alibaba.com>
[ Upstream commit c37460cd9b2fcb61ec66b7eb4fde737e65ec2a56 ]
EROFS over fscache was introduced to provide image lazy pulling
functionality. After the feature landed, the fscache subsystem made
netfs a new hard dependency, which is unexpected for a local filesystem
and has an kernel-defined caching hierarchy which could be inflexible
compared to the fanotify pre-content hooks. Therefore, this feature has
been deprecated for almost two years.
As EROFS file-backed mounts and fanotify pre-content hooks both upstream
for a while and already providing equivalent functionality (erofs-utils
has supported fanotify pre-content hooks), let's remove the fscache
backend now.
The main application of this feature is Nydus [1], and they plan to move
to use fanotify pre-content hooks in the near future too.
I hope this patch can be merged into Linux 7.2, which is also motivated
by newly found implementation issues [2][3] that are not worth
investigating given the deprecation and limited development resources.
The associated fscache/cachefiles cleanup patch will follow separately
through the vfs tree (netfs) later: it seems fine since the codebase is
isolated by CONFIG_CACHEFILES_ONDEMAND.
[1] https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fscache.md
[2] https://github.com/dragonflyoss/nydus/pull/1824
[3] https://lore.kernel.org/r/20260619135800.1594811-1-michael.bommarito@gmail.com
Acked-by: Jingbo Xu <jefflexu@linux.alibaba.com>
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Stable-dep-of: 96b2dbbe58a1 ("erofs: ensure valid f_path for page cache sharing")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/filesystems/erofs.rst | 9 +-
fs/erofs/Kconfig | 21 +-
fs/erofs/Makefile | 1 -
fs/erofs/data.c | 4 +-
fs/erofs/fscache.c | 664 ----------------------------
fs/erofs/inode.c | 2 +-
fs/erofs/internal.h | 70 +--
fs/erofs/ishare.c | 2 +-
fs/erofs/super.c | 94 +---
fs/erofs/zdata.c | 6 -
10 files changed, 26 insertions(+), 847 deletions(-)
delete mode 100644 fs/erofs/fscache.c
diff --git a/Documentation/filesystems/erofs.rst b/Documentation/filesystems/erofs.rst
index fe06308e546c1..4a82e1e31e5fa 100644
--- a/Documentation/filesystems/erofs.rst
+++ b/Documentation/filesystems/erofs.rst
@@ -127,12 +127,9 @@ dax A legacy option which is an alias for ``dax=always``.
device=%s Specify a path to an extra device to be used together.
directio (For file-backed mounts) Use direct I/O to access backing
files, and asynchronous I/O will be enabled if supported.
-fsid=%s Specify a filesystem image ID for Fscache back-end.
-domain_id=%s Specify a trusted domain ID for fscache mode so that
- different images with the same blobs, identified by blob IDs,
- can share storage within the same trusted domain.
- Also used for different filesystems with inode page sharing
- enabled to share page cache within the trusted domain.
+domain_id=%s Specify a trusted domain ID. Filesystems sharing the same
+ domain ID can share page cache across mounts when inode
+ page sharing is enabled. (not shown in mountinfo output)
fsoffset=%llu Specify block-aligned filesystem offset for the primary device.
inode_share Enable inode page sharing for this filesystem. Inodes with
identical content within the same domain ID can share the
diff --git a/fs/erofs/Kconfig b/fs/erofs/Kconfig
index 97c48ebe84584..4789b1077d8ce 100644
--- a/fs/erofs/Kconfig
+++ b/fs/erofs/Kconfig
@@ -3,13 +3,11 @@
config EROFS_FS
tristate "EROFS filesystem support"
depends on BLOCK
- select CACHEFILES if EROFS_FS_ONDEMAND
select CRC32
select CRYPTO if EROFS_FS_ZIP_ACCEL
select CRYPTO_DEFLATE if EROFS_FS_ZIP_ACCEL
select FS_IOMAP
select LZ4_DECOMPRESS if EROFS_FS_ZIP
- select NETFS_SUPPORT if EROFS_FS_ONDEMAND
select XXHASH if EROFS_FS_XATTR
select XZ_DEC if EROFS_FS_ZIP_LZMA
select XZ_DEC_MICROLZMA if EROFS_FS_ZIP_LZMA
@@ -109,9 +107,6 @@ config EROFS_FS_BACKED_BY_FILE
be used to simplify error-prone lifetime management of unnecessary
virtual block devices.
- Note that this feature, along with ongoing fanotify pre-content
- hooks, will eventually replace "EROFS over fscache."
-
If you don't want to enable this feature, say N.
config EROFS_FS_ZIP
@@ -172,20 +167,6 @@ config EROFS_FS_ZIP_ACCEL
If unsure, say N.
-config EROFS_FS_ONDEMAND
- bool "EROFS fscache-based on-demand read support (deprecated)"
- depends on EROFS_FS
- select FSCACHE
- select CACHEFILES_ONDEMAND
- help
- This permits EROFS to use fscache-backed data blobs with on-demand
- read support.
-
- It is now deprecated and scheduled to be removed from the kernel
- after fanotify pre-content hooks are landed.
-
- If unsure, say N.
-
config EROFS_FS_PCPU_KTHREAD
bool "EROFS per-cpu decompression kthread workers"
depends on EROFS_FS_ZIP
@@ -207,7 +188,7 @@ config EROFS_FS_PCPU_KTHREAD_HIPRI
config EROFS_FS_PAGE_CACHE_SHARE
bool "EROFS page cache share support (experimental)"
- depends on EROFS_FS && EROFS_FS_XATTR && !EROFS_FS_ONDEMAND
+ depends on EROFS_FS && EROFS_FS_XATTR
help
This enables page cache sharing among inodes with identical
content fingerprints on the same machine.
diff --git a/fs/erofs/Makefile b/fs/erofs/Makefile
index a80e1762b6079..30423496786fe 100644
--- a/fs/erofs/Makefile
+++ b/fs/erofs/Makefile
@@ -9,5 +9,4 @@ erofs-$(CONFIG_EROFS_FS_ZIP_DEFLATE) += decompressor_deflate.o
erofs-$(CONFIG_EROFS_FS_ZIP_ZSTD) += decompressor_zstd.o
erofs-$(CONFIG_EROFS_FS_ZIP_ACCEL) += decompressor_crypto.o
erofs-$(CONFIG_EROFS_FS_BACKED_BY_FILE) += fileio.o
-erofs-$(CONFIG_EROFS_FS_ONDEMAND) += fscache.o
erofs-$(CONFIG_EROFS_FS_PAGE_CACHE_SHARE) += ishare.o
diff --git a/fs/erofs/data.c b/fs/erofs/data.c
index 44da21c9d7776..af846bab1368c 100644
--- a/fs/erofs/data.c
+++ b/fs/erofs/data.c
@@ -80,9 +80,7 @@ int erofs_init_metabuf(struct erofs_buf *buf, struct super_block *sb,
if (erofs_is_fileio_mode(sbi)) {
buf->file = sbi->dif0.file; /* some fs like FUSE needs it */
buf->mapping = buf->file->f_mapping;
- } else if (erofs_is_fscache_mode(sb))
- buf->mapping = sbi->dif0.fscache->inode->i_mapping;
- else
+ } else
buf->mapping = sb->s_bdev->bd_mapping;
return 0;
}
diff --git a/fs/erofs/fscache.c b/fs/erofs/fscache.c
deleted file mode 100644
index 685c68774379b..0000000000000
--- a/fs/erofs/fscache.c
+++ /dev/null
@@ -1,664 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0-or-later
-/*
- * Copyright (C) 2022, Alibaba Cloud
- * Copyright (C) 2022, Bytedance Inc. All rights reserved.
- */
-#include <linux/fscache.h>
-#include "internal.h"
-
-static DEFINE_MUTEX(erofs_domain_list_lock);
-static DEFINE_MUTEX(erofs_domain_cookies_lock);
-static LIST_HEAD(erofs_domain_list);
-static LIST_HEAD(erofs_domain_cookies_list);
-static struct vfsmount *erofs_pseudo_mnt;
-
-struct erofs_fscache_io {
- struct netfs_cache_resources cres;
- struct iov_iter iter;
- netfs_io_terminated_t end_io;
- void *private;
- refcount_t ref;
-};
-
-struct erofs_fscache_rq {
- struct address_space *mapping; /* The mapping being accessed */
- loff_t start; /* Start position */
- size_t len; /* Length of the request */
- size_t submitted; /* Length of submitted */
- short error; /* 0 or error that occurred */
- refcount_t ref;
-};
-
-static bool erofs_fscache_io_put(struct erofs_fscache_io *io)
-{
- if (!refcount_dec_and_test(&io->ref))
- return false;
- if (io->cres.ops)
- io->cres.ops->end_operation(&io->cres);
- kfree(io);
- return true;
-}
-
-static void erofs_fscache_req_complete(struct erofs_fscache_rq *req)
-{
- struct folio *folio;
- bool failed = req->error;
- pgoff_t start_page = req->start / PAGE_SIZE;
- pgoff_t last_page = ((req->start + req->len) / PAGE_SIZE) - 1;
-
- XA_STATE(xas, &req->mapping->i_pages, start_page);
-
- rcu_read_lock();
- xas_for_each(&xas, folio, last_page) {
- if (xas_retry(&xas, folio))
- continue;
- if (!failed)
- folio_mark_uptodate(folio);
- folio_unlock(folio);
- }
- rcu_read_unlock();
-}
-
-static void erofs_fscache_req_put(struct erofs_fscache_rq *req)
-{
- if (!refcount_dec_and_test(&req->ref))
- return;
- erofs_fscache_req_complete(req);
- kfree(req);
-}
-
-static struct erofs_fscache_rq *erofs_fscache_req_alloc(struct address_space *mapping,
- loff_t start, size_t len)
-{
- struct erofs_fscache_rq *req = kzalloc_obj(*req);
-
- if (!req)
- return NULL;
- req->mapping = mapping;
- req->start = start;
- req->len = len;
- refcount_set(&req->ref, 1);
- return req;
-}
-
-static void erofs_fscache_req_io_put(struct erofs_fscache_io *io)
-{
- struct erofs_fscache_rq *req = io->private;
-
- if (erofs_fscache_io_put(io))
- erofs_fscache_req_put(req);
-}
-
-static void erofs_fscache_req_end_io(void *priv, ssize_t transferred_or_error)
-{
- struct erofs_fscache_io *io = priv;
- struct erofs_fscache_rq *req = io->private;
-
- if (IS_ERR_VALUE(transferred_or_error))
- req->error = transferred_or_error;
- erofs_fscache_req_io_put(io);
-}
-
-static struct erofs_fscache_io *erofs_fscache_req_io_alloc(struct erofs_fscache_rq *req)
-{
- struct erofs_fscache_io *io = kzalloc_obj(*io);
-
- if (!io)
- return NULL;
- io->end_io = erofs_fscache_req_end_io;
- io->private = req;
- refcount_inc(&req->ref);
- refcount_set(&io->ref, 1);
- return io;
-}
-
-/*
- * Read data from fscache described by cookie at pstart physical address
- * offset, and fill the read data into buffer described by io->iter.
- */
-static int erofs_fscache_read_io_async(struct fscache_cookie *cookie,
- loff_t pstart, struct erofs_fscache_io *io)
-{
- enum netfs_io_source source;
- struct netfs_cache_resources *cres = &io->cres;
- struct iov_iter *iter = &io->iter;
- int ret;
-
- ret = fscache_begin_read_operation(cres, cookie);
- if (ret)
- return ret;
-
- while (iov_iter_count(iter)) {
- size_t orig_count = iov_iter_count(iter), len = orig_count;
- unsigned long flags = 1 << NETFS_SREQ_ONDEMAND;
-
- source = cres->ops->prepare_ondemand_read(cres,
- pstart, &len, LLONG_MAX, &flags, 0);
- if (WARN_ON(len == 0))
- source = NETFS_INVALID_READ;
- if (source != NETFS_READ_FROM_CACHE) {
- erofs_err(NULL, "prepare_ondemand_read failed (source %d)", source);
- return -EIO;
- }
-
- iov_iter_truncate(iter, len);
- refcount_inc(&io->ref);
- ret = fscache_read(cres, pstart, iter, NETFS_READ_HOLE_FAIL,
- io->end_io, io);
- if (ret == -EIOCBQUEUED)
- ret = 0;
- if (ret) {
- erofs_err(NULL, "fscache_read failed (ret %d)", ret);
- return ret;
- }
- if (WARN_ON(iov_iter_count(iter)))
- return -EIO;
-
- iov_iter_reexpand(iter, orig_count - len);
- pstart += len;
- }
- return 0;
-}
-
-struct erofs_fscache_bio {
- struct erofs_fscache_io io;
- struct bio bio; /* w/o bdev to share bio_add_page/endio() */
- struct bio_vec bvecs[BIO_MAX_VECS];
-};
-
-static void erofs_fscache_bio_endio(void *priv, ssize_t transferred_or_error)
-{
- struct erofs_fscache_bio *io = priv;
-
- if (IS_ERR_VALUE(transferred_or_error))
- io->bio.bi_status = errno_to_blk_status(transferred_or_error);
- bio_endio(&io->bio);
- BUILD_BUG_ON(offsetof(struct erofs_fscache_bio, io) != 0);
- erofs_fscache_io_put(&io->io);
-}
-
-struct bio *erofs_fscache_bio_alloc(struct erofs_map_dev *mdev)
-{
- struct erofs_fscache_bio *io;
-
- io = kmalloc_obj(*io, GFP_KERNEL | __GFP_NOFAIL);
- bio_init(&io->bio, NULL, io->bvecs, BIO_MAX_VECS, REQ_OP_READ);
- io->io.private = mdev->m_dif->fscache->cookie;
- io->io.end_io = erofs_fscache_bio_endio;
- refcount_set(&io->io.ref, 1);
- return &io->bio;
-}
-
-void erofs_fscache_submit_bio(struct bio *bio)
-{
- struct erofs_fscache_bio *io = container_of(bio,
- struct erofs_fscache_bio, bio);
- int ret;
-
- iov_iter_bvec(&io->io.iter, ITER_DEST, io->bvecs, bio->bi_vcnt,
- bio->bi_iter.bi_size);
- ret = erofs_fscache_read_io_async(io->io.private,
- bio->bi_iter.bi_sector << 9, &io->io);
- erofs_fscache_io_put(&io->io);
- if (!ret)
- return;
- bio->bi_status = errno_to_blk_status(ret);
- bio_endio(bio);
-}
-
-static int erofs_fscache_meta_read_folio(struct file *data, struct folio *folio)
-{
- struct erofs_fscache *ctx = folio->mapping->host->i_private;
- int ret = -ENOMEM;
- struct erofs_fscache_rq *req;
- struct erofs_fscache_io *io;
-
- req = erofs_fscache_req_alloc(folio->mapping,
- folio_pos(folio), folio_size(folio));
- if (!req) {
- folio_unlock(folio);
- return ret;
- }
-
- io = erofs_fscache_req_io_alloc(req);
- if (!io) {
- req->error = ret;
- goto out;
- }
- iov_iter_xarray(&io->iter, ITER_DEST, &folio->mapping->i_pages,
- folio_pos(folio), folio_size(folio));
-
- ret = erofs_fscache_read_io_async(ctx->cookie, folio_pos(folio), io);
- if (ret)
- req->error = ret;
-
- erofs_fscache_req_io_put(io);
-out:
- erofs_fscache_req_put(req);
- return ret;
-}
-
-static int erofs_fscache_data_read_slice(struct erofs_fscache_rq *req)
-{
- struct address_space *mapping = req->mapping;
- struct inode *inode = mapping->host;
- struct super_block *sb = inode->i_sb;
- struct erofs_fscache_io *io;
- struct erofs_map_blocks map;
- struct erofs_map_dev mdev;
- loff_t pos = req->start + req->submitted;
- size_t count;
- int ret;
-
- map.m_la = pos;
- ret = erofs_map_blocks(inode, &map);
- if (ret)
- return ret;
-
- if (map.m_flags & EROFS_MAP_META) {
- struct erofs_buf buf = __EROFS_BUF_INITIALIZER;
- struct iov_iter iter;
- size_t size = map.m_llen;
- void *src;
-
- src = erofs_read_metabuf(&buf, sb, map.m_pa,
- erofs_inode_in_metabox(inode));
- if (IS_ERR(src))
- return PTR_ERR(src);
-
- iov_iter_xarray(&iter, ITER_DEST, &mapping->i_pages, pos, PAGE_SIZE);
- if (copy_to_iter(src, size, &iter) != size) {
- erofs_put_metabuf(&buf);
- return -EFAULT;
- }
- iov_iter_zero(PAGE_SIZE - size, &iter);
- erofs_put_metabuf(&buf);
- req->submitted += PAGE_SIZE;
- return 0;
- }
-
- count = req->len - req->submitted;
- if (!(map.m_flags & EROFS_MAP_MAPPED)) {
- struct iov_iter iter;
-
- iov_iter_xarray(&iter, ITER_DEST, &mapping->i_pages, pos, count);
- iov_iter_zero(count, &iter);
- req->submitted += count;
- return 0;
- }
-
- count = min_t(size_t, map.m_llen - (pos - map.m_la), count);
- DBG_BUGON(!count || count % PAGE_SIZE);
-
- mdev = (struct erofs_map_dev) {
- .m_deviceid = map.m_deviceid,
- .m_pa = map.m_pa,
- };
- ret = erofs_map_dev(sb, &mdev);
- if (ret)
- return ret;
-
- io = erofs_fscache_req_io_alloc(req);
- if (!io)
- return -ENOMEM;
- iov_iter_xarray(&io->iter, ITER_DEST, &mapping->i_pages, pos, count);
- ret = erofs_fscache_read_io_async(mdev.m_dif->fscache->cookie,
- mdev.m_pa + (pos - map.m_la), io);
- erofs_fscache_req_io_put(io);
-
- req->submitted += count;
- return ret;
-}
-
-static int erofs_fscache_data_read(struct erofs_fscache_rq *req)
-{
- int ret;
-
- do {
- ret = erofs_fscache_data_read_slice(req);
- if (ret)
- req->error = ret;
- } while (!ret && req->submitted < req->len);
- return ret;
-}
-
-static int erofs_fscache_read_folio(struct file *file, struct folio *folio)
-{
- struct erofs_fscache_rq *req;
- int ret;
-
- req = erofs_fscache_req_alloc(folio->mapping,
- folio_pos(folio), folio_size(folio));
- if (!req) {
- folio_unlock(folio);
- return -ENOMEM;
- }
-
- ret = erofs_fscache_data_read(req);
- erofs_fscache_req_put(req);
- return ret;
-}
-
-static void erofs_fscache_readahead(struct readahead_control *rac)
-{
- struct erofs_fscache_rq *req;
-
- if (!readahead_count(rac))
- return;
-
- req = erofs_fscache_req_alloc(rac->mapping,
- readahead_pos(rac), readahead_length(rac));
- if (!req)
- return;
-
- /* The request completion will drop refs on the folios. */
- while (readahead_folio(rac))
- ;
-
- erofs_fscache_data_read(req);
- erofs_fscache_req_put(req);
-}
-
-static const struct address_space_operations erofs_fscache_meta_aops = {
- .read_folio = erofs_fscache_meta_read_folio,
-};
-
-const struct address_space_operations erofs_fscache_access_aops = {
- .read_folio = erofs_fscache_read_folio,
- .readahead = erofs_fscache_readahead,
-};
-
-static void erofs_fscache_domain_put(struct erofs_domain *domain)
-{
- mutex_lock(&erofs_domain_list_lock);
- if (refcount_dec_and_test(&domain->ref)) {
- list_del(&domain->list);
- if (list_empty(&erofs_domain_list)) {
- kern_unmount(erofs_pseudo_mnt);
- erofs_pseudo_mnt = NULL;
- }
- fscache_relinquish_volume(domain->volume, NULL, false);
- mutex_unlock(&erofs_domain_list_lock);
- kfree_sensitive(domain->domain_id);
- kfree(domain);
- return;
- }
- mutex_unlock(&erofs_domain_list_lock);
-}
-
-static int erofs_fscache_register_volume(struct super_block *sb)
-{
- struct erofs_sb_info *sbi = EROFS_SB(sb);
- char *domain_id = sbi->domain_id;
- struct fscache_volume *volume;
- char *name;
- int ret = 0;
-
- name = kasprintf(GFP_KERNEL, "erofs,%s",
- domain_id ? domain_id : sbi->fsid);
- if (!name)
- return -ENOMEM;
-
- volume = fscache_acquire_volume(name, NULL, NULL, 0);
- if (IS_ERR_OR_NULL(volume)) {
- erofs_err(sb, "failed to register volume for %s", name);
- ret = volume ? PTR_ERR(volume) : -EOPNOTSUPP;
- volume = NULL;
- }
-
- sbi->volume = volume;
- kfree(name);
- return ret;
-}
-
-static int erofs_fscache_init_domain(struct super_block *sb)
-{
- int err;
- struct erofs_domain *domain;
- struct erofs_sb_info *sbi = EROFS_SB(sb);
-
- domain = kzalloc_obj(struct erofs_domain);
- if (!domain)
- return -ENOMEM;
-
- domain->domain_id = kstrdup(sbi->domain_id, GFP_KERNEL);
- if (!domain->domain_id) {
- kfree(domain);
- return -ENOMEM;
- }
-
- err = erofs_fscache_register_volume(sb);
- if (err)
- goto out;
-
- if (!erofs_pseudo_mnt) {
- struct vfsmount *mnt = kern_mount(&erofs_anon_fs_type);
- if (IS_ERR(mnt)) {
- err = PTR_ERR(mnt);
- goto out;
- }
- erofs_pseudo_mnt = mnt;
- }
-
- domain->volume = sbi->volume;
- refcount_set(&domain->ref, 1);
- list_add(&domain->list, &erofs_domain_list);
- sbi->domain = domain;
- return 0;
-out:
- kfree_sensitive(domain->domain_id);
- kfree(domain);
- return err;
-}
-
-static int erofs_fscache_register_domain(struct super_block *sb)
-{
- int err;
- struct erofs_domain *domain;
- struct erofs_sb_info *sbi = EROFS_SB(sb);
-
- mutex_lock(&erofs_domain_list_lock);
- list_for_each_entry(domain, &erofs_domain_list, list) {
- if (!strcmp(domain->domain_id, sbi->domain_id)) {
- sbi->domain = domain;
- sbi->volume = domain->volume;
- refcount_inc(&domain->ref);
- mutex_unlock(&erofs_domain_list_lock);
- return 0;
- }
- }
- err = erofs_fscache_init_domain(sb);
- mutex_unlock(&erofs_domain_list_lock);
- return err;
-}
-
-static struct erofs_fscache *erofs_fscache_acquire_cookie(struct super_block *sb,
- char *name, unsigned int flags)
-{
- struct fscache_volume *volume = EROFS_SB(sb)->volume;
- struct erofs_fscache *ctx;
- struct fscache_cookie *cookie;
- struct super_block *isb;
- struct inode *inode;
- int ret;
-
- ctx = kzalloc_obj(*ctx);
- if (!ctx)
- return ERR_PTR(-ENOMEM);
- INIT_LIST_HEAD(&ctx->node);
- refcount_set(&ctx->ref, 1);
-
- cookie = fscache_acquire_cookie(volume, FSCACHE_ADV_WANT_CACHE_SIZE,
- name, strlen(name), NULL, 0, 0);
- if (!cookie) {
- erofs_err(sb, "failed to get cookie for %s", name);
- ret = -EINVAL;
- goto err;
- }
- fscache_use_cookie(cookie, false);
-
- /*
- * Allocate anonymous inode in global pseudo mount for shareable blobs,
- * so that they are accessible among erofs fs instances.
- */
- isb = flags & EROFS_REG_COOKIE_SHARE ? erofs_pseudo_mnt->mnt_sb : sb;
- inode = new_inode(isb);
- if (!inode) {
- erofs_err(sb, "failed to get anon inode for %s", name);
- ret = -ENOMEM;
- goto err_cookie;
- }
-
- inode->i_size = OFFSET_MAX;
- inode->i_mapping->a_ops = &erofs_fscache_meta_aops;
- mapping_set_gfp_mask(inode->i_mapping, GFP_KERNEL);
- inode->i_blkbits = EROFS_SB(sb)->blkszbits;
- inode->i_private = ctx;
-
- ctx->cookie = cookie;
- ctx->inode = inode;
- return ctx;
-
-err_cookie:
- fscache_unuse_cookie(cookie, NULL, NULL);
- fscache_relinquish_cookie(cookie, false);
-err:
- kfree(ctx);
- return ERR_PTR(ret);
-}
-
-static void erofs_fscache_relinquish_cookie(struct erofs_fscache *ctx)
-{
- fscache_unuse_cookie(ctx->cookie, NULL, NULL);
- fscache_relinquish_cookie(ctx->cookie, false);
- iput(ctx->inode);
- kfree(ctx->name);
- kfree(ctx);
-}
-
-static struct erofs_fscache *erofs_domain_init_cookie(struct super_block *sb,
- char *name, unsigned int flags)
-{
- struct erofs_fscache *ctx;
- struct erofs_domain *domain = EROFS_SB(sb)->domain;
-
- ctx = erofs_fscache_acquire_cookie(sb, name, flags);
- if (IS_ERR(ctx))
- return ctx;
-
- ctx->name = kstrdup(name, GFP_KERNEL);
- if (!ctx->name) {
- erofs_fscache_relinquish_cookie(ctx);
- return ERR_PTR(-ENOMEM);
- }
-
- refcount_inc(&domain->ref);
- ctx->domain = domain;
- list_add(&ctx->node, &erofs_domain_cookies_list);
- return ctx;
-}
-
-static struct erofs_fscache *erofs_domain_register_cookie(struct super_block *sb,
- char *name, unsigned int flags)
-{
- struct erofs_fscache *ctx;
- struct erofs_domain *domain = EROFS_SB(sb)->domain;
-
- flags |= EROFS_REG_COOKIE_SHARE;
- mutex_lock(&erofs_domain_cookies_lock);
- list_for_each_entry(ctx, &erofs_domain_cookies_list, node) {
- if (ctx->domain != domain || strcmp(ctx->name, name))
- continue;
- if (!(flags & EROFS_REG_COOKIE_NEED_NOEXIST)) {
- refcount_inc(&ctx->ref);
- } else {
- erofs_err(sb, "%s already exists in domain %s", name,
- domain->domain_id);
- ctx = ERR_PTR(-EEXIST);
- }
- mutex_unlock(&erofs_domain_cookies_lock);
- return ctx;
- }
- ctx = erofs_domain_init_cookie(sb, name, flags);
- mutex_unlock(&erofs_domain_cookies_lock);
- return ctx;
-}
-
-struct erofs_fscache *erofs_fscache_register_cookie(struct super_block *sb,
- char *name,
- unsigned int flags)
-{
- if (EROFS_SB(sb)->domain_id)
- return erofs_domain_register_cookie(sb, name, flags);
- return erofs_fscache_acquire_cookie(sb, name, flags);
-}
-
-void erofs_fscache_unregister_cookie(struct erofs_fscache *ctx)
-{
- struct erofs_domain *domain = NULL;
-
- if (!ctx)
- return;
- if (!ctx->domain)
- return erofs_fscache_relinquish_cookie(ctx);
-
- mutex_lock(&erofs_domain_cookies_lock);
- if (refcount_dec_and_test(&ctx->ref)) {
- domain = ctx->domain;
- list_del(&ctx->node);
- erofs_fscache_relinquish_cookie(ctx);
- }
- mutex_unlock(&erofs_domain_cookies_lock);
- if (domain)
- erofs_fscache_domain_put(domain);
-}
-
-int erofs_fscache_register_fs(struct super_block *sb)
-{
- int ret;
- struct erofs_sb_info *sbi = EROFS_SB(sb);
- struct erofs_fscache *fscache;
- unsigned int flags = 0;
-
- if (sbi->domain_id)
- ret = erofs_fscache_register_domain(sb);
- else
- ret = erofs_fscache_register_volume(sb);
- if (ret)
- return ret;
-
- /*
- * When shared domain is enabled, using NEED_NOEXIST to guarantee
- * the primary data blob (aka fsid) is unique in the shared domain.
- *
- * For non-shared-domain case, fscache_acquire_volume() invoked by
- * erofs_fscache_register_volume() has already guaranteed
- * the uniqueness of primary data blob.
- *
- * Acquired domain/volume will be relinquished in kill_sb() on error.
- */
- if (sbi->domain_id)
- flags |= EROFS_REG_COOKIE_NEED_NOEXIST;
- fscache = erofs_fscache_register_cookie(sb, sbi->fsid, flags);
- if (IS_ERR(fscache))
- return PTR_ERR(fscache);
-
- sbi->dif0.fscache = fscache;
- return 0;
-}
-
-void erofs_fscache_unregister_fs(struct super_block *sb)
-{
- struct erofs_sb_info *sbi = EROFS_SB(sb);
-
- erofs_fscache_unregister_cookie(sbi->dif0.fscache);
-
- if (sbi->domain)
- erofs_fscache_domain_put(sbi->domain);
- else
- fscache_relinquish_volume(sbi->volume, NULL, false);
-
- sbi->dif0.fscache = NULL;
- sbi->volume = NULL;
- sbi->domain = NULL;
-}
diff --git a/fs/erofs/inode.c b/fs/erofs/inode.c
index e0c47da4f09e0..45afe5c50de83 100644
--- a/fs/erofs/inode.c
+++ b/fs/erofs/inode.c
@@ -256,7 +256,7 @@ static int erofs_fill_inode(struct inode *inode)
}
mapping_set_large_folios(inode->i_mapping);
- aops = erofs_get_aops(inode, false);
+ aops = erofs_get_aops(inode);
if (IS_ERR(aops))
return PTR_ERR(aops);
inode->i_mapping->a_ops = aops;
diff --git a/fs/erofs/internal.h b/fs/erofs/internal.h
index 9e2ae7b619773..580f8d9f14e7f 100644
--- a/fs/erofs/internal.h
+++ b/fs/erofs/internal.h
@@ -43,7 +43,6 @@ typedef u64 erofs_blk_t;
struct erofs_device_info {
char *path;
- struct erofs_fscache *fscache;
struct file *file;
struct dax_device *dax_dev;
u64 fsoff, dax_part_off;
@@ -80,24 +79,6 @@ struct erofs_sb_lz4_info {
u16 max_pclusterblks;
};
-struct erofs_domain {
- refcount_t ref;
- struct list_head list;
- struct fscache_volume *volume;
- char *domain_id;
-};
-
-struct erofs_fscache {
- struct fscache_cookie *cookie;
- struct inode *inode; /* anonymous inode for the blob */
-
- /* used for share domain mode */
- struct erofs_domain *domain;
- struct list_head node;
- refcount_t ref;
- char *name;
-};
-
struct erofs_xattr_prefix_item {
struct erofs_xattr_long_prefix *prefix;
u8 infix_len;
@@ -162,10 +143,6 @@ struct erofs_sb_info {
struct completion s_kobj_unregister;
erofs_off_t dir_ra_bytes;
- /* fscache support */
- struct fscache_volume *volume;
- struct erofs_domain *domain;
- char *fsid;
char *domain_id;
};
@@ -191,12 +168,6 @@ static inline bool erofs_is_fileio_mode(struct erofs_sb_info *sbi)
extern struct file_system_type erofs_anon_fs_type;
-static inline bool erofs_is_fscache_mode(struct super_block *sb)
-{
- return IS_ENABLED(CONFIG_EROFS_FS_ONDEMAND) &&
- !erofs_is_fileio_mode(EROFS_SB(sb)) && !sb->s_bdev;
-}
-
enum {
EROFS_ZIP_CACHE_DISABLED,
EROFS_ZIP_CACHE_READAHEAD,
@@ -413,11 +384,9 @@ struct erofs_map_dev {
};
extern const struct super_operations erofs_sops;
-
extern const struct address_space_operations erofs_aops;
extern const struct address_space_operations erofs_fileio_aops;
extern const struct address_space_operations z_erofs_aops;
-extern const struct address_space_operations erofs_fscache_access_aops;
extern const struct inode_operations erofs_generic_iops;
extern const struct inode_operations erofs_symlink_iops;
@@ -430,10 +399,6 @@ extern const struct file_operations erofs_ishare_fops;
extern const struct iomap_ops z_erofs_iomap_report_ops;
-/* flags for erofs_fscache_register_cookie() */
-#define EROFS_REG_COOKIE_SHARE 0x0001
-#define EROFS_REG_COOKIE_NEED_NOEXIST 0x0002
-
void *erofs_read_metadata(struct super_block *sb, struct erofs_buf *buf,
erofs_off_t *offset, int *lengthp);
void erofs_unmap_metabuf(struct erofs_buf *buf);
@@ -473,7 +438,7 @@ static inline void *erofs_vm_map_ram(struct page **pages, unsigned int count)
}
static inline const struct address_space_operations *
-erofs_get_aops(struct inode *realinode, bool no_fscache)
+erofs_get_aops(struct inode *realinode)
{
if (erofs_inode_is_data_compressed(EROFS_I(realinode)->datalayout)) {
if (!IS_ENABLED(CONFIG_EROFS_FS_ZIP))
@@ -483,9 +448,6 @@ erofs_get_aops(struct inode *realinode, bool no_fscache)
"EXPERIMENTAL EROFS subpage compressed block support in use. Use at your own risk!");
return &z_erofs_aops;
}
- if (IS_ENABLED(CONFIG_EROFS_FS_ONDEMAND) && !no_fscache &&
- erofs_is_fscache_mode(realinode->i_sb))
- return &erofs_fscache_access_aops;
if (IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE) &&
erofs_is_fileio_mode(EROFS_SB(realinode->i_sb)))
return &erofs_fileio_aops;
@@ -548,36 +510,6 @@ static inline struct bio *erofs_fileio_bio_alloc(struct erofs_map_dev *mdev) { r
static inline void erofs_fileio_submit_bio(struct bio *bio) {}
#endif
-#ifdef CONFIG_EROFS_FS_ONDEMAND
-int erofs_fscache_register_fs(struct super_block *sb);
-void erofs_fscache_unregister_fs(struct super_block *sb);
-
-struct erofs_fscache *erofs_fscache_register_cookie(struct super_block *sb,
- char *name, unsigned int flags);
-void erofs_fscache_unregister_cookie(struct erofs_fscache *fscache);
-struct bio *erofs_fscache_bio_alloc(struct erofs_map_dev *mdev);
-void erofs_fscache_submit_bio(struct bio *bio);
-#else
-static inline int erofs_fscache_register_fs(struct super_block *sb)
-{
- return -EOPNOTSUPP;
-}
-static inline void erofs_fscache_unregister_fs(struct super_block *sb) {}
-
-static inline
-struct erofs_fscache *erofs_fscache_register_cookie(struct super_block *sb,
- char *name, unsigned int flags)
-{
- return ERR_PTR(-EOPNOTSUPP);
-}
-
-static inline void erofs_fscache_unregister_cookie(struct erofs_fscache *fscache)
-{
-}
-static inline struct bio *erofs_fscache_bio_alloc(struct erofs_map_dev *mdev) { return NULL; }
-static inline void erofs_fscache_submit_bio(struct bio *bio) {}
-#endif
-
#ifdef CONFIG_EROFS_FS_PAGE_CACHE_SHARE
int __init erofs_init_ishare(void);
void erofs_exit_ishare(void);
diff --git a/fs/erofs/ishare.c b/fs/erofs/ishare.c
index 35cbd0bc04d7d..0868c12fc15b4 100644
--- a/fs/erofs/ishare.c
+++ b/fs/erofs/ishare.c
@@ -45,7 +45,7 @@ bool erofs_ishare_fill_inode(struct inode *inode)
struct erofs_inode_fingerprint fp;
struct inode *si;
- aops = erofs_get_aops(inode, true);
+ aops = erofs_get_aops(inode);
if (IS_ERR(aops))
return false;
if (erofs_xattr_fill_inode_fingerprint(&fp, inode, sbi->domain_id))
diff --git a/fs/erofs/super.c b/fs/erofs/super.c
index 579443e6acfeb..86fa5c6a0c708 100644
--- a/fs/erofs/super.c
+++ b/fs/erofs/super.c
@@ -126,7 +126,6 @@ static int erofs_init_device(struct erofs_buf *buf, struct super_block *sb,
struct erofs_device_info *dif, erofs_off_t *pos)
{
struct erofs_sb_info *sbi = EROFS_SB(sb);
- struct erofs_fscache *fscache;
struct erofs_deviceslot *dis;
struct file *file;
bool _48bit;
@@ -145,12 +144,7 @@ static int erofs_init_device(struct erofs_buf *buf, struct super_block *sb,
return -ENOMEM;
}
- if (erofs_is_fscache_mode(sb)) {
- fscache = erofs_fscache_register_cookie(sb, dif->path, 0);
- if (IS_ERR(fscache))
- return PTR_ERR(fscache);
- dif->fscache = fscache;
- } else if (!sbi->devs->flatdev) {
+ if (!sbi->devs->flatdev) {
file = erofs_is_fileio_mode(sbi) ?
filp_open(dif->path, O_RDONLY | O_LARGEFILE, 0) :
bdev_file_open_by_path(dif->path,
@@ -216,7 +210,7 @@ static int erofs_scan_devices(struct super_block *sb,
if (!ondisk_extradevs)
return 0;
- if (!sbi->devs->extra_devices && !erofs_is_fscache_mode(sb))
+ if (!sbi->devs->extra_devices)
sbi->devs->flatdev = true;
sbi->device_id_mask = roundup_pow_of_two(ondisk_extradevs + 1) - 1;
@@ -372,8 +366,6 @@ static int erofs_read_superblock(struct super_block *sb)
erofs_info(sb, "EXPERIMENTAL 48-bit layout support in use. Use at your own risk!");
if (erofs_sb_has_metabox(sbi))
erofs_info(sb, "EXPERIMENTAL metadata compression support in use. Use at your own risk!");
- if (erofs_is_fscache_mode(sb))
- erofs_info(sb, "[deprecated] fscache-based on-demand read feature in use. Use at your own risk!");
out:
erofs_put_metabuf(&buf);
return ret;
@@ -393,8 +385,7 @@ static void erofs_default_options(struct erofs_sb_info *sbi)
enum {
Opt_user_xattr, Opt_acl, Opt_cache_strategy, Opt_dax, Opt_dax_enum,
- Opt_device, Opt_fsid, Opt_domain_id, Opt_directio, Opt_fsoffset,
- Opt_inode_share,
+ Opt_device, Opt_domain_id, Opt_directio, Opt_fsoffset, Opt_inode_share,
};
static const struct constant_table erofs_param_cache_strategy[] = {
@@ -418,7 +409,6 @@ static const struct fs_parameter_spec erofs_fs_parameters[] = {
fsparam_flag("dax", Opt_dax),
fsparam_enum("dax", Opt_dax_enum, erofs_dax_param_enums),
fsparam_string("device", Opt_device),
- fsparam_string("fsid", Opt_fsid),
fsparam_string("domain_id", Opt_domain_id),
fsparam_flag_no("directio", Opt_directio),
fsparam_u64("fsoffset", Opt_fsoffset),
@@ -509,25 +499,14 @@ static int erofs_fc_parse_param(struct fs_context *fc,
}
++sbi->devs->extra_devices;
break;
-#ifdef CONFIG_EROFS_FS_ONDEMAND
- case Opt_fsid:
- kfree(sbi->fsid);
- sbi->fsid = kstrdup(param->string, GFP_KERNEL);
- if (!sbi->fsid)
- return -ENOMEM;
- break;
-#endif
-#if defined(CONFIG_EROFS_FS_ONDEMAND) || defined(CONFIG_EROFS_FS_PAGE_CACHE_SHARE)
case Opt_domain_id:
- kfree_sensitive(sbi->domain_id);
- sbi->domain_id = no_free_ptr(param->string);
- break;
-#else
- case Opt_fsid:
- case Opt_domain_id:
- errorfc(fc, "%s option not supported", erofs_fs_parameters[opt].name);
+ if (!IS_ENABLED(CONFIG_EROFS_FS_PAGE_CACHE_SHARE)) {
+ errorfc(fc, "%s option not supported", erofs_fs_parameters[opt].name);
+ } else {
+ kfree_sensitive(sbi->domain_id);
+ sbi->domain_id = no_free_ptr(param->string);
+ }
break;
-#endif
case Opt_directio:
if (!IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE))
errorfc(fc, "%s option not supported", erofs_fs_parameters[opt].name);
@@ -620,12 +599,7 @@ static void erofs_set_sysfs_name(struct super_block *sb)
{
struct erofs_sb_info *sbi = EROFS_SB(sb);
- if (sbi->domain_id && sbi->fsid)
- super_set_sysfs_name_generic(sb, "%s,%s", sbi->domain_id,
- sbi->fsid);
- else if (sbi->fsid)
- super_set_sysfs_name_generic(sb, "%s", sbi->fsid);
- else if (erofs_is_fileio_mode(sbi))
+ if (erofs_is_fileio_mode(sbi))
super_set_sysfs_name_generic(sb, "%s",
bdi_dev_name(sb->s_bdi));
else
@@ -680,11 +654,6 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
sb->s_blocksize = PAGE_SIZE;
sb->s_blocksize_bits = PAGE_SHIFT;
- if (erofs_is_fscache_mode(sb)) {
- err = erofs_fscache_register_fs(sb);
- if (err)
- return err;
- }
err = super_setup_bdi(sb);
if (err)
return err;
@@ -703,11 +672,6 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
return err;
if (sb->s_blocksize_bits != sbi->blkszbits) {
- if (erofs_is_fscache_mode(sb)) {
- errorfc(fc, "unsupported blksize for fscache mode");
- return -EINVAL;
- }
-
if (erofs_is_fileio_mode(sbi)) {
sb->s_blocksize = 1 << sbi->blkszbits;
sb->s_blocksize_bits = sbi->blkszbits;
@@ -716,14 +680,9 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
return -EINVAL;
}
}
-
- if (sbi->dif0.fsoff) {
- if (sbi->dif0.fsoff & (sb->s_blocksize - 1))
- return invalfc(fc, "fsoffset %llu is not aligned to block size %lu",
- sbi->dif0.fsoff, sb->s_blocksize);
- if (erofs_is_fscache_mode(sb))
- return invalfc(fc, "cannot use fsoffset in fscache mode");
- }
+ if (sbi->dif0.fsoff & (sb->s_blocksize - 1))
+ return invalfc(fc, "fsoffset %llu is not aligned to block size %lu",
+ sbi->dif0.fsoff, sb->s_blocksize);
if (test_opt(&sbi->opt, DAX_ALWAYS) && sbi->blkszbits != PAGE_SHIFT) {
erofs_info(sb, "unsupported blocksize for DAX");
@@ -793,16 +752,13 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
static int erofs_fc_get_tree(struct fs_context *fc)
{
- struct erofs_sb_info *sbi = fc->s_fs_info;
int ret;
- if (IS_ENABLED(CONFIG_EROFS_FS_ONDEMAND) && sbi->fsid)
- return get_tree_nodev(fc, erofs_fc_fill_super);
-
ret = get_tree_bdev_flags(fc, erofs_fc_fill_super,
IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE) ?
GET_TREE_BDEV_QUIET_LOOKUP : 0);
if (IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE) && ret == -ENOTBLK) {
+ struct erofs_sb_info *sbi = fc->s_fs_info;
struct file *file;
if (!fc->source)
@@ -827,8 +783,8 @@ static int erofs_fc_reconfigure(struct fs_context *fc)
DBG_BUGON(!sb_rdonly(sb));
- if (new_sbi->fsid || new_sbi->domain_id)
- erofs_info(sb, "ignoring reconfiguration for fsid|domain_id.");
+ if (new_sbi->domain_id)
+ erofs_info(sb, "ignoring reconfiguration for domain_id.");
if (test_opt(&new_sbi->opt, POSIX_ACL))
fc->sb_flags |= SB_POSIXACL;
@@ -848,8 +804,6 @@ static int erofs_release_device_info(int id, void *ptr, void *data)
fs_put_dax(dif->dax_dev, NULL);
if (dif->file)
fput(dif->file);
- erofs_fscache_unregister_cookie(dif->fscache);
- dif->fscache = NULL;
kfree(dif->path);
kfree(dif);
return 0;
@@ -867,7 +821,6 @@ static void erofs_free_dev_context(struct erofs_dev_context *devs)
static void erofs_sb_free(struct erofs_sb_info *sbi)
{
erofs_free_dev_context(sbi->devs);
- kfree(sbi->fsid);
kfree_sensitive(sbi->domain_id);
if (sbi->dif0.file)
fput(sbi->dif0.file);
@@ -928,14 +881,12 @@ static void erofs_kill_sb(struct super_block *sb)
{
struct erofs_sb_info *sbi = EROFS_SB(sb);
- if ((IS_ENABLED(CONFIG_EROFS_FS_ONDEMAND) && sbi->fsid) ||
- sbi->dif0.file)
+ if (sbi->dif0.file)
kill_anon_super(sb);
else
kill_block_super(sb);
erofs_drop_internal_inodes(sbi);
fs_put_dax(sbi->dif0.dax_dev, NULL);
- erofs_fscache_unregister_fs(sb);
erofs_sb_free(sbi);
sb->s_fs_info = NULL;
}
@@ -950,7 +901,6 @@ static void erofs_put_super(struct super_block *sb)
erofs_drop_internal_inodes(sbi);
erofs_free_dev_context(sbi->devs);
sbi->devs = NULL;
- erofs_fscache_unregister_fs(sb);
}
static struct file_system_type erofs_fs_type = {
@@ -962,14 +912,12 @@ static struct file_system_type erofs_fs_type = {
};
MODULE_ALIAS_FS("erofs");
-#if defined(CONFIG_EROFS_FS_ONDEMAND) || defined(CONFIG_EROFS_FS_PAGE_CACHE_SHARE)
+#ifdef CONFIG_EROFS_FS_PAGE_CACHE_SHARE
static void erofs_free_anon_inode(struct inode *inode)
{
struct erofs_inode *vi = EROFS_I(inode);
-#ifdef CONFIG_EROFS_FS_PAGE_CACHE_SHARE
kfree(vi->fingerprint.opaque);
-#endif
kmem_cache_free(erofs_inode_cachep, vi);
}
@@ -1099,12 +1047,6 @@ static int erofs_show_options(struct seq_file *seq, struct dentry *root)
seq_puts(seq, ",dax=never");
if (erofs_is_fileio_mode(sbi) && test_opt(opt, DIRECT_IO))
seq_puts(seq, ",directio");
- if (IS_ENABLED(CONFIG_EROFS_FS_ONDEMAND)) {
- if (sbi->fsid)
- seq_printf(seq, ",fsid=%s", sbi->fsid);
- if (sbi->domain_id)
- seq_printf(seq, ",domain_id=%s", sbi->domain_id);
- }
if (sbi->dif0.fsoff)
seq_printf(seq, ",fsoffset=%llu", sbi->dif0.fsoff);
if (test_opt(opt, INODE_SHARE))
diff --git a/fs/erofs/zdata.c b/fs/erofs/zdata.c
index c6240dccbb0f0..5fa6651147eaa 100644
--- a/fs/erofs/zdata.c
+++ b/fs/erofs/zdata.c
@@ -1714,8 +1714,6 @@ static void z_erofs_submit_queue(struct z_erofs_frontend *f,
drain_io:
if (erofs_is_fileio_mode(EROFS_SB(sb)))
erofs_fileio_submit_bio(bio);
- else if (erofs_is_fscache_mode(sb))
- erofs_fscache_submit_bio(bio);
else
submit_bio(bio);
@@ -1744,8 +1742,6 @@ static void z_erofs_submit_queue(struct z_erofs_frontend *f,
if (!bio) {
if (erofs_is_fileio_mode(EROFS_SB(sb)))
bio = erofs_fileio_bio_alloc(&mdev);
- else if (erofs_is_fscache_mode(sb))
- bio = erofs_fscache_bio_alloc(&mdev);
else
bio = bio_alloc(mdev.m_bdev, BIO_MAX_VECS,
REQ_OP_READ, GFP_NOIO);
@@ -1774,8 +1770,6 @@ static void z_erofs_submit_queue(struct z_erofs_frontend *f,
if (bio) {
if (erofs_is_fileio_mode(EROFS_SB(sb)))
erofs_fileio_submit_bio(bio);
- else if (erofs_is_fscache_mode(sb))
- erofs_fscache_submit_bio(bio);
else
submit_bio(bio);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 085/438] erofs: ensure valid f_path for page cache sharing
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 084/438] erofs: remove fscache backend entirely Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 086/438] gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper Greg Kroah-Hartman
` (366 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hongbo Li, Gao Xiang, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gao Xiang <xiang@kernel.org>
[ Upstream commit 96b2dbbe58a1ea5df8d29c2fe24b5f04715f4443 ]
Previously, backing files for page cache sharing were set up with
f_path left as NULL (only f_inode was valid). It worked, but a recent
mincore fix relies on f_path.mnt and crashes (found by "erofs/028" on
7.2-rc4):
BUG: kernel NULL pointer dereference, address: 0000000000000018
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: Oops: 0000 [#1] SMP PTI
CPU: 3 UID: 0 PID: 675528 Comm: fincore Not tainted 7.2.0-rc4-00002-g[]-dirty #1 PREEMPT(lazy)
Hardware name: Red Hat KVM, BIOS 1.16.0-4.al8 04/01/2014
RIP: 0010:__do_sys_mincore+0xc0/0x2c0
...
Specify valid paths using valid disconnected dentries together with
erofs_ishare_mnt instead of leaving f_path empty, so they are more
like real backing files in a pseudo filesystem and standard
backing_file_open() can be used directly.
Fixes: e187bc02f8fa ("mm: do file ownership checks with the proper mount idmap")
Acked-by: Hongbo Li <hongbohbli@tencent.com>
Signed-off-by: Gao Xiang <xiang@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/erofs/Kconfig | 1 +
fs/erofs/internal.h | 4 ++--
fs/erofs/ishare.c | 58 ++++++++++++++++++++++-----------------------
3 files changed, 31 insertions(+), 32 deletions(-)
diff --git a/fs/erofs/Kconfig b/fs/erofs/Kconfig
index 4789b1077d8ce..1feb28cfe557d 100644
--- a/fs/erofs/Kconfig
+++ b/fs/erofs/Kconfig
@@ -189,6 +189,7 @@ config EROFS_FS_PCPU_KTHREAD_HIPRI
config EROFS_FS_PAGE_CACHE_SHARE
bool "EROFS page cache share support (experimental)"
depends on EROFS_FS && EROFS_FS_XATTR
+ select FS_STACK
help
This enables page cache sharing among inodes with identical
content fingerprints on the same machine.
diff --git a/fs/erofs/internal.h b/fs/erofs/internal.h
index 580f8d9f14e7f..57bd21859c65d 100644
--- a/fs/erofs/internal.h
+++ b/fs/erofs/internal.h
@@ -288,8 +288,8 @@ struct erofs_inode {
struct erofs_inode_fingerprint fingerprint;
spinlock_t ishare_lock;
};
- /* for each real inode */
- struct inode *sharedinode;
+ /* for each real filesystem inode */
+ struct dentry *sharedentry;
};
#endif
/* the corresponding vfs inode */
diff --git a/fs/erofs/ishare.c b/fs/erofs/ishare.c
index 0868c12fc15b4..25558df98a389 100644
--- a/fs/erofs/ishare.c
+++ b/fs/erofs/ishare.c
@@ -2,14 +2,13 @@
/*
* Copyright (C) 2024, Alibaba Cloud
*/
+#include <linux/backing-file.h>
#include <linux/xxhash.h>
#include <linux/mount.h>
#include <linux/security.h>
#include "internal.h"
#include "xattr.h"
-#include "../internal.h"
-
static struct vfsmount *erofs_ishare_mnt;
static inline bool erofs_is_ishare_inode(struct inode *inode)
@@ -39,10 +38,12 @@ static int erofs_ishare_iget5_set(struct inode *inode, void *data)
bool erofs_ishare_fill_inode(struct inode *inode)
{
+ static const struct file_operations empty_fops = {};
struct erofs_sb_info *sbi = EROFS_SB(inode->i_sb);
const struct address_space_operations *aops;
struct erofs_inode *vi = EROFS_I(inode);
struct erofs_inode_fingerprint fp;
+ struct dentry *sd;
struct inode *si;
aops = erofs_get_aops(inode);
@@ -55,7 +56,9 @@ bool erofs_ishare_fill_inode(struct inode *inode)
xxh32(fp.opaque, fp.size, 0),
erofs_ishare_iget5_eq, erofs_ishare_iget5_set, &fp);
if (si && (inode_state_read_once(si) & I_NEW)) {
+ si->i_fop = &empty_fops;
si->i_mapping->a_ops = aops;
+ si->i_mode = 0444 | S_IFREG;
si->i_size = inode->i_size;
unlock_new_inode(si);
} else {
@@ -71,7 +74,10 @@ bool erofs_ishare_fill_inode(struct inode *inode)
return false;
}
}
- vi->sharedinode = si;
+ sd = d_obtain_alias(si); /* disconnected denties for sharedinodes */
+ if (IS_ERR(sd))
+ return false;
+ vi->sharedentry = sd;
INIT_LIST_HEAD(&vi->ishare_list);
spin_lock(&EROFS_I(si)->ishare_lock);
list_add(&vi->ishare_list, &EROFS_I(si)->ishare_list);
@@ -81,48 +87,40 @@ bool erofs_ishare_fill_inode(struct inode *inode)
void erofs_ishare_free_inode(struct inode *inode)
{
- struct erofs_inode *vi = EROFS_I(inode);
- struct inode *sharedinode = vi->sharedinode;
+ struct erofs_inode *vi = EROFS_I(inode), *svi;
- if (!sharedinode)
+ if (!vi->sharedentry)
return;
- spin_lock(&EROFS_I(sharedinode)->ishare_lock);
+ svi = EROFS_I(d_inode(vi->sharedentry));
+ spin_lock(&svi->ishare_lock);
list_del(&vi->ishare_list);
- spin_unlock(&EROFS_I(sharedinode)->ishare_lock);
- iput(sharedinode);
- vi->sharedinode = NULL;
+ spin_unlock(&svi->ishare_lock);
+ dput(vi->sharedentry);
+ vi->sharedentry = NULL;
}
static int erofs_ishare_file_open(struct inode *inode, struct file *file)
{
- struct inode *sharedinode = EROFS_I(inode)->sharedinode;
- struct file *realfile;
+ struct path sharedpath = {
+ .mnt = erofs_ishare_mnt,
+ .dentry = EROFS_I(inode)->sharedentry,
+ };
+ struct file *rf;
if (file->f_flags & O_DIRECT)
return -EINVAL;
- realfile = alloc_empty_backing_file(O_RDONLY|O_NOATIME, current_cred(),
- file);
- if (IS_ERR(realfile))
- return PTR_ERR(realfile);
- ihold(sharedinode);
- realfile->f_op = &erofs_file_fops;
- realfile->f_inode = sharedinode;
- realfile->f_mapping = sharedinode->i_mapping;
- path_get(&file->f_path);
- backing_file_set_user_path(realfile, &file->f_path);
-
- file_ra_state_init(&realfile->f_ra, file->f_mapping);
- realfile->private_data = EROFS_I(inode);
- file->private_data = realfile;
+
+ rf = backing_file_open(file, file->f_flags | O_NOATIME,
+ &sharedpath, current_cred());
+ if (IS_ERR(rf))
+ return PTR_ERR(rf);
+ file->private_data = rf;
return 0;
}
static int erofs_ishare_file_release(struct inode *inode, struct file *file)
{
- struct file *realfile = file->private_data;
-
- iput(realfile->f_inode);
- fput(realfile);
+ fput(file->private_data);
file->private_data = NULL;
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 086/438] gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 085/438] erofs: ensure valid f_path for page cache sharing Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 087/438] ACPI: CPPC: Skip writes to unsupported performance controls Greg Kroah-Hartman
` (365 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Tran, Linus Walleij,
Bartosz Golaszewski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Tran <alex.tran@oss.qualcomm.com>
[ Upstream commit 67ff4bf723c8bd1f1b10450fa3e8f55762418104 ]
After successfully configuring gpio pin as output, set the
requested initial output value via the existing gpio set
wrapper, so that the pin is not left at its previous level.
Fixes: 7671f4949a6c ("gpio: gpio-by-pinctrl: add pinctrl based generic GPIO driver")
Signed-off-by: Alex Tran <alex.tran@oss.qualcomm.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260724-gpio-pinctrl-output-set-val-v2-1-cad55d025636@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-by-pinctrl.c | 18 ++++++++++++------
1 file changed, 12 insertions(+), 6 deletions(-)
diff --git a/drivers/gpio/gpio-by-pinctrl.c b/drivers/gpio/gpio-by-pinctrl.c
index ddfdc479d38a8..b3b3c11376172 100644
--- a/drivers/gpio/gpio-by-pinctrl.c
+++ b/drivers/gpio/gpio-by-pinctrl.c
@@ -28,12 +28,6 @@ static int pin_control_gpio_get_direction(struct gpio_chip *gc, unsigned int off
return GPIO_LINE_DIRECTION_IN;
}
-static int pin_control_gpio_direction_output(struct gpio_chip *chip,
- unsigned int offset, int val)
-{
- return pinctrl_gpio_direction_output(chip, offset);
-}
-
static int pin_control_gpio_get(struct gpio_chip *chip, unsigned int offset)
{
unsigned long config;
@@ -56,6 +50,18 @@ static int pin_control_gpio_set(struct gpio_chip *chip, unsigned int offset,
return pinctrl_gpio_set_config(chip, offset, config);
}
+static int pin_control_gpio_direction_output(struct gpio_chip *chip,
+ unsigned int offset, int val)
+{
+ int ret;
+
+ ret = pinctrl_gpio_direction_output(chip, offset);
+ if (ret)
+ return ret;
+
+ return pin_control_gpio_set(chip, offset, val);
+}
+
static int pin_control_gpio_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 087/438] ACPI: CPPC: Skip writes to unsupported performance controls
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 086/438] gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 088/438] wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() Greg Kroah-Hartman
` (364 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sumit Gupta, Christian Loehle,
Lifeng Zheng, Rafael J. Wysocki, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Loehle <christian.loehle@arm.com>
[ Upstream commit 47d4e945dff8139050473be4ab263a32e1da910c ]
MIN_PERF and MAX_PERF are optional CPPC controls. DESIRED_PERF is also
optional with CPPC2 when autonomous selection is supported.
The cppc-cpufreq target callbacks populate both limits for every request
without checking whether the controls are implemented. cppc_set_perf()
consequently passes NULL register descriptors to cpc_write(). The writes
fail width validation and their return values are ignored, so the failed
access paths are repeated on every target request. An autonomous-only
platform can take the same path for DESIRED_PERF.
Check that each performance control is supported before calling
cpc_write().
Fixes: ea3db45ae476 ("cpufreq: cppc: Update MIN_PERF/MAX_PERF in target callbacks")
Reviewed-by: Sumit Gupta <sumitg@nvidia.com>
Signed-off-by: Christian Loehle <christian.loehle@arm.com>
Reviewed-by: Lifeng Zheng <zhenglifeng1@huawei.com>
Link: https://patch.msgid.link/20260724104042.1481804-1-christian.loehle@arm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/cppc_acpi.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/acpi/cppc_acpi.c b/drivers/acpi/cppc_acpi.c
index 34edec0f2bde2..aa4017be960a0 100644
--- a/drivers/acpi/cppc_acpi.c
+++ b/drivers/acpi/cppc_acpi.c
@@ -1940,16 +1940,17 @@ int cppc_set_perf(int cpu, struct cppc_perf_ctrls *perf_ctrls)
cpc_desc->write_cmd_status = 0;
}
- cpc_write(cpu, desired_reg, perf_ctrls->desired_perf);
+ if (CPC_SUPPORTED(desired_reg))
+ cpc_write(cpu, desired_reg, perf_ctrls->desired_perf);
/*
* Only write if min_perf and max_perf not zero. Some drivers pass zero
* value to min and max perf, but they don't mean to set the zero value,
* they just don't want to write to those registers.
*/
- if (perf_ctrls->min_perf)
+ if (perf_ctrls->min_perf && CPC_SUPPORTED(min_perf_reg))
cpc_write(cpu, min_perf_reg, perf_ctrls->min_perf);
- if (perf_ctrls->max_perf)
+ if (perf_ctrls->max_perf && CPC_SUPPORTED(max_perf_reg))
cpc_write(cpu, max_perf_reg, perf_ctrls->max_perf);
if (CPC_IN_PCC(desired_reg) || CPC_IN_PCC(min_perf_reg) || CPC_IN_PCC(max_perf_reg))
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 088/438] wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 087/438] ACPI: CPPC: Skip writes to unsupported performance controls Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 089/438] ASoC: tas2781: Use correct calibration data for SINEGAIN2 register Greg Kroah-Hartman
` (363 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
[ Upstream commit 47abd2ca281531deee38a3b3770d885e270e9fc9 ]
ath12k_mac_dp_peer_cleanup() clears the ML peer ID slot on the
free_ml_peer_id_map bitmap by indexing it with dp_peer->peer_id. That is
wrong: dp_peer->peer_id for an MLO peer always carries the
ATH12K_PEER_ML_ID_VALID bit (BIT(13)), so clear_bit() is invoked with
index >= 0x2000, which is far outside the bitmap of ATH12K_MAX_MLO_PEERS
(256) bits and corrupts memory adjacent to ah->free_ml_peer_id_map. The
intended bitmap entry also never gets cleared, so subsequent
ath12k_peer_ml_alloc() calls eventually run out of IDs.
The ID without the VALID bit is what ath12k_peer_ml_alloc() returned and
is stored in ahsta->ml_peer_id. Use that instead.
While there, also reset ahsta->ml_peer_id to ATH12K_MLO_PEER_ID_INVALID so
the bitmap and ahsta->ml_peer_id stay in sync.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3
Fixes: ee16dcf573d5 ("wifi: ath12k: Define ath12k_dp_peer structure & APIs for create & delete")
Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260720-ath12k-fw-allocated-ml-peer-id-v2-1-630632758a80@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/mac.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
index 7408c2577dc2e..d13fb31d13014 100644
--- a/drivers/net/wireless/ath/ath12k/mac.c
+++ b/drivers/net/wireless/ath/ath12k/mac.c
@@ -1283,8 +1283,11 @@ void ath12k_mac_dp_peer_cleanup(struct ath12k_hw *ah)
spin_lock_bh(&dp_hw->peer_lock);
list_for_each_entry_safe(dp_peer, tmp, &dp_hw->dp_peers_list, list) {
if (dp_peer->is_mlo) {
+ struct ath12k_sta *ahsta = ath12k_sta_to_ahsta(dp_peer->sta);
+
rcu_assign_pointer(dp_hw->dp_peers[dp_peer->peer_id], NULL);
- clear_bit(dp_peer->peer_id, ah->free_ml_peer_id_map);
+ clear_bit(ahsta->ml_peer_id, ah->free_ml_peer_id_map);
+ ahsta->ml_peer_id = ATH12K_MLO_PEER_ID_INVALID;
}
list_move(&dp_peer->list, &peers);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 089/438] ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 088/438] wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 090/438] spi: spi-cadence: Move TX FIFO full busy-wait into FIFO Greg Kroah-Hartman
` (362 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, wangdicheng, Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: wangdicheng <wangdicheng@kylinos.cn>
[ Upstream commit dd88cf6273de61f2f7206c2066af97798dbb38b0 ]
The SINEGAIN2_REG case in cali_reg_update() references t->sin_gn[]
rather than t->sin_gn2[], causing the second pilot tone gain
calibration to be programmed with the wrong register address.
These are distinct fields in struct fct_param_address and are
populated from separate firmware parameters by the parser in
tas2781-fmwlib.c.
Fixes: 84d6a465f211 ("ASoC: tas2781: Support dsp firmware Alpha and Beta seaies")
Signed-off-by: wangdicheng <wangdicheng@kylinos.cn>
Link: https://patch.msgid.link/20260720081616.631413-1-wangdich9700@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/tas2781-i2c.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/soc/codecs/tas2781-i2c.c b/sound/soc/codecs/tas2781-i2c.c
index a78a8f9b98338..775c3767bf3a8 100644
--- a/sound/soc/codecs/tas2781-i2c.c
+++ b/sound/soc/codecs/tas2781-i2c.c
@@ -1308,8 +1308,8 @@ static void cali_reg_update(struct bulk_reg_val *p,
t->sin_gn[2]);
break;
case TAS2781_PRM_SINEGAIN2_REG:
- reg = TASDEVICE_REG(t->sin_gn[0], t->sin_gn[1],
- t->sin_gn[2]);
+ reg = TASDEVICE_REG(t->sin_gn2[0], t->sin_gn2[1],
+ t->sin_gn2[2]);
break;
default:
reg = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 090/438] spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 089/438] ASoC: tas2781: Use correct calibration data for SINEGAIN2 register Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 091/438] hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 Greg Kroah-Hartman
` (361 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Srikanth Boyapally,
Radhey Shyam Pandey, Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Srikanth Boyapally <srikanth.boyapally@amd.com>
[ Upstream commit d9eadfce2fac49445db40808fe4d8259f20a9d2b ]
SPI host transfers could intermittently stall with spi_transfer timeouts.
The TXFULL condition was checked only once in cdns_transfer_one() before
cdns_spi_process_fifo(), so if the FIFO became full again during refill,
writes could be dropped and the transfer would never complete.
Move the TXFULL busy-wait into the TX path of cdns_spi_process_fifo() so
the 10µs back-off is applied per FIFO entry during filling, ensuring
forward progress and eliminating spurious timeouts.
Restrict the delay to host mode using spi_controller_is_target(), the
controller is passed into cdns_spi_process_fifo() so the check is made at
the point of use. In target mode this delay must not run as it causes the
target to miss its transfer window and corrupt data.
Fixes: 49530e641178 ("spi: cadence: Add usleep_range() for cdns_spi_fill_tx_fifo()")
Signed-off-by: Srikanth Boyapally <srikanth.boyapally@amd.com>
Reviewed-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Link: https://patch.msgid.link/20260720125510.60166-1-srikanth.boyapally@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-cadence.c | 26 ++++++++++++++++----------
1 file changed, 16 insertions(+), 10 deletions(-)
diff --git a/drivers/spi/spi-cadence.c b/drivers/spi/spi-cadence.c
index 891e2ba369584..2f549e668ae6a 100644
--- a/drivers/spi/spi-cadence.c
+++ b/drivers/spi/spi-cadence.c
@@ -388,11 +388,13 @@ static inline void cdns_spi_writer(struct cdns_spi *xspi)
/**
* cdns_spi_process_fifo - Fills the TX FIFO, and drain the RX FIFO
+ * @ctlr: Pointer to the spi_controller structure
* @xspi: Pointer to the cdns_spi structure
* @ntx: Number of bytes to pack into the TX FIFO
* @nrx: Number of bytes to drain from the RX FIFO
*/
-static void cdns_spi_process_fifo(struct cdns_spi *xspi, int ntx, int nrx)
+static void cdns_spi_process_fifo(struct spi_controller *ctlr,
+ struct cdns_spi *xspi, int ntx, int nrx)
{
ntx = clamp(ntx, 0, xspi->tx_bytes);
nrx = clamp(nrx, 0, xspi->rx_bytes);
@@ -407,6 +409,16 @@ static void cdns_spi_process_fifo(struct cdns_spi *xspi, int ntx, int nrx)
}
if (ntx) {
+ /* When xspi in busy condition, bytes may send failed,
+ * then spi control didn't work thoroughly, add one byte
+ * delay. Only in host mode; in target mode this delay
+ * causes data corruption as the target fails to prepare
+ * data in time.
+ */
+ if (!spi_controller_is_target(ctlr) &&
+ (cdns_spi_read(xspi, CDNS_SPI_ISR) & CDNS_SPI_IXR_TXFULL))
+ udelay(10);
+
cdns_spi_writer(xspi);
ntx--;
}
@@ -460,14 +472,14 @@ static irqreturn_t cdns_spi_irq(int irq, void *dev_id)
cdns_spi_write(xspi, CDNS_SPI_THLD, 1);
if (xspi->tx_bytes) {
- cdns_spi_process_fifo(xspi, trans_cnt, trans_cnt);
+ cdns_spi_process_fifo(ctlr, xspi, trans_cnt, trans_cnt);
} else {
/* Fixed delay due to controller limitation with
* RX_NEMPTY incorrect status
* Xilinx AR:65885 contains more details
*/
udelay(10);
- cdns_spi_process_fifo(xspi, 0, trans_cnt);
+ cdns_spi_process_fifo(ctlr, xspi, 0, trans_cnt);
cdns_spi_write(xspi, CDNS_SPI_IDR,
CDNS_SPI_IXR_DEFAULT);
spi_finalize_current_transfer(ctlr);
@@ -520,17 +532,11 @@ static int cdns_transfer_one(struct spi_controller *ctlr,
cdns_spi_write(xspi, CDNS_SPI_THLD, xspi->tx_fifo_depth >> 1);
}
- /* When xspi in busy condition, bytes may send failed,
- * then spi control didn't work thoroughly, add one byte delay
- */
- if (cdns_spi_read(xspi, CDNS_SPI_ISR) & CDNS_SPI_IXR_TXFULL)
- udelay(10);
-
xspi->n_bytes = cdns_spi_n_bytes(transfer);
xspi->tx_bytes = DIV_ROUND_UP(xspi->tx_bytes, xspi->n_bytes);
xspi->rx_bytes = DIV_ROUND_UP(xspi->rx_bytes, xspi->n_bytes);
- cdns_spi_process_fifo(xspi, xspi->tx_fifo_depth, 0);
+ cdns_spi_process_fifo(ctlr, xspi, xspi->tx_fifo_depth, 0);
cdns_spi_write(xspi, CDNS_SPI_IER, CDNS_SPI_IXR_DEFAULT);
return transfer->len;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 091/438] hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 090/438] spi: spi-cadence: Move TX FIFO full busy-wait into FIFO Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 092/438] hwmon: (ina2xx) Fix various overflow issues Greg Kroah-Hartman
` (360 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Bezdeka, Björn Gerhart,
Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit b0e8adb2ccb43009796897ced09f91636685c9d3 ]
Unlike NCT6106, NCT6116 only has three temperature registers, and with
it only three temperature source and temperature source configuration
registers. The register addresses match those of NCT6106 and can be
re-used.
The code used a separate array to list the temperature source registers
for NCT6116, but used the size of the NCT6106 register array to set
the number of registers. The NCT6106 register array provides six addresses,
while the temperature source register array for NCT6116 only provides three
addresses. This causes a KASAN report.
BUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775]
Read of size 2 at addr ffffffffc19561a6 by task modprobe/954
...
Call Trace:
dump_stack+0x7d/0xa7
print_address_description.constprop.0+0x1c/0x220
? __kasan_kmalloc.constprop.0+0xc9/0xd0
? __kmalloc_node_track_caller+0x194/0x5b0
? nct6775_probe+0x936/0x46f0 [nct6775]
? nct6775_probe+0x936/0x46f0 [nct6775]
...
Fix the problem by hard-coding the number of temperature and temperature
configuration registers to three for NCT6116. Drop the unnecessary
NCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE.
Reported-by: Florian Bezdeka <florian.bezdeka@siemens.com>
Closes: https://lore.kernel.org/linux-hwmon/57cfc3fa-d4e9-4c10-8aa7-4ad0af7ebebe@roeck-us.net/T/#t
Fixes: 29c7cb485b32 ("hwmon: (nct6775) Integrate new model nct6116")
Cc: Björn Gerhart <gerhart@posteo.de>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/nct6775-core.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/hwmon/nct6775-core.c b/drivers/hwmon/nct6775-core.c
index d668dc390def8..51253acff4b06 100644
--- a/drivers/hwmon/nct6775-core.c
+++ b/drivers/hwmon/nct6775-core.c
@@ -846,8 +846,6 @@ static const u16 NCT6116_FAN_PULSE_SHIFT[] = { 0, 2, 4, 6, 6 };
static const u16 NCT6116_REG_PWM[] = { 0x119, 0x129, 0x139, 0x199, 0x1a9 };
static const u16 NCT6116_REG_FAN_MODE[] = { 0x113, 0x123, 0x133, 0x193, 0x1a3 };
static const u16 NCT6116_REG_TEMP_SEL[] = { 0x110, 0x120, 0x130, 0x190, 0x1a0 };
-static const u16 NCT6116_REG_TEMP_SOURCE[] = {
- 0xb0, 0xb1, 0xb2 };
static const u16 NCT6116_REG_CRITICAL_TEMP[] = {
0x11a, 0x12a, 0x13a, 0x19a, 0x1aa };
@@ -3652,7 +3650,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
= NCT6106_CRITICAL_PWM_ENABLE_MASK;
data->REG_CRITICAL_PWM = NCT6116_REG_CRITICAL_PWM;
data->REG_TEMP_OFFSET = NCT6106_REG_TEMP_OFFSET;
- data->REG_TEMP_SOURCE = NCT6116_REG_TEMP_SOURCE;
+ data->REG_TEMP_SOURCE = NCT6106_REG_TEMP_SOURCE;
data->REG_TEMP_SEL = NCT6116_REG_TEMP_SEL;
data->REG_WEIGHT_TEMP_SEL = NCT6106_REG_WEIGHT_TEMP_SEL;
data->REG_WEIGHT_TEMP[0] = NCT6106_REG_WEIGHT_TEMP_STEP;
@@ -3666,13 +3664,13 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
reg_temp = NCT6106_REG_TEMP;
reg_temp_mon = NCT6106_REG_TEMP_MON;
- num_reg_temp = ARRAY_SIZE(NCT6106_REG_TEMP);
+ num_reg_temp = 3;
num_reg_temp_mon = ARRAY_SIZE(NCT6106_REG_TEMP_MON);
num_reg_tsi_temp = ARRAY_SIZE(NCT6116_REG_TSI_TEMP);
reg_temp_over = NCT6106_REG_TEMP_OVER;
reg_temp_hyst = NCT6106_REG_TEMP_HYST;
reg_temp_config = NCT6106_REG_TEMP_CONFIG;
- num_reg_temp_config = ARRAY_SIZE(NCT6106_REG_TEMP_CONFIG);
+ num_reg_temp_config = 3;
reg_temp_alternate = NCT6106_REG_TEMP_ALTERNATE;
reg_temp_crit = NCT6106_REG_TEMP_CRIT;
reg_temp_crit_l = NCT6106_REG_TEMP_CRIT_L;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 092/438] hwmon: (ina2xx) Fix various overflow issues
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 091/438] hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 093/438] hwmon: (ltc4282) Fix reading the minimum alarm voltage Greg Kroah-Hartman
` (359 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guenter Roeck,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit e6c80061ca239f45c0eaf7e47a91d6d6df9bd636 ]
Sashiko reports several integer overflow problems in the ina2xx driver
caused by unbounded multiplications and inadequate types for intermediate
calculations.
Specifically:
- In ina2xx_get_value(), the return type is changed from int to long.
Intermediate calculations for current are now performed using 64-bit
types to prevent 32-bit integer overflow before the division by 1000.
- When calculating power in ina2xx_get_value() and
sy24655_average_power_read(), interim values are cast to u64 and clamped
to LONG_MAX. This prevents overflow when regval or accumulator_24 is
multiplied by power_lsb_uW.
- In ina226_alert_to_reg(), the clamping logic is rewritten using min_t().
This safely avoids integer overflows when scaling user-provided values
for shunt voltage, bus voltage, power, and current limits.
Cc: Loic Poulain <loic.poulain@oss.qualcomm.com>
Fixes: ab7fbee452be ("hwmon: (ina2xx) Fix various overflow issues")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/ina2xx.c | 61 ++++++++++++++++++++++++------------------
1 file changed, 35 insertions(+), 26 deletions(-)
diff --git a/drivers/hwmon/ina2xx.c b/drivers/hwmon/ina2xx.c
index 32bf4595bcb48..789eeb718b1ca 100644
--- a/drivers/hwmon/ina2xx.c
+++ b/drivers/hwmon/ina2xx.c
@@ -16,6 +16,7 @@
#include <linux/i2c.h>
#include <linux/init.h>
#include <linux/kernel.h>
+#include <linux/limits.h>
#include <linux/module.h>
#include <linux/property.h>
#include <linux/regmap.h>
@@ -266,30 +267,34 @@ static u16 ina226_interval_to_reg(long interval)
return FIELD_PREP(INA226_AVG_RD_MASK, avg_bits);
}
-static int ina2xx_get_value(struct ina2xx_data *data, u8 reg,
- unsigned int regval)
+static long ina2xx_get_value(struct ina2xx_data *data, u8 reg,
+ unsigned int regval)
{
- int val;
+ s64 val64;
+ long val;
switch (reg) {
case INA2XX_SHUNT_VOLTAGE:
/* signed register */
- val = (s16)regval >> data->config->shunt_voltage_shift;
- val = DIV_ROUND_CLOSEST(val, data->config->shunt_div);
+ val = DIV_ROUND_CLOSEST((s16)regval >> data->config->shunt_voltage_shift,
+ data->config->shunt_div);
break;
case INA2XX_BUS_VOLTAGE:
- val = (regval >> data->config->bus_voltage_shift) *
- data->config->bus_voltage_lsb;
- val = DIV_ROUND_CLOSEST(val, 1000);
+ val = DIV_ROUND_CLOSEST((regval >> data->config->bus_voltage_shift) *
+ data->config->bus_voltage_lsb, 1000);
break;
case INA2XX_POWER:
- val = regval * data->power_lsb_uW;
+ val = min_t(u64, (u64)regval * data->power_lsb_uW, LONG_MAX);
break;
case INA2XX_CURRENT:
/* signed register, result in mA */
- val = ((s16)regval >> data->config->current_shift) *
+ val64 = (s64)((s16)regval >> data->config->current_shift) *
data->current_lsb_uA;
- val = DIV_ROUND_CLOSEST(val, 1000);
+ if (val64 < 0)
+ val64 = -DIV_ROUND_CLOSEST_ULL(-val64, 1000);
+ else
+ val64 = DIV_ROUND_CLOSEST_ULL(val64, 1000);
+ val = clamp_val(val64, LONG_MIN, LONG_MAX);
break;
case INA2XX_CALIBRATION:
val = regval;
@@ -378,27 +383,29 @@ static int ina2xx_read_init(struct device *dev, int reg, long *val)
*/
static u16 ina226_alert_to_reg(struct ina2xx_data *data, int reg, long val)
{
+ long limit;
+
switch (reg) {
case INA2XX_SHUNT_VOLTAGE:
- val = clamp_val(val, 0, SHRT_MAX * data->config->shunt_div);
- val *= data->config->shunt_div;
- val <<= data->config->shunt_voltage_shift;
- return clamp_val(val, 0, SHRT_MAX);
+ val = min_t(long, val, DIV_ROUND_CLOSEST(SHRT_MAX, data->config->shunt_div));
+ return min_t(long, (val * data->config->shunt_div) << data->config->shunt_voltage_shift,
+ SHRT_MAX);
case INA2XX_BUS_VOLTAGE:
- val = clamp_val(val, 0, 200000);
- val = (val * 1000) << data->config->bus_voltage_shift;
- val = DIV_ROUND_CLOSEST(val, data->config->bus_voltage_lsb);
- return clamp_val(val, 0, USHRT_MAX);
+ val = min_t(long, val, 130000);
+ return min_t(long,
+ DIV_ROUND_CLOSEST((val * 1000) << data->config->bus_voltage_shift,
+ data->config->bus_voltage_lsb),
+ USHRT_MAX);
case INA2XX_POWER:
- val = clamp_val(val, 0, UINT_MAX - data->power_lsb_uW);
- val = DIV_ROUND_CLOSEST(val, data->power_lsb_uW);
- return clamp_val(val, 0, USHRT_MAX);
+ val = min_t(long, val, LONG_MAX - data->power_lsb_uW);
+ return min_t(long, DIV_ROUND_CLOSEST(val, data->power_lsb_uW), USHRT_MAX);
case INA2XX_CURRENT:
- val = clamp_val(val, INT_MIN / 1000, INT_MAX / 1000);
+ limit = (LONG_MAX - (data->current_lsb_uA / 2)) / 1000;
+ val = min_t(long, val, limit);
/* signed register, result in mA */
val = DIV_ROUND_CLOSEST(val * 1000, data->current_lsb_uA);
- val <<= data->config->current_shift;
- return clamp_val(val, SHRT_MIN, SHRT_MAX);
+ limit = SHRT_MAX >> data->config->current_shift;
+ return (u16)(min_t(long, val, limit) << data->config->current_shift);
default:
/* programmer goofed */
WARN_ON_ONCE(1);
@@ -537,6 +544,7 @@ static int sy24655_average_power_read(struct ina2xx_data *data, u8 reg, long *va
u8 template[6];
int ret;
long accumulator_24, sample_count;
+ u64 val64;
/* 48-bit register read */
ret = i2c_smbus_read_i2c_block_data(data->client, reg, 6, template);
@@ -555,7 +563,8 @@ static int sy24655_average_power_read(struct ina2xx_data *data, u8 reg, long *va
return 0;
}
- *val = DIV_ROUND_CLOSEST(accumulator_24, sample_count) * data->power_lsb_uW;
+ val64 = (u64)DIV_ROUND_CLOSEST(accumulator_24, sample_count) * data->power_lsb_uW;
+ *val = min_t(u64, val64, LONG_MAX);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 093/438] hwmon: (ltc4282) Fix reading the minimum alarm voltage
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 092/438] hwmon: (ina2xx) Fix various overflow issues Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 094/438] hwmon: (sht3x) Fix unaligned accesses Greg Kroah-Hartman
` (358 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nuno Sa, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit 00feb1cce93dab948a299b69753d99c681d45a0b ]
Coverity reports an out-of-bounds access when reading the minimum alarm
voltage for the VGPIO channel. Add the missing return statement to fix
the problem.
Fixes: cbc29538dbf7 ("hwmon: Add driver for LTC4282")
Cc: Nuno Sa <nuno.sa@analog.com>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/ltc4282.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/ltc4282.c b/drivers/hwmon/ltc4282.c
index b9084424160d6..bdbf370233d71 100644
--- a/drivers/hwmon/ltc4282.c
+++ b/drivers/hwmon/ltc4282.c
@@ -375,8 +375,8 @@ static int ltc4282_read_in(struct ltc4282_state *st, u32 attr, long *val,
channel, val);
case hwmon_in_min_alarm:
if (channel == LTC4282_CHAN_VGPIO)
- ltc4282_read_alarm(st, LTC4282_ADC_ALERT_LOG,
- LTC4282_GPIO_ALARM_L_MASK, val);
+ return ltc4282_read_alarm(st, LTC4282_ADC_ALERT_LOG,
+ LTC4282_GPIO_ALARM_L_MASK, val);
return ltc4282_vdd_source_read_alm(st,
LTC4282_VSOURCE_ALARM_L_MASK,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 094/438] hwmon: (sht3x) Fix unaligned accesses
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 093/438] hwmon: (ltc4282) Fix reading the minimum alarm voltage Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 095/438] hwmon: (lm90) Only report alarms if driver is ready Greg Kroah-Hartman
` (357 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit f46d5ab43a572b84773015a76966f5da56fc1748 ]
Sashiko reports:
In sht3x_update_client(), the 16-bit temperature and humidity values are
extracted from a stack-allocated byte array using be16_to_cpup(). The
pointers passed to this function are calculated as buf and buf + 3. Since
the difference between the two pointers is an odd number of bytes, at
least one of them is guaranteed to be at an unaligned offset.
This will trigger an alignment fault on strict-alignment architectures
such as ARMv5 or SPARC, resulting in a kernel panic.
Fix the problem by using get_unaligned_be16() instead of be16_to_cpup(),
and put_unaligned_be16() instead of cpu_to_be16().
Fixes: 7c84f7f80d6f ("hwmon: add support for Sensirion SHT3x sensors")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/sht3x.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/hwmon/sht3x.c b/drivers/hwmon/sht3x.c
index c2f6b73aa7f34..4d90f89a99297 100644
--- a/drivers/hwmon/sht3x.c
+++ b/drivers/hwmon/sht3x.c
@@ -21,6 +21,7 @@
#include <linux/module.h>
#include <linux/slab.h>
#include <linux/jiffies.h>
+#include <linux/unaligned.h>
/* commands (high repeatability mode) */
static const unsigned char sht3x_cmd_measure_single_hpm[] = { 0x24, 0x00 };
@@ -276,9 +277,9 @@ static struct sht3x_data *sht3x_update_client(struct device *dev)
if (ret)
goto out;
- val = be16_to_cpup((__be16 *)buf);
+ val = get_unaligned_be16(buf);
data->temperature = sht3x_extract_temperature(val);
- val = be16_to_cpup((__be16 *)(buf + 3));
+ val = get_unaligned_be16(buf + 3);
data->humidity = sht3x_extract_humidity(val);
data->last_update = jiffies;
}
@@ -336,7 +337,7 @@ static int limits_update(struct sht3x_data *data)
if (ret)
return ret;
- raw = be16_to_cpup((__be16 *)buffer);
+ raw = get_unaligned_be16(buffer);
temperature = sht3x_extract_temperature((raw & 0x01ff) << 7);
humidity = sht3x_extract_humidity(raw & 0xfe00);
data->temperature_limits[index] = temperature;
@@ -389,7 +390,7 @@ static size_t limit_write(struct device *dev,
raw = ((u32)(temperature + 45000) * 24543) >> (16 + 7);
raw |= ((humidity * 42950) >> 16) & 0xfe00;
- *((__be16 *)position) = cpu_to_be16(raw);
+ put_unaligned_be16(raw, position);
position += SHT3X_WORD_LEN;
*position = crc8(sht3x_crc8_table,
position - SHT3X_WORD_LEN,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 095/438] hwmon: (lm90) Only report alarms if driver is ready
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 094/438] hwmon: (sht3x) Fix unaligned accesses Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 096/438] hwmon: (nzxt-smart2) DMA-align output buffer Greg Kroah-Hartman
` (356 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 ]
Userspace can read sysfs attributes before driver registration is complete,
immediately after devm_hwmon_device_register_with_info() has been called.
At that time, data->hwmon_dev is not yet initialized. This can trigger
a NULL pointer access since lm90_update_device() and with it
lm90_update_alarms_locked() will be called. This call schedules
report_work and lm90_report_alarms(), which passes the still-NULL
data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer
dereference.
Fix the problem by only scheduling the report and alert workers
data->hwmon_dev is set.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: f6d0775119fb9 ("hwmon: (lm90) Rework alarm/status handling")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/lm90.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/lm90.c b/drivers/hwmon/lm90.c
index c78c96e1bd83f..c56dd958429be 100644
--- a/drivers/hwmon/lm90.c
+++ b/drivers/hwmon/lm90.c
@@ -1194,7 +1194,7 @@ static int lm90_update_alarms_locked(struct lm90_data *data, bool force)
check_enable = (client->irq || !(data->config_orig & 0x80)) &&
(data->config & 0x80);
- if (force || check_enable)
+ if (data->hwmon_dev && (force || check_enable))
schedule_work(&data->report_work);
/*
@@ -1202,7 +1202,7 @@ static int lm90_update_alarms_locked(struct lm90_data *data, bool force)
* alarms are all clear, and alerts are currently disabled.
* Otherwise (re)schedule worker if needed.
*/
- if (check_enable) {
+ if (check_enable && data->hwmon_dev) {
if (!(data->current_alarms & data->alert_alarms)) {
dev_dbg(&client->dev, "Re-enabling ALERT#\n");
lm90_update_confreg(data, data->config & ~0x80);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 096/438] hwmon: (nzxt-smart2) DMA-align output buffer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 095/438] hwmon: (lm90) Only report alarms if driver is ready Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 097/438] net: do not send ICMP/NDISC Redirects when peer allocation fails Greg Kroah-Hartman
` (355 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Aleksandr Mezin,
Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit 080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8 ]
Sashiko reports:
When send_output_report() calls hid_hw_output_report(), the underlying USB
HID core calls usb_interrupt_msg() which maps this buffer directly for DMA.
When the DMA mapping flushes or invalidates the cacheline, it will corrupt
the adjacent variables (mutex, update_interval) that were modified
concurrently by the CPU. This causes memory corruption due to cacheline
sharing on non-coherent CPU architectures (such as ARM or MIPS). The DMA
API debugging tool (CONFIG_DMA_API_DEBUG) will trigger runtime warnings
for this violation.
Any operation that triggers send_output_report() (like setting a fan speed
or updating the interval) causes the USB DMA mapping. On systems with
non-coherent caches, this structural bug causes immediate and deterministic
memory corruption.
Align the output buffer to ARCH_DMA_MINALIGN to fix the problem.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 53e68c20aeb1 ("hwmon: add driver for NZXT RGB&Fan Controller/Smart Device v2.")
Cc: Aleksandr Mezin <mezin.alexander@gmail.com>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/nzxt-smart2.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hwmon/nzxt-smart2.c b/drivers/hwmon/nzxt-smart2.c
index e2316c46629d6..ff0c0bee0e839 100644
--- a/drivers/hwmon/nzxt-smart2.c
+++ b/drivers/hwmon/nzxt-smart2.c
@@ -203,7 +203,7 @@ struct drvdata {
*/
struct mutex mutex;
long update_interval;
- u8 output_buffer[OUTPUT_REPORT_SIZE];
+ u8 output_buffer[OUTPUT_REPORT_SIZE] __aligned(ARCH_DMA_MINALIGN);
};
static long scale_pwm_value(long val, long orig_max, long new_max)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 097/438] net: do not send ICMP/NDISC Redirects when peer allocation fails
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 096/438] hwmon: (nzxt-smart2) DMA-align output buffer Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 098/438] hwmon: (nct6775-core) Prevent access to unsupported weight registers Greg Kroah-Hartman
` (354 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit dbc3791e3b2472e1ccc08947e0f83b443470ff4f ]
When inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry
under memory pressure or tree size caps, redirect handlers previously fell
back to sending un-rate-limited ICMP/NDISC Redirect messages.
In IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL.
In IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into
inet_peer_xrlim_allow(), which returned true when peer == NULL.
Because ICMP/NDISC Redirects are not part of the default global rate limit
mask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates
an un-rate-limited ICMP packet storm.
Fix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and
ndisc_send_redirect() when peer is NULL.
Fixes: 92d868292634 ("inetpeer: Move ICMP rate limiting state into inet_peer entries.")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260724072901.1633601-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/route.c | 2 --
net/ipv6/ip6_output.c | 2 +-
net/ipv6/ndisc.c | 2 ++
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 3d62d45d84bda..7cc9a7336c30a 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -892,8 +892,6 @@ void ip_rt_send_redirect(struct sk_buff *skb)
peer = inet_getpeer_v4(net->ipv4.peers, ip_hdr(skb)->saddr, vif);
if (!peer) {
rcu_read_unlock();
- icmp_send(skb, ICMP_REDIRECT, ICMP_REDIR_HOST,
- rt_nexthop(rt, ip_hdr(skb)->daddr));
return;
}
diff --git a/net/ipv6/ip6_output.c b/net/ipv6/ip6_output.c
index b5d9c57fe439f..634f581e17114 100644
--- a/net/ipv6/ip6_output.c
+++ b/net/ipv6/ip6_output.c
@@ -641,7 +641,7 @@ int ip6_forward(struct sk_buff *skb)
/* Limit redirects both by destination (here)
and by source (inside ndisc_send_redirect)
*/
- if (inet_peer_xrlim_allow(peer, 1*HZ))
+ if (peer && inet_peer_xrlim_allow(peer, 1*HZ))
ndisc_send_redirect(skb, target);
rcu_read_unlock();
} else {
diff --git a/net/ipv6/ndisc.c b/net/ipv6/ndisc.c
index f867ec8d3d905..fe36b3f512850 100644
--- a/net/ipv6/ndisc.c
+++ b/net/ipv6/ndisc.c
@@ -1707,6 +1707,8 @@ void ndisc_send_redirect(struct sk_buff *skb, const struct in6_addr *target)
}
peer = inet_getpeer_v6(net->ipv6.peers, &ipv6_hdr(skb)->saddr);
+ if (!peer)
+ goto release;
ret = inet_peer_xrlim_allow(peer, 1*HZ);
if (!ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 098/438] hwmon: (nct6775-core) Prevent access to unsupported weight registers
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 097/438] net: do not send ICMP/NDISC Redirects when peer allocation fails Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 099/438] net: bridge: mrp: fix Option TLV length in MRP_Test frames Greg Kroah-Hartman
` (353 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Björn Gerhart,
Florian Bezdeka, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit d0b704e569ac3b8416d8e02270cdc9bf830ed395 ]
Sashiko reports:
During initialization of the nct6116 chip, the driver sets data->pwm_num
to 5. However, it assigns several NCT6106 register arrays (such as
NCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and
NCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP.
These arrays only contain 3 elements.
In nct6775_update_pwm(), the driver iterates up to data->pwm_num. If
data->has_pwm has bits 3 or 4 set (which is structurally possible for
nct6116), the loop attempts to read elements at index 3 and 4 from these
3-element arrays. This results in a global out-of-bounds read, which can
be caught by KASAN.
Furthermore, the driver uses these garbage out-of-bounds values as
hardware register addresses for subsequent read and write operations. This
leads to invalid hardware register access, potentially causing hardware
misconfiguration or system crashes.
The underlying problem is that the chip does support up to five fan
control channels, but only the first three support weight control.
Fix the problem by extending the affected weight register arrays with
zeroed fields. The driver uses zeroed register addresses to determine
if a register is supported or not, and skips accesses for unsupported
registers.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 29c7cb485b32 ("hwmon: (nct6775) Integrate new model nct6116")
Cc: Björn Gerhart <gerhart@posteo.de>
Cc: Florian Bezdeka <florian.bezdeka@siemens.com>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/nct6775-core.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/hwmon/nct6775-core.c b/drivers/hwmon/nct6775-core.c
index 51253acff4b06..94482c8092cda 100644
--- a/drivers/hwmon/nct6775-core.c
+++ b/drivers/hwmon/nct6775-core.c
@@ -791,12 +791,12 @@ static const u16 NCT6106_REG_TOLERANCE_H[] = { 0x112, 0x122, 0x132 };
static const u16 NCT6106_REG_TARGET[] = { 0x111, 0x121, 0x131 };
-static const u16 NCT6106_REG_WEIGHT_TEMP_SEL[] = { 0x168, 0x178, 0x188 };
-static const u16 NCT6106_REG_WEIGHT_TEMP_STEP[] = { 0x169, 0x179, 0x189 };
-static const u16 NCT6106_REG_WEIGHT_TEMP_STEP_TOL[] = { 0x16a, 0x17a, 0x18a };
-static const u16 NCT6106_REG_WEIGHT_DUTY_STEP[] = { 0x16b, 0x17b, 0x18b };
-static const u16 NCT6106_REG_WEIGHT_TEMP_BASE[] = { 0x16c, 0x17c, 0x18c };
-static const u16 NCT6106_REG_WEIGHT_DUTY_BASE[] = { 0x16d, 0x17d, 0x18d };
+static const u16 NCT6106_REG_WEIGHT_TEMP_SEL[] = { 0x168, 0x178, 0x188, 0, 0 };
+static const u16 NCT6106_REG_WEIGHT_TEMP_STEP[] = { 0x169, 0x179, 0x189, 0, 0 };
+static const u16 NCT6106_REG_WEIGHT_TEMP_STEP_TOL[] = { 0x16a, 0x17a, 0x18a, 0, 0 };
+static const u16 NCT6106_REG_WEIGHT_DUTY_STEP[] = { 0x16b, 0x17b, 0x18b, 0, 0 };
+static const u16 NCT6106_REG_WEIGHT_TEMP_BASE[] = { 0x16c, 0x17c, 0x18c, 0, 0 };
+static const u16 NCT6106_REG_WEIGHT_DUTY_BASE[] = { 0x16d, 0x17d, 0x18d, 0, 0 };
static const u16 NCT6106_REG_AUTO_TEMP[] = { 0x160, 0x170, 0x180 };
static const u16 NCT6106_REG_AUTO_PWM[] = { 0x164, 0x174, 0x184 };
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 099/438] net: bridge: mrp: fix Option TLV length in MRP_Test frames
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 098/438] hwmon: (nct6775-core) Prevent access to unsupported weight registers Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 100/438] ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set() Greg Kroah-Hartman
` (352 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Corvaglia, Nikolay Aleksandrov,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Corvaglia <david@corvaglia.dev>
[ Upstream commit 5546da86894d5906f131b05890705a7abf949d84 ]
oui is a pointer, so sizeof(oui) is the pointer size. The MRA
Option TLV thus advertises a wrong length (15 vs 10 on x86_64),
causing misparsing of the frame on peers. Fix is to replace
with sizeof(*oui).
Fixes: f7458934b079 ("net: bridge: mrp: Update the Test frames for MRA")
Signed-off-by: David Corvaglia <david@corvaglia.dev>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260726062605.2746-1-david@corvaglia.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_mrp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/bridge/br_mrp.c b/net/bridge/br_mrp.c
index f1aa67f7a0510..460be392af477 100644
--- a/net/bridge/br_mrp.c
+++ b/net/bridge/br_mrp.c
@@ -215,7 +215,7 @@ static struct sk_buff *br_mrp_alloc_test_skb(struct br_mrp *mrp,
struct br_mrp_oui_hdr *oui = NULL;
u8 length;
- length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(oui) +
+ length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(*oui) +
MRP_OPT_PADDING;
br_mrp_skb_tlv(skb, BR_MRP_TLV_HEADER_OPTION, length);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 100/438] ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 099/438] net: bridge: mrp: fix Option TLV length in MRP_Test frames Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 101/438] forcedeth: fix UAF of txrx_stats in nv_remove Greg Kroah-Hartman
` (351 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Surendra Singh Chouhan, Mark Brown,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Surendra Singh Chouhan <kr494167@gmail.com>
[ Upstream commit f47064c970d3e920a27435454c02df310695f6e1 ]
cv1800b_adc_volume_set() serves as the .put callback for the "Internal
I2S Capture Volume" control.
ALSA mixer control callbacks must return 1 when the register value is
modified, 0 if unchanged, or a negative error code on failure. Returning
0 unconditionally causes ALSA core to assume the value was unchanged,
suppressing SNDRV_CTL_EVENT_MASK_VALUE change notifications to userspace
sound servers (e.g. PipeWire/PulseAudio).
Fix this by comparing the new register value with the existing register
value. If unchanged, return 0; otherwise, write the updated value and
return 1.
Fixes: 4cf8752a03e6 ("ASoC: sophgo: add CV1800B internal ADC codec driver")
Signed-off-by: Surendra Singh Chouhan <kr494167@gmail.com>
Link: https://patch.msgid.link/20260727053804.25599-1-kr494167@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sophgo/cv1800b-sound-adc.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/sound/soc/sophgo/cv1800b-sound-adc.c b/sound/soc/sophgo/cv1800b-sound-adc.c
index b66761156b993..bd93e261bdd1d 100644
--- a/sound/soc/sophgo/cv1800b-sound-adc.c
+++ b/sound/soc/sophgo/cv1800b-sound-adc.c
@@ -251,16 +251,22 @@ static int cv1800b_adc_volume_set(struct snd_kcontrol *kcontrol,
u32 v_left = clamp_t(u32, ucontrol->value.integer.value[0], 0, 24);
u32 v_right = clamp_t(u32, ucontrol->value.integer.value[1], 0, 24);
- u32 val;
+ u32 val, old_val;
val = readl(priv->regs + CV1800B_RXADC_ANA0);
+ old_val = val;
+
val = u32_replace_bits(val, cv1800b_gains[v_left],
REG_COMB_LEFT_VOLUME);
val = u32_replace_bits(val, cv1800b_gains[v_right],
REG_COMB_RIGHT_VOLUME);
+
+ if (val == old_val)
+ return 0;
+
writel(val, priv->regs + CV1800B_RXADC_ANA0);
- return 0;
+ return 1;
}
static DECLARE_TLV_DB_SCALE(cv1800b_volume_tlv, 0, 200, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 101/438] forcedeth: fix UAF of txrx_stats in nv_remove
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 100/438] ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set() Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 102/438] hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors Greg Kroah-Hartman
` (350 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chenguang Zhao, Vadim Fedorenko,
Zhu Yanjun, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chenguang Zhao <zhaochenguang@kylinos.cn>
[ Upstream commit 22666ba1420164753d7b0f5a841986b25ace5435 ]
nv_remove() frees the per-CPU txrx_stats before unregister_netdev().
Until unregister completes, ndo_get_stats64, the NAPI/xmit data path,
and nv_close()/drain may still access txrx_stats, leading to a
use-after-free.
Free the stats only after unregister_netdev().
Fixes: f4b633b911fd ("forcedeth: use per cpu to collect xmit/recv statistics")
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Link: https://patch.msgid.link/20260723092637.2135095-1-chenguang.zhao@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/nvidia/forcedeth.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/nvidia/forcedeth.c b/drivers/net/ethernet/nvidia/forcedeth.c
index 5b0435d7bc395..58d3e55def486 100644
--- a/drivers/net/ethernet/nvidia/forcedeth.c
+++ b/drivers/net/ethernet/nvidia/forcedeth.c
@@ -6187,10 +6187,10 @@ static void nv_remove(struct pci_dev *pci_dev)
struct net_device *dev = pci_get_drvdata(pci_dev);
struct fe_priv *np = netdev_priv(dev);
- free_percpu(np->txrx_stats);
-
unregister_netdev(dev);
+ free_percpu(np->txrx_stats);
+
nv_restore_mac_addr(pci_dev);
/* restore any phy related changes */
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 102/438] hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 101/438] forcedeth: fix UAF of txrx_stats in nv_remove Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 103/438] hwmon: (adt7470) Fix cache updated before hardware write on I2C error Greg Kroah-Hartman
` (349 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Luiz Angelo Daros de Luca, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit 625a2c02a1c04571232a746fe188b4d9a8d63edd ]
During adt7470_read_temperatures(), the driver temporarily switches
the PWM channels to manual mode, performs the temperature collection,
and then restores the original configuration registers.
However, if an I2C transaction fails at any point after entering manual
mode, the function aborts and returns immediately. This leaves the
configuration registers un-restored, permanently trapping the fans in
manual mode.
Introduce a recovery path to ensure that the original PWM configuration
registers are always restored, even when intermediate I2C operations
fail.
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/r/20260716213252.EACA71F000E9@smtp.kernel.org
Fixes: ef67959c4253 ("hwmon: (adt7470) Convert to use regmap")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-1-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 40 +++++++++++++++++++++++++++++-----------
1 file changed, 29 insertions(+), 11 deletions(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 664349756dc2b..481d51617f4be 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -205,11 +205,12 @@ static inline int adt7470_write_word_data(struct adt7470_data *data, unsigned in
/* Probe for temperature sensors. Assumes lock is held */
static int adt7470_read_temperatures(struct adt7470_data *data)
{
- unsigned long res;
+ struct device *dev = regmap_get_device(data->regmap);
+ u8 pwm[ADT7470_FAN_COUNT];
unsigned int pwm_cfg[2];
- int err;
+ unsigned long res;
+ int err, err2;
int i;
- u8 pwm[ADT7470_FAN_COUNT];
/* save pwm[1-4] config register */
err = regmap_read(data->regmap, ADT7470_REG_PWM_CFG(0), &pwm_cfg[0]);
@@ -233,19 +234,19 @@ static int adt7470_read_temperatures(struct adt7470_data *data)
err = regmap_update_bits(data->regmap, ADT7470_REG_PWM_CFG(2),
ADT7470_PWM_AUTO_MASK, 0);
if (err < 0)
- return err;
+ goto out_restore;
/* write pwm control to whatever it was */
err = regmap_bulk_write(data->regmap, ADT7470_REG_PWM(0), &pwm[0],
ADT7470_PWM_COUNT);
if (err < 0)
- return err;
+ goto out_restore;
/* start reading temperature sensors */
err = regmap_update_bits(data->regmap, ADT7470_REG_CFG,
ADT7470_T05_STB_MASK, ADT7470_T05_STB_MASK);
if (err < 0)
- return err;
+ goto out_restore;
/* Delay is 200ms * number of temp sensors. */
res = msleep_interruptible((data->num_temp_sensors >= 0 ?
@@ -256,13 +257,30 @@ static int adt7470_read_temperatures(struct adt7470_data *data)
err = regmap_update_bits(data->regmap, ADT7470_REG_CFG,
ADT7470_T05_STB_MASK, 0);
if (err < 0)
- return err;
+ goto out_restore;
+out_restore:
/* restore pwm[1-4] config registers */
- err = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(0), pwm_cfg[0]);
- if (err < 0)
- return err;
- err = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(2), pwm_cfg[1]);
+ err2 = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(0), pwm_cfg[0]);
+ if (err2 < 0) {
+ dev_warn_ratelimited(dev,
+ "failed to restore PWM{1,2} config (%d)\n",
+ err2);
+
+ if (!err)
+ err = err2;
+ }
+
+ err2 = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(2), pwm_cfg[1]);
+ if (err2 < 0) {
+ dev_warn_ratelimited(dev,
+ "failed to restore PWM{3,4} config (%d)\n",
+ err2);
+
+ if (!err)
+ err = err2;
+ }
+
if (err < 0)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 103/438] hwmon: (adt7470) Fix cache updated before hardware write on I2C error
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 102/438] hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors Greg Kroah-Hartman
@ 2026-08-07 14:34 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 104/438] hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread Greg Kroah-Hartman
` (348 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:34 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Angelo Daros de Luca,
Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit 05270bd38d9bf88a2f4c212246a8fa29f4032078 ]
adt7470_temp_write() and adt7470_pwm_write() update the driver's
cached values (temp_min, temp_max, pwm_input, pwm_enable) before issuing
the corresponding regmap_write(), and never check whether the write
succeeded before committing that update. If the I2C transaction fails,
the function correctly propagates the error to the caller, but the cache
silently keeps the new value, which was never actually applied to the
hardware. Subsequent reads then report a value that does not match the
device state.
Reorder both write paths to update the cache only after a successful
regmap_write(), so the cache always reflects what was actually
written to the hardware.
Fixes: ef67959c4253 ("hwmon: (adt7470) Convert to use regmap")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-2-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 481d51617f4be..62ec68ea0a406 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -589,14 +589,16 @@ static int adt7470_temp_write(struct device *dev, u32 attr, int channel, long va
switch (attr) {
case hwmon_temp_min:
mutex_lock(&data->lock);
- data->temp_min[channel] = val;
err = regmap_write(data->regmap, ADT7470_TEMP_MIN_REG(channel), val);
+ if (!err)
+ data->temp_min[channel] = val;
mutex_unlock(&data->lock);
break;
case hwmon_temp_max:
mutex_lock(&data->lock);
- data->temp_max[channel] = val;
err = regmap_write(data->regmap, ADT7470_TEMP_MAX_REG(channel), val);
+ if (!err)
+ data->temp_max[channel] = val;
mutex_unlock(&data->lock);
break;
default:
@@ -831,9 +833,10 @@ static int adt7470_pwm_write(struct device *dev, u32 attr, int channel, long val
case hwmon_pwm_input:
val = clamp_val(val, 0, 255);
mutex_lock(&data->lock);
- data->pwm[channel] = val;
err = regmap_write(data->regmap, ADT7470_REG_PWM(channel),
- data->pwm[channel]);
+ val);
+ if (!err)
+ data->pwm[channel] = val;
mutex_unlock(&data->lock);
break;
case hwmon_pwm_enable:
@@ -847,10 +850,11 @@ static int adt7470_pwm_write(struct device *dev, u32 attr, int channel, long val
val--;
mutex_lock(&data->lock);
- data->pwm_automatic[channel] = val;
err = regmap_update_bits(data->regmap, ADT7470_REG_PWM_CFG(channel),
pwm_auto_reg_mask,
val ? pwm_auto_reg_mask : 0);
+ if (!err)
+ data->pwm_automatic[channel] = val;
mutex_unlock(&data->lock);
break;
case hwmon_pwm_freq:
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 104/438] hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-08-07 14:34 ` [PATCH 7.1 103/438] hwmon: (adt7470) Fix cache updated before hardware write on I2C error Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 105/438] hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() Greg Kroah-Hartman
` (347 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Luiz Angelo Daros de Luca, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit cb0b7f9c43b0abbd422a7e4c2c85e91db429207c ]
When userspace configures 'auto_update_interval' to 0 via sysfs, the
background kthread executes schedule_timeout_interruptible(0), which
returns immediately.
If 'num_temp_sensors' is concurrently or previously set to 0, the
msleep_interruptible() delay inside adt7470_read_temperatures() also
becomes 0. This combination forces the background thread into a tight,
unbounded busy-loop, hogging the CPU and flooding the I2C bus with a
continuous stream of transactions.
Fix this vulnerability by raising the lower limit of the clamp_val in
auto_update_interval_store() from 0 to 500 milliseconds. This guarantees
a reasonable minimum sleep window between sensor updates, protecting the
system from intentional or accidental I2C bus denial of service.
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/r/20260716213252.EACA71F000E9@smtp.kernel.org
Fixes: 89fac11cb3e7 ("adt7470: make automatic fan control really work")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-3-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 62ec68ea0a406..0b19b0925d1c7 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -509,7 +509,7 @@ static ssize_t auto_update_interval_store(struct device *dev,
if (kstrtol(buf, 10, &temp))
return -EINVAL;
- temp = clamp_val(temp, 0, 60000);
+ temp = clamp_val(temp, 500, 60000);
mutex_lock(&data->lock);
data->auto_update_interval = temp;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 105/438] hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 104/438] hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 106/438] hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks Greg Kroah-Hartman
` (346 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Luiz Angelo Daros de Luca, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit 1a18c79c4bc44cc5349c60e16b0b744dc6ec5f77 ]
During the conversion the alarm callback started interpreting the
channel index as an alarm bitmask, resulting in incorrect alarm
reporting. Compute the proper alarm bit instead.
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/r/20260717211224.B9E291F000E9@smtp.kernel.org
Fixes: fc958a61ff6d ("hwmon: (adt7470) Convert to devm_hwmon_device_register_with_info API")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-5-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 19 +++++++++++++++++--
1 file changed, 17 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 0b19b0925d1c7..428bd1d91e700 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -110,6 +110,21 @@ static const unsigned short normal_i2c[] = { 0x2C, 0x2E, 0x2F, I2C_CLIENT_END };
#define ALARM2(x) ((x) << 8)
+/* TEMP1..TEMP7 (ch 0..6) are, respectively BIT(0)..BIT(6) of reg 0x41 and
+ * 0x72, or BIT(0)..BIT(6) of data->alarm.
+ * TEMP8..TEMP9 (ch 7..9) are, respectively BIT(0)..BIT(2) of reg 0x42 and
+ * 0x73, or BIT(8)..BIT(10) of data->alarm.
+ */
+#define TEMP_ALARM_BIT(ch) ({ \
+ typeof(ch) _ch = (ch); \
+ (1 << (_ch < 7 ? _ch : _ch + 1)); \
+})
+
+/* FAN1..FAN4 (ch 0..3) are respectively BIT(4)..BIT(7) in
+ * reg 0x42 and 0x73 or BIT(12)..BIT(15) in data->alarm.
+ */
+#define FAN_ALARM_BIT(ch) (1 << (12 + (ch)))
+
#define ADT7470_VENDOR 0x41
#define ADT7470_DEVICE 0x70
/* datasheet only mentions a revision 2 */
@@ -569,7 +584,7 @@ static int adt7470_temp_read(struct device *dev, u32 attr, int channel, long *va
*val = 1000 * data->temp_max[channel];
break;
case hwmon_temp_alarm:
- *val = !!(data->alarm & channel);
+ *val = !!(data->alarm & TEMP_ALARM_BIT(channel));
break;
default:
return -EOPNOTSUPP;
@@ -668,7 +683,7 @@ static int adt7470_fan_read(struct device *dev, u32 attr, int channel, long *val
*val = 0;
break;
case hwmon_fan_alarm:
- *val = !!(data->alarm & (1 << (12 + channel)));
+ *val = !!(data->alarm & FAN_ALARM_BIT(channel));
break;
default:
return -EOPNOTSUPP;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 106/438] hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 105/438] hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 107/438] hwmon: (adt7470) Use cached PWM frequency value Greg Kroah-Hartman
` (345 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Angelo Daros de Luca,
Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit a3850231521b06bbbb18c8ebea100320c14a08be ]
The ADT7470_PWM3_AUTO_MASK and ADT7470_PWM4_AUTO_MASK macros are
currently defined with swapped bit values.
According to Table 22 of the ADT7470 datasheet, the Fan Control Mode
Configuration for register 0x69 follows the exact same bit position
layout as register 0x68:
- 0x68 Bit[7] corresponds to BHVR1 (PWM1) -> 0x80
- 0x68 Bit[6] corresponds to BHVR2 (PWM2) -> 0x40
- 0x69 Bit[7] corresponds to BHVR3 (PWM3) -> 0x80
- 0x69 Bit[6] corresponds to BHVR4 (PWM4) -> 0x40
Consequently, PWM3 should use mask 0x80 and PWM4 should use 0x40.
This typo did not cause any functional bugs because these specific
macros are never referenced in the driver code. Instead, the driver
correctly applies the configuration by relying on the modulo parity of
the channel index (e.g., `channel % 2`) to selectively apply either
ADT7470_PWM1_AUTO_MASK (0x80) or ADT7470_PWM2_AUTO_MASK (0x40).
Since the bit layout is identical between the two configuration
registers, the hardware is currently configured correctly.
Fix the macro definitions to reflect the datasheet accurately and
prevent future bugs or confusion during code review and refactoring.
As this is a purely cosmetic fix with no functional impact, a backport
to stable kernels is not necessary.
Fixes: 6f9703d0be16 ("hwmon: add support for adt7470")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-4-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 428bd1d91e700..c6fc7d38d698c 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -70,8 +70,8 @@ static const unsigned short normal_i2c[] = { 0x2C, 0x2E, 0x2F, I2C_CLIENT_END };
#define ADT7470_PWM1_AUTO_MASK 0x80
#define ADT7470_PWM_AUTO_MASK 0xC0
#define ADT7470_REG_PWM34_CFG 0x69
-#define ADT7470_PWM3_AUTO_MASK 0x40
-#define ADT7470_PWM4_AUTO_MASK 0x80
+#define ADT7470_PWM4_AUTO_MASK 0x40
+#define ADT7470_PWM3_AUTO_MASK 0x80
#define ADT7470_REG_PWM_MIN_BASE_ADDR 0x6A
#define ADT7470_REG_PWM_MIN_MAX_ADDR 0x6D
#define ADT7470_REG_PWM_TEMP_MIN_BASE_ADDR 0x6E
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 107/438] hwmon: (adt7470) Use cached PWM frequency value
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 106/438] hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 108/438] hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read Greg Kroah-Hartman
` (344 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Angelo Daros de Luca,
Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit 60677cd4c28f44d5b307d3029dccece38fcce90f ]
adt7470_pwm_read() currently ignores failures returned by
pwm1_freq_get(). If the register read fails, the negative error code is
returned through *val while the function itself reports success,
potentially exposing a negative PWM frequency through sysfs.
Fix this by using the cached PWM frequency maintained by the driver,
eliminating the register access from the read path.
Apart from the corrected error propagation and using the cached value,
no functional change is intended.
Fixes: ef67959c4253 ("hwmon: (adt7470) Convert to use regmap")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-6-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index c6fc7d38d698c..1fbca4869b7b6 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -182,6 +182,7 @@ struct adt7470_data {
u8 pwm_min[ADT7470_PWM_COUNT];
s8 pwm_tmin[ADT7470_PWM_COUNT];
u8 pwm_auto_temp[ADT7470_PWM_COUNT];
+ u32 pwm_freq;
struct task_struct *auto_update;
unsigned int auto_update_interval;
@@ -756,7 +757,7 @@ static ssize_t force_pwm_max_store(struct device *dev,
}
/* These are the valid PWM frequencies to the nearest Hz */
-static const int adt7470_freq_map[] = {
+static const u32 adt7470_freq_map[] = {
11, 15, 22, 29, 35, 44, 59, 88, 1400, 22500
};
@@ -796,7 +797,7 @@ static int adt7470_pwm_read(struct device *dev, u32 attr, int channel, long *val
*val = 1 + data->pwm_automatic[channel];
break;
case hwmon_pwm_freq:
- *val = pwm1_freq_get(dev);
+ *val = data->pwm_freq;
break;
default:
return -EOPNOTSUPP;
@@ -809,12 +810,14 @@ static int pwm1_freq_set(struct device *dev, long freq)
{
struct adt7470_data *data = dev_get_drvdata(dev);
unsigned int low_freq = ADT7470_CFG_LF;
+ u32 closest_freq;
int index;
int err;
/* Round the user value given to the closest available frequency */
index = find_closest(freq, adt7470_freq_map,
ARRAY_SIZE(adt7470_freq_map));
+ closest_freq = adt7470_freq_map[index];
if (index >= 8) {
index -= 8;
@@ -832,6 +835,10 @@ static int pwm1_freq_set(struct device *dev, long freq)
err = regmap_update_bits(data->regmap, ADT7470_REG_CFG_2,
ADT7470_FREQ_MASK,
index << ADT7470_FREQ_SHIFT);
+ if (err < 0)
+ goto out;
+
+ data->pwm_freq = closest_freq;
out:
mutex_unlock(&data->lock);
@@ -1285,6 +1292,7 @@ static int adt7470_probe(struct i2c_client *client)
struct device *dev = &client->dev;
struct adt7470_data *data;
struct device *hwmon_dev;
+ int freq_val;
int err;
data = devm_kzalloc(dev, sizeof(struct adt7470_data), GFP_KERNEL);
@@ -1309,6 +1317,14 @@ static int adt7470_probe(struct i2c_client *client)
if (err < 0)
return err;
+ freq_val = pwm1_freq_get(dev);
+ if (freq_val <= 0) {
+ err = freq_val < 0 ? freq_val : -EINVAL;
+ return err;
+ }
+
+ data->pwm_freq = (u32)freq_val;
+
/* Register sysfs hooks */
hwmon_dev = devm_hwmon_device_register_with_info(dev, client->name, data,
&adt7470_chip_info,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 108/438] hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 107/438] hwmon: (adt7470) Use cached PWM frequency value Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 109/438] hwmon: (adt7470) Fix PWM auto temp state array and bounds check Greg Kroah-Hartman
` (343 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Luiz Angelo Daros de Luca, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit 1b46fe9dc8f8de59310f37e6c5e5c0e05ded46c3 ]
If the fan data becomes 0 between the FAN_DATA_VALID() check and the
FAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash
due to a race with a concurrent update of the cached fan value.
Fix a TOCTOU issue by reading fan data once.
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/r/20260727034929.E29B71F000E9@smtp.kernel.org/
Fixes: fc958a61ff6d ("hwmon: (adt7470) Convert to devm_hwmon_device_register_with_info API")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-7-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 23 ++++++++++-------------
1 file changed, 10 insertions(+), 13 deletions(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 1fbca4869b7b6..772d2a409bb5c 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -660,36 +660,33 @@ static ssize_t alarm_mask_store(struct device *dev,
static int adt7470_fan_read(struct device *dev, u32 attr, int channel, long *val)
{
struct adt7470_data *data = adt7470_update_device(dev);
+ u16 fan_data;
if (IS_ERR(data))
return PTR_ERR(data);
switch (attr) {
case hwmon_fan_input:
- if (FAN_DATA_VALID(data->fan[channel]))
- *val = FAN_PERIOD_TO_RPM(data->fan[channel]);
- else
- *val = 0;
+ fan_data = READ_ONCE(data->fan[channel]);
break;
case hwmon_fan_min:
- if (FAN_DATA_VALID(data->fan_min[channel]))
- *val = FAN_PERIOD_TO_RPM(data->fan_min[channel]);
- else
- *val = 0;
+ fan_data = READ_ONCE(data->fan_min[channel]);
break;
case hwmon_fan_max:
- if (FAN_DATA_VALID(data->fan_max[channel]))
- *val = FAN_PERIOD_TO_RPM(data->fan_max[channel]);
- else
- *val = 0;
+ fan_data = READ_ONCE(data->fan_max[channel]);
break;
case hwmon_fan_alarm:
*val = !!(data->alarm & FAN_ALARM_BIT(channel));
- break;
+ return 0;
default:
return -EOPNOTSUPP;
}
+ if (FAN_DATA_VALID(fan_data))
+ *val = FAN_PERIOD_TO_RPM(fan_data);
+ else
+ *val = 0;
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 109/438] hwmon: (adt7470) Fix PWM auto temp state array and bounds check
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 108/438] hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 110/438] rtase: fix double free of multi-frag skb on DMA map failure Greg Kroah-Hartman
` (342 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Luiz Angelo Daros de Luca, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Angelo Daros de Luca <luizluca@gmail.com>
[ Upstream commit 92413f439d1ec5e55b73ede8d66a7b971cbd1ced ]
In pwm_auto_temp_store(), the parsed user input was missing bounds
checks, allowing values > 0xF to overflow into the adjacent channel's
bits. Furthermore, the value was being incorrectly written to the
pwm_automatic state array instead of pwm_auto_temp.
Fix this by rejecting values > 0xF with -EINVAL, and assigning the
value to the correct array only after a successful I2C write.
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/all/20260727034932.0B7C41F000E9@smtp.kernel.org/#t
Fixes: 6f9703d0be16 ("hwmon: add support for adt7470")
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Link: https://lore.kernel.org/r/20260727-adt7470_fixes-v2-8-598e38a46ba6@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7470.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
index 772d2a409bb5c..c45b984c02e6b 100644
--- a/drivers/hwmon/adt7470.c
+++ b/drivers/hwmon/adt7470.c
@@ -1049,8 +1049,10 @@ static ssize_t pwm_auto_temp_store(struct device *dev,
if (temp < 0)
return temp;
+ if (temp > 0xF)
+ return -EINVAL;
+
mutex_lock(&data->lock);
- data->pwm_automatic[attr->index] = temp;
if (!(attr->index % 2)) {
mask = 0xF0;
@@ -1061,6 +1063,9 @@ static ssize_t pwm_auto_temp_store(struct device *dev,
}
err = regmap_update_bits(data->regmap, pwm_auto_reg, mask, val);
+ if (!err)
+ data->pwm_auto_temp[attr->index] = temp;
+
mutex_unlock(&data->lock);
return err < 0 ? err : count;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 110/438] rtase: fix double free of multi-frag skb on DMA map failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 109/438] hwmon: (adt7470) Fix PWM auto temp state array and bounds check Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 111/438] ethtool: Embed FEC hist ranges as buffer in struct Greg Kroah-Hartman
` (341 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yun Lu, Jacob Keller, Justin Lai,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yun Lu <luyun@kylinos.cn>
[ Upstream commit 6fb7b769d6ed6d1d2e02af4a80e57a2477f35086 ]
In rtase_start_xmit(), when the head buffer DMA mapping fails after
rtase_xmit_frags() has mapped all fragments, the error path clears
the fragment descriptors with rtase_tx_clear_range(), which frees
the skb through the last-frag slot and accounts tx_dropped. Control
then falls through to the common error label, which frees the same
skb a second time and counts it again.
Return right after clearing the fragments when the skb owns frags;
the no-frag case still drops through and frees the head skb once.
Fixes: d6e882b89fdf ("rtase: Implement .ndo_start_xmit function")
Signed-off-by: Yun Lu <luyun@kylinos.cn>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Reviewed-by: Justin Lai <justinlai0215@realtek.com>
Link: https://patch.msgid.link/20260721023836.6691-1-luyun_611@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/realtek/rtase/rtase_main.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/realtek/rtase/rtase_main.c b/drivers/net/ethernet/realtek/rtase/rtase_main.c
index a57a525327a3b..bc9b14614f7a7 100644
--- a/drivers/net/ethernet/realtek/rtase/rtase_main.c
+++ b/drivers/net/ethernet/realtek/rtase/rtase_main.c
@@ -1620,6 +1620,9 @@ static netdev_tx_t rtase_start_xmit(struct sk_buff *skb,
err_dma_1:
ring->skbuff[entry] = NULL;
rtase_tx_clear_range(ring, ring->cur_idx + 1, frags);
+ if (frags)
+ /* the frags were cleared above, along with the skb */
+ return NETDEV_TX_OK;
err_dma_0:
tp->stats.tx_dropped++;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 111/438] ethtool: Embed FEC hist ranges as buffer in struct
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 110/438] rtase: fix double free of multi-frag skb on DMA map failure Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 112/438] powerpc/boot: Fix simpleboot CPU node lookup check Greg Kroah-Hartman
` (340 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Joyner, Vadim Fedorenko,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Joyner <eric.joyner@amd.com>
[ Upstream commit 97ac08560d236ca17f6606d9e671118e5eae5721 ]
When a driver's .get_fec_stats() handler is called and the driver
supports FEC histogram stats, the driver supplies the histogram bin
ranges via a pointer. This pointer is assigned while under the netdev
ops lock in fec_prepare_data(), but the actual data is only read after
the lock is released; so this allows the driver to change the ranges
(e.g. from another .get_fec_stats() call) while the current call chain
is reading them in fec_fill_reply().
Fix this by adding an ethtool core-owned buffer, ranges_buf, to struct
ethtool_fec_hist. Drivers whose ranges are built dynamically (currently
just mlx5) fill ranges_buf and then point the existing ranges pointer at
it, giving ethtool a consistent copy that stays valid after the netdev
ops lock is dropped and later in fec_fill_reply(). Drivers whose ranges
are compile-time constants (bnxt, netdevsim) are unaffected by the
potential race and keep setting the existing ranges pointer to their
constant array, without making copies.
Fixes: cc2f08129925 ("ethtool: add FEC bins histogram report")
Signed-off-by: Eric Joyner <eric.joyner@amd.com>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260723041342.39238-1-eric.joyner@amd.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en.h | 1 -
.../net/ethernet/mellanox/mlx5/core/en_main.c | 7 -------
.../ethernet/mellanox/mlx5/core/en_stats.c | 19 +++++++++----------
include/linux/ethtool.h | 1 +
4 files changed, 10 insertions(+), 18 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en.h b/drivers/net/ethernet/mellanox/mlx5/core/en.h
index d507289096c20..6867a5aed42c0 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en.h
@@ -984,7 +984,6 @@ struct mlx5e_priv {
struct mlx5e_mqprio_rl *mqprio_rl;
struct dentry *dfs_root;
struct mlx5_devcom_comp_dev *devcom;
- struct ethtool_fec_hist_range *fec_ranges;
};
static inline u16 mlx5e_stats_nch_read(const struct mlx5e_priv *priv)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
index fd442109aea8c..7d1063c7bf649 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
@@ -6374,14 +6374,8 @@ int mlx5e_priv_init(struct mlx5e_priv *priv,
if (!priv->channel_stats)
goto err_free_tx_rates;
- priv->fec_ranges = kzalloc_objs(*priv->fec_ranges, ETHTOOL_FEC_HIST_MAX);
- if (!priv->fec_ranges)
- goto err_free_channel_stats;
-
return 0;
-err_free_channel_stats:
- kfree(priv->channel_stats);
err_free_tx_rates:
kfree(priv->tx_rates);
err_free_txq2sq_stats:
@@ -6406,7 +6400,6 @@ void mlx5e_priv_cleanup(struct mlx5e_priv *priv)
if (!priv->mdev)
return;
- kfree(priv->fec_ranges);
for (i = 0; i < priv->stats_nch; i++)
kvfree(priv->channel_stats[i]);
kfree(priv->channel_stats);
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c b/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c
index 8632b73179cbc..bba51e198d731 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_stats.c
@@ -1551,7 +1551,7 @@ static bool fec_rs_validate_hist_type(int mode, int hist_type)
static u8
fec_rs_histogram_fill_ranges(struct mlx5e_priv *priv, int mode,
- const struct ethtool_fec_hist_range **ranges)
+ struct ethtool_fec_hist_range *ranges)
{
struct mlx5_core_dev *mdev = priv->mdev;
u32 out[MLX5_ST_SZ_DW(pphcr_reg)] = {0};
@@ -1559,8 +1559,6 @@ fec_rs_histogram_fill_ranges(struct mlx5e_priv *priv, int mode,
int sz = MLX5_ST_SZ_BYTES(pphcr_reg);
u8 hist_type, num_of_bins;
- memset(priv->fec_ranges, 0,
- ETHTOOL_FEC_HIST_MAX * sizeof(*priv->fec_ranges));
MLX5_SET(pphcr_reg, in, local_port, 1);
if (mlx5_core_access_reg(mdev, in, sz, out, sz, MLX5_REG_PPHCR, 0, 0))
return 0;
@@ -1576,12 +1574,11 @@ fec_rs_histogram_fill_ranges(struct mlx5e_priv *priv, int mode,
for (int i = 0; i < num_of_bins; i++) {
void *bin_range = MLX5_ADDR_OF(pphcr_reg, out, bin_range[i]);
- priv->fec_ranges[i].high = MLX5_GET(bin_range_layout, bin_range,
- high_val);
- priv->fec_ranges[i].low = MLX5_GET(bin_range_layout, bin_range,
- low_val);
+ ranges[i].high = MLX5_GET(bin_range_layout, bin_range,
+ high_val);
+ ranges[i].low = MLX5_GET(bin_range_layout, bin_range,
+ low_val);
}
- *ranges = priv->fec_ranges;
return num_of_bins;
}
@@ -1623,10 +1620,12 @@ static void fec_set_histograms_stats(struct mlx5e_priv *priv, int mode,
case MLX5E_FEC_LLRS_272_257_1:
case MLX5E_FEC_RS_544_514_INTERLEAVED_QUAD:
num_of_bins =
- fec_rs_histogram_fill_ranges(priv, mode, &hist->ranges);
- if (num_of_bins)
+ fec_rs_histogram_fill_ranges(priv, mode, hist->ranges_buf);
+ if (num_of_bins) {
+ hist->ranges = hist->ranges_buf;
return fec_rs_histogram_fill_stats(priv, num_of_bins,
hist);
+ }
break;
default:
return;
diff --git a/include/linux/ethtool.h b/include/linux/ethtool.h
index 1cb0740ba3310..091d382f0a2d3 100644
--- a/include/linux/ethtool.h
+++ b/include/linux/ethtool.h
@@ -560,6 +560,7 @@ struct ethtool_fec_hist {
u64 per_lane[ETHTOOL_MAX_LANES];
} values[ETHTOOL_FEC_HIST_MAX];
const struct ethtool_fec_hist_range *ranges;
+ struct ethtool_fec_hist_range ranges_buf[ETHTOOL_FEC_HIST_MAX];
};
/**
* struct ethtool_fec_stats - statistics for IEEE 802.3 FEC
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 112/438] powerpc/boot: Fix simpleboot CPU node lookup check
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 111/438] ethtool: Embed FEC hist ranges as buffer in struct Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 113/438] powerpc/boot: Fix treeboot-currituck " Greg Kroah-Hartman
` (339 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Ritesh Harjani (IBM),
Madhavan Srinivasan, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit c824ab65685bb119c6c6a3a200b3428c72862d5a ]
fdt_node_offset_by_prop_value() returns a negative error code on
failure - fix the check accordingly.
Fixes: d2477b5cc8ca ("[POWERPC] bootwrapper: Add a firmware-independent simpleboot target.")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260702211554.56923-4-thorsten.blum@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/boot/simpleboot.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/boot/simpleboot.c b/arch/powerpc/boot/simpleboot.c
index c80691d83880b..27591df41e9e8 100644
--- a/arch/powerpc/boot/simpleboot.c
+++ b/arch/powerpc/boot/simpleboot.c
@@ -68,7 +68,7 @@ void platform_init(unsigned long r3, unsigned long r4, unsigned long r5,
/* finally, setup the timebase */
node = fdt_node_offset_by_prop_value(_dtb_start, -1, "device_type",
"cpu", sizeof("cpu"));
- if (!node)
+ if (node < 0)
fatal("Cannot find cpu node\n");
timebase = fdt_getprop(_dtb_start, node, "timebase-frequency", &size);
if (timebase && (size == 4))
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 113/438] powerpc/boot: Fix treeboot-currituck CPU node lookup check
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 112/438] powerpc/boot: Fix simpleboot CPU node lookup check Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 114/438] powerpc/boot: Fix treeboot-akebono " Greg Kroah-Hartman
` (338 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Ritesh Harjani (IBM),
Madhavan Srinivasan, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit 43863f6575d2211e8c5157fefb83ad0ad046aab4 ]
fdt_node_offset_by_prop_value() returns a negative error code on
failure - fix the check accordingly.
Fixes: 228d55053397 ("powerpc/47x: Add support for the new IBM currituck platform")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260702211554.56923-5-thorsten.blum@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/boot/treeboot-currituck.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/boot/treeboot-currituck.c b/arch/powerpc/boot/treeboot-currituck.c
index d53e8a592f816..5b5363b74f9f3 100644
--- a/arch/powerpc/boot/treeboot-currituck.c
+++ b/arch/powerpc/boot/treeboot-currituck.c
@@ -102,7 +102,7 @@ void platform_init(void)
node = fdt_node_offset_by_prop_value(_dtb_start, -1, "device_type",
"cpu", sizeof("cpu"));
- if (!node)
+ if (node < 0)
fatal("Cannot find cpu node\n");
timebase = fdt_getprop(_dtb_start, node, "timebase-frequency", &size);
if (timebase && (size == 4))
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 114/438] powerpc/boot: Fix treeboot-akebono CPU node lookup check
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 113/438] powerpc/boot: Fix treeboot-currituck " Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 115/438] net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds Greg Kroah-Hartman
` (337 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Ritesh Harjani (IBM),
Madhavan Srinivasan, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit b24fc8278b70a9d27ec801a427ab4de9b769d69a ]
fdt_node_offset_by_prop_value() returns a negative error code on
failure - fix the check accordingly.
Fixes: 2a2c74b2efcb ("IBM Akebono: Add the Akebono platform")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260702211554.56923-6-thorsten.blum@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/boot/treeboot-akebono.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/boot/treeboot-akebono.c b/arch/powerpc/boot/treeboot-akebono.c
index e3cc2599869cc..1b529037480fb 100644
--- a/arch/powerpc/boot/treeboot-akebono.c
+++ b/arch/powerpc/boot/treeboot-akebono.c
@@ -146,7 +146,7 @@ void platform_init(char *userdata)
node = fdt_node_offset_by_prop_value(_dtb_start, -1, "device_type",
"cpu", sizeof("cpu"));
- if (!node)
+ if (node < 0)
fatal("Cannot find cpu node\n");
timebase = fdt_getprop(_dtb_start, node, "timebase-frequency", &size);
if (timebase && (size == 4))
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 115/438] net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 114/438] powerpc/boot: Fix treeboot-akebono " Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 116/438] net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() Greg Kroah-Hartman
` (336 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AutonomousCodeSecurity,
Cen Zhang (Microsoft), Jamal Hadi Salim, Victor Nogueira,
Paolo Abeni, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang (Microsoft) <blbllhy@gmail.com>
[ Upstream commit aef96eead2860cbfa371e4471d4f04412213b958 ]
u32_change() copies the user-provided tc_u32_sel.offshift (unsigned char,
0-255) into the kernel knode object without bounds validation. When a
packet later hits u32_classify() with TC_U32_VAROFFSET set, it evaluates
`ntohs(offmask & *data) >> offshift` where the left operand is a 16-bit
value promoted to a 32-bit int. Any offshift >= 32 is undefined behavior
per C11 6.5.7p3, triggerable by an unprivileged user via user/network
namespaces.
UBSAN: shift-out-of-bounds in net/sched/cls_u32.c:236:43
shift exponent 32 is too large for 32-bit type int
Fix this by rejecting offshift >= 16 during filter creation in
u32_change().
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: AutonomousCodeSecurity@microsoft.com
Link: https://lore.kernel.org/all/20260720034514.23053-1-blbllhy@gmail.com
Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Tested-by: Jamal Hadi Salim <jhs@mojatatu.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260723044955.89471-1-blbllhy@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/cls_u32.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
index 8f30cc82181d9..ac98b1c2144a7 100644
--- a/net/sched/cls_u32.c
+++ b/net/sched/cls_u32.c
@@ -1107,6 +1107,13 @@ static int u32_change(struct net *net, struct sk_buff *in_skb,
goto erridr;
}
+ if (s->offshift >= 16) {
+ NL_SET_ERR_MSG_MOD(extack,
+ "offshift must be less than 16");
+ err = -EINVAL;
+ goto erridr;
+ }
+
n = kzalloc_flex(*n, sel.keys, s->nkeys);
if (n == NULL) {
err = -ENOBUFS;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 116/438] net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 115/438] net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 117/438] wifi: mac80211: validate individual TWT params before driver setup Greg Kroah-Hartman
` (335 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+eca845fb8c18dd6b44c1,
Eric Dumazet, Paolo Abeni, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 080695e6f005e2396f1207fd69d24c442cb230c6 ]
syzbot reported a memory leak [1] in the UDP tunnel NIC offload code.
When device registration fails (e.g. in register_netdevice()), netdev core
unwinds by sending a single NETDEV_UNREGISTER notification. If work was queued
during NETDEV_REGISTER (utn->work_pending is set), udp_tunnel_nic_unregister()
returns early:
if (utn->work_pending)
return;
Because failed registrations do not enter netdev_wait_allrefs_any(), no
subsequent NETDEV_UNREGISTER rebroadcast will ever occur. As a result, the
struct udp_tunnel_nic allocated in udp_tunnel_nic_alloc() is leaked
permanently.
Fix this by removing the early return. Instead, synchronously cancel any
pending work with cancel_delayed_work_sync() before freeing @utn.
To be able to call cancel_delayed_work_sync() while holding RTNL (the work also
needs RTNL), switch udp_tunnel_nic_device_sync_work() to rtnl_trylock(). If RTNL
is contended, requeue the work with a 1 jiffy delay (via queue_delayed_work())
to prevent high CPU contention while waiting for RTNL lock.
The utn->work_pending bookkeeping is no longer needed and is removed, as
the workqueue core already tracks the pending/running state of the work.
[1]
BUG: memory leak
unreferenced object 0xffff888127d5f840 (size 96):
comm "syz-executor", pid 5806, jiffies 4294942188
backtrace (crc 99fdb6c8):
__kmalloc_noprof+0x3bf/0x550
udp_tunnel_nic_alloc net/ipv4/udp_tunnel_nic.c:756 [inline]
udp_tunnel_nic_register net/ipv4/udp_tunnel_nic.c:833 [inline]
udp_tunnel_nic_netdevice_event+0x804/0xab0 net/ipv4/udp_tunnel_nic.c:931
notifier_call_chain+0x59/0x160 kernel/notifier.c:85
call_netdevice_notifiers_info+0x7d/0xb0 net/core/dev.c:2250
register_netdevice+0xc10/0xeb0 net/core/dev.c:11478
Fixes: cc4e3835eff4 ("udp_tunnel: add central NIC RX port offload infrastructure")
Reported-by: syzbot+eca845fb8c18dd6b44c1@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a632b15.dde6c935.cf6c8.0011.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260724091137.1792543-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/udp_tunnel_nic.c | 32 +++++++++++++++++---------------
1 file changed, 17 insertions(+), 15 deletions(-)
diff --git a/net/ipv4/udp_tunnel_nic.c b/net/ipv4/udp_tunnel_nic.c
index 3b32a0afa9798..53a1a9c1f8bff 100644
--- a/net/ipv4/udp_tunnel_nic.c
+++ b/net/ipv4/udp_tunnel_nic.c
@@ -32,13 +32,12 @@ struct udp_tunnel_nic_table_entry {
* @lock: protects all fields
* @need_sync: at least one port start changed
* @need_replay: space was freed, we need a replay of all ports
- * @work_pending: @work is currently scheduled
* @n_tables: number of tables under @entries
* @missed: bitmap of tables which overflown
* @entries: table of tables of ports currently offloaded
*/
struct udp_tunnel_nic {
- struct work_struct work;
+ struct delayed_work work;
struct net_device *dev;
@@ -46,7 +45,6 @@ struct udp_tunnel_nic {
u8 need_sync:1;
u8 need_replay:1;
- u8 work_pending:1;
unsigned int n_tables;
unsigned long missed;
@@ -301,11 +299,10 @@ __udp_tunnel_nic_device_sync(struct net_device *dev, struct udp_tunnel_nic *utn)
static void
udp_tunnel_nic_device_sync(struct net_device *dev, struct udp_tunnel_nic *utn)
{
- if (!utn->need_sync || utn->work_pending)
+ if (!utn->need_sync)
return;
- queue_work(udp_tunnel_nic_workqueue, &utn->work);
- utn->work_pending = 1;
+ queue_delayed_work(udp_tunnel_nic_workqueue, &utn->work, 0);
}
static bool
@@ -731,12 +728,17 @@ udp_tunnel_nic_replay(struct net_device *dev, struct udp_tunnel_nic *utn)
static void udp_tunnel_nic_device_sync_work(struct work_struct *work)
{
struct udp_tunnel_nic *utn =
- container_of(work, struct udp_tunnel_nic, work);
+ container_of(work, struct udp_tunnel_nic, work.work);
- rtnl_lock();
+ /* We cannot block on RTNL here, otherwise we would deadlock with
+ * udp_tunnel_nic_unregister() calling cancel_delayed_work_sync()
+ * while holding RTNL. Requeue with 1 jiffy delay if RTNL is contended.
+ */
+ if (!rtnl_trylock()) {
+ queue_delayed_work(udp_tunnel_nic_workqueue, &utn->work, 1);
+ return;
+ }
mutex_lock(&utn->lock);
-
- utn->work_pending = 0;
__udp_tunnel_nic_device_sync(utn->dev, utn);
if (utn->need_replay)
@@ -757,7 +759,7 @@ udp_tunnel_nic_alloc(const struct udp_tunnel_nic_info *info,
if (!utn)
return NULL;
utn->n_tables = n_tables;
- INIT_WORK(&utn->work, udp_tunnel_nic_device_sync_work);
+ INIT_DELAYED_WORK(&utn->work, udp_tunnel_nic_device_sync_work);
mutex_init(&utn->lock);
for (i = 0; i < n_tables; i++) {
@@ -901,11 +903,11 @@ udp_tunnel_nic_unregister(struct net_device *dev, struct udp_tunnel_nic *utn)
udp_tunnel_nic_flush(dev, utn);
udp_tunnel_nic_unlock(dev);
- /* Wait for the work to be done using the state, netdev core will
- * retry unregister until we give up our reference on this device.
+ /* Make sure no work is running or queued before freeing @utn.
+ * The work handler uses rtnl_trylock(), so it will not deadlock
+ * against the RTNL we are holding here.
*/
- if (utn->work_pending)
- return;
+ cancel_delayed_work_sync(&utn->work);
udp_tunnel_nic_free(utn);
release_dev:
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 117/438] wifi: mac80211: validate individual TWT params before driver setup
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 116/438] net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 118/438] netfs: clear PG_private_2 on copy-to-cache append failure Greg Kroah-Hartman
` (334 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit 0502d5077e419427d80f4d46ba95d0067f5fb916 ]
ieee80211_process_rx_twt_action() only partially validates a received
S1G TWT setup frame before queueing it.
An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup()
with twt->length too short for the full struct ieee80211_twt_params.
The individual path passes twt to drv_add_twt_setup(). Both the tracepoint
and the driver callback consume the complete parameters block, not merely
req_type. Do not pass a short individual agreement to the driver.
Broadcast agreements remain unchanged because they are rejected locally
after accessing only req_type.
Fixes: f5a4c24e689f ("mac80211: introduce individual TWT support in AP mode")
Assisted-by: Codex:gpt-5
Assisted-by: Claude:opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260723010928.76551-1-enderaoelyther@gmail.com
[edit commit message to not overclaim lack of validation nor
understate driver impact]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/s1g.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/s1g.c b/net/mac80211/s1g.c
index 5af4a0c6c6424..abc338e22e59c 100644
--- a/net/mac80211/s1g.c
+++ b/net/mac80211/s1g.c
@@ -101,6 +101,10 @@ ieee80211_s1g_rx_twt_setup(struct ieee80211_sub_if_data *sdata,
struct ieee80211_twt_setup *twt = (void *)mgmt->u.action.s1g.variable;
struct ieee80211_twt_params *twt_agrt = (void *)twt->params;
+ if (!(twt->control & IEEE80211_TWT_CONTROL_NEG_TYPE_BROADCAST) &&
+ twt->length < sizeof(twt->control) + sizeof(*twt_agrt))
+ return;
+
twt_agrt->req_type &= cpu_to_le16(~IEEE80211_TWT_REQTYPE_REQUEST);
/* broadcast TWT not supported yet */
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 118/438] netfs: clear PG_private_2 on copy-to-cache append failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 117/438] wifi: mac80211: validate individual TWT params before driver setup Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 119/438] netfs: handle single writeback rolling buffer allocation failure Greg Kroah-Hartman
` (333 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, David Howells,
Paulo Alcantara, netfs, linux-fsdevel,
Christian Brauner (Amutable), Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit a81fc9266e1c5fef9ccf675a9b44b2f4ab464923 ]
netfs_pgpriv2_copy_to_cache() marks the folio with PG_private_2 before
netfs_pgpriv2_copy_folio() appends it to the copy-to-cache rolling
buffer.
If the append fails, the folio is not queued for cache writeback, so
the PG_private_2 state and its reference must be released immediately.
Fixes: e2d46f2ec332 ("netfs: Change the read result collector to only use one work item")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260727130716.1099906-2-dhowells@redhat.com
cc: Paulo Alcantara <pc@manguebit.org>
cc: netfs@lists.linux.dev
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/netfs/read_pgpriv2.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/netfs/read_pgpriv2.c b/fs/netfs/read_pgpriv2.c
index a1489aa29f782..7eacc58abadb7 100644
--- a/fs/netfs/read_pgpriv2.c
+++ b/fs/netfs/read_pgpriv2.c
@@ -54,6 +54,7 @@ static void netfs_pgpriv2_copy_folio(struct netfs_io_request *creq, struct folio
/* Attach the folio to the rolling buffer. */
if (rolling_buffer_append(&creq->buffer, folio, 0) < 0) {
+ folio_end_private_2(folio);
clear_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &creq->flags);
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 119/438] netfs: handle single writeback rolling buffer allocation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 118/438] netfs: clear PG_private_2 on copy-to-cache append failure Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 120/438] netfs: release readahead folios on iterator preparation failure Greg Kroah-Hartman
` (332 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, David Howells,
Paulo Alcantara, netfs, linux-fsdevel,
Christian Brauner (Amutable), Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 37a1c535c80c67d98668d190c7432f9ebda43310 ]
netfs_write_folio_single() takes an extra folio reference before
appending the folio to the rolling buffer.
rolling_buffer_append() can fail if it cannot allocate another
folio_queue. Check the return value and drop the extra folio reference
before returning the error.
Fixes: 49866ce7ea8d ("netfs: Add support for caching single monolithic objects such as AFS dirs")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260727130716.1099906-3-dhowells@redhat.com
cc: Paulo Alcantara <pc@manguebit.org>
cc: netfs@lists.linux.dev
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/netfs/write_issue.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/fs/netfs/write_issue.c b/fs/netfs/write_issue.c
index d0d884731dc5d..8d3a6cad42d5e 100644
--- a/fs/netfs/write_issue.c
+++ b/fs/netfs/write_issue.c
@@ -731,6 +731,7 @@ static int netfs_write_folio_single(struct netfs_io_request *wreq,
size_t iter_off = 0;
size_t fsize = folio_size(folio), flen;
loff_t fpos = folio_pos(folio);
+ ssize_t ret;
bool to_eof = false;
bool no_debug = false;
@@ -759,7 +760,11 @@ static int netfs_write_folio_single(struct netfs_io_request *wreq,
/* Attach the folio to the rolling buffer. */
folio_get(folio);
- rolling_buffer_append(&wreq->buffer, folio, NETFS_ROLLBUF_PUT_MARK);
+ ret = rolling_buffer_append(&wreq->buffer, folio, NETFS_ROLLBUF_PUT_MARK);
+ if (ret < 0) {
+ folio_put(folio);
+ return ret;
+ }
/* Move the submission point forward to allow for write-streaming data
* not starting at the front of the page. We don't do write-streaming
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 120/438] netfs: release readahead folios on iterator preparation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 119/438] netfs: handle single writeback rolling buffer allocation failure Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 121/438] netfs: Fix folio_queue ENOMEM in writeback by adding a mempool Greg Kroah-Hartman
` (331 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, David Howells,
Paulo Alcantara, netfs, linux-fsdevel,
Christian Brauner (Amutable), Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 87eb3d272dcbcbbfe5c1576c10e5dc72810cf1f6 ]
netfs_prepare_read_iterator() batches readahead folios in put_batch so that
the folio references can be dropped after the I/O iterator has been
prepared.
If rolling_buffer_load_from_ra() fails after earlier folios have been
batched, the function returns immediately and leaves those references held.
Release the batch before returning the error.
Fixes: 06fa229ceb36 ("netfs: Abstract out a rolling folio buffer implementation")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260727130716.1099906-4-dhowells@redhat.com
cc: Paulo Alcantara <pc@manguebit.org>
cc: netfs@lists.linux.dev
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/netfs/buffered_read.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c
index 76d0f6a29abab..68534cef37cd2 100644
--- a/fs/netfs/buffered_read.c
+++ b/fs/netfs/buffered_read.c
@@ -102,8 +102,10 @@ static ssize_t netfs_prepare_read_iterator(struct netfs_io_subrequest *subreq,
added = rolling_buffer_load_from_ra(&rreq->buffer, ractl,
&put_batch);
- if (added < 0)
+ if (added < 0) {
+ folio_batch_release(&put_batch);
return added;
+ }
rreq->submitted += added;
}
folio_batch_release(&put_batch);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 121/438] netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 120/438] netfs: release readahead folios on iterator preparation failure Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 122/438] net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller Greg Kroah-Hartman
` (330 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0da43efa72f88bd3a8af,
David Howells, Paulo Alcantara, Yun Zhou, Matthew Wilcox,
Christoph Hellwig, netfs, linux-fsdevel,
Christian Brauner (Amutable), Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
[ Upstream commit 1d78d56c43ef3768183e8370e7367b162700e049 ]
Fix the handling of folio_queue allocation failure in writeback by adding a
mempool and passing in gfp_t flags to the rolling buffer functions that
allocate memory, using the mempool if gfp != GFP_KERNEL.
This is then extended upwards and the gfp to be used for a request is stored
in the netfs_io_request struct and is then used for both requests and
subrequests, eliminating the sleeping loops there.
The failure caused:
folio != NULL
WARNING: fs/netfs/write_issue.c:603 at netfs_writepages+0x883/0xa10 fs/netfs/write_issue.c:603, CPU#3: syz.0.17/5919
Fixes: cd0277ed0c18 ("netfs: Use new folio_queue data type and iterator instead of xarray iter")
Reported-by: syzbot+0da43efa72f88bd3a8af@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0da43efa72f88bd3a8af
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260727130716.1099906-5-dhowells@redhat.com
Tested-by: syzbot+0da43efa72f88bd3a8af@syzkaller.appspotmail.com
cc: Paulo Alcantara <pc@manguebit.org>
cc: Yun Zhou <yun.zhou@windriver.com>
cc: Matthew Wilcox <willy@infradead.org>
cc: Christoph Hellwig <hch@infradead.org>
cc: netfs@lists.linux.dev
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/netfs/buffered_read.c | 6 +++---
fs/netfs/internal.h | 1 +
fs/netfs/main.c | 7 +++++++
fs/netfs/objects.c | 30 +++++++++++++++++-------------
fs/netfs/read_pgpriv2.c | 2 +-
fs/netfs/rolling_buffer.c | 22 +++++++++++++---------
fs/netfs/write_issue.c | 10 +++++-----
include/linux/netfs.h | 1 +
include/linux/rolling_buffer.h | 6 +++---
9 files changed, 51 insertions(+), 34 deletions(-)
diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c
index 68534cef37cd2..6c2192bb49cfc 100644
--- a/fs/netfs/buffered_read.c
+++ b/fs/netfs/buffered_read.c
@@ -361,7 +361,7 @@ void netfs_readahead(struct readahead_control *ractl)
netfs_rreq_expand(rreq, ractl);
rreq->submitted = rreq->start;
- if (rolling_buffer_init(&rreq->buffer, rreq->debug_id, ITER_DEST) < 0)
+ if (rolling_buffer_init(&rreq->buffer, rreq->debug_id, ITER_DEST, rreq->gfp) < 0)
goto cleanup_free;
netfs_read_to_pagecache(rreq, ractl);
@@ -380,10 +380,10 @@ static int netfs_create_singular_buffer(struct netfs_io_request *rreq, struct fo
{
ssize_t added;
- if (rolling_buffer_init(&rreq->buffer, rreq->debug_id, ITER_DEST) < 0)
+ if (rolling_buffer_init(&rreq->buffer, rreq->debug_id, ITER_DEST, rreq->gfp) < 0)
return -ENOMEM;
- added = rolling_buffer_append(&rreq->buffer, folio, rollbuf_flags);
+ added = rolling_buffer_append(&rreq->buffer, folio, rollbuf_flags, rreq->gfp);
if (added < 0)
return added;
rreq->submitted = rreq->start + added;
diff --git a/fs/netfs/internal.h b/fs/netfs/internal.h
index 645996ecfc803..acdd543349915 100644
--- a/fs/netfs/internal.h
+++ b/fs/netfs/internal.h
@@ -43,6 +43,7 @@ extern struct list_head netfs_io_requests;
extern spinlock_t netfs_proc_lock;
extern mempool_t netfs_request_pool;
extern mempool_t netfs_subrequest_pool;
+extern mempool_t netfs_folioq_pool;
#ifdef CONFIG_PROC_FS
static inline void netfs_proc_add_rreq(struct netfs_io_request *rreq)
diff --git a/fs/netfs/main.c b/fs/netfs/main.c
index 73da6c9f5777c..927badf3989db 100644
--- a/fs/netfs/main.c
+++ b/fs/netfs/main.c
@@ -28,6 +28,7 @@ static struct kmem_cache *netfs_request_slab;
static struct kmem_cache *netfs_subrequest_slab;
mempool_t netfs_request_pool;
mempool_t netfs_subrequest_pool;
+mempool_t netfs_folioq_pool;
#ifdef CONFIG_PROC_FS
LIST_HEAD(netfs_io_requests);
@@ -108,6 +109,9 @@ static int __init netfs_init(void)
{
int ret = -ENOMEM;
+ if (mempool_init_kmalloc_pool(&netfs_folioq_pool, 100, sizeof(struct folio_queue)) < 0)
+ goto error_folioq_pool;
+
netfs_request_slab = kmem_cache_create("netfs_request",
sizeof(struct netfs_io_request), 0,
SLAB_HWCACHE_ALIGN | SLAB_ACCOUNT,
@@ -160,6 +164,8 @@ static int __init netfs_init(void)
error_reqpool:
kmem_cache_destroy(netfs_request_slab);
error_req:
+ mempool_exit(&netfs_folioq_pool);
+error_folioq_pool:
return ret;
}
fs_initcall(netfs_init);
@@ -172,5 +178,6 @@ static void __exit netfs_exit(void)
kmem_cache_destroy(netfs_subrequest_slab);
mempool_exit(&netfs_request_pool);
kmem_cache_destroy(netfs_request_slab);
+ mempool_exit(&netfs_folioq_pool);
}
module_exit(netfs_exit);
diff --git a/fs/netfs/objects.c b/fs/netfs/objects.c
index b8c4918d3dcda..01461a74642d6 100644
--- a/fs/netfs/objects.c
+++ b/fs/netfs/objects.c
@@ -7,7 +7,6 @@
#include <linux/slab.h>
#include <linux/mempool.h>
-#include <linux/delay.h>
#include "internal.h"
static void netfs_free_request(struct work_struct *work);
@@ -26,17 +25,23 @@ struct netfs_io_request *netfs_alloc_request(struct address_space *mapping,
struct netfs_io_request *rreq;
mempool_t *mempool = ctx->ops->request_pool ?: &netfs_request_pool;
struct kmem_cache *cache = mempool->pool_data;
+ gfp_t gfp = GFP_KERNEL;
int ret;
- for (;;) {
- rreq = mempool_alloc(mempool, GFP_KERNEL);
- if (rreq)
- break;
- msleep(10);
+ /* Writeback is part of memory reclaim and must not fail due to ENOMEM. */
+ if (origin == NETFS_WRITEBACK || origin == NETFS_WRITEBACK_SINGLE) {
+ gfp = GFP_NOFS; /* Allows use of mempools. */
+
+ rreq = mempool_alloc(mempool, gfp);
+ } else {
+ rreq = mempool->alloc(gfp, mempool->pool_data);
+ if (!rreq)
+ return ERR_PTR(-ENOMEM);
}
memset(rreq, 0, kmem_cache_size(cache));
INIT_WORK(&rreq->cleanup_work, netfs_free_request);
+ rreq->gfp = gfp;
rreq->start = start;
rreq->len = len;
rreq->origin = origin;
@@ -200,13 +205,12 @@ struct netfs_io_subrequest *netfs_alloc_subrequest(struct netfs_io_request *rreq
mempool_t *mempool = rreq->netfs_ops->subrequest_pool ?: &netfs_subrequest_pool;
struct kmem_cache *cache = mempool->pool_data;
- for (;;) {
- subreq = mempool_alloc(rreq->netfs_ops->subrequest_pool ?: &netfs_subrequest_pool,
- GFP_KERNEL);
- if (subreq)
- break;
- msleep(10);
- }
+ if (rreq->gfp == GFP_KERNEL)
+ subreq = mempool->alloc(rreq->gfp, mempool->pool_data);
+ else
+ subreq = mempool_alloc(mempool, rreq->gfp);
+ if (!subreq)
+ return NULL;
memset(subreq, 0, kmem_cache_size(cache));
INIT_WORK(&subreq->work, NULL);
diff --git a/fs/netfs/read_pgpriv2.c b/fs/netfs/read_pgpriv2.c
index 7eacc58abadb7..c31190993b762 100644
--- a/fs/netfs/read_pgpriv2.c
+++ b/fs/netfs/read_pgpriv2.c
@@ -53,7 +53,7 @@ static void netfs_pgpriv2_copy_folio(struct netfs_io_request *creq, struct folio
trace_netfs_folio(folio, netfs_folio_trace_store_copy);
/* Attach the folio to the rolling buffer. */
- if (rolling_buffer_append(&creq->buffer, folio, 0) < 0) {
+ if (rolling_buffer_append(&creq->buffer, folio, 0, creq->gfp) < 0) {
folio_end_private_2(folio);
clear_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &creq->flags);
return;
diff --git a/fs/netfs/rolling_buffer.c b/fs/netfs/rolling_buffer.c
index a17fbf9853a44..8c0026836f9c1 100644
--- a/fs/netfs/rolling_buffer.c
+++ b/fs/netfs/rolling_buffer.c
@@ -6,6 +6,7 @@
*/
#include <linux/bitops.h>
+#include <linux/mempool.h>
#include <linux/pagemap.h>
#include <linux/rolling_buffer.h>
#include <linux/slab.h>
@@ -27,7 +28,10 @@ struct folio_queue *netfs_folioq_alloc(unsigned int rreq_id, gfp_t gfp,
{
struct folio_queue *fq;
- fq = kmalloc_obj(*fq, gfp);
+ if (gfp == GFP_KERNEL)
+ fq = netfs_folioq_pool.alloc(gfp, netfs_folioq_pool.pool_data);
+ else
+ fq = mempool_alloc(&netfs_folioq_pool, gfp);
if (fq) {
netfs_stat(&netfs_n_folioq);
folioq_init(fq, rreq_id);
@@ -50,7 +54,7 @@ void netfs_folioq_free(struct folio_queue *folioq,
{
trace_netfs_folioq(folioq, trace);
netfs_stat_d(&netfs_n_folioq);
- kfree(folioq);
+ mempool_free(folioq, &netfs_folioq_pool);
}
EXPORT_SYMBOL(netfs_folioq_free);
@@ -60,11 +64,11 @@ EXPORT_SYMBOL(netfs_folioq_free);
* consumer.
*/
int rolling_buffer_init(struct rolling_buffer *roll, unsigned int rreq_id,
- unsigned int direction)
+ unsigned int direction, gfp_t gfp)
{
struct folio_queue *fq;
- fq = netfs_folioq_alloc(rreq_id, GFP_NOFS, netfs_trace_folioq_rollbuf_init);
+ fq = netfs_folioq_alloc(rreq_id, gfp, netfs_trace_folioq_rollbuf_init);
if (!fq)
return -ENOMEM;
@@ -77,14 +81,14 @@ int rolling_buffer_init(struct rolling_buffer *roll, unsigned int rreq_id,
/*
* Add another folio_queue to a rolling buffer if there's no space left.
*/
-int rolling_buffer_make_space(struct rolling_buffer *roll)
+int rolling_buffer_make_space(struct rolling_buffer *roll, gfp_t gfp)
{
struct folio_queue *fq, *head = roll->head;
if (!folioq_full(head))
return 0;
- fq = netfs_folioq_alloc(head->rreq_id, GFP_NOFS, netfs_trace_folioq_make_space);
+ fq = netfs_folioq_alloc(head->rreq_id, gfp, netfs_trace_folioq_make_space);
if (!fq)
return -ENOMEM;
fq->prev = head;
@@ -122,7 +126,7 @@ ssize_t rolling_buffer_load_from_ra(struct rolling_buffer *roll,
int nr, ix, to;
ssize_t size = 0;
- if (rolling_buffer_make_space(roll) < 0)
+ if (rolling_buffer_make_space(roll, GFP_KERNEL) < 0)
return -ENOMEM;
fq = roll->head;
@@ -153,12 +157,12 @@ ssize_t rolling_buffer_load_from_ra(struct rolling_buffer *roll,
* Append a folio to the rolling buffer.
*/
ssize_t rolling_buffer_append(struct rolling_buffer *roll, struct folio *folio,
- unsigned int flags)
+ unsigned int flags, gfp_t gfp)
{
ssize_t size = folio_size(folio);
int slot;
- if (rolling_buffer_make_space(roll) < 0)
+ if (rolling_buffer_make_space(roll, gfp) < 0)
return -ENOMEM;
slot = folioq_append(roll->head, folio);
diff --git a/fs/netfs/write_issue.c b/fs/netfs/write_issue.c
index 8d3a6cad42d5e..0e5f0f259bd05 100644
--- a/fs/netfs/write_issue.c
+++ b/fs/netfs/write_issue.c
@@ -108,7 +108,7 @@ struct netfs_io_request *netfs_create_write_req(struct address_space *mapping,
ictx = netfs_inode(wreq->inode);
if (is_cacheable)
fscache_begin_write_operation(&wreq->cache_resources, netfs_i_cookie(ictx));
- if (rolling_buffer_init(&wreq->buffer, wreq->debug_id, ITER_SOURCE) < 0)
+ if (rolling_buffer_init(&wreq->buffer, wreq->debug_id, ITER_SOURCE, wreq->gfp) < 0)
goto nomem;
wreq->cleaned_to = wreq->start;
@@ -167,7 +167,7 @@ void netfs_prepare_write(struct netfs_io_request *wreq,
*/
if (iov_iter_is_folioq(wreq_iter) &&
wreq_iter->folioq_slot >= folioq_nr_slots(wreq_iter->folioq))
- rolling_buffer_make_space(&wreq->buffer);
+ rolling_buffer_make_space(&wreq->buffer, wreq->gfp);
subreq = netfs_alloc_subrequest(wreq);
subreq->source = stream->source;
@@ -334,7 +334,7 @@ static int netfs_write_folio(struct netfs_io_request *wreq,
_enter("");
- if (rolling_buffer_make_space(&wreq->buffer) < 0)
+ if (rolling_buffer_make_space(&wreq->buffer, wreq->gfp) < 0)
return -ENOMEM;
/* netfs_perform_write() may shift i_size around the page or from out
@@ -436,7 +436,7 @@ static int netfs_write_folio(struct netfs_io_request *wreq,
}
/* Attach the folio to the rolling buffer. */
- rolling_buffer_append(&wreq->buffer, folio, 0);
+ rolling_buffer_append(&wreq->buffer, folio, 0, wreq->gfp);
/* Move the submission point forward to allow for write-streaming data
* not starting at the front of the page. We don't do write-streaming
@@ -760,7 +760,7 @@ static int netfs_write_folio_single(struct netfs_io_request *wreq,
/* Attach the folio to the rolling buffer. */
folio_get(folio);
- ret = rolling_buffer_append(&wreq->buffer, folio, NETFS_ROLLBUF_PUT_MARK);
+ ret = rolling_buffer_append(&wreq->buffer, folio, NETFS_ROLLBUF_PUT_MARK, wreq->gfp);
if (ret < 0) {
folio_put(folio);
return ret;
diff --git a/include/linux/netfs.h b/include/linux/netfs.h
index 243c0f7379388..7b2daadffe198 100644
--- a/include/linux/netfs.h
+++ b/include/linux/netfs.h
@@ -253,6 +253,7 @@ struct netfs_io_request {
unsigned long long cleaned_to; /* Position we've cleaned folios to */
unsigned long long abandon_to; /* Position to abandon folios to */
const struct folio *no_unlock_folio; /* Don't unlock this folio after read */
+ gfp_t gfp; /* GFP flags to use */
unsigned int direct_bv_count; /* Number of elements in direct_bv[] */
unsigned int debug_id;
unsigned int rsize; /* Maximum read size (0 for none) */
diff --git a/include/linux/rolling_buffer.h b/include/linux/rolling_buffer.h
index ac15b1ffdd831..9e5dad29669cf 100644
--- a/include/linux/rolling_buffer.h
+++ b/include/linux/rolling_buffer.h
@@ -43,13 +43,13 @@ struct rolling_buffer_snapshot {
#define ROLLBUF_MARK_2 BIT(1)
int rolling_buffer_init(struct rolling_buffer *roll, unsigned int rreq_id,
- unsigned int direction);
-int rolling_buffer_make_space(struct rolling_buffer *roll);
+ unsigned int direction, gfp_t gfp);
+int rolling_buffer_make_space(struct rolling_buffer *roll, gfp_t gfp);
ssize_t rolling_buffer_load_from_ra(struct rolling_buffer *roll,
struct readahead_control *ractl,
struct folio_batch *put_batch);
ssize_t rolling_buffer_append(struct rolling_buffer *roll, struct folio *folio,
- unsigned int flags);
+ unsigned int flags, gfp_t gfp);
struct folio_queue *rolling_buffer_delete_spent(struct rolling_buffer *roll);
void rolling_buffer_clear(struct rolling_buffer *roll);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 122/438] net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 121/438] netfs: Fix folio_queue ENOMEM in writeback by adding a mempool Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 123/438] hwmon: (pmbus) Fix return value from pmbus_update_byte_data() Greg Kroah-Hartman
` (329 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chenguang Zhao, Paolo Abeni,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chenguang Zhao <zhaochenguang@kylinos.cn>
[ Upstream commit e095f249e2209674f6366f6db0383a2b96e19239 ]
mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq
cookie), but mtk_poll_controller incorrectly passed the net_device *.
Calling ndo_poll_controller with CONFIG_NET_POLL_CONTROLLER enabled
would then crash.
Fixes: 8186f6e382d8 ("net-next: mediatek: fix compile error inside mtk_poll_controller()")
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Link: https://patch.msgid.link/20260723055735.885112-1-chenguang.zhao@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mediatek/mtk_eth_soc.c b/drivers/net/ethernet/mediatek/mtk_eth_soc.c
index 5d291e50a47bb..351444fb48716 100644
--- a/drivers/net/ethernet/mediatek/mtk_eth_soc.c
+++ b/drivers/net/ethernet/mediatek/mtk_eth_soc.c
@@ -3467,7 +3467,7 @@ static void mtk_poll_controller(struct net_device *dev)
mtk_tx_irq_disable(eth, MTK_TX_DONE_INT);
mtk_rx_irq_disable(eth, eth->soc->rx.irq_done_mask);
- mtk_handle_irq_rx(eth->irq[MTK_FE_IRQ_RX], dev);
+ mtk_handle_irq_rx(eth->irq[MTK_FE_IRQ_RX], eth);
mtk_tx_irq_enable(eth, MTK_TX_DONE_INT);
mtk_rx_irq_enable(eth, eth->soc->rx.irq_done_mask);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 123/438] hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 122/438] net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 124/438] idpf: bound interrupt-vector register fill to the allocated array Greg Kroah-Hartman
` (328 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guenter Roeck, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
[ Upstream commit a19038a200f18d9e74ac30081797917d0886e16b ]
pmbus_update_byte_data() is supposed to return a negative error code or 0.
However, if no change is made to the register, it actually returns the
register value. This can result in problems if the calling code explicitly
expects to see an error code or 0.
Fix it to return 0 on success or the error code as expected.
Fixes: 11c119986f270 ("hwmon: (pmbus) add helpers for byte write and read modify write")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/pmbus/pmbus_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hwmon/pmbus/pmbus_core.c b/drivers/hwmon/pmbus/pmbus_core.c
index 3143b9e0316c4..7f2d28e41d816 100644
--- a/drivers/hwmon/pmbus/pmbus_core.c
+++ b/drivers/hwmon/pmbus/pmbus_core.c
@@ -513,7 +513,7 @@ int pmbus_update_byte_data(struct i2c_client *client, int page, u8 reg,
if (tmp != rv)
rv = _pmbus_write_byte_data(client, page, reg, tmp);
- return rv;
+ return rv < 0 ? rv : 0;
}
EXPORT_SYMBOL_NS_GPL(pmbus_update_byte_data, "PMBUS");
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 124/438] idpf: bound interrupt-vector register fill to the allocated array
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 123/438] hwmon: (pmbus) Fix return value from pmbus_update_byte_data() Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 125/438] idpf: adjust TxQ ring count minimum Greg Kroah-Hartman
` (327 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito,
Aleksandr Loktionov, Samuel Salin, Tony Nguyen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 9f7007ee9858c99aa43101bc8352c672fee85644 ]
idpf_get_reg_intr_vecs() fills the caller-allocated reg_vals[] array from
the VIRTCHNL2_OP_ALLOC_VECTORS reply in adapter->req_vec_chunks, bounding
its inner loop only by the per-chunk num_vectors. The array is sized
separately: idpf_intr_reg_init() allocates
kzalloc_objs(struct idpf_vec_regs, total_vecs) from
caps.num_allocated_vectors and only checks the returned count after the
fill. The sum of per-chunk num_vectors is never reconciled against
total_vecs, so a reply with a small num_allocated_vectors but chunks
summing higher writes past the end of reg_vals[].
Impact: a control plane (a PF or hypervisor device model) that returns a
VIRTCHNL2_OP_ALLOC_VECTORS reply whose per-chunk num_vectors sum exceeds
num_allocated_vectors writes struct idpf_vec_regs entries past the end of
the reg_vals kmalloc allocation (KASAN slab-out-of-bounds write).
Bound the fill loop to the array capacity passed in by the callers,
mirroring the sibling idpf_vport_get_q_reg(). The existing
num_regs < num_vecs check then rejects an undersized reply without the
out-of-bounds write happening first.
Fixes: d4d558718266 ("idpf: initialize interrupts and enable vport")
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Tested-by: Samuel Salin <Samuel.salin@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/idpf/idpf_dev.c | 2 +-
drivers/net/ethernet/intel/idpf/idpf_vf_dev.c | 2 +-
drivers/net/ethernet/intel/idpf/idpf_virtchnl.c | 5 +++--
drivers/net/ethernet/intel/idpf/idpf_virtchnl.h | 2 +-
4 files changed, 6 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/intel/idpf/idpf_dev.c b/drivers/net/ethernet/intel/idpf/idpf_dev.c
index 1a0c71c95ef12..4079a787657f1 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_dev.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_dev.c
@@ -87,7 +87,7 @@ static int idpf_intr_reg_init(struct idpf_vport *vport,
if (!reg_vals)
return -ENOMEM;
- num_regs = idpf_get_reg_intr_vecs(adapter, reg_vals);
+ num_regs = idpf_get_reg_intr_vecs(adapter, reg_vals, total_vecs);
if (num_regs < num_vecs) {
err = -EINVAL;
goto free_reg_vals;
diff --git a/drivers/net/ethernet/intel/idpf/idpf_vf_dev.c b/drivers/net/ethernet/intel/idpf/idpf_vf_dev.c
index a07d7e808ca9b..6726084f6cfa0 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_vf_dev.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_vf_dev.c
@@ -86,7 +86,7 @@ static int idpf_vf_intr_reg_init(struct idpf_vport *vport,
if (!reg_vals)
return -ENOMEM;
- num_regs = idpf_get_reg_intr_vecs(adapter, reg_vals);
+ num_regs = idpf_get_reg_intr_vecs(adapter, reg_vals, total_vecs);
if (num_regs < num_vecs) {
err = -EINVAL;
goto free_reg_vals;
diff --git a/drivers/net/ethernet/intel/idpf/idpf_virtchnl.c b/drivers/net/ethernet/intel/idpf/idpf_virtchnl.c
index dc5ad784f456f..8bd6cca64c9bf 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_virtchnl.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_virtchnl.c
@@ -1318,11 +1318,12 @@ idpf_vport_init_queue_reg_chunks(struct idpf_vport_config *vport_config,
* idpf_get_reg_intr_vecs - Get vector queue register offset
* @adapter: adapter structure to get the vector chunks
* @reg_vals: Register offsets to store in
+ * @num_vecs: number of entries the @reg_vals array can hold
*
* Return: number of registers that got populated
*/
int idpf_get_reg_intr_vecs(struct idpf_adapter *adapter,
- struct idpf_vec_regs *reg_vals)
+ struct idpf_vec_regs *reg_vals, int num_vecs)
{
struct virtchnl2_vector_chunks *chunks;
struct idpf_vec_regs reg_val;
@@ -1346,7 +1347,7 @@ int idpf_get_reg_intr_vecs(struct idpf_adapter *adapter,
dynctl_reg_spacing = le32_to_cpu(chunk->dynctl_reg_spacing);
itrn_reg_spacing = le32_to_cpu(chunk->itrn_reg_spacing);
- for (i = 0; i < num_vec; i++) {
+ for (i = 0; i < num_vec && num_regs < num_vecs; i++) {
reg_vals[num_regs].dyn_ctl_reg = reg_val.dyn_ctl_reg;
reg_vals[num_regs].itrn_reg = reg_val.itrn_reg;
reg_vals[num_regs].itrn_index_spacing =
diff --git a/drivers/net/ethernet/intel/idpf/idpf_virtchnl.h b/drivers/net/ethernet/intel/idpf/idpf_virtchnl.h
index 6876e3ed9d1be..9b1c9c86f6eac 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_virtchnl.h
+++ b/drivers/net/ethernet/intel/idpf/idpf_virtchnl.h
@@ -104,7 +104,7 @@ int idpf_vc_core_init(struct idpf_adapter *adapter);
void idpf_vc_core_deinit(struct idpf_adapter *adapter);
int idpf_get_reg_intr_vecs(struct idpf_adapter *adapter,
- struct idpf_vec_regs *reg_vals);
+ struct idpf_vec_regs *reg_vals, int num_vecs);
int idpf_queue_reg_init(struct idpf_vport *vport,
struct idpf_q_vec_rsrc *rsrc,
struct idpf_queue_id_reg_info *chunks);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 125/438] idpf: adjust TxQ ring count minimum
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 124/438] idpf: bound interrupt-vector register fill to the allocated array Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 126/438] idpf: Fix mailbox IRQ name leak on request failure Greg Kroah-Hartman
` (326 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joshua Hay, Aleksandr Loktionov,
Samuel Salin, Tony Nguyen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joshua Hay <joshua.a.hay@intel.com>
[ Upstream commit bef152db47debcd14cbacefc5767f6f026c4bc89 ]
Set the TxQ ring count minimum to 128 descriptors. Any lower than this,
and the queue will stall and trigger Tx timeouts in flow based
scheduling mode. This is because next_to_clean might never be updated.
In flow based scheduling mode, next_to_clean is only updated after a
descriptor completion is processed, i.e. after the RE bit is set in the
last descriptor of a Tx packet. This will never happen with a ring size
of 64 and an IDPF_TX_SPLITQ_RE_MIN_GAP of 64. No matter what the value
of last_re is initialized/set to, the calculated gap will be at most 63
and never trigger the RE bit.
Even a ring size of 96 does not solve this. Because of how infrequent
next_to_clean is updated and how small the ring is, IDPF_DESC_UNUSED
will be much smaller on average. This increases the chance the queue
will be stopped because a multi-descriptor packet, e.g. a large LSO
packet, does not see enough resources on the ring. In this case, the
queue will trigger the stop logic. The queue permanently stalls because
there is no chance for a descriptor completion to update next_to_clean
since it is dependent on a packet being sent.
Fixes: 5f417d551324 ("idpf: replace flow scheduling buffer ring with buffer pool")
Signed-off-by: Joshua Hay <joshua.a.hay@intel.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Tested-by: Samuel Salin <Samuel.salin@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/idpf/idpf_txrx.c | 5 +----
drivers/net/ethernet/intel/idpf/idpf_txrx.h | 2 +-
2 files changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/intel/idpf/idpf_txrx.c b/drivers/net/ethernet/intel/idpf/idpf_txrx.c
index f6b3b15364ff6..bddb601ee411c 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_txrx.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_txrx.c
@@ -3097,10 +3097,7 @@ static netdev_tx_t idpf_tx_splitq_frame(struct sk_buff *skb,
tx_params.dtype = IDPF_TX_DESC_DTYPE_FLEX_FLOW_SCHE;
tx_params.eop_cmd = IDPF_TXD_FLEX_FLOW_CMD_EOP;
- /* Set the RE bit to periodically "clean" the descriptor ring.
- * MIN_GAP is set to MIN_RING size to ensure it will be set at
- * least once each time around the ring.
- */
+ /* Set the RE bit periodically to "clean" the descriptor ring */
if (idpf_tx_splitq_need_re(tx_q)) {
tx_params.eop_cmd |= IDPF_TXD_FLEX_FLOW_CMD_RE;
tx_q->txq_grp->num_completions_pending++;
diff --git a/drivers/net/ethernet/intel/idpf/idpf_txrx.h b/drivers/net/ethernet/intel/idpf/idpf_txrx.h
index 4be5b3b6d3ed2..908dfa28674eb 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_txrx.h
+++ b/drivers/net/ethernet/intel/idpf/idpf_txrx.h
@@ -21,7 +21,7 @@
/* Mailbox Queue */
#define IDPF_MAX_MBXQ 1
-#define IDPF_MIN_TXQ_DESC 64
+#define IDPF_MIN_TXQ_DESC 128
#define IDPF_MIN_RXQ_DESC 64
#define IDPF_MIN_TXQ_COMPLQ_DESC 256
#define IDPF_MAX_QIDS 256
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 126/438] idpf: Fix mailbox IRQ name leak on request failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 125/438] idpf: adjust TxQ ring count minimum Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 127/438] ice: suppress DPLL errors during reset recovery Greg Kroah-Hartman
` (325 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Aleksandr Loktionov,
Samuel Salin, Tony Nguyen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 9bff30482c10f70d9e56c0633a6616e07140e217 ]
idpf_mb_intr_req_irq() allocates the mailbox IRQ name before calling
request_irq(). On success, the name is released later through
kfree(free_irq()), but request_irq() failure returns without freeing it.
Free the allocated name on the request_irq() failure path.
Fixes: 4930fbf419a7 ("idpf: add core init and interrupt request")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Tested-by: Samuel Salin <Samuel.salin@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/idpf/idpf_lib.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/intel/idpf/idpf_lib.c b/drivers/net/ethernet/intel/idpf/idpf_lib.c
index cf966fe6c759c..bb81e620c5c87 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_lib.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_lib.c
@@ -139,7 +139,7 @@ static int idpf_mb_intr_req_irq(struct idpf_adapter *adapter)
if (err) {
dev_err(&adapter->pdev->dev,
"IRQ request for mailbox failed, error: %d\n", err);
-
+ kfree(name);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 127/438] ice: suppress DPLL errors during reset recovery
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 126/438] idpf: Fix mailbox IRQ name leak on request failure Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 128/438] Bluetooth: ISO: clear iso_data always when detaching conn from hcon Greg Kroah-Hartman
` (324 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Przemyslaw Korba, Simon Horman,
Aleksandr Loktionov, Tony Nguyen, Sasha Levin, Rinitha S
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Przemyslaw Korba <przemyslaw.korba@intel.com>
[ Upstream commit b00be7c6b4bd7da3d510753b27ff6cb7ec647d07 ]
During reset recovery, the admin queue returns EBUSY which is expected
behavior. However, the DPLL subsystem was logging these as errors and
incrementing the error counter, potentially leading to unnecessary
warnings and even disabling the DPLL periodic worker if the threshold
was reached.
Suppress error logging and error counter increments when the admin
queue returns EBUSY, as this is expected during reset recovery and
not a real failure condition.
test case:
- ethtool --reset eth3 irq-shared dma-shared filter-shared offload-shared
mac-shared phy-shared ram-shared
- observe if dmesg EBUSY errors are gone
Fixes: d7999f5ea64b ("ice: implement dpll interface to control cgu")
Signed-off-by: Przemyslaw Korba <przemyslaw.korba@intel.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Tested-by: Rinitha S <sx.rinitha@intel.com> (A Contingent worker at Intel)
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/ice/ice_dpll.c | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_dpll.c b/drivers/net/ethernet/intel/ice/ice_dpll.c
index 5f6f29142e301..14dfddc85d1c0 100644
--- a/drivers/net/ethernet/intel/ice/ice_dpll.c
+++ b/drivers/net/ethernet/intel/ice/ice_dpll.c
@@ -784,7 +784,7 @@ ice_dpll_pin_state_update(struct ice_pf *pf, struct ice_dpll_pin *pin,
ret,
libie_aq_str(pf->hw.adminq.sq_last_status),
pin_type_name[pin_type], pin->idx);
- else
+ else if (pf->hw.adminq.sq_last_status != LIBIE_AQ_RC_EBUSY)
dev_err_ratelimited(ice_pf_to_dev(pf),
"err:%d %s failed to update %s pin:%u\n",
ret,
@@ -2821,7 +2821,8 @@ static int ice_dpll_pps_update_phase_offsets(struct ice_pf *pf,
*phase_offset_pins_updated = 0;
ret = ice_aq_get_cgu_input_pin_measure(&pf->hw, DPLL_TYPE_PPS, meas,
ARRAY_SIZE(meas));
- if (ret && pf->hw.adminq.sq_last_status == LIBIE_AQ_RC_EAGAIN) {
+ if (ret && (pf->hw.adminq.sq_last_status == LIBIE_AQ_RC_EAGAIN ||
+ pf->hw.adminq.sq_last_status == LIBIE_AQ_RC_EBUSY)) {
return 0;
} else if (ret) {
dev_err(ice_pf_to_dev(pf),
@@ -2883,10 +2884,12 @@ ice_dpll_update_state(struct ice_pf *pf, struct ice_dpll *d, bool init)
d->dpll_idx, d->prev_input_idx, d->input_idx,
d->dpll_state, d->prev_dpll_state, d->mode);
if (ret) {
- dev_err(ice_pf_to_dev(pf),
- "update dpll=%d state failed, ret=%d %s\n",
- d->dpll_idx, ret,
- libie_aq_str(pf->hw.adminq.sq_last_status));
+ /* EBUSY is expected during reset recovery, don't log error */
+ if (pf->hw.adminq.sq_last_status != LIBIE_AQ_RC_EBUSY)
+ dev_err(ice_pf_to_dev(pf),
+ "update dpll=%d state failed, ret=%d %s\n",
+ d->dpll_idx, ret,
+ libie_aq_str(pf->hw.adminq.sq_last_status));
return ret;
}
if (init) {
@@ -2955,7 +2958,9 @@ static void ice_dpll_periodic_work(struct kthread_work *work)
d->periodic_counter % dp->phase_offset_monitor_period == 0)
ret = ice_dpll_pps_update_phase_offsets(pf, &phase_offset_ntf);
if (ret) {
- d->cgu_state_acq_err_num++;
+ /* EBUSY is expected during reset recovery */
+ if (pf->hw.adminq.sq_last_status != LIBIE_AQ_RC_EBUSY)
+ d->cgu_state_acq_err_num++;
/* stop rescheduling this worker */
if (d->cgu_state_acq_err_num >
ICE_CGU_STATE_ACQ_ERR_THRESHOLD) {
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 128/438] Bluetooth: ISO: clear iso_data always when detaching conn from hcon
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 127/438] ice: suppress DPLL errors during reset recovery Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 129/438] Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp Greg Kroah-Hartman
` (323 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit d57e506f6a1e3929611340fae87c1e4823f4d85c ]
When setting conn->hcon = NULL, also conn->hcon->iso_data = NULL is
necessary, otherwise later iso_conn_free() will UAF.
Fix clearing of iso_data in iso_sock_disconn()
Fixes KASAN: slab-use-after-free in iso_conn_hold_unless_zero on
iso_sock_release() followed by hci_abort_conn_sync().
Fixes: fbdc4bc47268 ("Bluetooth: ISO: Use defer setup to separate PA sync and BIG sync")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 1d5ce87e6496e..6bbbbce4c5f27 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -836,6 +836,7 @@ static void iso_sock_disconn(struct sock *sk)
sk->sk_state = BT_DISCONN;
iso_conn_lock(iso_pi(sk)->conn);
hci_conn_drop(iso_pi(sk)->conn->hcon);
+ iso_pi(sk)->conn->hcon->iso_data = NULL;
iso_pi(sk)->conn->hcon = NULL;
iso_conn_unlock(iso_pi(sk)->conn);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 129/438] Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 128/438] Bluetooth: ISO: clear iso_data always when detaching conn from hcon Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 130/438] Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release Greg Kroah-Hartman
` (322 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiale Yao, Luiz Augusto von Dentz,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiale Yao <yaojiale02@163.com>
[ Upstream commit c4740e7f23ff9a8210198d8b4703259e21b9f69d ]
l2cap_le_connect_rsp() obtains a channel via
__l2cap_get_chan_by_ident() but neither holds a reference nor uses
l2cap_chan_hold_unless_zero() before locking and operating on it.
A concurrent l2cap_chan_del() triggered by a remote disconnect can
free the channel between the lookup and l2cap_chan_lock(), causing
a use-after-free.
The BR/EDR counterpart l2cap_connect_rsp() and the sibling handler
l2cap_le_command_rej() already use l2cap_chan_hold_unless_zero()
to safely hold a reference, but l2cap_le_connect_rsp() was left
unprotected.
Fix by adding l2cap_chan_hold_unless_zero() after the ident lookup
and l2cap_chan_put() on the exit path, consistent with other L2CAP
response handlers.
Fixes: f1496dee9cbd ("Bluetooth: Add initial code for LE L2CAP Connect Request")
Assisted-by: Claude:deepseek-v4-pro
Signed-off-by: Jiale Yao <yaojiale02@163.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/l2cap_core.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
index 189085000c73b..6585f08fe4a14 100644
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -4823,6 +4823,10 @@ static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
if (!chan)
return -EBADSLT;
+ chan = l2cap_chan_hold_unless_zero(chan);
+ if (!chan)
+ return -EBADSLT;
+
err = 0;
l2cap_chan_lock(chan);
@@ -4868,6 +4872,7 @@ static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
}
l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 130/438] Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 129/438] Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 131/438] Bluetooth: ISO: lock sk in iso_sock_getname Greg Kroah-Hartman
` (321 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 0786469ee242952008628ed0e2d386098e2065ab ]
Commit d57e506f6a1e ("Bluetooth: ISO: clear iso_data always when detaching conn from hcon")
merged a version of the UAF fix that breaks releasing connected
ISO sockets. Since hci_conn::iso_data is set to NULL, iso_chan_del() won't
be called when the hci_conn disconnects, and the ISO socket does not emit
POLLHUP correctly.
Fix by retaining full hci_conn <-> iso_conn association while in
BT_DISCONNECT state, so that local disconnect via shutdown() follows
similar ISO socket code path as remote disconnect. Use a separate flag
to track whether hci_conn_drop() is needed, instead of setting
iso_conn::hcon = NULL
In iso_sock_ready(), disallow disconnecting socket going BT_CONNECTED,
in case hcon connects while its drop is pending.
Fixes: d57e506f6a1e ("Bluetooth: ISO: clear iso_data always when detaching conn from hcon")
Fixes: fbdc4bc47268 ("Bluetooth: ISO: Use defer setup to separate PA sync and BIG sync")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 26 ++++++++++++++++++++------
1 file changed, 20 insertions(+), 6 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 6bbbbce4c5f27..f1399ddd6ad05 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -23,8 +23,14 @@ static struct bt_sock_list iso_sk_list = {
};
/* ---- ISO connections ---- */
+enum {
+ ISO_CONN_DROPPED,
+ __ISO_CONN_NUM_FLAGS
+};
+
struct iso_conn {
struct hci_conn *hcon;
+ DECLARE_BITMAP(flags, __ISO_CONN_NUM_FLAGS);
/* @lock: spinlock protecting changes to iso_conn fields */
spinlock_t lock;
@@ -106,7 +112,8 @@ static void iso_conn_free(struct kref *ref)
if (conn->hcon) {
conn->hcon->iso_data = NULL;
- hci_conn_drop(conn->hcon);
+ if (!test_and_set_bit(ISO_CONN_DROPPED, conn->flags))
+ hci_conn_drop(conn->hcon);
}
/* Ensure no more work items will run since hci_conn has been dropped */
@@ -305,6 +312,7 @@ static int __iso_chan_add(struct iso_conn *conn, struct sock *sk,
iso_pi(sk)->conn = conn;
conn->sk = sk;
+ clear_bit(ISO_CONN_DROPPED, conn->flags);
if (parent)
bt_accept_enqueue(parent, sk, true);
@@ -834,11 +842,8 @@ static void iso_sock_disconn(struct sock *sk)
}
sk->sk_state = BT_DISCONN;
- iso_conn_lock(iso_pi(sk)->conn);
- hci_conn_drop(iso_pi(sk)->conn->hcon);
- iso_pi(sk)->conn->hcon->iso_data = NULL;
- iso_pi(sk)->conn->hcon = NULL;
- iso_conn_unlock(iso_pi(sk)->conn);
+ if (!test_and_set_bit(ISO_CONN_DROPPED, iso_pi(sk)->conn->flags))
+ hci_conn_drop(iso_pi(sk)->conn->hcon);
}
static void __iso_sock_close(struct sock *sk)
@@ -2041,9 +2046,18 @@ static void iso_sock_ready(struct sock *sk)
return;
lock_sock(sk);
+
+ switch (sk->sk_state) {
+ case BT_DISCONN:
+ case BT_CLOSED:
+ release_sock(sk);
+ return;
+ }
+
iso_sock_clear_timer(sk);
sk->sk_state = BT_CONNECTED;
sk->sk_state_change(sk);
+
release_sock(sk);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 131/438] Bluetooth: ISO: lock sk in iso_sock_getname
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 130/438] Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 132/438] Bluetooth: ISO: lock sk in iso_connect_ind Greg Kroah-Hartman
` (320 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 89cf154d7c18e6e94a3da83051f3cf2bac317ae2 ]
Accessing iso_pi(sk)->conn requires lock_sock, which is not held here.
Fix by adding the lock/release.
Fixes: 2df108c227b2 ("Bluetooth: ISO: Fix using BT_SK_PA_SYNC to detect BIS sockets")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index f1399ddd6ad05..476c679791234 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -1471,6 +1471,8 @@ static int iso_sock_getname(struct socket *sock, struct sockaddr *addr,
BT_DBG("sock %p, sk %p", sock, sk);
+ lock_sock(sk);
+
addr->sa_family = AF_BLUETOOTH;
if (peer) {
@@ -1492,6 +1494,8 @@ static int iso_sock_getname(struct socket *sock, struct sockaddr *addr,
sa->iso_bdaddr_type = iso_pi(sk)->src_type;
}
+ release_sock(sk);
+
return len;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 132/438] Bluetooth: ISO: lock sk in iso_connect_ind
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 131/438] Bluetooth: ISO: lock sk in iso_sock_getname Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 133/438] Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos Greg Kroah-Hartman
` (319 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 4311fd6f429065a8ba208660360a895627a00cf3 ]
Accessing iso_pi(sk)->conn requires lock_sock, which is not taken in the
"ev3" part of iso_connect_ind. It may also be NULL if socket has
transitioned away from the LISTEN/CONNECT states before locking.
Fix by adding lock/release. Recheck hcon is valid after lock acquire
where needed.
Fixes: 168d9bf9c7f0 ("Bluetooth: ISO: Reassemble PA data for bcast sink")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 19 +++++++++++--------
1 file changed, 11 insertions(+), 8 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 476c679791234..6fadaeb1f7e96 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -2368,7 +2368,7 @@ int iso_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 *flags)
lock_sock(sk);
- hcon = iso_pi(sk)->conn->hcon;
+ hcon = iso_pi(sk)->conn ? iso_pi(sk)->conn->hcon : NULL;
iso_pi(sk)->qos.bcast.encryption = ev2->encryption;
if (ev2->num_bis < iso_pi(sk)->bc_num_bis)
@@ -2408,9 +2408,11 @@ int iso_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 *flags)
if (!sk)
goto done;
- hcon = iso_pi(sk)->conn->hcon;
+ lock_sock(sk);
+
+ hcon = iso_pi(sk)->conn ? iso_pi(sk)->conn->hcon : NULL;
if (!hcon)
- goto done;
+ goto release3;
if (ev3->data_status == LE_PA_DATA_TRUNCATED) {
/* The controller was unable to retrieve PA data. */
@@ -2418,12 +2420,12 @@ int iso_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 *flags)
HCI_MAX_PER_AD_TOT_LEN);
hcon->le_per_adv_data_len = 0;
hcon->le_per_adv_data_offset = 0;
- goto done;
+ goto release3;
}
if (hcon->le_per_adv_data_offset + ev3->length >
HCI_MAX_PER_AD_TOT_LEN)
- goto done;
+ goto release3;
memcpy(hcon->le_per_adv_data + hcon->le_per_adv_data_offset,
ev3->data, ev3->length);
@@ -2442,18 +2444,19 @@ int iso_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 *flags)
&base_len);
if (!base || base_len > BASE_MAX_LENGTH)
- goto done;
+ goto release3;
- lock_sock(sk);
memcpy(iso_pi(sk)->base, base, base_len);
iso_pi(sk)->base_len = base_len;
- release_sock(sk);
} else {
/* This is a PA data fragment. Keep pa_data_len set to 0
* until all data has been reassembled.
*/
hcon->le_per_adv_data_len = 0;
}
+
+release3:
+ release_sock(sk);
} else {
sk = iso_get_sock(hdev, &hdev->bdaddr, BDADDR_ANY,
BT_LISTEN, iso_match_dst, BDADDR_ANY);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 133/438] Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 132/438] Bluetooth: ISO: lock sk in iso_connect_ind Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 134/438] Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() Greg Kroah-Hartman
` (318 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit e9cb51813d79fc9aae4a2098aab3ab6ebd7fb6c8 ]
In iso.c check_bcast_qos(), missing bcast.timeout is not set to its
default value, and appears typoed as bcast.sync_timeout.
Fix the typo.
Fixes: b37cab587aa3 ("Bluetooth: ISO: Don't reject BT_ISO_QOS if parameters are unset")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 6fadaeb1f7e96..7e8f8a51eebd2 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -1795,7 +1795,7 @@ static bool check_bcast_qos(struct bt_iso_qos *qos)
return false;
if (!qos->bcast.timeout)
- qos->bcast.sync_timeout = BT_ISO_SYNC_TIMEOUT;
+ qos->bcast.timeout = BT_ISO_SYNC_TIMEOUT;
if (qos->bcast.timeout < 0x000a || qos->bcast.timeout > 0x4000)
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 134/438] Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 133/438] Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 135/438] Bluetooth: ISO: hold sk properly in iso_conn_ready Greg Kroah-Hartman
` (317 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 4e20192d46a685d73e590a60a4a2419a0a8afcbf ]
iso_sock_rebind_bis() updates socket iso_pi(sk)->bc_num_bis before
validating the BIS values, so it's possible to end up with bc_num_bis
inconsistent.
Assign to iso_pi(sk)->bc_num_bis only after validation.
Fixes: 80837140c1f2 ("Bluetooth: ISO: Allow binding a PA sync socket")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 7e8f8a51eebd2..06b6fec364485 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -1038,15 +1038,15 @@ static int iso_sock_rebind_bis(struct sock *sk, struct sockaddr_iso *sa,
goto done;
}
- iso_pi(sk)->bc_num_bis = sa->iso_bc->bc_num_bis;
-
- for (int i = 0; i < iso_pi(sk)->bc_num_bis; i++)
+ for (int i = 0; i < sa->iso_bc->bc_num_bis; i++)
if (sa->iso_bc->bc_bis[i] < 0x01 ||
sa->iso_bc->bc_bis[i] > 0x1f) {
err = -EINVAL;
goto done;
}
+ iso_pi(sk)->bc_num_bis = sa->iso_bc->bc_num_bis;
+
memcpy(iso_pi(sk)->bc_bis, sa->iso_bc->bc_bis,
iso_pi(sk)->bc_num_bis);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 135/438] Bluetooth: ISO: hold sk properly in iso_conn_ready
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 134/438] Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 136/438] Bluetooth: ISO: fix leaking sk after socket release Greg Kroah-Hartman
` (316 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 0d255e63fcf3f13a570d7ac11678fa1164ac015c ]
sk deref in iso_conn_ready must be done either under conn->lock, or
holding a refcount, to avoid concurrent close. conn->sk is currently
accessed without either:
[Task 1] [Task 2]
iso_sock_release
iso_conn_ready
sk = conn->sk
lock_sock(sk)
conn->sk = NULL
lock_sock(sk)
release_sock(sk)
iso_sock_kill(sk)
UAF on sk deref
Fix possible UAF by holding sk refcount in iso_conn_ready(). Also
recheck after lock_sock that the socket is still valid. Adjust locking
so conn->sk is cleared only under lock_sock.
Fixes: 27c24fda62b60 ("Bluetooth: switch to lock_sock in SCO")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 34 +++++++++++++++++++++++-----------
1 file changed, 23 insertions(+), 11 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 06b6fec364485..9d1ac27202664 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -804,11 +804,13 @@ static void iso_sock_kill(struct sock *sk)
BT_DBG("sk %p state %d", sk, sk->sk_state);
/* Sock is dead, so set conn->sk to NULL to avoid possible UAF */
+ lock_sock(sk);
if (iso_pi(sk)->conn) {
iso_conn_lock(iso_pi(sk)->conn);
iso_pi(sk)->conn->sk = NULL;
iso_conn_unlock(iso_pi(sk)->conn);
}
+ release_sock(sk);
/* Kill poor orphan */
bt_sock_unlink(&iso_sk_list, sk);
@@ -2046,23 +2048,17 @@ static void iso_sock_ready(struct sock *sk)
{
BT_DBG("sk %p", sk);
- if (!sk)
- return;
-
- lock_sock(sk);
+ lockdep_assert(lockdep_sock_is_held(sk));
switch (sk->sk_state) {
case BT_DISCONN:
case BT_CLOSED:
- release_sock(sk);
return;
}
iso_sock_clear_timer(sk);
sk->sk_state = BT_CONNECTED;
sk->sk_state_change(sk);
-
- release_sock(sk);
}
static bool iso_match_big(struct sock *sk, void *data)
@@ -2092,7 +2088,7 @@ static bool iso_match_dst(struct sock *sk, void *data)
static void iso_conn_ready(struct iso_conn *conn)
{
struct sock *parent = NULL;
- struct sock *sk = conn->sk;
+ struct sock *sk;
struct hci_ev_le_big_sync_established *ev = NULL;
struct hci_ev_le_pa_sync_established *ev2 = NULL;
struct hci_ev_le_per_adv_report *ev3 = NULL;
@@ -2101,7 +2097,22 @@ static void iso_conn_ready(struct iso_conn *conn)
BT_DBG("conn %p", conn);
+ iso_conn_lock(conn);
+ sk = iso_sock_hold(conn);
+ iso_conn_unlock(conn);
+
if (sk) {
+ lock_sock(sk);
+
+ /* conn->sk may have become NULL if racing with sk close, but
+ * due to held hdev->lock, it can't become different sk.
+ */
+ if (!conn->sk) {
+ release_sock(sk);
+ sock_put(sk);
+ return;
+ }
+
/* Attempt to update source address in case of BIS Sender if
* the advertisement is using a random address.
*/
@@ -2114,14 +2125,15 @@ static void iso_conn_ready(struct iso_conn *conn)
adv = hci_find_adv_instance(bis->hdev,
bis->iso_qos.bcast.bis);
if (adv && bacmp(&adv->random_addr, BDADDR_ANY)) {
- lock_sock(sk);
iso_pi(sk)->src_type = BDADDR_LE_RANDOM;
bacpy(&iso_pi(sk)->src, &adv->random_addr);
- release_sock(sk);
}
}
- iso_sock_ready(conn->sk);
+ iso_sock_ready(sk);
+
+ release_sock(sk);
+ sock_put(sk);
} else {
hcon = conn->hcon;
if (!hcon)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 136/438] Bluetooth: ISO: fix leaking sk after socket release
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 135/438] Bluetooth: ISO: hold sk properly in iso_conn_ready Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 137/438] Bluetooth: ISO: avoid deadlocks in iso_sock_timeout Greg Kroah-Hartman
` (315 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit ce57442a379212fe3fda59c9437ee8217eceb5b1 ]
iso_sock_kill() tests !sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket ||
sock_flag(sk, SOCK_DEAD) for early return, but this is always true since
sock_orphan(sk) sets SOCK_DEAD, so the sk reference released by socket
always leaks, iso_sock_destruct is never called.
The socket reference also leaks when __iso_sock_close() does not set
SOCK_ZAPPED, since iso_conn_del() does not call iso_sock_kill() after
zapping.
Fix by replacing SOCK_DEAD by BT_SK_KILLED flag that is not used for
something else, and lock_sock to ensure iso_sock_kill() puts sk only
after socket release only once. Release and iso_conn_del may run
concurrently. Call iso_sock_kill() from iso_conn_del() to clean sk up
after zapping.
Remove call to iso_sock_kill() from iso_sock_close(), as it's generally
no-op there.
Fixes: ccf74f2390d6 ("Bluetooth: Add BTPROTO_ISO socket type")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 22 ++++++++++++++++++----
1 file changed, 18 insertions(+), 4 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 9d1ac27202664..1ca3576357006 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -61,6 +61,7 @@ static void iso_sock_kill(struct sock *sk);
enum {
BT_SK_BIG_SYNC,
BT_SK_PA_SYNC,
+ BT_SK_KILLED,
};
struct iso_pinfo {
@@ -294,6 +295,7 @@ static void iso_conn_del(struct hci_conn *hcon, int err)
iso_sock_clear_timer(sk);
iso_chan_del(sk, err);
release_sock(sk);
+ iso_sock_kill(sk);
sock_put(sk);
}
@@ -797,24 +799,29 @@ static void iso_sock_cleanup_listen(struct sock *parent)
*/
static void iso_sock_kill(struct sock *sk)
{
+ lock_sock(sk);
+
if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket ||
- sock_flag(sk, SOCK_DEAD))
+ test_bit(BT_SK_KILLED, &iso_pi(sk)->flags)) {
+ release_sock(sk);
return;
+ }
BT_DBG("sk %p state %d", sk, sk->sk_state);
/* Sock is dead, so set conn->sk to NULL to avoid possible UAF */
- lock_sock(sk);
if (iso_pi(sk)->conn) {
iso_conn_lock(iso_pi(sk)->conn);
iso_pi(sk)->conn->sk = NULL;
iso_conn_unlock(iso_pi(sk)->conn);
}
- release_sock(sk);
/* Kill poor orphan */
bt_sock_unlink(&iso_sk_list, sk);
sock_set_flag(sk, SOCK_DEAD);
+ set_bit(BT_SK_KILLED, &iso_pi(sk)->flags);
+
+ release_sock(sk);
sock_put(sk);
}
@@ -891,7 +898,6 @@ static void iso_sock_close(struct sock *sk)
iso_sock_clear_timer(sk);
__iso_sock_close(sk);
release_sock(sk);
- iso_sock_kill(sk);
}
static void iso_sock_init(struct sock *sk, struct sock *parent)
@@ -2039,8 +2045,16 @@ static int iso_sock_release(struct socket *sock)
release_sock(sk);
}
+ /* Make sure sk is valid even if iso_conn_del() is concurrent */
+ sock_hold(sk);
+
+ lock_sock(sk);
sock_orphan(sk);
+ release_sock(sk);
+
iso_sock_kill(sk);
+
+ sock_put(sk);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 137/438] Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 136/438] Bluetooth: ISO: fix leaking sk after socket release Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 138/438] Bluetooth: ISO: ensure no dangling hcon references in iso_conn Greg Kroah-Hartman
` (314 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 200fa1629c57a3ca2b03d3ca63fd3a9bfd910c43 ]
iso_sock_timeout() takes lock_sock, so sync disabling the timer while
holding that lock may deadlock.
iso_sock_timeout() may also run concurrently with iso_conn_del(), which
leads to UAF
[Task 1] [Task hdev->workqueue]
iso_sock_timeout iso_conn_del
iso_conn_hold_unless_zero iso_chan_del
`------------> iso_conn_put
caller frees hcon
iso_conn_put
iso_conn_free
conn->hcon->iso_data = NULL; /* UAF */
Fix the deadlock by removing the disable from the lock_sock sections.
Move the timer from iso_conn to iso_pinfo to decouple it from iso_conn
which may need to be freed in lock_sock section. Convert some of the
clear_timer to disable_timer.
Fixes: dc26097bdb86 ("Bluetooth: ISO: Use kref to track lifetime of iso_conn")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 60 ++++++++++++++++++++++-----------------------
1 file changed, 29 insertions(+), 31 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 1ca3576357006..7e1dcaa22a5b2 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -36,8 +36,6 @@ struct iso_conn {
spinlock_t lock;
struct sock *sk;
- struct delayed_work timeout_work;
-
struct sk_buff *rx_skb;
__u32 rx_len;
__u16 tx_sn;
@@ -80,6 +78,7 @@ struct iso_pinfo {
__u8 base_len;
__u8 base[BASE_MAX_LENGTH];
struct iso_conn *conn;
+ struct delayed_work timeout_work;
};
static struct bt_iso_qos default_qos;
@@ -117,9 +116,6 @@ static void iso_conn_free(struct kref *ref)
hci_conn_drop(conn->hcon);
}
- /* Ensure no more work items will run since hci_conn has been dropped */
- disable_delayed_work_sync(&conn->timeout_work);
-
kfree_skb(conn->rx_skb);
kfree(conn);
@@ -160,48 +156,45 @@ static struct sock *iso_sock_hold(struct iso_conn *conn)
static void iso_sock_timeout(struct work_struct *work)
{
- struct iso_conn *conn = container_of(work, struct iso_conn,
- timeout_work.work);
- struct sock *sk;
-
- conn = iso_conn_hold_unless_zero(conn);
- if (!conn)
- return;
-
- iso_conn_lock(conn);
- sk = iso_sock_hold(conn);
- iso_conn_unlock(conn);
- iso_conn_put(conn);
-
- if (!sk)
- return;
+ struct iso_pinfo *pi = container_of(work, struct iso_pinfo,
+ timeout_work.work);
+ struct sock *sk = &pi->bt.sk;
BT_DBG("sock %p state %d", sk, sk->sk_state);
lock_sock(sk);
- sk->sk_err = ETIMEDOUT;
- sk->sk_state_change(sk);
+ if (!sock_flag(sk, SOCK_ZAPPED)) {
+ sk->sk_err = ETIMEDOUT;
+ sk->sk_state_change(sk);
+ }
release_sock(sk);
- sock_put(sk);
}
static void iso_sock_set_timer(struct sock *sk, long timeout)
{
+ lockdep_assert(lockdep_sock_is_held(sk));
+
+ cancel_delayed_work(&iso_pi(sk)->timeout_work);
+
if (!iso_pi(sk)->conn)
return;
BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
- cancel_delayed_work(&iso_pi(sk)->conn->timeout_work);
- schedule_delayed_work(&iso_pi(sk)->conn->timeout_work, timeout);
+ schedule_delayed_work(&iso_pi(sk)->timeout_work, timeout);
}
static void iso_sock_clear_timer(struct sock *sk)
{
- if (!iso_pi(sk)->conn)
- return;
+ BT_DBG("sock %p state %d", sk, sk->sk_state);
+ cancel_delayed_work(&iso_pi(sk)->timeout_work);
+}
+
+static void iso_sock_disable_timer(struct sock *sk)
+{
+ lockdep_assert(!lockdep_sock_is_held(sk));
BT_DBG("sock %p state %d", sk, sk->sk_state);
- cancel_delayed_work(&iso_pi(sk)->conn->timeout_work);
+ disable_delayed_work_sync(&iso_pi(sk)->timeout_work);
}
/* ---- ISO connections ---- */
@@ -226,7 +219,6 @@ static struct iso_conn *iso_conn_add(struct hci_conn *hcon)
kref_init(&conn->ref);
spin_lock_init(&conn->lock);
- INIT_DELAYED_WORK(&conn->timeout_work, iso_sock_timeout);
hcon->iso_data = conn;
conn->hcon = hcon;
@@ -291,8 +283,9 @@ static void iso_conn_del(struct hci_conn *hcon, int err)
return;
}
+ iso_sock_disable_timer(sk);
+
lock_sock(sk);
- iso_sock_clear_timer(sk);
iso_chan_del(sk, err);
release_sock(sk);
iso_sock_kill(sk);
@@ -799,6 +792,8 @@ static void iso_sock_cleanup_listen(struct sock *parent)
*/
static void iso_sock_kill(struct sock *sk)
{
+ iso_sock_disable_timer(sk);
+
lock_sock(sk);
if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket ||
@@ -894,8 +889,9 @@ static void __iso_sock_close(struct sock *sk)
/* Must be called on unlocked socket. */
static void iso_sock_close(struct sock *sk)
{
+ iso_sock_disable_timer(sk);
+
lock_sock(sk);
- iso_sock_clear_timer(sk);
__iso_sock_close(sk);
release_sock(sk);
}
@@ -964,6 +960,8 @@ static struct sock *iso_sock_alloc(struct net *net, struct socket *sock,
iso_pi(sk)->qos = default_qos;
iso_pi(sk)->sync_handle = -1;
+ INIT_DELAYED_WORK(&iso_pi(sk)->timeout_work, iso_sock_timeout);
+
bt_sock_link(&iso_sk_list, sk);
return sk;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 138/438] Bluetooth: ISO: ensure no dangling hcon references in iso_conn
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 137/438] Bluetooth: ISO: avoid deadlocks in iso_sock_timeout Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 139/438] Bluetooth: ISO: fix refcounting of iso_conn Greg Kroah-Hartman
` (313 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit aa9f7cb2bd3a2be998ceb739fc9a2f986eba43eb ]
After iso_conn_del(), ISO sockets should not dereference the hcon any
more. Currently, clearing iso_conn::hcon relies on iso_conn_del()
releasing the last reference to the iso_conn.
Simplify this by explicitly clearing conn->hcon in iso_conn_del(), to
avoid more complex reasoning on races about who holds the last
reference.
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: fdfde532ab1c ("Bluetooth: ISO: fix refcounting of iso_conn")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 24 +++++++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 7e1dcaa22a5b2..31ceb1338dc23 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -262,6 +262,7 @@ static void iso_chan_del(struct sock *sk, int err)
}
static void iso_conn_del(struct hci_conn *hcon, int err)
+ __must_hold(&hcon->hdev->lock)
{
struct iso_conn *conn = hcon->iso_data;
struct sock *sk;
@@ -276,11 +277,10 @@ static void iso_conn_del(struct hci_conn *hcon, int err)
iso_conn_lock(conn);
sk = iso_sock_hold(conn);
iso_conn_unlock(conn);
- iso_conn_put(conn);
if (!sk) {
iso_conn_put(conn);
- return;
+ goto done;
}
iso_sock_disable_timer(sk);
@@ -290,6 +290,15 @@ static void iso_conn_del(struct hci_conn *hcon, int err)
release_sock(sk);
iso_sock_kill(sk);
sock_put(sk);
+
+done:
+ /* No sk access to conn->hcon any more (lock_sock + hdev->lock) */
+ iso_conn_lock(conn);
+ conn->hcon = NULL;
+ hcon->iso_data = NULL;
+ iso_conn_unlock(conn);
+
+ iso_conn_put(conn);
}
static int __iso_chan_add(struct iso_conn *conn, struct sock *sk,
@@ -305,6 +314,11 @@ static int __iso_chan_add(struct iso_conn *conn, struct sock *sk,
return -EBUSY;
}
+ if (!conn->hcon) {
+ BT_ERR("conn->hcon missing");
+ return -EIO;
+ }
+
iso_pi(sk)->conn = conn;
conn->sk = sk;
clear_bit(ISO_CONN_DROPPED, conn->flags);
@@ -2499,6 +2513,7 @@ int iso_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 *flags)
}
static void iso_connect_cfm(struct hci_conn *hcon, __u8 status)
+ __must_hold(&hcon->hdev->lock)
{
if (hcon->type != CIS_LINK && hcon->type != BIS_LINK &&
hcon->type != PA_LINK) {
@@ -2510,8 +2525,10 @@ static void iso_connect_cfm(struct hci_conn *hcon, __u8 status)
struct hci_link *link, *t;
list_for_each_entry_safe(link, t, &hcon->link_list,
- list)
+ list) {
+ lockdep_assert_held(&link->conn->hdev->lock);
iso_conn_del(link->conn, bt_to_errno(status));
+ }
return;
}
@@ -2541,6 +2558,7 @@ static void iso_connect_cfm(struct hci_conn *hcon, __u8 status)
}
static void iso_disconn_cfm(struct hci_conn *hcon, __u8 reason)
+ __must_hold(&hcon->hdev->lock)
{
if (hcon->type != CIS_LINK && hcon->type != BIS_LINK &&
hcon->type != PA_LINK)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 139/438] Bluetooth: ISO: fix refcounting of iso_conn
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 138/438] Bluetooth: ISO: ensure no dangling hcon references in iso_conn Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 140/438] Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero Greg Kroah-Hartman
` (312 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit fdfde532ab1caa165fcd8985001157ac8b4db365 ]
iso_conn_del() and iso_chan_del() have a race that results to double-put
of iso_conn:
[Task hdev->workqueue] [Task 2]
iso_conn_del iso_chan_del
iso_conn_hold_unless_zero iso_conn_lock
iso_conn_lock conn->sk = NULL
iso_conn_unlock
sk = iso_sock_hold(conn) <---------´
if (!sk) iso_conn_put iso_conn_put
iso_conn_put /* UAF */
The extra put for !sk in iso_conn_del() is currently required since
failing iso_chan_add() may leave iso_conn not associated with any sk.
Fix by having iso_pi(sk)->conn own refcount when non-NULL, so
iso_conn_del does not need to put it. Adjust the iso_conn_add()
refcounting so that conn is put if it does not get associated with an
sk.
Fixes: dc26097bdb86 ("Bluetooth: ISO: Use kref to track lifetime of iso_conn")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 29 +++++++++++++++++------------
1 file changed, 17 insertions(+), 12 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 31ceb1338dc23..3b22193a9ec32 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -107,9 +107,6 @@ static void iso_conn_free(struct kref *ref)
BT_DBG("conn %p", conn);
- if (conn->sk)
- iso_pi(conn->sk)->conn = NULL;
-
if (conn->hcon) {
conn->hcon->iso_data = NULL;
if (!test_and_set_bit(ISO_CONN_DROPPED, conn->flags))
@@ -144,6 +141,14 @@ static struct iso_conn *iso_conn_hold_unless_zero(struct iso_conn *conn)
return conn;
}
+static struct iso_conn *iso_conn_hold(struct iso_conn *conn)
+{
+ BT_DBG("conn %p refcnt %u", conn, kref_read(&conn->ref));
+
+ kref_get(&conn->ref);
+ return conn;
+}
+
static struct sock *iso_sock_hold(struct iso_conn *conn)
{
if (!conn || !bt_sock_linked(&iso_sk_list, conn->sk))
@@ -209,7 +214,6 @@ static struct iso_conn *iso_conn_add(struct hci_conn *hcon)
conn->hcon = hcon;
iso_conn_unlock(conn);
}
- iso_conn_put(conn);
return conn;
}
@@ -278,10 +282,8 @@ static void iso_conn_del(struct hci_conn *hcon, int err)
sk = iso_sock_hold(conn);
iso_conn_unlock(conn);
- if (!sk) {
- iso_conn_put(conn);
+ if (!sk)
goto done;
- }
iso_sock_disable_timer(sk);
@@ -319,7 +321,7 @@ static int __iso_chan_add(struct iso_conn *conn, struct sock *sk,
return -EIO;
}
- iso_pi(sk)->conn = conn;
+ iso_pi(sk)->conn = iso_conn_hold(conn);
conn->sk = sk;
clear_bit(ISO_CONN_DROPPED, conn->flags);
@@ -426,6 +428,7 @@ static int iso_connect_bis(struct sock *sk)
}
err = iso_chan_add(conn, sk, NULL);
+ iso_conn_put(conn);
if (err)
goto unlock;
@@ -528,6 +531,7 @@ static int iso_connect_cis(struct sock *sk)
}
err = iso_chan_add(conn, sk, NULL);
+ iso_conn_put(conn);
if (err)
goto unlock;
@@ -1309,10 +1313,9 @@ static int iso_listen_bis(struct sock *sk)
}
err = iso_chan_add(conn, sk, NULL);
- if (err) {
- hci_conn_drop(hcon);
+ iso_conn_put(conn);
+ if (err)
goto unlock;
- }
unlock:
release_sock(sk);
@@ -2550,8 +2553,10 @@ static void iso_connect_cfm(struct hci_conn *hcon, __u8 status)
struct iso_conn *conn;
conn = iso_conn_add(hcon);
- if (conn)
+ if (conn) {
iso_conn_ready(conn);
+ iso_conn_put(conn);
+ }
} else {
iso_conn_del(hcon, bt_to_errno(status));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 140/438] Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 139/438] Bluetooth: ISO: fix refcounting of iso_conn Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 141/438] Bluetooth: btintel: Validate length before parsing diagnostics TLV Greg Kroah-Hartman
` (311 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit af24e338bf5dafb80f42baa9a0b9e9b57b1c5d9c ]
hci_conn::iso_data is accessed and modified without lock or RCU.
This leads to a race
[Task hdev->workqueue] [Task 2]
iso_recv iso_conn_put(conn)
conn = LOAD hcon->iso_data iso_conn_free(conn)
iso_conn_hold_unless_zero(conn) hcon->iso_data = NULL
kfree(conn)
kref_get_unless_zero(&conn->ref) /* UAF */
and also to races in iso_conn_add() vs. iso_conn_free().
Fix by adding spinlock hci_conn::proto_lock and using it to guard
hci_conn::iso_data.
Fixes: dc26097bdb86 ("Bluetooth: ISO: Use kref to track lifetime of iso_conn")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/bluetooth/hci_core.h | 4 +-
net/bluetooth/hci_conn.c | 2 +
net/bluetooth/iso.c | 64 ++++++++++++++++++++++++++------
3 files changed, 58 insertions(+), 12 deletions(-)
diff --git a/include/net/bluetooth/hci_core.h b/include/net/bluetooth/hci_core.h
index 02ba1cba6b236..2c15c9d8dbf74 100644
--- a/include/net/bluetooth/hci_core.h
+++ b/include/net/bluetooth/hci_core.h
@@ -770,9 +770,11 @@ struct hci_conn {
struct dentry *debugfs;
struct hci_dev *hdev;
+
+ spinlock_t proto_lock; /* lock guarding protocol data */
void *l2cap_data;
void *sco_data;
- void *iso_data;
+ void *iso_data __guarded_by(&proto_lock);
struct list_head link_list;
struct hci_conn *parent;
diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c
index eba4a548bef52..924c7795e368a 100644
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -1126,6 +1126,8 @@ static struct hci_conn *__hci_conn_add(struct hci_dev *hdev, int type,
INIT_DELAYED_WORK(&conn->idle_work, hci_conn_idle);
INIT_DELAYED_WORK(&conn->le_conn_timeout, le_conn_timeout);
+ spin_lock_init(&conn->proto_lock);
+
atomic_set(&conn->refcnt, 0);
hci_dev_hold(hdev);
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 3b22193a9ec32..f946ef5f37b37 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -108,9 +108,16 @@ static void iso_conn_free(struct kref *ref)
BT_DBG("conn %p", conn);
if (conn->hcon) {
- conn->hcon->iso_data = NULL;
- if (!test_and_set_bit(ISO_CONN_DROPPED, conn->flags))
- hci_conn_drop(conn->hcon);
+ spin_lock(&conn->hcon->proto_lock);
+
+ /* Check we are not racing with iso_conn_add */
+ if (conn->hcon->iso_data == conn) {
+ conn->hcon->iso_data = NULL;
+ if (!test_and_set_bit(ISO_CONN_DROPPED, conn->flags))
+ hci_conn_drop(conn->hcon);
+ }
+
+ spin_unlock(&conn->hcon->proto_lock);
}
kfree_skb(conn->rx_skb);
@@ -125,7 +132,21 @@ static void iso_conn_put(struct iso_conn *conn)
BT_DBG("conn %p refcnt %d", conn, kref_read(&conn->ref));
+ /* The following race vs. iso_conn_del() is possible:
+ *
+ * 1. conn->hcon != NULL here
+ * 2. kref_put puts the last reference
+ * 3. concurrent iso_conn_del() gets iso_conn_hold_unless_zero() -> NULL
+ * and returns immediately, so conn->hcon is not cleared
+ * 4. iso_conn_free() dereferences conn->hcon
+ *
+ * To avoid UAF in step 4, take RCU before decrementing the refcount.
+ */
+ rcu_read_lock();
+
kref_put(&conn->ref, iso_conn_free);
+
+ rcu_read_unlock();
}
static struct iso_conn *iso_conn_hold_unless_zero(struct iso_conn *conn)
@@ -204,22 +225,28 @@ static void iso_sock_disable_timer(struct sock *sk)
/* ---- ISO connections ---- */
static struct iso_conn *iso_conn_add(struct hci_conn *hcon)
+ __must_hold(&hcon->hdev->lock)
{
- struct iso_conn *conn = hcon->iso_data;
+ struct iso_conn *conn;
+
+ spin_lock(&hcon->proto_lock);
- conn = iso_conn_hold_unless_zero(conn);
+ conn = iso_conn_hold_unless_zero(hcon->iso_data);
if (conn) {
if (!conn->hcon) {
iso_conn_lock(conn);
conn->hcon = hcon;
iso_conn_unlock(conn);
}
+ spin_unlock(&hcon->proto_lock);
return conn;
}
- conn = kzalloc_obj(*conn);
- if (!conn)
+ conn = kzalloc_obj(*conn, GFP_ATOMIC);
+ if (!conn) {
+ spin_unlock(&hcon->proto_lock);
return NULL;
+ }
kref_init(&conn->ref);
spin_lock_init(&conn->lock);
@@ -228,6 +255,8 @@ static struct iso_conn *iso_conn_add(struct hci_conn *hcon)
conn->hcon = hcon;
conn->tx_sn = 0;
+ spin_unlock(&hcon->proto_lock);
+
BT_DBG("hcon %p conn %p", hcon, conn);
return conn;
@@ -268,10 +297,12 @@ static void iso_chan_del(struct sock *sk, int err)
static void iso_conn_del(struct hci_conn *hcon, int err)
__must_hold(&hcon->hdev->lock)
{
- struct iso_conn *conn = hcon->iso_data;
+ struct iso_conn *conn;
struct sock *sk;
- conn = iso_conn_hold_unless_zero(conn);
+ spin_lock(&hcon->proto_lock);
+ conn = iso_conn_hold_unless_zero(hcon->iso_data);
+ spin_unlock(&hcon->proto_lock);
if (!conn)
return;
@@ -295,10 +326,12 @@ static void iso_conn_del(struct hci_conn *hcon, int err)
done:
/* No sk access to conn->hcon any more (lock_sock + hdev->lock) */
+ spin_lock(&hcon->proto_lock);
iso_conn_lock(conn);
conn->hcon = NULL;
hcon->iso_data = NULL;
iso_conn_unlock(conn);
+ spin_unlock(&hcon->proto_lock);
iso_conn_put(conn);
}
@@ -420,6 +453,8 @@ static int iso_connect_bis(struct sock *sk)
iso_pi(sk)->bc_sid = hcon->sid;
}
+ lockdep_assert_held(&hcon->hdev->lock);
+
conn = iso_conn_add(hcon);
if (!conn) {
hci_conn_drop(hcon);
@@ -523,6 +558,8 @@ static int iso_connect_cis(struct sock *sk)
}
}
+ lockdep_assert_held(&hcon->hdev->lock);
+
conn = iso_conn_add(hcon);
if (!conn) {
hci_conn_drop(hcon);
@@ -854,8 +891,8 @@ static void iso_sock_disconn(struct sock *sk)
*/
if (bis_sk) {
hcon->state = BT_OPEN;
- hcon->iso_data = NULL;
- iso_pi(sk)->conn->hcon = NULL;
+ set_bit(ISO_CONN_DROPPED, iso_pi(sk)->conn->flags);
+
iso_sock_clear_timer(sk);
iso_chan_del(sk, bt_to_errno(hcon->abort_reason));
sock_put(bis_sk);
@@ -1305,6 +1342,8 @@ static int iso_listen_bis(struct sock *sk)
goto unlock;
}
+ lockdep_assert_held(&hcon->hdev->lock);
+
conn = iso_conn_add(hcon);
if (!conn) {
hci_conn_drop(hcon);
@@ -2590,7 +2629,10 @@ int iso_recv(struct hci_dev *hdev, u16 handle, struct sk_buff *skb, u16 flags)
return -ENOENT;
}
+ spin_lock(&hcon->proto_lock);
conn = iso_conn_hold_unless_zero(hcon->iso_data);
+ spin_unlock(&hcon->proto_lock);
+
hcon = NULL;
hci_dev_unlock(hdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 141/438] Bluetooth: btintel: Validate length before parsing diagnostics TLV
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 140/438] Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 142/438] Bluetooth: hci_conn: hold conn reference in abort_conn_sync() Greg Kroah-Hartman
` (310 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
[ Upstream commit b640ff9af3c809ff5ea2077fbba17df1594ec1e4 ]
btintel_diagnostics() accesses tlv->val[0] without first validating
that the diagnostics VSE is long enough to contain that field, so
may cause reading data beyond the received frame.
Fix by validating the length before access.
Fixes: af395330abed ("Bluetooth: btintel: Add Intel devcoredump support")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/bluetooth/btintel.c b/drivers/bluetooth/btintel.c
index 5e9cac090bd8f..bf567b7c5f00b 100644
--- a/drivers/bluetooth/btintel.c
+++ b/drivers/bluetooth/btintel.c
@@ -3771,6 +3771,9 @@ static int btintel_diagnostics(struct hci_dev *hdev, struct sk_buff *skb)
{
struct intel_tlv *tlv = (void *)&skb->data[5];
+ if (skb->len < 5 + sizeof(*tlv) + sizeof(tlv->val[0]))
+ goto recv_frame;
+
/* The first event is always an event type TLV */
if (tlv->type != INTEL_TLV_TYPE_ID)
goto recv_frame;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 142/438] Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 141/438] Bluetooth: btintel: Validate length before parsing diagnostics TLV Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 143/438] Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks Greg Kroah-Hartman
` (309 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 5761d003daa987ac81463f570713ce9c9dd204e5 ]
There is theoretical UAF if the conn is freed while the hci_sync task is
running.
Hold refcount to avoid that.
Fixes: 227a0cdf4a02 ("Bluetooth: MGMT: Fix not generating command complete for MGMT_OP_DISCONNECT")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_conn.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c
index 924c7795e368a..fb96d019cf856 100644
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -3168,6 +3168,13 @@ static int abort_conn_sync(struct hci_dev *hdev, void *data)
return hci_abort_conn_sync(hdev, conn, conn->abort_reason);
}
+static void abort_conn_destroy(struct hci_dev *hdev, void *data, int err)
+{
+ struct hci_conn *conn = data;
+
+ hci_conn_put(conn);
+}
+
int hci_abort_conn(struct hci_conn *conn, u8 reason)
{
struct hci_dev *hdev = conn->hdev;
@@ -3193,7 +3200,10 @@ int hci_abort_conn(struct hci_conn *conn, u8 reason)
* as a result to MGMT_OP_DISCONNECT/MGMT_OP_UNPAIR which does
* already queue its callback on cmd_sync_work.
*/
- err = hci_cmd_sync_run_once(hdev, abort_conn_sync, conn, NULL);
+ err = hci_cmd_sync_run_once(hdev, abort_conn_sync, hci_conn_get(conn),
+ abort_conn_destroy);
+ if (err)
+ hci_conn_put(conn);
return (err == -EEXIST) ? 0 : err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 143/438] Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 142/438] Bluetooth: hci_conn: hold conn reference in abort_conn_sync() Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 144/438] Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback Greg Kroah-Hartman
` (308 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 2f5d635ad5906b0235bc0c870e8beba3116e1e98 ]
There is theoretical UAF if the conn is freed while the hci_sync task
is running.
Hold refcount to avoid that.
Fixes: 881559af5f5c ("Bluetooth: hci_sync: Attempt to dequeue connection attempt")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 32 ++++++++++++++++++++++++--------
1 file changed, 24 insertions(+), 8 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 42bbffba2172e..2cac69922353a 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -7067,12 +7067,23 @@ static int hci_acl_create_conn_sync(struct hci_dev *hdev, void *data)
return err;
}
+static void hci_acl_create_conn_sync_complete(struct hci_dev *hdev, void *data,
+ int err)
+{
+ struct hci_conn *conn = data;
+
+ hci_conn_put(conn);
+}
+
int hci_connect_acl_sync(struct hci_dev *hdev, struct hci_conn *conn)
{
int err;
- err = hci_cmd_sync_queue_once(hdev, hci_acl_create_conn_sync, conn,
- NULL);
+ err = hci_cmd_sync_queue_once(hdev, hci_acl_create_conn_sync,
+ hci_conn_get(conn),
+ hci_acl_create_conn_sync_complete);
+ if (err)
+ hci_conn_put(conn);
return (err == -EEXIST) ? 0 : err;
}
@@ -7083,36 +7094,41 @@ static void create_le_conn_complete(struct hci_dev *hdev, void *data, int err)
bt_dev_dbg(hdev, "err %d", err);
if (err == -ECANCELED)
- return;
+ goto done;
hci_dev_lock(hdev);
if (!hci_conn_valid(hdev, conn))
- goto done;
+ goto unlock;
if (!err) {
hci_connect_le_scan_cleanup(conn, 0x00);
- goto done;
+ goto unlock;
}
/* Check if connection is still pending */
if (conn != hci_lookup_le_connect(hdev))
- goto done;
+ goto unlock;
/* Flush to make sure we send create conn cancel command if needed */
flush_delayed_work(&conn->le_conn_timeout);
hci_conn_failed(conn, bt_status(err));
-done:
+unlock:
hci_dev_unlock(hdev);
+done:
+ hci_conn_put(conn);
}
int hci_connect_le_sync(struct hci_dev *hdev, struct hci_conn *conn)
{
int err;
- err = hci_cmd_sync_queue_once(hdev, hci_le_create_conn_sync, conn,
+ err = hci_cmd_sync_queue_once(hdev, hci_le_create_conn_sync,
+ hci_conn_get(conn),
create_le_conn_complete);
+ if (err)
+ hci_conn_put(conn);
return (err == -EEXIST) ? 0 : err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 144/438] Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 143/438] Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 145/438] Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback Greg Kroah-Hartman
` (307 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 56e78b670356caab0b607e8aad4cf819a1909d07 ]
There is theoretical UAF if the conn is freed while the hci_sync task is
running.
Hold refcount to avoid that. Handle NULL hcon, return 0 + do nothing to
match the previous behavior.
Fixes: 024421cf3992 ("Bluetooth: hci_conn: Fix not setting timeout for BIG Create Sync")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 2cac69922353a..2860779e6a791 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -7437,10 +7437,12 @@ static void create_big_complete(struct hci_dev *hdev, void *data, int err)
bt_dev_dbg(hdev, "err %d", err);
if (err == -ECANCELED)
- return;
+ goto done;
- if (hci_conn_valid(hdev, conn))
- clear_bit(HCI_CONN_CREATE_BIG_SYNC, &conn->flags);
+ clear_bit(HCI_CONN_CREATE_BIG_SYNC, &conn->flags);
+
+done:
+ hci_conn_put(conn);
}
static int hci_le_big_create_sync(struct hci_dev *hdev, void *data)
@@ -7492,8 +7494,14 @@ int hci_connect_big_sync(struct hci_dev *hdev, struct hci_conn *conn)
{
int err;
- err = hci_cmd_sync_queue_once(hdev, hci_le_big_create_sync, conn,
+ if (!conn)
+ return 0;
+
+ err = hci_cmd_sync_queue_once(hdev, hci_le_big_create_sync,
+ hci_conn_get(conn),
create_big_complete);
+ if (err)
+ hci_conn_put(conn);
return (err == -EEXIST) ? 0 : err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 145/438] Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 144/438] Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 146/438] Bluetooth: hci_sync: hold conn in hci_past_sync() callback Greg Kroah-Hartman
` (306 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 44fc74069d8988f2825246f9401218e29de2c0ab ]
There is theoretical UAF if the conn is freed while the hci_sync task is
running.
Hold refcount to avoid that.
Fixes: 6d0417e4e1cf ("Bluetooth: hci_conn: Fix not setting conn_timeout for Broadcast Receiver")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 2860779e6a791..6c3dc910fdeba 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -7251,7 +7251,7 @@ static void create_pa_complete(struct hci_dev *hdev, void *data, int err)
bt_dev_dbg(hdev, "err %d", err);
if (err == -ECANCELED)
- return;
+ goto done;
hci_dev_lock(hdev);
@@ -7275,6 +7275,8 @@ static void create_pa_complete(struct hci_dev *hdev, void *data, int err)
unlock:
hci_dev_unlock(hdev);
+done:
+ hci_conn_put(conn);
}
static int hci_le_past_params_sync(struct hci_dev *hdev, struct hci_conn *conn,
@@ -7425,8 +7427,11 @@ int hci_connect_pa_sync(struct hci_dev *hdev, struct hci_conn *conn)
{
int err;
- err = hci_cmd_sync_queue_once(hdev, hci_le_pa_create_sync, conn,
+ err = hci_cmd_sync_queue_once(hdev, hci_le_pa_create_sync,
+ hci_conn_get(conn),
create_pa_complete);
+ if (err)
+ hci_conn_put(conn);
return (err == -EEXIST) ? 0 : err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 146/438] Bluetooth: hci_sync: hold conn in hci_past_sync() callback
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 145/438] Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 147/438] Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync Greg Kroah-Hartman
` (305 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit abf9753edf3f88282c44a605f3945d8d4f8dd86c ]
Avoids giving freed pointers to hci_conn_valid(), which kmalloc may have
reused.
Hold refcount to avoid that.
Fixes: d3413703d5f8 ("Bluetooth: ISO: Add support to bind to trigger PAST")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 6c3dc910fdeba..70ac18fe74448 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -7521,6 +7521,8 @@ static void past_complete(struct hci_dev *hdev, void *data, int err)
bt_dev_dbg(hdev, "err %d", err);
+ hci_conn_put(past->conn);
+ hci_conn_put(past->le);
kfree(past);
}
@@ -7585,8 +7587,8 @@ int hci_past_sync(struct hci_conn *conn, struct hci_conn *le)
if (!data)
return -ENOMEM;
- data->conn = conn;
- data->le = le;
+ data->conn = hci_conn_get(conn);
+ data->le = hci_conn_get(le);
if (conn->role == HCI_ROLE_MASTER)
err = hci_cmd_sync_queue_once(conn->hdev,
@@ -7596,8 +7598,11 @@ int hci_past_sync(struct hci_conn *conn, struct hci_conn *le)
err = hci_cmd_sync_queue_once(conn->hdev, hci_le_past_sync,
data, past_complete);
- if (err)
+ if (err) {
+ hci_conn_put(data->conn);
+ hci_conn_put(data->le);
kfree(data);
+ }
return (err == -EEXIST) ? 0 : err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 147/438] Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 146/438] Bluetooth: hci_sync: hold conn in hci_past_sync() callback Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 148/438] Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync Greg Kroah-Hartman
` (304 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 2c1e4e00613dfd105f978be2276e5e265801ec9f ]
hci_conn_del() caller must hold hdev->lock, check the conn was not
concurrently deleted, and usually inform socket the conn is going to be
deleted.
Use hci_abort_conn_sync() instead of calling hci_conn_del() without
locks etc.
Fixes: 8e8b92ee60de5 ("Bluetooth: hci_sync: Add hci_le_create_conn_sync")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 70ac18fe74448..0bb015da6f88c 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -6672,7 +6672,9 @@ static int hci_le_create_conn_sync(struct hci_dev *hdev, void *data)
if (hci_dev_test_flag(hdev, HCI_LE_SCAN) &&
hdev->le_scan_type == LE_SCAN_ACTIVE &&
!hci_dev_test_flag(hdev, HCI_LE_SIMULTANEOUS_ROLES)) {
- hci_conn_del(conn);
+ conn->state = BT_OPEN;
+ hci_abort_conn_sync(hdev, conn,
+ HCI_ERROR_REJ_LIMITED_RESOURCES);
hci_conn_put(conn);
return -EBUSY;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 148/438] Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 147/438] Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 149/438] x86/boot: Add volatile, clobbers and zero-length test in memcmp() Greg Kroah-Hartman
` (303 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit c0a9dcd2be398eee505d4b254ec3a845aa8ab189 ]
hci_conn_get() without already held reference is data race against
concurrent deletion.
In previous patches, the refcount has been changed to be taken before
starting the hci_sync task, so remove these extra get() + put() as they
are not needed.
Fixes: 12917f591cea ("Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 13 -------------
1 file changed, 13 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 0bb015da6f88c..540da127ecea6 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -6656,11 +6656,6 @@ static int hci_le_create_conn_sync(struct hci_dev *hdev, void *data)
bt_dev_dbg(hdev, "conn %p", conn);
- /* Hold a reference so conn stays valid for the HCI_CONN_CREATE
- * clear_bit() at done.
- */
- hci_conn_get(conn);
-
clear_bit(HCI_CONN_SCANNING, &conn->flags);
conn->state = BT_CONNECT;
@@ -6675,7 +6670,6 @@ static int hci_le_create_conn_sync(struct hci_dev *hdev, void *data)
conn->state = BT_OPEN;
hci_abort_conn_sync(hdev, conn,
HCI_ERROR_REJ_LIMITED_RESOURCES);
- hci_conn_put(conn);
return -EBUSY;
}
@@ -6773,7 +6767,6 @@ static int hci_le_create_conn_sync(struct hci_dev *hdev, void *data)
/* Re-enable advertising after the connection attempt is finished. */
hci_resume_advertising_sync(hdev);
- hci_conn_put(conn);
return err;
}
@@ -7048,11 +7041,6 @@ static int hci_acl_create_conn_sync(struct hci_dev *hdev, void *data)
else
cp.role_switch = 0x00;
- /* Hold a reference so conn stays valid for the HCI_CONN_CREATE
- * clear_bit() below.
- */
- hci_conn_get(conn);
-
/* Mark create connection in flight so hci_cancel_connect_sync() can
* cancel it while blocking on the connection complete event.
*/
@@ -7064,7 +7052,6 @@ static int hci_acl_create_conn_sync(struct hci_dev *hdev, void *data)
conn->conn_timeout, NULL);
clear_bit(HCI_CONN_CREATE, &conn->flags);
- hci_conn_put(conn);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 149/438] x86/boot: Add volatile, clobbers and zero-length test in memcmp()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 148/438] Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 150/438] net: phylink: put link_gpio if phylink_create fails Greg Kroah-Hartman
` (302 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Borislav Petkov,
Mauricio Faria de Oliveira, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mauricio Faria de Oliveira <mfo@igalia.com>
[ Upstream commit a8c171c107c0b61a5e7e10cedab0fb72aeaf640d ]
Add the volatile qualifier and clobbers parameter to prevent bugs with
instruction reordering and optimization.
Also add TEST for the zero-length case to set ZF, as, if the count register
is zero, the REPE prefix does not run the CMPSB instruction, leaving the ZF
flag undetermined.
[ bp: Add a comment about the len==0 case. ]
Fixes: 62bd0337d0c4 ("Top header file for new x86 setup code")
Closes: https://sashiko.dev/#/patchset/20260701-pvh-kasan-inline-v6-0-ba99045dfa9f%40igalia.com
Suggested-by: Borislav Petkov <bp@alien8.de>
Signed-off-by: Mauricio Faria de Oliveira <mfo@igalia.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://lore.kernel.org/all/20260721-pvh-kasan-inline-v7-2-38979a50cef0@igalia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/boot/string.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/arch/x86/boot/string.c b/arch/x86/boot/string.c
index b25c6a9303b73..3a2bba7c25e9d 100644
--- a/arch/x86/boot/string.c
+++ b/arch/x86/boot/string.c
@@ -32,8 +32,15 @@
int memcmp(const void *s1, const void *s2, size_t len)
{
bool diff;
- asm("repe cmpsb"
- : "=@ccnz" (diff), "+D" (s1), "+S" (s2), "+c" (len));
+
+ /*
+ * Make sure ZF is properly set in the len==0 case because in it,
+ * RCX==0 and the REPE; CMPSB won't get executed.
+ */
+ asm volatile("test %3, %3\n\t"
+ "repe cmpsb"
+ : "=@ccnz" (diff), "+D" (s1), "+S" (s2), "+c" (len)
+ : : "cc", "memory");
return diff;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 150/438] net: phylink: put link_gpio if phylink_create fails
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 149/438] x86/boot: Add volatile, clobbers and zero-length test in memcmp() Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 151/438] scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE Greg Kroah-Hartman
` (301 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Marangi, Andrew Lunn,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Marangi <ansuelsmth@gmail.com>
[ Upstream commit 0fe1e3e8f3380d7862296a73b528d164e96c76b8 ]
In phylink_create() if phylink_register_sfp() returns an error, link_gpio
obtained by phylink_parse_fixedlink() is never released. While this is a
very unlikely scenario, it's worth to fix/handle this.
This was present from the very first implementation of phylink but got
relevant only with the introduction of ce0aa27ff3f6 ("sfp: add sfp-bus to
bridge between network devices and sfp cages") where additional function
were added after phylink_parse_fixedlink() making the release of link_gpio
needed if such additional function errored out.
While at it, restructure the exit condition of phylink_create() with the
goto pattern to reduce code duplication on handling error conditions.
Fixes: ce0aa27ff3f6 ("sfp: add sfp-bus to bridge between network devices and sfp cages")
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260726150806.2437-1-ansuelsmth@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/phy/phylink.c | 29 +++++++++++++++--------------
1 file changed, 15 insertions(+), 14 deletions(-)
diff --git a/drivers/net/phy/phylink.c b/drivers/net/phy/phylink.c
index 087ac63f9193d..18d2ead97aa54 100644
--- a/drivers/net/phy/phylink.c
+++ b/drivers/net/phy/phylink.c
@@ -1875,8 +1875,8 @@ struct phylink *phylink_create(struct phylink_config *config,
} else if (config->type == PHYLINK_DEV) {
pl->dev = config->dev;
} else {
- kfree(pl);
- return ERR_PTR(-EINVAL);
+ ret = -EINVAL;
+ goto free_pl;
}
pl->mac_supports_eee_ops = phylink_mac_implements_lpi(mac_ops);
@@ -1909,28 +1909,29 @@ struct phylink *phylink_create(struct phylink_config *config,
phylink_validate(pl, pl->supported, &pl->link_config);
ret = phylink_parse_mode(pl, fwnode);
- if (ret < 0) {
- kfree(pl);
- return ERR_PTR(ret);
- }
+ if (ret < 0)
+ goto free_pl;
if (pl->cfg_link_an_mode == MLO_AN_FIXED) {
ret = phylink_parse_fixedlink(pl, fwnode);
- if (ret < 0) {
- kfree(pl);
- return ERR_PTR(ret);
- }
+ if (ret < 0)
+ goto release_link_gpio;
}
pl->req_link_an_mode = pl->cfg_link_an_mode;
ret = phylink_register_sfp(pl, fwnode);
- if (ret < 0) {
- kfree(pl);
- return ERR_PTR(ret);
- }
+ if (ret < 0)
+ goto release_link_gpio;
return pl;
+
+release_link_gpio:
+ if (pl->link_gpio)
+ gpiod_put(pl->link_gpio);
+free_pl:
+ kfree(pl);
+ return ERR_PTR(ret);
}
EXPORT_SYMBOL_GPL(phylink_create);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 151/438] scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 150/438] net: phylink: put link_gpio if phylink_create fails Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 152/438] scsi: ufs: core: Cancel RTC work in active-active suspend Greg Kroah-Hartman
` (300 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TanZheng, Mike Christie,
Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: TanZheng <tanzheng@kylinos.cn>
[ Upstream commit 9c33222bd387312874fbe36ca8002e5c945b9653 ]
In the iblock_execute_pr_out() function, PRO_PREEMPT,
PRO_PREEMPT_AND_ABORT, and PRO_RELEASE all perform callback capability
checks through ops->pr_clear. The error check allows unimplemented hooks
to pass through the gate, resulting dereferencing a NULL function
pointer.
Check whether the hooks that need to be called are supported.
Fixes: 394f81184882 ("scsi: target: Add block PR support to iblock")
Signed-off-by: TanZheng <tanzheng@kylinos.cn>
Reviewed-by: Mike Christie <michael.christie@oracle.com>
Link: https://patch.msgid.link/20260724075850.280699-1-kensanya@163.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/target/target_core_iblock.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/target/target_core_iblock.c b/drivers/target/target_core_iblock.c
index 1087d1d17c36d..ea65d39fef884 100644
--- a/drivers/target/target_core_iblock.c
+++ b/drivers/target/target_core_iblock.c
@@ -906,7 +906,7 @@ static sense_reason_t iblock_execute_pr_out(struct se_cmd *cmd, u8 sa, u64 key,
break;
case PRO_PREEMPT:
case PRO_PREEMPT_AND_ABORT:
- if (!ops->pr_clear) {
+ if (!ops->pr_preempt) {
pr_err("block_device does not support pr_preempt.\n");
return TCM_UNSUPPORTED_SCSI_OPCODE;
}
@@ -916,8 +916,8 @@ static sense_reason_t iblock_execute_pr_out(struct se_cmd *cmd, u8 sa, u64 key,
sa == PRO_PREEMPT_AND_ABORT);
break;
case PRO_RELEASE:
- if (!ops->pr_clear) {
- pr_err("block_device does not support pr_pclear.\n");
+ if (!ops->pr_release) {
+ pr_err("block_device does not support pr_release.\n");
return TCM_UNSUPPORTED_SCSI_OPCODE;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 152/438] scsi: ufs: core: Cancel RTC work in active-active suspend
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 151/438] scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 153/438] scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler" Greg Kroah-Hartman
` (299 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Peter Wang, Bean Huo,
Bart Van Assche, Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit f71b4a30983b846b4075bf544e835121e70e6a43 ]
UFS RTC support schedules ufs_rtc_update_work to periodically update the
device RTC. The work can issue query commands and access the UFS host
controller.
A previous change moved the RTC work cancellation before the PRE_CHANGE
vendor suspend callback to close a race in the common suspend path.
However, the active-active path jumps directly to vops_suspend after
flushing exception handling work and therefore bypasses the
cancellation.
If the RTC work runs while the vendor suspend callback is gating or
otherwise changing hardware state, it can access the controller during
suspend and trigger an SError.
Cancel the RTC work before entering the vendor suspend callback in the
active-active path. Since this path now cancels the work, move the RTC
work scheduling outside the device and link state restoration block in
the resume path. This restarts RTC updates after an active-active
suspend and resume cycle.
Fixes: b0bd84c39289 ("scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Reviewed-by: Bean Huo <beanhuo@micron.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260714172726.1736967-1-lgs201920130244@gmail.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ufs/core/ufshcd.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index 84e32957c332d..d6361e42ba553 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -10238,6 +10238,7 @@ static int __ufshcd_wl_suspend(struct ufs_hba *hba, enum ufs_pm_op pm_op)
req_link_state == UIC_LINK_ACTIVE_STATE) {
ufshcd_disable_auto_bkops(hba);
flush_work(&hba->eeh_work);
+ cancel_delayed_work_sync(&hba->ufs_rtc_update_work);
goto vops_suspend;
}
@@ -10447,10 +10448,11 @@ static int __ufshcd_wl_resume(struct ufs_hba *hba, enum ufs_pm_op pm_op)
if (ret)
goto set_old_link_state;
ufshcd_set_timestamp_attr(hba);
- schedule_delayed_work(&hba->ufs_rtc_update_work,
- msecs_to_jiffies(UFS_RTC_UPDATE_INTERVAL_MS));
}
+ schedule_delayed_work(&hba->ufs_rtc_update_work,
+ msecs_to_jiffies(UFS_RTC_UPDATE_INTERVAL_MS));
+
if (ufshcd_keep_autobkops_enabled_except_suspend(hba))
ufshcd_enable_auto_bkops(hba);
else
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 153/438] scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 152/438] scsi: ufs: core: Cancel RTC work in active-active suspend Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 154/438] scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req Greg Kroah-Hartman
` (298 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Neil Armstrong, 孙魁 ,
André Draszik, Gregory CLEMENT, Sebastian Andrzej Siewior,
Bart Van Assche, Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
[ Upstream commit 8a309036f557d3ff4efb2beea5132ba91172d934 ]
There have been multiple reports of performance regressions caused by
commit 3c7ac40d7322 ("scsi: ufs: core: Delegate the interrupt service
routine to a threaded IRQ handler"). Hence this revert.
This patch reverts most of the following commits:
* 3c7ac40d7322 ("scsi: ufs: core: Delegate the interrupt service
routine to a threaded IRQ handler")
* 6475cfb81fc4 ("scsi: ufs: core: Avoid IRQ thread wakeup during active
UIC command")
This patch preserves the following commits:
* 034d319c8899 ("scsi: ufs: core: Fix interrupt handling for MCQ Mode")
* eabcac808ca3 ("scsi: ufs: core: Fix IRQ lock inversion for the SCSI
host lock")
Cc: Neil Armstrong <neil.armstrong@linaro.org>
Cc: 孙魁 (Kui Sun) <kui.sun@unisoc.com>
Cc: André Draszik <andre.draszik@linaro.org>
Cc: Gregory CLEMENT <gregory.clement@bootlin.com>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Fixes: 3c7ac40d7322 ("scsi: ufs: core: Delegate the interrupt service routine to a threaded IRQ handler")
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Tested-by: André Draszik <andre.draszik@linaro.org> # on Pixel 6
Reviewed-by: André Draszik <andre.draszik@linaro.org>
Link: https://patch.msgid.link/b70eb60a01f971bed68c42c5b555929db5f835df.1784135511.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ufs/core/ufshcd.c | 39 +++------------------------------------
1 file changed, 3 insertions(+), 36 deletions(-)
diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index d6361e42ba553..082eac1e13463 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -7309,7 +7309,7 @@ static irqreturn_t ufshcd_sl_intr(struct ufs_hba *hba, u32 intr_status)
}
/**
- * ufshcd_threaded_intr - Threaded interrupt service routine
+ * ufshcd_intr - Main interrupt service routine
* @irq: irq number
* @__hba: pointer to adapter instance
*
@@ -7317,7 +7317,7 @@ static irqreturn_t ufshcd_sl_intr(struct ufs_hba *hba, u32 intr_status)
* IRQ_HANDLED - If interrupt is valid
* IRQ_NONE - If invalid interrupt
*/
-static irqreturn_t ufshcd_threaded_intr(int irq, void *__hba)
+static irqreturn_t ufshcd_intr(int irq, void *__hba)
{
u32 last_intr_status, intr_status, enabled_intr_status = 0;
irqreturn_t retval = IRQ_NONE;
@@ -7356,38 +7356,6 @@ static irqreturn_t ufshcd_threaded_intr(int irq, void *__hba)
return retval;
}
-/**
- * ufshcd_intr - Main interrupt service routine
- * @irq: irq number
- * @__hba: pointer to adapter instance
- *
- * Return:
- * IRQ_HANDLED - If interrupt is valid
- * IRQ_WAKE_THREAD - If handling is moved to threaded handled
- * IRQ_NONE - If invalid interrupt
- */
-static irqreturn_t ufshcd_intr(int irq, void *__hba)
-{
- struct ufs_hba *hba = __hba;
- u32 intr_status, enabled_intr_status;
-
- /*
- * Handle interrupt in thread if MCQ or ESI is disabled,
- * and no active UIC command.
- */
- if ((!hba->mcq_enabled || !hba->mcq_esi_enabled) &&
- !hba->active_uic_cmd)
- return IRQ_WAKE_THREAD;
-
- intr_status = ufshcd_readl(hba, REG_INTERRUPT_STATUS);
- enabled_intr_status = intr_status & ufshcd_readl(hba, REG_INTERRUPT_ENABLE);
-
- ufshcd_writel(hba, intr_status, REG_INTERRUPT_STATUS);
-
- /* Directly handle interrupts since MCQ ESI handlers does the hard job */
- return ufshcd_sl_intr(hba, enabled_intr_status);
-}
-
static int ufshcd_clear_tm_cmd(struct ufs_hba *hba, int tag)
{
int err = 0;
@@ -11204,8 +11172,7 @@ int ufshcd_init(struct ufs_hba *hba, void __iomem *mmio_base, unsigned int irq)
ufshcd_readl(hba, REG_INTERRUPT_ENABLE);
/* IRQ registration */
- err = devm_request_threaded_irq(dev, irq, ufshcd_intr, ufshcd_threaded_intr,
- IRQF_ONESHOT | IRQF_SHARED, UFSHCD, hba);
+ err = devm_request_irq(dev, irq, ufshcd_intr, IRQF_SHARED, UFSHCD, hba);
if (err) {
dev_err(hba->dev, "request irq failed\n");
goto out_disable;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 154/438] scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 153/438] scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler" Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 155/438] scsi: target: Clear cmd_cnt when initial counter enrollment fails Greg Kroah-Hartman
` (297 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Block, M Nikhil,
Chinmaya Kajagar, Nihar Panda, Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benjamin Block <bblock@linux.ibm.com>
[ Upstream commit b601fa590e667bd9643feed8c869b6b3e418480d ]
When releasing an adapter we don't free the mempool 'gid_pn_req' that is
allocated during the enqueue. This leaks memory:
unreferenced object 0xd8d29297de700 (size 256):
comm "(udev-worker)", pid 2105, jiffies 4294945794
hex dump (first 32 bytes):
00 00 00 00 de ad 4e ad ff ff ff ff 00 00 00 00 ......N.........
ff ff ff ff ff ff ff ff 00 0d c4 5f 67 9d 99 e0 ..........._g...
backtrace (crc 4a5b5da2):
[<000dc45f64da418c>] kmemleak_alloc+0x6c/0xa0
[<000dc45f62b430aa>] __kmalloc_cache_node_noprof+0x36a/0x4d0
[<000dc45f629a535a>] mempool_create_node_noprof+0xaa/0x150
[<000dc45ee2c065e6>] zfcp_allocate_low_mem_buffers+0x96/0x370 [zfcp]
[<000dc45ee2c070f8>] zfcp_adapter_enqueue+0x598/0xd40 [zfcp]
[<000dc45ee2c08eb0>] zfcp_ccw_set_online+0x160/0x210 [zfcp]
[<000dc45f643d4762>] ccw_device_set_online+0x232/0xd80
[<000dc45f643d53d4>] online_store_recog_and_online+0x124/0x390
[<000dc45f643d8238>] online_store+0x298/0x5b0
[<000dc45f62eb0a04>] kernfs_fop_write_iter+0x2c4/0x480
[<000dc45f62c81150>] new_sync_write+0x370/0x4b0
[<000dc45f62c87abe>] vfs_write+0x43e/0x5b0
[<000dc45f62c87ff4>] ksys_write+0x114/0x1f0
[<000dc45f621c4a16>] do_syscall+0x2f6/0x430
[<000dc45f64d9d5d8>] __do_syscall+0xc8/0x1c0
[<000dc45f64dc2224>] system_call+0x74/0xa0
Fix this by destroying the mempool during the adapter's release.
Fixes: 799b76d09aee ("[SCSI] zfcp: Decouple gid_pn requests from erp")
Signed-off-by: Benjamin Block <bblock@linux.ibm.com>
Tested-by: M Nikhil <nikh1092@linux.ibm.com>
Acked-by: M Nikhil <nikh1092@linux.ibm.com>
Reviewed-by: Chinmaya Kajagar <chinmayk@linux.ibm.com>
Reviewed-by: Nihar Panda <niharp@linux.ibm.com>
Link: https://patch.msgid.link/20260720072736.3381816-2-niharp@linux.ibm.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/scsi/zfcp_aux.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/s390/scsi/zfcp_aux.c b/drivers/s390/scsi/zfcp_aux.c
index 8ff7db7921b5a..fea573e00f9df 100644
--- a/drivers/s390/scsi/zfcp_aux.c
+++ b/drivers/s390/scsi/zfcp_aux.c
@@ -253,6 +253,7 @@ static int zfcp_allocate_low_mem_buffers(struct zfcp_adapter *adapter)
static void zfcp_free_low_mem_buffers(struct zfcp_adapter *adapter)
{
mempool_destroy(adapter->pool.erp_req);
+ mempool_destroy(adapter->pool.gid_pn_req);
mempool_destroy(adapter->pool.scsi_req);
mempool_destroy(adapter->pool.scsi_abort);
mempool_destroy(adapter->pool.qtcb_pool);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 155/438] scsi: target: Clear cmd_cnt when initial counter enrollment fails
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 154/438] scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 156/438] octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle Greg Kroah-Hartman
` (296 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Mike Christie,
Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit a8ddfd2425bbbafadae8700d63ed8a61a4109878 ]
When target_get_sess_cmd() fails during session shutdown because
percpu_ref_tryget_live() returns false, the command keeps the
se_cmd->cmd_cnt pointer that __target_init_cmd() assigned earlier
without owning a reference. Final release through
target_release_cmd_kref() then issues an unmatched percpu_ref_put().
Commit 8e288be8606a ("scsi: target: Pass in cmd counter to use during
cmd setup") moved the cmd_cnt assignment ahead of the reference
acquisition. Clear se_cmd->cmd_cnt whenever the initial
target_get_sess_cmd() fails in target_init_cmd() and
target_submit_tmr(), so release performs exactly one matching put per
acquired reference.
Fixes: 8e288be8606a ("scsi: target: Pass in cmd counter to use during cmd setup")
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Reviewed-by: Mike Christie <michael.christie@oracle.com>
Link: https://patch.msgid.link/20260722-reference-count-underflow-in-target-v1-1-63ab664f12fd@nvidia.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/target/target_core_transport.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c
index fad03a15c969e..dcfe945949167 100644
--- a/drivers/target/target_core_transport.c
+++ b/drivers/target/target_core_transport.c
@@ -1734,6 +1734,7 @@ int target_init_cmd(struct se_cmd *se_cmd, struct se_session *se_sess,
u32 data_length, int task_attr, int data_dir, int flags)
{
struct se_portal_group *se_tpg;
+ int ret;
se_tpg = se_sess->se_tpg;
BUG_ON(!se_tpg);
@@ -1763,7 +1764,11 @@ int target_init_cmd(struct se_cmd *se_cmd, struct se_session *se_sess,
* necessary for fabrics using TARGET_SCF_ACK_KREF that expect a second
* kref_put() to happen during fabric packet acknowledgement.
*/
- return target_get_sess_cmd(se_cmd, flags & TARGET_SCF_ACK_KREF);
+ ret = target_get_sess_cmd(se_cmd, flags & TARGET_SCF_ACK_KREF);
+ if (ret)
+ se_cmd->cmd_cnt = NULL;
+
+ return ret;
}
EXPORT_SYMBOL_GPL(target_init_cmd);
@@ -2039,8 +2044,10 @@ int target_submit_tmr(struct se_cmd *se_cmd, struct se_session *se_sess,
* allocation failure.
*/
ret = core_tmr_alloc_req(se_cmd, fabric_tmr_ptr, tm_type, gfp);
- if (ret < 0)
+ if (ret < 0) {
+ se_cmd->cmd_cnt = NULL;
return -ENOMEM;
+ }
if (tm_type == TMR_ABORT_TASK)
se_cmd->se_tmr_req->ref_task_tag = tag;
@@ -2048,6 +2055,7 @@ int target_submit_tmr(struct se_cmd *se_cmd, struct se_session *se_sess,
/* See target_submit_cmd for commentary */
ret = target_get_sess_cmd(se_cmd, flags & TARGET_SCF_ACK_KREF);
if (ret) {
+ se_cmd->cmd_cnt = NULL;
core_tmr_release_req(se_cmd->se_tmr_req);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 156/438] octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 155/438] scsi: target: Clear cmd_cnt when initial counter enrollment fails Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 157/438] octeontx2-af: Block VFs from clobbering special CGX PKIND state Greg Kroah-Hartman
` (295 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ratheesh Kannoth, Jakub Kicinski,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ratheesh Kannoth <rkannoth@marvell.com>
[ Upstream commit aac055dbc0fadf64c9d6fbcfc066b8ba33216dc4 ]
Add NIX_LF_DONT_FREE_DFT_IDXS so the PF can send NIX LF free during hw
reinit or teardown without the AF freeing CN20K default NPC rule indexes
while the driver still owns that state (otx2_init_hw_resources and
otx2_free_hw_resources).
On CN20K, allocate default NPC rules from NIX LF alloc before
nix_interface_init, roll back with npc_cn20k_dft_rules_free on failure,
and free from NIX LF free when the new flag is not set. Tighten
rvu_mbox_handler_nix_lf_alloc error handling: use a single rc, propagate
qmem_alloc and other errors, and set -ENOMEM only when kcalloc fails
(remove the blanket -ENOMEM at the free_mem path).
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Link: https://patch.msgid.link/20260609040453.711932-7-rkannoth@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 3bd438a58e91 ("octeontx2-af: Block VFs from clobbering special CGX PKIND state")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/marvell/octeontx2/af/mbox.h | 1 +
.../ethernet/marvell/octeontx2/af/rvu_nix.c | 77 +++++++++++++------
.../ethernet/marvell/octeontx2/af/rvu_npc.c | 20 +++--
.../ethernet/marvell/octeontx2/nic/otx2_pf.c | 6 +-
4 files changed, 69 insertions(+), 35 deletions(-)
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/mbox.h b/drivers/net/ethernet/marvell/octeontx2/af/mbox.h
index 44fdd6ba7307c..714e47f68d932 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/mbox.h
+++ b/drivers/net/ethernet/marvell/octeontx2/af/mbox.h
@@ -1008,6 +1008,7 @@ struct nix_lf_free_req {
struct mbox_msghdr hdr;
#define NIX_LF_DISABLE_FLOWS BIT_ULL(0)
#define NIX_LF_DONT_FREE_TX_VTAG BIT_ULL(1)
+#define NIX_LF_DONT_FREE_DFT_IDXS BIT_ULL(2)
u64 flags;
};
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c
index 219fc44ab68d4..6a0ce2665031d 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c
@@ -16,6 +16,7 @@
#include "cgx.h"
#include "lmac_common.h"
#include "rvu_npc_hash.h"
+#include "cn20k/npc.h"
static void nix_free_tx_vtag_entries(struct rvu *rvu, u16 pcifunc);
static int rvu_nix_get_bpid(struct rvu *rvu, struct nix_bp_cfg_req *req,
@@ -1504,9 +1505,11 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
struct nix_lf_alloc_req *req,
struct nix_lf_alloc_rsp *rsp)
{
- int nixlf, qints, hwctx_size, intf, err, rc = 0;
+ int nixlf, qints, hwctx_size, intf, rc = 0;
+ u16 bcast, mcast, promisc, ucast;
struct rvu_hwinfo *hw = rvu->hw;
u16 pcifunc = req->hdr.pcifunc;
+ bool rules_created = false;
struct rvu_block *block;
struct rvu_pfvf *pfvf;
u64 cfg, ctx_cfg;
@@ -1560,8 +1563,8 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
return NIX_AF_ERR_RSS_GRPS_INVALID;
/* Reset this NIX LF */
- err = rvu_lf_reset(rvu, block, nixlf);
- if (err) {
+ rc = rvu_lf_reset(rvu, block, nixlf);
+ if (rc) {
dev_err(rvu->dev, "Failed to reset NIX%d LF%d\n",
block->addr - BLKADDR_NIX0, nixlf);
return NIX_AF_ERR_LF_RESET;
@@ -1571,13 +1574,15 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
/* Alloc NIX RQ HW context memory and config the base */
hwctx_size = 1UL << ((ctx_cfg >> 4) & 0xF);
- err = qmem_alloc(rvu->dev, &pfvf->rq_ctx, req->rq_cnt, hwctx_size);
- if (err)
+ rc = qmem_alloc(rvu->dev, &pfvf->rq_ctx, req->rq_cnt, hwctx_size);
+ if (rc)
goto free_mem;
pfvf->rq_bmap = kcalloc(req->rq_cnt, sizeof(long), GFP_KERNEL);
- if (!pfvf->rq_bmap)
+ if (!pfvf->rq_bmap) {
+ rc = -ENOMEM;
goto free_mem;
+ }
rvu_write64(rvu, blkaddr, NIX_AF_LFX_RQS_BASE(nixlf),
(u64)pfvf->rq_ctx->iova);
@@ -1588,13 +1593,15 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
/* Alloc NIX SQ HW context memory and config the base */
hwctx_size = 1UL << (ctx_cfg & 0xF);
- err = qmem_alloc(rvu->dev, &pfvf->sq_ctx, req->sq_cnt, hwctx_size);
- if (err)
+ rc = qmem_alloc(rvu->dev, &pfvf->sq_ctx, req->sq_cnt, hwctx_size);
+ if (rc)
goto free_mem;
pfvf->sq_bmap = kcalloc(req->sq_cnt, sizeof(long), GFP_KERNEL);
- if (!pfvf->sq_bmap)
+ if (!pfvf->sq_bmap) {
+ rc = -ENOMEM;
goto free_mem;
+ }
rvu_write64(rvu, blkaddr, NIX_AF_LFX_SQS_BASE(nixlf),
(u64)pfvf->sq_ctx->iova);
@@ -1604,13 +1611,15 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
/* Alloc NIX CQ HW context memory and config the base */
hwctx_size = 1UL << ((ctx_cfg >> 8) & 0xF);
- err = qmem_alloc(rvu->dev, &pfvf->cq_ctx, req->cq_cnt, hwctx_size);
- if (err)
+ rc = qmem_alloc(rvu->dev, &pfvf->cq_ctx, req->cq_cnt, hwctx_size);
+ if (rc)
goto free_mem;
pfvf->cq_bmap = kcalloc(req->cq_cnt, sizeof(long), GFP_KERNEL);
- if (!pfvf->cq_bmap)
+ if (!pfvf->cq_bmap) {
+ rc = -ENOMEM;
goto free_mem;
+ }
rvu_write64(rvu, blkaddr, NIX_AF_LFX_CQS_BASE(nixlf),
(u64)pfvf->cq_ctx->iova);
@@ -1620,18 +1629,18 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
/* Initialize receive side scaling (RSS) */
hwctx_size = 1UL << ((ctx_cfg >> 12) & 0xF);
- err = nixlf_rss_ctx_init(rvu, blkaddr, pfvf, nixlf, req->rss_sz,
- req->rss_grps, hwctx_size, req->way_mask,
- !!(req->flags & NIX_LF_RSS_TAG_LSB_AS_ADDER));
- if (err)
+ rc = nixlf_rss_ctx_init(rvu, blkaddr, pfvf, nixlf, req->rss_sz,
+ req->rss_grps, hwctx_size, req->way_mask,
+ !!(req->flags & NIX_LF_RSS_TAG_LSB_AS_ADDER));
+ if (rc)
goto free_mem;
/* Alloc memory for CQINT's HW contexts */
cfg = rvu_read64(rvu, blkaddr, NIX_AF_CONST2);
qints = (cfg >> 24) & 0xFFF;
hwctx_size = 1UL << ((ctx_cfg >> 24) & 0xF);
- err = qmem_alloc(rvu->dev, &pfvf->cq_ints_ctx, qints, hwctx_size);
- if (err)
+ rc = qmem_alloc(rvu->dev, &pfvf->cq_ints_ctx, qints, hwctx_size);
+ if (rc)
goto free_mem;
rvu_write64(rvu, blkaddr, NIX_AF_LFX_CINTS_BASE(nixlf),
@@ -1644,8 +1653,8 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
cfg = rvu_read64(rvu, blkaddr, NIX_AF_CONST2);
qints = (cfg >> 12) & 0xFFF;
hwctx_size = 1UL << ((ctx_cfg >> 20) & 0xF);
- err = qmem_alloc(rvu->dev, &pfvf->nix_qints_ctx, qints, hwctx_size);
- if (err)
+ rc = qmem_alloc(rvu->dev, &pfvf->nix_qints_ctx, qints, hwctx_size);
+ if (rc)
goto free_mem;
rvu_write64(rvu, blkaddr, NIX_AF_LFX_QINTS_BASE(nixlf),
@@ -1689,10 +1698,22 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
if (is_sdp_pfvf(rvu, pcifunc))
intf = NIX_INTF_TYPE_SDP;
- err = nix_interface_init(rvu, pcifunc, intf, nixlf, rsp,
- !!(req->flags & NIX_LF_LBK_BLK_SEL));
- if (err)
- goto free_mem;
+ if (is_cn20k(rvu->pdev)) {
+ rc = npc_cn20k_dft_rules_idx_get(rvu, pcifunc, &bcast, &mcast,
+ &promisc, &ucast);
+ if (rc) {
+ rc = npc_cn20k_dft_rules_alloc(rvu, pcifunc);
+ if (rc)
+ goto free_mem;
+
+ rules_created = true;
+ }
+ }
+
+ rc = nix_interface_init(rvu, pcifunc, intf, nixlf, rsp,
+ !!(req->flags & NIX_LF_LBK_BLK_SEL));
+ if (rc)
+ goto free_dft;
/* Disable NPC entries as NIXLF's contexts are not initialized yet */
rvu_npc_disable_default_entries(rvu, pcifunc, nixlf);
@@ -1704,9 +1725,12 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
goto exit;
+free_dft:
+ if (is_cn20k(rvu->pdev) && rules_created)
+ npc_cn20k_dft_rules_free(rvu, pcifunc);
+
free_mem:
nix_ctx_free(rvu, pfvf);
- rc = -ENOMEM;
exit:
/* Set macaddr of this PF/VF */
@@ -1780,6 +1804,9 @@ int rvu_mbox_handler_nix_lf_free(struct rvu *rvu, struct nix_lf_free_req *req,
nix_ctx_free(rvu, pfvf);
+ if (is_cn20k(rvu->pdev) && !(req->flags & NIX_LF_DONT_FREE_DFT_IDXS))
+ npc_cn20k_dft_rules_free(rvu, pcifunc);
+
return 0;
}
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
index 4994385a822b7..41d92eb652af9 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
@@ -1285,11 +1285,18 @@ void npc_enadis_default_mce_entry(struct rvu *rvu, u16 pcifunc,
struct nix_mce_list *mce_list;
int index, blkaddr, mce_idx;
struct rvu_pfvf *pfvf;
+ u16 ptr[4];
/* multicast pkt replication is not enabled for AF's VFs & SDP links */
if (is_lbk_vf(rvu, pcifunc) || is_sdp_pfvf(rvu, pcifunc))
return;
+ /* In cn20k, only CGX mapped devices have default MCAST entry */
+ if (is_cn20k(rvu->pdev) &&
+ npc_cn20k_dft_rules_idx_get(rvu, pcifunc, &ptr[0], &ptr[1],
+ &ptr[2], &ptr[3]))
+ return;
+
blkaddr = rvu_get_blkaddr(rvu, BLKTYPE_NPC, 0);
if (blkaddr < 0)
return;
@@ -1329,9 +1336,12 @@ static void npc_enadis_default_entries(struct rvu *rvu, u16 pcifunc,
struct rvu_pfvf *pfvf = rvu_get_pfvf(rvu, pcifunc);
struct npc_mcam *mcam = &rvu->hw->mcam;
int index, blkaddr;
+ u16 ptr[4];
/* only CGX or LBK interfaces have default entries */
- if (is_cn20k(rvu->pdev) && !npc_is_cgx_or_lbk(rvu, pcifunc))
+ if (is_cn20k(rvu->pdev) &&
+ npc_cn20k_dft_rules_idx_get(rvu, pcifunc, &ptr[0], &ptr[1],
+ &ptr[2], &ptr[3]))
return;
blkaddr = rvu_get_blkaddr(rvu, BLKTYPE_NPC, 0);
@@ -4075,12 +4085,10 @@ void rvu_npc_clear_ucast_entry(struct rvu *rvu, int pcifunc, int nixlf)
ucast_idx = npc_get_nixlf_mcam_index(mcam, pcifunc,
nixlf, NIXLF_UCAST_ENTRY);
- if (ucast_idx < 0) {
- dev_err(rvu->dev,
- "%s: Error to get ucast entry for pcifunc=%#x\n",
- __func__, pcifunc);
+
+ /* In cn20k, default rules are freed before detach rsrc */
+ if (ucast_idx < 0)
return;
- }
npc_enable_mcam_entry(rvu, mcam, blkaddr, ucast_idx, false);
diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
index 617a0db97e804..2e33b33ec9934 100644
--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
+++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
@@ -1053,7 +1053,6 @@ irqreturn_t otx2_pfaf_mbox_intr_handler(int irq, void *pf_irq)
/* Clear the IRQ */
otx2_write64(pf, RVU_PF_INT, BIT_ULL(0));
-
mbox_data = otx2_read64(pf, RVU_PF_PFAF_MBOX0);
if (mbox_data & MBOX_UP_MSG) {
@@ -1727,7 +1726,7 @@ int otx2_init_hw_resources(struct otx2_nic *pf)
mutex_lock(&mbox->lock);
free_req = otx2_mbox_alloc_msg_nix_lf_free(mbox);
if (free_req) {
- free_req->flags = NIX_LF_DISABLE_FLOWS;
+ free_req->flags = NIX_LF_DISABLE_FLOWS | NIX_LF_DONT_FREE_DFT_IDXS;
if (otx2_sync_mbox_msg(mbox))
dev_err(pf->dev, "%s failed to free nixlf\n", __func__);
}
@@ -1801,7 +1800,7 @@ void otx2_free_hw_resources(struct otx2_nic *pf)
/* Reset NIX LF */
free_req = otx2_mbox_alloc_msg_nix_lf_free(mbox);
if (free_req) {
- free_req->flags = NIX_LF_DISABLE_FLOWS;
+ free_req->flags = NIX_LF_DISABLE_FLOWS | NIX_LF_DONT_FREE_DFT_IDXS;
if (!(pf->flags & OTX2_FLAG_PF_SHUTDOWN))
free_req->flags |= NIX_LF_DONT_FREE_TX_VTAG;
if (otx2_sync_mbox_msg(mbox))
@@ -1924,7 +1923,6 @@ int otx2_alloc_queue_mem(struct otx2_nic *pf)
struct otx2_qset *qset = &pf->qset;
struct otx2_cq_poll *cq_poll;
-
/* RQ and SQs are mapped to different CQs,
* so find out max CQ IRQs (i.e CINTs) needed.
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 157/438] octeontx2-af: Block VFs from clobbering special CGX PKIND state
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 156/438] octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 158/438] scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit Greg Kroah-Hartman
` (294 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geetha sowjanya, Hariprasad Kelam,
Ratheesh Kannoth, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hariprasad Kelam <hkelam@marvell.com>
[ Upstream commit 3bd438a58e910db5dc369aa25dfed1fc95f1b596 ]
PF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND
programming. When HiGig2 or EDSA parsing is enabled, a VF NIX LF alloc must
not reset the LMAC RX PKIND or default TX parse config over the PF setup.
Add cgx_get_pkind() and rvu_cgx_is_pkind_config_permitted() so VFs skip
cgx_set_pkind(), rvu_npc_set_pkind(), and NIX_AF_LFX_TX_PARSE_CFG updates
when the LMAC is using NPC_RX_HIGIG_PKIND or NPC_RX_EDSA_PKIND.
Fixes: 94d942c5fb97 ("octeontx2-af: Config pkind for CGX mapped PFs")
Cc: Geetha sowjanya <gakula@marvell.com>
Signed-off-by: Hariprasad Kelam <hkelam@marvell.com>
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Link: https://patch.msgid.link/20260722081229.1653619-1-rkannoth@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/marvell/octeontx2/af/cgx.c | 12 +++
.../net/ethernet/marvell/octeontx2/af/cgx.h | 1 +
.../net/ethernet/marvell/octeontx2/af/rvu.h | 2 +
.../ethernet/marvell/octeontx2/af/rvu_cgx.c | 79 +++++++++++++++++++
.../ethernet/marvell/octeontx2/af/rvu_nix.c | 22 +++++-
.../ethernet/marvell/octeontx2/af/rvu_npc.c | 29 ++++---
6 files changed, 131 insertions(+), 14 deletions(-)
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/cgx.c b/drivers/net/ethernet/marvell/octeontx2/af/cgx.c
index 2e94d5105016b..f5fd6138c352f 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/cgx.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/cgx.c
@@ -518,6 +518,18 @@ int cgx_set_pkind(void *cgxd, u8 lmac_id, int pkind)
return 0;
}
+int cgx_get_pkind(void *cgxd, u8 lmac_id, int *pkind)
+{
+ struct cgx *cgx = cgxd;
+
+ if (!is_lmac_valid(cgx, lmac_id))
+ return -ENODEV;
+
+ *pkind = cgx_read(cgx, lmac_id, cgx->mac_ops->rxid_map_offset);
+ *pkind = *pkind & 0x3F;
+ return 0;
+}
+
static u8 cgx_get_lmac_type(void *cgxd, int lmac_id)
{
struct cgx *cgx = cgxd;
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/cgx.h b/drivers/net/ethernet/marvell/octeontx2/af/cgx.h
index 92ccf343dfe04..8411a75dd723f 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/cgx.h
+++ b/drivers/net/ethernet/marvell/octeontx2/af/cgx.h
@@ -141,6 +141,7 @@ int cgx_get_cgxid(void *cgxd);
int cgx_get_lmac_cnt(void *cgxd);
void *cgx_get_pdata(int cgx_id);
int cgx_set_pkind(void *cgxd, u8 lmac_id, int pkind);
+int cgx_get_pkind(void *cgxd, u8 lmac_id, int *pkind);
int cgx_lmac_evh_register(struct cgx_event_cb *cb, void *cgxd, int lmac_id);
int cgx_lmac_evh_unregister(void *cgxd, int lmac_id);
int cgx_get_tx_stats(void *cgxd, int lmac_id, int idx, u64 *tx_stat);
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu.h b/drivers/net/ethernet/marvell/octeontx2/af/rvu.h
index 65397daae4c2f..635a7630238e6 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu.h
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu.h
@@ -1113,6 +1113,8 @@ void npc_read_mcam_entry(struct rvu *rvu, struct npc_mcam *mcam,
u8 *intf, u8 *ena);
int npc_config_cntr_default_entries(struct rvu *rvu, bool enable);
bool is_cgx_config_permitted(struct rvu *rvu, u16 pcifunc);
+bool rvu_cgx_check_permission_and_set_pkind(struct rvu *rvu, u16 pcifunc, int pkind);
+bool rvu_cgx_is_pkind_config_permitted(struct rvu *rvu, u16 pcifunc);
bool is_mac_feature_supported(struct rvu *rvu, int pf, int feature);
u32 rvu_cgx_get_fifolen(struct rvu *rvu);
void *rvu_first_cgx_pdata(struct rvu *rvu);
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_cgx.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_cgx.c
index 4ff3935ed3fe8..87d21889dc49e 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_cgx.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_cgx.c
@@ -1355,3 +1355,82 @@ void rvu_mac_reset(struct rvu *rvu, u16 pcifunc)
if (mac_ops->mac_reset(cgxd, lmac, !is_vf(pcifunc)))
dev_err(rvu->dev, "Failed to reset MAC\n");
}
+
+/* Do not allow CGX-mapped VFs to overwrite PKIND when special parse kinds
+ * (HiGig, EDSA, etc.) are in use on the shared LMAC. VFs must not program
+ * NPC_TX_DEF_PKIND on NIX_AF_LFX_TX_PARSE_CFG in that case: the PF owns
+ * parse mode and no separate NPC_TX_HIGIG_PKIND is installed on the VF LF.
+ * TX-parse callers skip the write when denied; rvu_lf_reset() clears each LF
+ * before alloc so the next permitted owner programs NPC_TX_DEF_PKIND.
+ */
+bool rvu_cgx_is_pkind_config_permitted(struct rvu *rvu, u16 pcifunc)
+{
+ int pf, err, rxpkind;
+ u8 cgx_id, lmac_id;
+ void *cgxd;
+
+ pf = rvu_get_pf(rvu->pdev, pcifunc);
+
+ if (!(pcifunc & RVU_PFVF_FUNC_MASK))
+ return true;
+
+ if (!is_pf_cgxmapped(rvu, pf))
+ return true;
+
+ rvu_get_cgx_lmac_id(rvu->pf2cgxlmac_map[pf], &cgx_id, &lmac_id);
+ cgxd = rvu_cgx_pdata(cgx_id, rvu);
+ err = cgx_get_pkind(cgxd, lmac_id, &rxpkind);
+ if (err)
+ return false;
+
+ switch (rxpkind) {
+ case NPC_RX_HIGIG_PKIND:
+ case NPC_RX_EDSA_PKIND:
+ return false;
+ default:
+ return true;
+ }
+}
+
+/* Do not allow CGX-mapped VFs to overwrite PKIND when special parse kinds
+ * (HiGig, EDSA, etc.) are in use on the shared LMAC.
+ */
+bool rvu_cgx_check_permission_and_set_pkind(struct rvu *rvu, u16 pcifunc, int pkind)
+{
+ int pf, err, rxpkind;
+ u8 cgx_id, lmac_id;
+ struct cgx *cgxd;
+
+ pf = rvu_get_pf(rvu->pdev, pcifunc);
+
+ if (!is_pf_cgxmapped(rvu, pf))
+ return false;
+
+ rvu_get_cgx_lmac_id(rvu->pf2cgxlmac_map[pf], &cgx_id, &lmac_id);
+ cgxd = rvu_cgx_pdata(cgx_id, rvu);
+
+ mutex_lock(&cgxd->lock);
+ if (!is_vf(pcifunc))
+ goto set;
+
+ err = cgx_get_pkind(cgxd, lmac_id, &rxpkind);
+ if (err)
+ goto err;
+
+ switch (rxpkind) {
+ case NPC_RX_HIGIG_PKIND:
+ case NPC_RX_EDSA_PKIND:
+ goto err;
+ default:
+ break;
+ }
+
+set:
+ cgx_set_pkind(rvu_cgx_pdata(cgx_id, rvu), lmac_id, pkind);
+ mutex_unlock(&cgxd->lock);
+ return true;
+
+err:
+ mutex_unlock(&cgxd->lock);
+ return false;
+}
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c
index 6a0ce2665031d..964bcaae098e2 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c
@@ -363,8 +363,8 @@ static int nix_interface_init(struct rvu *rvu, u16 pcifunc, int type, int nixlf,
pfvf->tx_chan_cnt = 1;
rsp->tx_link = cgx_id * hw->lmac_per_cgx + lmac_id;
- cgx_set_pkind(rvu_cgx_pdata(cgx_id, rvu), lmac_id, pkind);
- rvu_npc_set_pkind(rvu, pkind, pfvf);
+ if (rvu_cgx_check_permission_and_set_pkind(rvu, pcifunc, pkind))
+ rvu_npc_set_pkind(rvu, pkind, pfvf);
break;
case NIX_INTF_TYPE_LBK:
vf = (pcifunc & RVU_PFVF_FUNC_MASK) - 1;
@@ -1505,13 +1505,15 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
struct nix_lf_alloc_req *req,
struct nix_lf_alloc_rsp *rsp)
{
- int nixlf, qints, hwctx_size, intf, rc = 0;
+ int nixlf, qints, hwctx_size, intf, rc = 0, pf;
u16 bcast, mcast, promisc, ucast;
struct rvu_hwinfo *hw = rvu->hw;
u16 pcifunc = req->hdr.pcifunc;
+ u8 cgx_id = 0, lmac_id = 0;
bool rules_created = false;
struct rvu_block *block;
struct rvu_pfvf *pfvf;
+ struct cgx *cgxd;
u64 cfg, ctx_cfg;
int blkaddr;
@@ -1685,8 +1687,20 @@ int rvu_mbox_handler_nix_lf_alloc(struct rvu *rvu,
rvu_write64(rvu, blkaddr, NIX_AF_LFX_RX_CFG(nixlf), req->rx_cfg);
/* Configure pkind for TX parse config */
+
+ pf = rvu_get_pf(rvu->pdev, pcifunc);
cfg = NPC_TX_DEF_PKIND;
- rvu_write64(rvu, blkaddr, NIX_AF_LFX_TX_PARSE_CFG(nixlf), cfg);
+
+ if (is_pf_cgxmapped(rvu, pf) && is_vf(pcifunc)) {
+ rvu_get_cgx_lmac_id(rvu->pf2cgxlmac_map[pf], &cgx_id, &lmac_id);
+ cgxd = rvu_cgx_pdata(cgx_id, rvu);
+ mutex_lock(&cgxd->lock);
+ if (rvu_cgx_is_pkind_config_permitted(rvu, pcifunc))
+ rvu_write64(rvu, blkaddr, NIX_AF_LFX_TX_PARSE_CFG(nixlf), cfg);
+ mutex_unlock(&cgxd->lock);
+ } else {
+ rvu_write64(rvu, blkaddr, NIX_AF_LFX_TX_PARSE_CFG(nixlf), cfg);
+ }
if (is_rep_dev(rvu, pcifunc)) {
pfvf->tx_chan_base = RVU_SWITCH_LBK_CHAN;
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
index 41d92eb652af9..1e090508f958d 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
@@ -19,6 +19,7 @@
#include "cn20k/npc.h"
#include "rvu_npc.h"
#include "cn20k/reg.h"
+#include "lmac_common.h"
#define RSVD_MCAM_ENTRIES_PER_PF 3 /* Broadcast, Promisc and AllMulticast */
#define RSVD_MCAM_ENTRIES_PER_NIXLF 1 /* Ucast for LFs */
@@ -3912,10 +3913,11 @@ int rvu_npc_set_parse_mode(struct rvu *rvu, u16 pcifunc, u64 mode, u8 dir,
{
struct rvu_pfvf *pfvf = rvu_get_pfvf(rvu, pcifunc);
- int blkaddr, nixlf, rc, intf_mode;
int pf = rvu_get_pf(rvu->pdev, pcifunc);
+ int blkaddr, nixlf, rc, intf_mode;
+ u8 cgx_id = 0, lmac_id = 0;
u64 rxpkind, txpkind;
- u8 cgx_id, lmac_id;
+ struct cgx *cgxd;
/* use default pkind to disable edsa/higig */
rxpkind = rvu_npc_get_pkind(rvu, pf);
@@ -3939,12 +3941,8 @@ int rvu_npc_set_parse_mode(struct rvu *rvu, u16 pcifunc, u64 mode, u8 dir,
/* rx pkind set req valid only for cgx mapped PFs */
if (!is_cgx_config_permitted(rvu, pcifunc))
return 0;
- rvu_get_cgx_lmac_id(rvu->pf2cgxlmac_map[pf], &cgx_id, &lmac_id);
-
- rc = cgx_set_pkind(rvu_cgx_pdata(cgx_id, rvu), lmac_id,
- rxpkind);
- if (rc)
- return rc;
+ if (!rvu_cgx_check_permission_and_set_pkind(rvu, pcifunc, rxpkind))
+ return -EINVAL;
}
if (dir & PKIND_TX) {
@@ -3953,8 +3951,19 @@ int rvu_npc_set_parse_mode(struct rvu *rvu, u16 pcifunc, u64 mode, u8 dir,
if (rc)
return rc;
- rvu_write64(rvu, blkaddr, NIX_AF_LFX_TX_PARSE_CFG(nixlf),
- txpkind);
+ if (is_pf_cgxmapped(rvu, pf) && is_vf(pcifunc)) {
+ rvu_get_cgx_lmac_id(rvu->pf2cgxlmac_map[pf], &cgx_id,
+ &lmac_id);
+ cgxd = rvu_cgx_pdata(cgx_id, rvu);
+ mutex_lock(&cgxd->lock);
+ if (rvu_cgx_is_pkind_config_permitted(rvu, pcifunc))
+ rvu_write64(rvu, blkaddr, NIX_AF_LFX_TX_PARSE_CFG(nixlf),
+ txpkind);
+ mutex_unlock(&cgxd->lock);
+ } else {
+ rvu_write64(rvu, blkaddr, NIX_AF_LFX_TX_PARSE_CFG(nixlf),
+ txpkind);
+ }
}
pfvf->intf_mode = intf_mode;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 158/438] scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 157/438] octeontx2-af: Block VFs from clobbering special CGX PKIND state Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 159/438] scsi: ufs: core: Initialize hba->rpmbs list in ufshcd Greg Kroah-Hartman
` (293 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Chandrakanth Patil,
Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chandrakanth Patil <chandrakanth.patil@broadcom.com>
[ Upstream commit ccff8c92571500fcfed21281e33daaf645bf692f ]
mpi3mr_fault_uevent_emit() runs from the fault watchdog and reset paths
where host I/O may already be blocked. GFP_KERNEL allocations here, both
the local kzalloc_obj() and the ones inside kobject_uevent_env() itself,
can trigger reclaim that waits on that blocked I/O and deadlock.
Use memalloc_noio_save()/restore() to cover the whole call instead of
just the local allocation.
Fixes: ec54b348f274 ("scsi: mpi3mr: Record and report controller firmware faults")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260724164630.924288-1-chandrakanth.patil%40broadcom.com
Signed-off-by: Chandrakanth Patil <chandrakanth.patil@broadcom.com>
Link: https://patch.msgid.link/20260724175231.935192-1-chandrakanth.patil@broadcom.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/mpi3mr/mpi3mr_fw.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/mpi3mr/mpi3mr_fw.c b/drivers/scsi/mpi3mr/mpi3mr_fw.c
index 31b19ed1528e5..681868716ebdb 100644
--- a/drivers/scsi/mpi3mr/mpi3mr_fw.c
+++ b/drivers/scsi/mpi3mr/mpi3mr_fw.c
@@ -9,6 +9,7 @@
#include "mpi3mr.h"
#include <linux/io-64-nonatomic-lo-hi.h>
+#include <linux/sched/mm.h>
static int
mpi3mr_issue_reset(struct mpi3mr_ioc *mrioc, u16 reset_type, u16 reset_reason);
@@ -1287,11 +1288,14 @@ static void mpi3mr_alloc_ioctl_dma_memory(struct mpi3mr_ioc *mrioc)
static void mpi3mr_fault_uevent_emit(struct mpi3mr_ioc *mrioc)
{
struct kobj_uevent_env *env;
+ unsigned int noio_flag;
int ret;
+ noio_flag = memalloc_noio_save();
+
env = kzalloc_obj(*env);
if (!env)
- return;
+ goto out_restore;
ret = add_uevent_var(env, "DRIVER=%s", mrioc->driver_name);
if (ret)
@@ -1326,7 +1330,8 @@ static void mpi3mr_fault_uevent_emit(struct mpi3mr_ioc *mrioc)
out_free:
kfree(env);
-
+out_restore:
+ memalloc_noio_restore(noio_flag);
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 159/438] scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 158/438] scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 160/438] net: sxgbe: free TX rings on RX allocation failure Greg Kroah-Hartman
` (292 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiazi Li, Ao Sun, Bean Huo,
Martin K. Petersen, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ao Sun <ao.sun@transsion.com>
[ Upstream commit 0279fd451a9971c0d5b959fc59f3e11b55e1694e ]
Initialize the hba->rpmbs list in ufshcd_alloc_host() to prevent NULL
pointer dereference in the device teardown path if ufs_rpmb_probe()
fails.
Fixes: b06b8c421485 ("scsi: ufs: core: Add OP-TEE based RPMB driver for UFS devices")
Co-developed-by: Jiazi Li <jiazi.li@transsion.com>
Signed-off-by: Jiazi Li <jiazi.li@transsion.com>
Signed-off-by: Ao Sun <ao.sun@transsion.com>
Reviewed-by: Bean Huo <beanhuo@micron.com>
Link: https://patch.msgid.link/20260723034440.217-1-ao.sun@transsion.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ufs/core/ufs-rpmb.c | 2 --
drivers/ufs/core/ufshcd.c | 1 +
2 files changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/ufs/core/ufs-rpmb.c b/drivers/ufs/core/ufs-rpmb.c
index ffad049872b9a..62120dc2e9da7 100644
--- a/drivers/ufs/core/ufs-rpmb.c
+++ b/drivers/ufs/core/ufs-rpmb.c
@@ -152,8 +152,6 @@ int ufs_rpmb_probe(struct ufs_hba *hba)
return -EINVAL;
}
- INIT_LIST_HEAD(&hba->rpmbs);
-
struct rpmb_descr descr = {
.type = RPMB_TYPE_UFS,
.route_frames = ufs_rpmb_route_frames,
diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index 082eac1e13463..d6444b3c2ef16 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -10924,6 +10924,7 @@ int ufshcd_alloc_host(struct device *dev, struct ufs_hba **hba_handle)
hba->nop_out_timeout = NOP_OUT_TIMEOUT;
ufshcd_set_sg_entry_size(hba, sizeof(struct ufshcd_sg_entry));
INIT_LIST_HEAD(&hba->clk_list_head);
+ INIT_LIST_HEAD(&hba->rpmbs);
spin_lock_init(&hba->outstanding_lock);
*hba_handle = hba;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 160/438] net: sxgbe: free TX rings on RX allocation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 159/438] scsi: ufs: core: Initialize hba->rpmbs list in ufshcd Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 161/438] net: sxgbe: check descriptor ring allocation failures Greg Kroah-Hartman
` (291 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chenguang Zhao, Vadim Fedorenko,
David S. Miller, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chenguang Zhao <zhaochenguang@kylinos.cn>
[ Upstream commit c870f7e2890b9f78ac84515a9809cc5c183c975e ]
When RX descriptor ring allocation fails, init_dma_desc_rings() only
frees the partially allocated RX rings and returns. The TX rings that
were allocated earlier in the same function are leaked.
Rearrange error labels to clean up TX rings upon RX failures.
Fixes: 1edb9ca69e8a ("net: sxgbe: add basic framework for Samsung 10Gb ethernet driver")
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
index 5051ada43d2fa..9b48a587d5c2e 100644
--- a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
+++ b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
@@ -597,14 +597,13 @@ static int init_dma_desc_rings(struct net_device *netd)
return 0;
-txalloc_err:
- while (queue_num--)
- free_tx_ring(priv->device, priv->txq[queue_num], tx_rsize);
- return ret;
-
rxalloc_err:
while (queue_num--)
free_rx_ring(priv->device, priv->rxq[queue_num], rx_rsize);
+ queue_num = SXGBE_TX_QUEUES;
+txalloc_err:
+ while (queue_num--)
+ free_tx_ring(priv->device, priv->txq[queue_num], tx_rsize);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 161/438] net: sxgbe: check descriptor ring allocation failures
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 160/438] net: sxgbe: free TX rings on RX allocation failure Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 162/438] can: isotp: check register_netdevice_notifier() error in module init Greg Kroah-Hartman
` (290 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chenguang Zhao, Vadim Fedorenko,
David S. Miller, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chenguang Zhao <zhaochenguang@kylinos.cn>
[ Upstream commit 51b093a7ba27476e1f639455f005e8d2e75390e4 ]
sxgbe_open() ignores the return value of init_dma_desc_rings() and
continues to program DMA with invalid ring addresses when allocation
fails. Check the return value and disconnect the PHY on failure.
Fixes: 1edb9ca69e8a ("net: sxgbe: add basic framework for Samsung 10Gb ethernet driver")
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
index 9b48a587d5c2e..70cf3619555f9 100644
--- a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
+++ b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
@@ -1078,7 +1078,9 @@ static int sxgbe_open(struct net_device *dev)
priv->dma_buf_sz = SXGBE_ALIGN(DMA_BUFFER_SIZE);
priv->tx_tc = TC_DEFAULT;
priv->rx_tc = TC_DEFAULT;
- init_dma_desc_rings(dev);
+ ret = init_dma_desc_rings(dev);
+ if (ret)
+ goto init_phy_error;
/* DMA initialization and SW reset */
ret = sxgbe_init_dma_engine(priv);
@@ -1187,6 +1189,7 @@ static int sxgbe_open(struct net_device *dev)
init_error:
free_dma_desc_resources(priv);
+init_phy_error:
if (dev->phydev)
phy_disconnect(dev->phydev);
phy_error:
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 162/438] can: isotp: check register_netdevice_notifier() error in module init
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 161/438] net: sxgbe: check descriptor ring allocation failures Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 163/438] drm/i915/dp: Ignore the sinks DSC max FRL rate without a PCON DSC encoder Greg Kroah-Hartman
` (289 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Minhong He, Marc Kleine-Budde,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Minhong He <heminhong@kylinos.cn>
[ Upstream commit ef09a13c5afac41a3c4b5f22b8572820d9e7518c ]
Register the netdevice notifier before can_proto_register() and check the
return value. If protocol registration fails, unregister the notifier
before returning the error.
Align isotp_module_init() with the reordering already done for raw.c
(commit c28b3bffe49e ("can: raw: process optimization in raw_init()")) and
bcm.c (commit edd1a7e42f1d ("can: bcm: registration process optimization
in bcm_module_init()")).
Fixes: 8d0caedb7596 ("can: bcm/raw/isotp: use per module netdevice notifier")
Signed-off-by: Minhong He <heminhong@kylinos.cn>
Link: https://patch.msgid.link/20260729085656.134523-1-heminhong@kylinos.cn
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/can/isotp.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/can/isotp.c b/net/can/isotp.c
index 54becaf6898f1..ae6260e98a7a6 100644
--- a/net/can/isotp.c
+++ b/net/can/isotp.c
@@ -1907,13 +1907,18 @@ static __init int isotp_module_init(void)
pr_info("can: isotp protocol (max_pdu_size %d)\n", max_pdu_size);
+ err = register_netdevice_notifier(&canisotp_notifier);
+ if (err)
+ return err;
+
err = can_proto_register(&isotp_can_proto);
- if (err < 0)
+ if (err < 0) {
pr_err("can: registration of isotp protocol failed %pe\n", ERR_PTR(err));
- else
- register_netdevice_notifier(&canisotp_notifier);
+ unregister_netdevice_notifier(&canisotp_notifier);
+ return err;
+ }
- return err;
+ return 0;
}
static __exit void isotp_module_exit(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 163/438] drm/i915/dp: Ignore the sinks DSC max FRL rate without a PCON DSC encoder
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 162/438] can: isotp: check register_netdevice_notifier() error in module init Greg Kroah-Hartman
@ 2026-08-07 14:35 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 164/438] drm/xe/pt: check no-DMA huge-pte cases before DMA segment test Greg Kroah-Hartman
` (288 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:35 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ankit Nautiyal,
Ville Syrjälä, Alexander Kaplan, Rodrigo Vivi,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Kaplan <alexander.kaplan@sms-medipool.de>
[ Upstream commit 8891e39e89042e285fd82fdde325d1311ec750a1 ]
intel_dp_hdmi_sink_max_frl() limits the sink's max FRL rate by its
DSC max FRL rate whenever the sink supports DSC 1.2.
However, the DSC max FRL rate (HF-VSDB DSC_Max_FRL_Rate) only applies
to compressed video transport, which requires a DSC 1.2 encoder in
the PCON (configured via intel_dp_pcon_dsc_configure()).
Without such an encoder the HDMI link always carries uncompressed
video, for which the regular Max_FRL_Rate is the correct limit.
Applying the DSC limit unconditionally trains the FRL link at a lower
rate than both the PCON and the sink support.
E.g. an LG OLED G4 (Max_FRL_Rate 48 Gbps, DSC_Max_FRL_Rate 24 Gbps)
behind a Synaptics VMM7100 PCON (PCON max FRL bw 48 Gbps, no DSC
encoder):
Sink max rate from EDID = 24 Gbps
FRL trained with : 24 Gbps
while Windows/macOS train the same hardware at 40/48 Gbps.
The too low FRL rate needlessly constrains the formats available to
the sink.
Only apply the sink's DSC max FRL rate if the PCON has a DSC 1.2
encoder, matching the gate in intel_dp_pcon_dsc_configure().
PCONs with a DSC encoder keep the current conservative behavior,
since the link is trained once and compressed transport may be used
for any subsequent mode.
With this the setup above trains at 48 Gbps.
Tested on PTL (xe) with the above PCON/sink combo.
Fixes: 10fec80b48c5 ("drm/i915/display: Configure PCON for DSC1.1 to DSC1.2 encoding")
Cc: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Cc: Ville Syrjälä <ville.syrjala@linux.intel.com>
Reviewed-by: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Signed-off-by: Alexander Kaplan <alexander.kaplan@sms-medipool.de>
Signed-off-by: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Link: https://patch.msgid.link/20260718105207.5565-3-alexander.kaplan@sms-medipool.de
(cherry picked from commit 71b57dd92f94569dca4bdf883fbd8ca5d4ed4bae)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/i915/display/intel_dp.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/i915/display/intel_dp.c b/drivers/gpu/drm/i915/display/intel_dp.c
index f34da1a055dd5..c12a8ee846d74 100644
--- a/drivers/gpu/drm/i915/display/intel_dp.c
+++ b/drivers/gpu/drm/i915/display/intel_dp.c
@@ -4109,7 +4109,14 @@ static int intel_dp_hdmi_sink_max_frl(struct intel_dp *intel_dp)
rate_per_lane = info->hdmi.max_frl_rate_per_lane;
max_frl_rate = max_lanes * rate_per_lane;
- if (info->hdmi.dsc_cap.v_1p2) {
+ /*
+ * The sink's DSC max FRL rate only applies to compressed video
+ * transport, which requires a DSC 1.2 encoder in the PCON. Without
+ * one the HDMI link always carries uncompressed video, for which
+ * the regular max FRL rate is the limit.
+ */
+ if (drm_dp_pcon_enc_is_dsc_1_2(intel_dp->pcon_dsc_dpcd) &&
+ info->hdmi.dsc_cap.v_1p2) {
max_dsc_lanes = info->hdmi.dsc_cap.max_lanes;
dsc_rate_per_lane = info->hdmi.dsc_cap.max_frl_rate_per_lane;
if (max_dsc_lanes && dsc_rate_per_lane)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 164/438] drm/xe/pt: check no-DMA huge-pte cases before DMA segment test
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-08-07 14:35 ` [PATCH 7.1 163/438] drm/i915/dp: Ignore the sinks DSC max FRL rate without a PCON DSC encoder Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 165/438] fprobe: Fix module reference count leak on error in register_fprobe() Greg Kroah-Hartman
` (287 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Brost, Sashiko,
Himal Prasad Ghimiray, Rodrigo Vivi, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
[ Upstream commit d94f82d57e7a86def6946f22b34eb53f96628f8a ]
On a non-range clear, curs.size is never set, so the segment test
(next - va_curs_start > curs->size) returns false for every level > 0
before the clear_pt short-circuit is reached. The clear then descends to
level 0 instead of forming a huge zero-leaf, wasting page tables and
risking -ENOMEM on unbind.
Move the null-VMA, purged-BO and clear_pt short-circuits above the
curs->size test. The bind path always sets curs.size, so it is unaffected.
v2
- Also set curs.size on the clear path so the cursor stays meaningful
during the walk. clear_pt is only reached with range == NULL, so assert
that invariant. (Matthew Brost)
Cc: Matthew Brost <matthew.brost@intel.com>
Fixes: 5b658b7e89c3 ("drm/xe: Clear scratch page on vm_bind")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260728055916.593707-2-himal.prasad.ghimiray@intel.com
Signed-off-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
(cherry picked from commit 04eeeb45cb61b8a3e9d785003457e550c920ba49)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_pt.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_pt.c b/drivers/gpu/drm/xe/xe_pt.c
index cf371c0d7b2bb..a4d0d9bf0c8eb 100644
--- a/drivers/gpu/drm/xe/xe_pt.c
+++ b/drivers/gpu/drm/xe/xe_pt.c
@@ -442,10 +442,6 @@ static bool xe_pt_hugepte_possible(u64 addr, u64 next, unsigned int level,
if (!xe_pt_covers(addr, next, level, &xe_walk->base))
return false;
- /* Does the DMA segment cover the whole pte? */
- if (next - xe_walk->va_curs_start > xe_walk->curs->size)
- return false;
-
/* null VMA's and purged BO's do not have dma addresses */
if (xe_vma_is_null(xe_walk->vma) || (bo && xe_bo_is_purged(bo)))
return true;
@@ -454,6 +450,10 @@ static bool xe_pt_hugepte_possible(u64 addr, u64 next, unsigned int level,
if (xe_walk->clear_pt)
return true;
+ /* Does the DMA segment cover the whole pte? */
+ if (next - xe_walk->va_curs_start > xe_walk->curs->size)
+ return false;
+
/* Is the DMA address huge PTE size aligned? */
size = next - addr;
dma = addr - xe_walk->va_curs_start + xe_res_dma(xe_walk->curs);
@@ -774,8 +774,11 @@ xe_pt_stage_bind(struct xe_tile *tile, struct xe_vma *vma,
}
xe_walk.needs_64K = (vm->flags & XE_VM_FLAG_64K);
- if (clear_pt)
+ if (clear_pt) {
+ xe_assert(xe, !range);
+ curs.size = xe_vma_size(vma);
goto walk_pt;
+ }
if (vma->gpuva.flags & XE_VMA_ATOMIC_PTE_BIT) {
xe_walk.default_vram_pte = xe_atomic_for_vram(vm, vma) ? XE_USM_PPGTT_PTE_AE : 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 165/438] fprobe: Fix module reference count leak on error in register_fprobe()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 164/438] drm/xe/pt: check no-DMA huge-pte cases before DMA segment test Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 166/438] tracing/mmiotrace: Reset dropped_count in mmio_reset_data() Greg Kroah-Hartman
` (286 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
[ Upstream commit 8cf2f40ceb85047ad8a84dffae3bebc9fed18216 ]
In register_fprobe(), get_ips_from_filter() resolves target function
addresses and increments module reference counts via try_module_get() for
symbols in kernel modules. If get_ips_from_filter() fails on the second
pass and returns an error, register_fprobe() returned directly without
releasing module references acquired up to that point.
Fix this by ensuring the cleanup loop executing module_put() runs even when
get_ips_from_filter() returns a negative error.
Link: https://lore.kernel.org/all/178528125360.101985.4144133640239273153.stgit@devnote2/
Fixes: d24fa977eec5 ("tracing: fprobe: Fix to lock module while registering fprobe")
Assisted-by: Antigravity:gemini-3.6-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/fprobe.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/kernel/trace/fprobe.c b/kernel/trace/fprobe.c
index f215990b90613..f681015413b83 100644
--- a/kernel/trace/fprobe.c
+++ b/kernel/trace/fprobe.c
@@ -961,10 +961,8 @@ int register_fprobe(struct fprobe *fp, const char *filter, const char *notfilter
return -ENOMEM;
ret = get_ips_from_filter(filter, notfilter, addrs, mods, num);
- if (ret < 0)
- return ret;
-
- ret = register_fprobe_ips(fp, addrs, ret);
+ if (ret >= 0)
+ ret = register_fprobe_ips(fp, addrs, ret);
for (int i = 0; i < num; i++) {
if (mods[i])
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 166/438] tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 165/438] fprobe: Fix module reference count leak on error in register_fprobe() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 167/438] tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions Greg Kroah-Hartman
` (285 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Steven Rostedt, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
[ Upstream commit c786d2bdf1f3964deee192ad942dee2a741c1e2c ]
mmio_reset_data() is called during tracer initialization, reset, and
start. While it resets overrun_detected and prev_overruns, it neglects
to reset dropped_count. Consequently, dropped event counts from prior
tracing sessions persist in dropped_count and corrupt overrun reports
in subsequent runs.
Fix this by explicitly calling atomic_set(&dropped_count, 0) in
mmio_reset_data().
Link: https://patch.msgid.link/178524299122.56416.16277704230639425172.stgit@devnote2
Fixes: 173ed24ee2d6 ("mmiotrace: count events lost due to not recording")
Assisted-by: Antigravity:gemini-3.6-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/trace_mmiotrace.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/trace/trace_mmiotrace.c b/kernel/trace/trace_mmiotrace.c
index b88b8d9923adb..e064ba3f28cb9 100644
--- a/kernel/trace/trace_mmiotrace.c
+++ b/kernel/trace/trace_mmiotrace.c
@@ -29,6 +29,7 @@ static void mmio_reset_data(struct trace_array *tr)
{
overrun_detected = false;
prev_overruns = 0;
+ atomic_set(&dropped_count, 0);
tracing_reset_online_cpus(&tr->array_buffer);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 167/438] tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 166/438] tracing/mmiotrace: Reset dropped_count in mmio_reset_data() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 168/438] riscv: drop __init from vec_check_unaligned_access_speed_all_cpus Greg Kroah-Hartman
` (284 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Steven Rostedt, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
[ Upstream commit 12b80cdbc54cf615b4717a4e8180063408091ea2 ]
mmio_trace_rw() and mmio_trace_mapping() retrieve mmio_trace_array into
tr and pass it to __trace_mmiotrace_rw() and __trace_mmiotrace_map().
If these functions are invoked while mmio_trace_array is NULL (e.g. before
initialization or after disabled), accessing tr->array_buffer.buffer will
result in a NULL pointer dereference crash.
Fix this by adding an explicit NULL check for tr at the beginning of
__trace_mmiotrace_rw() and __trace_mmiotrace_map().
Link: https://patch.msgid.link/178524300062.56416.8362487250709962380.stgit@devnote2
Fixes: f984b51e0779 ("ftrace: add mmiotrace plugin")
Assisted-by: Antigravity:gemini-3.6-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/trace_mmiotrace.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/kernel/trace/trace_mmiotrace.c b/kernel/trace/trace_mmiotrace.c
index e064ba3f28cb9..df8692c2dea8a 100644
--- a/kernel/trace/trace_mmiotrace.c
+++ b/kernel/trace/trace_mmiotrace.c
@@ -294,11 +294,15 @@ device_initcall(init_mmio_trace);
static void __trace_mmiotrace_rw(struct trace_array *tr,
struct mmiotrace_rw *rw)
{
- struct trace_buffer *buffer = tr->array_buffer.buffer;
+ struct trace_buffer *buffer;
struct ring_buffer_event *event;
struct trace_mmiotrace_rw *entry;
unsigned int trace_ctx;
+ if (!tr)
+ return;
+
+ buffer = tr->array_buffer.buffer;
trace_ctx = tracing_gen_ctx_flags(0);
event = trace_buffer_lock_reserve(buffer, TRACE_MMIO_RW,
sizeof(*entry), trace_ctx);
@@ -321,11 +325,15 @@ void mmio_trace_rw(struct mmiotrace_rw *rw)
static void __trace_mmiotrace_map(struct trace_array *tr,
struct mmiotrace_map *map)
{
- struct trace_buffer *buffer = tr->array_buffer.buffer;
+ struct trace_buffer *buffer;
struct ring_buffer_event *event;
struct trace_mmiotrace_map *entry;
unsigned int trace_ctx;
+ if (!tr)
+ return;
+
+ buffer = tr->array_buffer.buffer;
trace_ctx = tracing_gen_ctx_flags(0);
event = trace_buffer_lock_reserve(buffer, TRACE_MMIO_MAP,
sizeof(*entry), trace_ctx);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 168/438] riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 167/438] tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 169/438] accel/qaic: use sizeof(*trans_hdr) for transaction length check Greg Kroah-Hartman
` (283 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Anirudh Srinivasan, Paul Walmsley,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Anirudh Srinivasan <asrinivasan@oss.tenstorrent.com>
[ Upstream commit f51fed61eea0daba2f95f1a6074085e4cd513c7b ]
This function runs within a kthread and need not necessarily finish
before system finishes boot and free_initmem() unmaps the .init.text
section. This function makes calls to SBI for probing unaligned access
speed, and if this is slow for some reason (say some debug prints were
added to SBI), the kthread can still be running at this point and result
in an instruction page fault when trying to fetch from the freed region.
[ 25.642087] Unable to handle kernel paging request at virtual address ffffffff80a04ef8
[ 25.646694] Current vec_check_unali pgtable: 4K pagesize, 48-bit VAs, pgdp=0x00004000316e9000
[ 25.653170] [ffffffff80a04ef8] pgd=000010004be7e401, p4d=000010004be7e401, pud=000010004be7e001, pmd=000010000c3000e3
[ 25.661244] Oops [#1]
[ 25.662997] Modules linked in:
[ 25.665357] CPU: 3 UID: 0 PID: 42 Comm: vec_check_unali Not tainted 7.0.0-tt-blackhole-asrinivasan-00007-g30ff73f18211 #570 PREEMPTLAZY
[ 25.674669] Hardware name: Tenstorrent Blackhole (DT)
[ 25.678545] epc : vec_check_unaligned_access_speed_all_cpus+0x18/0x2c
[ 25.683458] ra : vec_check_unaligned_access_speed_all_cpus+0x18/0x2c
[ 25.688372] epc : ffffffff80a04ef8 ra : ffffffff80a04ef8 sp : ffff8f8000203e20
[ 25.693874] gp : ffffffff814dc168 tp : ffffaf8001ad9900 t0 : 0000000000000000
[ 25.699401] t1 : fffffffffffffff0 t2 : ffffaf8001ad9a10 s0 : ffff8f8000203e30
[ 25.704912] s1 : ffffaf80018dc780 a0 : 0000000000000000 a1 : 0000000000000002
[ 25.710407] a2 : 00000000000001f0 a3 : 0000000000000018 a4 : 0000000000000000
[ 25.715917] a5 : 0000000000000000 a6 : ffffaf8001c03d98 a7 : ffffaf8001c03e30
[ 25.721419] s2 : ffff8f8000023c98 s3 : ffffaf8001aa1240 s4 : ffffffff80a04ee0
[ 25.726937] s5 : 0000000000000000 s6 : 0000000000000000 s7 : 0000000000000000
[ 25.732450] s8 : 0000000000000000 s9 : 0000000000000000 s10: 0000000000000000
[ 25.737944] s11: 0000000000000000 t3 : 0000000000000002 t4 : 0000000000000402
[ 25.743481] t5 : 0000000000000040 t6 : 0000000000000004 ssp : 0000000000000000
[ 25.749024] status: 0000000200000120 badaddr: ffffffff80a04ef8 cause: 000000000000000c
[ 25.755060] [<ffffffff80a04ef8>] vec_check_unaligned_access_speed_all_cpus+0x18/0x2c
[ 25.760964] [<ffffffff80047a10>] kthread+0xd8/0xfc
[ 25.764660] [<ffffffff80010c48>] ret_from_fork_kernel+0x18/0x1c4
[ 25.769220] [<ffffffff80895fe6>] ret_from_fork_kernel_asm+0x16/0x18
[ 25.774018] Code: cccc cccc cccc cccc cccc cccc cccc cccc cccc cccc (cccc) cccc
Drop __init from its signature so that this doesn't happen.
Fixes: a00e022be531 ("riscv: Annotate unaligned access init functions")
Signed-off-by: Anirudh Srinivasan <asrinivasan@oss.tenstorrent.com>
Assisted-by: Claude:claude-opus-4-6
Link: https://patch.msgid.link/20260612-vec_unaligned_drop_init-v1-1-df969210ae34@oss.tenstorrent.com
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/kernel/unaligned_access_speed.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/riscv/kernel/unaligned_access_speed.c b/arch/riscv/kernel/unaligned_access_speed.c
index 11c781a4de733..557d661364ac5 100644
--- a/arch/riscv/kernel/unaligned_access_speed.c
+++ b/arch/riscv/kernel/unaligned_access_speed.c
@@ -314,7 +314,7 @@ static void check_vector_unaligned_access(struct work_struct *work __always_unus
}
/* Measure unaligned access speed on all CPUs present at boot in parallel. */
-static int __init vec_check_unaligned_access_speed_all_cpus(void *unused __always_unused)
+static int vec_check_unaligned_access_speed_all_cpus(void *unused __always_unused)
{
schedule_on_each_cpu(check_vector_unaligned_access);
riscv_hwprobe_complete_async_probe();
@@ -322,7 +322,7 @@ static int __init vec_check_unaligned_access_speed_all_cpus(void *unused __alway
return 0;
}
#else /* CONFIG_RISCV_PROBE_VECTOR_UNALIGNED_ACCESS */
-static int __init vec_check_unaligned_access_speed_all_cpus(void *unused __always_unused)
+static int vec_check_unaligned_access_speed_all_cpus(void *unused __always_unused)
{
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 169/438] accel/qaic: use sizeof(*trans_hdr) for transaction length check
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 168/438] riscv: drop __init from vec_check_unaligned_access_speed_all_cpus Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 170/438] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove Greg Kroah-Hartman
` (282 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, Jeff Hugo,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Bilal <meatuni001@gmail.com>
[ Upstream commit d6c075f797a672a6e3bd2fd44aee713801698ec2 ]
In encode_message() the per-transaction lower-bound check compares
trans_hdr->len against sizeof(trans_hdr), i.e. the size of the pointer,
instead of sizeof(*trans_hdr), the size of struct qaic_manage_trans_hdr.
Every other length check in this file (encode_message() at the loop
guard, decode_message(), etc.) correctly uses sizeof(*trans_hdr), so
this is an inconsistency. On 64-bit builds the pointer and the struct
are both 8 bytes, so the check is correct by coincidence and there is
no behavioural change. On 32-bit builds the pointer is 4 bytes, which
weakens the minimum-length check below the 8-byte header size.
Use sizeof(*trans_hdr) so the check validates against the actual
transaction header size on all builds.
Fixes: ea33cb6fc278 ("accel/qaic: tighten bounds checking in encode_message()")
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Reviewed-by: Jeff Hugo <jeff.hugo@oss.qualcomm.com>
Signed-off-by: Jeff Hugo <jeff.hugo@oss.qualcomm.com>
Link: https://patch.msgid.link/20260617212520.59801-1-meatuni001@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/accel/qaic/qaic_control.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/accel/qaic/qaic_control.c b/drivers/accel/qaic/qaic_control.c
index 43f84d4389602..4d4e789d5fcb8 100644
--- a/drivers/accel/qaic/qaic_control.c
+++ b/drivers/accel/qaic/qaic_control.c
@@ -786,7 +786,7 @@ static int encode_message(struct qaic_device *qdev, struct manage_msg *user_msg,
break;
}
trans_hdr = (struct qaic_manage_trans_hdr *)(user_msg->data + user_len);
- if (trans_hdr->len < sizeof(trans_hdr) ||
+ if (trans_hdr->len < sizeof(*trans_hdr) ||
size_add(user_len, trans_hdr->len) > user_msg->len) {
ret = -EINVAL;
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 170/438] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 169/438] accel/qaic: use sizeof(*trans_hdr) for transaction length check Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 171/438] ring-buffer: Fix reader page read offset for remote buffers Greg Kroah-Hartman
` (281 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Paul Walmsley,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit a0188cc133696627857d16054e43f9ebc7efc821 ]
remove_pud_mapping() and remove_p4d_mapping() obtain a child table base
with pud_offset(p4dp, 0) and p4d_offset(pgd, 0), then add the index for
addr.
RISC-V folds page-table levels at runtime. When a level is folded, its
offset helper returns the parent entry itself, but the index can still be
nonzero. Adding it walks past the parent table. Sv48 folds P4D, while Sv39
folds both P4D and PUD, so memory hot-remove can descend into unrelated
memory and pass an invalid page to __free_pages(). This can trigger:
kernel BUG at include/linux/mm.h:1810!
VM_BUG_ON_PAGE(page_ref_count(page) == 0)
arch_remove_memory+0x1e/0x5c
try_remove_memory+0x15e/0x200
remove_memory+0x24/0x3c
Only add the index when the corresponding page-table level is enabled,
matching p4d_offset() and pud_offset().
Fixes: c75a74f4ba19 ("riscv: mm: Add memory hotplugging support")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260729012132.24882-1-kmehltretter@gmail.com
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/mm/init.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/riscv/mm/init.c b/arch/riscv/mm/init.c
index 885f1db4e9bfd..6aae507d8e818 100644
--- a/arch/riscv/mm/init.c
+++ b/arch/riscv/mm/init.c
@@ -1629,7 +1629,7 @@ static void __meminit remove_pud_mapping(pud_t *pud_base, unsigned long addr, un
for (; addr < end; addr = next) {
next = pud_addr_end(addr, end);
- pudp = pud_base + pud_index(addr);
+ pudp = pgtable_l4_enabled ? pud_base + pud_index(addr) : pud_base;
pud = pudp_get(pudp);
if (!pud_present(pud))
continue;
@@ -1660,7 +1660,7 @@ static void __meminit remove_p4d_mapping(p4d_t *p4d_base, unsigned long addr, un
for (; addr < end; addr = next) {
next = p4d_addr_end(addr, end);
- p4dp = p4d_base + p4d_index(addr);
+ p4dp = pgtable_l5_enabled ? p4d_base + p4d_index(addr) : p4d_base;
p4d = p4dp_get(p4dp);
if (!p4d_present(p4d))
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 171/438] ring-buffer: Fix reader page read offset for remote buffers
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 170/438] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 172/438] ipv6: release fib6_null_entry on subtree failure Greg Kroah-Hartman
` (280 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vincent Donnefort, Keir Fraser,
Steven Rostedt, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Donnefort <vdonnefort@google.com>
[ Upstream commit 78cd56c2a9d2e8da763cea3b06b636266ca66911 ]
A page swapped in by __rb_get_reader_page_from_remote() retains its
stale read offset, causing subsequent reads to skip events or read
past valid data. Fix it.
Link: https://patch.msgid.link/20260729133609.4022734-1-vdonnefort@google.com
Fixes: fbd1743ecba1 ("ring-buffer: Add non-consuming read for ring-buffer remotes")
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Reviewed-by: Keir Fraser <keirf@google.com>
Tested-by: Keir Fraser <keirf@google.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/ring_buffer.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index da9339466bddd..d896fb25de702 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -5624,6 +5624,7 @@ __rb_get_reader_page_from_remote(struct ring_buffer_per_cpu *cpu_buffer)
cpu_buffer->head_page = new_head;
cpu_buffer->reader_page = new_reader;
+ cpu_buffer->reader_page->read = 0;
cpu_buffer->pages = &new_head->list;
cpu_buffer->read_stamp = new_reader->page->time_stamp;
cpu_buffer->lost_events = cpu_buffer->meta_page->reader.lost_events;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 172/438] ipv6: release fib6_null_entry on subtree failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 171/438] ring-buffer: Fix reader page read offset for remote buffers Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 173/438] riscv: vdso: Only try to install vDSO when present Greg Kroah-Hartman
` (279 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
[ Upstream commit 93cad1f6bd1e27c75c4a5ab000c2a2fc01181ccf ]
When adding a source-specific route creates a new subtree, fib6_add()
installs fib6_null_entry as the temporary leaf of the new subtree root
and takes a fib6_info reference for that holder.
If adding the first source leaf fails, the code frees the just allocated
subtree root but leaves that hold behind. fib6_null_entry is a per-netns
sentinel and is freed directly at netns teardown, so this does not keep
the object alive. However, it leaves its visible refcount permanently
elevated and can eventually saturate the refcount on repeated failures.
Drop the null-entry reference before freeing the unlinked subtree root.
Fixes: 5ea715289af6 ("ipv6: broadly use fib6_info_hold() helper")
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Link: https://patch.msgid.link/20260727185339.1545169-1-shuangpeng.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ip6_fib.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/ipv6/ip6_fib.c b/net/ipv6/ip6_fib.c
index 414fc3c567360..b4641bfffdf3f 100644
--- a/net/ipv6/ip6_fib.c
+++ b/net/ipv6/ip6_fib.c
@@ -1495,6 +1495,7 @@ int fib6_add(struct fib6_node *root, struct fib6_info *rt,
root, and then (in failure) stale node
in main tree.
*/
+ fib6_info_release(info->nl_net->ipv6.fib6_null_entry);
node_free_immediate(info->nl_net, sfn);
err = PTR_ERR(sn);
goto failure;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 173/438] riscv: vdso: Only try to install vDSO when present
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 172/438] ipv6: release fib6_null_entry on subtree failure Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 174/438] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend Greg Kroah-Hartman
` (278 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot,
Thomas Weißschuh, Paul Walmsley, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit c052927905710de1ab7364bf1925efbd12517ea3 ]
vdso.so.dbg is only built with CONFIG_MMU.
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202607090258.iSAUYlO1-lkp@intel.com/
Fixes: f157d411a9eb ("riscv: add missing vdso_install target")
Fixes: 3edf39916977 ("vDSO, kbuild: Provide vDSO debug variants at runtime")
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Link: https://patch.msgid.link/20260709-riscv-install-vdso-v1-1-0ba4345419ca@linutronix.de
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/Makefile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/riscv/Makefile b/arch/riscv/Makefile
index ce0cc737f8709..1363e5bef35cd 100644
--- a/arch/riscv/Makefile
+++ b/arch/riscv/Makefile
@@ -168,7 +168,7 @@ vdso_prepare: prepare0
endif
endif
-vdso-install-y += arch/riscv/kernel/vdso/vdso.so.dbg
+vdso-install-$(CONFIG_MMU) += arch/riscv/kernel/vdso/vdso.so.dbg
vdso-install-$(CONFIG_RISCV_USER_CFI) += arch/riscv/kernel/vdso_cfi/vdso-cfi.so.dbg
vdso-install-$(CONFIG_COMPAT) += arch/riscv/kernel/compat_vdso/compat_vdso.so.dbg
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 174/438] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 173/438] riscv: vdso: Only try to install vDSO when present Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 175/438] net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling Greg Kroah-Hartman
` (277 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Golle, Andrew Lunn,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Golle <daniel@makrotopia.org>
[ Upstream commit b4ce102b2cd88424c5860fbbb20b9eb343a93bf4 ]
bus->read() returns a negative errno on failure, but
mt7530_regmap_read() assigns it to a u16, truncating e.g. -ETIMEDOUT
into 0xff92, and returns success. The garbage word is then consumed as
register data, and read-modify-write cycles write it back to the
switch. Check both reads and propagate their errors.
The same defect existed in mt7530_mii_read() since the driver was
introduced and moved into the regmap backend unchanged.
Fixes: b8f126a8d543 ("net-next: dsa: add dsa support for Mediatek MT7530 switch")
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/3c628e48276c2e5522c8795a6be60d11c7a76a7d.1785213071.git.daniel@makrotopia.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mt7530-mdio.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/net/dsa/mt7530-mdio.c b/drivers/net/dsa/mt7530-mdio.c
index 11ea924a9f357..784dd58a71589 100644
--- a/drivers/net/dsa/mt7530-mdio.c
+++ b/drivers/net/dsa/mt7530-mdio.c
@@ -55,8 +55,15 @@ mt7530_regmap_read(void *context, unsigned int reg, unsigned int *val)
if (ret < 0)
return ret;
- lo = bus->read(bus, priv->mdiodev->addr, r);
- hi = bus->read(bus, priv->mdiodev->addr, 0x10);
+ ret = bus->read(bus, priv->mdiodev->addr, r);
+ if (ret < 0)
+ return ret;
+ lo = ret;
+
+ ret = bus->read(bus, priv->mdiodev->addr, 0x10);
+ if (ret < 0)
+ return ret;
+ hi = ret;
*val = (hi << 16) | (lo & 0xffff);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 175/438] net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 174/438] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 176/438] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling Greg Kroah-Hartman
` (276 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Golle, Andrew Lunn,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Golle <daniel@makrotopia.org>
[ Upstream commit ed9adac35b8fac635f40e28461505e2e5b6c8fcc ]
mt7530_fdb_cmd() and mt7530_vlan_cmd() poll the command register
through a helper which returns 0 when the underlying read fails. A
failed bus transaction thus clears ATC_BUSY/VTCR_BUSY and is treated
as successful command completion, and the subsequent ATC_INVALID and
VTCR_INVALID checks are defeated the same way.
Poll using regmap_read_poll_timeout(), which stops on read errors and
propagates them, and check the completion status read as well. Take
the MDIO bus lock across the sequence as the switch regmap is set up
with locking disabled.
Fixes: b8f126a8d543 ("net-next: dsa: add dsa support for Mediatek MT7530 switch")
Fixes: 83163f7dca56 ("net: dsa: mediatek: add VLAN support for MT7530")
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/eea1d8f15c54375b3770c23e09fb3217df487169.1785213071.git.daniel@makrotopia.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mt7530.c | 28 ++++++++++++++++++----------
1 file changed, 18 insertions(+), 10 deletions(-)
diff --git a/drivers/net/dsa/mt7530.c b/drivers/net/dsa/mt7530.c
index 3c2a3029b10cf..292cde961f1af 100644
--- a/drivers/net/dsa/mt7530.c
+++ b/drivers/net/dsa/mt7530.c
@@ -248,15 +248,20 @@ mt7530_fdb_cmd(struct mt7530_priv *priv, enum mt7530_fdb_cmd cmd, u32 *rsp)
{
u32 val;
int ret;
- struct mt7530_dummy_poll p;
/* Set the command operating upon the MAC address entries */
val = ATC_BUSY | ATC_MAT(0) | cmd;
mt7530_write(priv, MT7530_ATC, val);
- INIT_MT7530_DUMMY_POLL(&p, priv, MT7530_ATC);
- ret = readx_poll_timeout(_mt7530_read, &p, val,
- !(val & ATC_BUSY), 20, 20000);
+ mt7530_mutex_lock(priv);
+
+ ret = regmap_read_poll_timeout(priv->regmap, MT7530_ATC, val,
+ !(val & ATC_BUSY), 20, 20000);
+ if (!ret)
+ ret = regmap_read(priv->regmap, MT7530_ATC, &val);
+
+ mt7530_mutex_unlock(priv);
+
if (ret < 0) {
dev_err(priv->dev, "reset timeout\n");
return ret;
@@ -265,7 +270,6 @@ mt7530_fdb_cmd(struct mt7530_priv *priv, enum mt7530_fdb_cmd cmd, u32 *rsp)
/* Additional sanity for read command if the specified
* entry is invalid
*/
- val = mt7530_read(priv, MT7530_ATC);
if ((cmd == MT7530_FDB_READ) && (val & ATC_INVALID))
return -EINVAL;
@@ -1626,22 +1630,26 @@ mt7530_port_bridge_join(struct dsa_switch *ds, int port,
static int
mt7530_vlan_cmd(struct mt7530_priv *priv, enum mt7530_vlan_cmd cmd, u16 vid)
{
- struct mt7530_dummy_poll p;
u32 val;
int ret;
val = VTCR_BUSY | VTCR_FUNC(cmd) | vid;
mt7530_write(priv, MT7530_VTCR, val);
- INIT_MT7530_DUMMY_POLL(&p, priv, MT7530_VTCR);
- ret = readx_poll_timeout(_mt7530_read, &p, val,
- !(val & VTCR_BUSY), 20, 20000);
+ mt7530_mutex_lock(priv);
+
+ ret = regmap_read_poll_timeout(priv->regmap, MT7530_VTCR, val,
+ !(val & VTCR_BUSY), 20, 20000);
+ if (!ret)
+ ret = regmap_read(priv->regmap, MT7530_VTCR, &val);
+
+ mt7530_mutex_unlock(priv);
+
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
return ret;
}
- val = mt7530_read(priv, MT7530_VTCR);
if (val & VTCR_INVALID) {
dev_err(priv->dev, "read VTCR invalid\n");
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 176/438] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 175/438] net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 177/438] net: stmmac: Fix E2E delay mechanism Greg Kroah-Hartman
` (275 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Golle, Andrew Lunn,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Golle <daniel@makrotopia.org>
[ Upstream commit 77a9ebe8818cf6dd1699bd6728cb5d66307801d7 ]
The MT7531 indirect PHY access functions poll MT7531_PHY_IAC through
a helper which returns 0 when the underlying read fails, so a failed
bus transaction clears MT7531_PHY_ACS_ST and the access carries on,
returning garbage PHY register data to phylib.
Poll using regmap_read_poll_timeout(), which stops on read errors and
propagates them. These functions hold the MDIO bus lock across the
whole sequence, so the unlocked regmap accesses remain correct. Remove
the now-unused _mt7530_unlocked_read().
Fixes: c288575f7810 ("net: dsa: mt7530: Add the support of MT7531 switch")
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/79e85d68d210cc37342978171aa6432aa2954333.1785213071.git.daniel@makrotopia.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mt7530.c | 58 ++++++++++++++--------------------------
1 file changed, 20 insertions(+), 38 deletions(-)
diff --git a/drivers/net/dsa/mt7530.c b/drivers/net/dsa/mt7530.c
index 292cde961f1af..aa33d94e11b5f 100644
--- a/drivers/net/dsa/mt7530.c
+++ b/drivers/net/dsa/mt7530.c
@@ -191,12 +191,6 @@ mt7530_write(struct mt7530_priv *priv, u32 reg, u32 val)
mt7530_mutex_unlock(priv);
}
-static u32
-_mt7530_unlocked_read(struct mt7530_dummy_poll *p)
-{
- return mt7530_mii_read(p->priv, p->reg);
-}
-
static u32
_mt7530_read(struct mt7530_dummy_poll *p)
{
@@ -553,16 +547,13 @@ static int
mt7531_ind_c45_phy_read(struct mt7530_priv *priv, int port, int devad,
int regnum)
{
- struct mt7530_dummy_poll p;
u32 reg, val;
int ret;
- INIT_MT7530_DUMMY_POLL(&p, priv, MT7531_PHY_IAC);
-
mt7530_mutex_lock(priv);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -572,8 +563,8 @@ mt7531_ind_c45_phy_read(struct mt7530_priv *priv, int port, int devad,
MT7531_MDIO_DEV_ADDR(devad) | regnum;
mt7530_mii_write(priv, MT7531_PHY_IAC, reg | MT7531_PHY_ACS_ST);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -583,8 +574,8 @@ mt7531_ind_c45_phy_read(struct mt7530_priv *priv, int port, int devad,
MT7531_MDIO_DEV_ADDR(devad);
mt7530_mii_write(priv, MT7531_PHY_IAC, reg | MT7531_PHY_ACS_ST);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -601,16 +592,13 @@ static int
mt7531_ind_c45_phy_write(struct mt7530_priv *priv, int port, int devad,
int regnum, u16 data)
{
- struct mt7530_dummy_poll p;
u32 val, reg;
int ret;
- INIT_MT7530_DUMMY_POLL(&p, priv, MT7531_PHY_IAC);
-
mt7530_mutex_lock(priv);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -620,8 +608,8 @@ mt7531_ind_c45_phy_write(struct mt7530_priv *priv, int port, int devad,
MT7531_MDIO_DEV_ADDR(devad) | regnum;
mt7530_mii_write(priv, MT7531_PHY_IAC, reg | MT7531_PHY_ACS_ST);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -631,8 +619,8 @@ mt7531_ind_c45_phy_write(struct mt7530_priv *priv, int port, int devad,
MT7531_MDIO_DEV_ADDR(devad) | data;
mt7530_mii_write(priv, MT7531_PHY_IAC, reg | MT7531_PHY_ACS_ST);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -647,16 +635,13 @@ mt7531_ind_c45_phy_write(struct mt7530_priv *priv, int port, int devad,
static int
mt7531_ind_c22_phy_read(struct mt7530_priv *priv, int port, int regnum)
{
- struct mt7530_dummy_poll p;
int ret;
u32 val;
- INIT_MT7530_DUMMY_POLL(&p, priv, MT7531_PHY_IAC);
-
mt7530_mutex_lock(priv);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -667,8 +652,8 @@ mt7531_ind_c22_phy_read(struct mt7530_priv *priv, int port, int regnum)
mt7530_mii_write(priv, MT7531_PHY_IAC, val | MT7531_PHY_ACS_ST);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, val,
- !(val & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, val,
+ !(val & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -685,16 +670,13 @@ static int
mt7531_ind_c22_phy_write(struct mt7530_priv *priv, int port, int regnum,
u16 data)
{
- struct mt7530_dummy_poll p;
int ret;
u32 reg;
- INIT_MT7530_DUMMY_POLL(&p, priv, MT7531_PHY_IAC);
-
mt7530_mutex_lock(priv);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, reg,
- !(reg & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, reg,
+ !(reg & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
@@ -705,8 +687,8 @@ mt7531_ind_c22_phy_write(struct mt7530_priv *priv, int port, int regnum,
mt7530_mii_write(priv, MT7531_PHY_IAC, reg | MT7531_PHY_ACS_ST);
- ret = readx_poll_timeout(_mt7530_unlocked_read, &p, reg,
- !(reg & MT7531_PHY_ACS_ST), 20, 100000);
+ ret = regmap_read_poll_timeout(priv->regmap, MT7531_PHY_IAC, reg,
+ !(reg & MT7531_PHY_ACS_ST), 20, 100000);
if (ret < 0) {
dev_err(priv->dev, "poll timeout\n");
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 177/438] net: stmmac: Fix E2E delay mechanism
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 176/438] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 178/438] net: mana: Create separate EQs for each vPort Greg Kroah-Hartman
` (274 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Rohan G Thomas,
Nazim Amirul, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nazim Amirul <muhammad.nazim.amirul.nazle.asmade@altera.com>
[ Upstream commit b041ed62aa6e3b2d7d36127e0e5d7bf2701f8231 ]
For E2E delay mechanism, "received DELAY_REQ without timestamp" error
messages show up for dwmac v3.70+ and dwxgmac IPs.
This issue affects socfpga platforms, Agilex7 (dwmac 3.70) and
Agilex5 (dwxgmac). According to the databook, to enable timestamping
for all events, the SNAPTYPSEL bits in the MAC_Timestamp_Control
register must be set to 2'b01, and the TSEVNTENA bit must be cleared
to 0'b0.
Commit 3cb958027cb8 ("net: stmmac: Fix E2E delay mechanism") already
addresses this problem for all dwmacs above version v4.10. However,
same holds true for v3.70 and above, as well as for dwxgmac. Updates
the check accordingly.
Fixes: 14f347334bf2 ("net: stmmac: Correctly take timestamp for PTPv2")
Fixes: f2fb6b6275eb ("net: stmmac: enable timestamp snapshot for required PTP packets in dwmac v5.10a")
Fixes: 3cb958027cb8 ("net: stmmac: Fix E2E delay mechanism")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Signed-off-by: Rohan G Thomas <rohan.g.thomas@altera.com>
Signed-off-by: Nazim Amirul <muhammad.nazim.amirul.nazle.asmade@altera.com>
Link: https://patch.msgid.link/20260728060904.31993-1-muhammad.nazim.amirul.nazle.asmade@altera.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index 755f48a34314b..f28367fbcaf81 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -755,7 +755,8 @@ static int stmmac_hwtstamp_set(struct net_device *dev,
config->rx_filter = HWTSTAMP_FILTER_PTP_V2_EVENT;
ptp_v2 = PTP_TCR_TSVER2ENA;
snap_type_sel = PTP_TCR_SNAPTYPSEL_1;
- if (priv->synopsys_id < DWMAC_CORE_4_10)
+ if (priv->synopsys_id < DWMAC_CORE_3_70 &&
+ priv->plat->core_type != DWMAC_CORE_XGMAC)
ts_event_en = PTP_TCR_TSEVNTENA;
ptp_over_ipv4_udp = PTP_TCR_TSIPV4ENA;
ptp_over_ipv6_udp = PTP_TCR_TSIPV6ENA;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 178/438] net: mana: Create separate EQs for each vPort
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 177/438] net: stmmac: Fix E2E delay mechanism Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 179/438] net: mana: Return error code from mana_create_rxq() Greg Kroah-Hartman
` (273 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Long Li, Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Long Li <longli@microsoft.com>
[ Upstream commit fa1a3b7bcd161028e038025c1a4a8963b2f56a95 ]
To prepare for assigning vPorts to dedicated MSI-X vectors, remove EQ
sharing among the vPorts and create dedicated EQs for each vPort.
Move the EQ definition from struct mana_context to struct mana_port_context
and update related support functions. Export mana_create_eq() and
mana_destroy_eq() for use by the MANA RDMA driver.
RSS QPs now take a vport reference via pd->vport_use_count to ensure
EQs outlive all QP consumers. The vport must already be configured by
a raw QP before an RSS QP can be created. EQs are only destroyed when
the last QP (raw or RSS) on the PD releases its reference.
Restrict each vport to a single RSS QP. The hardware only supports one
steering configuration (indirection table / hash key) per vport, and
mana_disable_vport_rx() on QP destroy disables RX globally for the
vport. Previously, creating a second RSS QP would silently overwrite
the first QP's steering config and destroy would blackhole all traffic.
This is now explicitly rejected with -EBUSY. Existing applications
(DPDK being the primary RDMA consumer) always create one RSS QP per
vport, so no real-world flows are affected.
Reject cross-port PD sharing for both raw and RSS QPs. Since EQs and
vport configuration are per-port, a PD is bound to the port used by
its first raw QP. Subsequent QPs on the same PD must use the same
port or the creation fails with -EINVAL. Previously this was silently
broken: with shared EQs it appeared to work, but with per-vPort EQs
a cross-port PD would cause wrong-port EQ teardown and corruption.
DPDK creates one PD per port so no existing flows are affected.
Serialize mana_set_channels() and the async per-port queue reset
handler against RDMA vport configuration to prevent RDMA from claiming
the vport during the detach/attach window. A channel_changing flag is
set under apc->vport_mutex before detach and checked by
mana_cfg_vport() when called from the RDMA path, blocking RDMA from
grabbing the vport during the entire window. When the port is down
and RDMA already holds the vport, the channel change is rejected with
-EBUSY.
Signed-off-by: Long Li <longli@microsoft.com>
Link: https://patch.msgid.link/20260605005717.2059954-2-longli@microsoft.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: e67cc80b50f5 ("net: mana: Return error code from mana_create_rxq()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mana/main.c | 40 ++++--
drivers/infiniband/hw/mana/mana_ib.h | 14 ++
drivers/infiniband/hw/mana/qp.c | 68 ++++++++-
drivers/net/ethernet/microsoft/mana/mana_en.c | 135 +++++++++++-------
.../ethernet/microsoft/mana/mana_ethtool.c | 23 ++-
include/net/mana/mana.h | 15 +-
6 files changed, 228 insertions(+), 67 deletions(-)
diff --git a/drivers/infiniband/hw/mana/main.c b/drivers/infiniband/hw/mana/main.c
index 307ae01bf26f3..0e1727c53d5d2 100644
--- a/drivers/infiniband/hw/mana/main.c
+++ b/drivers/infiniband/hw/mana/main.c
@@ -20,8 +20,10 @@ void mana_ib_uncfg_vport(struct mana_ib_dev *dev, struct mana_ib_pd *pd,
pd->vport_use_count--;
WARN_ON(pd->vport_use_count < 0);
- if (!pd->vport_use_count)
+ if (!pd->vport_use_count) {
+ mana_destroy_eq(mpc);
mana_uncfg_vport(mpc);
+ }
mutex_unlock(&pd->vport_mutex);
}
@@ -40,13 +42,27 @@ int mana_ib_cfg_vport(struct mana_ib_dev *dev, u32 port, struct mana_ib_pd *pd,
pd->vport_use_count++;
if (pd->vport_use_count > 1) {
+ /* Reject cross-port PD sharing. EQs and vport config
+ * are per-port, so the PD must stay bound to the port
+ * that was configured on the first raw QP creation.
+ */
+ if (pd->vport_port != port) {
+ pd->vport_use_count--;
+ mutex_unlock(&pd->vport_mutex);
+ ibdev_dbg(&dev->ib_dev,
+ "PD already bound to port %u\n",
+ pd->vport_port);
+ return -EINVAL;
+ }
ibdev_dbg(&dev->ib_dev,
"Skip as this PD is already configured vport\n");
mutex_unlock(&pd->vport_mutex);
return 0;
}
- err = mana_cfg_vport(mpc, pd->pdn, doorbell_id);
+ pd->vport_port = port;
+
+ err = mana_cfg_vport(mpc, pd->pdn, doorbell_id, true);
if (err) {
pd->vport_use_count--;
mutex_unlock(&pd->vport_mutex);
@@ -55,15 +71,23 @@ int mana_ib_cfg_vport(struct mana_ib_dev *dev, u32 port, struct mana_ib_pd *pd,
return err;
}
- mutex_unlock(&pd->vport_mutex);
- pd->tx_shortform_allowed = mpc->tx_shortform_allowed;
- pd->tx_vp_offset = mpc->tx_vp_offset;
+ err = mana_create_eq(mpc);
+ if (err) {
+ mana_uncfg_vport(mpc);
+ pd->vport_use_count--;
+ } else {
+ pd->tx_shortform_allowed = mpc->tx_shortform_allowed;
+ pd->tx_vp_offset = mpc->tx_vp_offset;
+ }
+
+ mutex_unlock(&pd->vport_mutex);
- ibdev_dbg(&dev->ib_dev, "vport handle %llx pdid %x doorbell_id %x\n",
- mpc->port_handle, pd->pdn, doorbell_id);
+ if (!err)
+ ibdev_dbg(&dev->ib_dev, "vport handle %llx pdid %x doorbell_id %x\n",
+ mpc->port_handle, pd->pdn, doorbell_id);
- return 0;
+ return err;
}
int mana_ib_alloc_pd(struct ib_pd *ibpd, struct ib_udata *udata)
diff --git a/drivers/infiniband/hw/mana/mana_ib.h b/drivers/infiniband/hw/mana/mana_ib.h
index c9c94e86a72bd..da05966aff191 100644
--- a/drivers/infiniband/hw/mana/mana_ib.h
+++ b/drivers/infiniband/hw/mana/mana_ib.h
@@ -102,6 +102,20 @@ struct mana_ib_pd {
struct mutex vport_mutex;
int vport_use_count;
+ /* Port bound to this PD for raw QP usage. Only valid when
+ * vport_use_count > 0. A PD can only be associated with a
+ * single physical port because per-port EQs and vport
+ * configuration are tied to the PD's refcount.
+ */
+ u32 vport_port;
+
+ /* Only one RSS QP is allowed per vport because each RSS QP
+ * overwrites the vport steering config (indirection table /
+ * hash key) and mana_disable_vport_rx() on destroy would
+ * blackhole traffic for any other RSS QP on the same vport.
+ */
+ bool has_rss_qp;
+
bool tx_shortform_allowed;
u32 tx_vp_offset;
};
diff --git a/drivers/infiniband/hw/mana/qp.c b/drivers/infiniband/hw/mana/qp.c
index 0fbcf449c134b..d3ee30b64f53a 100644
--- a/drivers/infiniband/hw/mana/qp.c
+++ b/drivers/infiniband/hw/mana/qp.c
@@ -79,6 +79,7 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
struct ib_qp_init_attr *attr,
struct ib_udata *udata)
{
+ struct mana_ib_pd *mana_pd = container_of(pd, struct mana_ib_pd, ibpd);
struct mana_ib_qp *qp = container_of(ibqp, struct mana_ib_qp, ibqp);
struct mana_ib_dev *mdev =
container_of(pd->device, struct mana_ib_dev, ib_dev);
@@ -155,6 +156,30 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
qp->port = port;
+ /* Take a reference on the vport to ensure EQs outlive this QP.
+ * The vport must already be configured by a raw QP on the
+ * same port — cross-port PD sharing is not supported.
+ * Only one RSS QP per vport is allowed because each one
+ * overwrites the steering config and destroy disables RX
+ * globally.
+ */
+ mutex_lock(&mana_pd->vport_mutex);
+ if (!mana_pd->vport_use_count || mana_pd->vport_port != port) {
+ mutex_unlock(&mana_pd->vport_mutex);
+ ret = -EINVAL;
+ goto fail;
+ }
+ if (mana_pd->has_rss_qp) {
+ mutex_unlock(&mana_pd->vport_mutex);
+ ibdev_dbg(&mdev->ib_dev,
+ "Only one RSS QP per vport is supported\n");
+ ret = -EBUSY;
+ goto fail;
+ }
+ mana_pd->vport_use_count++;
+ mana_pd->has_rss_qp = true;
+ mutex_unlock(&mana_pd->vport_mutex);
+
for (i = 0; i < ind_tbl_size; i++) {
struct mana_obj_spec wq_spec = {};
struct mana_obj_spec cq_spec = {};
@@ -171,13 +196,19 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
cq_spec.gdma_region = cq->queue.gdma_region;
cq_spec.queue_size = cq->cqe * COMP_ENTRY_SIZE;
cq_spec.modr_ctx_id = 0;
- eq = &mpc->ac->eqs[cq->comp_vector];
+ /* Map comp_vector to a per-vPort EQ. The modulo handles
+ * the case where the RDMA-advertised num_comp_vectors
+ * exceeds this port's num_queues (e.g. after ethtool -L
+ * reduces it), remapping to an available EQ rather than
+ * failing the QP creation.
+ */
+ eq = &mpc->eqs[cq->comp_vector % mpc->num_queues];
cq_spec.attached_eq = eq->eq->id;
ret = mana_create_wq_obj(mpc, mpc->port_handle, GDMA_RQ,
&wq_spec, &cq_spec, &wq->rx_object);
if (ret)
- goto fail;
+ goto free_vport;
/* The GDMA regions are now owned by the WQ object */
wq->queue.gdma_region = GDMA_INVALID_DMA_REGION;
@@ -199,7 +230,7 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
ret = mana_ib_install_cq_cb(mdev, cq);
if (ret) {
mana_destroy_wq_obj(mpc, GDMA_RQ, wq->rx_object);
- goto fail;
+ goto free_vport;
}
}
resp.num_entries = i;
@@ -210,7 +241,7 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
ucmd.rx_hash_key_len,
ucmd.rx_hash_key);
if (ret)
- goto fail;
+ goto free_vport;
ret = ib_copy_to_udata(udata, &resp, sizeof(resp));
if (ret) {
@@ -226,7 +257,7 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
err_disable_vport_rx:
mana_disable_vport_rx(mpc);
-fail:
+free_vport:
while (i-- > 0) {
ibwq = ind_tbl->ind_tbl[i];
ibcq = ibwq->cq;
@@ -237,6 +268,13 @@ static int mana_ib_create_qp_rss(struct ib_qp *ibqp, struct ib_pd *pd,
mana_destroy_wq_obj(mpc, GDMA_RQ, wq->rx_object);
}
+ mutex_lock(&mana_pd->vport_mutex);
+ mana_pd->has_rss_qp = false;
+ mutex_unlock(&mana_pd->vport_mutex);
+
+ mana_ib_uncfg_vport(mdev, mana_pd, port);
+
+fail:
kfree(mana_ind_table);
return ret;
@@ -299,7 +337,7 @@ static int mana_ib_create_qp_raw(struct ib_qp *ibqp, struct ib_pd *ibpd,
err = mana_ib_cfg_vport(mdev, port, pd, mana_ucontext->doorbell);
if (err)
- return -ENODEV;
+ return err;
qp->port = port;
@@ -321,7 +359,14 @@ static int mana_ib_create_qp_raw(struct ib_qp *ibqp, struct ib_pd *ibpd,
cq_spec.queue_size = send_cq->cqe * COMP_ENTRY_SIZE;
cq_spec.modr_ctx_id = 0;
eq_vec = send_cq->comp_vector;
- eq = &mpc->ac->eqs[eq_vec];
+ if (!mpc->eqs) {
+ err = -EINVAL;
+ goto err_destroy_queue;
+ }
+ /* Map comp_vector to a per-vPort EQ. See comment in
+ * mana_ib_create_qp_rss() for the modulo rationale.
+ */
+ eq = &mpc->eqs[eq_vec % mpc->num_queues];
cq_spec.attached_eq = eq->eq->id;
err = mana_create_wq_obj(mpc, mpc->port_handle, GDMA_SQ, &wq_spec,
@@ -785,14 +830,17 @@ static int mana_ib_destroy_qp_rss(struct mana_ib_qp *qp,
{
struct mana_ib_dev *mdev =
container_of(qp->ibqp.device, struct mana_ib_dev, ib_dev);
+ struct ib_pd *ibpd = qp->ibqp.pd;
struct mana_port_context *mpc;
struct net_device *ndev;
+ struct mana_ib_pd *pd;
struct mana_ib_wq *wq;
struct ib_wq *ibwq;
int i;
ndev = mana_ib_get_netdev(qp->ibqp.device, qp->port);
mpc = netdev_priv(ndev);
+ pd = container_of(ibpd, struct mana_ib_pd, ibpd);
/* Disable vPort RX steering before destroying RX WQ objects.
* Otherwise firmware still routes traffic to the destroyed queues,
@@ -817,6 +865,12 @@ static int mana_ib_destroy_qp_rss(struct mana_ib_qp *qp,
mana_destroy_wq_obj(mpc, GDMA_RQ, wq->rx_object);
}
+ mutex_lock(&pd->vport_mutex);
+ pd->has_rss_qp = false;
+ mutex_unlock(&pd->vport_mutex);
+
+ mana_ib_uncfg_vport(mdev, pd, qp->port);
+
return 0;
}
diff --git a/drivers/net/ethernet/microsoft/mana/mana_en.c b/drivers/net/ethernet/microsoft/mana/mana_en.c
index 352398ae0376e..9d8c91d36b3bc 100644
--- a/drivers/net/ethernet/microsoft/mana/mana_en.c
+++ b/drivers/net/ethernet/microsoft/mana/mana_en.c
@@ -309,11 +309,18 @@ static void mana_per_port_queue_reset_work_handler(struct work_struct *work)
rtnl_lock();
+ /* Block RDMA from grabbing the vport during the detach/attach
+ * window, same as mana_set_channels().
+ */
+ mutex_lock(&apc->vport_mutex);
+ apc->channel_changing = true;
+ mutex_unlock(&apc->vport_mutex);
+
/* Pre-allocate buffers to prevent failure in mana_attach later */
err = mana_pre_alloc_rxbufs(apc, ndev->mtu, apc->num_queues);
if (err) {
netdev_err(ndev, "Insufficient memory for reset post tx stall detection\n");
- goto out;
+ goto clear_flag;
}
err = mana_detach(ndev, false);
@@ -328,7 +335,11 @@ static void mana_per_port_queue_reset_work_handler(struct work_struct *work)
dealloc_pre_rxbufs:
mana_pre_dealloc_rxbufs(apc);
-out:
+clear_flag:
+ mutex_lock(&apc->vport_mutex);
+ apc->channel_changing = false;
+ mutex_unlock(&apc->vport_mutex);
+
rtnl_unlock();
}
@@ -1301,7 +1312,7 @@ void mana_uncfg_vport(struct mana_port_context *apc)
EXPORT_SYMBOL_NS(mana_uncfg_vport, "NET_MANA");
int mana_cfg_vport(struct mana_port_context *apc, u32 protection_dom_id,
- u32 doorbell_pg_id)
+ u32 doorbell_pg_id, bool check_channel_changing)
{
struct mana_config_vport_resp resp = {};
struct mana_config_vport_req req = {};
@@ -1326,7 +1337,8 @@ int mana_cfg_vport(struct mana_port_context *apc, u32 protection_dom_id,
* Ethernet usage on the same port.
*/
mutex_lock(&apc->vport_mutex);
- if (apc->vport_use_count > 0) {
+ if (apc->vport_use_count > 0 ||
+ (check_channel_changing && apc->channel_changing)) {
mutex_unlock(&apc->vport_mutex);
return -EBUSY;
}
@@ -1621,78 +1633,84 @@ void mana_destroy_wq_obj(struct mana_port_context *apc, u32 wq_type,
}
EXPORT_SYMBOL_NS(mana_destroy_wq_obj, "NET_MANA");
-static void mana_destroy_eq(struct mana_context *ac)
+void mana_destroy_eq(struct mana_port_context *apc)
{
+ struct mana_context *ac = apc->ac;
struct gdma_context *gc = ac->gdma_dev->gdma_context;
struct gdma_queue *eq;
int i;
- if (!ac->eqs)
+ if (!apc->eqs)
return;
- debugfs_remove_recursive(ac->mana_eqs_debugfs);
- ac->mana_eqs_debugfs = NULL;
+ debugfs_remove_recursive(apc->mana_eqs_debugfs);
+ apc->mana_eqs_debugfs = NULL;
- for (i = 0; i < gc->max_num_queues; i++) {
- eq = ac->eqs[i].eq;
+ for (i = 0; i < apc->num_queues; i++) {
+ eq = apc->eqs[i].eq;
if (!eq)
continue;
mana_gd_destroy_queue(gc, eq);
}
- kfree(ac->eqs);
- ac->eqs = NULL;
+ kfree(apc->eqs);
+ apc->eqs = NULL;
}
+EXPORT_SYMBOL_NS(mana_destroy_eq, "NET_MANA");
-static void mana_create_eq_debugfs(struct mana_context *ac, int i)
+static void mana_create_eq_debugfs(struct mana_port_context *apc, int i)
{
- struct mana_eq eq = ac->eqs[i];
+ struct mana_eq eq = apc->eqs[i];
char eqnum[32];
sprintf(eqnum, "eq%d", i);
- eq.mana_eq_debugfs = debugfs_create_dir(eqnum, ac->mana_eqs_debugfs);
+ eq.mana_eq_debugfs = debugfs_create_dir(eqnum, apc->mana_eqs_debugfs);
debugfs_create_u32("head", 0400, eq.mana_eq_debugfs, &eq.eq->head);
debugfs_create_u32("tail", 0400, eq.mana_eq_debugfs, &eq.eq->tail);
debugfs_create_file("eq_dump", 0400, eq.mana_eq_debugfs, eq.eq, &mana_dbg_q_fops);
}
-static int mana_create_eq(struct mana_context *ac)
+int mana_create_eq(struct mana_port_context *apc)
{
- struct gdma_dev *gd = ac->gdma_dev;
+ struct gdma_dev *gd = apc->ac->gdma_dev;
struct gdma_context *gc = gd->gdma_context;
struct gdma_queue_spec spec = {};
int err;
int i;
- ac->eqs = kzalloc_objs(struct mana_eq, gc->max_num_queues);
- if (!ac->eqs)
+ if (WARN_ON(apc->eqs))
+ return -EEXIST;
+ apc->eqs = kzalloc_objs(struct mana_eq, apc->num_queues);
+ if (!apc->eqs)
return -ENOMEM;
spec.type = GDMA_EQ;
spec.monitor_avl_buf = false;
spec.queue_size = EQ_SIZE;
spec.eq.callback = NULL;
- spec.eq.context = ac->eqs;
+ spec.eq.context = apc->eqs;
spec.eq.log2_throttle_limit = LOG2_EQ_THROTTLE;
- ac->mana_eqs_debugfs = debugfs_create_dir("EQs", gc->mana_pci_debugfs);
+ apc->mana_eqs_debugfs =
+ debugfs_create_dir("EQs", apc->mana_port_debugfs);
- for (i = 0; i < gc->max_num_queues; i++) {
+ for (i = 0; i < apc->num_queues; i++) {
spec.eq.msix_index = (i + 1) % gc->num_msix_usable;
- err = mana_gd_create_mana_eq(gd, &spec, &ac->eqs[i].eq);
+ err = mana_gd_create_mana_eq(gd, &spec, &apc->eqs[i].eq);
if (err) {
dev_err(gc->dev, "Failed to create EQ %d : %d\n", i, err);
goto out;
}
- mana_create_eq_debugfs(ac, i);
+ mana_create_eq_debugfs(apc, i);
}
return 0;
out:
- mana_destroy_eq(ac);
+ mana_destroy_eq(apc);
return err;
}
+EXPORT_SYMBOL_NS(mana_create_eq, "NET_MANA");
static int mana_fence_rq(struct mana_port_context *apc, struct mana_rxq *rxq)
{
@@ -2484,7 +2502,7 @@ static int mana_create_txq(struct mana_port_context *apc,
spec.monitor_avl_buf = false;
spec.queue_size = cq_size;
spec.cq.callback = mana_schedule_napi;
- spec.cq.parent_eq = ac->eqs[i].eq;
+ spec.cq.parent_eq = apc->eqs[i].eq;
spec.cq.context = cq;
err = mana_gd_create_mana_wq_cq(gd, &spec, &cq->gdma_cq);
if (err)
@@ -2882,13 +2900,12 @@ static void mana_create_rxq_debugfs(struct mana_port_context *apc, int idx)
static int mana_add_rx_queues(struct mana_port_context *apc,
struct net_device *ndev)
{
- struct mana_context *ac = apc->ac;
struct mana_rxq *rxq;
int err = 0;
int i;
for (i = 0; i < apc->num_queues; i++) {
- rxq = mana_create_rxq(apc, i, &ac->eqs[i], ndev);
+ rxq = mana_create_rxq(apc, i, &apc->eqs[i], ndev);
if (!rxq) {
err = -ENOMEM;
netdev_err(ndev, "Failed to create rxq %d : %d\n", i, err);
@@ -2907,9 +2924,8 @@ static int mana_add_rx_queues(struct mana_port_context *apc,
return err;
}
-static void mana_destroy_vport(struct mana_port_context *apc)
+static void mana_destroy_rxqs(struct mana_port_context *apc)
{
- struct gdma_dev *gd = apc->ac->gdma_dev;
struct mana_rxq *rxq;
u32 rxq_idx;
@@ -2924,8 +2940,12 @@ static void mana_destroy_vport(struct mana_port_context *apc)
apc->rxqs[rxq_idx] = NULL;
}
}
+}
+
+static void mana_destroy_vport(struct mana_port_context *apc)
+{
+ struct gdma_dev *gd = apc->ac->gdma_dev;
- mana_destroy_txq(apc);
mana_uncfg_vport(apc);
if (gd->gdma_context->is_pf && !apc->ac->bm_hostmode)
@@ -2946,11 +2966,14 @@ static int mana_create_vport(struct mana_port_context *apc,
return err;
}
- err = mana_cfg_vport(apc, gd->pdid, gd->doorbell);
- if (err)
+ err = mana_cfg_vport(apc, gd->pdid, gd->doorbell, false);
+ if (err) {
+ if (gd->gdma_context->is_pf && !apc->ac->bm_hostmode)
+ mana_pf_deregister_hw_vport(apc);
return err;
+ }
- return mana_create_txq(apc, net);
+ return 0;
}
static int mana_rss_table_alloc(struct mana_port_context *apc)
@@ -3236,21 +3259,36 @@ int mana_alloc_queues(struct net_device *ndev)
err = mana_create_vport(apc, ndev);
if (err) {
- netdev_err(ndev, "Failed to create vPort %u : %d\n", apc->port_idx, err);
+ netdev_err(ndev, "Failed to create vPort %u : %d\n",
+ apc->port_idx, err);
return err;
}
+ err = mana_create_eq(apc);
+ if (err) {
+ netdev_err(ndev, "Failed to create EQ on vPort %u: %d\n",
+ apc->port_idx, err);
+ goto destroy_vport;
+ }
+
+ err = mana_create_txq(apc, ndev);
+ if (err) {
+ netdev_err(ndev, "Failed to create TXQ on vPort %u: %d\n",
+ apc->port_idx, err);
+ goto destroy_eq;
+ }
+
err = netif_set_real_num_tx_queues(ndev, apc->num_queues);
if (err) {
netdev_err(ndev,
"netif_set_real_num_tx_queues () failed for ndev with num_queues %u : %d\n",
apc->num_queues, err);
- goto destroy_vport;
+ goto destroy_txq;
}
err = mana_add_rx_queues(apc, ndev);
if (err)
- goto destroy_vport;
+ goto destroy_rxq;
apc->rss_state = apc->num_queues > 1 ? TRI_STATE_TRUE : TRI_STATE_FALSE;
@@ -3259,7 +3297,7 @@ int mana_alloc_queues(struct net_device *ndev)
netdev_err(ndev,
"netif_set_real_num_rx_queues () failed for ndev with num_queues %u : %d\n",
apc->num_queues, err);
- goto destroy_vport;
+ goto destroy_rxq;
}
mana_rss_table_init(apc);
@@ -3267,19 +3305,25 @@ int mana_alloc_queues(struct net_device *ndev)
err = mana_config_rss(apc, TRI_STATE_TRUE, true, true);
if (err) {
netdev_err(ndev, "Failed to configure RSS table: %d\n", err);
- goto destroy_vport;
+ goto destroy_rxq;
}
if (gd->gdma_context->is_pf && !apc->ac->bm_hostmode) {
err = mana_pf_register_filter(apc);
if (err)
- goto destroy_vport;
+ goto destroy_rxq;
}
mana_chn_setxdp(apc, mana_xdp_get(apc));
return 0;
+destroy_rxq:
+ mana_destroy_rxqs(apc);
+destroy_txq:
+ mana_destroy_txq(apc);
+destroy_eq:
+ mana_destroy_eq(apc);
destroy_vport:
mana_destroy_vport(apc);
return err;
@@ -3390,6 +3434,9 @@ static int mana_dealloc_queues(struct net_device *ndev)
mana_fence_rqs(apc);
/* Even in err case, still need to cleanup the vPort */
+ mana_destroy_rxqs(apc);
+ mana_destroy_txq(apc);
+ mana_destroy_eq(apc);
mana_destroy_vport(apc);
return 0;
@@ -3716,12 +3763,6 @@ int mana_probe(struct gdma_dev *gd, bool resuming)
INIT_DELAYED_WORK(&ac->gf_stats_work, mana_gf_stats_work_handler);
- err = mana_create_eq(ac);
- if (err) {
- dev_err(dev, "Failed to create EQs: %d\n", err);
- goto out;
- }
-
err = mana_query_device_cfg(ac, MANA_MAJOR_VERSION, MANA_MINOR_VERSION,
MANA_MICRO_VERSION, &num_ports, &bm_hostmode);
if (err)
@@ -3861,8 +3902,6 @@ void mana_remove(struct gdma_dev *gd, bool suspending)
free_netdev(ndev);
}
- mana_destroy_eq(ac);
-
if (ac->per_port_queue_reset_wq) {
destroy_workqueue(ac->per_port_queue_reset_wq);
ac->per_port_queue_reset_wq = NULL;
diff --git a/drivers/net/ethernet/microsoft/mana/mana_ethtool.c b/drivers/net/ethernet/microsoft/mana/mana_ethtool.c
index 6a4b42fe09445..a9440c4b8825b 100644
--- a/drivers/net/ethernet/microsoft/mana/mana_ethtool.c
+++ b/drivers/net/ethernet/microsoft/mana/mana_ethtool.c
@@ -454,6 +454,11 @@ static int mana_set_coalesce(struct net_device *ndev,
return err;
}
+/* mana_set_channels - change the number of queues on a port
+ *
+ * Returns -EBUSY if RDMA holds the vport with EQs sized to the
+ * current num_queues.
+ */
static int mana_set_channels(struct net_device *ndev,
struct ethtool_channels *channels)
{
@@ -462,10 +467,22 @@ static int mana_set_channels(struct net_device *ndev,
unsigned int old_count = apc->num_queues;
int err;
+ /* Set channel_changing to block RDMA from grabbing the vport
+ * during the detach/attach window. mana_cfg_vport() checks
+ * this flag under vport_mutex and returns -EBUSY if set.
+ */
+ mutex_lock(&apc->vport_mutex);
+ if (!apc->port_is_up && apc->vport_use_count) {
+ mutex_unlock(&apc->vport_mutex);
+ return -EBUSY;
+ }
+ apc->channel_changing = true;
+ mutex_unlock(&apc->vport_mutex);
+
err = mana_pre_alloc_rxbufs(apc, ndev->mtu, new_count);
if (err) {
netdev_err(ndev, "Insufficient memory for new allocations");
- return err;
+ goto clear_flag;
}
err = mana_detach(ndev, false);
@@ -483,6 +500,10 @@ static int mana_set_channels(struct net_device *ndev,
out:
mana_pre_dealloc_rxbufs(apc);
+clear_flag:
+ mutex_lock(&apc->vport_mutex);
+ apc->channel_changing = false;
+ mutex_unlock(&apc->vport_mutex);
return err;
}
diff --git a/include/net/mana/mana.h b/include/net/mana/mana.h
index 4111b93169d2f..f8e05456888e4 100644
--- a/include/net/mana/mana.h
+++ b/include/net/mana/mana.h
@@ -488,8 +488,6 @@ struct mana_context {
u8 bm_hostmode;
struct mana_ethtool_hc_stats hc_stats;
- struct mana_eq *eqs;
- struct dentry *mana_eqs_debugfs;
struct workqueue_struct *per_port_queue_reset_wq;
/* Workqueue for querying hardware stats */
struct delayed_work gf_stats_work;
@@ -509,6 +507,9 @@ struct mana_port_context {
u8 mac_addr[ETH_ALEN];
+ struct mana_eq *eqs;
+ struct dentry *mana_eqs_debugfs;
+
enum TRI_STATE rss_state;
mana_handle_t default_rxobj;
@@ -555,6 +556,12 @@ struct mana_port_context {
struct mutex vport_mutex;
int vport_use_count;
+ /* Set by mana_set_channels() under vport_mutex to block RDMA
+ * from grabbing the vport during the detach/attach window.
+ * Checked by mana_cfg_vport() when called from the RDMA path.
+ */
+ bool channel_changing;
+
/* Net shaper handle*/
struct net_shaper_handle handle;
@@ -1040,8 +1047,10 @@ void mana_destroy_wq_obj(struct mana_port_context *apc, u32 wq_type,
mana_handle_t wq_obj);
int mana_cfg_vport(struct mana_port_context *apc, u32 protection_dom_id,
- u32 doorbell_pg_id);
+ u32 doorbell_pg_id, bool check_channel_changing);
void mana_uncfg_vport(struct mana_port_context *apc);
+int mana_create_eq(struct mana_port_context *apc);
+void mana_destroy_eq(struct mana_port_context *apc);
struct net_device *mana_get_primary_netdev(struct mana_context *ac,
u32 port_index,
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 179/438] net: mana: Return error code from mana_create_rxq()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 178/438] net: mana: Create separate EQs for each vPort Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 180/438] ptp: netc: fix potential interrupt storm caused by incorrect unbind order Greg Kroah-Hartman
` (272 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aditya Garg, Joe Damato,
Jakub Kicinski, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aditya Garg <gargaditya@linux.microsoft.com>
[ Upstream commit e67cc80b50f587cd1d8ffc8989dcec3291720bc3 ]
mana_create_rxq() returns a struct mana_rxq pointer and returns NULL on
any failure. The caller, mana_add_rx_queues(), cannot tell what went
wrong and hardcodes the error as -ENOMEM. As a result the actual failure
reported by the lower layers (for example -EPROTO from a failed HW
request) is masked and every RX queue creation failure looks like an
out-of-memory error.
Return an ERR_PTR() encoded error code from mana_create_rxq() on failure
instead of NULL. The caller now propagates the returned error code
directly instead of substituting -ENOMEM.
Fixes: ca9c54d2d6a5 ("net: mana: Add a driver for Microsoft Azure Network Adapter (MANA)")
Signed-off-by: Aditya Garg <gargaditya@linux.microsoft.com>
Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260727113759.2881500-1-gargaditya@linux.microsoft.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/microsoft/mana/mana_en.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/microsoft/mana/mana_en.c b/drivers/net/ethernet/microsoft/mana/mana_en.c
index 9d8c91d36b3bc..7e6bc6e5ff232 100644
--- a/drivers/net/ethernet/microsoft/mana/mana_en.c
+++ b/drivers/net/ethernet/microsoft/mana/mana_en.c
@@ -2771,7 +2771,7 @@ static struct mana_rxq *mana_create_rxq(struct mana_port_context *apc,
rxq = kzalloc_flex(*rxq, rx_oobs, apc->rx_queue_size);
if (!rxq)
- return NULL;
+ return ERR_PTR(-ENOMEM);
rxq->ndev = ndev;
rxq->num_rx_buf = apc->rx_queue_size;
@@ -2872,7 +2872,7 @@ static struct mana_rxq *mana_create_rxq(struct mana_port_context *apc,
mana_destroy_rxq(apc, rxq, false);
- return NULL;
+ return ERR_PTR(err);
}
static void mana_create_rxq_debugfs(struct mana_port_context *apc, int idx)
@@ -2906,8 +2906,8 @@ static int mana_add_rx_queues(struct mana_port_context *apc,
for (i = 0; i < apc->num_queues; i++) {
rxq = mana_create_rxq(apc, i, &apc->eqs[i], ndev);
- if (!rxq) {
- err = -ENOMEM;
+ if (IS_ERR(rxq)) {
+ err = PTR_ERR(rxq);
netdev_err(ndev, "Failed to create rxq %d : %d\n", i, err);
goto out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 180/438] ptp: netc: fix potential interrupt storm caused by incorrect unbind order
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 179/438] net: mana: Return error code from mana_create_rxq() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 181/438] net: libwx: fix FDIR ATR queue mismatch for software VLAN packets Greg Kroah-Hartman
` (271 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Wei Fang, Jakub Kicinski,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Fang <wei.fang@nxp.com>
[ Upstream commit 54ad7ea45d63146a8e3c57375f8a269d4cf7ecea ]
In netc_timer_remove(), hardware interrupts are disabled by clearing
TMR_TEMASK before ptp_clock_unregister() is called. This may cause a
race condition during driver unbind that could leave hardware interrupts
active. For example, a concurrent PTP_CLK_REQ_EXTTS ioctl can re-enable
TMR_TEMASK after it has been cleared, leaving a pending hardware
interrupt when the driver unbinds.
Since the NETC Timer does not support PCIe FLR, hardware state is not
reset during probe. When the driver is rebound and the IRQ is registered,
the pending interrupt fires immediately. At that point priv->tmr_emask
is still zero, so netc_timer_isr() does not clear the interrupt status
and unconditionally returns IRQ_HANDLED, resulting in an uninterruptible
infinite interrupt storm.
Fix this in several ways. First, request the IRQ with IRQF_NO_AUTOEN so
it is not enabled when request_irq() runs, and clear TMR_TEMASK in
netc_timer_init() before enabling it. The IRQ is only enabled at the end
of probe once the timer has been reprogrammed and the PTP clock has been
registered. This ensures a stale pending interrupt from a previous unbind
or an unclean shutdown cannot be delivered before the driver is fully
initialized.
Second, in netc_timer_remove() call disable_irq() before
ptp_clock_unregister() and move the TMR_TEMASK/TMR_CTRL clearing after
it. disable_irq() masks the line and waits for any in-flight
netc_timer_isr() to finish, so no ISR can dereference priv->clock after
ptp_clock_unregister() has freed it. Unregistering the PTP clock before
clearing the mask also guarantees that no in-flight or concurrent ioctl
can re-enable hardware interrupts.
Finally, return IRQ_NONE from netc_timer_isr() when the masked event
status is zero, so the kernel's spurious interrupt detection can disable
a stuck line instead of looping forever.
Fixes: 671e266835b8 ("ptp: netc: add periodic pulse output support")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260720012508.23227-1-wei.fang%40oss.nxp.com
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260727060348.1887464-1-wei.fang@oss.nxp.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ptp/ptp_netc.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/ptp/ptp_netc.c b/drivers/ptp/ptp_netc.c
index 5e381c354d746..1c20d7efab929 100644
--- a/drivers/ptp/ptp_netc.c
+++ b/drivers/ptp/ptp_netc.c
@@ -769,6 +769,7 @@ static void netc_timer_init(struct netc_timer *priv)
TMR_CTRL_TE | TMR_CTRL_FS;
netc_timer_wr(priv, NETC_TMR_CTRL, tmr_ctrl);
netc_timer_wr(priv, NETC_TMR_PRSC, priv->oclk_prsc);
+ netc_timer_wr(priv, NETC_TMR_TEMASK, 0);
/* Disable FIPER by default */
fiper_ctrl = netc_timer_rd(priv, NETC_TMR_FIPER_CTRL);
@@ -901,6 +902,11 @@ static irqreturn_t netc_timer_isr(int irq, void *data)
/* Clear interrupts status */
netc_timer_wr(priv, NETC_TMR_TEVENT, tmr_event);
+ if (!tmr_event) {
+ spin_unlock(&priv->lock);
+ return IRQ_NONE;
+ }
+
if (tmr_event & TMR_TEVENT_ALMEN(0))
netc_timer_alarm_write(priv, NETC_TMR_DEFAULT_ALARM, 0);
@@ -936,7 +942,8 @@ static int netc_timer_init_msix_irq(struct netc_timer *priv)
}
priv->irq = pci_irq_vector(pdev, 0);
- err = request_irq(priv->irq, netc_timer_isr, 0, priv->irq_name, priv);
+ err = request_irq(priv->irq, netc_timer_isr, IRQF_NO_AUTOEN,
+ priv->irq_name, priv);
if (err) {
dev_err(&pdev->dev, "request_irq() failed\n");
pci_free_irq_vectors(pdev);
@@ -951,7 +958,6 @@ static void netc_timer_free_msix_irq(struct netc_timer *priv)
{
struct pci_dev *pdev = priv->pdev;
- disable_irq(priv->irq);
free_irq(priv->irq, priv);
pci_free_irq_vectors(pdev);
}
@@ -1005,6 +1011,8 @@ static int netc_timer_probe(struct pci_dev *pdev,
goto free_msix_irq;
}
+ enable_irq(priv->irq);
+
return 0;
free_msix_irq:
@@ -1019,9 +1027,10 @@ static void netc_timer_remove(struct pci_dev *pdev)
{
struct netc_timer *priv = pci_get_drvdata(pdev);
+ disable_irq(priv->irq);
+ ptp_clock_unregister(priv->clock);
netc_timer_wr(priv, NETC_TMR_TEMASK, 0);
netc_timer_wr(priv, NETC_TMR_CTRL, 0);
- ptp_clock_unregister(priv->clock);
netc_timer_free_msix_irq(priv);
netc_timer_pci_remove(pdev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 181/438] net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 180/438] ptp: netc: fix potential interrupt storm caused by incorrect unbind order Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 182/438] octeontx2-pf: Set correct sequence for carrier off and tx queue stop Greg Kroah-Hartman
` (270 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiawen Wu, Simon Horman, Paolo Abeni,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiawen Wu <jiawenwu@trustnetic.com>
[ Upstream commit 732ed8f75ce583d115716f668dc80d730f3ad610 ]
When TX VLAN hardware offload is disabled, VLAN tags are embedded in
the packet payload (software VLAN). Previously, the driver failed to
set the WX_TX_FLAGS_SW_VLAN flag for these packets during transmission.
This missing flag caused the txgbe FDIR ATR logic to fall through to the
default hash calculation path. This resulted in asymmetric hash values
for Tx and Rx flows, preventing return packets from being steered to the
same queue as the transmit packets.
Fix this by detecting software VLANs via eth_type_vlan(skb->protocol)
and setting WX_TX_FLAGS_SW_VLAN. This ensures the ATR feature selects
the correct hashing algorithm to maintain Tx/Rx queue symmetry.
Fixes: b501d261a5b3 ("net: txgbe: add FDIR ATR support")
Signed-off-by: Jiawen Wu <jiawenwu@trustnetic.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/0879DA38A8E32701+20260724074657.10773-1-jiawenwu@trustnetic.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/wangxun/libwx/wx_lib.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_lib.c b/drivers/net/ethernet/wangxun/libwx/wx_lib.c
index 5c2cd5756f8a9..a553365b69943 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_lib.c
+++ b/drivers/net/ethernet/wangxun/libwx/wx_lib.c
@@ -1606,6 +1606,8 @@ static netdev_tx_t wx_xmit_frame_ring(struct sk_buff *skb,
if (skb_vlan_tag_present(skb)) {
tx_flags |= skb_vlan_tag_get(skb) << WX_TX_FLAGS_VLAN_SHIFT;
tx_flags |= WX_TX_FLAGS_HW_VLAN;
+ } else if (eth_type_vlan(skb->protocol)) {
+ tx_flags |= WX_TX_FLAGS_SW_VLAN;
}
if (unlikely(skb_shinfo(skb)->tx_flags & SKBTX_HW_TSTAMP) &&
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 182/438] octeontx2-pf: Set correct sequence for carrier off and tx queue stop
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 181/438] net: libwx: fix FDIR ATR queue mismatch for software VLAN packets Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 183/438] sched/deadline: Use revised wakeup rule only for running dl_server Greg Kroah-Hartman
` (269 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Suman Ghosh, Ratheesh Kannoth,
Simon Horman, Paolo Abeni, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Suman Ghosh <sumang@marvell.com>
[ Upstream commit 16809472409d998afcda402e32b8229b389337c4 ]
During link down event, we were doing netif_tx_stop_all_queues() first
and then netif_carrier_off(). This can cause a potential race since
carrier is still on during down event. This patch reverse the calling
order to fix the issue.
Fixes: 50fe6c02e5ad ("octeontx2-pf: Register and handle link notifications")
Signed-off-by: Suman Ghosh <sumang@marvell.com>
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260724072831.2415281-1-rkannoth@marvell.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
index 2e33b33ec9934..c995f29008590 100644
--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
+++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
@@ -889,8 +889,8 @@ static void otx2_handle_link_event(struct otx2_nic *pf)
netif_carrier_on(netdev);
netif_tx_start_all_queues(netdev);
} else {
- netif_tx_stop_all_queues(netdev);
netif_carrier_off(netdev);
+ netif_tx_stop_all_queues(netdev);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 183/438] sched/deadline: Use revised wakeup rule only for running dl_server
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 182/438] octeontx2-pf: Set correct sequence for carrier off and tx queue stop Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 184/438] spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs Greg Kroah-Hartman
` (268 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gabriele Monaco,
Peter Zijlstra (Intel), Juri Lelli, Andrea Righi, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gabriele Monaco <gmonaco@redhat.com>
[ Upstream commit 1842bf97af109f5ebf830175c9725bf81ebb78b1 ]
Commit 14a857056466 ("sched/deadline: Use revised wakeup rule for
dl_server") applies the revised wakeup rule to any server, as a result
servers that are not running (dl_defer_running == 0) and start with a
deadline overflow get enqueued and can boost tasks as if they were
running, invalidating the defer rule and the documented state model.
Apply the revised wakeup rule only for deferrable servers that are
marked as running.
Fixes: 14a857056466 ("sched/deadline: Use revised wakeup rule for dl_server")
Signed-off-by: Gabriele Monaco <gmonaco@redhat.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Juri Lelli <juri.lelli@redhat.com>
Tested-by: Andrea Righi <arighi@nvidia.com>
Link: https://patch.msgid.link/20260522125833.264145-1-gmonaco@redhat.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/deadline.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/kernel/sched/deadline.c b/kernel/sched/deadline.c
index 7db4c87df83b0..e5a7701a8af71 100644
--- a/kernel/sched/deadline.c
+++ b/kernel/sched/deadline.c
@@ -1017,7 +1017,8 @@ static void update_dl_entity(struct sched_dl_entity *dl_se)
if (dl_time_before(dl_se->deadline, rq_clock(rq)) ||
dl_entity_overflow(dl_se, rq_clock(rq))) {
- if (unlikely((!dl_is_implicit(dl_se) || dl_se->dl_defer) &&
+ if (unlikely((!dl_is_implicit(dl_se) ||
+ (dl_se->dl_defer && dl_se->dl_defer_running)) &&
!dl_time_before(dl_se->deadline, rq_clock(rq)) &&
!is_dl_boosted(dl_se))) {
update_dl_revised_wakeup(dl_se, rq);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 184/438] spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 183/438] sched/deadline: Use revised wakeup rule only for running dl_server Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 185/438] qede: sync udp_tunnel ports outside qede_lock in the recovery path Greg Kroah-Hartman
` (267 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Haibo Chen, Mark Brown, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haibo Chen <haibo.chen@nxp.com>
[ Upstream commit 9c19d60fea9f46ed0c3394653ef4941f1a459968 ]
The commit f43579ef3500 ("spi: spi-nxp-fspi: limit the clock rate for
different sample clock source selection") introduced a global 166MHz
cap for DTR mode (RXCLKSRC=3), based on the i.MX8MN datasheet timing
specification (Section 3.9.9, page 65).
After reviewing the FlexSPI timing parameters in the datasheets for all
supported SoCs, the following corrections and additions are needed:
1. SDR mode (RXCLKSRC=0) limits vary per SoC:
- i.MX8MN/MM/MP/95: 66MHz (IMX8MNCEC §3.9.9, IMX8MMCEC §3.9.10,
IMX8MPCEC, IMX95CEC Rev.8 §4.11.7)
- i.MX8QXP/QM/DXL/ULP: 60MHz (IMX8QXPCEC, IMX8QMCEC, IMX8DXLCEC,
IMX8ULPCEC §7.3.1 ND mode)
- LX2160A: 100MHz (LX2160ACEC FlexSPI timing parameters)
2. DTR mode (RXCLKSRC=3) limits vary per SoC:
- i.MX8MN/MM/MP/ULP: 166MHz
- i.MX8QXP/QM/DXL: 200MHz (same FlexSPI IP across this family)
- i.MX95: 200MHz (IMX95CEC §4.11.7.3.2.3 Table 106)
- LX2160A: DTR disabled (FSPI_QUIRK_DISABLE_DTR)
Update related platform data with correct speed limation according
to datasheet.
Fixes: f43579ef3500 ("spi: spi-nxp-fspi: limit the clock rate for different sample clock source selection")
Signed-off-by: Haibo Chen <haibo.chen@nxp.com>
Link: https://patch.msgid.link/20260728-fspi-clock-v2-1-dbe786a4a6eb@nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-nxp-fspi.c | 83 ++++++++++++++++++++++++++++++++++++--
1 file changed, 80 insertions(+), 3 deletions(-)
diff --git a/drivers/spi/spi-nxp-fspi.c b/drivers/spi/spi-nxp-fspi.c
index 1e36ae084dd86..39c1eaaf9e0ae 100644
--- a/drivers/spi/spi-nxp-fspi.c
+++ b/drivers/spi/spi-nxp-fspi.c
@@ -340,6 +340,18 @@ struct nxp_fspi_devtype_data {
unsigned int quirks;
unsigned int lut_num;
bool little_endian;
+ /*
+ * The max clock rate (Hz) that FlexSPI can output to the device
+ * in SDR mode (RXCLKSRC=0). Defaults to 66MHz if zero.
+ * Some SoCs (e.g. LX2160A) support up to 100MHz in SDR mode.
+ */
+ unsigned long max_sdr_rate;
+ /*
+ * The max clock rate (Hz) that FlexSPI can output to the device
+ * in DTR mode (RXCLKSRC=3). Defaults to 166MHz if zero.
+ * Some SoCs (e.g. i.MX95, i.MX8QM, i.MX8DXL) support up to 200MHz.
+ */
+ unsigned long max_dtr_rate;
};
static struct nxp_fspi_devtype_data lx2160a_data = {
@@ -349,6 +361,10 @@ static struct nxp_fspi_devtype_data lx2160a_data = {
.quirks = FSPI_QUIRK_DISABLE_DTR,
.lut_num = 32,
.little_endian = true, /* little-endian */
+ /*
+ * LX2160ACEC: SDR RXCLKSRC=0 max 100MHz, DTR disabled via quirk.
+ */
+ .max_sdr_rate = 100000000,
};
static struct nxp_fspi_devtype_data imx8mm_data = {
@@ -358,6 +374,21 @@ static struct nxp_fspi_devtype_data imx8mm_data = {
.quirks = 0,
.lut_num = 32,
.little_endian = true, /* little-endian */
+ /* IMX8MMCEC §3.9.10: SDR RXCLKSRC=0 max 66MHz, DDR RXCLKSRC=3 max 166MHz */
+ .max_sdr_rate = 66000000,
+ .max_dtr_rate = 166000000,
+};
+
+static struct nxp_fspi_devtype_data imx8mp_data = {
+ .rxfifo = SZ_512, /* (64 * 64 bits) */
+ .txfifo = SZ_1K, /* (128 * 64 bits) */
+ .ahb_buf_size = SZ_2K, /* (256 * 64 bits) */
+ .quirks = 0,
+ .lut_num = 32,
+ .little_endian = true, /* little-endian */
+ /* IMX8MPCEC: SDR RXCLKSRC=0 max 66MHz, DDR RXCLKSRC=3 max 166MHz */
+ .max_sdr_rate = 66000000,
+ .max_dtr_rate = 166000000,
};
static struct nxp_fspi_devtype_data imx8qxp_data = {
@@ -367,6 +398,12 @@ static struct nxp_fspi_devtype_data imx8qxp_data = {
.quirks = 0,
.lut_num = 32,
.little_endian = true, /* little-endian */
+ /*
+ * IMX8QXPCEC: SDR RXCLKSRC=0 max 60MHz, DDR RXCLKSRC=3 max 200MHz.
+ * i.MX8QM and i.MX8DXL share the same FlexSPI IP and limits.
+ */
+ .max_sdr_rate = 60000000,
+ .max_dtr_rate = 200000000,
};
static struct nxp_fspi_devtype_data imx8dxl_data = {
@@ -376,6 +413,12 @@ static struct nxp_fspi_devtype_data imx8dxl_data = {
.quirks = FSPI_QUIRK_USE_IP_ONLY,
.lut_num = 32,
.little_endian = true, /* little-endian */
+ /*
+ * IMX8DXLCEC (i.MX 8XLite): SDR RXCLKSRC=0 max 60MHz,
+ * DDR RXCLKSRC=3 max 200MHz.
+ */
+ .max_sdr_rate = 60000000,
+ .max_dtr_rate = 200000000,
};
static struct nxp_fspi_devtype_data imx8ulp_data = {
@@ -385,6 +428,29 @@ static struct nxp_fspi_devtype_data imx8ulp_data = {
.quirks = 0,
.lut_num = 16,
.little_endian = true, /* little-endian */
+ /*
+ * IMX8ULPCEC §7.3.1, Normal Drive (ND, 1.0V) mode:
+ * SDR RXCLKSRC=0 max 60MHz, DDR RXCLKSRC=3 max 166MHz.
+ * Note: Overdrive (OD, 1.05V) allows up to 180MHz DTR
+ * but is not the default use case.
+ */
+ .max_sdr_rate = 60000000,
+ .max_dtr_rate = 166000000,
+};
+
+static struct nxp_fspi_devtype_data imx95_data = {
+ .rxfifo = SZ_512, /* (64 * 64 bits) */
+ .txfifo = SZ_1K, /* (128 * 64 bits) */
+ .ahb_buf_size = SZ_2K, /* (256 * 64 bits) */
+ .quirks = 0,
+ .lut_num = 32,
+ .little_endian = true, /* little-endian */
+ /*
+ * IMX95CEC Rev.8 §4.11.7: SDR RXCLKSRC=0 max 66MHz,
+ * DDR RXCLKSRC=3 max 200MHz (Nominal/Overdrive mode).
+ */
+ .max_sdr_rate = 66000000,
+ .max_dtr_rate = 200000000,
};
struct nxp_fspi {
@@ -691,10 +757,20 @@ static void nxp_fspi_select_rx_sample_clk_source(struct nxp_fspi *f,
reg = fspi_readl(f, f->iobase + FSPI_MCR0);
if (op_is_dtr) {
reg |= FSPI_MCR0_RXCLKSRC(3);
- f->max_rate = 166000000;
+ /*
+ * Use the SoC-specific DTR max rate if provided, otherwise
+ * fall back to 166MHz (limit from IMX8MN datasheet §3.9.9).
+ */
+ f->max_rate = f->devtype_data->max_dtr_rate ?
+ f->devtype_data->max_dtr_rate : 166000000;
} else { /*select mode 0 */
reg &= ~FSPI_MCR0_RXCLKSRC(3);
- f->max_rate = 66000000;
+ /*
+ * Use the SoC-specific SDR max rate if provided, otherwise
+ * fall back to 66MHz (limit from IMX8MN datasheet §3.9.9).
+ */
+ f->max_rate = f->devtype_data->max_sdr_rate ?
+ f->devtype_data->max_sdr_rate : 66000000;
}
fspi_writel(f, reg, f->iobase + FSPI_MCR0);
}
@@ -1444,10 +1520,11 @@ static const struct dev_pm_ops nxp_fspi_pm_ops = {
static const struct of_device_id nxp_fspi_dt_ids[] = {
{ .compatible = "nxp,lx2160a-fspi", .data = (void *)&lx2160a_data, },
{ .compatible = "nxp,imx8mm-fspi", .data = (void *)&imx8mm_data, },
- { .compatible = "nxp,imx8mp-fspi", .data = (void *)&imx8mm_data, },
+ { .compatible = "nxp,imx8mp-fspi", .data = (void *)&imx8mp_data, },
{ .compatible = "nxp,imx8qxp-fspi", .data = (void *)&imx8qxp_data, },
{ .compatible = "nxp,imx8dxl-fspi", .data = (void *)&imx8dxl_data, },
{ .compatible = "nxp,imx8ulp-fspi", .data = (void *)&imx8ulp_data, },
+ { .compatible = "nxp,imx95-fspi", .data = (void *)&imx95_data, },
{ /* sentinel */ }
};
MODULE_DEVICE_TABLE(of, nxp_fspi_dt_ids);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 185/438] qede: sync udp_tunnel ports outside qede_lock in the recovery path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (183 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 184/438] spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 186/438] drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status Greg Kroah-Hartman
` (266 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Denis V. Lunev, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Jacob Keller, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Denis V. Lunev <den@openvz.org>
[ Upstream commit 451c9075d6c53f2438d110addbeeeea6fac18567 ]
A TX timeout on a qede NIC that has VXLAN/GENEVE tunnel ports
configured wedges the rtnetlink control plane of the whole machine:
NETDEV WATCHDOG: ens6f1 (qede): transmit queue 2 timed out 10226 ms
[qede_tx_timeout:586(ens6f1)]TX timeout on queue 2!
[qede_recovery_handler:2665(ens6f0)]Starting a recovery process
The recovery path deadlocks on the driver's own mutex:
qede_sp_task
rtnl_lock()
mutex_lock(&edev->qede_lock) <- taken
qede_recovery_handler
qede_load
udp_tunnel_nic_reset_ntf
__udp_tunnel_nic_device_sync
info->sync_table == qede_udp_tunnel_sync
mutex_lock(&edev->qede_lock) <- same task: deadlock
The mutex is not recursive, so the kworker blocks on itself with
rtnl_lock held, and neither lock is ever released. Every task that
calls rtnl_lock() afterwards (ip, ovs-vswitchd, lldpad, IPv6
addrconf, sshd) blocks forever while the node still answers ping.
In a vmcore from an affected production node rtnl_mutex.owner
decodes to the very kworker blocked at the innermost mutex_lock()
above.
Re-sync the tunnel ports from qede_sp_task() after the internal lock
is dropped, still under rtnl_lock as the udp_tunnel API requires.
This mirrors qede_open(), which calls udp_tunnel_nic_reset_ntf()
under rtnl without the internal lock.
qede_recovery_handler() now returns whether it has successfully
reloaded an open device, and the caller re-syncs the ports only in
that case. This keeps the old gating exactly: a device that was down
or a failed recovery returns false, as those paths never reached the
udp_tunnel_nic_reset_ntf() call before either.
This was the only user of the qede_lock()/qede_unlock() helpers, so
remove them.
Fixes: 8cd160a29415 ("qede: convert to new udp_tunnel_nic infra")
Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Andrew Lunn <andrew+netdev@lunn.ch>
CC: "David S. Miller" <davem@davemloft.net>
CC: Eric Dumazet <edumazet@google.com>
CC: Jakub Kicinski <kuba@kernel.org>
CC: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Link: https://patch.msgid.link/20260726104311.1782900-1-den@openvz.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/qlogic/qede/qede_main.c | 44 ++++++++++----------
1 file changed, 22 insertions(+), 22 deletions(-)
diff --git a/drivers/net/ethernet/qlogic/qede/qede_main.c b/drivers/net/ethernet/qlogic/qede/qede_main.c
index 39842eb73bc33..da92c580a3dcf 100644
--- a/drivers/net/ethernet/qlogic/qede/qede_main.c
+++ b/drivers/net/ethernet/qlogic/qede/qede_main.c
@@ -107,7 +107,7 @@ static void qede_remove(struct pci_dev *pdev);
static void qede_shutdown(struct pci_dev *pdev);
static void qede_link_update(void *dev, struct qed_link_output *link);
static void qede_schedule_recovery_handler(void *dev);
-static void qede_recovery_handler(struct qede_dev *edev);
+static bool qede_recovery_handler(struct qede_dev *edev);
static void qede_schedule_hw_err_handler(void *dev,
enum qed_hw_err_type err_type);
static void qede_get_eth_tlv_data(void *edev, void *data);
@@ -1043,21 +1043,6 @@ void __qede_unlock(struct qede_dev *edev)
mutex_unlock(&edev->qede_lock);
}
-/* This version of the lock should be used when acquiring the RTNL lock is also
- * needed in addition to the internal qede lock.
- */
-static void qede_lock(struct qede_dev *edev)
-{
- rtnl_lock();
- __qede_lock(edev);
-}
-
-static void qede_unlock(struct qede_dev *edev)
-{
- __qede_unlock(edev);
- rtnl_unlock();
-}
-
static void qede_periodic_task(struct work_struct *work)
{
struct qede_dev *edev = container_of(work, struct qede_dev,
@@ -1094,6 +1079,8 @@ static void qede_sp_task(struct work_struct *work)
*/
if (test_and_clear_bit(QEDE_SP_RECOVERY, &edev->sp_flags)) {
+ bool reloaded;
+
cancel_delayed_work_sync(&edev->periodic_task);
#ifdef CONFIG_QED_SRIOV
/* SRIOV must be disabled outside the lock to avoid a deadlock.
@@ -1102,9 +1089,17 @@ static void qede_sp_task(struct work_struct *work)
if (pci_num_vf(edev->pdev))
qede_sriov_configure(edev->pdev, 0);
#endif
- qede_lock(edev);
- qede_recovery_handler(edev);
- qede_unlock(edev);
+ rtnl_lock();
+ __qede_lock(edev);
+ reloaded = qede_recovery_handler(edev);
+ __qede_unlock(edev);
+
+ /* The udp_tunnel core synchronously calls back into
+ * qede_udp_tunnel_sync(), which takes the qede lock.
+ */
+ if (reloaded)
+ udp_tunnel_nic_reset_ntf(edev->ndev);
+ rtnl_unlock();
}
__qede_lock(edev);
@@ -2645,9 +2640,13 @@ static void qede_recovery_failed(struct qede_dev *edev)
edev->ops->common->set_power_state(edev->cdev, PCI_D3hot);
}
-static void qede_recovery_handler(struct qede_dev *edev)
+/* Returns true if an open device was successfully reloaded and its
+ * udp_tunnel ports need to be re-synced by the caller.
+ */
+static bool qede_recovery_handler(struct qede_dev *edev)
{
u32 curr_state = edev->state;
+ bool reloaded = false;
int rc;
DP_NOTICE(edev, "Starting a recovery process\n");
@@ -2677,17 +2676,18 @@ static void qede_recovery_handler(struct qede_dev *edev)
goto err;
qede_config_rx_mode(edev->ndev);
- udp_tunnel_nic_reset_ntf(edev->ndev);
+ reloaded = true;
}
edev->state = curr_state;
DP_NOTICE(edev, "Recovery handling is done\n");
- return;
+ return reloaded;
err:
qede_recovery_failed(edev);
+ return false;
}
static void qede_atomic_hw_err_handler(struct qede_dev *edev)
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 186/438] drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (184 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 185/438] qede: sync udp_tunnel ports outside qede_lock in the recovery path Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 187/438] ksmbd: return success for deferred final close Greg Kroah-Hartman
` (265 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jerome Tollet, Jerome Tollet,
Ankit Nautiyal, Arun R Murthy, Rodrigo Vivi, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jerome Tollet <jerome.tollet@gmail.com>
[ Upstream commit 1afb8eaeec44fd011f2b93ccd9fd426d753d963b ]
HDMI 2.0 section 6.1.3.1 specifies that after enabling
Scrambling_Enable and starting scrambled video transmission, the source
should poll Scrambling_Status until it reads 1 or until a timeout of
200 ms expires.
Add a polling step after enabling the HDMI port to check the scrambling
status when HDMI scrambling is enabled.
On some HDMI 2.0 sinks, omitting this check can result in 4K@60Hz
(594 MHz) failing to come up correctly because the sink has not yet
finished its scrambling setup. In practice, waiting for the scrambling
status here fixes such sinks.
While this synchronous polling is not itself explicitly required for
correct modeset sequencing, HDMI 2.0 section 6.1.3.1 does recommend it
as the way for the source to verify that the TMDS link is functioning
correctly with scrambling enabled.
v3:
- Add explicit HDMI 2.0 section reference in code comment
- Clarify commit message around the observed sink fix
v2:
- Poll TMDS_Scrambler_Status for up to 200 ms instead of using a fixed
delay
Reported-by: Jerome Tollet <jtollet@cisco.com>
Closes: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/6868
Link: https://lore.kernel.org/dri-devel/20251230091037.5603-1-jerome.tollet@gmail.com/
Signed-off-by: Jerome Tollet <jerome.tollet@gmail.com>
Signed-off-by: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Reviewed-by: Arun R Murthy <arun.r.murthy@intel.com>
Link: https://patch.msgid.link/20260520022544.3097252-1-ankit.k.nautiyal@intel.com
(cherry picked from commit b7d51d65e4f12a48392d260613108ec262bc7774)
Fixes: 15953637886d ("drm/i915: enable scrambling")
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/i915/display/intel_ddi.c | 2 ++
drivers/gpu/drm/i915/display/intel_hdmi.c | 26 +++++++++++++++++++++++
drivers/gpu/drm/i915/display/intel_hdmi.h | 2 ++
3 files changed, 30 insertions(+)
diff --git a/drivers/gpu/drm/i915/display/intel_ddi.c b/drivers/gpu/drm/i915/display/intel_ddi.c
index 0987eee38bd13..a3bfb1be51de8 100644
--- a/drivers/gpu/drm/i915/display/intel_ddi.c
+++ b/drivers/gpu/drm/i915/display/intel_ddi.c
@@ -3502,6 +3502,8 @@ static void intel_ddi_enable_hdmi(struct intel_atomic_state *state,
}
intel_ddi_buf_enable(encoder, buf_ctl);
+
+ intel_hdmi_poll_for_scrambling_enable(crtc_state, connector);
}
static void intel_ddi_enable(struct intel_atomic_state *state,
diff --git a/drivers/gpu/drm/i915/display/intel_hdmi.c b/drivers/gpu/drm/i915/display/intel_hdmi.c
index 05e898d10a2be..234866310c14d 100644
--- a/drivers/gpu/drm/i915/display/intel_hdmi.c
+++ b/drivers/gpu/drm/i915/display/intel_hdmi.c
@@ -2693,6 +2693,32 @@ intel_hdmi_add_properties(struct intel_hdmi *intel_hdmi, struct drm_connector *_
drm_connector_attach_max_bpc_property(&connector->base, 8, 12);
}
+/*
+ * HDMI 2.0 spec, section 6.1.3.1 (Scrambling Control): after
+ * enabling Scrambling_Enable and starting scrambled video
+ * transmission, poll Scrambling_Status for up to 200 ms.
+ */
+void
+intel_hdmi_poll_for_scrambling_enable(const struct intel_crtc_state *crtc_state,
+ struct drm_connector *_connector)
+{
+ struct intel_connector *connector = to_intel_connector(_connector);
+ struct intel_display *display = to_intel_display(crtc_state);
+ bool scrambling_enabled = false;
+ int ret;
+
+ if (!crtc_state->hdmi_scrambling)
+ return;
+
+ /* Poll for a max of 200 msec as per HDMI spec */
+ ret = poll_timeout_us(scrambling_enabled = drm_scdc_get_scrambling_status(&connector->base),
+ scrambling_enabled, 1000, 200 * 1000, false);
+ if (ret)
+ drm_dbg_kms(display->drm,
+ "[CONNECTOR:%d:%s] Timed out waiting for scrambling enable\n",
+ connector->base.base.id, connector->base.name);
+}
+
/*
* intel_hdmi_handle_sink_scrambling: handle sink scrambling/clock ratio setup
* @encoder: intel_encoder
diff --git a/drivers/gpu/drm/i915/display/intel_hdmi.h b/drivers/gpu/drm/i915/display/intel_hdmi.h
index be2fad57e4ad0..0fa3661568e86 100644
--- a/drivers/gpu/drm/i915/display/intel_hdmi.h
+++ b/drivers/gpu/drm/i915/display/intel_hdmi.h
@@ -70,5 +70,7 @@ void hsw_read_infoframe(struct intel_encoder *encoder,
const struct intel_crtc_state *crtc_state,
unsigned int type,
void *frame, ssize_t len);
+void intel_hdmi_poll_for_scrambling_enable(const struct intel_crtc_state *crtc_state,
+ struct drm_connector *_connector);
#endif /* __INTEL_HDMI_H__ */
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 187/438] ksmbd: return success for deferred final close
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (185 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 186/438] drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 188/438] ksmbd: fix use-after-free in __close_file_table_ids() Greg Kroah-Hartman
` (264 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit c5db4de8988f1a621556ca5c4537f77b766ca07d ]
ksmbd_close_fd() marks an open file as FP_CLOSED and drops the file table
reference. If another in-flight request still holds a reference, the final
close is deferred until that request drops its reference.
The function currently returns -EINVAL in that deferred-final-close case
because fp is cleared when the reference count does not reach zero. That
turns a valid close into STATUS_FILE_CLOSED.
smb2.compound_find.compound_find_close sends QUERY_DIRECTORY and then
closes the same directory handle before receiving the find response.
The query holds a reference while it builds the response, so close must
mark the handle closed and return success even though final teardown is
delayed. Track whether the handle was successfully transitioned to
FP_CLOSED and return success when only the final close is deferred.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Stable-dep-of: e7188199eff4 ("ksmbd: fix use-after-free in __close_file_table_ids()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/vfs_cache.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/smb/server/vfs_cache.c b/fs/smb/server/vfs_cache.c
index aa0924c9fdf96..b12c0bb527e41 100644
--- a/fs/smb/server/vfs_cache.c
+++ b/fs/smb/server/vfs_cache.c
@@ -580,6 +580,7 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
{
struct ksmbd_file *fp;
struct ksmbd_file_table *ft;
+ bool closed = false;
if (!has_file_id(id))
return 0;
@@ -594,6 +595,7 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
fp = NULL;
else {
fp->f_state = FP_CLOSED;
+ closed = true;
if (!atomic_dec_and_test(&fp->refcount))
fp = NULL;
}
@@ -601,7 +603,7 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
write_unlock(&ft->lock);
if (!fp)
- return -EINVAL;
+ return closed ? 0 : -EINVAL;
__put_fd_final(work, fp);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 188/438] ksmbd: fix use-after-free in __close_file_table_ids()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (186 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 187/438] ksmbd: return success for deferred final close Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 189/438] ksmbd: use memcmp() to compare ClientGUIDs Greg Kroah-Hartman
` (263 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yunseong Kim, Namjae Jeon,
Steve French, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit e7188199eff46a636f3436356f0aae039be6dd66 ]
A ksmbd_file can remain alive after logical close while another session
holds a temporary reference obtained through ksmbd_lookup_fd_inode().
ksmbd_close_fd() currently marks the file closed and drops the idr-owned
reference, but leaves the pointer published in the closing session's idr
until the final reference is dropped.
If the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()
supplies the foreign session's file table to __ksmbd_close_fd(). The object
is then freed without being removed from its owner's idr, and the owner
session later dereferences the stale pointer during file-table teardown.
Remove the volatile id from the owner's idr while ksmbd_close_fd() still
holds that table's lock, and clear volatile_id before dropping
the idr-owned reference. A later foreign final put then only performs
physical destruction and cannot remove the object from the wrong table.
Fixes: 8510a043d334 ("ksmbd: increment reference count of parent fp")
Reported-by: Yunseong Kim <yunseong.kim@est.tech>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/vfs_cache.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/smb/server/vfs_cache.c b/fs/smb/server/vfs_cache.c
index b12c0bb527e41..c7d49aac7470a 100644
--- a/fs/smb/server/vfs_cache.c
+++ b/fs/smb/server/vfs_cache.c
@@ -595,6 +595,8 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
fp = NULL;
else {
fp->f_state = FP_CLOSED;
+ idr_remove(ft->idr, id);
+ fp->volatile_id = KSMBD_NO_FID;
closed = true;
if (!atomic_dec_and_test(&fp->refcount))
fp = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 189/438] ksmbd: use memcmp() to compare ClientGUIDs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (187 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 188/438] ksmbd: fix use-after-free in __close_file_table_ids() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 190/438] iomap: add a separate bio_set for iomap_split_ioend Greg Kroah-Hartman
` (262 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Samu, Namjae Jeon, Steve French,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit e8bb506e6ef749ac0336f3e579d8d02396b7d832 ]
ClientGUID is a fixed-size binary value and can contain embedded NUL
bytes. strncmp() stops comparing at the first NUL byte, so different
ClientGUID values can incorrectly be treated as equal.
Use memcmp() in SMB3 multichannel session binding and
FSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE
bytes.
Fixes: f5a544e3bab7 ("ksmbd: add support for SMB3 multichannel")
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Reported-by: Samu <nomomentomori@gmail.com>
Suggested-by: Samu <nomomentomori@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index c29850170b315..5df4a8cc4d2e6 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -1792,7 +1792,7 @@ int smb2_sess_setup(struct ksmbd_work *work)
goto out_err;
}
- if (strncmp(conn->ClientGUID, sess->ClientGUID,
+ if (memcmp(conn->ClientGUID, sess->ClientGUID,
SMB2_CLIENT_GUID_SIZE)) {
rc = -ENOENT;
goto out_err;
@@ -8186,7 +8186,7 @@ static int fsctl_validate_negotiate_info(struct ksmbd_conn *conn,
goto err_out;
}
- if (strncmp(neg_req->Guid, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE)) {
+ if (memcmp(neg_req->Guid, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE)) {
ret = -EINVAL;
goto err_out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 190/438] iomap: add a separate bio_set for iomap_split_ioend
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (188 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 189/438] ksmbd: use memcmp() to compare ClientGUIDs Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 191/438] mshv: Fix race in mshv_irqfd_deassign Greg Kroah-Hartman
` (261 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit c679ce3be6cb63763d68ab9b5d9d73ddc0a40762 ]
iomap_split_ioend can split bios that already come from
iomap_ioend_bioset and thus deadlock when the bioset is exhausted.
Add a separate bio_set to avoid this deadlock.
Christian Brauner <brauner@kernel.org> says:
Mark iomap_ioend_split_bioset static as it is only used in ioend.c,
fixing the sparse warning reported by the kernel test robot.
Fixes: 5fcbd555d483 ("iomap: split bios to zone append limits in the submission handlers")
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260629125229.3400726-1-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/iomap/ioend.c | 21 +++++++++++++++++++--
1 file changed, 19 insertions(+), 2 deletions(-)
diff --git a/fs/iomap/ioend.c b/fs/iomap/ioend.c
index 2d5611f6cc57d..9fe0aea8e8d9b 100644
--- a/fs/iomap/ioend.c
+++ b/fs/iomap/ioend.c
@@ -13,6 +13,7 @@
struct bio_set iomap_ioend_bioset;
EXPORT_SYMBOL_GPL(iomap_ioend_bioset);
+static struct bio_set iomap_ioend_split_bioset;
struct iomap_ioend *iomap_init_ioend(struct inode *inode,
struct bio *bio, loff_t file_offset, u16 ioend_flags)
@@ -485,7 +486,8 @@ struct iomap_ioend *iomap_split_ioend(struct iomap_ioend *ioend,
sector_offset = ALIGN_DOWN(sector_offset << SECTOR_SHIFT,
i_blocksize(ioend->io_inode)) >> SECTOR_SHIFT;
- split = bio_split(bio, sector_offset, GFP_NOFS, &iomap_ioend_bioset);
+ split = bio_split(bio, sector_offset, GFP_NOFS,
+ &iomap_ioend_split_bioset);
if (IS_ERR(split))
return ERR_CAST(split);
split->bi_private = bio->bi_private;
@@ -508,8 +510,23 @@ EXPORT_SYMBOL_GPL(iomap_split_ioend);
static int __init iomap_ioend_init(void)
{
- return bioset_init(&iomap_ioend_bioset, 4 * (PAGE_SIZE / SECTOR_SIZE),
+ const unsigned int nr_mempool_entries = 4 * (PAGE_SIZE / SECTOR_SIZE);
+ int error;
+
+ error = bioset_init(&iomap_ioend_bioset, nr_mempool_entries,
offsetof(struct iomap_ioend, io_bio),
BIOSET_NEED_BVECS);
+ if (error)
+ return error;
+ error = bioset_init(&iomap_ioend_split_bioset, nr_mempool_entries,
+ offsetof(struct iomap_ioend, io_bio),
+ BIOSET_NEED_BVECS);
+ if (error)
+ goto out_exit_ioend_bioset;
+ return 0;
+
+out_exit_ioend_bioset:
+ bioset_exit(&iomap_ioend_bioset);
+ return error;
}
fs_initcall(iomap_ioend_init);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 191/438] mshv: Fix race in mshv_irqfd_deassign
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (189 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 190/438] iomap: add a separate bio_set for iomap_split_ioend Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 192/438] mshv: Fix level-triggered check on uninitialized data Greg Kroah-Hartman
` (260 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit 0762262ac3e70f65b3bb843fe892f8bac1562d08 ]
mshv_irqfd_deactivate() and the hlist traversal of pt_irqfds_list
require pt->pt_irqfds_lock to be held, but mshv_irqfd_deassign()
omits it. This races with the EPOLLHUP path in mshv_irqfd_wakeup(),
which does take the lock before calling mshv_irqfd_deactivate().
Additionally, mshv_irqfd_deactivate() uses hlist_del() which poisons
the node pointers rather than resetting them. Since
mshv_irqfd_is_active() relies on hlist_unhashed() (checks pprev ==
NULL), a poisoned node still appears active. If a concurrent path calls
mshv_irqfd_deactivate() again on the same irqfd, the guard fails to
prevent a double hlist_del() on poisoned pointers.
Fix both issues:
- Add the missing spin_lock_irq/spin_unlock_irq around the list
traversal in mshv_irqfd_deassign(), matching mshv_irqfd_release().
- Use hlist_del_init() instead of hlist_del() so the node is properly
marked as unhashed after removal, making the is_active guard reliable.
Fixes: 621191d709b14 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_eventfd.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/hv/mshv_eventfd.c b/drivers/hv/mshv_eventfd.c
index 90959f639dc32..5995a62aff8d8 100644
--- a/drivers/hv/mshv_eventfd.c
+++ b/drivers/hv/mshv_eventfd.c
@@ -284,7 +284,7 @@ static void mshv_irqfd_deactivate(struct mshv_irqfd *irqfd)
if (!mshv_irqfd_is_active(irqfd))
return;
- hlist_del(&irqfd->irqfd_hnode);
+ hlist_del_init(&irqfd->irqfd_hnode);
queue_work(irqfd_cleanup_wq, &irqfd->irqfd_shutdown);
}
@@ -541,13 +541,14 @@ static int mshv_irqfd_deassign(struct mshv_partition *pt,
if (IS_ERR(eventfd))
return PTR_ERR(eventfd);
+ spin_lock_irq(&pt->pt_irqfds_lock);
hlist_for_each_entry_safe(irqfd, n, &pt->pt_irqfds_list,
irqfd_hnode) {
if (irqfd->irqfd_eventfd_ctx == eventfd &&
irqfd->irqfd_irqnum == args->gsi)
-
mshv_irqfd_deactivate(irqfd);
}
+ spin_unlock_irq(&pt->pt_irqfds_lock);
eventfd_ctx_put(eventfd);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 192/438] mshv: Fix level-triggered check on uninitialized data
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (190 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 191/438] mshv: Fix race in mshv_irqfd_deassign Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 193/438] mshv: Fix missing error code on VP allocation failure Greg Kroah-Hartman
` (259 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit 0289a67cd70bf9d3807e289f4efd643e16a6c6b4 ]
In mshv_irqfd_assign(), the level-triggered validation for resample
irqfds checks irqfd_lapic_irq.lapic_control.level_triggered before
mshv_irqfd_update() has populated the field. Since the irqfd struct is
zero-allocated, level_triggered is always 0 at that point, causing the
check to always reject resample irqfds with -EINVAL. This makes
level-triggered interrupt resampling — used to avoid interrupt storms
with assigned devices — completely non-functional.
Move the check after the mshv_irqfd_update() call, which resolves the
IRQ routing entry and populates irqfd_lapic_irq with the actual trigger
mode.
Fixes: 621191d709b14 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_eventfd.c | 25 ++++++++++++++-----------
1 file changed, 14 insertions(+), 11 deletions(-)
diff --git a/drivers/hv/mshv_eventfd.c b/drivers/hv/mshv_eventfd.c
index 5995a62aff8d8..047e5bd432381 100644
--- a/drivers/hv/mshv_eventfd.c
+++ b/drivers/hv/mshv_eventfd.c
@@ -473,6 +473,19 @@ static int mshv_irqfd_assign(struct mshv_partition *pt,
init_poll_funcptr(&irqfd->irqfd_polltbl, mshv_irqfd_queue_proc);
spin_lock_irq(&pt->pt_irqfds_lock);
+ ret = 0;
+ hlist_for_each_entry(tmp, &pt->pt_irqfds_list, irqfd_hnode) {
+ if (irqfd->irqfd_eventfd_ctx != tmp->irqfd_eventfd_ctx)
+ continue;
+ /* This fd is used for another irq already. */
+ ret = -EBUSY;
+ spin_unlock_irq(&pt->pt_irqfds_lock);
+ goto fail;
+ }
+
+ idx = srcu_read_lock(&pt->pt_irq_srcu);
+ mshv_irqfd_update(pt, irqfd);
+
#if IS_ENABLED(CONFIG_X86)
if (args->flags & BIT(MSHV_IRQFD_BIT_RESAMPLE) &&
!irqfd->irqfd_lapic_irq.lapic_control.level_triggered) {
@@ -481,22 +494,12 @@ static int mshv_irqfd_assign(struct mshv_partition *pt,
* Otherwise return with failure
*/
spin_unlock_irq(&pt->pt_irqfds_lock);
+ srcu_read_unlock(&pt->pt_irq_srcu, idx);
ret = -EINVAL;
goto fail;
}
#endif
- ret = 0;
- hlist_for_each_entry(tmp, &pt->pt_irqfds_list, irqfd_hnode) {
- if (irqfd->irqfd_eventfd_ctx != tmp->irqfd_eventfd_ctx)
- continue;
- /* This fd is used for another irq already. */
- ret = -EBUSY;
- spin_unlock_irq(&pt->pt_irqfds_lock);
- goto fail;
- }
- idx = srcu_read_lock(&pt->pt_irq_srcu);
- mshv_irqfd_update(pt, irqfd);
hlist_add_head(&irqfd->irqfd_hnode, &pt->pt_irqfds_list);
spin_unlock_irq(&pt->pt_irqfds_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 193/438] mshv: Fix missing error code on VP allocation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (191 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 192/438] mshv: Fix level-triggered check on uninitialized data Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 194/438] mshv: Order pt_vp_array publish against irqfd assertion path Greg Kroah-Hartman
` (258 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit f546be6a19d24d02be576d8617cb26c7acb61594 ]
In mshv_partition_ioctl_create_vp(), when kzalloc for the VP struct
fails, the code jumps to the cleanup path without setting ret. At that
point ret is 0 from the preceding successful mshv_vp_stats_map() call,
so the function returns success to userspace despite having failed to
create the VP. No fd is installed and no VP is registered in pt_vp_array,
but userspace has no way to know the operation failed.
Set ret to -ENOMEM before jumping to the cleanup path.
Fixes: 621191d709b14 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_root_main.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/hv/mshv_root_main.c b/drivers/hv/mshv_root_main.c
index 146726cc4e9ba..644f9b10cbba4 100644
--- a/drivers/hv/mshv_root_main.c
+++ b/drivers/hv/mshv_root_main.c
@@ -1117,8 +1117,10 @@ mshv_partition_ioctl_create_vp(struct mshv_partition *partition,
goto unmap_ghcb_page;
vp = kzalloc_obj(*vp);
- if (!vp)
+ if (!vp) {
+ ret = -ENOMEM;
goto unmap_stats_pages;
+ }
vp->vp_partition = mshv_partition_get(partition);
if (!vp->vp_partition) {
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 194/438] mshv: Order pt_vp_array publish against irqfd assertion path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (192 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 193/438] mshv: Fix missing error code on VP allocation failure Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 195/438] mshv: Publish VP to pt_vp_array before installing the file descriptor Greg Kroah-Hartman
` (257 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit b098dc869219c15dc49bf9cf63fb5fc1481d3373 ]
mshv_partition_ioctl_create_vp() initialises a VP struct (allocations,
mutex_init, init_waitqueue_head, page mappings) and then publishes the
pointer into partition->pt_vp_array. Several ISR paths read this array
locklessly: the intercept ISR, the two scheduler ISRs, and
mshv_try_assert_irq_fast() on the irqfd fast path.
Of these, only mshv_try_assert_irq_fast() can structurally race the
publish. It runs from an eventfd waker without holding pt_mutex, and
MSHV_IRQFD does not require the target lapic_apic_id (== vp_index) to
refer to an existing VP at registration time. A user can therefore
register an irqfd targeting a yet-to-be-created VP, then trigger
mshv_try_assert_irq_fast() concurrently with MSHV_CREATE_VP for the
same index. On weakly-ordered architectures the reader can observe a
non-NULL pointer in pt_vp_array before the initialising stores to the
VP struct become visible, leading to use of partially-initialised
fields (e.g. vp_register_page).
The other ISR readers cannot reach this race: the hypervisor will not
generate intercept or scheduler messages for a VP that has never been
told to run, and the user can only call MSHV_RUN_VP on the VP fd
returned by MSHV_CREATE_VP, which by construction is returned after
the publish. Leave those readers as plain loads.
Use smp_store_release() in mshv_partition_ioctl_create_vp() to publish
the pointer, and pair it with smp_load_acquire() in
mshv_try_assert_irq_fast(). On x86 these compile to plain accesses
under TSO; on ARM64 they emit one-instruction acquire/release barriers,
acceptable on this fast path.
The destroy-side path (destroy_partition() clearing pt_vp_array[i] to
NULL after kfree(vp)) has a separate ordering and lifetime concern
that is out of scope here.
Fixes: 621191d709b14 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_eventfd.c | 9 ++++++++-
drivers/hv/mshv_root_main.c | 8 +++++++-
2 files changed, 15 insertions(+), 2 deletions(-)
diff --git a/drivers/hv/mshv_eventfd.c b/drivers/hv/mshv_eventfd.c
index 047e5bd432381..06aef99c8298d 100644
--- a/drivers/hv/mshv_eventfd.c
+++ b/drivers/hv/mshv_eventfd.c
@@ -169,7 +169,14 @@ static int mshv_try_assert_irq_fast(struct mshv_irqfd *irqfd)
return -EOPNOTSUPP;
#endif
- vp = partition->pt_vp_array[irq->lapic_apic_id];
+ /*
+ * Pairs with smp_store_release() in mshv_partition_ioctl_create_vp().
+ * MSHV_IRQFD does not require the target lapic_apic_id to refer to an
+ * existing VP, so this read can race a concurrent VP creation; the
+ * acquire ensures that a non-NULL pointer implies the VP's
+ * initialising stores are visible.
+ */
+ vp = smp_load_acquire(&partition->pt_vp_array[irq->lapic_apic_id]);
if (!vp->vp_register_page)
return -EOPNOTSUPP;
diff --git a/drivers/hv/mshv_root_main.c b/drivers/hv/mshv_root_main.c
index 644f9b10cbba4..8a15448e2ace9 100644
--- a/drivers/hv/mshv_root_main.c
+++ b/drivers/hv/mshv_root_main.c
@@ -1157,7 +1157,13 @@ mshv_partition_ioctl_create_vp(struct mshv_partition *partition,
/* already exclusive with the partition mutex for all ioctls */
partition->pt_vp_count++;
- partition->pt_vp_array[args.vp_index] = vp;
+ /*
+ * Pairs with smp_load_acquire() in mshv_try_assert_irq_fast(), which
+ * can run concurrently from an irqfd waker without holding pt_mutex.
+ * The release ensures the VP's initialising stores are visible to any
+ * reader that observes a non-NULL pointer in pt_vp_array.
+ */
+ smp_store_release(&partition->pt_vp_array[args.vp_index], vp);
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 195/438] mshv: Publish VP to pt_vp_array before installing the file descriptor
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (193 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 194/438] mshv: Order pt_vp_array publish against irqfd assertion path Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 196/438] ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path Greg Kroah-Hartman
` (256 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Anirudh Rayabharam (Microsoft), Wei Liu, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit 72e3b0311aa90568a4b42a64445d1d3e1dc5a34d ]
mshv_partition_ioctl_create_vp() called anon_inode_getfd() before
publishing the new VP into partition->pt_vp_array. anon_inode_getfd()
includes fd_install(), so the fd was live in current->files before the
publish ran.
A concurrent MSHV_RUN_VP ioctl on that fd does not serialise against the
in-progress MSHV_CREATE_VP — it takes vp->vp_mutex, not the partition
mutex. Once the VP starts running and traps, mshv_intercept_isr() can look
up partition->pt_vp_array[vp_index] and observe NULL, silently dropping the
intercept message.
Split the fd creation: reserve an fd with get_unused_fd_flags(), create the
file with anon_inode_getfile(), publish the VP via smp_store_release(), and
finally call fd_install() as the userspace-visibility commit point.
Fixes: 621191d709b14 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Reviewed-by: Anirudh Rayabharam (Microsoft) <anirudh@anirudhrb.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hv/mshv_root_main.c | 29 ++++++++++++++++++++++-------
1 file changed, 22 insertions(+), 7 deletions(-)
diff --git a/drivers/hv/mshv_root_main.c b/drivers/hv/mshv_root_main.c
index 8a15448e2ace9..cc2cfce2aefdb 100644
--- a/drivers/hv/mshv_root_main.c
+++ b/drivers/hv/mshv_root_main.c
@@ -1072,6 +1072,8 @@ mshv_partition_ioctl_create_vp(struct mshv_partition *partition,
struct mshv_vp *vp;
struct page *intercept_msg_page, *register_page, *ghcb_page;
struct hv_stats_page *stats_pages[2];
+ struct file *file;
+ int fd;
long ret;
if (copy_from_user(&args, arg, sizeof(args)))
@@ -1146,14 +1148,18 @@ mshv_partition_ioctl_create_vp(struct mshv_partition *partition,
if (ret)
goto put_partition;
- /*
- * Keep anon_inode_getfd last: it installs fd in the file struct and
- * thus makes the state accessible in user space.
- */
- ret = anon_inode_getfd("mshv_vp", &mshv_vp_fops, vp,
- O_RDWR | O_CLOEXEC);
- if (ret < 0)
+ fd = get_unused_fd_flags(O_RDWR | O_CLOEXEC);
+ if (fd < 0) {
+ ret = fd;
goto remove_debugfs_vp;
+ }
+
+ file = anon_inode_getfile("mshv_vp", &mshv_vp_fops, vp,
+ O_RDWR | O_CLOEXEC);
+ if (IS_ERR(file)) {
+ ret = PTR_ERR(file);
+ goto put_unused_vp_fd;
+ }
/* already exclusive with the partition mutex for all ioctls */
partition->pt_vp_count++;
@@ -1165,8 +1171,17 @@ mshv_partition_ioctl_create_vp(struct mshv_partition *partition,
*/
smp_store_release(&partition->pt_vp_array[args.vp_index], vp);
+ /*
+ * fd_install() is the userspace-visibility commit point. Must be the
+ * last operation that can fail or be observed.
+ */
+ fd_install(fd, file);
+ ret = fd;
+
goto out;
+put_unused_vp_fd:
+ put_unused_fd(fd);
remove_debugfs_vp:
mshv_debugfs_vp_remove(vp);
put_partition:
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 196/438] ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (194 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 195/438] mshv: Publish VP to pt_vp_array before installing the file descriptor Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 197/438] iommufd/viommu: Release the igroup lock on the vdevice_size " Greg Kroah-Hartman
` (255 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Vincent Donnefort, Steven Rostedt, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
[ Upstream commit 260b20d9b78bf002f89088fb62d60e8dee98f6f8 ]
In rb_allocate_cpu_buffer(), cpu_buffer->subbuf_ids is allocated using
kcalloc() when buffer->remote is non-NULL. If a subsequent page allocation
fails (e.g., ring_buffer_desc_page() returns NULL or rb_allocate_pages()
fails), execution jumps to fail_free_reader.
While __free(kfree) automatically frees the outer cpu_buffer structure
at scope exit, kfree(cpu_buffer) does not recursively free nested heap
pointers such as cpu_buffer->subbuf_ids, resulting in a memory leak.
Fix this by explicitly freeing cpu_buffer->subbuf_ids in the
fail_free_reader error unwinding path when cpu_buffer->remote is set.
Link: https://patch.msgid.link/178550740672.380917.6067449683620196150.stgit@devnote2
Fixes: 2e67fabd8b77 ("ring-buffer: Introduce ring-buffer remotes")
Assisted-by: Antigravity:gemini-3.6-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Vincent Donnefort <vdonnefort@google.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/ring_buffer.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index d896fb25de702..d2e2cf18bfdbe 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -2489,6 +2489,7 @@ rb_allocate_cpu_buffer(struct trace_buffer *buffer, long nr_pages, int cpu)
return_ptr(cpu_buffer);
fail_free_reader:
+ kfree(cpu_buffer->subbuf_ids);
free_buffer_page(cpu_buffer->reader_page);
return NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 197/438] iommufd/viommu: Release the igroup lock on the vdevice_size error path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (195 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 196/438] ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 198/438] iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds Greg Kroah-Hartman
` (254 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kevin Tian, Pranjal Shrivastava,
Nicolin Chen, Jason Gunthorpe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
commit 339bd11591593ab7ce88136ab7fd01ef3813b724 upstream.
iommufd_vdevice_alloc_ioctl() takes idev->igroup->lock, then validates the
driver's vdevice_size against the core structure size with a WARN_ON_ONCE.
On failure that guard jumps to out_put_idev, below out_unlock_igroup, so it
skips the mutex_unlock(), leaving the igroup lock held and deadlocking the
next vDEVICE operation on that group.
Jump to out_unlock_igroup instead.
Fixes: ed42eee797ff3 ("iommufd/viommu: Add driver-defined vDEVICE support")
Link: https://patch.msgid.link/r/e903f775d491296a525097e2a90b3eb6a47cf2ef.1783311134.git.nicolinc@nvidia.com
Cc: stable@vger.kernel.org
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Pranjal Shrivastava <praan@google.com>
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/iommufd/viommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/iommu/iommufd/viommu.c
+++ b/drivers/iommu/iommufd/viommu.c
@@ -189,7 +189,7 @@ int iommufd_vdevice_alloc_ioctl(struct i
if (WARN_ON_ONCE(viommu->ops->vdevice_size < vdev_size ||
!viommu->ops->vdevice_init)) {
rc = -EOPNOTSUPP;
- goto out_put_idev;
+ goto out_unlock_igroup;
}
vdev_size = viommu->ops->vdevice_size;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 198/438] iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (196 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 197/438] iommufd/viommu: Release the igroup lock on the vdevice_size " Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 199/438] iommufd: Reject DMABUF pages from the access pin path Greg Kroah-Hartman
` (253 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kevin Tian, Pranjal Shrivastava,
Nicolin Chen, Jason Gunthorpe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
commit 9be311cfbe6154da146a7408e0d5e518a9321ed3 upstream.
iommufd_vdevice_alloc_ioctl() adds the vDEVICE to the viommu->vdevs xarray
with xa_cmpxchg() before the driver's vdevice_init() op runs. That op is
where a driver validates the device and may reject it, but the xarray entry
is already live by then: a concurrent IOMMU_HWPT_INVALIDATE can look it up
with iommufd_viommu_find_dev() and run the driver invalidation path against
a device that vdevice_init() would have refused.
Reserve the index with xa_insert(): it stores a zero entry that reads back
as NULL, and returns -EBUSY on a duplicate virt_id. Run vdevice_init() and
store the vDEVICE pointer only once it succeeds. A failed vdevice_init()
releases the reservation, so lookups observe the vDEVICE only after it is
fully initialized and accepted.
Fixes: ed42eee797ff3 ("iommufd/viommu: Add driver-defined vDEVICE support")
Link: https://patch.msgid.link/r/1e05999347f4bf583edbc6a1312c857d5548708c.1783311134.git.nicolinc@nvidia.com
Cc: stable@vger.kernel.org
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Pranjal Shrivastava <praan@google.com>
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/iommufd/viommu.c | 20 +++++++++++++++-----
1 file changed, 15 insertions(+), 5 deletions(-)
--- a/drivers/iommu/iommufd/viommu.c
+++ b/drivers/iommu/iommufd/viommu.c
@@ -143,7 +143,7 @@ void iommufd_vdevice_destroy(struct iomm
int iommufd_vdevice_alloc_ioctl(struct iommufd_ucmd *ucmd)
{
struct iommu_vdevice_alloc *cmd = ucmd->cmd;
- struct iommufd_vdevice *vdev, *curr;
+ struct iommufd_vdevice *vdev;
size_t vdev_size = sizeof(*vdev);
struct iommufd_viommu *viommu;
struct iommufd_device *idev;
@@ -218,18 +218,28 @@ int iommufd_vdevice_alloc_ioctl(struct i
*/
idev->vdev = vdev;
- curr = xa_cmpxchg(&viommu->vdevs, virt_id, NULL, vdev, GFP_KERNEL);
- if (curr) {
- rc = xa_err(curr) ?: -EEXIST;
+ /*
+ * Reserve the slot with a zero entry (reads back as NULL) until the
+ * vdevice_init() op accepts the vDEVICE. Only the xa_* helpers hide a
+ * reserved entry, so never use a raw xas_* iterator on this xarray.
+ */
+ rc = xa_insert(&viommu->vdevs, virt_id, NULL, GFP_KERNEL);
+ if (rc) {
+ if (rc == -EBUSY)
+ rc = -EEXIST;
goto out_abort;
}
if (viommu->ops && viommu->ops->vdevice_init) {
rc = viommu->ops->vdevice_init(vdev);
- if (rc)
+ if (rc) {
+ xa_release(&viommu->vdevs, virt_id);
goto out_abort;
+ }
}
+ xa_store(&viommu->vdevs, virt_id, vdev, GFP_KERNEL);
+
cmd->out_vdevice_id = vdev->obj.id;
rc = iommufd_ucmd_respond(ucmd, sizeof(*cmd));
if (rc)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 199/438] iommufd: Reject DMABUF pages from the access pin path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (197 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 198/438] iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 200/438] iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace Greg Kroah-Hartman
` (252 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Kevin Tian,
Jason Gunthorpe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 5f3fc0ad9a41883a62098359b9fdbe4257f20e53 upstream.
DMABUF pages are not supported for iommufd access pinning.
iommufd_access_pin_pages() returns struct page pointers for
in-kernel CPU access, but DMABUF-backed iopt_pages do not carry
a userspace address that can be passed to the GUP path.
iopt_pages_rw_access() already rejects IOPT_ADDRESS_DMABUF before doing
CPU access. Apply the same rejection to iopt_area_add_access() before it
takes pages->mutex and calls iopt_pages_fill_xarray().
Otherwise a DMABUF-backed iopt_pages can reach the hole-fill path, where
pfn_reader_user_pin() interprets the union as uptr and
calls pin_user_pages_fast()/pin_user_pages_remote().
This fix also avoids the lockdep warning reported from that path, where
pages_dmabuf_mutex_key is held while gup_fast_fallback() may acquire
mmap_lock.
Link: https://patch.msgid.link/r/CD68F549BF3761B7+20260709050800.520607-1-peiyang_he@smail.nju.edu.cn
Reported-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Closes: https://lore.kernel.org/all/E8540D7D05768C91+8b2ef227-3368-494e-909d-7b28e1489dfb@smail.nju.edu.cn/
Fixes: 71db84a092c3 ("iommufd: Add DMABUF to iopt_pages")
Cc: stable@vger.kernel.org
Tested-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/iommufd/pages.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/iommu/iommufd/pages.c
+++ b/drivers/iommu/iommufd/pages.c
@@ -2451,6 +2451,9 @@ int iopt_area_add_access(struct iopt_are
if ((flags & IOMMUFD_ACCESS_RW_WRITE) && !pages->writable)
return -EPERM;
+ if (iopt_is_dmabuf(pages))
+ return -EINVAL;
+
mutex_lock(&pages->mutex);
access = iopt_pages_get_exact_access(pages, start_index, last_index);
if (access) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 200/438] iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (198 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 199/438] iommufd: Reject DMABUF pages from the access pin path Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 201/438] iommu/iommufd: Fix IOPF group ownership UAF Greg Kroah-Hartman
` (251 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Kevin Tian,
Jason Gunthorpe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit ba5c0f28a26e7d9be1e0997f8920dd638e2782fd upstream.
iommufd_hwpt_replace_device() calls:
iommufd_auto_response_faults(hwpt, old_handle);
passing the *new* hwpt together with the handle of
the device's *old* domain. This should be a parameter mismatch:
1. Semantically, iommufd_auto_response_faults(x, handle) scans
x->fault's deliver list and response xarray for groups matching
"handle". A group is queued under the hwpt that was attached at
fault-delivery time. old_handle is fetched *before* the domain switch,
so its group lives on old->fault, not on the new hwpt->fault.
2. Historically, the first argument was "old". The routine was
introduced by commit b7d8833677ba ("iommufd: Fault-capable hwpt
attach/detach/replace") as __fault_domain_replace_dev() in
fault.c, correctly calling iommufd_auto_response_faults(old, curr).
Commit fb21b1568ada ("iommufd: Make attach_handle generic than
fault specific") moved this into iommufd_hwpt_replace_device() in
device.c and swapped it to "hwpt". This should be a refactor regression,
not an intentional change.
Fix this by passing "old" instead.
Link: https://patch.msgid.link/r/9D652384339C69D5+20260710122952.885325-1-peiyang_he@smail.nju.edu.cn
Fixes: fb21b1568ada ("iommufd: Make attach_handle generic than fault specific")
Cc: stable@vger.kernel.org
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/iommufd/device.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/iommu/iommufd/device.c
+++ b/drivers/iommu/iommufd/device.c
@@ -589,7 +589,7 @@ static int iommufd_hwpt_replace_device(s
if (rc)
goto out_free_handle;
- iommufd_auto_response_faults(hwpt, old_handle);
+ iommufd_auto_response_faults(old, old_handle);
kfree(old_handle);
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 201/438] iommu/iommufd: Fix IOPF group ownership UAF
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (199 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 200/438] iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 202/438] kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos Greg Kroah-Hartman
` (250 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Kevin Tian,
Jason Gunthorpe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 738e6f32e61d80b554e37015ecb7bc620b88001c upstream.
iopf_group_alloc() links each last-page IOPF group into the generic IOPF
pending list before invoking the domain fault handler.
iommufd_fault_iopf_handler() also queued an accepted group in the
IOMMUFD deliver list without removing it from the generic pending list.
When detach or HWPT replacement drops the device's IOPF reference count
to zero, an IOMMU driver may call iopf_queue_remove_device(). That
function responds to and frees groups through the generic pending list
without removing the same groups from IOMMUFD's deliver list or response
xarray. A later read, response, or cleanup can then access the freed
group and cause a UAF.
Fix this by dequeuing an accepted group from the generic pending list
before IOMMUFD queues it for userspace response.
Make iopf_group_response() send a response regardless of pending-list
membership, so the dequeued group can still be completed by IOMMUFD.
Link: https://patch.msgid.link/r/3CFD314D0FE4D7EC+20260720085017.3998878-2-peiyang_he@smail.nju.edu.cn
Closes: https://lore.kernel.org/all/B4F28798E2E784CA+d29f723c-b2b5-4b67-8d1c-4f7b9b0b27cb@smail.nju.edu.cn/
Fixes: 34765cbc679c ("iommufd: Associate fault object with iommufd_hw_pgtable")
Cc: stable@vger.kernel.org
Tested-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/io-pgfault.c | 24 +++++++++++++++++++-----
drivers/iommu/iommufd/eventq.c | 2 ++
include/linux/iommu.h | 5 +++++
3 files changed, 26 insertions(+), 5 deletions(-)
--- a/drivers/iommu/io-pgfault.c
+++ b/drivers/iommu/io-pgfault.c
@@ -332,17 +332,31 @@ void iopf_group_response(struct iopf_gro
.code = status,
};
- /* Only send response if there is a fault report pending */
mutex_lock(&fault_param->lock);
- if (!list_empty(&group->pending_node)) {
- ops->page_response(dev, &group->last_fault, &resp);
- list_del_init(&group->pending_node);
- }
+ ops->page_response(dev, &group->last_fault, &resp);
+ list_del_init(&group->pending_node);
mutex_unlock(&fault_param->lock);
}
EXPORT_SYMBOL_GPL(iopf_group_response);
/**
+ * iopf_group_dequeue - Dequeue a page fault group from the pending list
+ * @group: the group to dequeue
+ *
+ * The fault handler is responsible for responding to the group after
+ * this function returns.
+ */
+void iopf_group_dequeue(struct iopf_group *group)
+{
+ struct iommu_fault_param *fault_param = group->fault_param;
+
+ mutex_lock(&fault_param->lock);
+ list_del_init(&group->pending_node);
+ mutex_unlock(&fault_param->lock);
+}
+EXPORT_SYMBOL_GPL(iopf_group_dequeue);
+
+/**
* iopf_queue_discard_partial - Remove all pending partial fault
* @queue: the queue whose partial faults need to be discarded
*
--- a/drivers/iommu/iommufd/eventq.c
+++ b/drivers/iommu/iommufd/eventq.c
@@ -484,6 +484,8 @@ int iommufd_fault_iopf_handler(struct io
hwpt = group->attach_handle->domain->iommufd_hwpt;
fault = hwpt->fault;
+ iopf_group_dequeue(group);
+
spin_lock(&fault->common.lock);
list_add_tail(&group->node, &fault->common.deliver);
spin_unlock(&fault->common.lock);
--- a/include/linux/iommu.h
+++ b/include/linux/iommu.h
@@ -1676,6 +1676,7 @@ void iopf_free_group(struct iopf_group *
int iommu_report_device_fault(struct device *dev, struct iopf_fault *evt);
void iopf_group_response(struct iopf_group *group,
enum iommu_page_response_code status);
+void iopf_group_dequeue(struct iopf_group *group);
#else
static inline int
iopf_queue_add_device(struct iopf_queue *queue, struct device *dev)
@@ -1721,5 +1722,9 @@ static inline void iopf_group_response(s
enum iommu_page_response_code status)
{
}
+
+static inline void iopf_group_dequeue(struct iopf_group *group)
+{
+}
#endif /* CONFIG_IOMMU_IOPF */
#endif /* __LINUX_IOMMU_H */
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 202/438] kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (200 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 201/438] iommu/iommufd: Fix IOPF group ownership UAF Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 203/438] ACPI: CPPC: Check all controls for fast switching Greg Kroah-Hartman
` (249 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Anish Rashinkar, Philipp Hahn,
Nicolas Schier, Nicolas Schier, Nathan Chancellor
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Schier <n.schier@fritz.com>
commit 39d6e68f50f4a444a6ba23b9ea2eaee806601c6d upstream.
Update output Makefile in the corresponding tree only: for out-of-source
in-tree builds update $(objtree)/Makefile, for out-of-source out-of-tree
module builds update $(KBUILD_EXTMOD_OUTPUT)/Makefile instead.
In-source builds are not affected.
Since commit c9bb03ac2c66 ("kbuild: reduce output spam when building out
of tree"), building out-of-tree kernel modules out-of-source (make M=...
MO=...) causes a rewrite of $(objtree)/Makefile with KBUILD_EXTMOD and
KBUILD_EXTMOD_OUTPUT being set. That is problematic:
* $(objtree)/ must not be changed in any way when building out-of-tree
modules as it breaks other uses of $(objtree).
* Setting KBUILD_EXTMOD and KBUILD_EXTMOD_OUTPUT in $(objtree)/Makefile
kills the tree for incremental builds that start right there
('make -C $(objtree)'); builds starting in $(srctree) reset
$(objtree)/Makefile to its original content.
Further, $(KBUILD_EXTMOD_OUTPUT)/Makefile was not generated any more at
all.
This commit restores the previous kbuild behaviour prior to commit
c9bb03ac2c66 ("kbuild: reduce output spam when building out of tree")
but leaves in-place the use of filechk for output spam reduction.
Fixes: c9bb03ac2c66 ("kbuild: reduce output spam when building out of tree")
Reported-by: Anish Rashinkar <rashinkar.anish@gmail.com>
Closes: https://lore.kernel.org/r/CAOESE2Q2-0KUDaM0mUo+c_F-tMaUsBZ-gpnhdoe0rmYdgnnuJQ@mail.gmail.com
Cc: stable@vger.kernel.org
Tested-by: Philipp Hahn <p.hahn@avm.de>
Reviewed-by: Philipp Hahn <p.hahn@avm.de>
Signed-off-by: Nicolas Schier <n.schier@fritz.com>
Signed-off-by: Nicolas Schier <nsc@kernel.org>
Link: https://patch.msgid.link/20260723105845.1704689-2-nsc@kernel.org
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Makefile | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/Makefile b/Makefile
index 11539c3fd405..17d34968b7f0 100644
--- a/Makefile
+++ b/Makefile
@@ -695,13 +695,11 @@ filechk_makefile = { \
echo "include $(abs_srctree)/Makefile"; \
}
-$(objtree)/Makefile: FORCE
+PHONY += $(CURDIR)/Makefile
+$(CURDIR)/Makefile: FORCE
$(call filechk,makefile)
-# Prevent $(srcroot)/Makefile from inhibiting the rule to run.
-PHONY += $(objtree)/Makefile
-
-outputmakefile: $(objtree)/Makefile
+outputmakefile: $(CURDIR)/Makefile
ifeq ($(KBUILD_EXTMOD),)
@if [ -f $(srctree)/.config -o \
-d $(srctree)/include/config -o \
--
2.55.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 203/438] ACPI: CPPC: Check all controls for fast switching
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (201 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 202/438] kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 204/438] mm: mglru: fix stale batch updates after memcg reparenting Greg Kroah-Hartman
` (248 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Loehle, Rafael J. Wysocki
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Loehle <christian.loehle@arm.com>
commit 11055a46f398779b69aa36afb7c9f4124529a075 upstream.
ACPI 6.2, Section 6.2.11.2 permits _CPC registers to use flexible
address spaces. Linux advertises that capability through _OSC and parses
the address space of each _CPC register independently. A directly
accessible DESIRED_PERF combined with PCC-backed limits is therefore a
valid configuration.
cppc_allow_fast_switch() only checks DESIRED_PERF, although the fast-switch
callback passes DESIRED_PERF, MIN_PERF and MAX_PERF to cppc_set_perf(). If
a limit uses PCC, that function can sleep while called from scheduler
context.
Allow fast switching only when every supported control used by the
callback has an address space already accepted for fast access. Check the
complete policy domain, including initialized CPUs that are currently
offline and may later become the policy's managing CPU.
Fixes: 658fa7b1c47a ("ACPI: CPPC: Add cppc_get_perf() API to read performance controls")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Loehle <christian.loehle@arm.com>
Link: https://patch.msgid.link/20260722093825.1030594-2-christian.loehle@arm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/acpi/cppc_acpi.c | 22 +++++++++++++++++-----
drivers/cpufreq/cppc_cpufreq.c | 2 +-
include/acpi/cppc_acpi.h | 5 +++--
3 files changed, 21 insertions(+), 8 deletions(-)
--- a/drivers/acpi/cppc_acpi.c
+++ b/drivers/acpi/cppc_acpi.c
@@ -475,17 +475,29 @@ bool acpi_cpc_valid(void)
}
EXPORT_SYMBOL_GPL(acpi_cpc_valid);
-bool cppc_allow_fast_switch(void)
+bool cppc_allow_fast_switch(const struct cpumask *cpus)
{
- struct cpc_register_resource *desired_reg;
+ struct cpc_register_resource *desired_reg, *min_reg, *max_reg;
struct cpc_desc *cpc_ptr;
int cpu;
- for_each_online_cpu(cpu) {
+ for_each_cpu(cpu, cpus) {
cpc_ptr = per_cpu(cpc_desc_ptr, cpu);
+ if (!cpc_ptr)
+ return false;
desired_reg = &cpc_ptr->cpc_regs[DESIRED_PERF];
- if (!CPC_IN_SYSTEM_MEMORY(desired_reg) &&
- !CPC_IN_SYSTEM_IO(desired_reg))
+ min_reg = &cpc_ptr->cpc_regs[MIN_PERF];
+ max_reg = &cpc_ptr->cpc_regs[MAX_PERF];
+
+ if (!CPC_SUPPORTED(desired_reg) ||
+ (!CPC_IN_SYSTEM_MEMORY(desired_reg) &&
+ !CPC_IN_SYSTEM_IO(desired_reg)) ||
+ (CPC_SUPPORTED(min_reg) &&
+ !CPC_IN_SYSTEM_MEMORY(min_reg) &&
+ !CPC_IN_SYSTEM_IO(min_reg)) ||
+ (CPC_SUPPORTED(max_reg) &&
+ !CPC_IN_SYSTEM_MEMORY(max_reg) &&
+ !CPC_IN_SYSTEM_IO(max_reg)))
return false;
}
--- a/drivers/cpufreq/cppc_cpufreq.c
+++ b/drivers/cpufreq/cppc_cpufreq.c
@@ -694,7 +694,7 @@ static int cppc_cpufreq_cpu_init(struct
goto out;
}
- policy->fast_switch_possible = cppc_allow_fast_switch();
+ policy->fast_switch_possible = cppc_allow_fast_switch(policy->cpus);
policy->dvfs_possible_from_any_cpu = true;
/*
--- a/include/acpi/cppc_acpi.h
+++ b/include/acpi/cppc_acpi.h
@@ -166,7 +166,7 @@ extern u64 cppc_get_dmi_max_khz(void);
extern unsigned int cppc_perf_to_khz(struct cppc_perf_caps *caps, unsigned int perf);
extern unsigned int cppc_khz_to_perf(struct cppc_perf_caps *caps, unsigned int freq);
extern bool acpi_cpc_valid(void);
-extern bool cppc_allow_fast_switch(void);
+bool cppc_allow_fast_switch(const struct cpumask *cpus);
extern int acpi_get_psd_map(unsigned int cpu, struct cppc_cpudata *cpu_data);
extern int cppc_get_transition_latency(int cpu);
extern bool cpc_ffh_supported(void);
@@ -230,7 +230,8 @@ static inline bool acpi_cpc_valid(void)
{
return false;
}
-static inline bool cppc_allow_fast_switch(void)
+
+static inline bool cppc_allow_fast_switch(const struct cpumask *cpus)
{
return false;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 204/438] mm: mglru: fix stale batch updates after memcg reparenting
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (202 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 203/438] ACPI: CPPC: Check all controls for fast switching Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 205/438] mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() Greg Kroah-Hartman
` (247 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qi Zheng, Peiyang He,
Harry Yoo (Oracle), Johannes Weiner, Shakeel Butt, Axel Rasmussen,
Barry Song, David Hildenbrand, Kairui Song, Lorenzo Stoakes,
Michal Hocko, Muchun Song, Roman Gushchin, Wei Xu, Yuanchu Xie,
Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qi Zheng <zhengqi.arch@bytedance.com>
commit de4660898b7aa7e03d3b120a6bfa6b26211e4e77 upstream.
The mglru page table walker batches per-generation size deltas in
walk->nr_pages while walking page tables without holding the lruvec lock.
The reset_batch_size() later folds those deltas into walk->lruvec under
the lruvec lock.
The page table walker can run concurrently with the memcg reparenting path
as follows:
CPU0 CPU1
==== ====
walk_mm
--> walk_page_range
--> update_batch_size
--> walk->nr_pages += delta
mem_cgroup_css_offline
--> memcg_reparent_objcgs
--> lock lruvec
lru_gen_reparent_memcg
--> reparent child folios to parent
unlock lruvec
lock lruvec
reset_batch_size
--> child lrugen->nr_pages += delta
This will trigger the following warning in lru_gen_exit_memcg():
VM_WARN_ON_ONCE(memchr_inv(lruvec->lrugen.nr_pages, 0,
sizeof(lruvec->lrugen.nr_pages)));
And the user-visible impact of underestimated nr_pages in MGLRU was
premature OOMs because MGLRU does not try to reclaim memory when nr_pages
reaches zero, but there are still more pages.
To fix it, make reset_batch_size() check CSS_DYING under RCU before
flushing the pending batch. A non-dying memcg keeps the original lruvec
stable against RCU-delayed offlining; a dying memcg redirects the deltas
to the first non-dying ancestor.
Link: https://lore.kernel.org/20260710154318.75388-1-qi.zheng@linux.dev
Fixes: f304652609ea ("mm: vmscan: prepare for reparenting MGLRU folios")
Signed-off-by: Qi Zheng <zhengqi.arch@bytedance.com>
Reported-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Closes: https://lore.kernel.org/all/5A9E929D82717101+12fcf643-efb8-4b9a-a53a-1e28cc894f0b@smail.nju.edu.cn
Reviewed-by: Harry Yoo (Oracle) <harry@kernel.org>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Acked-by: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Axel Rasmussen <axelrasmussen@google.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Kairui Song <kasong@tencent.com>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Wei Xu <weixugc@google.com>
Cc: Yuanchu Xie <yuanchu@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/memcontrol.h | 25 +++++++++++++++++++++++++
mm/vmscan.c | 11 ++++-------
2 files changed, 29 insertions(+), 7 deletions(-)
--- a/include/linux/memcontrol.h
+++ b/include/linux/memcontrol.h
@@ -1475,6 +1475,31 @@ static inline void lruvec_lock_irq(struc
spin_lock_irq(&lruvec->lru_lock);
}
+static inline struct lruvec *lruvec_live_lock_irq(struct lruvec *lruvec)
+{
+#ifdef CONFIG_MEMCG
+ struct pglist_data *pgdat = lruvec_pgdat(lruvec);
+ struct mem_cgroup *memcg = lruvec_memcg(lruvec);
+
+ rcu_read_lock();
+
+ /*
+ * The memcg can be NULL when the memory controller is disabled.
+ * Otherwise, the caller keeps the memcg owning @lruvec alive.
+ */
+ while (unlikely(memcg && css_is_dying(&memcg->css))) {
+ memcg = parent_mem_cgroup(memcg);
+ lruvec = mem_cgroup_lruvec(memcg, pgdat);
+ }
+
+ spin_lock_irq(&lruvec->lru_lock);
+#else
+ lruvec_lock_irq(lruvec);
+#endif
+
+ return lruvec;
+}
+
static inline void lruvec_unlock(struct lruvec *lruvec)
{
spin_unlock(&lruvec->lru_lock);
--- a/mm/vmscan.c
+++ b/mm/vmscan.c
@@ -3268,7 +3268,7 @@ static void update_batch_size(struct lru
static void reset_batch_size(struct lru_gen_mm_walk *walk)
{
int gen, type, zone;
- struct lruvec *lruvec = walk->lruvec;
+ struct lruvec *lruvec = lruvec_live_lock_irq(walk->lruvec);
struct lru_gen_folio *lrugen = &lruvec->lrugen;
walk->batched = 0;
@@ -3288,6 +3288,8 @@ static void reset_batch_size(struct lru_
lru += LRU_ACTIVE;
__update_lru_size(lruvec, lru, zone, delta);
}
+
+ lruvec_unlock_irq(lruvec);
}
static int should_skip_vma(unsigned long start, unsigned long end, struct mm_walk *args)
@@ -3782,11 +3784,8 @@ static void walk_mm(struct mm_struct *mm
mmap_read_unlock(mm);
}
- if (walk->batched) {
- lruvec_lock_irq(lruvec);
+ if (walk->batched)
reset_batch_size(walk);
- lruvec_unlock_irq(lruvec);
- }
cond_resched();
} while (err == -EAGAIN);
@@ -4884,9 +4883,7 @@ retry:
walk = current->reclaim_state->mm_walk;
if (walk && walk->batched) {
walk->lruvec = lruvec;
- lruvec_lock_irq(lruvec);
reset_batch_size(walk);
- lruvec_unlock_irq(lruvec);
}
mod_lruvec_state(lruvec, PGDEMOTE_KSWAPD + reclaimer_offset(sc),
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 205/438] mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (203 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 204/438] mm: mglru: fix stale batch updates after memcg reparenting Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 206/438] pinctrl: microchip-sgpio: add missing select REGMAP_MMIO Greg Kroah-Hartman
` (246 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kiryl Shutsemau, Sashiko AI review,
David Hildenbrand, Muchun Song, Oscar Salvador, Peter Xu,
Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kiryl Shutsemau (Meta) <kas@kernel.org>
commit 83abe2fd5b3aeb3123b5408a5a91709c5538fb23 upstream.
copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison
entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE
bit position. Swap entries keep the uffd-wp state elsewhere -- the
migration branch reads and sets it with pte_swp_uffd_wp() and
pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap
payload. On x86-64 it lands in the inverted swap offset, where a
naturally-aligned hugetlb PFN always has the affected bit set, so the
clear advances the encoded PFN by two pages.
No userfaultfd needs to be involved: the clear is guarded only by the
child VMA not being uffd-wp registered, so a plain fork() with an
in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts
the entry copied into the child. Instrumenting the clear and forking
after MADV_HWPOISON on a 2MB anon hugetlb page shows:
offset before=120e00
offset after =120e02
The fallout is mostly latent: rmap walks match migration entries by folio
range and remove_migration_pte() rebuilds the PTE from the folio, so a
within-folio PFN skew heals once migration completes. But any path that
re-encodes the corrupted offset -- e.g. hugetlb_change_protection()
rewriting a writable migration entry via
make_readable_migration_entry(swp_offset(entry)) -- propagates it.
Migration entries legitimately carry uffd-wp, so clear it with
pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and
move_huge_pte().
A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is
installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not
preserve uffd-wp on the hwpoison path) and hugetlb_change_protection()
leaves hwpoison entries untouched. There was nothing to clear there, only
the corruption, so drop the clear entirely.
Link: https://lore.kernel.org/20260708090110.136162-1-kirill@shutemov.name
Fixes: bc70fbf269fd ("mm/hugetlb: handle uffd-wp during fork()")
Signed-off-by: Kiryl Shutsemau <kas@kernel.org>
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260703140011.99E601F000E9@smtp.kernel.org/
Suggested-by: David Hildenbrand <david@kernel.org>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Assisted-by: Claude:claude-fable-5
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Peter Xu <peterx@redhat.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/hugetlb.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -4917,8 +4917,12 @@ again:
softleaf = softleaf_from_pte(entry);
if (unlikely(softleaf_is_hwpoison(softleaf))) {
- if (!userfaultfd_wp(dst_vma))
- entry = huge_pte_clear_uffd_wp(entry);
+ /*
+ * A hwpoison entry never carries the uffd-wp bit: it is
+ * installed fresh by make_hwpoison_entry() and
+ * hugetlb_change_protection() leaves it untouched, so
+ * there is nothing to clear for the child.
+ */
set_huge_pte_at(dst, addr, dst_pte, entry, sz);
} else if (unlikely(softleaf_is_migration(softleaf))) {
bool uffd_wp = pte_swp_uffd_wp(entry);
@@ -4936,7 +4940,7 @@ again:
set_huge_pte_at(src, addr, src_pte, entry, sz);
}
if (!userfaultfd_wp(dst_vma))
- entry = huge_pte_clear_uffd_wp(entry);
+ entry = pte_swp_clear_uffd_wp(entry);
set_huge_pte_at(dst, addr, dst_pte, entry, sz);
} else if (unlikely(pte_is_marker(entry))) {
const pte_marker marker = copy_pte_marker(softleaf, dst_vma);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 206/438] pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (204 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 205/438] mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 207/438] pinctrl: devicetree: dont free uninitialized dev_name on error path Greg Kroah-Hartman
` (245 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Boortz, Andy Shevchenko,
Linus Walleij
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benjamin Boortz <bennib@mailbox.org>
commit 25cb6e9a13123d1039cdc75b446ac52e1ebdc26d upstream.
The driver calls ocelot_regmap_from_resource() via <linux/mfd/ocelot.h>,
which internally uses devm_regmap_init_mmio() and requires REGMAP_MMIO.
The Kconfig entry does not select REGMAP_MMIO, causing a build failure
when no other driver in the config happens to pull in REGMAP_MMIO:
include/linux/mfd/ocelot.h:34:24: error: implicit declaration of function 'devm_regmap_init_mmio'
Found by randconfig testing on arm64; tinyconfig reproducer below.
Fixes: 2afbbab45c26 ("pinctrl: microchip-sgpio: update to support regmap")
Cc: stable@vger.kernel.org
Signed-off-by: Benjamin Boortz <bennib@mailbox.org>
Reviewed-by: Andy Shevchenko <andy@kernel.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/Kconfig | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/pinctrl/Kconfig
+++ b/drivers/pinctrl/Kconfig
@@ -416,6 +416,7 @@ config PINCTRL_MICROCHIP_SGPIO
select GENERIC_PINCONF
select GENERIC_PINCTRL_GROUPS
select GENERIC_PINMUX_FUNCTIONS
+ select REGMAP_MMIO
help
Support for the serial GPIO interface used on Microsemi and
Microchip SoCs. By using a serial interface, the SIO
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 207/438] pinctrl: devicetree: dont free uninitialized dev_name on error path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (205 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 206/438] pinctrl: microchip-sgpio: add missing select REGMAP_MMIO Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 208/438] btrfs: raid56: fix scrub read assembly submitting no reads Greg Kroah-Hartman
` (244 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Linus Walleij
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 015b5bcbcb622b32317642be91a7f79aa5413649 upstream.
dt_remember_or_free_map() duplicates dev_name for each map entry. If
kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps
entries, including entries that have not been initialized.
Some pinctrl drivers, including pinctrl-imx, allocate the map with
kmalloc() and leave dev_name for the core to initialize. The untouched
entries therefore contain uninitialized data which is passed to
kfree_const().
Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection
while binding the pinctrl-consuming device, under KASAN:
BUG: KASAN: double-free in dt_free_map+0x34/0xa4
Free of addr c425a900 by task init/1
kfree from dt_free_map+0x34/0xa4
dt_free_map from dt_remember_or_free_map+0x184/0x198
dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8
pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0
Initialize all dev_name fields to NULL before duplicating the device
name, making the full-map cleanup safe after a partial failure.
Fixes: be4c60b563ed ("pinctrl: devicetree: Avoid taking direct reference to device name string")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/devicetree.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/pinctrl/devicetree.c
+++ b/drivers/pinctrl/devicetree.c
@@ -69,6 +69,10 @@ static int dt_remember_or_free_map(struc
int i;
struct pinctrl_dt_map *dt_map;
+ /* Initialize dev_name before any allocation can fail */
+ for (i = 0; i < num_maps; i++)
+ map[i].dev_name = NULL;
+
/* Initialize common mapping table entry fields */
for (i = 0; i < num_maps; i++) {
const char *devname;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 208/438] btrfs: raid56: fix scrub read assembly submitting no reads
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (206 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 207/438] pinctrl: devicetree: dont free uninitialized dev_name on error path Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 209/438] erofs: cap LZMA stream pool size Greg Kroah-Hartman
` (243 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Qu Wenruo, Mykola Lysenko,
David Sterba
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mykola Lysenko <nickolay.lysenko@gmail.com>
commit c4c0673e4cb15b0c127e6d00732a2427bdd12c11 upstream.
Commit 5387bd958180 ("btrfs: raid56: remove sector_ptr structure")
converted the bio-list membership checks from sector pointers to
physical addresses. The two conversions in rmw_assemble_write_bios()
kept their polarity (skip the sector when it is NOT in the bio list,
i.e. when there is nothing to write), but scrub_assemble_read_bios()
has the opposite polarity -- skip the sector when it IS in the bio
list, because then there is nothing to read -- and the conversion
flipped it:
- sector = sector_in_rbio(rbio, stripe, sectornr, 1);
- if (sector)
+ paddr = sector_paddr_in_rbio(rbio, stripe, sectornr, 1);
+ if (paddr == INVALID_PADDR)
continue;
Since a parity-scrub rbio's bio list only holds the empty completion
bio, the result is that scrub_assemble_read_bios() submits no reads at
all. finish_parity_scrub() then compares the parity it computes from
the (cached, correct) data stripes against whatever happens to be in
the freshly allocated, uninitialized stripe pages:
- if the garbage differs from the computed parity, the sector is
"repaired" and written back -- accidentally producing the correct
on-disk result;
- if a recycled page happens to still hold the old (correct) parity
content, the sector is deemed clean, dropped from dbitmap, and the
actually-corrupt on-disk parity is left in place. (Scrub reports
no errors either way: there is no counter for P/Q corruption by
design, so the bug here is purely the failure to read and repair.)
The second case is intermittent because it depends on page-allocator
recycling. Observed with fstests btrfs/297 (raid5, 2 devices): the
corrupted P stripe intermittently stays corrupt after a scrub --
roughly 1/10 runs on x86-64 KVM and up to 7/8 on a UML build whose
timing favors page reuse.
Since the bio-list check can never be true for a parity-scrub rbio --
raid56_parity_alloc_scrub_rbio() adds a single empty completion bio
(asserting bi_size == 0), bio_paddrs[] is only populated by
index_rbio_pages() which is never called for BTRFS_RBIO_PARITY_SCRUB,
and rbio_can_merge() refuses to merge rbios of different operations --
remove the dead check entirely and assert the invariant instead, as
suggested by Qu Wenruo.
After this fix the injected corruption is read, detected and repaired
in every run (8/8 UML, 10/10 KVM), and the new assertion never fires
across the full fstests raid group.
Fixes: 5387bd958180 ("btrfs: raid56: remove sector_ptr structure")
CC: stable@vger.kernel.org # 7.1+
Suggested-by: Qu Wenruo <quwenruo.btrfs@gmx.com>
Assisted-by: Claude:claude-fable-5
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/raid56.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/fs/btrfs/raid56.c b/fs/btrfs/raid56.c
index 3f2896e793e3..ca94c9e3d563 100644
--- a/fs/btrfs/raid56.c
+++ b/fs/btrfs/raid56.c
@@ -2911,13 +2911,12 @@ static int scrub_assemble_read_bios(struct btrfs_raid_bio *rbio)
continue;
/*
- * We want to find all the sectors missing from the rbio and
- * read them from the disk. If sector_paddr_in_rbio() finds a sector
- * in the bio list we don't need to read it off the stripe.
+ * A parity-scrub rbio carries no data in its bio list: the
+ * only bio there is the empty completion bio added by
+ * raid56_parity_alloc_scrub_rbio(). Every sector is read
+ * from the stripe, so only assert that invariant here.
*/
- paddrs = sector_paddrs_in_rbio(rbio, stripe, sectornr, 1);
- if (paddrs == NULL)
- continue;
+ ASSERT(!sector_paddrs_in_rbio(rbio, stripe, sectornr, 1));
paddrs = rbio_stripe_paddrs(rbio, stripe, sectornr);
/*
--
2.55.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 209/438] erofs: cap LZMA stream pool size
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (207 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 208/438] btrfs: raid56: fix scrub read assembly submitting no reads Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 210/438] pinctrl: bm1880: add missing select GENERIC_PINCONF Greg Kroah-Hartman
` (242 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Gao Xiang
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
commit c9b47e6b23114e939b17f818471c7a46e59006e7 upstream.
fs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream
pool from num_possible_cpus() when the lzma_streams module parameter is
unset, then z_erofs_load_lzma_config() preallocates one image-supplied
dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU
systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed
decoder state until the erofs module is unloaded.
Impact: An EROFS image mounted by the system can pin up to 8 MiB of
vmalloc memory per LZMA stream, either as intended or unexpectedly.
Bound the default stream count by a new
CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the
worst-case default preallocation is 128 MiB if the number of CPUs is no
less than 16 while preserving the existing per-image dictionary limit.
An explicit lzma_streams module parameter is still honoured as-is, so
administrators who deliberately size the pool are not affected.
Fixes: 622ceaddb764 ("erofs: lzma compression support")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/erofs/Kconfig | 14 ++++++++++++++
fs/erofs/decompressor_lzma.c | 3 ++-
2 files changed, 16 insertions(+), 1 deletion(-)
--- a/fs/erofs/Kconfig
+++ b/fs/erofs/Kconfig
@@ -131,6 +131,20 @@ config EROFS_FS_ZIP_LZMA
Say N if you want to disable LZMA compression support.
+config EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS
+ int "EROFS LZMA default maximum decompression streams"
+ depends on EROFS_FS_ZIP_LZMA
+ range 1 NR_CPUS
+ default 16
+ help
+ By default EROFS allocates one LZMA decompression stream per CPU.
+ Each stream can hold a dictionary of up to 8 MiB taken from the
+ mounted image, so on systems with many CPUs this can reserve a lot
+ of memory. This caps the default; the lzma_streams module parameter
+ still overrides it.
+
+ If unsure, keep the default of 16.
+
config EROFS_FS_ZIP_DEFLATE
bool "EROFS DEFLATE compressed data support"
depends on EROFS_FS_ZIP
--- a/fs/erofs/decompressor_lzma.c
+++ b/fs/erofs/decompressor_lzma.c
@@ -51,7 +51,8 @@ static int __init z_erofs_lzma_init(void
/* by default, use # of possible CPUs instead */
if (!z_erofs_lzma_nstrms)
- z_erofs_lzma_nstrms = num_possible_cpus();
+ z_erofs_lzma_nstrms = min_t(unsigned int, num_possible_cpus(),
+ CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS);
for (i = 0; i < z_erofs_lzma_nstrms; ++i) {
struct z_erofs_lzma *strm = kzalloc_obj(*strm);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 210/438] pinctrl: bm1880: add missing select GENERIC_PINCONF
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (208 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 209/438] erofs: cap LZMA stream pool size Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 211/438] fortify: Disable -Wstringop-overread in tests Greg Kroah-Hartman
` (241 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Benjamin Boortz, Linus Walleij
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benjamin Boortz <bennib@mailbox.org>
commit dad6e107b3cd9d20514e7799b7ad8674f81e3f30 upstream.
drivers/pinctrl/pinctrl-bm1880.c initialises its pinconf_ops with
.is_generic = true, but that field is only present when
CONFIG_GENERIC_PINCONF is enabled (guarded by #ifdef in pinconf.h).
The Kconfig entry for PINCTRL_BM1880 never selects GENERIC_PINCONF,
so any config that enables CONFIG_PINCTRL_BM1880=y without
CONFIG_GENERIC_PINCONF=y fails to compile:
drivers/pinctrl/pinctrl-bm1880.c:1288:10: error: 'const struct pinconf_ops' has no member named 'is_generic'
Found by randconfig testing on arm64; tinyconfig reproducer below.
Add the missing select to fix the build.
Fixes: 49bd61ebce5f ("pinctrl: Add pinconf support for BM1880 SoC")
Cc: stable@vger.kernel.org
Signed-off-by: Benjamin Boortz <bennib@mailbox.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/Kconfig | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/pinctrl/Kconfig
+++ b/drivers/pinctrl/Kconfig
@@ -166,6 +166,7 @@ config PINCTRL_BM1880
depends on OF && (ARCH_BITMAIN || COMPILE_TEST)
default ARCH_BITMAIN
select PINMUX
+ select GENERIC_PINCONF
help
Pinctrl driver for Bitmain BM1880 SoC.
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 211/438] fortify: Disable -Wstringop-overread in tests
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (209 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 210/438] pinctrl: bm1880: add missing select GENERIC_PINCONF Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 212/438] lib: test_hmm: use device devt for coherent device range selection Greg Kroah-Hartman
` (240 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nathan Chancellor, Kees Cook
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nathan Chancellor <nathan@kernel.org>
commit c1f3e770eec26d6f96dd6d2ea30555ba7c09a244 upstream.
clang recently added support for -Wstringop-overread [1], which is on by
default like -Wfortify-source. This breaks the usage of -Werror in the
fortify tests, resulting in the following false positive warnings in the
kernel build:
warning: unsafe memcmp() usage lacked '__read_overflow2' warning in lib/test_fortify/read_overflow2-memcmp.c
warning: unsafe memcmp() usage lacked '__read_overflow' warning in lib/test_fortify/read_overflow-memcmp.c
warning: unsafe memchr() usage lacked '__read_overflow' warning in lib/test_fortify/read_overflow-memchr.c
Examining the fortify test logs shows a warning like the following in
each of the failed logs:
In file included from lib/test_fortify/read_overflow2-memcmp.c:5:
lib/test_fortify/test_fortify.h:34:2: error: 'memcmp' reading 17 bytes from a region of size 16 [-Werror,-Wstringop-overread]
34 | TEST;
| ^
lib/test_fortify/read_overflow2-memcmp.c:3:2: note: expanded from macro 'TEST'
3 | memcmp(large, small, sizeof(small) + 1)
| ^
1 error generated.
Disable -Wstringop-overread for the fortify tests, as it defeats the
purpose of testing the Linux specific implementation of fortify, like
-Wfortify-source.
Cc: stable@vger.kernel.org
Closes: https://github.com/ClangBuiltLinux/linux/issues/2168
Link: https://github.com/llvm/llvm-project/commit/86f2e71cb8d165b59ad31a442b2391e23826133e [1]
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Link: https://patch.msgid.link/20260623-fix-test_fortify-for-clang-stringop-overread-v1-1-15ee8342a953@kernel.org
Signed-off-by: Kees Cook <kees@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
lib/test_fortify/Makefile | 1 +
1 file changed, 1 insertion(+)
--- a/lib/test_fortify/Makefile
+++ b/lib/test_fortify/Makefile
@@ -1,6 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
ccflags-y := $(call cc-disable-warning,fortify-source)
+ccflags-y += $(call cc-disable-warning,stringop-overread)
quiet_cmd_test_fortify = TEST $@
cmd_test_fortify = $(CONFIG_SHELL) $(src)/test_fortify.sh \
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 212/438] lib: test_hmm: use device devt for coherent device range selection
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (210 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 211/438] fortify: Disable -Wstringop-overread in tests Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 213/438] btrfs: zoned: fix missing chunk metadata reservation Greg Kroah-Hartman
` (239 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Alistair Popple, Balbir Singh, Zenghui Yu (Huawei),
Jason Gunthorpe, Leon Romanovsky, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@gmail.com>
commit 4fc089235378d1f9ddb6bcbe67c192ffdcaae0ed upstream.
Commit af69016dab96 ("lib: test_hmm: implement a device release method")
moved the initial dmirror_allocate_chunk() call before cdev_device_add().
That means the struct cdev has not been added yet, so cdev_add() has not
initialized mdevice->cdevice.dev.
The coherent-device range selection uses the device minor to choose
between spm_addr_dev0 and spm_addr_dev1. Reading
MINOR(mdevice->cdevice.dev) before cdev_add() therefore always sees an
uninitialized dev_t. As a result, both coherent devices select the same
physical range, and adding the second device fails due to the overlapping
dev_pagemap range.
Use mdevice->device.devt instead. It is initialized in
dmirror_device_init() before dmirror_allocate_chunk() is called and is the
same dev_t later passed to cdev_device_add().
Link: https://lore.kernel.org/178277581197.172200.16265155329935822153.stgit@skinsburskii
Fixes: af69016dab96 ("lib: test_hmm: implement a device release method")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@gmail.com>
Reviewed-by: Alistair Popple <apopple@nvidia.com>
Cc: Balbir Singh <balbirs@nvidia.com>
Cc: Zenghui Yu (Huawei) <zenghui.yu@linux.dev>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Leon Romanovsky <leon@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
lib/test_hmm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/test_hmm.c b/lib/test_hmm.c
index 9c59d1ceb5b5..c4adbf98fac7 100644
--- a/lib/test_hmm.c
+++ b/lib/test_hmm.c
@@ -581,7 +581,7 @@ static int dmirror_allocate_chunk(struct dmirror_device *mdevice,
devmem->pagemap.type = MEMORY_DEVICE_PRIVATE;
break;
case HMM_DMIRROR_MEMORY_DEVICE_COHERENT:
- devmem->pagemap.range.start = (MINOR(mdevice->cdevice.dev) - 2) ?
+ devmem->pagemap.range.start = (MINOR(mdevice->device.devt) - 2) ?
spm_addr_dev0 :
spm_addr_dev1;
devmem->pagemap.range.end = devmem->pagemap.range.start +
--
2.55.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 213/438] btrfs: zoned: fix missing chunk metadata reservation
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (211 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 212/438] lib: test_hmm: use device devt for coherent device range selection Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 214/438] ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset Greg Kroah-Hartman
` (238 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Thumshirn, Guanghui Yang,
David Sterba
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanghui Yang <3497809730@qq.com>
commit 8bc4d7209611e8aa9d5409b6a4a86a9eb91b69a3 upstream.
reserve_chunk_space() stores the return value of
btrfs_zoned_activate_one_bg() in ret. The helper can return 1 after
successfully activating a block group, but ret is later used to decide
whether to reserve metadata for chunk tree updates.
As a result, successful activation skips btrfs_block_rsv_add() and leaves
trans->chunk_bytes_reserved unchanged. Use a separate variable for the
activation result so positive success does not affect the later
reservation. Keep activation failures in ret instead of returning early so
the function uses the common tail path.
Fixes: b6a98021e401 ("btrfs: zoned: activate necessary block group")
CC: stable@vger.kernel.org
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/block-group.c | 34 +++++++++++++++++++---------------
1 file changed, 19 insertions(+), 15 deletions(-)
--- a/fs/btrfs/block-group.c
+++ b/fs/btrfs/block-group.c
@@ -4504,25 +4504,29 @@ static void reserve_chunk_space(struct b
if (IS_ERR(bg)) {
ret = PTR_ERR(bg);
} else {
+ int activate_ret;
+
/*
* We have a new chunk. We also need to activate it for
* zoned filesystem.
*/
- ret = btrfs_zoned_activate_one_bg(info, true);
- if (ret < 0)
- return;
-
- /*
- * If we fail to add the chunk item here, we end up
- * trying again at phase 2 of chunk allocation, at
- * btrfs_create_pending_block_groups(). So ignore
- * any error here. An ENOSPC here could happen, due to
- * the cases described at do_chunk_alloc() - the system
- * block group we just created was just turned into RO
- * mode by a scrub for example, or a running discard
- * temporarily removed its free space entries, etc.
- */
- btrfs_chunk_alloc_add_chunk_item(trans, bg);
+ activate_ret = btrfs_zoned_activate_one_bg(info, true);
+ if (activate_ret < 0) {
+ ret = activate_ret;
+ } else {
+ /*
+ * If we fail to add the chunk item here, we end
+ * up trying again at phase 2 of chunk allocation,
+ * at btrfs_create_pending_block_groups(). So
+ * ignore any error here. An ENOSPC here could
+ * happen, due to the cases described at
+ * do_chunk_alloc() - the system block group we
+ * just created was just turned into RO mode by a
+ * scrub for example, or a running discard
+ * temporarily removed its free space entries, etc.
+ */
+ btrfs_chunk_alloc_add_chunk_item(trans, bg);
+ }
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 214/438] ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (212 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 213/438] btrfs: zoned: fix missing chunk metadata reservation Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 215/438] mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE Greg Kroah-Hartman
` (237 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joseph Qi, Dmitry Antipov,
Mark Fasheh, Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao,
Heming Zhao, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joseph Qi <joseph.qi@linux.alibaba.com>
commit df8ce7ab48d01ac4f247599b35f0506d95ff57e1 upstream.
Commit 390ac56cf0f6 ("ocfs2: add boundary check to
ocfs2_check_dir_entry()") added an out-of-bounds guard using the
caller-supplied 'offset' argument:
if (offset > size - OCFS2_DIR_REC_LEN(1))
return 0;
However, 'offset' and 'size' are not measured against the same base for
all callers. In the block-based lookup path, ocfs2_find_entry_el() passes
'offset' as an absolute offset into the whole directory:
i = ocfs2_search_dirblock(bh, dir, name, namelen,
block << sb->s_blocksize_bits,
bh->b_data, sb->s_blocksize, res_dir);
while 'size' is a single block size (sb->s_blocksize). For any directory
entry located in the second or later block, 'offset' is >=
sb->s_blocksize, so the guard rejects every such entry even though it is
perfectly valid and lies entirely within its block buffer.
This makes mounting fail for filesystems whose system directory spans more
than one block, e.g. a volume formatted with a small block size:
mkfs.ocfs2 -b 512 -C 4096 -N 2 -T datafiles --fs-features=usrquota,grpquota
ocfs2_check_dir_entry:314 ERROR: directory entry (#18: offset=512) too close to end or out-of-bounds
ocfs2_init_local_system_inodes:496 ERROR: status=-22, sysfile=12, slot=0
ocfs2_mount_volume:1757 ERROR: status = -22
The dirent's position within the buffer being validated is ((char *)de -
buf), which is what the rest of the function already uses (via
next_offset) and what must be bounds-checked against 'size'. Compute that
buffer-relative offset and use it for the guard. The subtraction is
reordered to size - buf_offset < OCFS2_DIR_REC_LEN(1) to avoid an unsigned
underflow when size is smaller than the minimal record length.
Link: https://lore.kernel.org/20260710040512.3310736-1-joseph.qi@linux.alibaba.com
Fixes: 390ac56cf0f6 ("ocfs2: add boundary check to ocfs2_check_dir_entry()")
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Reviewed-by: Dmitry Antipov <dmantipov@yandex.ru>
Tested-by: Dmitry Antipov <dmantipov@yandex.ru>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/ocfs2/dir.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/fs/ocfs2/dir.c
+++ b/fs/ocfs2/dir.c
@@ -302,10 +302,11 @@ static int ocfs2_check_dir_entry(struct
unsigned long offset)
{
const char *error_msg = NULL;
+ unsigned long buf_offset = (char *)de - buf;
unsigned long next_offset;
int rlen;
- if (offset > size - OCFS2_DIR_REC_LEN(1)) {
+ if (buf_offset > size || size - buf_offset < OCFS2_DIR_REC_LEN(1)) {
/* Dirent is (maybe partially) beyond the buffer
* boundaries so touching 'de' members is unsafe.
*/
@@ -316,7 +317,7 @@ static int ocfs2_check_dir_entry(struct
}
rlen = le16_to_cpu(de->rec_len);
- next_offset = ((char *) de - buf) + rlen;
+ next_offset = buf_offset + rlen;
if (unlikely(rlen < OCFS2_DIR_REC_LEN(1)))
error_msg = "rec_len is smaller than minimal";
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 215/438] mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (213 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 214/438] ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 216/438] mm/util: dont read __page_2 for order-1 folios in snapshot_page() Greg Kroah-Hartman
` (236 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kefeng Wang, Balbir Singh, Zi Yan,
Alistair Popple, Byungchul Park, David Hildenbrand, Gregory Price,
Huang, Ying, Joshua Hahn, Matthew Brost, Rakie Kim, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kefeng Wang <wangkefeng.wang@huawei.com>
commit 63867c82d0c0c2d182016a32b1cc0103116b0ea5 upstream.
pte_pfn() and pte_dirty() have undefined behaviour when called on a
non-present PTE. In migrate_vma_collect_pmd(), these functions may be
invoked on non-present entries (e.g., device-private entries), leading
to potential crashes from pte_pfn() or incorrect dirty folio accounting
from pte_dirty(). Fix both by guarding with pte_present() checks.
Link: https://lore.kernel.org/20260708003955.4024340-1-wangkefeng.wang@huawei.com
Link: https://lore.kernel.org/20260706111958.3649651-1-wangkefeng.wang@huawei.com
Fixes: fd35ca3d12cc ("mm/migrate_device.c: copy pte dirty bit to page")
Fixes: 6c287605fd56 ("mm: remember exclusively mapped anonymous pages with PG_anon_exclusive")
Signed-off-by: Kefeng Wang <wangkefeng.wang@huawei.com>
Reviewed-by: Balbir Singh <balbirs@nvidia.com>
Acked-by: Zi Yan <ziy@nvidia.com>
Cc: Alistair Popple <apopple@nvidia.com>
Cc: Byungchul Park <byungchul@sk.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Gregory Price <gourry@gourry.net>
Cc: "Huang, Ying" <ying.huang@linux.alibaba.com>
Cc: Joshua Hahn <joshua.hahnjy@gmail.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: Rakie Kim <rakie.kim@sk.com>
Cc: Ying Huang <ying.huang@linux.alibaba.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/migrate_device.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/mm/migrate_device.c
+++ b/mm/migrate_device.c
@@ -401,7 +401,8 @@ again:
bool anon_exclusive;
pte_t swp_pte;
- flush_cache_page(vma, addr, pte_pfn(pte));
+ if (pte_present(pte))
+ flush_cache_page(vma, addr, pte_pfn(pte));
anon_exclusive = folio_test_anon(folio) &&
PageAnonExclusive(page);
if (anon_exclusive) {
@@ -422,7 +423,7 @@ again:
migrate->cpages++;
/* Set the dirty flag on the folio now the pte is gone. */
- if (pte_dirty(pte))
+ if (pte_present(pte) && pte_dirty(pte))
folio_mark_dirty(folio);
/* Setup special migration page table entry */
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 216/438] mm/util: dont read __page_2 for order-1 folios in snapshot_page()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (214 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 215/438] mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 217/438] selftest: fix headers in fclog.c Greg Kroah-Hartman
` (235 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aboorva Devarajan, Sourabh Jain,
David Hildenbrand (Arm), Lorenzo Stoakes, Matthew Wilcox (Oracle),
Luiz Capitulino, Liam R. Howlett, Michal Hocko, Mike Rapoport,
Ritesh Harjani (IBM), Suren Baghdasaryan, Vlastimil Babka,
Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aboorva Devarajan <aboorvad@linux.ibm.com>
commit 7441d6348c70738e9ed307510db171c7a9b3f4bf upstream.
snapshot_page() currently reads __page_2 after checking nr_pages > 1, but
it should only do so when nr_pages > 2.
If an order-1 folio is allocated at the end of a vmemmap section,
__page_2 will not exist and reading it will cause a fault.
During DLPAR memory remove on a 22 TB ppc64le LPAR, snapshot_page() oopsed
on the page isolation path while reading an order-1 folio's __page_2 from
an adjacent absent section (unmapped vmemmap).
Fix this to avoid reading memmap that doesn't exist (e.g., a vmemmap
hole).
Link: https://lore.kernel.org/20260708201954.686111-1-aboorvad@linux.ibm.com
Fixes: 31a31da8a618 ("mm: move _pincount in folio to page[2] on 32bit")
Signed-off-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
Reported-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Lorenzo Stoakes <ljs@kernel.org>
Reviewed-by: Matthew Wilcox (Oracle) <willy@infradead.org>
Reviewed-by: Luiz Capitulino <luizcap@redhat.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: "Ritesh Harjani (IBM)" <ritesh.list@gmail.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org> # v6.15+
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/util.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/util.c
+++ b/mm/util.c
@@ -1352,7 +1352,7 @@ again:
if (ps->idx < MAX_FOLIO_NR_PAGES) {
memcpy(&ps->folio_snapshot, foliop, 2 * sizeof(struct page));
nr_pages = folio_nr_pages(&ps->folio_snapshot);
- if (nr_pages > 1)
+ if (nr_pages > 2)
memcpy(&ps->folio_snapshot.__page_2, &foliop->__page_2,
sizeof(struct page));
set_ps_flags(ps, foliop, page);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 217/438] selftest: fix headers in fclog.c
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (215 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 216/438] mm/util: dont read __page_2 for order-1 folios in snapshot_page() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 218/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes Greg Kroah-Hartman
` (234 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jori Koolstra, Aleksa Sarai,
Shuah Khan, Wei Yang, Christian Brauner, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jori Koolstra <jkoolstra@xs4all.nl>
commit e3a0127eee04db8769e53c8102c4e76aa49be8c3 upstream.
fclog.c does not compile because it is missing fcntl.h, needed for
O_RDONLY etc.
There are also some redundant includes that are also in
kselftest_harness.h.
Link: https://lore.kernel.org/20260710171741.837308-1-jkoolstra@xs4all.nl
Signed-off-by: Jori Koolstra <jkoolstra@xs4all.nl>
Cc: Aleksa Sarai <cyphar@cyphar.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wei Yang <richard.weiyang@gmail.com>
Cc: Christian Brauner <brauner@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/filesystems/fclog.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/tools/testing/selftests/filesystems/fclog.c
+++ b/tools/testing/selftests/filesystems/fclog.c
@@ -6,10 +6,8 @@
#include <assert.h>
#include <errno.h>
+#include <fcntl.h>
#include <sched.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
#include <unistd.h>
#include <sys/mount.h>
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 218/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (216 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 217/438] selftest: fix headers in fclog.c Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 219/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes Greg Kroah-Hartman
` (233 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kiryl Shutsemau,
Muhammad Usama Anjum, David Hildenbrand, Jann Horn,
Liam R. Howlett, Lorenzo Stoakes, Michal Hocko, Mike Rapoport,
Pedro Falcato, Peter Xu, Shuah Khan, Suren Baghdasaryan,
Vlastimil Babka, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kiryl Shutsemau (Meta) <kas@kernel.org>
commit 07b4377bdbe74a3ec0c8da5849d014f70e003384 upstream.
PAGEMAP_SCAN reports an unpopulated pte differently depending on which
path serves the request. The PAGE_IS_WRITTEN fast path in
pagemap_scan_pmd_entry() reports a pte_none as written (and, under
PM_SCAN_WP_MATCHING, arms a marker); pagemap_page_category() returns 0 for
the same pte_none. A request that cannot take the fast path (an extra
category bit, category_anyof_mask or category_inverted) therefore reports
the pte as clean and skips arming it.
A range that was populated and then MADV_DONTNEED'd reads as written via
one mask and clean via another, and in the latter case is not re-armed for
the next round -- an incremental-dump consumer (e.g. CRIU) using a richer
mask drops the zapped range and stops tracking writes to it.
Report pte_none as written in pagemap_page_category() too. A pte_none
carries no uffd-wp marker, i.e. it is not write-protected -- the same
condition under which the present and swap cases already report
PAGE_IS_WRITTEN. The fast path applies no VMA test, so neither does this.
The hugetlb and fully-unpopulated-PMD (no page table) scans have no
PAGE_IS_WRITTEN fast path, so they do not exhibit the per-entry divergence
and are left unchanged.
Add a pagemap_ioctl selftest that populates a range, drops it with
MADV_DONTNEED, and checks that the fast path and the generic
(category_anyof_mask) path both report every page written.
Link: https://lore.kernel.org/20260707151349.92143-1-kirill@shutemov.name
Fixes: 12f6b01a0bcb ("fs/proc/task_mmu: add fast paths to get/clear PAGE_IS_WRITTEN flag")
Signed-off-by: Kiryl Shutsemau <kas@kernel.org>
Cc: Muhammad Usama Anjum <usama.anjum@collabora.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Assisted-by: Claude:claude-fable-5
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/proc/task_mmu.c | 14 ++++++-
tools/testing/selftests/mm/pagemap_ioctl.c | 56 ++++++++++++++++++++++++++++-
2 files changed, 67 insertions(+), 3 deletions(-)
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -2345,8 +2345,18 @@ static unsigned long pagemap_page_catego
{
unsigned long categories;
- if (pte_none(pte))
- return 0;
+ if (pte_none(pte)) {
+ /*
+ * An unpopulated pte carries no uffd-wp marker, i.e. it is not
+ * write-protected, the same condition under which the present
+ * and swap cases below report PAGE_IS_WRITTEN. Report it here
+ * too so this generic path agrees with the PAGE_IS_WRITTEN fast
+ * path in pagemap_scan_pmd_entry(), which reports pte_none as
+ * written and, under PM_SCAN_WP_MATCHING, arms a marker. The
+ * fast path applies no VMA test, so neither does this.
+ */
+ return PAGE_IS_WRITTEN;
+ }
if (pte_present(pte)) {
struct page *page;
--- a/tools/testing/selftests/mm/pagemap_ioctl.c
+++ b/tools/testing/selftests/mm/pagemap_ioctl.c
@@ -1049,6 +1049,57 @@ static void test_simple(void)
ksft_test_result(i == TEST_ITERATIONS, "Test %s\n", __func__);
}
+/*
+ * A range that was populated and then MADV_DONTNEED'd is genuine pte_none
+ * with no uffd-wp marker. Such a pte must read the same regardless of which
+ * PAGEMAP_SCAN path serves the request: both the PAGE_IS_WRITTEN fast path and
+ * the generic path (reached e.g. via category_anyof_mask) must report every
+ * page written.
+ */
+static void unpopulated_scan_test(void)
+{
+ int npages = 16, i;
+ long mem_size = npages * page_size;
+ struct page_region regions[16];
+ long fast = 0, slow = 0, ret;
+ char *mem;
+
+ mem = mmap(NULL, mem_size, PROT_READ | PROT_WRITE,
+ MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
+ if (mem == MAP_FAILED)
+ ksft_exit_fail_msg("%s mmap failed\n", __func__);
+
+ wp_init(mem, mem_size);
+
+ /* Populate, then drop: the ptes become pte_none without a marker. */
+ memset(mem, 1, mem_size);
+ if (madvise(mem, mem_size, MADV_DONTNEED))
+ ksft_exit_fail_msg("%s MADV_DONTNEED failed\n", __func__);
+
+ /* Fast path: category_mask == return_mask == PAGE_IS_WRITTEN. */
+ ret = pagemap_ioctl(mem, mem_size, regions, npages, 0, 0,
+ PAGE_IS_WRITTEN, 0, 0, PAGE_IS_WRITTEN);
+ if (ret < 0)
+ ksft_exit_fail_msg("%s fast scan failed\n", __func__);
+ for (i = 0; i < ret; i++)
+ fast += LEN(regions[i]);
+
+ /* Generic path: same query expressed via category_anyof_mask. */
+ ret = pagemap_ioctl(mem, mem_size, regions, npages, 0, 0,
+ 0, PAGE_IS_WRITTEN, 0, PAGE_IS_WRITTEN);
+ if (ret < 0)
+ ksft_exit_fail_msg("%s generic scan failed\n", __func__);
+ for (i = 0; i < ret; i++)
+ slow += LEN(regions[i]);
+
+ ksft_test_result(fast == npages && slow == npages,
+ "%s unpopulated ptes reported written by both paths (%ld, %ld of %d)\n",
+ __func__, fast, slow, npages);
+
+ wp_free(mem, mem_size);
+ munmap(mem, mem_size);
+}
+
int sanity_tests(void)
{
unsigned long long mem_size, vec_size;
@@ -1554,7 +1605,7 @@ int main(int __attribute__((unused)) arg
if (init_uffd())
ksft_exit_skip("Failed to initialize userfaultfd\n");
- ksft_set_plan(117);
+ ksft_set_plan(118);
page_size = getpagesize();
hpage_size = read_pmd_pagesize();
@@ -1732,6 +1783,9 @@ int main(int __attribute__((unused)) arg
/* 17. ZEROPFN tests */
zeropfn_tests();
+ /* 18. Unpopulated pte scan-path consistency */
+ unpopulated_scan_test();
+
close(pagemap_fd);
ksft_finished();
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 219/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (217 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 218/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 220/438] mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() Greg Kroah-Hartman
` (232 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kiryl Shutsemau, Sashiko AI review,
Muhammad Usama Anjum, David Hildenbrand (Arm), Peter Xu,
Jann Horn, Liam R. Howlett, Lorenzo Stoakes, Michal Hocko,
Mike Rapoport, Pedro Falcato, Shuah Khan, Suren Baghdasaryan,
Vlastimil Babka, Zenghui Yu, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kiryl Shutsemau (Meta) <kas@kernel.org>
commit 40de8160ca7f67d14619ee0351ce5d68fc4a237a upstream.
PAGEMAP_SCAN reports an unpopulated PTE in a uffd-wp VMA as written, but a
range with no page table at all -- a PMD hole -- is skipped:
pagemap_scan_pte_hole() tests p->cur_vma_category, which never carries
PAGE_IS_WRITTEN, so the hole is neither reported nor (under
PM_SCAN_WP_MATCHING) armed.
In a uffd-wp VMA, WP_UNPOPULATED installs uffd-wp markers when protecting
a range, allocating page tables as needed, so an unpopulated slot is
treated as written -- see the pte_none() handling in
pagemap_page_category(). A missing marker therefore means the range was
zapped, e.g. via MADV_DONTNEED. This applies to anon and shmem VMAs.
An anonymous THP is write-protected in place as a huge PMD, so a full-PMD
MADV_DONTNEED clears it to pmd_none -- a hole with no page table -- and
pagemap_scan_pte_hole() misses it. For a MAP_PRIVATE|MAP_ANON mapping
MADV_DONTNEED has fill-with-zeros semantics, so a write-tracking
checkpoint/migration tool (e.g. CRIU) treats the range as unchanged and
keeps its previous contents; after restore or live migration the process
reads stale data instead of zeroes -- data corruption.
Report a hole in a non-hugetlb uffd-wp VMA as written, matching the
pte_none handling in pagemap_page_category(); the existing
PM_SCAN_WP_MATCHING path then arms it via uffd_wp_range().
hugetlb is excluded: pagemap_hugetlb_category() reports an empty hugetlb
entry (huge_pte_none) as not-written, unlike pagemap_page_category(),
which reports pte_none as written. pagemap_scan_pte_hole() fires for a
hugetlb slot only when it has no page table; keeping that not-written
matches how an allocated-but-empty hugetlb entry reads, so the hole and
the empty-entry cases agree within the VMA.
Link: https://lore.kernel.org/20260715144234.442721-2-kirill@shutemov.name
Fixes: 2bad466cc9d9 ("mm/uffd: UFFD_FEATURE_WP_UNPOPULATED")
Signed-off-by: Kiryl Shutsemau <kas@kernel.org>
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260707151349.92143-1-kirill@shutemov.name
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Cc: Peter Xu <peterx@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: Zenghui Yu <zenghui.yu@linux.dev>
Assisted-by: Claude:claude-fable-5
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/proc/task_mmu.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -2962,12 +2962,28 @@ static int pagemap_scan_pte_hole(unsigne
{
struct pagemap_scan_private *p = walk->private;
struct vm_area_struct *vma = walk->vma;
+ unsigned long categories;
int ret, err;
- if (!vma || !pagemap_scan_is_interesting_page(p->cur_vma_category, p))
+ if (!vma)
return 0;
- ret = pagemap_scan_output(p->cur_vma_category, p, addr, &end);
+ /*
+ * In a uffd-wp VMA an unpopulated range is treated as written:
+ * uffd-wp registration populates page tables and installs markers
+ * with WP_UNPOPULATED, so a missing marker means the range was
+ * zapped. See the pte_none() handling in pagemap_page_category().
+ *
+ * hugetlb differs, see pagemap_hugetlb_category().
+ */
+ categories = p->cur_vma_category;
+ if (userfaultfd_wp(vma) && !is_vm_hugetlb_page(vma))
+ categories |= PAGE_IS_WRITTEN;
+
+ if (!pagemap_scan_is_interesting_page(categories, p))
+ return 0;
+
+ ret = pagemap_scan_output(categories, p, addr, &end);
if (addr == end)
return ret;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 220/438] mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (218 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 219/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 221/438] mm/hugetlb: fix list corruption in allocate_file_region_entries() Greg Kroah-Hartman
` (231 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Zi Yan, Dennis Zhou,
Christoph Lameter, Tejun Heo, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zi Yan <ziy@nvidia.com>
commit 89b1b79c308818a715e75f28744b70d8940a07c9 upstream.
In pcpu_create_chunk(), nr_pages is the total contiguous backing
allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()
uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap.
Since bit N in chunk->populated means page offset N inside every unit is
backed. When nr_units > 1, the function writes beyond chunk->populated.
Fix it by using chunk->nr_pages.
It also fixes the global pcpu_nr_empty_pop_pages accounting, since
pcpu_balance_free() only iterates up to chunk->nr_pages.
Commit a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap
properly") introduced the bitmap overflow issue. Later, commit
b539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and
chunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the
accounting issue.
Link: https://lore.kernel.org/20260709-fix-pcpu_create_chunk-in-percpu-km-v1-1-1f64745a84cc@nvidia.com
Fixes: a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap properly")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260703-keep-subpage-private-zero-at-free-v2-0-2970fe777dd6%40nvidia.com?part=1
Assisted-by: Codex:GPT-5
Signed-off-by: Zi Yan <ziy@nvidia.com>
Acked-by: Dennis Zhou <dennis@kernel.org>
Cc: Christoph Lameter <cl@linux.com>
Cc: Tejun Heo <tj@kernel.org>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/percpu-km.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/percpu-km.c
+++ b/mm/percpu-km.c
@@ -75,7 +75,7 @@ static struct pcpu_chunk *pcpu_create_ch
chunk->base_addr = page_address(pages);
spin_lock_irqsave(&pcpu_lock, flags);
- pcpu_chunk_populated(chunk, 0, nr_pages);
+ pcpu_chunk_populated(chunk, 0, chunk->nr_pages);
spin_unlock_irqrestore(&pcpu_lock, flags);
pcpu_stats_chunk_alloc();
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 221/438] mm/hugetlb: fix list corruption in allocate_file_region_entries()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (219 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 220/438] mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 222/438] userfaultfd: wait on source PMD during UFFDIO_MOVE Greg Kroah-Hartman
` (230 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiangfeng Cai, Muchun Song,
Baoquan He, David Hildenbrand, Oscar Salvador, Shuah Khan,
Wei Yang, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiangfeng Cai <caixiangfeng@bytedance.com>
commit dd9623f58ec702a07b2d67179d6fcea79c52231a upstream.
allocate_file_region_entries() tops up resv->region_cache with freshly
allocated file_region descriptors. The allocation uses GFP_KERNEL, so
resv->lock is dropped around it: the new entries are gathered on a
stack-local list head, allocated_regions, and spliced into
resv->region_cache once the lock is re-acquired.
The splice used list_splice(), which moves the entries but does not
re-initialize the source head, so allocated_regions is left pointing at an
entry that now lives on resv->region_cache. The top-up runs in a while
loop that re-checks the cache deficit after re-acquiring the lock. For a
shared mapping the resv_map is shared by every mapper of the hugetlbfs
inode, so a concurrent region_chg()/region_add()/region_del() on the same
resv_map can consume cache entries during the unlocked window and force a
second iteration. That iteration calls list_add() on the stale head and
corrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check
trips:
list_add corruption. next->prev should be prev (ffffc900011ff7f8),
but was ffff88814c281460. (next=ffff88814c545640).
kernel BUG at lib/list_debug.c:31!
allocate_file_region_entries+0x191/0x420
region_chg+0x267/0x300
hugetlb_reserve_pages+0x387/0xc80
hugetlbfs_file_mmap+0x2ce/0x3f0
mmap_region+0x1348/0x1a80
do_mmap+0x85e/0xb90
vm_mmap_pgoff+0x18c/0x330
ksys_mmap_pgoff+0x2a1/0x3e0
do_syscall_64+0xd7/0x420
Without CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack
address into resv->region_cache, leading to later use-after-free.
This was observed as a real host panic on a dense KVM host where a QEMU
guest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate
SPDK/DPDK vhost-user target, generating concurrent region_* traffic on one
shared resv_map.
Use list_splice_init() so the source head is re-initialized empty after
each splice, making the retry loop safe.
Link: https://lore.kernel.org/20260713171456.300518-2-caixiangfeng@bytedance.com
Fixes: d3ec7b6e09e5 ("mm/hugetlb: use list_splice to merge two list at once")
Signed-off-by: Xiangfeng Cai <caixiangfeng@bytedance.com>
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Cc: Baoquan He <baoquan.he@linux.dev>
Cc: David Hildenbrand <david@kernel.org>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wei Yang <richard.weiyang@linux.alibaba.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/hugetlb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -693,7 +693,7 @@ static int allocate_file_region_entries(
spin_lock(&resv->lock);
- list_splice(&allocated_regions, &resv->region_cache);
+ list_splice_init(&allocated_regions, &resv->region_cache);
resv->region_cache_count += to_allocate;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 222/438] userfaultfd: wait on source PMD during UFFDIO_MOVE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (220 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 221/438] mm/hugetlb: fix list corruption in allocate_file_region_entries() Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 223/438] mm/vmstat: fold stranded per-cpu node stats when a node comes online Greg Kroah-Hartman
` (229 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Usama Arif,
Rik van Riel, Baolin Wang, Lance Yang, David Hildenbrand (Arm),
Lorenzo Stoakes, Andrea Arcangeli, Barry Song, Dev Jain,
Johannes Weiner, Liam R. Howlett, Nico Pache, Ryan Roberts,
Shakeel Butt, Zi Yan, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Usama Arif <usama.arif@linux.dev>
commit 4165b7d1c45c2da0dfefe528f8d1fb7d79f0d344 upstream.
move_pages_huge_pmd() snapshots src_pmdval under src_ptl, drops the lock,
and, for migration entries, waits with pmd_migration_entry_wait().
Passing &src_pmdval is wrong. pmd_migration_entry_wait() must lock and
re-read the real page-table PMD; on split-PMD-lock kernels, a stack
address also resolves to the wrong lock. softleaf_entry_wait_on_locked()
then waits without a folio reference, which is safe only while serialized
against migration-entry removal by the real PT lock.
Pass src_pmd, matching __handle_mm_fault() and hmm_vma_walk_pmd().
Link: https://lore.kernel.org/20260705131231.1499198-1-usama.arif@linux.dev
Fixes: adef440691ba ("userfaultfd: UFFDIO_MOVE uABI")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260703173903.3789516-1-usama.arif%40linux.dev?part=8
Signed-off-by: Usama Arif <usama.arif@linux.dev>
Reviewed-by: Rik van Riel <riel@surriel.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Reviewed-by: Lance Yang <lance.yang@linux.dev>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Lance Yang <lance.yang@linux.dev>
Reviewed-by: Lorenzo Stoakes <ljs@kernel.org>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Barry Song <baohua@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Nico Pache <npache@redhat.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/huge_memory.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -2836,7 +2836,7 @@ int move_pages_huge_pmd(struct mm_struct
if (!pmd_trans_huge(src_pmdval)) {
spin_unlock(src_ptl);
if (pmd_is_migration_entry(src_pmdval)) {
- pmd_migration_entry_wait(mm, &src_pmdval);
+ pmd_migration_entry_wait(mm, src_pmd);
return -EAGAIN;
}
return -ENOENT;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 223/438] mm/vmstat: fold stranded per-cpu node stats when a node comes online
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (221 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 222/438] userfaultfd: wait on source PMD during UFFDIO_MOVE Greg Kroah-Hartman
@ 2026-08-07 14:36 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 224/438] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs Greg Kroah-Hartman
` (228 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gregory Price, Johannes Weiner,
Mel Gorman, Mike Rapoport, Vlastimil Babka, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gregory Price <gourry@gourry.net>
commit ea3034b2b00fa50c8d2518d0804c9d427bbafa86 upstream.
A per-node vmstat counter is pgdat->vm_stat[] plus per-cpu deltas. A
balanced counter can sit split as global=+N / per-cpu=-N.
The folds reconciling the split only walk online nodes, so when
try_offline_node() marks a node offline the per-cpu deltas are stranded.
A subsequent online resets the per-cpu area but not pgdat->vm_stat[],
orphaning the +N permanently. All NR_VM_NODE_STAT_ITEMS are affected.
The existing code zeroes the per-cpu counters and causes a permanent skew.
Fold the stranded deltas instead, before the node rejoins the online set.
The node is not online yet and the hotplug lock is held, so the remote
access to per-cpu values is safe.
Discovered when node compaction hung for a nearly empty node, as the math
to determine throttling broke. Reproduced by repeated memory
hotplug/unplug cycles on a node under pressure: NR_ISOLATED_ANON ratchets
up and never returns to zero.
Link: https://lore.kernel.org/20260627202243.758289-1-gourry@gourry.net
Fixes: 75ef71840539 ("mm, vmstat: add infrastructure for per-node vmstats")
Signed-off-by: Gregory Price <gourry@gourry.net>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Mel Gorman <mgorman@techsingularity.net>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mm_init.c | 15 +++++++++++----
1 file changed, 11 insertions(+), 4 deletions(-)
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1548,7 +1548,7 @@ void __ref free_area_init_core_hotplug(s
{
int nid = pgdat->node_id;
enum zone_type z;
- int cpu;
+ int cpu, i;
pgdat_init_internals(pgdat);
@@ -1566,10 +1566,17 @@ void __ref free_area_init_core_hotplug(s
pgdat->node_start_pfn = 0;
pgdat->node_present_pages = 0;
- for_each_online_cpu(cpu) {
- struct per_cpu_nodestat *p;
+ /*
+ * Hot-unplug can leave per-cpu vmstat deltas unfolded (folders skip
+ * offline nodes) - reconcile this at online. Foreign access to counters
+ * is safe: the node is not online yet and we hold the hotplug lock.
+ */
+ for_each_possible_cpu(cpu) {
+ struct per_cpu_nodestat *p = per_cpu_ptr(pgdat->per_cpu_nodestats, cpu);
- p = per_cpu_ptr(pgdat->per_cpu_nodestats, cpu);
+ for (i = 0; i < NR_VM_NODE_STAT_ITEMS; i++)
+ if (p->vm_node_stat_diff[i])
+ node_page_state_add(p->vm_node_stat_diff[i], pgdat, i);
memset(p, 0, sizeof(*p));
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 224/438] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (222 preceding siblings ...)
2026-08-07 14:36 ` [PATCH 7.1 223/438] mm/vmstat: fold stranded per-cpu node stats when a node comes online Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 225/438] tracing/probes: Reject $arg0 in meta argument expansion Greg Kroah-Hartman
` (227 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, zdi-disclosures, Zhong Wang,
Xuanqing Shi, Weiming Shi, Sean Christopherson, Paolo Bonzini
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit 9910e835580fef3bef53b70241dd00c4bffad693 upstream.
Cancel (and flush) the I/O APIC's delayed EOI handling work during the
"pre VM destroy" phase, before vCPUs are destroyed, as processing the EOI
broadcast will inject another IRQ if the line is asserted, i.e. will try
to deliver an IRQ to the target vCPU(s). Canceling the work after vCPUs
are destroyed leads to UAF if the delayed work is processed after vCPUs are
destroyed.
BUG: KASAN: slab-use-after-free in __kvm_irq_delivery_to_apic_fast+0x9bf/0xa20 arch/x86/kvm/lapic.c:1250
Read of size 8 at addr ffff8880499abea0 by task kworker/1:2/1218
CPU: 1 UID: 0 PID: 1218 Comm: kworker/1:2 Not tainted 7.1.0-rc7 #5 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: events kvm_ioapic_eoi_inject_work
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378
print_report+0x139/0x4ad mm/kasan/report.c:482
kasan_report+0xe4/0x1d0 mm/kasan/report.c:595
__kvm_irq_delivery_to_apic_fast+0x9bf/0xa20 arch/x86/kvm/lapic.c:1250
__kvm_irq_delivery_to_apic+0xd8/0xbf0 arch/x86/kvm/lapic.c:1345
kvm_irq_delivery_to_apic arch/x86/kvm/lapic.h:129
ioapic_service+0x308/0x590 arch/x86/kvm/ioapic.c:492
kvm_ioapic_eoi_inject_work+0x13c/0x190 arch/x86/kvm/ioapic.c:532
process_one_work+0xa59/0x19a0 kernel/workqueue.c:3314
process_scheduled_works kernel/workqueue.c:3397
worker_thread+0x5eb/0xe50 kernel/workqueue.c:3478
kthread+0x370/0x450 kernel/kthread.c:436
ret_from_fork+0x72b/0xd30 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Note, the VM is unreachable once kvm_destroy_vm() starts, and scheduling
new work via kvm_ioapic_send_eoi() can only be done via KVM_RUN, i.e.
requires a live vCPU.
Alternatively, KVM could simply destroy the I/O APIC during the "pre" phase
of VM destruction, but that gets more than a bit sketchy as KVM expects the
I/O APIC to exist if ioapic_in_kernel() is true, and nested virtualization
in particular has a bad habit of touching VM-scope state during vCPU
destruction. E.g. attempting to free the PIC during the pre phase would
lead to a NULL pointer dereference in kvm_cpu_has_extint(), and it's not
hard to imagine the I/O APIC having a similar flaw.
Fixes: 17bcd7144263 ("KVM: x86: Free vCPUs before freeing VM state")
Reported-by: <zdi-disclosures@trendmicro.com>
Reported-by: Zhong Wang <wangzhong.c0ss4ck@bytedance.com>
Reported-by: Xuanqing Shi <shixuanqing.11@bytedance.com>
Cc: stable@vger.kernel.org
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Co-developed-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-ID: <20260727171718.543491-1-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/x86.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -13460,9 +13460,15 @@ void kvm_arch_pre_destroy_vm(struct kvm
* iterating over vCPUs in a different task while vCPUs are being freed
* is unsafe, i.e. will lead to use-after-free. The PIT also needs to
* be stopped before IRQ routing is freed.
+ *
+ * Do NOT free the in-kernel PIC or I/O APIC here (but as above, make
+ * sure to flush any background work), as KVM expects interrupt routing
+ * structures to be valid until vCPUs are destroyed.
*/
#ifdef CONFIG_KVM_IOAPIC
kvm_free_pit(kvm);
+ if (kvm->arch.vioapic)
+ cancel_delayed_work_sync(&kvm->arch.vioapic->eoi_inject);
#endif
kvm_mmu_pre_destroy_vm(kvm);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 225/438] tracing/probes: Reject $arg0 in meta argument expansion
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (223 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 224/438] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 226/438] tracing/fprobe: Roll back on enable_trace_fprobe() failure Greg Kroah-Hartman
` (226 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Raushan Patel,
Masami Hiramatsu (Google)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raushan Patel <raushan.jhon@gmail.com>
commit 00a8ce2a2a9fa17674e1feec4d9105c1a5d6a419 upstream.
traceprobe_expand_meta_args() parses $argN with simple_strtoul() and
calls sprint_nth_btf_arg(n - 1, ...). For $arg0, n is 0 so the index is
-1. Because ctx->nr_params is signed, the "idx >= nr_params" guard in
sprint_nth_btf_arg() does not catch the negative index, and
ctx->params[-1].name_off is read out of bounds.
The normal per-argument path (parse_probe_vars()) already rejects
$arg0 via its argument-number check, but meta-argument expansion runs
before per-argument parsing and substitutes the value first, bypassing
that check.
Reject $arg0 explicitly during expansion.
Link: https://lore.kernel.org/all/20260724054435.146279-1-raushan.jhon@gmail.com/
Fixes: 18b1e870a496 ("tracing/probes: Add $arg* meta argument for all function args")
Cc: stable@vger.kernel.org
Signed-off-by: Raushan Patel <raushan.jhon@gmail.com>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_probe.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/kernel/trace/trace_probe.c
+++ b/kernel/trace/trace_probe.c
@@ -1906,7 +1906,11 @@ const char **traceprobe_expand_meta_args
trace_probe_log_err(0, BAD_VAR);
return ERR_PTR(-ENOENT);
}
- /* Note: $argN starts from $arg1 */
+ /* Note: $argN starts from $arg1, so $arg0 is invalid. */
+ if (n == 0) {
+ trace_probe_log_err(0, BAD_ARG_NUM);
+ return ERR_PTR(-EINVAL);
+ }
ret = sprint_nth_btf_arg(n - 1, type, buf + used,
bufsize - used, ctx);
if (ret < 0)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 226/438] tracing/fprobe: Roll back on enable_trace_fprobe() failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (224 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 225/438] tracing/probes: Reject $arg0 in meta argument expansion Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 227/438] KVM: VMX: add memory clobber to asm for VMX instructions Greg Kroah-Hartman
` (225 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Raushan Patel,
Masami Hiramatsu (Google)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raushan Patel <raushan.jhon@gmail.com>
commit aca0cd1bf16574327ef64f3178e5f5e37a61ef0b upstream.
enable_trace_fprobe() sets the file link or the TP_FLAG_PROFILE flag and
then registers each trace_fprobe in the probe list. If
__register_trace_fprobe() fails partway through, the function returns
immediately without unregistering the trace_fprobes it already registered
or undoing the file link / flag it set, leaving the event half-enabled and
leaking the registered fprobe(s).
enable_trace_kprobe() already handles this with a rollback path. Do the
same for fprobe: on failure, unregister all probes and clear the file link
or profile flag.
Link: https://lore.kernel.org/all/20260724064208.480030-1-raushan.jhon@gmail.com/
Fixes: 334e5519c375 ("tracing/probes: Add fprobe events for tracing function entry and exit.")
Cc: stable@vger.kernel.org
Signed-off-by: Raushan Patel <raushan.jhon@gmail.com>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_fprobe.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
--- a/kernel/trace/trace_fprobe.c
+++ b/kernel/trace/trace_fprobe.c
@@ -1481,11 +1481,21 @@ static int enable_trace_fprobe(struct tr
list_for_each_entry(tf, trace_probe_probe_list(tp), tp.list) {
ret = __register_trace_fprobe(tf);
if (ret < 0)
- return ret;
+ goto err;
}
}
return 0;
+
+err:
+ /* Failed to enable one of them. Roll back all */
+ list_for_each_entry(tf, trace_probe_probe_list(tp), tp.list)
+ __unregister_trace_fprobe(tf);
+ if (file)
+ trace_probe_remove_file(tp, file);
+ else
+ trace_probe_clear_flag(tp, TP_FLAG_PROFILE);
+ return ret;
}
/*
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 227/438] KVM: VMX: add memory clobber to asm for VMX instructions
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (225 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 226/438] tracing/fprobe: Roll back on enable_trace_fprobe() failure Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 228/438] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active Greg Kroah-Hartman
` (224 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Paolo Bonzini
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paolo Bonzini <pbonzini@redhat.com>
commit 0e65cd9e5d41c34f86b7c347967bedac54926041 upstream.
VMCLEAR/VMREAD/VMWRITE/VMPTRLD access the internal VMCS cache, which
is not visible to the compiler; without a memory clobber, the compiler
can reorder them in troublesome ways because "asm volatile" and "asm goto"
only protect against removal of the asm. For example, placing a VMWRITE
before the corresponding VMCS pointer is loaded can lead to corruption.
While none of this has been observed, it is better to prevent than cure.
Likewise, INVEPT and INVVPID access the TLB and, even though in their
case the effect is only visible to the next VMLAUNCH/VMRESUME, it is
technically correct to add the clobber there too. So avoid any urge to
special case them, and simply hardcode "memory" into the clobber list
of vmx_asm1() and vmx_asm2(). __vmcs_readl() open-codes its own asm,
so add the clobber there as well.
Link: https://lore.kernel.org/kvm/CABgObfbL3t21yVeSwiLSjjOUER+rTYDPHYAH9YU4TWGRjx6XHg@mail.gmail.com/
Cc: Sean Christopherson <seanjc@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/vmx/vmx_ops.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/x86/kvm/vmx/vmx_ops.h
+++ b/arch/x86/kvm/vmx/vmx_ops.h
@@ -101,7 +101,7 @@ static __always_inline unsigned long __v
: [output] "=r" (value)
: [field] "r" (field)
- : "cc"
+ : "cc", "memory"
: do_fail, do_exception);
return value;
@@ -145,7 +145,7 @@ do_exception:
: ASM_CALL_CONSTRAINT, [output] "=&r" (value)
: [field] "r" (field)
- : "cc");
+ : "cc", "memory");
return value;
#endif /* CONFIG_CC_HAS_ASM_GOTO_OUTPUT */
@@ -192,7 +192,7 @@ do { \
asm goto("1: " __stringify(insn) " %0\n\t" \
"jna %l[error]\n\t" \
_ASM_EXTABLE(1b, %l[fault]) \
- : : op1 : "cc" : error, fault); \
+ : : op1 : "cc", "memory" : error, fault); \
return; \
error: \
instrumentation_begin(); \
@@ -208,7 +208,7 @@ do { \
asm goto("1: " __stringify(insn) " %1, %0\n\t" \
"jna %l[error]\n\t" \
_ASM_EXTABLE(1b, %l[fault]) \
- : : op1, op2 : "cc" : error, fault); \
+ : : op1, op2 : "cc", "memory" : error, fault);\
return; \
error: \
instrumentation_begin(); \
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 228/438] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (226 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 227/438] KVM: VMX: add memory clobber to asm for VMX instructions Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 229/438] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled Greg Kroah-Hartman
` (223 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson,
Paolo Bonzini
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
commit 7d3aae206663c4e006b25a1c7a20a4029e67da76 upstream.
Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2. If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host's APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.
E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a "safe" PoC, yields:
Spurious interrupt (vector 0xee) on CPU#425. Acked
And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:
------------[ cut here ]------------
WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S U
Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
Call Trace:
<IRQ>
sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
</IRQ>
<TASK>
asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]
kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]
kvm_vcpu_ioctl+0x580/0x6b0 [kvm]
__se_sys_ioctl+0x6d/0xb0
do_syscall_64+0x10a/0x480
entry_SYSCALL_64_after_hwframe+0x4b/0x53
RIP: 0033:0x46ff4b
</TASK>
---[ end trace 0000000000000000 ]---
Fixes: 091abbf578f9 ("KVM: x86: nSVM: optimize svm_set_x2apic_msr_interception")
Cc: stable@vger.kernel.org
Cc: Yosry Ahmed <yosry@kernel.org>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Link: https://patch.msgid.link/20260729213558.639074-1-pbonzini@redhat.com/
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/svm/avic.c | 8 --------
1 file changed, 8 deletions(-)
--- a/arch/x86/kvm/svm/avic.c
+++ b/arch/x86/kvm/svm/avic.c
@@ -240,14 +240,6 @@ static void avic_deactivate_vmcb(struct
if (!is_sev_es_guest(&svm->vcpu))
svm_set_intercept(svm, INTERCEPT_CR8_WRITE);
- /*
- * If running nested and the guest uses its own MSR bitmap, there
- * is no need to update L0's msr bitmap
- */
- if (is_guest_mode(&svm->vcpu) &&
- vmcb12_is_intercept(&svm->nested.ctl, INTERCEPT_MSR_PROT))
- return;
-
/* Enabling MSR intercept for x2APIC registers */
avic_set_x2apic_msr_interception(svm, true);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 229/438] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (227 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 228/438] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 230/438] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages Greg Kroah-Hartman
` (222 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Matthew Rosato, Farhan Ali
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
commit 8fa01be5a6149404adb82c0979a78f6347edd3ef upstream.
The MPCIFC instruction doesn't allow registering adapter interrupts without
first unregistering. So reject any request to enable interrupt forwarding
if its already enabled for the zPCI device. This also fixes overwriting and
thus leaking resources when the ioctl is called multiple times for the same
device.
Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/pci.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/arch/s390/kvm/pci.c
+++ b/arch/s390/kvm/pci.c
@@ -237,6 +237,10 @@ static int kvm_s390_pci_aif_enable(struc
if (zdev->gisa == 0)
return -EINVAL;
+ /* AIF already enabled for the device */
+ if (zdev->kzdev->fib.fmt0.aibv != 0)
+ return -EINVAL;
+
kvm = zdev->kzdev->kvm;
msi_vecs = min_t(unsigned int, fib->fmt0.noi, zdev->max_msi);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 230/438] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (228 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 229/438] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 231/438] KVM: s390: pci: Fix missing error codes and memory unaccounting Greg Kroah-Hartman
` (221 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Matthew Rosato, Farhan Ali
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
commit 36f6999ecde3976731a8bfc0b8e667da6f593069 upstream.
The account_mem() and unaccount_mem() functions call get_uid() which
increments the reference count of struct user_struct on every invocation.
But we don't decrement the count by calling free_uid(). It also
accounted/unaccounted the pages against the current->mm. But its possible
the unaccount_mem() can be called from a different process context than the
one that originally pinned the pages.
Let's fix this by storing the pinning process user_struct and mm_struct
when accounting for pinned pages, and subsequently free these resources
when the pages are unpinned.
Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
[borntraeger@linux.ibm.com: Fixed whitespace]
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/pci.c | 43 ++++++++++++++++++++++++++++++++-----------
arch/s390/kvm/pci.h | 2 ++
2 files changed, 34 insertions(+), 11 deletions(-)
--- a/arch/s390/kvm/pci.c
+++ b/arch/s390/kvm/pci.c
@@ -190,33 +190,54 @@ static int kvm_zpci_clear_airq(struct zp
return cc ? -EIO : 0;
}
-static inline void unaccount_mem(unsigned long nr_pages)
+static inline void unaccount_mem(struct kvm_zdev *kzdev, unsigned long nr_pages)
{
- struct user_struct *user = get_uid(current_user());
+ struct user_struct *user = kzdev->user_account;
+ struct mm_struct *mm_account = kzdev->mm_account;
- if (user)
+ if (user) {
atomic_long_sub(nr_pages, &user->locked_vm);
- if (current->mm)
- atomic64_sub(nr_pages, ¤t->mm->pinned_vm);
+ free_uid(user);
+ kzdev->user_account = NULL;
+ }
+
+ if (mm_account) {
+ atomic64_sub(nr_pages, &mm_account->pinned_vm);
+ mmdrop(mm_account);
+ kzdev->mm_account = NULL;
+ }
}
-static inline int account_mem(unsigned long nr_pages)
+static inline int account_mem(struct kvm_zdev *kzdev, unsigned long nr_pages)
{
struct user_struct *user = get_uid(current_user());
unsigned long page_limit, cur_pages, new_pages;
+ int rc = 0;
page_limit = rlimit(RLIMIT_MEMLOCK) >> PAGE_SHIFT;
cur_pages = atomic_long_read(&user->locked_vm);
do {
new_pages = cur_pages + nr_pages;
- if (new_pages > page_limit)
- return -ENOMEM;
+ if (new_pages > page_limit) {
+ rc = -ENOMEM;
+ goto out;
+ }
} while (!atomic_long_try_cmpxchg(&user->locked_vm, &cur_pages, new_pages));
- atomic64_add(nr_pages, ¤t->mm->pinned_vm);
+ if (current->mm) {
+ mmgrab(current->mm);
+ atomic64_add(nr_pages, ¤t->mm->pinned_vm);
+ }
+
+ kzdev->user_account = user;
+ kzdev->mm_account = current->mm;
return 0;
+
+out:
+ free_uid(user);
+ return rc;
}
static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
@@ -279,7 +300,7 @@ static int kvm_s390_pci_aif_enable(struc
}
/* Account for pinned pages, roll back on failure */
- if (account_mem(pcount))
+ if (account_mem(zdev->kzdev, pcount))
goto unpin2;
/* AISB must be allocated before we can fill in GAITE */
@@ -400,7 +421,7 @@ static int kvm_s390_pci_aif_disable(stru
pcount++;
}
if (pcount > 0)
- unaccount_mem(pcount);
+ unaccount_mem(kzdev, pcount);
out:
mutex_unlock(&aift->aift_lock);
--- a/arch/s390/kvm/pci.h
+++ b/arch/s390/kvm/pci.h
@@ -22,6 +22,8 @@ struct kvm_zdev {
struct kvm *kvm;
struct zpci_fib fib;
struct list_head entry;
+ struct user_struct *user_account;
+ struct mm_struct *mm_account;
};
struct zpci_gaite {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 231/438] KVM: s390: pci: Fix missing error codes and memory unaccounting
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (229 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 230/438] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 232/438] KVM: s390: pci: Fix resource leak on IRQ registration failure Greg Kroah-Hartman
` (220 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Matthew Rosato, Farhan Ali
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
commit f86842e4d6c482300f4567f492d512c9ccf5bc4f upstream.
In kvm_s390_pci_aif_enable() two error paths failed to set an error code,
causing the function to return 0 on failure. It also failed to rollback
memory accounting on failure. Fix both by propagating an error code on
failure and calling unaccount_mem() in the cleanup path.
Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/pci.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
--- a/arch/s390/kvm/pci.c
+++ b/arch/s390/kvm/pci.c
@@ -300,14 +300,17 @@ static int kvm_s390_pci_aif_enable(struc
}
/* Account for pinned pages, roll back on failure */
- if (account_mem(zdev->kzdev, pcount))
+ rc = account_mem(zdev->kzdev, pcount);
+ if (rc)
goto unpin2;
/* AISB must be allocated before we can fill in GAITE */
mutex_lock(&aift->aift_lock);
bit = airq_iv_alloc_bit(aift->sbv);
- if (bit == -1UL)
+ if (bit == -1UL) {
+ rc = -ENOMEM;
goto unlock;
+ }
zdev->aisb = bit; /* store the summary bit number */
zdev->aibv = airq_iv_create(msi_vecs, AIRQ_IV_DATA |
AIRQ_IV_BITLOCK |
@@ -351,6 +354,8 @@ static int kvm_s390_pci_aif_enable(struc
return rc;
unlock:
+ if (pcount > 0)
+ unaccount_mem(zdev->kzdev, pcount);
mutex_unlock(&aift->aift_lock);
unpin2:
if (fib->fmt0.sum == 1)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 232/438] KVM: s390: pci: Fix resource leak on IRQ registration failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (230 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 231/438] KVM: s390: pci: Fix missing error codes and memory unaccounting Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 233/438] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure Greg Kroah-Hartman
` (219 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Rosato,
Christian Borntraeger, Farhan Ali
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
commit 5580c9858f1e00f60191eb09c3add359836d60b6 upstream.
Currently if kvm_zpci_set_airq() fails, kvm_s390_pci_aif_enable() returns
the error code but doesn't do any resource cleanup thus leaking resources.
Fix this by cleaning up all the resources such as the GAITE, AIBV, AISB and
unpinning any pinned pages. While at it, remove dead code that stored FIB
values that were never referenced.
As part of the cleanup, we are also holding the aift_lock a bit longer, as
we hold the lock while executing the MPCIFC instruction. Though this is not
strictly necessary, it means we don't have to drop and re-acquire in the
error case.
Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/pci.c | 29 +++++++++++++++++++++--------
1 file changed, 21 insertions(+), 8 deletions(-)
--- a/arch/s390/kvm/pci.c
+++ b/arch/s390/kvm/pci.c
@@ -339,19 +339,32 @@ static int kvm_s390_pci_aif_enable(struc
aift->kzdev[zdev->aisb] = zdev->kzdev;
spin_unlock_irq(&aift->gait_lock);
- /* Update guest FIB for re-issue */
- fib->fmt0.aisbo = zdev->aisb & 63;
- fib->fmt0.aisb = virt_to_phys(aift->sbv->vector) + (zdev->aisb / 64) * 8;
- fib->fmt0.isc = gisc;
-
/* Save some guest fib values in the host for later use */
- zdev->kzdev->fib.fmt0.isc = fib->fmt0.isc;
+ zdev->kzdev->fib.fmt0.isc = gisc;
zdev->kzdev->fib.fmt0.aibv = fib->fmt0.aibv;
- mutex_unlock(&aift->aift_lock);
/* Issue the clp to setup the irq now */
rc = kvm_zpci_set_airq(zdev);
- return rc;
+ if (!rc) {
+ mutex_unlock(&aift->aift_lock);
+ return rc;
+ }
+
+ /* Start cleanup */
+ zdev->kzdev->fib.fmt0.isc = 0;
+ zdev->kzdev->fib.fmt0.aibv = 0;
+
+ spin_lock_irq(&aift->gait_lock);
+ gaite->count--;
+ gaite->aisb = 0;
+ gaite->gisc = 0;
+ gaite->aisbo = 0;
+ gaite->gisa = 0;
+ aift->kzdev[zdev->aisb] = NULL;
+ spin_unlock_irq(&aift->gait_lock);
+
+ airq_iv_release(zdev->aibv);
+ zdev->aibv = NULL;
unlock:
if (pcount > 0)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 233/438] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (231 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 232/438] KVM: s390: pci: Fix resource leak on IRQ registration failure Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 234/438] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages Greg Kroah-Hartman
` (218 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Matthew Rosato, Farhan Ali
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
commit 8bf09b9b7d3232806df95f409581f8a9fd99a3fa upstream.
The airq_iv_create() can return NULL on failure, but the return value was
never checked. If it fails, zdev->aibv will be NULL and fail when
dereferenced in kvm_zpci_set_airq(). Add a NULL check and free the
previously allocated AISB bit and zdev->aisb on failure.
Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/pci.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/arch/s390/kvm/pci.c
+++ b/arch/s390/kvm/pci.c
@@ -317,6 +317,11 @@ static int kvm_s390_pci_aif_enable(struc
AIRQ_IV_GUESTVEC,
phys_to_virt(fib->fmt0.aibv));
+ if (!zdev->aibv) {
+ rc = -ENOMEM;
+ goto free_aisb;
+ }
+
spin_lock_irq(&aift->gait_lock);
gaite = aift->gait + zdev->aisb;
@@ -366,6 +371,9 @@ static int kvm_s390_pci_aif_enable(struc
airq_iv_release(zdev->aibv);
zdev->aibv = NULL;
+free_aisb:
+ airq_iv_free_bit(aift->sbv, zdev->aisb);
+ zdev->aisb = 0;
unlock:
if (pcount > 0)
unaccount_mem(zdev->kzdev, pcount);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 234/438] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (232 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 233/438] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 235/438] dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister Greg Kroah-Hartman
` (217 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Matthew Rosato, Farhan Ali
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
commit 868d32ac72cba21c5c6d8a66a814b7c25a3a5c01 upstream.
The AIBV holds one bit per MSI-X vector for a given function. The size of
the bit vector is derived from the NOI and the AIBVO. If the size of the
AIBV exceeds a single page boundary, then reject the request as we cannot
safely pin the guest AIBV.
Similarly reject the request if the AISB address is not 8-byte aligned as
the architecture requires doubleword alignment for the summary bit address.
Since the AISBO can address up to 64 bits, the size of the AISB can only be
8 bytes for the function. This also ensures the AISB doesn't exceed a
single page boundary.
Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/pci.c | 16 +++++++++++++++-
1 file changed, 15 insertions(+), 1 deletion(-)
--- a/arch/s390/kvm/pci.c
+++ b/arch/s390/kvm/pci.c
@@ -244,7 +244,7 @@ static int kvm_s390_pci_aif_enable(struc
bool assist)
{
struct page *pages[1], *aibv_page, *aisb_page = NULL;
- unsigned int msi_vecs, idx;
+ unsigned int msi_vecs, idx, size;
struct zpci_gaite *gaite;
unsigned long hva, bit;
struct kvm *kvm;
@@ -271,6 +271,14 @@ static int kvm_s390_pci_aif_enable(struc
return gisc;
/* Replace AIBV address */
+ size = BITS_TO_LONGS(msi_vecs + fib->fmt0.aibvo) * sizeof(unsigned long);
+ npages = DIV_ROUND_UP((fib->fmt0.aibv & ~PAGE_MASK) + size, PAGE_SIZE);
+ /* AIBV cannot span more than 1 page */
+ if (npages > 1) {
+ rc = -EINVAL;
+ goto out;
+ }
+
idx = srcu_read_lock(&kvm->srcu);
hva = gfn_to_hva(kvm, gpa_to_gfn((gpa_t)fib->fmt0.aibv));
npages = pin_user_pages_fast(hva, 1, FOLL_WRITE | FOLL_LONGTERM, pages);
@@ -286,6 +294,12 @@ static int kvm_s390_pci_aif_enable(struc
/* Pin the guest AISB if one was specified */
if (fib->fmt0.sum == 1) {
+ /* AISB must be dword aligned */
+ if (fib->fmt0.aisb & 0x7) {
+ rc = -EINVAL;
+ goto unpin1;
+ }
+
idx = srcu_read_lock(&kvm->srcu);
hva = gfn_to_hva(kvm, gpa_to_gfn((gpa_t)fib->fmt0.aisb));
npages = pin_user_pages_fast(hva, 1, FOLL_WRITE | FOLL_LONGTERM,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 235/438] dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (233 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 234/438] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 236/438] sctp: validate Adaptation Indication parameter length Greg Kroah-Hartman
` (216 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rahul Chandelkar, Hidayath Khan,
Alexandra Winter, Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hidayath Khan <hidayath@linux.ibm.com>
commit a10ea943356b9d70c5616a0a06f6fa97cfdaccb1 upstream.
dibs_lo_attach_dmb(), dibs_lo_detach_dmb() and dibs_lo_unregister_dmb()
look up the dmb_node under dmb_ht_lock, drop the lock and only then
operate on the node's refcount. Nothing keeps the node alive across
that window: __dibs_lo_unregister_dmb() removes the node from the hash
table under the write lock and immediately frees it.
A concurrent final put can therefore free the node between the lookup
and the refcount operation:
CPU0 (attach) CPU1 (owner unregisters)
read_lock_bh(&dmb_ht_lock)
find dmb_node (refcnt == 1)
read_unlock_bh(&dmb_ht_lock)
refcount_dec_and_test() 1 -> 0
write_lock_bh(&dmb_ht_lock)
hash_del(&dmb_node->list)
write_unlock_bh(&dmb_ht_lock)
kfree(dmb_node)
refcount_inc_not_zero(&dmb_node->refcnt) <-- use-after-free
The same window exists for the refcount_dec_and_test() calls in the
detach and unregister paths.
Close the race structurally by making hash table membership and the
refcount transitions atomic with respect to each other:
- Perform the final refcount_dec_and_test() and hash_del() in a single
dmb_ht_lock write-side critical section, in both the unregister and
the detach path. Freeing the node still happens after the lock is
dropped, which is safe because a node whose refcount reached zero has
left the hash table and can no longer be found.
- This establishes the invariant that any node found in the hash table
holds at least one reference, and that the final reference can only
be dropped under the write lock. dibs_lo_attach_dmb() can thus take
its reference with a plain refcount_inc() while still holding the
read lock; refcount_inc_not_zero() is no longer needed.
__dibs_lo_unregister_dmb() no longer touches the hash table and is
renamed to dibs_lo_free_dmb() accordingly.
Note: commit cc21191b584c ("dibs: Move data path to dibs layer") moved
the code to its current location; the race was introduced earlier by
commit c3a910f2380f ("net/smc: implement DMB-merged operations of
loopback-ism").
Tested SMC-D via ISM and dibs loopback.
Cc: stable@vger.kernel.org
Fixes: c3a910f2380f ("net/smc: implement DMB-merged operations of loopback-ism")
Reported-by: Rahul Chandelkar <rc@rexion.ai>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Link: https://patch.msgid.link/20260727093530.968834-1-hidayath@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dibs/dibs_loopback.c | 47 +++++++++++++++++++++----------------------
1 file changed, 24 insertions(+), 23 deletions(-)
--- a/drivers/dibs/dibs_loopback.c
+++ b/drivers/dibs/dibs_loopback.c
@@ -118,14 +118,9 @@ err_bit:
return rc;
}
-static void __dibs_lo_unregister_dmb(struct dibs_lo_dev *ldev,
- struct dibs_lo_dmb_node *dmb_node)
+static void dibs_lo_free_dmb(struct dibs_lo_dev *ldev,
+ struct dibs_lo_dmb_node *dmb_node)
{
- /* remove dmb from hash table */
- write_lock_bh(&ldev->dmb_ht_lock);
- hash_del(&dmb_node->list);
- write_unlock_bh(&ldev->dmb_ht_lock);
-
clear_bit(dmb_node->sba_idx, ldev->sba_idx_mask);
folio_put(virt_to_folio(dmb_node->cpu_addr));
kfree(dmb_node);
@@ -139,27 +134,33 @@ static int dibs_lo_unregister_dmb(struct
struct dibs_lo_dmb_node *dmb_node = NULL, *tmp_node;
struct dibs_lo_dev *ldev;
unsigned long flags;
+ bool last;
ldev = dibs->drv_priv;
/* find dmb from hash table */
- read_lock_bh(&ldev->dmb_ht_lock);
+ write_lock_bh(&ldev->dmb_ht_lock);
hash_for_each_possible(ldev->dmb_ht, tmp_node, list, dmb->dmb_tok) {
if (tmp_node->token == dmb->dmb_tok) {
dmb_node = tmp_node;
break;
}
}
- read_unlock_bh(&ldev->dmb_ht_lock);
- if (!dmb_node)
+ if (!dmb_node) {
+ write_unlock_bh(&ldev->dmb_ht_lock);
return -EINVAL;
+ }
+ last = refcount_dec_and_test(&dmb_node->refcnt);
+ if (last)
+ hash_del(&dmb_node->list);
+ write_unlock_bh(&ldev->dmb_ht_lock);
- if (refcount_dec_and_test(&dmb_node->refcnt)) {
+ if (last) {
spin_lock_irqsave(&dibs->lock, flags);
dibs->dmb_clientid_arr[dmb_node->sba_idx] = NO_DIBS_CLIENT;
spin_unlock_irqrestore(&dibs->lock, flags);
- __dibs_lo_unregister_dmb(ldev, dmb_node);
+ dibs_lo_free_dmb(ldev, dmb_node);
}
return 0;
}
@@ -188,14 +189,9 @@ static int dibs_lo_attach_dmb(struct dib
read_unlock_bh(&ldev->dmb_ht_lock);
return -EINVAL;
}
+ refcount_inc(&dmb_node->refcnt);
read_unlock_bh(&ldev->dmb_ht_lock);
- if (!refcount_inc_not_zero(&dmb_node->refcnt))
- /* the dmb is being unregistered, but has
- * not been removed from the hash table.
- */
- return -EINVAL;
-
/* provide dmb information */
dmb->idx = dmb_node->sba_idx;
dmb->dmb_tok = dmb_node->token;
@@ -209,11 +205,12 @@ static int dibs_lo_detach_dmb(struct dib
{
struct dibs_lo_dmb_node *dmb_node = NULL, *tmp_node;
struct dibs_lo_dev *ldev;
+ bool last;
ldev = dibs->drv_priv;
/* find dmb_node according to dmb->dmb_tok */
- read_lock_bh(&ldev->dmb_ht_lock);
+ write_lock_bh(&ldev->dmb_ht_lock);
hash_for_each_possible(ldev->dmb_ht, tmp_node, list, token) {
if (tmp_node->token == token) {
dmb_node = tmp_node;
@@ -221,13 +218,17 @@ static int dibs_lo_detach_dmb(struct dib
}
}
if (!dmb_node) {
- read_unlock_bh(&ldev->dmb_ht_lock);
+ write_unlock_bh(&ldev->dmb_ht_lock);
return -EINVAL;
}
- read_unlock_bh(&ldev->dmb_ht_lock);
+ last = refcount_dec_and_test(&dmb_node->refcnt);
+ if (last)
+ hash_del(&dmb_node->list);
+ write_unlock_bh(&ldev->dmb_ht_lock);
+
+ if (last)
+ dibs_lo_free_dmb(ldev, dmb_node);
- if (refcount_dec_and_test(&dmb_node->refcnt))
- __dibs_lo_unregister_dmb(ldev, dmb_node);
return 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 236/438] sctp: validate Adaptation Indication parameter length
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (234 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 235/438] dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 237/438] audit: fix potential integer overflow in audit_log_n_string() Greg Kroah-Hartman
` (215 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Charles Vosburgh, Xin Long,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Vosburgh <trilobyte777@gmail.com>
commit 74b21f52c5c5a71a05c0ff70e513f4f04ff28b17 upstream.
The Adaptation Layer Indication parameter contains a fixed 32-bit
Adaptation Code Point after its parameter header. However,
sctp_verify_param() accepts a header-only parameter because the generic
parameter walker only requires the header to be present.
sctp_process_param() then reads adaptation_ind beyond the declared
parameter. When the malformed parameter is last in an INIT, the read
starts at the receive skb tail, and the value is copied into the state
cookie returned in the INIT ACK. This may disclose four receive-buffer
tail bytes.
Require the declared parameter length to match the fixed structure size
and abort the association through the existing invalid parameter length
path otherwise.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Charles Vosburgh <trilobyte777@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260727-sctp-adaptation-length-v1-1-0ab58b2810a5@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sctp/sm_make_chunk.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@ -2168,7 +2168,13 @@ static enum sctp_ierror sctp_verify_para
case SCTP_PARAM_HEARTBEAT_INFO:
case SCTP_PARAM_UNRECOGNIZED_PARAMETERS:
case SCTP_PARAM_ECN_CAPABLE:
+ break;
case SCTP_PARAM_ADAPTATION_LAYER_IND:
+ if (ntohs(param.p->length) != sizeof(*param.aind)) {
+ sctp_process_inv_paramlength(asoc, param.p,
+ chunk, err_chunk);
+ retval = SCTP_IERROR_ABORT;
+ }
break;
case SCTP_PARAM_SUPPORTED_EXT:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 237/438] audit: fix potential integer overflow in audit_log_n_string()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (235 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 236/438] sctp: validate Adaptation Indication parameter length Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 238/438] audit: fix potential use-after-free in audit_del_rule() Greg Kroah-Hartman
` (214 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Paul Moore
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhan Xusheng <zhanxusheng1024@gmail.com>
commit f865c143629d4094866a811dba5f329250bad486 upstream.
audit_log_n_string() computes new_len as "slen + 3" (enclosing quotes
plus the NUL terminator) and stores it into an int, while slen is a
size_t. For a sufficiently large slen the addition can overflow and/or
the result be truncated when assigned to the int new_len, so the
"new_len > avail" check can be bypassed and the subsequent
memcpy(ptr, string, slen) can write past the skb tail.
This is the same class of bug that was fixed for the hex sibling in
commit 65dfde57d1e2 ("audit: fix potential integer overflow in
audit_log_n_hex()"); both helpers are reached through
audit_log_n_untrustedstring() with the same length source.
Make new_len a size_t and use check_add_overflow() to catch the
overflow, mirroring the audit_log_n_hex() fix. No functional change for
the in-tree callers, which all pass bounded lengths.
Cc: stable@vger.kernel.org
Fixes: 168b7173959f ("AUDIT: Clean up logging of untrusted strings")
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/audit.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
--- a/kernel/audit.c
+++ b/kernel/audit.c
@@ -2120,7 +2120,8 @@ void audit_log_n_hex(struct audit_buffer
void audit_log_n_string(struct audit_buffer *ab, const char *string,
size_t slen)
{
- int avail, new_len;
+ int avail;
+ size_t new_len;
unsigned char *ptr;
struct sk_buff *skb;
@@ -2130,7 +2131,13 @@ void audit_log_n_string(struct audit_buf
BUG_ON(!ab->skb);
skb = ab->skb;
avail = skb_tailroom(skb);
- new_len = slen + 3; /* enclosing quotes + null terminator */
+
+ /* enclosing quotes + null terminator */
+ if (check_add_overflow(slen, 3, &new_len)) {
+ audit_log_format(ab, "?");
+ return;
+ }
+
if (new_len > avail) {
avail = audit_expand(ab, new_len);
if (!avail)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 238/438] audit: fix potential use-after-free in audit_del_rule()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (236 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 237/438] audit: fix potential integer overflow in audit_log_n_string() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 239/438] Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() Greg Kroah-Hartman
` (213 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Luxiao Xu, Ren Wei, Paul Moore
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luxiao Xu <rakukuip@gmail.com>
commit 246df90b5f1a8a6e6abbd2f058b029558720adec upstream.
`audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()`
before unlinking the rule from RCU-visible filter lists and waiting for a
grace period. Concurrent readers in `audit_filter()` and
`audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify
mark can be freed on an independent lifetime path. This creates a
use-after-free window during rule deletion.
Fix this by unlinking the rule from the RCU-visible lists and invoking
`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other
rule removal helpers). This ensures that all existing RCU readers have
exited the critical section before any underlying resources are destroyed.
Cc: stable@vger.kernel.org
Fixes: 34d99af52ad4 ("audit: implement audit by executable")
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Luxiao Xu <rakukuip@gmail.com>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/auditfilter.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/kernel/auditfilter.c
+++ b/kernel/auditfilter.c
@@ -1045,6 +1045,10 @@ int audit_del_rule(struct audit_entry *e
goto out;
}
+ list_del_rcu(&e->list);
+ list_del(&e->rule.list);
+ synchronize_rcu();
+
if (e->rule.watch)
audit_remove_watch_rule(&e->rule);
@@ -1062,8 +1066,6 @@ int audit_del_rule(struct audit_entry *e
audit_signals--;
#endif
- list_del_rcu(&e->list);
- list_del(&e->rule.list);
call_rcu(&e->rcu, audit_free_rule_rcu);
out:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 239/438] Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (237 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 238/438] audit: fix potential use-after-free in audit_del_rule() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 240/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() Greg Kroah-Hartman
` (212 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
commit cac43d360c928bc0cbbd18809632388265649761 upstream.
If btusb_qca_send_vendor_req() gets a "short" read from a device, it
will accidentally treat that as a "real" read and populate the returned
value with some unknown and probably totally invalid data.
Fix this logic error up by calling usb_control_msg_recv() which
guarantees a "full" read happens, and then simplify the error checking
for when btusb_qca_send_vendor_req() is called.
Cc: stable <stable@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/btusb.c | 30 +++++++++---------------------
1 file changed, 9 insertions(+), 21 deletions(-)
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -3407,28 +3407,16 @@ static const char *qca_get_fw_subdirecto
static int btusb_qca_send_vendor_req(struct usb_device *udev, u8 request,
void *data, u16 size)
{
- int pipe, err;
- u8 *buf;
-
- buf = kmalloc(size, GFP_KERNEL);
- if (!buf)
- return -ENOMEM;
+ int err;
/* Found some of USB hosts have IOT issues with ours so that we should
* not wait until HCI layer is ready.
*/
- pipe = usb_rcvctrlpipe(udev, 0);
- err = usb_control_msg(udev, pipe, request, USB_TYPE_VENDOR | USB_DIR_IN,
- 0, 0, buf, size, USB_CTRL_GET_TIMEOUT);
- if (err < 0) {
+ err = usb_control_msg_recv(udev, 0, request, USB_TYPE_VENDOR | USB_DIR_IN,
+ 0, 0, data, size, USB_CTRL_GET_TIMEOUT,
+ GFP_KERNEL);
+ if (err)
dev_err(&udev->dev, "Failed to access otp area (%d)", err);
- goto done;
- }
-
- memcpy(data, buf, size);
-
-done:
- kfree(buf);
return err;
}
@@ -3635,7 +3623,7 @@ static bool btusb_qca_need_patch(struct
struct qca_version ver;
if (btusb_qca_send_vendor_req(udev, QCA_GET_TARGET_VERSION, &ver,
- sizeof(ver)) < 0)
+ sizeof(ver)))
return false;
/* only low ROM versions need patches */
return !(le32_to_cpu(ver.rom_version) & ~0xffffU);
@@ -3653,7 +3641,7 @@ static int btusb_setup_qca(struct hci_de
err = btusb_qca_send_vendor_req(udev, QCA_GET_TARGET_VERSION, &ver,
sizeof(ver));
- if (err < 0)
+ if (err)
return err;
ver_rom = le32_to_cpu(ver.rom_version);
@@ -3676,7 +3664,7 @@ static int btusb_setup_qca(struct hci_de
err = btusb_qca_send_vendor_req(udev, QCA_CHECK_STATUS, &status,
sizeof(status));
- if (err < 0)
+ if (err)
return err;
if (!(status & QCA_PATCH_UPDATED)) {
@@ -3687,7 +3675,7 @@ static int btusb_setup_qca(struct hci_de
err = btusb_qca_send_vendor_req(udev, QCA_GET_TARGET_VERSION, &ver,
sizeof(ver));
- if (err < 0)
+ if (err)
return err;
btdata->qca_dump.fw_version = le32_to_cpu(ver.patch_version);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 240/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (238 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 239/438] Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 241/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() Greg Kroah-Hartman
` (211 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
commit b186c18c4843dd58adc29443369bddc71cb626a3 upstream.
If btmtk_usb_uhw_reg_read() gets a "short" read from a device, it will
accidentally treat that as a "real" read and populate the returned value
with some unknown and probably totally invalid data.
Fix this logic error up by calling usb_control_msg_recv() which
guarantees a "full" read happens, and then simplify the error checking
for when btmtk_usb_uhw_reg_read() is called.
Note, one caller of btmtk_usb_uhw_reg_read() does not check the return
value, but as we pre-initialize the return value as 0, an incorrect read
will not do anything wrong.
Cc: stable <stable@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/btmtk.c | 50 ++++++++++++++++++++--------------------------
1 file changed, 22 insertions(+), 28 deletions(-)
--- a/drivers/bluetooth/btmtk.c
+++ b/drivers/bluetooth/btmtk.c
@@ -804,30 +804,24 @@ static int btmtk_usb_uhw_reg_write(struc
static int btmtk_usb_uhw_reg_read(struct hci_dev *hdev, u32 reg, u32 *val)
{
struct btmtk_data *data = hci_get_priv(hdev);
- int pipe, err;
- void *buf;
-
- buf = kzalloc(4, GFP_KERNEL);
- if (!buf)
- return -ENOMEM;
+ u8 buf[sizeof(u32)];
+ int err;
- pipe = usb_rcvctrlpipe(data->udev, 0);
- err = usb_control_msg(data->udev, pipe, 0x01,
- 0xDE,
- reg >> 16, reg & 0xffff,
- buf, 4, USB_CTRL_GET_TIMEOUT);
- if (err < 0) {
+ *val = 0;
+ err = usb_control_msg_recv(data->udev, 0, 0x01,
+ 0xDE,
+ reg >> 16, reg & 0xffff,
+ buf, sizeof(buf), USB_CTRL_GET_TIMEOUT,
+ GFP_KERNEL);
+ if (err) {
bt_dev_err(hdev, "Failed to read uhw reg(%d)", err);
- goto err_free_buf;
+ return err;
}
*val = get_unaligned_le32(buf);
bt_dev_dbg(hdev, "reg=%x, value=0x%08x", reg, *val);
-err_free_buf:
- kfree(buf);
-
- return err;
+ return 0;
}
static int btmtk_usb_reg_read(struct hci_dev *hdev, u32 reg, u32 *val)
@@ -877,7 +871,7 @@ int btmtk_usb_subsys_reset(struct hci_de
if (dev_id == 0x7922) {
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_SUBSYS_RST, &val);
- if (err < 0)
+ if (err)
return err;
val |= 0x00002020;
err = btmtk_usb_uhw_reg_write(hdev, MTK_BT_SUBSYS_RST, val);
@@ -887,7 +881,7 @@ int btmtk_usb_subsys_reset(struct hci_de
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_SUBSYS_RST, &val);
- if (err < 0)
+ if (err)
return err;
val |= BIT(0);
err = btmtk_usb_uhw_reg_write(hdev, MTK_BT_SUBSYS_RST, val);
@@ -896,14 +890,14 @@ int btmtk_usb_subsys_reset(struct hci_de
msleep(100);
} else if (dev_id == 0x7925 || dev_id == 0x6639) {
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_RESET_REG_CONNV3, &val);
- if (err < 0)
+ if (err)
return err;
val |= (1 << 5);
err = btmtk_usb_uhw_reg_write(hdev, MTK_BT_RESET_REG_CONNV3, val);
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_RESET_REG_CONNV3, &val);
- if (err < 0)
+ if (err)
return err;
val &= 0xFFFF00FF;
val |= (1 << 13);
@@ -914,7 +908,7 @@ int btmtk_usb_subsys_reset(struct hci_de
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_RESET_REG_CONNV3, &val);
- if (err < 0)
+ if (err)
return err;
val |= (1 << 0);
err = btmtk_usb_uhw_reg_write(hdev, MTK_BT_RESET_REG_CONNV3, val);
@@ -924,13 +918,13 @@ int btmtk_usb_subsys_reset(struct hci_de
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_UDMA_INT_STA_BT, &val);
- if (err < 0)
+ if (err)
return err;
err = btmtk_usb_uhw_reg_write(hdev, MTK_UDMA_INT_STA_BT1, 0x000000FF);
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_UDMA_INT_STA_BT1, &val);
- if (err < 0)
+ if (err)
return err;
msleep(100);
} else {
@@ -940,7 +934,7 @@ int btmtk_usb_subsys_reset(struct hci_de
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_WDT_STATUS, &val);
- if (err < 0)
+ if (err)
return err;
/* Reset the bluetooth chip via USB interface. */
err = btmtk_usb_uhw_reg_write(hdev, MTK_BT_SUBSYS_RST, 1);
@@ -950,13 +944,13 @@ int btmtk_usb_subsys_reset(struct hci_de
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_UDMA_INT_STA_BT, &val);
- if (err < 0)
+ if (err)
return err;
err = btmtk_usb_uhw_reg_write(hdev, MTK_UDMA_INT_STA_BT1, 0x000000FF);
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_UDMA_INT_STA_BT1, &val);
- if (err < 0)
+ if (err)
return err;
/* MT7921 need to delay 20ms between toggle reset bit */
msleep(20);
@@ -964,7 +958,7 @@ int btmtk_usb_subsys_reset(struct hci_de
if (err < 0)
return err;
err = btmtk_usb_uhw_reg_read(hdev, MTK_BT_SUBSYS_RST, &val);
- if (err < 0)
+ if (err)
return err;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 241/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (239 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 240/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 242/438] Bluetooth: mgmt: fix pending command UAF in EIR updates Greg Kroah-Hartman
` (210 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
commit 0cc4b5649ae83deb8222100dba31aa0f100a19cd upstream.
If btmtk_usb_reg_read() gets a "short" read from a device, it will
accidentally treat that as a "real" read and populate the returned value
with some unknown and probably totally invalid data.
Fix this logic error up by calling usb_control_msg_recv() which
guarantees a "full" read happens, and then simplify the error checking
for when btmtk_usb_reg_read() is called (it's really just
btmtk_usb_id_get() that calls btmtk_usb_reg_read(), so fix up those
return sites.
Cc: stable <stable@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/btmtk.c | 36 +++++++++++++++---------------------
1 file changed, 15 insertions(+), 21 deletions(-)
--- a/drivers/bluetooth/btmtk.c
+++ b/drivers/bluetooth/btmtk.c
@@ -827,27 +827,21 @@ static int btmtk_usb_uhw_reg_read(struct
static int btmtk_usb_reg_read(struct hci_dev *hdev, u32 reg, u32 *val)
{
struct btmtk_data *data = hci_get_priv(hdev);
- int pipe, err, size = sizeof(u32);
- void *buf;
-
- buf = kzalloc(size, GFP_KERNEL);
- if (!buf)
- return -ENOMEM;
+ u8 buf[sizeof(u32)];
+ int err;
- pipe = usb_rcvctrlpipe(data->udev, 0);
- err = usb_control_msg(data->udev, pipe, 0x63,
- USB_TYPE_VENDOR | USB_DIR_IN,
- reg >> 16, reg & 0xffff,
- buf, size, USB_CTRL_GET_TIMEOUT);
+ *val = 0;
+ err = usb_control_msg_recv(data->udev, 0, 0x63,
+ USB_TYPE_VENDOR | USB_DIR_IN,
+ reg >> 16, reg & 0xffff,
+ buf, sizeof(buf), USB_CTRL_GET_TIMEOUT,
+ GFP_KERNEL);
if (err < 0)
- goto err_free_buf;
+ return err;
*val = get_unaligned_le32(buf);
-err_free_buf:
- kfree(buf);
-
- return err;
+ return 0;
}
static int btmtk_usb_id_get(struct hci_dev *hdev, u32 reg, u32 *id)
@@ -974,7 +968,7 @@ int btmtk_usb_subsys_reset(struct hci_de
}
err = btmtk_usb_id_get(hdev, 0x70010200, &val);
- if (err < 0 || (!val && dev_id != 0x6639))
+ if (err || (!val && dev_id != 0x6639))
bt_dev_err(hdev, "Can't get device id, subsys reset fail.");
return err;
@@ -1318,24 +1312,24 @@ int btmtk_usb_setup(struct hci_dev *hdev
calltime = ktime_get();
err = btmtk_usb_id_get(hdev, 0x80000008, &dev_id);
- if (err < 0) {
+ if (err) {
bt_dev_err(hdev, "Failed to get device id (%d)", err);
return err;
}
if (!dev_id || dev_id != 0x7663) {
err = btmtk_usb_id_get(hdev, 0x70010200, &dev_id);
- if (err < 0) {
+ if (err) {
bt_dev_err(hdev, "Failed to get device id (%d)", err);
return err;
}
err = btmtk_usb_id_get(hdev, 0x80021004, &fw_version);
- if (err < 0) {
+ if (err) {
bt_dev_err(hdev, "Failed to get fw version (%d)", err);
return err;
}
err = btmtk_usb_id_get(hdev, 0x70010020, &fw_flavor);
- if (err < 0) {
+ if (err) {
bt_dev_err(hdev, "Failed to get fw flavor (%d)", err);
return err;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 242/438] Bluetooth: mgmt: fix pending command UAF in EIR updates
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (240 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 241/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 243/438] Bluetooth: SCO: give the socket its own sco_conn reference Greg Kroah-Hartman
` (209 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zihan Xi, Ren Wei,
Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit 8f2f62855a41d1730fb9e8122912bd2c8d6bed5d upstream.
MGMT_OP_SET_LOCAL_NAME is handled asynchronously on powered controllers
and can run set_name_sync(). When the controller is BR/EDR capable,
set_name_sync() updates the local name and then rebuilds EIR data through
eir_create(). The EIR builder walks hdev->uuids, but the UUID list can
be changed and entries can be freed by MGMT_OP_ADD_UUID and
MGMT_OP_REMOVE_UUID.
pending_eir_or_class() is meant to serialize management commands that
can change EIR or the class of device, but it did not include
MGMT_OP_SET_LOCAL_NAME. In addition, it walked hdev->mgmt_pending
without hdev->mgmt_pending_lock even though pending commands are added
and removed under that mutex. A racing command completion can therefore
remove and free a pending command while pending_eir_or_class() is still
inspecting it, leading to a use-after-free in the pending-command list or
allowing a local name update to rebuild EIR while UUID entries are being
removed.
Take hdev->mgmt_pending_lock while scanning hdev->mgmt_pending and treat
MGMT_OP_SET_LOCAL_NAME as an EIR/class-affecting pending command on the
powered asynchronous path. Check for a conflicting pending command before
copying the new short name so a rejected SET_LOCAL_NAME request does not
modify hdev->short_name.
Fixes: 6fe26f694c82 ("Bluetooth: MGMT: Protect mgmt_pending list with its own lock")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/mgmt.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -2699,18 +2699,28 @@ static int mgmt_hci_cmd_sync(struct sock
static bool pending_eir_or_class(struct hci_dev *hdev)
{
struct mgmt_pending_cmd *cmd;
+ bool pending = false;
+
+ mutex_lock(&hdev->mgmt_pending_lock);
list_for_each_entry(cmd, &hdev->mgmt_pending, list) {
switch (cmd->opcode) {
case MGMT_OP_ADD_UUID:
case MGMT_OP_REMOVE_UUID:
case MGMT_OP_SET_DEV_CLASS:
+ case MGMT_OP_SET_LOCAL_NAME:
case MGMT_OP_SET_POWERED:
- return true;
+ pending = true;
+ break;
}
+
+ if (pending)
+ break;
}
- return false;
+ mutex_unlock(&hdev->mgmt_pending_lock);
+
+ return pending;
}
static const u8 bluetooth_base_uuid[] = {
@@ -4046,6 +4056,12 @@ static int set_local_name(struct sock *s
goto failed;
}
+ if (hdev_is_powered(hdev) && pending_eir_or_class(hdev)) {
+ err = mgmt_cmd_status(sk, hdev->id, MGMT_OP_SET_LOCAL_NAME,
+ MGMT_STATUS_BUSY);
+ goto failed;
+ }
+
memcpy(hdev->short_name, cp->short_name, sizeof(hdev->short_name));
if (!hdev_is_powered(hdev)) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 243/438] Bluetooth: SCO: give the socket its own sco_conn reference
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (241 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 242/438] Bluetooth: mgmt: fix pending command UAF in EIR updates Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 244/438] Bluetooth: mgmt: fix UAF in pair command cancellation Greg Kroah-Hartman
` (208 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit abd93c85c8667add738ee82aeab95dd9fc8265a2 upstream.
sco_conn_del() drops a reference it does not own. It takes one transient
reference via sco_conn_hold_unless_zero() and releases it with the
sco_conn_put() that follows sco_sock_hold(); the additional put in the
!sk branch releases a second one:
conn = sco_conn_hold_unless_zero(conn);
...
sk = sco_sock_hold(conn);
sco_conn_unlock(conn);
sco_conn_put(conn);
if (!sk) {
sco_conn_put(conn);
return;
}
When close() races the controller's Disconnection Complete, sco_chan_del()
clears conn->sk and drops the socket's reference while sco_conn_del() is
running. sco_conn_del() then sees sk == NULL, its own put drops the count
to zero and frees the conn, and the second put writes to the freed kref:
BUG: KASAN: slab-use-after-free in sco_conn_put.part.0+0x1a/0x190
Write of size 4 at addr ffff8881099dec74 by task kworker/u17:3/413
Workqueue: hci1 hci_rx_work
Call Trace:
sco_conn_put.part.0+0x1a/0x190
hci_disconn_complete_evt+0x1ee/0x3e0
hci_event_packet+0x54a/0x650
hci_rx_work+0x321/0x3d0
Allocated by task 413:
sco_conn_add+0x72/0x1a0
sco_connect_cfm+0x88/0x670
Freed by task 413:
sco_conn_del.isra.0+0x3f/0xf0
hci_disconn_complete_evt+0x1ee/0x3e0
refcount_t: underflow; use-after-free.
The root cause is that the socket stores the connection without holding a
reference of its own. __sco_chan_add() does:
sco_pi(sk)->conn = conn;
so the socket borrows whatever reference its caller happened to hold, and
the callers paper over that with ad-hoc holds and puts. Give the socket a
counted reference instead: __sco_chan_add() takes one and it is released
together with the channel (sco_chan_del()) and in sco_sock_destruct().
With the socket holding its own reference, sco_conn_del() no longer needs
the extra put and the redundant hold in sco_conn_ready() goes away.
Making the socket own its reference means the connection is now actually
freed on the error paths of sco_connect() where it used to leak, which in
turn runs sco_conn_free() and its hci_conn_drop(conn->hcon). To keep the
hci_conn accounting balanced, make that ownership explicit as well:
sco_conn_add() consumes one hci_conn reference and the sco_conn owns it for
its lifetime. sco_connect() hands over the reference returned by
hci_connect_sco() and no longer drops it on the error paths;
sco_connect_cfm(), which is not given a reference, takes one with
hci_conn_hold() before handing it to sco_conn_add() (and drops it again if
the allocation fails); and the explicit hci_conn_hold() in sco_conn_ready()
is removed. Every reference then has a single, clear owner.
Fixes: e6720779ae61 ("Bluetooth: SCO: Use kref to track lifetime of sco_conn")
Cc: stable@vger.kernel.org
Suggested-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/sco.c | 22 +++++++++++++---------
1 file changed, 13 insertions(+), 9 deletions(-)
--- a/net/bluetooth/sco.c
+++ b/net/bluetooth/sco.c
@@ -190,6 +190,9 @@ static void sco_sock_clear_timer(struct
}
/* ---- SCO connections ---- */
+/* Consumes a reference on @hcon, which the returned sco_conn owns until it is
+ * freed. On failure (NULL return) the reference is left for the caller to drop.
+ */
static struct sco_conn *sco_conn_add(struct hci_conn *hcon)
{
struct sco_conn *conn = hcon->sco_data;
@@ -200,6 +203,9 @@ static struct sco_conn *sco_conn_add(str
sco_conn_lock(conn);
conn->hcon = hcon;
sco_conn_unlock(conn);
+ } else {
+ /* conn already owns a reference on hcon */
+ hci_conn_drop(hcon);
}
return conn;
}
@@ -267,10 +273,8 @@ static void sco_conn_del(struct hci_conn
sco_conn_unlock(conn);
sco_conn_put(conn);
- if (!sk) {
- sco_conn_put(conn);
+ if (!sk)
return;
- }
/* Kill socket */
lock_sock(sk);
@@ -285,7 +289,7 @@ static void __sco_chan_add(struct sco_co
{
BT_DBG("conn %p", conn);
- sco_pi(sk)->conn = conn;
+ sco_pi(sk)->conn = sco_conn_hold(conn);
conn->sk = sk;
if (parent)
@@ -368,15 +372,15 @@ static int sco_connect(struct sock *sk)
*/
if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND) {
release_sock(sk);
- hci_conn_drop(hcon);
+ sco_conn_put(conn);
err = -EBADFD;
goto unlock;
}
err = sco_chan_add(conn, sk, NULL);
+ sco_conn_put(conn);
if (err) {
release_sock(sk);
- hci_conn_drop(hcon);
goto unlock;
}
@@ -1452,8 +1456,6 @@ static void sco_conn_ready(struct sco_co
bacpy(&sco_pi(sk)->src, &conn->hcon->src);
bacpy(&sco_pi(sk)->dst, &conn->hcon->dst);
- sco_conn_hold(conn);
- hci_conn_hold(conn->hcon);
__sco_chan_add(conn, sk, parent);
if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(parent)->flags))
@@ -1509,10 +1511,12 @@ static void sco_connect_cfm(struct hci_c
if (!status) {
struct sco_conn *conn;
- conn = sco_conn_add(hcon);
+ conn = sco_conn_add(hci_conn_hold(hcon));
if (conn) {
sco_conn_ready(conn);
sco_conn_put(conn);
+ } else {
+ hci_conn_drop(hcon);
}
} else
sco_conn_del(hcon, bt_to_errno(status));
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 244/438] Bluetooth: mgmt: fix UAF in pair command cancellation
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (242 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 243/438] Bluetooth: SCO: give the socket its own sco_conn reference Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 245/438] Bluetooth: hci_sync: Fix advertising data UAFs Greg Kroah-Hartman
` (207 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zihan Xi, Ren Wei,
Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <xizh2024@lzu.edu.cn>
commit d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd upstream.
The pairing completion and authentication failure callbacks look up the
pending MGMT_OP_PAIR_DEVICE command by walking hdev->mgmt_pending. The
lookup returned a command that was still linked on the shared pending list,
without keeping mgmt_pending_lock held for the later dereference and
removal.
A concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the
same pending command before the callback uses it. The reverse race is also
possible when cancel_pair_device() gets a command from pending_find() and a
callback removes it before the cancel path dereferences it. This can lead
to a use-after-free and a second list_del().
Make the pairing lookup helpers transfer ownership of the pending command
by removing it from hdev->mgmt_pending while holding mgmt_pending_lock.
The callbacks and cancel path then complete the command and free it
directly, so racing paths cannot find or free the same command again. Take
a temporary hci_conn reference in cancel_pair_device() because the command
completion drops the reference stored in the pending command.
Fixes: e9a416b5ce0c ("Bluetooth: Add mgmt_pair_device command")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Zihan Xi <xizh2024@lzu.edu.cn>
Reviewed-by: Ren Wei <enjou1224z@gmail.com>
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/mgmt.c | 64 ++++++++++++++++++++++++++++++++++++---------------
1 file changed, 46 insertions(+), 18 deletions(-)
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -3527,11 +3527,13 @@ static int set_io_capability(struct sock
NULL, 0);
}
-static struct mgmt_pending_cmd *find_pairing(struct hci_conn *conn)
+static struct mgmt_pending_cmd *remove_pairing(struct hci_conn *conn)
{
struct hci_dev *hdev = conn->hdev;
struct mgmt_pending_cmd *cmd;
+ mutex_lock(&hdev->mgmt_pending_lock);
+
list_for_each_entry(cmd, &hdev->mgmt_pending, list) {
if (cmd->opcode != MGMT_OP_PAIR_DEVICE)
continue;
@@ -3539,9 +3541,39 @@ static struct mgmt_pending_cmd *find_pai
if (cmd->user_data != conn)
continue;
+ list_del(&cmd->list);
+ mutex_unlock(&hdev->mgmt_pending_lock);
return cmd;
}
+ mutex_unlock(&hdev->mgmt_pending_lock);
+
+ return NULL;
+}
+
+static struct mgmt_pending_cmd *remove_pairing_by_addr(struct hci_dev *hdev,
+ bdaddr_t *bdaddr)
+{
+ struct mgmt_pending_cmd *cmd;
+ struct hci_conn *conn;
+
+ mutex_lock(&hdev->mgmt_pending_lock);
+
+ list_for_each_entry(cmd, &hdev->mgmt_pending, list) {
+ if (cmd->opcode != MGMT_OP_PAIR_DEVICE)
+ continue;
+
+ conn = cmd->user_data;
+ if (bacmp(bdaddr, &conn->dst) != 0)
+ continue;
+
+ list_del(&cmd->list);
+ mutex_unlock(&hdev->mgmt_pending_lock);
+ return cmd;
+ }
+
+ mutex_unlock(&hdev->mgmt_pending_lock);
+
return NULL;
}
@@ -3579,10 +3611,10 @@ void mgmt_smp_complete(struct hci_conn *
u8 status = complete ? MGMT_STATUS_SUCCESS : MGMT_STATUS_FAILED;
struct mgmt_pending_cmd *cmd;
- cmd = find_pairing(conn);
+ cmd = remove_pairing(conn);
if (cmd) {
cmd->cmd_complete(cmd, status);
- mgmt_pending_remove(cmd);
+ mgmt_pending_free(cmd);
}
}
@@ -3592,14 +3624,14 @@ static void pairing_complete_cb(struct h
BT_DBG("status %u", status);
- cmd = find_pairing(conn);
+ cmd = remove_pairing(conn);
if (!cmd) {
BT_DBG("Unable to find a pending command");
return;
}
cmd->cmd_complete(cmd, mgmt_status(status));
- mgmt_pending_remove(cmd);
+ mgmt_pending_free(cmd);
}
static void le_pairing_complete_cb(struct hci_conn *conn, u8 status)
@@ -3611,14 +3643,14 @@ static void le_pairing_complete_cb(struc
if (!status)
return;
- cmd = find_pairing(conn);
+ cmd = remove_pairing(conn);
if (!cmd) {
BT_DBG("Unable to find a pending command");
return;
}
cmd->cmd_complete(cmd, mgmt_status(status));
- mgmt_pending_remove(cmd);
+ mgmt_pending_free(cmd);
}
static int pair_device(struct sock *sk, struct hci_dev *hdev, void *data,
@@ -3775,23 +3807,17 @@ static int cancel_pair_device(struct soc
goto unlock;
}
- cmd = pending_find(MGMT_OP_PAIR_DEVICE, hdev);
+ cmd = remove_pairing_by_addr(hdev, &addr->bdaddr);
if (!cmd) {
err = mgmt_cmd_status(sk, hdev->id, MGMT_OP_CANCEL_PAIR_DEVICE,
MGMT_STATUS_INVALID_PARAMS);
goto unlock;
}
- conn = cmd->user_data;
-
- if (bacmp(&addr->bdaddr, &conn->dst) != 0) {
- err = mgmt_cmd_status(sk, hdev->id, MGMT_OP_CANCEL_PAIR_DEVICE,
- MGMT_STATUS_INVALID_PARAMS);
- goto unlock;
- }
+ conn = hci_conn_get(cmd->user_data);
cmd->cmd_complete(cmd, MGMT_STATUS_CANCELLED);
- mgmt_pending_remove(cmd);
+ mgmt_pending_free(cmd);
err = mgmt_cmd_complete(sk, hdev->id, MGMT_OP_CANCEL_PAIR_DEVICE, 0,
addr, sizeof(*addr));
@@ -3809,6 +3835,8 @@ static int cancel_pair_device(struct soc
if (conn->conn_reason == CONN_REASON_PAIR_DEVICE)
hci_abort_conn(conn, HCI_ERROR_REMOTE_USER_TERM);
+ hci_conn_put(conn);
+
unlock:
hci_dev_unlock(hdev);
return err;
@@ -10156,14 +10184,14 @@ void mgmt_auth_failed(struct hci_conn *c
ev.addr.type = link_to_bdaddr(conn->type, conn->dst_type);
ev.status = status;
- cmd = find_pairing(conn);
+ cmd = remove_pairing(conn);
mgmt_event(MGMT_EV_AUTH_FAILED, conn->hdev, &ev, sizeof(ev),
cmd ? cmd->sk : NULL);
if (cmd) {
cmd->cmd_complete(cmd, status);
- mgmt_pending_remove(cmd);
+ mgmt_pending_free(cmd);
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 245/438] Bluetooth: hci_sync: Fix advertising data UAFs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (243 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 244/438] Bluetooth: mgmt: fix UAF in pair command cancellation Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 246/438] Bluetooth: HIDP: reject frames without a transaction header Greg Kroah-Hartman
` (206 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Chengfeng Ye,
Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit cdc36db204ffd97b947d64374cf23a210dc74777 upstream.
hci_find_adv_instance() returns an adv_info pointer that is valid only
while hdev->lock is held. The advertising command-sync paths perform
instance lookups without that lock and, in some cases, retain the pointer
while waiting for a controller response.
An advertising termination event can therefore interleave as follows:
hci_cmd_sync_work hci_rx_work
hci_find_adv_instance()
__hci_cmd_sync_status()
wait for controller reply hci_dev_lock()
hci_remove_adv_instance()
kfree(adv)
adv->scan_rsp_changed = false
KASAN reported:
BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
hci_schedule_adv_instance_sync+0x390/0x4c0
hci_cmd_sync_work+0x173/0x300
Allocated by task 87:
hci_add_adv_instance+0x538/0xac0
add_advertising+0x885/0x1160
Freed by task 89:
kfree+0x131/0x3c0
hci_remove_adv_instance+0x1d8/0x3b0
hci_le_ext_adv_term_evt+0x17b/0x730
Protect the instance lookup and payload construction in the extended
advertising, scan response, and periodic advertising data paths. Snapshot
the advertising parameters under hdev->lock, but release the lock before
waiting for the controller.
Clear advertising-data dirty bits before issuing their commands and
restore them after a failure using a fresh lookup. Likewise, update the
reported transmit power through a fresh lookup after the parameter command
completes. No adv_info pointer then survives an HCI command wait.
Fixes: cba6b758711c ("Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2")
Cc: stable@vger.kernel.org
Suggested-by: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sync.c | 131 ++++++++++++++++++++++++++++++++++-------------
1 file changed, 97 insertions(+), 34 deletions(-)
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -1233,10 +1233,11 @@ static int hci_set_adv_set_random_addr_s
}
static int
-hci_set_ext_adv_params_sync(struct hci_dev *hdev, struct adv_info *adv,
+hci_set_ext_adv_params_sync(struct hci_dev *hdev, u8 instance,
const struct hci_cp_le_set_ext_adv_params *cp,
struct hci_rp_le_set_ext_adv_params *rp)
{
+ struct adv_info *adv;
struct sk_buff *skb;
skb = __hci_cmd_sync(hdev, HCI_OP_LE_SET_EXT_ADV_PARAMS, sizeof(*cp),
@@ -1264,11 +1265,15 @@ hci_set_ext_adv_params_sync(struct hci_d
if (!rp->status) {
hdev->adv_addr_type = cp->own_addr_type;
- if (!cp->handle) {
+ if (!instance) {
/* Store in hdev for instance 0 */
hdev->adv_tx_power = rp->tx_power;
- } else if (adv) {
- adv->tx_power = rp->tx_power;
+ } else {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (adv)
+ adv->tx_power = rp->tx_power;
+ hci_dev_unlock(hdev);
}
}
@@ -1284,9 +1289,13 @@ static int hci_set_ext_adv_data_sync(str
int err;
if (instance) {
+ hci_dev_lock(hdev);
+
adv = hci_find_adv_instance(hdev, instance);
- if (!adv || !adv->adv_data_changed)
+ if (!adv || !adv->adv_data_changed) {
+ hci_dev_unlock(hdev);
return 0;
+ }
}
len = eir_create_adv_data(hdev, instance, pdu->data,
@@ -1297,16 +1306,27 @@ static int hci_set_ext_adv_data_sync(str
pdu->operation = LE_SET_ADV_DATA_OP_COMPLETE;
pdu->frag_pref = LE_SET_ADV_DATA_NO_FRAG;
+ if (adv) {
+ adv->adv_data_changed = false;
+ hci_dev_unlock(hdev);
+ }
+
err = __hci_cmd_sync_status(hdev, HCI_OP_LE_SET_EXT_ADV_DATA,
struct_size(pdu, data, len), pdu,
HCI_CMD_TIMEOUT);
- if (err)
+ if (err) {
+ if (instance) {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (adv)
+ adv->adv_data_changed = true;
+ hci_dev_unlock(hdev);
+ }
+
return err;
+ }
- /* Update data if the command succeed */
- if (adv) {
- adv->adv_data_changed = false;
- } else {
+ if (!instance) {
memcpy(hdev->adv_data, pdu->data, len);
hdev->adv_data_len = len;
}
@@ -1360,22 +1380,22 @@ int hci_setup_ext_adv_instance_sync(stru
struct adv_info *adv;
bool secondary_adv;
- if (instance > 0) {
- adv = hci_find_adv_instance(hdev, instance);
- if (!adv)
- return -EINVAL;
- } else {
- adv = NULL;
- }
-
/* Updating parameters of an active instance will return a
- * Command Disallowed error, so we must first disable the
- * instance if it is active.
+ * Command Disallowed error, so disable it before taking a snapshot.
*/
- if (adv) {
+ if (instance > 0) {
err = hci_disable_ext_adv_instance_sync(hdev, instance);
if (err)
return err;
+
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (!adv) {
+ hci_dev_unlock(hdev);
+ return -EINVAL;
+ }
+ } else {
+ adv = NULL;
}
flags = hci_adv_instance_flags(hdev, instance);
@@ -1386,8 +1406,11 @@ int hci_setup_ext_adv_instance_sync(stru
connectable = (flags & MGMT_ADV_FLAG_CONNECTABLE) ||
mgmt_get_connectable(hdev);
- if (!is_advertising_allowed(hdev, connectable))
+ if (!is_advertising_allowed(hdev, connectable)) {
+ if (instance)
+ hci_dev_unlock(hdev);
return -EPERM;
+ }
/* Set require_privacy to true only when non-connectable
* advertising is used and it is not periodic.
@@ -1398,8 +1421,11 @@ int hci_setup_ext_adv_instance_sync(stru
err = hci_get_random_address(hdev, require_privacy,
adv_use_rpa(hdev, flags), adv,
&own_addr_type, &random_addr);
- if (err < 0)
+ if (err < 0) {
+ if (instance)
+ hci_dev_unlock(hdev);
return err;
+ }
memset(&cp, 0, sizeof(cp));
@@ -1450,6 +1476,9 @@ int hci_setup_ext_adv_instance_sync(stru
cp.channel_map = hdev->le_adv_channel_map;
cp.handle = adv ? adv->handle : instance;
+ if (instance)
+ hci_dev_unlock(hdev);
+
if (flags & MGMT_ADV_FLAG_SEC_2M) {
cp.primary_phy = HCI_ADV_PHY_1M;
cp.secondary_phy = HCI_ADV_PHY_2M;
@@ -1462,12 +1491,12 @@ int hci_setup_ext_adv_instance_sync(stru
cp.secondary_phy = HCI_ADV_PHY_1M;
}
- err = hci_set_ext_adv_params_sync(hdev, adv, &cp, &rp);
+ err = hci_set_ext_adv_params_sync(hdev, instance, &cp, &rp);
if (err)
return err;
/* Update adv data as tx power is known now */
- err = hci_set_ext_adv_data_sync(hdev, cp.handle);
+ err = hci_set_ext_adv_data_sync(hdev, instance);
if (err)
return err;
@@ -1475,9 +1504,14 @@ int hci_setup_ext_adv_instance_sync(stru
own_addr_type == ADDR_LE_DEV_RANDOM_RESOLVED) &&
bacmp(&random_addr, BDADDR_ANY)) {
/* Check if random address need to be updated */
- if (adv) {
- if (!bacmp(&random_addr, &adv->random_addr))
+ if (instance) {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (!adv || !bacmp(&random_addr, &adv->random_addr)) {
+ hci_dev_unlock(hdev);
return 0;
+ }
+ hci_dev_unlock(hdev);
} else {
if (!bacmp(&random_addr, &hdev->random_addr))
return 0;
@@ -1499,9 +1533,13 @@ static int hci_set_ext_scan_rsp_data_syn
int err;
if (instance) {
+ hci_dev_lock(hdev);
+
adv = hci_find_adv_instance(hdev, instance);
- if (!adv || !adv->scan_rsp_changed)
+ if (!adv || !adv->scan_rsp_changed) {
+ hci_dev_unlock(hdev);
return 0;
+ }
}
len = eir_create_scan_rsp(hdev, instance, pdu->data);
@@ -1511,15 +1549,27 @@ static int hci_set_ext_scan_rsp_data_syn
pdu->operation = LE_SET_ADV_DATA_OP_COMPLETE;
pdu->frag_pref = LE_SET_ADV_DATA_NO_FRAG;
+ if (adv) {
+ adv->scan_rsp_changed = false;
+ hci_dev_unlock(hdev);
+ }
+
err = __hci_cmd_sync_status(hdev, HCI_OP_LE_SET_EXT_SCAN_RSP_DATA,
struct_size(pdu, data, len), pdu,
HCI_CMD_TIMEOUT);
- if (err)
+ if (err) {
+ if (instance) {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (adv)
+ adv->scan_rsp_changed = true;
+ hci_dev_unlock(hdev);
+ }
+
return err;
+ }
- if (adv) {
- adv->scan_rsp_changed = false;
- } else {
+ if (!instance) {
memcpy(hdev->scan_rsp_data, pdu->data, len);
hdev->scan_rsp_data_len = len;
}
@@ -1534,8 +1584,14 @@ static int __hci_set_scan_rsp_data_sync(
memset(&cp, 0, sizeof(cp));
+ if (instance)
+ hci_dev_lock(hdev);
+
len = eir_create_scan_rsp(hdev, instance, cp.data);
+ if (instance)
+ hci_dev_unlock(hdev);
+
if (hdev->scan_rsp_data_len == len &&
!memcmp(cp.data, hdev->scan_rsp_data, len))
return 0;
@@ -1670,9 +1726,13 @@ static int hci_set_per_adv_data_sync(str
struct adv_info *adv = NULL;
if (instance) {
+ hci_dev_lock(hdev);
+
adv = hci_find_adv_instance(hdev, instance);
- if (!adv || !adv->periodic)
+ if (!adv || !adv->periodic) {
+ hci_dev_unlock(hdev);
return 0;
+ }
}
len = eir_create_per_adv_data(hdev, instance, pdu->data);
@@ -1681,6 +1741,9 @@ static int hci_set_per_adv_data_sync(str
pdu->handle = adv ? adv->handle : instance;
pdu->operation = LE_SET_ADV_DATA_OP_COMPLETE;
+ if (adv)
+ hci_dev_unlock(hdev);
+
return __hci_cmd_sync_status(hdev, HCI_OP_LE_SET_PER_ADV_DATA,
struct_size(pdu, data, len), pdu,
HCI_CMD_TIMEOUT);
@@ -6501,7 +6564,7 @@ static int hci_le_ext_directed_advertisi
if (err)
return err;
- err = hci_set_ext_adv_params_sync(hdev, NULL, &cp, &rp);
+ err = hci_set_ext_adv_params_sync(hdev, 0, &cp, &rp);
if (err)
return err;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 246/438] Bluetooth: HIDP: reject frames without a transaction header
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (244 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 245/438] Bluetooth: hci_sync: Fix advertising data UAFs Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 247/438] Bluetooth: HIDP: validate numbered report payloads Greg Kroah-Hartman
` (205 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sangho Lee, Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sangho Lee <kudo3228@gmail.com>
commit 47778d2c2087b5d192398f6fddf692d16a5431cf upstream.
hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0]
before checking that the L2CAP SDU contains a transaction header. A
connected HIDP peer can send an empty basic-mode SDU and make both paths
use an uninitialized byte from skb tailroom.
KMSAN reports the use in hidp_session_run(), with the uninitialized value
originating in __alloc_skb() through vhci_write(). The control path
produces two reports and the interrupt path produces one.
The byte can also be controlled by a malformed lower-layer packet. If an
HCI ACL packet contains an L2CAP PDU with a declared zero-length payload
followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to
the declared PDU length before dispatch. The current HIDP path nevertheless
consumes the extra byte as HIDP_TRANS_HID_CONTROL |
HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this
change, the same packet is discarded and a subsequent feature report
request succeeds.
Pull the transaction header with skb_pull_data() and discard frames that
do not contain it.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Sangho Lee <kudo3228@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hidp/core.c | 25 +++++++++++++++----------
1 file changed, 15 insertions(+), 10 deletions(-)
--- a/net/bluetooth/hidp/core.c
+++ b/net/bluetooth/hidp/core.c
@@ -563,16 +563,18 @@ static int hidp_process_data(struct hidp
static void hidp_recv_ctrl_frame(struct hidp_session *session,
struct sk_buff *skb)
{
- unsigned char hdr, type, param;
+ unsigned char type, param;
+ u8 *hdr;
int free_skb = 1;
BT_DBG("session %p skb %p len %u", session, skb, skb->len);
- hdr = skb->data[0];
- skb_pull(skb, 1);
+ hdr = skb_pull_data(skb, 1);
+ if (!hdr)
+ goto free;
- type = hdr & HIDP_HEADER_TRANS_MASK;
- param = hdr & HIDP_HEADER_PARAM_MASK;
+ type = *hdr & HIDP_HEADER_TRANS_MASK;
+ param = *hdr & HIDP_HEADER_PARAM_MASK;
switch (type) {
case HIDP_TRANS_HANDSHAKE:
@@ -593,6 +595,7 @@ static void hidp_recv_ctrl_frame(struct
break;
}
+free:
if (free_skb)
kfree_skb(skb);
}
@@ -600,14 +603,15 @@ static void hidp_recv_ctrl_frame(struct
static void hidp_recv_intr_frame(struct hidp_session *session,
struct sk_buff *skb)
{
- unsigned char hdr;
+ u8 *hdr;
BT_DBG("session %p skb %p len %u", session, skb, skb->len);
- hdr = skb->data[0];
- skb_pull(skb, 1);
+ hdr = skb_pull_data(skb, 1);
+ if (!hdr)
+ goto free;
- if (hdr == (HIDP_TRANS_DATA | HIDP_DATA_RTYPE_INPUT)) {
+ if (*hdr == (HIDP_TRANS_DATA | HIDP_DATA_RTYPE_INPUT)) {
hidp_set_timer(session);
if (session->input)
@@ -619,9 +623,10 @@ static void hidp_recv_intr_frame(struct
BT_DBG("report len %d", skb->len);
}
} else {
- BT_DBG("Unsupported protocol header 0x%02x", hdr);
+ BT_DBG("Unsupported protocol header 0x%02x", *hdr);
}
+free:
kfree_skb(skb);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 247/438] Bluetooth: HIDP: validate numbered report payloads
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (245 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 246/438] Bluetooth: HIDP: reject frames without a transaction header Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 248/438] bpf: lwt: Fix dst reference leak on reroute failure Greg Kroah-Hartman
` (204 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sangho Lee, Luiz Augusto von Dentz
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sangho Lee <kudo3228@gmail.com>
commit 34f53d27b81a16a02828c8fdfa4e02badc326f17 upstream.
When hidp_get_raw_report() waits for a numbered report,
hidp_process_data() compares the expected report number with skb->data[0].
A connected HIDP peer can reply with only a DATA transaction header,
leaving the skb empty after the header is removed.
KMSAN reports an uninitialized-value use in hidp_session_run(), with the
value originating in __alloc_skb() through vhci_write(). The transaction
header checks remove the empty-frame reports, but this report remains until
the payload check is added.
The comparison can also consume a peer-controlled byte beyond the declared
L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made
the current code accept that byte as report ID 1 and complete
HIDIOCGFEATURE with a zero-byte result. With this change the malformed
response is rejected with -EIO, while a subsequent valid response still
succeeds.
Require a payload byte before comparing a numbered report ID. Unnumbered
reports continue to accept an empty payload.
Fixes: 0ff1731a1ae5 ("HID: bt: Add support for hidraw HIDIOCGFEATURE and HIDIOCSFEATURE")
Cc: stable@vger.kernel.org
Signed-off-by: Sangho Lee <kudo3228@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hidp/core.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/net/bluetooth/hidp/core.c
+++ b/net/bluetooth/hidp/core.c
@@ -546,9 +546,10 @@ static int hidp_process_data(struct hidp
}
if (test_bit(HIDP_WAITING_FOR_RETURN, &session->flags) &&
- param == session->waiting_report_type) {
+ param == session->waiting_report_type) {
if (session->waiting_report_number < 0 ||
- session->waiting_report_number == skb->data[0]) {
+ (skb->len &&
+ session->waiting_report_number == skb->data[0])) {
/* hidp_get_raw_report() is waiting on this report. */
session->report_return = skb;
done_with_skb = 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 248/438] bpf: lwt: Fix dst reference leak on reroute failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (246 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 247/438] Bluetooth: HIDP: validate numbered report payloads Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 249/438] afs: Fix afs_fs_fetch_data() to set call->async Greg Kroah-Hartman
` (203 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Paolo Abeni
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
commit 88c17de85ddb459c3fe1e3c65d61fa366b1cf0a8 upstream.
bpf_lwt_xmit_reroute() obtains a referenced dst from the route
lookup. When skb_cow_head() fails before that dst is installed on the
skb, the error path only frees the skb. The skb still owns its previous
dst, so the newly looked up dst reference is leaked.
Release the new dst reference before freeing the skb on this error
path.
Fixes: 3bd0b15281af ("bpf: add handling of BPF_LWT_REROUTE to lwt_bpf.c")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260723060445.21926-1-xuanqiang.luo@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/core/lwt_bpf.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/core/lwt_bpf.c
+++ b/net/core/lwt_bpf.c
@@ -255,8 +255,10 @@ static int bpf_lwt_xmit_reroute(struct s
* if there is enough header space in skb.
*/
err = skb_cow_head(skb, LL_RESERVED_SPACE(dst->dev));
- if (unlikely(err))
+ if (unlikely(err)) {
+ dst_release(dst);
goto err;
+ }
skb_dst_drop(skb);
skb_dst_set(skb, dst);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 249/438] afs: Fix afs_fs_fetch_data() to set call->async
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (247 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 248/438] bpf: lwt: Fix dst reference leak on reroute failure Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 250/438] afs: Fix afs_fs_fetch_data() to subtract transferred from len Greg Kroah-Hartman
` (202 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
Jeffrey Altman, linux-afs, stable, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
commit d568a43f6dbba3ba006304d95fd09862bd482a2f upstream.
Fix afs_fs_fetch_data() to set call->async on an async operation as does
afs_fs_fetch_data64().
Fixes: eddf51f2bb2c ("afs: Make {Y,}FS.FetchData an asynchronous operation")
Link: https://sashiko.dev/#/patchset/20260702144919.172295-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260723113452.566619-2-dhowells@redhat.com
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/afs/fsclient.c | 3 +++
1 file changed, 3 insertions(+)
--- a/fs/afs/fsclient.c
+++ b/fs/afs/fsclient.c
@@ -477,6 +477,9 @@ void afs_fs_fetch_data(struct afs_operat
if (!call)
return afs_op_nomem(op);
+ if (op->flags & AFS_OPERATION_ASYNC)
+ call->async = true;
+
/* marshall the parameters */
bp = call->request;
bp[0] = htonl(FSFETCHDATA);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 250/438] afs: Fix afs_fs_fetch_data() to subtract transferred from len
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (248 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 249/438] afs: Fix afs_fs_fetch_data() to set call->async Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 251/438] afs: Fix UAF when sending a message Greg Kroah-Hartman
` (201 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
Jeffrey Altman, linux-afs, stable, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
commit 222052c6be186f2074b3a4d741d5de200f654c43 upstream.
Fix afs_fs_fetch_data() to subtract subreq->transferred from subreq->len
rather than adding it.
Fixes: f28fc2010d62 ("afs: Eliminate afs_read")
Link: https://sashiko.dev/#/patchset/20260713081022.2186481-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260723113452.566619-3-dhowells@redhat.com
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/afs/fsclient.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/afs/fsclient.c
+++ b/fs/afs/fsclient.c
@@ -487,7 +487,7 @@ void afs_fs_fetch_data(struct afs_operat
bp[2] = htonl(vp->fid.vnode);
bp[3] = htonl(vp->fid.unique);
bp[4] = htonl(lower_32_bits(subreq->start + subreq->transferred));
- bp[5] = htonl(lower_32_bits(subreq->len + subreq->transferred));
+ bp[5] = htonl(lower_32_bits(subreq->len - subreq->transferred));
call->fid = vp->fid;
trace_afs_make_fs_call(call, &vp->fid);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 251/438] afs: Fix UAF when sending a message
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (249 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 250/438] afs: Fix afs_fs_fetch_data() to subtract transferred from len Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 252/438] ALSA: 6fire: Fix UAF at error handling during probe Greg Kroah-Hartman
` (200 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marc Dionne, David Howells,
Jeffrey Altman, linux-afs, stable, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
commit 4af1ec68d54b3871155914d584fb10669c41a861 upstream.
In afs_make_call(), there's a race with async call reception and
destruction. If a call is dispatched that doesn't have call->write_iter
set (used to specify the data content for FS.StoreData), then the first
rxrpc_kernel_send_data() will not set MSG_MORE in the msghdr.
Once rxrpc_send_data() queues the last request packet, the response could
come in at any time and cause the call to be completed and put. However,
afs_make_call() will look at the call again to see it ->write_iter should
be handled - something it's only allowed to do if it has its own ref on the
call. Whilst this is the case for synchronous calls, it isn't true for
async calls such as FS.FetchData.
There's also a potential UAF in afs_make_call() in the event that an
asynchronous call is being sent, but the call fails in some way (e.g. it
gets aborted from the server). The problem there is that afs_make_call()
tries to abort a call if the rxrpc send fails, but the asynchronous
notification from rxrpc may have caused the afs_call to be torn down.
generic/650 plays games with randomly taking CPUs offline, and can
interject a significant delay such that the call is deallocated before
afs_make_call() gets to check call->write_iter - and a UAF ensues (caught
by KASAN).
BUG: KASAN: slab-use-after-free in afs_make_call+0x1c90/0x2210 [kafs]
Read of size 8 at addr ffff888035e050e8 by task fsstress/1409
Fix this by making afs_make_op_call() give the op->call its own ref rather
than transferring the caller's ref to it and then dropping the ref when
afs_make_call() returns.
This also means that the afs_make_call() func never loses its ref on the
call now.
Fixes: eddf51f2bb2c ("afs: Make {Y,}FS.FetchData an asynchronous operation")
Fixes: e49c7b2f6de7 ("afs: Build an abstraction around an "operation" concept")
Link: https://sashiko.dev/#/patchset/20260702144919.172295-1-dhowells%40redhat.com
Reported-by: Marc Dionne <marc.dionne@auristor.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260723113452.566619-4-dhowells@redhat.com
cc: Jeffrey Altman <jaltman@auristor.com>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/afs/internal.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/fs/afs/internal.h
+++ b/fs/afs/internal.h
@@ -1421,7 +1421,7 @@ static inline void afs_make_op_call(stru
{
struct afs_addr_list *alist = op->estate->addresses;
- op->call = call;
+ op->call = afs_get_call(call, afs_call_trace_get);
op->type = call->type;
call->op = op;
call->key = op->key;
@@ -1429,6 +1429,7 @@ static inline void afs_make_op_call(stru
call->peer = rxrpc_kernel_get_peer(alist->addrs[op->addr_index].peer);
call->service_id = op->server->service_id;
afs_make_call(call, gfp);
+ afs_put_call(call);
}
static inline void afs_extract_begin(struct afs_call *call, void *buf, size_t size)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 252/438] ALSA: 6fire: Fix UAF at error handling during probe
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (250 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 251/438] afs: Fix UAF when sending a message Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 253/438] ALSA: hda/realtek: Add quirk for TongFang X6SP45xU Greg Kroah-Hartman
` (199 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Shuangpeng Bai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit a54bf16965f896415c3337bc4fbb40fb11941d99 upstream.
Although 6fire driver had a few fixes for dealing with the early error
handling during the probe phase, it forgot a pending URB before
freeing the resources, which may lead to a UAF.
This patch addresses it by doing the almost same cleanup procedure
like the normal disconnect phase at the error path.
Reported-and-tested-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Closes: https://lore.kernel.org/20260724030900.1984491-1-shuangpeng.kernel@gmail.com
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260726074821.2288158-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/6fire/chip.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/sound/usb/6fire/chip.c
+++ b/sound/usb/6fire/chip.c
@@ -150,6 +150,10 @@ static int usb6fire_chip_probe(struct us
return 0;
destroy_chip:
+ chip->shutdown = true;
+ if (card)
+ snd_card_disconnect(card);
+ usb6fire_chip_abort(chip);
snd_card_free(card);
return ret;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 253/438] ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (251 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 252/438] ALSA: 6fire: Fix UAF at error handling during probe Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 254/438] ALSA: lx6464es: fix period byte count for 16-bit streams Greg Kroah-Hartman
` (198 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eckhart Mohr, Werner Sembach,
Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eckhart Mohr <e.mohr@tuxedocomputers.com>
commit 26a94400ffa4fcbeff32e23abebb83a1a20eb401 upstream.
TongFang X6KK45xU and X6SP45xU have actually different PCI IDs. This patch
Adds the missing PCI ID to fix headphone detection and clarifies the
naming.
Fixes: d595255241e5 ("ALSA: hda/realtek: Add quirk for TongFang X6xx45xU")
Signed-off-by: Eckhart Mohr <e.mohr@tuxedocomputers.com>
Cc: stable@vger.kernel.org
Signed-off-by: Werner Sembach <wse@tuxedocomputers.com>
Link: https://patch.msgid.link/20260724190109.169889-1-wse@tuxedocomputers.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/hda/codecs/realtek/alc269.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -7858,7 +7858,8 @@ static const struct hda_quirk alc269_fix
SND_PCI_QUIRK(0x1d05, 0x300f, "TongFang X6AR5xxY", ALC2XX_FIXUP_HEADSET_MIC),
SND_PCI_QUIRK(0x1d05, 0x3019, "TongFang X6FR5xxY", ALC2XX_FIXUP_HEADSET_MIC),
SND_PCI_QUIRK(0x1d05, 0x3031, "TongFang X6AR55xU", ALC2XX_FIXUP_HEADSET_MIC),
- SND_PCI_QUIRK(0x1d05, 0x3034, "TongFang X6xx45xU", ALC2XX_FIXUP_HEADSET_MIC),
+ SND_PCI_QUIRK(0x1d05, 0x3033, "TongFang X6SP45xU", ALC2XX_FIXUP_HEADSET_MIC),
+ SND_PCI_QUIRK(0x1d05, 0x3034, "TongFang X6KK45xU", ALC2XX_FIXUP_HEADSET_MIC),
SND_PCI_QUIRK(0x1d17, 0x3288, "Haier Boyue G42", ALC269VC_FIXUP_ACER_VCOPPERBOX_PINS),
SND_PCI_QUIRK(0x1d72, 0x1602, "RedmiBook", ALC255_FIXUP_XIAOMI_HEADSET_MIC),
SND_PCI_QUIRK(0x1d72, 0x1701, "XiaomiNotebook Pro", ALC298_FIXUP_DELL1_MIC_NO_PRESENCE),
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 254/438] ALSA: lx6464es: fix period byte count for 16-bit streams
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (252 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 253/438] ALSA: hda/realtek: Add quirk for TongFang X6SP45xU Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 255/438] ALSA: pcm: wake linked drain waiters on unlink Greg Kroah-Hartman
` (197 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Rao <raoxu@uniontech.com>
commit 6437033bffe8bd2af174d139af552d90d40c7ac6 upstream.
The lx6464es driver advertises both 16-bit and packed 24-bit PCM formats,
but lx_trigger_start() and lx_interrupt_request_new_buffer() calculate the
DMA period size as runtime->period_size * runtime->channels * 3. That is
only correct for the packed 24-bit formats.
For 16-bit streams the driver submits buffers that are 50% larger than the
actual ALSA period and advances the DMA address by the same wrong amount.
For example, with 2 channels, 256 frames and 4 periods, the third buffer
already extends beyond the ALSA buffer and the fourth buffer starts outside
it.
Use snd_pcm_lib_period_bytes() so the byte count matches the runtime
format, channel count and period size.
Fixes: 02bec4904508 ("ALSA: lx6464es - driver for the digigram lx6464es interface")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Link: https://patch.msgid.link/8BB12E8D92A7CDBA+20260723085710.2567463-1-raoxu@uniontech.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/pci/lx6464es/lx6464es.c | 5 +----
sound/pci/lx6464es/lx_core.c | 5 +----
2 files changed, 2 insertions(+), 8 deletions(-)
--- a/sound/pci/lx6464es/lx6464es.c
+++ b/sound/pci/lx6464es/lx6464es.c
@@ -402,11 +402,8 @@ static void lx_trigger_start(struct lx64
int err;
- const u32 channels = substream->runtime->channels;
- const u32 bytes_per_frame = channels * 3;
- const u32 period_size = substream->runtime->period_size;
const u32 periods = substream->runtime->periods;
- const u32 period_bytes = period_size * bytes_per_frame;
+ const u32 period_bytes = snd_pcm_lib_period_bytes(substream);
dma_addr_t buf = substream->dma_buffer.addr;
int i;
--- a/sound/pci/lx6464es/lx_core.c
+++ b/sound/pci/lx6464es/lx_core.c
@@ -969,10 +969,7 @@ static int lx_interrupt_request_new_buff
const unsigned int is_capture = lx_stream->is_capture;
int err;
- const u32 channels = substream->runtime->channels;
- const u32 bytes_per_frame = channels * 3;
- const u32 period_size = substream->runtime->period_size;
- const u32 period_bytes = period_size * bytes_per_frame;
+ const u32 period_bytes = snd_pcm_lib_period_bytes(substream);
const u32 pos = lx_stream->frame_pos;
const u32 next_pos = ((pos+1) == substream->runtime->periods) ?
0 : pos + 1;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 255/438] ALSA: pcm: wake linked drain waiters on unlink
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (253 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 254/438] ALSA: lx6464es: fix period byte count for 16-bit streams Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 256/438] ALSA: seq: Fix division by zero in initialize_timer() Greg Kroah-Hartman
` (196 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
commit f495b6c4c8594122918552c9be2b51eb71647cd9 upstream.
snd_pcm_drain() on a linked stream parks an on-stack wait entry on the
drained peer's runtime->sleep, and after schedule_timeout() removes it
only if that peer is still found in the caller's group. If group
membership changes during the wait and the sleep ends by signal or
timeout (so autoremove_wake_function() does not run), finish_wait() is
skipped and snd_pcm_drain() returns with the entry still queued on that
stream's sleep list; a later wake_up() then walks a freed stack frame.
This is reachable by unlinking either the drained or the draining stream.
Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()),
snd_pcm_unlink() never wakes the sleep queues. Wake every group member
under the group lock before the membership change, so a linked drainer is
released and drops its entry while the streams are still grouped.
The window was opened when snd_pcm_link_rwsem stopped being held across
the wait and the removal became conditional on group membership (see
Fixes). The later switch to finish_wait() kept that conditional removal,
so the signal/timeout case remained.
Fixes: f57f3df03a8e ("ALSA: pcm: More fine-grained PCM link locking")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/A0705100-D10B-4286-9980-0142ABEEAD51@doyensec.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/pcm_native.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/sound/core/pcm_native.c
+++ b/sound/core/pcm_native.c
@@ -2357,6 +2357,7 @@ static void relink_to_local(struct snd_p
static int snd_pcm_unlink(struct snd_pcm_substream *substream)
{
+ struct snd_pcm_substream *s;
struct snd_pcm_group *group;
bool nonatomic = substream->pcm->nonatomic;
bool do_free = false;
@@ -2369,6 +2370,12 @@ static int snd_pcm_unlink(struct snd_pcm
group = substream->group;
snd_pcm_group_lock_irq(group, nonatomic);
+ /* release drain waiters before changing membership, else snd_pcm_drain()
+ * leaves its on-stack wait entry queued on a member's sleep list
+ */
+ snd_pcm_group_for_each_entry(s, substream)
+ wake_up(&s->runtime->sleep);
+
relink_to_local(substream);
refcount_dec(&group->refs);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 256/438] ALSA: seq: Fix division by zero in initialize_timer()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (254 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 255/438] ALSA: pcm: wake linked drain waiters on unlink Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 257/438] ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes Greg Kroah-Hartman
` (195 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
commit 21e19688433452dfbbbe6b2bb670dea6eb92f0f6 upstream.
A userspace-driven ALSA timer (SND_UTIMER) lets an unprivileged user set
the backing snd_timer's hardware resolution to an arbitrary 64-bit value
via SNDRV_TIMER_IOCTL_CREATE. snd_utimer_create() only rejects zero.
When such a timer is bound to a sequencer queue, initialize_timer()
computes the tick period as
tmr->ticks = 1000000000 / (r * freq);
where r is that user-controlled resolution and freq is the sequencer
update rate in Hz, clamped to MIN_FREQUENCY..MAX_FREQUENCY (10..6250).
A resolution of 2^63 makes the 64-bit product r * freq wrap to zero for
any even freq, including DEFAULT_FREQUENCY (1000), so the division faults
with a divide-by-zero.
The division runs under tmr->lock with interrupts disabled, so the oops
leaves the spinlock held and hangs the CPU. It is reachable by an
unprivileged user with access to /dev/snd/timer and /dev/snd/seq.
Oops: divide error: 0000 [#1] SMP KASAN PTI
CPU: 7 UID: 1000 PID: 456 Comm: alsa_seq_utimer Not tainted 7.2.0-rc4+
RIP: 0010:initialize_timer.constprop.0+0x20a/0x2d0
snd_seq_timer_start+0x15e/0x2b0
snd_seq_control_queue+0x56f/0xba0
snd_seq_write+0x3e0/0x730
Reject an overflowing product with check_mul_overflow() and fall back to
a single tick, which also avoids feeding a wrapped-but-nonzero divisor
(e.g. 2^63 * 1000 mod 2^64 == 0, or other resolutions wrapping to a small
value) into the period computation.
Fixes: 37745918e0e7 ("ALSA: timer: Introduce virtual userspace-driven timers")
Cc: <stable@vger.kernel.org>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/DF8A3844-AD5E-4B8A-9CFC-BD83C212BA38@doyensec.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/seq/seq_timer.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
--- a/sound/core/seq/seq_timer.c
+++ b/sound/core/seq/seq_timer.c
@@ -362,11 +362,10 @@ static int initialize_timer(struct snd_s
tmr->ticks = 1;
if (!(t->hw.flags & SNDRV_TIMER_HW_SLAVE)) {
unsigned long r = snd_timer_resolution(tmr->timeri);
- if (r) {
- tmr->ticks = (unsigned int)(1000000000uL / (r * freq));
- if (! tmr->ticks)
- tmr->ticks = 1;
- }
+ unsigned long den;
+
+ if (r && !check_mul_overflow(r, freq, &den))
+ tmr->ticks = max(1U, (unsigned int)(1000000000uL / den));
}
tmr->initialized = 1;
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 257/438] ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (255 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 256/438] ALSA: seq: Fix division by zero in initialize_timer() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 258/438] ALSA: ump: fix double free of out_cvts on rawmidi error Greg Kroah-Hartman
` (194 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
commit c2744d5f3aea474513fd2298daecb94a952ce441 upstream.
snd_timer_close_locked() marks an instance with SNDRV_TIMER_IFLG_DEAD
and returns early when the flag is already set, but the flag is never
cleared again. A completed close ends in remove_slave_links(), which
leaves timeri->timer NULL, so a second close is already harmless through
the timer == NULL path; the early return can only be reached by an
instance that was opened again in between. For such an instance the
close unlinks nothing, so snd_timer_instance_free() frees an object that
is still on timer->open_list_head, still on snd_timer_master_list if it
was opened with a slave key, still owns any adopted slaves, and still
holds its timer and module references.
snd_seq_timer_open() reopens an instance exactly like that: it retries
its fallback open on the same object after a failure that has already
run snd_timer_close_locked() internally. An unprivileged user with
access to /dev/snd/timer and /dev/snd/seq can force that failure, since
snd_timer_check_master() returns -EBUSY when a pending slave matches the
new master's (slave_class, slave_id) key and the target timer has
reached max_instances, and SNDRV_TIMER_IOCTL_SELECT with dev_class =
SNDRV_TIMER_CLASS_SLAVE keeps the caller-supplied dev_sclass, so a
sequencer queue's key can be forged. The freed instance is afterwards
dereferenced by any further snd_timer_open() on that timer, by
snd_timer_check_slave(), and by /proc/asound/timers, which faults on the
stale ti->owner pointer.
The flag only has to be visible while the close is in progress, which is
all its other users need. Clear it in remove_slave_links(), under the
same timer->lock that sets it, once the instance is off every list.
Fixes: da3039e91d1f ("ALSA: timer: Forcibly close timer instances at closing")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/CA41AA48-75BF-45E9-A36D-3A5D2F124F60@doyensec.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/timer.c | 2 ++
1 file changed, 2 insertions(+)
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -417,6 +417,8 @@ static void remove_slave_links(struct sn
list_del_init(&slave->ack_list);
list_del_init(&slave->active_list);
}
+ /* the close is done; a reopen must not see the mark */
+ timeri->flags &= ~SNDRV_TIMER_IFLG_DEAD;
}
/*
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 258/438] ALSA: ump: fix double free of out_cvts on rawmidi error
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (256 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 257/438] ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 259/438] ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return Greg Kroah-Hartman
` (193 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Federico Kirschbaum, Baul Lee,
Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baul Lee <baul.lee@xbow.com>
commit 70c977815af0d997feb2d0c5d284d55689bf7051 upstream.
snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array
ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with
kfree() but leaves ump->out_cvts pointing at the freed memory. When the
endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts
a second time, resulting in a double free.
The host snd-usb-audio driver attaches the legacy rawmidi for any USB
MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail
reaches this path on enumeration.
Clear ump->out_cvts after freeing it on the error path so it is not
freed again during teardown.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Fixes: 33cd7630782d ("ALSA: ump: Export MIDI1 / UMP conversion helpers")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260726051633.41206-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/ump.c | 1 +
1 file changed, 1 insertion(+)
--- a/sound/core/ump.c
+++ b/sound/core/ump.c
@@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct
&rmidi);
if (err < 0) {
kfree(ump->out_cvts);
+ ump->out_cvts = NULL;
return err;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 259/438] ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (257 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 258/438] ALSA: ump: fix double free of out_cvts on rawmidi error Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 260/438] ASoC: fsl_easrc: " Greg Kroah-Hartman
` (192 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengjiu Wang, Mark Brown
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengjiu Wang <shengjiu.wang@nxp.com>
commit 890b4253134f3a39883af7d5bea67af9c494c56d upstream.
When fsl_asrc_m2m_init() fails in fsl_asrc_probe(), the code did a
bare return ret, bypassing pm_runtime_disable() in err_pm_get_sync.
Use goto err_pm_get_sync to ensure proper cleanup on failure.
Fixes: 286d658477a4 ("ASoC: fsl_asrc: register m2m platform device")
Cc: stable@vger.kernel.org
Signed-off-by: Shengjiu Wang <shengjiu.wang@nxp.com>
Link: https://patch.msgid.link/20260715024758.1252801-2-shengjiu.wang@oss.nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/fsl/fsl_asrc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/sound/soc/fsl/fsl_asrc.c
+++ b/sound/soc/fsl/fsl_asrc.c
@@ -1419,7 +1419,7 @@ static int fsl_asrc_probe(struct platfor
ret = fsl_asrc_m2m_init(asrc);
if (ret) {
dev_err(&pdev->dev, "failed to init m2m device %d\n", ret);
- return ret;
+ goto err_pm_get_sync;
}
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 260/438] ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (258 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 259/438] ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 261/438] ASoC: tas2562: fix DVC coefficient write order Greg Kroah-Hartman
` (191 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengjiu Wang, Mark Brown
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengjiu Wang <shengjiu.wang@nxp.com>
commit a54bc0eef90ea760039c14bb7f3b5db42529f84d upstream.
When fsl_asrc_m2m_init() fails in fsl_easrc_probe(), the code did a
bare return ret, bypassing pm_runtime_disable() in err_pm_disable.
Use goto err_pm_disable to ensure proper cleanup on failure.
Fixes: b62eaff0650d ("ASoC: fsl_easrc: register m2m platform device")
Cc: stable@vger.kernel.org
Signed-off-by: Shengjiu Wang <shengjiu.wang@nxp.com>
Link: https://patch.msgid.link/20260715024758.1252801-3-shengjiu.wang@oss.nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/fsl/fsl_easrc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/sound/soc/fsl/fsl_easrc.c
+++ b/sound/soc/fsl/fsl_easrc.c
@@ -2269,7 +2269,7 @@ static int fsl_easrc_probe(struct platfo
ret = fsl_asrc_m2m_init(easrc);
if (ret) {
dev_err(&pdev->dev, "failed to init m2m device %d\n", ret);
- return ret;
+ goto err_pm_disable;
}
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 261/438] ASoC: tas2562: fix DVC coefficient write order
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (259 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 260/438] ASoC: fsl_easrc: " Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 262/438] ASoC: tas2562: fix broken entries in the volume lookup table Greg Kroah-Hartman
` (190 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Haidar Lee, Mark Brown
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haidar Lee <haidar.lee@adlinktech.com>
commit 8e957e4907c58e9ca944f98799524f2bbb9cf68a upstream.
The TAS2562 applies the 32-bit digital volume coefficient to the
playback path when the last byte, DVC_CFG4 (book 0 page 2 reg 0x0F), is
written. tas2562_volume_control_put() wrote DVC_CFG4 first and DVC_CFG1
(the MSB) last, so every volume change latched a value made of the
previous coefficient's upper three bytes combined with the new LSB; the
remaining bytes only took effect on the next volume change.
In practice the control was unusable: the first setting after power-on
always played at roughly 0 dB no matter what value was requested (the
chip's default upper bytes were still latched), and most subsequent
changes muted the output entirely or produced a distorted, over-unity
gain.
Verified on a TAS2562 (ADLINK OSM-520 / MT8189 board) by tracing the
I2C writes with ftrace and by writing the same coefficients manually in
both byte orders: written MSB-first the register block behaves exactly
as the driver expects, LSB-first reproduces the broken behaviour.
Write the bytes MSB first with DVC_CFG4 last so the complete new
coefficient is latched atomically.
Fixes: bf726b1c86f2 ("ASoC: tas2562: Add support for digital volume control")
Cc: stable@vger.kernel.org
Signed-off-by: Haidar Lee <haidar.lee@adlinktech.com>
Link: https://patch.msgid.link/20260715-tas2562-dvc-fix-v1-1-072b13901b20@adlinktech.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/codecs/tas2562.c | 23 +++++++++++++++--------
1 file changed, 15 insertions(+), 8 deletions(-)
--- a/sound/soc/codecs/tas2562.c
+++ b/sound/soc/codecs/tas2562.c
@@ -475,20 +475,27 @@ static int tas2562_volume_control_put(st
u32 reg_val;
reg_val = float_vol_db_lookup[ucontrol->value.integer.value[0]/2];
- ret = snd_soc_component_write(component, TAS2562_DVC_CFG4,
- (reg_val & 0xff));
- if (ret)
- return ret;
- ret = snd_soc_component_write(component, TAS2562_DVC_CFG3,
- ((reg_val >> 8) & 0xff));
+ /*
+ * The device applies the 32-bit coefficient to the playback path on
+ * the write to DVC_CFG4 (the LSB, book 0 page 2 reg 0x0F), so the
+ * bytes must be written MSB first and DVC_CFG4 last. Writing CFG4
+ * first latches a mix of the previous coefficient's upper bytes and
+ * the new LSB instead of the requested value.
+ */
+ ret = snd_soc_component_write(component, TAS2562_DVC_CFG1,
+ ((reg_val >> 24) & 0xff));
if (ret)
return ret;
ret = snd_soc_component_write(component, TAS2562_DVC_CFG2,
((reg_val >> 16) & 0xff));
if (ret)
return ret;
- ret = snd_soc_component_write(component, TAS2562_DVC_CFG1,
- ((reg_val >> 24) & 0xff));
+ ret = snd_soc_component_write(component, TAS2562_DVC_CFG3,
+ ((reg_val >> 8) & 0xff));
+ if (ret)
+ return ret;
+ ret = snd_soc_component_write(component, TAS2562_DVC_CFG4,
+ (reg_val & 0xff));
if (ret)
return ret;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 262/438] ASoC: tas2562: fix broken entries in the volume lookup table
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (260 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 261/438] ASoC: tas2562: fix DVC coefficient write order Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 263/438] ata: libata-eh: Increase STANDBY IMMEDIATE timeout Greg Kroah-Hartman
` (189 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Haidar Lee, Mark Brown
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haidar Lee <haidar.lee@adlinktech.com>
commit bdb0fd6de403fcea7b85dc9d38f0a571583ebe80 upstream.
The float_vol_db_lookup table is supposed to hold
round(10^(dB/20) * 2^30) for every 2 dB step from -110 dB to 0 dB,
which is 56 entries, but it only has 55: the -90 dB entry duplicates
the -92 dB value (0x0000695b) and the -20 dB entry (0x06666666) is
missing altogether. As a result every step between -90 dB and -22 dB
is off by 2 dB, and the control's maximum raw value of 110 indexes one
element past the end of the array.
Replace the duplicated -90 dB entry with the correct value 0x000084a3
and add the missing -20 dB entry, bringing the table to the full 56
entries so index 55 (raw value 110, 0 dB) is in range again.
Fixes: bf726b1c86f2 ("ASoC: tas2562: Add support for digital volume control")
Cc: stable@vger.kernel.org
Signed-off-by: Haidar Lee <haidar.lee@adlinktech.com>
Link: https://patch.msgid.link/20260715-tas2562-dvc-fix-v1-2-072b13901b20@adlinktech.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/codecs/tas2562.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/sound/soc/codecs/tas2562.c
+++ b/sound/soc/codecs/tas2562.c
@@ -32,15 +32,16 @@
static const unsigned int float_vol_db_lookup[] = {
0x00000d43, 0x000010b2, 0x00001505, 0x00001a67, 0x00002151,
0x000029f1, 0x000034cd, 0x00004279, 0x000053af, 0x0000695b,
-0x0000695b, 0x0000a6fa, 0x0000d236, 0x000108a4, 0x00014d2a,
+0x000084a3, 0x0000a6fa, 0x0000d236, 0x000108a4, 0x00014d2a,
0x0001a36e, 0x00021008, 0x000298c0, 0x000344df, 0x00041d8f,
0x00052e5a, 0x000685c8, 0x00083621, 0x000a566d, 0x000d03a7,
0x0010624d, 0x0014a050, 0x0019f786, 0x0020b0bc, 0x0029279d,
0x0033cf8d, 0x004139d3, 0x00521d50, 0x00676044, 0x0082248a,
0x00a3d70a, 0x00ce4328, 0x0103ab3d, 0x0146e75d, 0x019b8c27,
0x02061b89, 0x028c423f, 0x03352529, 0x0409c2b0, 0x05156d68,
-0x080e9f96, 0x0a24b062, 0x0cc509ab, 0x10137987, 0x143d1362,
-0x197a967f, 0x2013739e, 0x28619ae9, 0x32d64617, 0x40000000
+0x06666666, 0x080e9f96, 0x0a24b062, 0x0cc509ab, 0x10137987,
+0x143d1362, 0x197a967f, 0x2013739e, 0x28619ae9, 0x32d64617,
+0x40000000
};
struct tas2562_data {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 263/438] ata: libata-eh: Increase STANDBY IMMEDIATE timeout
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (261 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 262/438] ASoC: tas2562: fix broken entries in the volume lookup table Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 264/438] ata: libata-sata: fix ata_scsi_lpm_supported() iteration Greg Kroah-Hartman
` (188 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Matt Vollrath, Damien Le Moal
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matt Vollrath <tactii@gmail.com>
commit 1e024d2b41ee32bc06818f7f09a3562c58842cf9 upstream.
Correct a previous change (see Fixes) which reduced the standby timeout
from 30 to 5 seconds. Increase it to 15 seconds.
I was troubleshooting an error spotted during system suspend:
[ 1217.152867] ata1.00: Entering standby power mode
[ 1222.322948] ata1.00: qc timeout after 5000 msecs (cmd 0xe0)
[ 1222.324010] ata1.00: STANDBY IMMEDIATE failed (err_mask=0x4)
This drive is a Samsung 870 EVO SSD in good SMART standing, and I wasn't
aware of any reason it should be taking so long to standby. The issue is
intermittent, but I observed it sometimes taking 7 seconds to manually
standby. I assume this was interruption of background maintenance after
a power outage.
As a desktop user, I would prefer to wait the extra 2 seconds at suspend
to let the drive finish its business rather than drop the rails from
under it.
The change from 30 to 5 seconds was implicit when switching suspend
from START STOP UNIT to an internal command with no timeout table entry.
No reason was stated for the change.
Fixes: aa3998dbeb3a ("ata: libata-scsi: Disable scsi device manage_system_start_stop")
Cc: stable@vger.kernel.org
Signed-off-by: Matt Vollrath <tactii@gmail.com>
Assisted-by: Claude:claude-5-fable
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libata-eh.c | 8 ++++++++
include/linux/libata.h | 2 +-
2 files changed, 9 insertions(+), 1 deletion(-)
--- a/drivers/ata/libata-eh.c
+++ b/drivers/ata/libata-eh.c
@@ -106,6 +106,12 @@ static const unsigned int ata_eh_flush_t
UINT_MAX,
};
+static const unsigned int ata_eh_standby_timeouts[] = {
+ 15000, /* Some drives may be slow to standby */
+ /* but don't hold up a suspend too long waiting for them */
+ UINT_MAX,
+};
+
static const unsigned int ata_eh_other_timeouts[] = {
5000, /* same rationale as identify timeout */
10000, /* ditto */
@@ -147,6 +153,8 @@ ata_eh_cmd_timeout_table[ATA_EH_CMD_TIME
.timeouts = ata_eh_other_timeouts, },
{ .commands = CMDS(ATA_CMD_FLUSH, ATA_CMD_FLUSH_EXT),
.timeouts = ata_eh_flush_timeouts },
+ { .commands = CMDS(ATA_CMD_STANDBYNOW1),
+ .timeouts = ata_eh_standby_timeouts },
{ .commands = CMDS(ATA_CMD_VERIFY),
.timeouts = ata_eh_reset_timeouts },
};
--- a/include/linux/libata.h
+++ b/include/linux/libata.h
@@ -425,7 +425,7 @@ enum {
/* This should match the actual table size of
* ata_eh_cmd_timeout_table in libata-eh.c.
*/
- ATA_EH_CMD_TIMEOUT_TABLE_SIZE = 8,
+ ATA_EH_CMD_TIMEOUT_TABLE_SIZE = 9,
/* User visible DMA mask for DMA control. DO NOT renumber. */
ATA_DMA_MASK_ATA = (1 << 0), /* DMA on ATA Disk */
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 264/438] ata: libata-sata: fix ata_scsi_lpm_supported() iteration
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (262 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 263/438] ata: libata-eh: Increase STANDBY IMMEDIATE timeout Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 265/438] ata: libata-scsi: terminate deferred commands on time out Greg Kroah-Hartman
` (187 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Niklas Cassel,
Damien Le Moal
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Cassel <cassel@kernel.org>
commit 3fd70e96914d761c17c376aadd0b0d1a3c9badba upstream.
The inner loop of ata_scsi_lpm_supported() uses the wrong variable when
iterating.
It should obviously use the link that we are currently iterating over,
rather than always using the host link.
ata_scsi_lpm_supported() is used to control if a user should be allowed
to change lpm policy (from the default) via sysfs.
Thus, this bug could potentially disallow users to change the LPM policy
for certain SATA devices via sysfs.
Cc: stable@vger.kernel.org
Fixes: 0060beec0bfa ("ata: libata-sata: Add link_power_management_supported sysfs attribute")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/linux-ide/20260728112200.B99F21F000E9@smtp.kernel.org/
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libata-sata.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/ata/libata-sata.c
+++ b/drivers/ata/libata-sata.c
@@ -913,7 +913,7 @@ static bool ata_scsi_lpm_supported(struc
return false;
ata_for_each_link(link, ap, EDGE) {
- ata_for_each_dev(dev, &ap->link, ENABLED) {
+ ata_for_each_dev(dev, link, ENABLED) {
if (dev->quirks & ATA_QUIRK_NOLPM)
return false;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 265/438] ata: libata-scsi: terminate deferred commands on time out
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (263 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 264/438] ata: libata-sata: fix ata_scsi_lpm_supported() iteration Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 266/438] ata: libata-scsi: schedule deferred atapi command Greg Kroah-Hartman
` (186 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Igor Pylypiv,
Niklas Cassel, Martin K. Petersen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damien Le Moal <dlemoal@kernel.org>
commit 2e1d2e65e773d67dab163127f11a47dab0fbca9f upstream.
If a command times out while we have deferred non-NCQ commands waiting to
be issued, the SCSI EH task is not immediately woken up as the waiting
deferred commands are never issued nor completed, thus leaving the SCSI
host in a busy state (shost->host_failed != scsi_host_busy(shost)) which
prevents the SCSI EH task from being woken up. Eventually, when the
deferred commands also time out, the SCSI EH task is woken up and the
timeout processing occurs.
Avoid this unnecessary SCSI EH task wake-up additional time by scheduling
a retry of all waiting deferred QCs, using the eh_timed_out SCSI host
template operation. The function ata_scsi_eh_timed_out() is introduced to
implement this operation.
However, terminating deferred commands with DID_REQUEUE to force a retry
by calling the function ata_scsi_requeue_deferred_qc() may still keep the
SCSI host in a busy state because the block layer may immediately re-issue
these commands. The solution to this is to schedule libata EH for the
port which suffered the command timeout to prevent accepting any new
command. ata_scsi_requeue_deferred_qc() is modified to add a call to
ata_port_schedule_eh() for this purpose.
In addition to this change, ata_scsi_requeue_deferred_qc() is also
modified to take a new timedout_scmd scsi command argument which indicates
the SCSI command that timed out. With this additional argument,
ata_scsi_requeue_deferred_qc() can now also terminate with DID_TIME_OUT
any timed out deferred qc, which simplifies ata_scsi_cmd_error_handler().
In this case, ata_scsi_requeue_deferred_qc() returns SCSI_EH_DONE, with
this return value propagated back to the ata_scsi_eh_timed_out() operation
to indicate to scsi_timeout() that the timed out command was handled and
no further processing is needed.
For non-timed out deferred qc that need to be retried,
ata_scsi_requeue_deferred_qc() returns SCSI_EH_NOT_HANDLED, thus
indicating to scsi_timeout() that the timed out command needs to go
through the SCSI EH (and libata EH) processing by adding it to the EH work
queue with scsi_eh_scmd_add().
One side effect of these changes is that the function atapi_qc_complete()
needs to be modified to ensure that a deferred ATAPI command that needs
to be retried is completed with DID_REQUEUE instead of the default
SAM_STAT_GOOD status, and a command that timed out is completed with
DID_TIME_OUT instead of SAM_STAT_CHECK_CONDITION.
Fixes: 0ea84089dbf6 ("ata: libata-scsi: avoid Non-NCQ command starvation")
Cc: stable@vger.kernel.org
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Igor Pylypiv <ipylypiv@google.com>
Tested-by: Igor Pylypiv <ipylypiv@google.com>
Reviewed-by: Niklas Cassel <cassel@kernel.org>
Reviewed-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libata-eh.c | 29 ++---------
drivers/ata/libata-scsi.c | 112 +++++++++++++++++++++++++++++++++++++++++-----
drivers/ata/libata.h | 3 -
include/linux/libata.h | 2
4 files changed, 111 insertions(+), 35 deletions(-)
--- a/drivers/ata/libata-eh.c
+++ b/drivers/ata/libata-eh.c
@@ -656,29 +656,12 @@ int ata_scsi_cmd_error_handler(struct Sc
set_host_byte(scmd, DID_OK);
ata_qc_for_each_raw(ap, qc, i) {
- if (qc->scsicmd != scmd)
- continue;
- if ((qc->flags & ATA_QCFLAG_ACTIVE) ||
- qc == qc->dev->link->deferred_qc)
+ if (qc->scsicmd == scmd &&
+ qc->flags & ATA_QCFLAG_ACTIVE)
break;
}
- if (i < ATA_MAX_QUEUE && qc == qc->dev->link->deferred_qc) {
- /*
- * This is a deferred command that timed out while
- * waiting for the command queue to drain. Since the qc
- * is not active yet (deferred_qc is still set, so the
- * deferred qc work has not issued the command yet),
- * simply signal the timeout by finishing the SCSI
- * command and clear the deferred qc to prevent the
- * deferred qc work from issuing this qc.
- */
- WARN_ON_ONCE(qc->flags & ATA_QCFLAG_ACTIVE);
- qc->dev->link->deferred_qc = NULL;
- cancel_work(&qc->dev->link->deferred_qc_work);
- set_host_byte(scmd, DID_TIME_OUT);
- scsi_eh_finish_cmd(scmd, &ap->eh_done_q);
- } else if (i < ATA_MAX_QUEUE) {
+ if (i < ATA_MAX_QUEUE) {
/* the scmd has an associated qc */
if (!(qc->flags & ATA_QCFLAG_EH)) {
/* which hasn't failed yet, timeout */
@@ -954,10 +937,10 @@ static void ata_eh_set_pending(struct at
ap->pflags |= ATA_PFLAG_EH_PENDING;
/*
- * If we have a deferred qc, requeue it so that it is retried once EH
- * completes.
+ * If we have deferred QCs, requeue them so that the SCSI EH task can
+ * run.
*/
- ata_scsi_requeue_deferred_qc(ap);
+ ata_scsi_requeue_deferred_qc(ap, NULL);
if (!fastdrain)
return;
--- a/drivers/ata/libata-scsi.c
+++ b/drivers/ata/libata-scsi.c
@@ -1685,26 +1685,80 @@ void ata_scsi_deferred_qc_work(struct wo
spin_unlock_irqrestore(ap->lock, flags);
}
-void ata_scsi_requeue_deferred_qc(struct ata_port *ap)
+enum scsi_timeout_action ata_scsi_requeue_deferred_qc(struct ata_port *ap,
+ struct scsi_cmnd *timedout_scmd)
{
+ enum scsi_timeout_action action = SCSI_EH_NOT_HANDLED;
+ struct ata_queued_cmd *qc;
struct ata_link *link;
+ u32 host_byte;
lockdep_assert_held(ap->lock);
/*
- * If we have a deferred qc when a reset occurs or NCQ commands fail,
- * do not try to be smart about what to do with this deferred command
- * and simply requeue it by completing it with DID_REQUEUE.
+ * If we have deferred QCs when a reset, a timeout or an NCQ command
+ * fails, do not try to be smart about what to do with the deferred
+ * commands and simply terminate them and let the SCSI layer decide
+ * what to do.
*/
ata_for_each_link(link, ap, PMP_FIRST) {
- struct ata_queued_cmd *qc = link->deferred_qc;
+ qc = link->deferred_qc;
+ if (!qc)
+ continue;
+
+ /*
+ * Clear the deferred QC so that the deferred work does not try
+ * to issue it.
+ */
+ link->deferred_qc = NULL;
+ cancel_work(&link->deferred_qc_work);
+
+ /*
+ * We are going to complete some scsi command, either with
+ * DID_TIME_OUT if the command timed out while waiting for being
+ * issued, or with DID_REQUEUE if another command timed out or
+ * we had a failed command. However, the block layer may re-issue
+ * these commands immediately, keeping the scsi host busy and
+ * thus preventing the SCSI EH task from running.
+ * So schedule EH on the port to prevent accepting new commands
+ * until everything is sorted out with the error or timeout that
+ * got us here in the first place. Note that we set EH pending
+ * on the port before calling ata_port_schedule_eh() so that we
+ * do not reenter this function from ata_eh_set_pending() with
+ * timedout_scmd being NULL and erroneously retry deferred QCs
+ * that have timed out on other links.
+ */
+ if (!ata_port_eh_scheduled(ap)) {
+ ap->pflags |= ATA_PFLAG_EH_PENDING;
+ ata_port_schedule_eh(ap);
+ }
- if (qc) {
- link->deferred_qc = NULL;
- cancel_work(&link->deferred_qc_work);
- ata_scsi_qc_done(qc, true, DID_REQUEUE << 16);
+ /*
+ * If we are being called from scsi_timeout(), then we have a
+ * non-NULL timedout_scmd. If the timed out command is for a
+ * deferred QC, terminate that deferred QC with DID_TIME_OUT and
+ * requeue all other deferred QCs. In this case we need to
+ * return SCSI_EH_DONE, because the timed out command was
+ * handled.
+ * If the timed out command is not for a deferred QC, we need to
+ * requeue all deferred QCs, and return SCSI_EH_NOT_HANDLED so
+ * that the timed out command gets added to the EH work queue
+ * with scsi_eh_scmd_add(), for later handling with libata EH
+ * ata_scsi_cmd_error_handler().
+ * If timedout_scmd is NULL, we simply need to requeue all
+ * deferred QCs and the return value does not matter as we were
+ * not called from scsi_timeout().
+ */
+ if (timedout_scmd && qc->scsicmd == timedout_scmd) {
+ host_byte = DID_TIME_OUT;
+ action = SCSI_EH_DONE;
+ } else {
+ host_byte = DID_REQUEUE;
}
+ ata_scsi_qc_done(qc, true, host_byte << 16);
}
+
+ return action;
}
static void ata_scsi_schedule_deferred_qc(struct ata_link *link)
@@ -1723,13 +1777,41 @@ static void ata_scsi_schedule_deferred_q
return;
if (ata_port_eh_scheduled(ap)) {
- ata_scsi_requeue_deferred_qc(ap);
+ ata_scsi_requeue_deferred_qc(ap, NULL);
return;
}
if (!ap->ops->qc_defer(qc))
queue_work(system_highpri_wq, &link->deferred_qc_work);
}
+static enum scsi_timeout_action
+ata_scsi_retry_deferred_qc(struct ata_port *ap, struct scsi_cmnd *scmd)
+{
+ enum scsi_timeout_action action;
+ unsigned long flags;
+
+ spin_lock_irqsave(ap->lock, flags);
+ action = ata_scsi_requeue_deferred_qc(ap, scmd);
+ spin_unlock_irqrestore(ap->lock, flags);
+
+ return action;
+}
+
+enum scsi_timeout_action ata_scsi_eh_timed_out(struct scsi_cmnd *scmd)
+{
+ struct ata_port *ap = ata_shost_to_port(scmd->device->host);
+
+ /*
+ * ata_scsi_cmd_error_handler() takes care of commands that timed out
+ * while executing. However, if we have deferred QCs while a timeout
+ * triggers, we must requeue these commands for retry so that we do not
+ * unnecessarily delay starting the SCSI EH task until these deferred
+ * commands also time out.
+ */
+ return ata_scsi_retry_deferred_qc(ap, scmd);
+}
+EXPORT_SYMBOL_GPL(ata_scsi_eh_timed_out);
+
static void ata_scsi_qc_complete(struct ata_queued_cmd *qc)
{
struct ata_link *link = qc->dev->link;
@@ -2934,7 +3016,15 @@ static void atapi_qc_complete(struct ata
if (qc->cdb[0] == ALLOW_MEDIUM_REMOVAL && qc->dev->sdev)
qc->dev->sdev->locked = 0;
- ata_scsi_qc_done(qc, true, SAM_STAT_CHECK_CONDITION);
+ if (cmd->result)
+ ata_scsi_qc_done(qc, false, 0);
+ else
+ ata_scsi_qc_done(qc, true, SAM_STAT_CHECK_CONDITION);
+ return;
+ }
+
+ if (cmd->result) {
+ ata_scsi_qc_done(qc, false, 0);
return;
}
--- a/drivers/ata/libata.h
+++ b/drivers/ata/libata.h
@@ -177,7 +177,8 @@ int ata_scsi_dev_config(struct scsi_devi
enum scsi_qc_status __ata_scsi_queuecmd(struct scsi_cmnd *scmd,
struct ata_device *dev);
void ata_scsi_deferred_qc_work(struct work_struct *work);
-void ata_scsi_requeue_deferred_qc(struct ata_port *ap);
+enum scsi_timeout_action ata_scsi_requeue_deferred_qc(struct ata_port *ap,
+ struct scsi_cmnd *scmd);
/* libata-eh.c */
extern unsigned int ata_internal_cmd_timeout(struct ata_device *dev, u8 cmd);
--- a/include/linux/libata.h
+++ b/include/linux/libata.h
@@ -1152,6 +1152,7 @@ extern int ata_scsi_ioctl(struct scsi_de
#endif
extern enum scsi_qc_status ata_scsi_queuecmd(struct Scsi_Host *h,
struct scsi_cmnd *cmd);
+enum scsi_timeout_action ata_scsi_eh_timed_out(struct scsi_cmnd *cmd);
#if IS_REACHABLE(CONFIG_ATA)
bool ata_scsi_dma_need_drain(struct request *rq);
#else
@@ -1461,6 +1462,7 @@ extern const struct attribute_group *ata
.ioctl = ata_scsi_ioctl, \
ATA_SCSI_COMPAT_IOCTL \
.queuecommand = ata_scsi_queuecmd, \
+ .eh_timed_out = ata_scsi_eh_timed_out, \
.dma_need_drain = ata_scsi_dma_need_drain, \
.this_id = ATA_SHT_THIS_ID, \
.emulated = ATA_SHT_EMULATED, \
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 266/438] ata: libata-scsi: schedule deferred atapi command
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (264 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 265/438] ata: libata-scsi: terminate deferred commands on time out Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 267/438] ALSA: usb-audio: fix use-after-free in ump_to_endpoint() Greg Kroah-Hartman
` (185 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Damien Le Moal
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damien Le Moal <dlemoal@kernel.org>
commit e7468b3f9b404ac7c1329ef07c146c3356dfbd01 upstream.
Modify atapi_qc_complete() to call ata_scsi_schedule_deferred_qc() to
ensure that any deferred queued command can execute. This is similar to
ata_scsi_qc_complete() function for regular ATA devices.
Fixes: 0ea84089dbf6 ("ata: libata-scsi: avoid Non-NCQ command starvation")
Cc: stable@vger.kernel.org
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libata-scsi.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/ata/libata-scsi.c
+++ b/drivers/ata/libata-scsi.c
@@ -2991,6 +2991,7 @@ static void atapi_fixup_inquiry(struct s
static void atapi_qc_complete(struct ata_queued_cmd *qc)
{
+ struct ata_link *link = qc->dev->link;
struct scsi_cmnd *cmd = qc->scsicmd;
unsigned int err_mask = qc->err_mask;
@@ -3020,12 +3021,12 @@ static void atapi_qc_complete(struct ata
ata_scsi_qc_done(qc, false, 0);
else
ata_scsi_qc_done(qc, true, SAM_STAT_CHECK_CONDITION);
- return;
+ goto schedule_deferred;
}
if (cmd->result) {
ata_scsi_qc_done(qc, false, 0);
- return;
+ goto schedule_deferred;
}
/* successful completion path */
@@ -3033,6 +3034,9 @@ static void atapi_qc_complete(struct ata
atapi_fixup_inquiry(cmd);
ata_scsi_qc_done(qc, true, SAM_STAT_GOOD);
+
+schedule_deferred:
+ ata_scsi_schedule_deferred_qc(link);
}
/**
* atapi_xlat - Initialize PACKET taskfile
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 267/438] ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (265 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 266/438] ata: libata-scsi: schedule deferred atapi command Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 268/438] ALSA: usb-audio: fix stack info leak in RME Digiface status Greg Kroah-Hartman
` (184 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Federico Kirschbaum, Baul Lee,
Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baul Lee <baul.lee@xbow.com>
commit 4a05b2d1b4642df74f30b6f54843e825c4a2bfd3 upstream.
create_midi2_ump() registers a card-owned snd_ump_endpoint and stores a
back-pointer to its per-interface snd_usb_midi2_ump object in
ump->private_data, but it never installs an ump->private_free hook and
never clears that pointer.
If a later step of snd_usb_midi_v2_create() fails, its error path calls
free_all_midi2_umps(), which kfree()s the snd_usb_midi2_ump object while
the already-registered endpoint keeps pointing at it. The created
/dev/snd/umpC*D* node stays exposed, so the first operation of any UMP
open, ump_to_endpoint(), dereferences the dangling ump->private_data and
reads rmidi->eps[dir] out of freed memory.
A malicious USB MIDI 2.0 device that makes creation fail after the
endpoint is registered can thus trigger a slab use-after-free read on a
subsequent open of the UMP node.
Clear the endpoint's back-pointer before freeing the object, and let
ump_to_endpoint() tolerate a NULL private_data so the open/close/trigger
callbacks fail cleanly (their callers already handle a NULL endpoint)
instead of dereferencing a stale pointer.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Fixes: ff49d1df79ae ("ALSA: usb-audio: USB MIDI 2.0 UMP support")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260726051337.41124-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/midi2.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/sound/usb/midi2.c
+++ b/sound/usb/midi2.c
@@ -329,7 +329,7 @@ ump_to_endpoint(struct snd_ump_endpoint
{
struct snd_usb_midi2_ump *rmidi = ump->private_data;
- return rmidi->eps[dir];
+ return rmidi ? rmidi->eps[dir] : NULL;
}
/* ump open callback */
@@ -685,6 +685,8 @@ static void free_all_midi2_umps(struct s
rmidi = list_first_entry(&umidi->rawmidi_list,
struct snd_usb_midi2_ump, list);
list_del(&rmidi->list);
+ if (rmidi->ump)
+ rmidi->ump->private_data = NULL;
kfree(rmidi);
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 268/438] ALSA: usb-audio: fix stack info leak in RME Digiface status
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (266 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 267/438] ALSA: usb-audio: fix use-after-free in ump_to_endpoint() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 269/438] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() Greg Kroah-Hartman
` (183 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Federico Kirschbaum, Baul Lee,
Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baul Lee <baul.lee@xbow.com>
commit 441aaad150c57edaf57ee482a79a3bf4c5b7e353 upstream.
snd_rme_digiface_read_status() reads a four-word status block from the
device into an uninitialised on-stack __le32 buf[4] and, whenever the
vendor control-IN transfer does not return a negative error, copies all
four words into the caller's status[].
snd_usb_ctl_msg() copies the full requested size back into the caller's
buffer regardless of how many bytes the data stage actually delivered:
buf = kmemdup(data, size, GFP_KERNEL);
err = usb_control_msg(dev, pipe, request, requesttype,
value, index, buf, size, timeout);
memcpy(data, buf, size);
usb_control_msg() returns the transferred length on a short control-IN,
which is a non-negative value, and writes only that many bytes. The
remainder of the copy back is the kmemdup()ed image of the caller's
buffer, so a device answering with a short data stage leaves the
trailing words of buf[] holding leftover kernel stack. The only guard
in the caller is err < 0, so those words are stored into status[].
They then reach user space: snd_rme_digiface_get_status_val() selects a
16-bit halfword of status[] per the control's reg/mask, and the eight
Digiface status controls together expose the whole 16-byte frame to an
unprivileged reader of /dev/snd/controlC*.
Zero-initialise the buffer so a short read yields zeros instead of stack
residue. This mirrors snd_rme_get_status1(), which already clears its
output word before the same kind of vendor read.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Fixes: 611a96f6acf2 ("ALSA: usb-audio: Add mixer quirk for RME Digiface USB")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260726065020.46070-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/mixer_quirks.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/sound/usb/mixer_quirks.c
+++ b/sound/usb/mixer_quirks.c
@@ -3454,7 +3454,7 @@ static int snd_rme_digiface_read_status(
struct usb_mixer_elem_list *list = snd_kcontrol_chip(kcontrol);
struct snd_usb_audio *chip = list->mixer->chip;
struct usb_device *dev = chip->dev;
- __le32 buf[4];
+ __le32 buf[4] = {};
int err;
err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0),
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 269/438] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (267 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 268/438] ALSA: usb-audio: fix stack info leak in RME Digiface status Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 270/438] ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set Greg Kroah-Hartman
` (182 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Federico Kirschbaum,
Baul Lee
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baul Lee <baul.lee@xbow.com>
commit 0970274613fb463d376211450cab066d34ebfe6a upstream.
snd_usbmidi_akai_output() computes its fill-loop bound
buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
as a signed int, so a small device-advertised bulk-OUT max_transfer
makes buf_end negative. The loop guard then compares the u32
urb->transfer_buffer_length against that negative int: the usual
arithmetic conversion turns buf_end into a large unsigned value, so the
guard stays true and each iteration keeps appending SysEx framing and
payload bytes past the end of the URB transfer buffer, which is only
max_transfer bytes long.
A USB device that advertises a tiny bulk-OUT endpoint can therefore
trigger an attacker-length- and content-controlled heap out-of-bounds
write when a process writes to the created /dev/snd/midiC*D* node.
Return early when there is no room for even one SysEx, so the loop is
never entered with a bound that would wrap. The loop is the last
statement of the function, so bailing out is equivalent to it not
running.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Fixes: 4434ade8c933 ("ALSA: usb-audio: add support for Akai MPD16")
Suggested-by: Takashi Iwai <tiwai@suse.de>
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260726074500.50145-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/midi.c | 2 ++
1 file changed, 2 insertions(+)
--- a/sound/usb/midi.c
+++ b/sound/usb/midi.c
@@ -797,6 +797,8 @@ static void snd_usbmidi_akai_output(stru
msg = urb->transfer_buffer + urb->transfer_buffer_length;
buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
+ if (buf_end <= 0)
+ return;
/* only try adding more data when there's space for at least 1 SysEx */
while (urb->transfer_buffer_length < buf_end) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 270/438] ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (268 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 269/438] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 271/438] ALSA: usb-audio: Clamp frame size in implicit-feedback mode Greg Kroah-Hartman
` (181 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sonali Pradhan, Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sonali Pradhan <sonalipradhan@google.com>
commit d0199ae1666ff9ae2d1d568d64c3430d4c47f0e5 upstream.
When a USB audio endpoint requests full packet transfers via the fill_max
descriptor flag, data_ep_set_params() promotes ep->curpacksize to
ep->maxpacksize. However, maxsize is left at the original sample-rate
derived value.
Since u->buffer_size is allocated as maxsize * packets, the resulting
DMA buffer is far too small for the requested transfer length. When the
USB host controller streams up to curpacksize bytes per packet, it writes
past the end of the buffer via DMA, corrupting kernel heap memory.
Update maxsize to curpacksize when fill_max is set so that the allocated
DMA buffer size matches the actual transfer request size.
[ changed to reassign maxsize only when ep->fill_max is set -- tiwai ]
Fixes: 8fdff6a319e7 ("ALSA: snd-usb: implement new endpoint streaming model")
Cc: stable@vger.kernel.org
Assisted-by: Jetski:Gemini-3.6-Flash
Signed-off-by: Sonali Pradhan <sonalipradhan@google.com>
Link: https://patch.msgid.link/20260728201716.2347726-1-sonalipradhan@google.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/endpoint.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/sound/usb/endpoint.c
+++ b/sound/usb/endpoint.c
@@ -1168,10 +1168,12 @@ static int data_ep_set_params(struct snd
<< (16 - ep->datainterval);
}
- if (ep->fill_max)
+ if (ep->fill_max) {
ep->curpacksize = ep->maxpacksize;
- else
+ maxsize = ep->curpacksize;
+ } else {
ep->curpacksize = maxsize;
+ }
if (snd_usb_get_speed(chip->dev) != USB_SPEED_FULL) {
packs_per_ms = 8 >> ep->datainterval;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 271/438] ALSA: usb-audio: Clamp frame size in implicit-feedback mode
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (269 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 270/438] ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 272/438] dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ Greg Kroah-Hartman
` (180 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sonali Pradhan, Takashi Iwai
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sonali Pradhan <sonalipradhan@google.com>
commit 8d7a30c50c2e58a6839634ed0acde14466d1dc61 upstream.
snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's
stride and stores the result directly in out_packet->packet_size[i]. If a
connected USB device sends an oversized sync packet, this frame count can
exceed ep->maxframesize.
The un-clamped frame count then propagates to the playback endpoint queue,
potentially driving packet transfers beyond the endpoint's hardware frame
limits.
Cap the calculated frame count against ep->maxframesize in
snd_usb_handle_sync_urb() to prevent oversized packets from entering the
playback queue.
Fixes: 28acb12014fb ("ALSA: usb-audio: use sender stride for implicit feedback")
Cc: stable@vger.kernel.org
Assisted-by: Jetski:Gemini-3.6-Flash
Signed-off-by: Sonali Pradhan <sonalipradhan@google.com>
Link: https://patch.msgid.link/20260728202432.2354994-1-sonalipradhan@google.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/endpoint.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
--- a/sound/usb/endpoint.c
+++ b/sound/usb/endpoint.c
@@ -1819,11 +1819,13 @@ static void snd_usb_handle_sync_urb(stru
out_packet->packets = in_ctx->packets;
for (i = 0; i < in_ctx->packets; i++) {
- if (urb->iso_frame_desc[i].status == 0)
- out_packet->packet_size[i] =
+ if (urb->iso_frame_desc[i].status == 0) {
+ unsigned int frames =
urb->iso_frame_desc[i].actual_length / sender->stride;
- else
+ out_packet->packet_size[i] = min(frames, ep->maxframesize);
+ } else {
out_packet->packet_size[i] = 0;
+ }
}
spin_unlock_irqrestore(&ep->lock, flags);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 272/438] dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (270 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 271/438] ALSA: usb-audio: Clamp frame size in implicit-feedback mode Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 273/438] e1000: fix memory leak in e1000_probe() Greg Kroah-Hartman
` (179 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lakshmi Sowjanya D, Md Sadre Alam,
Frank Li, Dmitry Baryshkov, Varadarajan Narayanan, Vinod Koul
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Md Sadre Alam <md.alam@oss.qualcomm.com>
commit 867621ba203027338b525af6729719c544135336 upstream.
BAM version 1.6.0 and later changed the behavior of the mask field in
command elements for read operations.
In older BAM versions, or prior implementation assumptions, the mask
field was effectively ignored for read commands. However, starting from
BAM v1.6.0, the mask field for read commands is repurposed to carry the
upper 4 bits of the destination address, enabling support for 36-bit
addressing. For write commands, the mask field continues to function as
a traditional write mask.
The current driver sets mask = 0xffffffff for all command elements.
While this works for write operations, it breaks read operations on
BAM v1.6.0+ hardware. In such cases, the hardware interprets the upper
address bits as 0xf, resulting in an invalid destination address
(0xf_xxxxxxxx instead of 0x0_xxxxxxxx).
This leads to failures such as NAND enumeration issues observed on
platforms like IPQ5424.
Fix this by assigning the mask field based on command type:
- For read commands: set mask = 0 (upper address bits = 0)
- For write commands: retain mask = 0xffffffff
Also update the bam_cmd_element structure documentation to reflect the
dual purpose of the mask field across BAM versions.
This ensures correct behavior on BAM v1.6.0+ while maintaining backward
compatibility with older hardware.
Fixes: dfebb055f73a2 ("dmaengine: qcom: bam_dma: wrapper functions for command descriptor")
Tested-by: Lakshmi Sowjanya D <lakshmi.d@oss.qualcomm.com>
Signed-off-by: Md Sadre Alam <md.alam@oss.qualcomm.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Cc: stable@vger.kernel.org
Signed-off-by: Varadarajan Narayanan <varadarajan.narayanan@oss.qualcomm.com>
Link: https://patch.msgid.link/20260615060908.1263171-1-varadarajan.narayanan@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/dma/qcom_bam_dma.h | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
--- a/include/linux/dma/qcom_bam_dma.h
+++ b/include/linux/dma/qcom_bam_dma.h
@@ -13,9 +13,12 @@
* supported by BAM DMA Engine.
*
* @cmd_and_addr - upper 8 bits command and lower 24 bits register address.
- * @data - for write command: content to be written into peripheral register.
- * for read command: dest addr to write peripheral register value.
- * @mask - register mask.
+ * @data - For write command: content to be written into peripheral register.
+ * For read command: lower 32 bits of destination address.
+ * @mask - For write command: register write mask.
+ * For read command on BAM v1.6.0+: upper 4 bits of destination address.
+ * For read command on BAM < v1.6.0: ignored by hardware.
+ * Setting to 0 ensures 32-bit addressing compatibility.
* @reserved - for future usage.
*
*/
@@ -42,6 +45,10 @@ enum bam_command_type {
* @addr: target address
* @cmd: BAM command
* @data: actual data for write and dest addr for read in le32
+ *
+ * For BAM v1.6.0+, the mask field behavior depends on command type:
+ * - Write commands: mask = write mask (typically 0xffffffff)
+ * - Read commands: mask = upper 4 bits of destination address (0 for 32-bit)
*/
static inline void
bam_prep_ce_le32(struct bam_cmd_element *bam_ce, u32 addr,
@@ -50,7 +57,11 @@ bam_prep_ce_le32(struct bam_cmd_element
bam_ce->cmd_and_addr =
cpu_to_le32((addr & 0xffffff) | ((cmd & 0xff) << 24));
bam_ce->data = data;
- bam_ce->mask = cpu_to_le32(0xffffffff);
+ if (cmd == BAM_READ_COMMAND)
+ bam_ce->mask = cpu_to_le32(0x0); /* 32-bit addressing */
+ else
+ bam_ce->mask = cpu_to_le32(0xffffffff); /* Write mask */
+ bam_ce->reserved = 0;
}
/*
@@ -60,7 +71,7 @@ bam_prep_ce_le32(struct bam_cmd_element
* @bam_ce: BAM command element
* @addr: target address
* @cmd: BAM command
- * @data: actual data for write and dest addr for read
+ * @data: actual data for write and destination address for read
*/
static inline void
bam_prep_ce(struct bam_cmd_element *bam_ce, u32 addr,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 273/438] e1000: fix memory leak in e1000_probe()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (271 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 272/438] dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 274/438] fou: Fix use-after-free in fou_create() Greg Kroah-Hartman
` (178 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zilin Guan, Dawei Feng,
Dima Ruinskiy, Tony Nguyen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawei Feng <dawei.feng@seu.edu.cn>
commit 816419dfea5c88126f35eb7a1b429a1bf546665e upstream.
In the e1000_probe() path, e1000_sw_init() allocates adapter->tx_ring and
adapter->rx_ring. If the subsequent CE4100-specific MDIO BAR mapping
fails, the error handling jumps past the ring cleanup code, leaking both
allocations.
Fix this leak by moving the err_mdio_ioremap label above the ring
deallocation logic. This guarantees the proper release of these resources
and prevents the memory leak.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc6.
An x86_64 allyesconfig build showed no new warnings. As we do not have a
CE4100 reference platform to test with, no runtime testing was able to
be performed.
Fixes: 5377a4160bb65 ("e1000: Add support for the CE4100 reference platform")
Cc: stable@vger.kernel.org
Signed-off-by: Zilin Guan <zilin@seu.edu.cn>
Signed-off-by: Dawei Feng <dawei.feng@seu.edu.cn>
Reviewed-by: Dima Ruinskiy <dima.ruinskiy@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/intel/e1000/e1000_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/ethernet/intel/e1000/e1000_main.c
+++ b/drivers/net/ethernet/intel/e1000/e1000_main.c
@@ -1222,11 +1222,11 @@ err_eeprom:
if (hw->flash_address)
iounmap(hw->flash_address);
+err_mdio_ioremap:
kfree(adapter->tx_ring);
kfree(adapter->rx_ring);
err_dma:
err_sw_init:
-err_mdio_ioremap:
iounmap(hw->ce4100_gbe_mdio_base_virt);
iounmap(hw->hw_addr);
err_ioremap:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 274/438] fou: Fix use-after-free in fou_create()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (272 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 273/438] e1000: fix memory leak in e1000_probe() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 275/438] igbvf: Fix leak in TX DMA error cleanup Greg Kroah-Hartman
` (177 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Xuanqiang Luo,
Paolo Abeni
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
commit b14361aca6350ff7907b0e9903c7b94dc7d5d4a0 upstream.
fou_create() publishes struct fou through sk_user_data before adding the
new FOU port to the per-netns list. If fou_add_to_port_list() fails,
the error path frees fou while it is still reachable through
sk_user_data. A concurrent receive can then dereference the freed
object in fou_from_sock().
This ordering issue was previously noted in the linked discussion.
The failure is reachable when local port 0 is requested. Each socket
binds to a different ephemeral port, but fou_cfg_cmp() compares the
requested port 0 and reports -EALREADY once an entry already exists.
Release the tunnel socket before freeing fou so sk_user_data is cleared
first, and defer reclamation with kfree_rcu() to protect concurrent RCU
readers. This matches the lifetime handling in fou_release().
Fixes: 23461551c006 ("fou: Support for foo-over-udp RX path")
Suggested-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://lore.kernel.org/netdev/20260502031401.3557229-12-kuniyu@google.com/
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260722083858.182506-1-xuanqiang.luo@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/fou_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/ipv4/fou_core.c
+++ b/net/ipv4/fou_core.c
@@ -629,9 +629,9 @@ static int fou_create(struct net *net, s
return 0;
error:
- kfree(fou);
if (sock)
udp_tunnel_sock_release(sock->sk);
+ kfree_rcu(fou, rcu);
return err;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 275/438] igbvf: Fix leak in TX DMA error cleanup
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (273 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 274/438] fou: Fix use-after-free in fou_create() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 276/438] igc: remove napi_synchronize() in igc_down() Greg Kroah-Hartman
` (176 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Matt Vollrath, Tony Nguyen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matt Vollrath <tactii@gmail.com>
commit 0565052b7e2f436b7f1541f4849da96dc0aa7a0e upstream.
If an error is encountered while mapping TX buffers, the driver should
unmap any buffers already mapped for that skb.
Because count is incremented before each frag mapping, it will always
match the correct number of unmappings needed when dma_error is reached.
Decrementing count before the while loop in dma_error causes an
off-by-one error. If any mapping was successful before an unsuccessful
mapping, exactly one DMA mapping (the head) would leak.
This bug was introduced by a 2010 fix for an endless loop in dma_error.
All other affected drivers have already been fixed.
Fixes: c1fa347f20f1 ("e1000/e1000e/igb/igbvf/ixgb/ixgbe: Fix tests of unsigned in *_tx_map()")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-4-7-opus
Signed-off-by: Matt Vollrath <tactii@gmail.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/intel/igbvf/netdev.c | 2 --
1 file changed, 2 deletions(-)
--- a/drivers/net/ethernet/intel/igbvf/netdev.c
+++ b/drivers/net/ethernet/intel/igbvf/netdev.c
@@ -2190,8 +2190,6 @@ dma_error:
buffer_info->time_stamp = 0;
buffer_info->length = 0;
buffer_info->mapped_as_page = false;
- if (count)
- count--;
/* clear timestamp and dma mappings for remaining portion of packet */
while (count--) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 276/438] igc: remove napi_synchronize() in igc_down()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (274 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 275/438] igbvf: Fix leak in TX DMA error cleanup Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 277/438] ipvs: do not propagate one-packet flag to synced conns Greg Kroah-Hartman
` (175 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maciej Fijalkowski, David Carlier,
Dima Ruinskiy, Moriya Kadosh, Tony Nguyen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Carlier <devnexen@gmail.com>
commit 5ffab5b9589c50e4cfc0cf36ffd76c89422d4019 upstream.
When an AF_XDP zero-copy application is killed abruptly, the XSK pool is
torn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the
full budget on every poll, so napi_complete_done() never clears
NAPI_STATE_SCHED.
igc_down() calls napi_synchronize() before napi_disable(), so it spins
forever waiting for that bit and the interface never goes down. Drop the
napi_synchronize() and let napi_disable() do the job -- it sets
NAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it
ahead of igc_set_queue_napi() so the NAPI mapping is cleared only after
polling has stopped, matching the recent igb fix b1e067240379.
Fixes: fc9df2a0b520 ("igc: Enable RX via AF_XDP zero-copy")
Suggested-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Cc: stable@vger.kernel.org
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Reviewed-by: Dima Ruinskiy <dima.ruinskiy@intel.com>
Tested-by: Moriya Kadosh <moriyax.kadosh@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/intel/igc/igc_main.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/net/ethernet/intel/igc/igc_main.c
+++ b/drivers/net/ethernet/intel/igc/igc_main.c
@@ -5352,9 +5352,8 @@ void igc_down(struct igc_adapter *adapte
for (i = 0; i < adapter->num_q_vectors; i++) {
if (adapter->q_vector[i]) {
- napi_synchronize(&adapter->q_vector[i]->napi);
- igc_set_queue_napi(adapter, i, NULL);
napi_disable(&adapter->q_vector[i]->napi);
+ igc_set_queue_napi(adapter, i, NULL);
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 277/438] ipvs: do not propagate one-packet flag to synced conns
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (275 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 276/438] igc: remove napi_synchronize() in igc_down() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 278/438] ksmbd: reject repeated SMB2 NEGOTIATE requests Greg Kroah-Hartman
` (174 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuan Tan, Yifan Wu, Juefei Pu,
Xin Liu, Julian Anastasov, Zhiling Zou, Ren Wei,
Pablo Neira Ayuso
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <roxy520tt@gmail.com>
commit a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b upstream.
Synced connections can be created before their destination exists. When
the destination is later added, ip_vs_bind_dest() copies connection flags
from the destination into cp->flags.
IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced
connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,
expiry can treat it as a one-packet connection and skip unlinking the
existing conn_tab node, leaving stale hash nodes pointing at a freed
struct ip_vs_conn.
Drop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced
connections.
Fixes: 26ec037f9841 ("IPVS: one-packet scheduling")
Cc: stable@vger.kernel.org
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Suggested-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Zhiling Zou <roxy520tt@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Acked-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/ipvs/ip_vs_conn.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/netfilter/ipvs/ip_vs_conn.c
+++ b/net/netfilter/ipvs/ip_vs_conn.c
@@ -1110,6 +1110,9 @@ ip_vs_bind_dest(struct ip_vs_conn *cp, s
flags = cp->flags;
/* Bind with the destination and its corresponding transmitter */
if (flags & IP_VS_CONN_F_SYNC) {
+ /* Synced conns are hashed, so they can not get this flag */
+ conn_flags &= ~IP_VS_CONN_F_ONE_PACKET;
+
/* if the connection is not template and is created
* by sync, preserve the activity flag.
*/
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 278/438] ksmbd: reject repeated SMB2 NEGOTIATE requests
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (276 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 277/438] ipvs: do not propagate one-packet flag to synced conns Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 279/438] mshv: fix hv_input_get_system_property struct Greg Kroah-Hartman
` (173 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runa Takemoto, Namjae Jeon,
Steve French
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
commit cb469993b3a61a72653770856d37af616d72d05f upstream.
Unauthenticated client can send multiple successful SMB2 NEGOTIATE
requests on one connection before SESSION_SETUP. While the connection is
in KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another
SMB3.1.1 NEGOTIATE and overwrites conn->preauth_info with a new allocation.
Only the final allocation is freed when the connection is released, leaking
one object for every additional successful request.
A repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol
violation. MS-SMB2 section 3.3.5.4 requires the server to disconnect
without replying in this case. Set the connection exiting when rejecting
the request, in addition to suppressing the response.
Reject SMB2 NEGOTIATE unless the connection is new or is waiting for the
SMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize
both SMB1 and SMB2 negotiation paths under conn->srv_mutex, since they
update connection-wide dialect and negotiation state.
Move the locking contract to ksmbd_smb_negotiate_common(), where the state
and dialect are selected, and add ksmbd_conn_new() for consistent state
access.
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org
Reported-by: Runa Takemoto <takemotoruna223@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/server/connection.h | 5 +++++
fs/smb/server/smb2pdu.c | 10 ++--------
fs/smb/server/smb_common.c | 37 ++++++++++++++++++++++++++++++-------
3 files changed, 37 insertions(+), 15 deletions(-)
--- a/fs/smb/server/connection.h
+++ b/fs/smb/server/connection.h
@@ -197,6 +197,11 @@ void ksmbd_conn_r_count_dec(struct ksmbd
* This is a hack. We will move status to a proper place once we land
* a multi-sessions support.
*/
+static inline bool ksmbd_conn_new(struct ksmbd_conn *conn)
+{
+ return READ_ONCE(conn->status) == KSMBD_SESS_NEW;
+}
+
static inline bool ksmbd_conn_good(struct ksmbd_conn *conn)
{
return READ_ONCE(conn->status) == KSMBD_SESS_GOOD;
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -1143,6 +1143,8 @@ static __le32 deassemble_neg_contexts(st
* smb2_handle_negotiate() - handler for smb2 negotiate command
* @work: smb work containing smb request buffer
*
+ * The caller holds conn->srv_mutex.
+ *
* Return: 0
*/
int smb2_handle_negotiate(struct ksmbd_work *work)
@@ -1156,13 +1158,6 @@ int smb2_handle_negotiate(struct ksmbd_w
ksmbd_debug(SMB, "Received negotiate request\n");
conn->need_neg = false;
- if (ksmbd_conn_good(conn)) {
- pr_err("conn->tcp_status is already in CifsGood State\n");
- work->send_no_response = 1;
- return rc;
- }
-
- ksmbd_conn_lock(conn);
smb2_buf_len = get_rfc1002_len(work->request_buf);
smb2_neg_size = offsetof(struct smb2_negotiate_req, Dialects);
if (smb2_neg_size > smb2_buf_len) {
@@ -1313,7 +1308,6 @@ int smb2_handle_negotiate(struct ksmbd_w
ksmbd_conn_set_need_setup(conn);
err_out:
- ksmbd_conn_unlock(conn);
if (rc)
rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES;
--- a/fs/smb/server/smb_common.c
+++ b/fs/smb/server/smb_common.c
@@ -616,23 +616,46 @@ int ksmbd_smb_negotiate_common(struct ks
struct ksmbd_conn *conn = work->conn;
int ret;
- conn->dialect =
- ksmbd_negotiate_smb_dialect(work->request_buf);
- ksmbd_debug(SMB, "conn->dialect 0x%x\n", conn->dialect);
-
if (command == SMB2_NEGOTIATE_HE) {
+ /*
+ * An SMB2 NEGOTIATE is valid for a new connection, or after an
+ * SMB1 multi-protocol negotiate has selected SMB2. Do not allow
+ * a second SMB2 NEGOTIATE to replace connection-wide state
+ * while a session setup is pending. KSMBD_SESS_NEED_RECONNECT
+ * is a transient session state and does not restart transport
+ * negotiation.
+ */
+ ksmbd_conn_lock(conn);
+ if (!ksmbd_conn_new(conn) &&
+ !ksmbd_conn_need_negotiate(conn)) {
+ work->send_no_response = 1;
+ ksmbd_conn_set_exiting(conn);
+ ksmbd_conn_unlock(conn);
+ return 0;
+ }
+
+ conn->dialect =
+ ksmbd_negotiate_smb_dialect(work->request_buf);
+ ksmbd_debug(SMB, "conn->dialect 0x%x\n", conn->dialect);
ret = smb2_handle_negotiate(work);
+ ksmbd_conn_unlock(conn);
return ret;
}
if (command == SMB_COM_NEGOTIATE) {
+ ksmbd_conn_lock(conn);
+ conn->dialect =
+ ksmbd_negotiate_smb_dialect(work->request_buf);
+ ksmbd_debug(SMB, "conn->dialect 0x%x\n", conn->dialect);
if (__smb2_negotiate(conn)) {
init_smb3_11_server(conn);
- init_smb2_neg_rsp(work);
+ ret = init_smb2_neg_rsp(work);
ksmbd_debug(SMB, "Upgrade to SMB2 negotiation\n");
- return 0;
+ } else {
+ ret = smb_handle_negotiate(work);
}
- return smb_handle_negotiate(work);
+ ksmbd_conn_unlock(conn);
+ return ret;
}
pr_err("Unknown SMB negotiation command: %u\n", command);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 279/438] mshv: fix hv_input_get_system_property struct
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (277 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 278/438] ksmbd: reject repeated SMB2 NEGOTIATE requests Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 280/438] net/smc: fix socket use-after-free during link group termination Greg Kroah-Hartman
` (172 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wei Liu
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Liu <wei.liu@kernel.org>
commit d6f0248f04a96249660591e47fcf37ba98ac7ea3 upstream.
Keep it in sync with the correct definition.
The old code worked by chance.
Fixes: e68bda71a2384 ("hyperv: Add new Hyper-V headers in include/hyperv")
Cc: stable@kernel.org
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/hyperv/hvhdk_mini.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/include/hyperv/hvhdk_mini.h
+++ b/include/hyperv/hvhdk_mini.h
@@ -184,8 +184,9 @@ enum hv_dynamic_processor_feature_proper
struct hv_input_get_system_property {
u32 property_id; /* enum hv_system_property */
+ u32 reserved;
union {
- u32 as_uint32;
+ u64 as_uint64;
#if IS_ENABLED(CONFIG_X86)
/* enum hv_dynamic_processor_feature_property */
u32 hv_processor_feature;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 280/438] net/smc: fix socket use-after-free during link group termination
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (278 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 279/438] mshv: fix hv_input_get_system_property struct Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 281/438] netfilter: ipset: do not update comments from kernel-side hash adds Greg Kroah-Hartman
` (171 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Mahanta Jambigi,
Paolo Abeni
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
commit f621d6ebeebb6374342571e4ddf45fdbc420f6cd upstream.
__smc_lgr_terminate() drops conns_lock after finding a connection in
lgr->conns_all, but before taking a reference on its socket. The connection
is embedded in the socket, and its registration reference protects it only
while the connection remains in the tree.
A concurrent close can unregister the connection and drop that reference,
freeing the socket before the termination worker reaches sock_hold().
The race is reachable when close overlaps link group termination.
Local stress testing reproduced the use-after-free and KASAN reported:
BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]
Write of size 4 by task kworker/3:3
Workqueue: events smc_lgr_terminate_work [smc]
__smc_lgr_terminate.part.0 [smc]
The socket was allocated by smc_create(), freed through
slab_free_after_rcu_debug(), and was followed by:
refcount_t: addition on 0; use-after-free.
__smc_lgr_terminate.part.0 [smc]
Take the socket reference while conns_lock still protects the tree entry.
The unregister path then cannot drop the last reference until termination
has finished using the socket.
Fixes: 69318b5215f2 ("net/smc: improve abnormal termination locking")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Link: https://patch.msgid.link/20260723105454.87016-1-xuanqiang.luo@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/smc/smc_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/smc/smc_core.c
+++ b/net/smc/smc_core.c
@@ -1572,10 +1572,10 @@ static void __smc_lgr_terminate(struct s
read_lock_bh(&lgr->conns_lock);
node = rb_first(&lgr->conns_all);
while (node) {
- read_unlock_bh(&lgr->conns_lock);
conn = rb_entry(node, struct smc_connection, alert_node);
smc = container_of(conn, struct smc_sock, conn);
sock_hold(&smc->sk); /* sock_put below */
+ read_unlock_bh(&lgr->conns_lock);
lock_sock(&smc->sk);
smc_conn_kill(conn, soft);
release_sock(&smc->sk);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 281/438] netfilter: ipset: do not update comments from kernel-side hash adds
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (279 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 280/438] net/smc: fix socket use-after-free during link group termination Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 282/438] of/address: Fix NULL bus dereference in of_pci_range_parser_one() Greg Kroah-Hartman
` (170 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Lee, Jozsef Kadlecsik,
Pablo Neira Ayuso
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Lee <david.lee@trailofbits.com>
commit f30415929be8aeb002d557c8d3f7ab2d2188003a upstream.
mtype_resize() copies comment pointers with memcpy(), not the comment
objects themselves. During the window after an entry has been copied but
before the table swap and backlog replay, the old table is still
published for packet-side updates while the replacement-table entry
already holds the same ip_set_comment_rcu pointer.
If xt_SET --add-set ... --exist hits that old entry in this window,
mtype_add() calls ip_set_init_comment() even though packet-side adds
carry no comment payload. That call frees the shared comment through the
old entry, so the replacement-table entry now holds a stale pointer.
When the queued add is replayed on the new table, mtype_add() calls
ip_set_init_comment() again and strlen() dereferences the stale pointer.
Fix this in mtype_add() by skipping ip_set_init_comment() when
ext->target marks a packet-side add. Userspace adds still update
comments, while packet-side adds can no longer free comment storage
shared with a resize copy.
Fixes: f66ee0410b1c ("netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports")
Cc: stable@vger.kernel.org
Signed-off-by: David Lee <david.lee@trailofbits.com>
Assisted-by: Codex:gpt-5.5
Acked-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/ipset/ip_set_hash_gen.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/netfilter/ipset/ip_set_hash_gen.h
+++ b/net/netfilter/ipset/ip_set_hash_gen.h
@@ -984,7 +984,7 @@ overwrite_extensions:
#endif
if (SET_WITH_COUNTER(set))
ip_set_init_counter(ext_counter(data, set), ext);
- if (SET_WITH_COMMENT(set))
+ if (SET_WITH_COMMENT(set) && !ext->target)
ip_set_init_comment(set, ext_comment(data, set), ext);
if (SET_WITH_SKBINFO(set))
ip_set_init_skbinfo(ext_skbinfo(data, set), ext);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 282/438] of/address: Fix NULL bus dereference in of_pci_range_parser_one()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (280 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 281/438] netfilter: ipset: do not update comments from kernel-side hash adds Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 283/438] PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug Greg Kroah-Hartman
` (169 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Carlo Caione, Rob Herring (Arm)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carlo Caione <ccaione@baylibre.com>
commit bba13ad17b1a11b3f1ed9b3a5d556191d7755a59 upstream.
The bus matching rework made of_match_bus() return NULL for nodes with
ranges/dma-ranges but no local #address-cells. parser_init() stored that
NULL bus, and the range iterator later dereferenced it.
Reject such nodes in parser_init(), leaving an explicit empty
iterator for callers that ignore the init return, and make
of_dma_get_max_cpu_address() honour the init failure so a rejected node
cannot clamp the DMA limit.
Fixes: 64ee3cf096ac ("of/address: Rework bus matching to avoid warnings")
Cc: stable@vger.kernel.org
Signed-off-by: Carlo Caione <ccaione@baylibre.com>
Link: https://patch.msgid.link/20260727-of-range-parser-null-bus-v3-1-be01b708a4ce@baylibre.com
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/of/address.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
--- a/drivers/of/address.c
+++ b/drivers/of/address.c
@@ -753,6 +753,7 @@ EXPORT_SYMBOL(of_property_read_reg);
static int parser_init(struct of_pci_range_parser *parser,
struct device_node *node, const char *name)
{
+ const __be32 *range;
int rlen;
parser->node = node;
@@ -761,12 +762,20 @@ static int parser_init(struct of_pci_ran
parser->ns = of_bus_n_size_cells(node);
parser->dma = !strcmp(name, "dma-ranges");
parser->bus = of_match_bus(node);
+ parser->range = NULL;
+ parser->end = NULL;
- parser->range = of_get_property(node, name, &rlen);
- if (parser->range == NULL)
+ range = of_get_property(node, name, &rlen);
+ if (!range)
return -ENOENT;
- parser->end = parser->range + rlen / sizeof(__be32);
+ if (!parser->bus ||
+ !OF_CHECK_COUNTS(parser->na, parser->ns) ||
+ !OF_CHECK_ADDR_COUNT(parser->pna))
+ return -EINVAL;
+
+ parser->range = range;
+ parser->end = range + rlen / sizeof(__be32);
return 0;
}
@@ -792,7 +801,7 @@ struct of_pci_range *of_pci_range_parser
int na = parser->na;
int ns = parser->ns;
int np = parser->pna + na + ns;
- int busflag_na = parser->bus->flag_cells;
+ int busflag_na;
if (!range)
return NULL;
@@ -800,6 +809,8 @@ struct of_pci_range *of_pci_range_parser
if (!parser->range || parser->range + np > parser->end)
return NULL;
+ busflag_na = parser->bus->flag_cells;
+
range->flags = parser->bus->get_flags(parser->range);
range->bus_addr = of_read_number(parser->range + busflag_na, na - busflag_na);
@@ -976,8 +987,7 @@ phys_addr_t __init of_dma_get_max_cpu_ad
np = of_root;
ranges = of_get_property(np, "dma-ranges", &len);
- if (ranges && len) {
- of_dma_range_parser_init(&parser, np);
+ if (ranges && len && !of_dma_range_parser_init(&parser, np)) {
for_each_of_range(&parser, &range)
if (range.cpu_addr + range.size > cpu_end)
cpu_end = range.cpu_addr + range.size - 1;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 283/438] PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (281 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 282/438] of/address: Fix NULL bus dereference in of_pci_range_parser_one() Greg Kroah-Hartman
@ 2026-08-07 14:37 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 284/438] tipc: avoid use-after-free in poll trace queue dumps Greg Kroah-Hartman
` (168 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Soeren Moch, Richard Zhu,
Bjorn Helgaas, Frank Li, Manivannan Sadhasivam
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Soeren Moch <smoch@web.de>
commit b4bee12ebeccfcd5959ace2c3a4af08f5a917d4c upstream.
On some NXP chipsets, disabling Root Port MSI/MSI-X Capabilities blocks
MSIs originating from Endpoints from reaching the iMSI-RX controller.
To address this hardware bug, commit 3a4e8302e72f ("PCI: imx6: Keep Root
Port MSI capability with iMSI-RX to work around hardware bug") preserves
Root Port MSI and MSI-X Capabilities on i.MX7D, i.MX8MM, and i.MX8MQ
when iMSI-RX is in use.
The same applies to i.MX6Q, i.MX6QP, and i.MX6SX, so preserve Root Port
MSI/MSI-X Capabilities there as well.
Note that preserving these Capabilities means Root Port-originated MSIs
such as AER and PME won't be received due to separate hardware limitations.
Users may need to use workarounds such as passing the 'pcie_pme=nomsi'
command-line parameter.
Fixes: f5cd8a929c825 ("PCI: dwc: Remove MSI/MSIX capability for Root Port if iMSI-RX is used as MSI controller")
Signed-off-by: Soeren Moch <smoch@web.de>
Signed-off-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Manivannan Sadhasivam <mani@kernel.org>
Acked-by: Richard Zhu <hongxing.zhu@nxp.com>
Cc: stable@vger.kernel.org # 7.0+
Link: https://patch.msgid.link/20260717033203.2965045-1-hongxing.zhu@oss.nxp.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pci/controller/dwc/pci-imx6.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
--- a/drivers/pci/controller/dwc/pci-imx6.c
+++ b/drivers/pci/controller/dwc/pci-imx6.c
@@ -1884,7 +1884,8 @@ static const struct imx_pcie_drvdata drv
.flags = IMX_PCIE_FLAG_IMX_PHY |
IMX_PCIE_FLAG_SPEED_CHANGE_WORKAROUND |
IMX_PCIE_FLAG_BROKEN_SUSPEND |
- IMX_PCIE_FLAG_SUPPORTS_SUSPEND,
+ IMX_PCIE_FLAG_SUPPORTS_SUSPEND |
+ IMX_PCIE_FLAG_KEEP_MSI_CAP,
.dbi_length = 0x200,
.gpr = "fsl,imx6q-iomuxc-gpr",
.ltssm_off = IOMUXC_GPR12,
@@ -1900,7 +1901,8 @@ static const struct imx_pcie_drvdata drv
.flags = IMX_PCIE_FLAG_IMX_PHY |
IMX_PCIE_FLAG_SPEED_CHANGE_WORKAROUND |
IMX_PCIE_FLAG_SKIP_L23_READY |
- IMX_PCIE_FLAG_SUPPORTS_SUSPEND,
+ IMX_PCIE_FLAG_SUPPORTS_SUSPEND |
+ IMX_PCIE_FLAG_KEEP_MSI_CAP,
.gpr = "fsl,imx6q-iomuxc-gpr",
.ltssm_off = IOMUXC_GPR12,
.ltssm_mask = IMX6Q_GPR12_PCIE_CTL_2,
@@ -1915,7 +1917,8 @@ static const struct imx_pcie_drvdata drv
.flags = IMX_PCIE_FLAG_IMX_PHY |
IMX_PCIE_FLAG_SPEED_CHANGE_WORKAROUND |
IMX_PCIE_FLAG_SKIP_L23_READY |
- IMX_PCIE_FLAG_SUPPORTS_SUSPEND,
+ IMX_PCIE_FLAG_SUPPORTS_SUSPEND |
+ IMX_PCIE_FLAG_KEEP_MSI_CAP,
.dbi_length = 0x200,
.gpr = "fsl,imx6q-iomuxc-gpr",
.ltssm_off = IOMUXC_GPR12,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 284/438] tipc: avoid use-after-free in poll trace queue dumps
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (282 preceding siblings ...)
2026-08-07 14:37 ` [PATCH 7.1 283/438] PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 285/438] x86/CPU/AMD: Carve out a Zen5 models range Greg Kroah-Hartman
` (167 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zihan Xi, Ren Wei, Tung Nguyen,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit b4f1719dfea023220e0e6bd892b087d76b2a6a49 upstream.
TIPC socket tracepoints dump queue state through tipc_sk_dump(). Most
queue-dump callsites already serialize that walk under the socket lock or
sk->sk_lock.slock, but tipc_poll() calls trace_tipc_sk_poll(...,
TIPC_DUMP_ALL, ...) without holding either lock.
That lets the poll trace path reach tipc_list_dump() and backlog head/tail
dumping while another context dequeues and frees an skb, leaving the trace
helper dereferencing a stale queue entry.
Stop the unlocked poll trace site from requesting queue dumps. Other queue
dump trace callsites keep their existing output under the locking they
already provide, while poll still emits the event itself without walking
live queue members from an unlocked context.
Fixes: b4b9771bcbbd ("tipc: enable tracepoints in tipc")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/f8119abd5e5ecc400597de667ae9d39656de56d0.1784794294.git.zihanx@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/tipc/socket.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/tipc/socket.c
+++ b/net/tipc/socket.c
@@ -795,7 +795,7 @@ static __poll_t tipc_poll(struct file *f
__poll_t revents = 0;
sock_poll_wait(file, sock, wait);
- trace_tipc_sk_poll(sk, NULL, TIPC_DUMP_ALL, " ");
+ trace_tipc_sk_poll(sk, NULL, TIPC_DUMP_NONE, " ");
if (sk->sk_shutdown & RCV_SHUTDOWN)
revents |= EPOLLRDHUP | EPOLLIN | EPOLLRDNORM;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 285/438] x86/CPU/AMD: Carve out a Zen5 models range
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (283 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 284/438] tipc: avoid use-after-free in poll trace queue dumps Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 286/438] wifi: mac80211: fix tid_tx use-after-free on BA session stop Greg Kroah-Hartman
` (166 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pratik Vishwakarma,
Borislav Petkov (AMD), stable
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pratik Vishwakarma <Pratik.Vishwakarma@amd.com>
commit 52075128273ace53e6254e37899a47d40d4baf45 upstream.
Family 0x1a, model 0xd0..0xd7 belongs to the Zen5 generation. Carve it
out from the larger, Zen6 range where former doesn't belong.
[ bp: Rewrite commit message, add tags. ]
Fixes: b5f53e6d3d32 ("x86/CPU/AMD: Add more Zen6 models")
Signed-off-by: Pratik Vishwakarma <Pratik.Vishwakarma@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Cc: <stable@kernel.org>
Link: https://patch.msgid.link/20260729055459.15904-1-Pratik.Vishwakarma@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kernel/cpu/amd.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/arch/x86/kernel/cpu/amd.c
+++ b/arch/x86/kernel/cpu/amd.c
@@ -514,11 +514,13 @@ static void bsp_init_amd(struct cpuinfo_
case 0x00 ... 0x2f:
case 0x40 ... 0x4f:
case 0x60 ... 0x7f:
+ case 0xd0 ... 0xd7:
setup_force_cpu_cap(X86_FEATURE_ZEN5);
break;
case 0x50 ... 0x5f:
case 0x80 ... 0xaf:
- case 0xc0 ... 0xef:
+ case 0xc0 ... 0xcf:
+ case 0xd8 ... 0xef:
setup_force_cpu_cap(X86_FEATURE_ZEN6);
break;
default:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 286/438] wifi: mac80211: fix tid_tx use-after-free on BA session stop
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (284 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 285/438] x86/CPU/AMD: Carve out a Zen5 models range Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 287/438] wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames Greg Kroah-Hartman
` (165 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
commit 2f067f5a450ea07efd249142a11d940a068fe29c upstream.
ieee80211_stop_tx_ba_cb() hands tid_tx to kfree_rcu() through
ieee80211_remove_tid_tx(), and then reads tid_tx->ndp after dropping
sta->lock:
ieee80211_remove_tid_tx(sta, tid); /* kfree_rcu(tid_tx, rcu_head) */
...
spin_unlock_bh(&sta->lock);
if (start_txq)
ieee80211_agg_start_txq(sta, tid, false);
if (send_delba)
ieee80211_send_delba(..., tid_tx->ndp);
That read is not covered by an RCU read-side critical section, and it runs
in preemptible process context: both callers hold the wiphy mutex, reaching
it either from the ieee80211_ba_session_work() wiphy work or from
ieee80211_sta_tear_down_BA_sessions() during station teardown.
Softirqs can run in that window too, both from the local_bh_enable() that
ends ieee80211_agg_start_txq() and from any interrupt exit, so the RCU
callback can free tid_tx before the read.
Driving the function from a test module with the grace period forced into
that window, KASAN reports the read, and the free arrives on the ordinary
RCU softirq path:
BUG: KASAN: slab-use-after-free in ieee80211_stop_tx_ba_cb+0x3cd/0x400
Read of size 1 at addr ffff888002b9f52e by task kworker/0:1/10
[...]
Freed by task 57:
__kasan_slab_free+0x47/0x70
__rcu_free_sheaf_prepare+0x70/0x250
rcu_free_sheaf_nobarn+0x18/0x40
rcu_core+0x426/0x1310
handle_softirqs+0x144/0x590
__irq_exit_rcu+0xea/0x150
irq_exit_rcu+0x9/0x20
sysvec_apic_timer_interrupt+0x6b/0x80
asm_sysvec_apic_timer_interrupt+0x1a/0x20
send_delba is only set when tx_stop is set, which happens for
AGG_STOP_LOCAL_REQUEST alone, so this is reached on local teardown -
session idle timeout, PTK rekey, suspend, HW reconfig - and not from a
peer's DELBA.
Read ndp into a local before the session is freed, while sta->lock is still
held. tid_tx->ndp has a single writer, in
ieee80211_tx_ba_session_handle_start(), which cannot run concurrently here:
both paths are serialised by the wiphy mutex, and the session is already
marked HT_AGG_STATE_STOPPING at this point. tid_tx->ndp is also the only
tid_tx dereference left after ieee80211_remove_tid_tx() in this function.
Fixes: 98acd4c1d9f7 ("wifi: mac80211: add support for NDP ADDBA/DELBA for S1G")
Assisted-by: Codex:gpt-5.6-sol
Assisted-by: Kimi:K3
Cc: stable@vger.kernel.org
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260728112156.96822-1-enderaoelyther@gmail.com
[move/change the comment a bit to be more general not just on ndp,
initialize ndp directly]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/agg-tx.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/mac80211/agg-tx.c
+++ b/net/mac80211/agg-tx.c
@@ -915,6 +915,7 @@ void ieee80211_stop_tx_ba_cb(struct sta_
struct tid_ampdu_tx *tid_tx)
{
struct ieee80211_sub_if_data *sdata = sta->sdata;
+ bool ndp = ndp = tid_tx->ndp;
bool send_delba = false;
bool start_txq = false;
@@ -934,6 +935,7 @@ void ieee80211_stop_tx_ba_cb(struct sta_
send_delba = true;
ieee80211_remove_tid_tx(sta, tid);
+ /* tid_tx is now invalid since ieee80211_remove_tid_tx() frees it */
start_txq = true;
unlock_sta:
@@ -946,7 +948,7 @@ void ieee80211_stop_tx_ba_cb(struct sta_
ieee80211_send_delba(sdata, sta->sta.addr, tid,
WLAN_BACK_INITIATOR,
WLAN_REASON_QSTA_NOT_USE,
- tid_tx->ndp);
+ ndp);
}
void ieee80211_stop_tx_ba_cb_irqsafe(struct ieee80211_vif *vif,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 287/438] wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (285 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 286/438] wifi: mac80211: fix tid_tx use-after-free on BA session stop Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 288/438] binfmt_misc: restore write access when removing an entry Greg Kroah-Hartman
` (164 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
commit 99a948382af8a225e2d5e54a7052158cd6281cc6 upstream.
mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with
ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each
subframe it passes the subframe data pointer to
mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the
length of the A-MSDU parent, instead of rx_skb->len:
rx_skb = __skb_dequeue(&list);
rx_hdr = (struct rx_packet_hdr *)rx_skb->data;
if (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) &&
ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {
mwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,
skb->len);
}
The parent is not a valid description of that buffer, and may not be
valid memory at all. ieee80211_amsdu_to_8023s() ends with
if (!reuse_skb)
dev_kfree_skb(skb);
and it only sets reuse_skb when the parent is linear, is not a
head_frag, and is being consumed as the *last* subframe. So when the
parent does not qualify for reuse it has already been freed, and the
read of skb->len is a use-after-free. When it is reused, skb->len is
the length of the last subframe, applied to every earlier subframe,
which over-states the buffer whenever an earlier subframe is shorter.
The callee cannot absorb a wrong length, because it derives its own
ceiling from the value it is given. Each frame type computes
ies_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;
and the element walk is then bounded entirely against that ceiling,
for (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) {
u8 ie_len = pos[1];
if (pos + 2 + ie_len > end)
break;
so a too-large len moves end past the end of the subframe and the walk
reads and copies beyond it. The A-MSDU layout is chosen by the sender,
which makes the difference between the last subframe and a shorter
earlier one remotely selectable. Reaching this requires TDLS support in
firmware and the TDLS ethertype on the subframe.
The other caller, mwifiex_process_rx_packet(), is correct: it passes a
pointer and a length that describe the same region of the RX buffer.
Pass rx_skb->len, the length of the subframe actually being parsed.
Fixes: 776f742040ca ("mwifiex: fix AMPDU not setup on TDLS link problem")
Assisted-by: Codex:gpt-5.6-sol
Assisted-by: Kimi:K3
Cc: stable@vger.kernel.org
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260728115325.19128-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c
+++ b/drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c
@@ -44,7 +44,7 @@ static int mwifiex_11n_dispatch_amsdu_pk
ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {
mwifiex_process_tdls_action_frame(priv,
(u8 *)rx_hdr,
- skb->len);
+ rx_skb->len);
}
if (priv->bss_role == MWIFIEX_BSS_ROLE_UAP)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 288/438] binfmt_misc: restore write access when removing an entry
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (286 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 287/438] wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 289/438] binfmt_misc: use exe_file_deny_write_access() for the interpreter clone Greg Kroah-Hartman
` (163 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
commit db1856ea9196cf6e015d12199a34c0b9313c7bfa upstream.
Registering an entry with the MISC_FMT_OPEN_FILE flag opens the
interpreter via open_exec() which denies write access to it for as
long as the entry exists. Removing the entry closes the interpreter
file via filp_close() but never restores write access, leaving the
inode's i_writecount permanently negative. Opening the interpreter
for writing keeps failing with ETXTBSY long after the entry is gone
until the inode is evicted from the inode cache.
Commit 90f601b497d7 ("binfmt_misc: restore write access before
closing files opened by open_exec()") fixed the same imbalance in the
error path of bm_register_write() but the actual removal path has
been leaking the write denial since the introduction of the flag.
Restore write access in put_binfmt_handler() before closing the
interpreter file.
Link: https://patch.msgid.link/20260710-work-binfmt_misc-locking-v3-1-a162f7cb58d6@kernel.org
Fixes: 948b701a607f ("binfmt_misc: add persistent opened binary handler for containers")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/binfmt_misc.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/fs/binfmt_misc.c
+++ b/fs/binfmt_misc.c
@@ -162,8 +162,10 @@ static Node *get_binfmt_handler(struct b
static void put_binfmt_handler(Node *e)
{
if (refcount_dec_and_test(&e->users)) {
- if (e->flags & MISC_FMT_OPEN_FILE)
+ if (e->flags & MISC_FMT_OPEN_FILE) {
+ exe_file_allow_write_access(e->interp_file);
filp_close(e->interp_file, NULL);
+ }
kfree(e);
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 289/438] binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (287 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 288/438] binfmt_misc: restore write access when removing an entry Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 290/438] binfmt_misc: reject a flag character as the field delimiter Greg Kroah-Hartman
` (162 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
commit fa5990ca8fd917003e526036bcc50413edb9722c upstream.
For MISC_FMT_OPEN_FILE entries load_misc_binary() clones the
registered interpreter file and denies write access to the clone via
plain deny_write_access(). The clone is installed as
bprm->interpreter and later released by the exec machinery through
exe_file_allow_write_access() which skips the i_writecount increment
for files with FMODE_FSNOTIFY_HSM set.
The deny and allow side can therefore come to different conclusions
when pre-content watches are in play: if a pre-content watch is added
to the interpreter after registration every subsequent exec through
that entry takes a write denial on the clone that is never paired
with a write allowance, driving the interpreter inode's i_writecount
further down with each exec and leaving the interpreter unwritable
even after the entry and all its users are gone.
Take the write denial via exe_file_deny_write_access() so both sides
of the pairing base their decision on the same file mode, and
propagate failure instead of silently ignoring it: an interpreter
that is concurrently open for writing now fails the exec with
ETXTBSY, exactly like an interpreter freshly opened via open_exec()
would.
Link: https://patch.msgid.link/20260710-work-binfmt_misc-locking-v3-2-a162f7cb58d6@kernel.org
Fixes: 0357ef03c94e ("fs: don't block write during exec on pre-content watched files")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/binfmt_misc.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/fs/binfmt_misc.c
+++ b/fs/binfmt_misc.c
@@ -249,8 +249,14 @@ static int load_misc_binary(struct linux
if (fmt->flags & MISC_FMT_OPEN_FILE) {
interp_file = file_clone_open(fmt->interp_file);
- if (!IS_ERR(interp_file))
- deny_write_access(interp_file);
+ if (!IS_ERR(interp_file)) {
+ int err = exe_file_deny_write_access(interp_file);
+
+ if (err) {
+ fput(interp_file);
+ interp_file = ERR_PTR(err);
+ }
+ }
} else {
interp_file = open_exec(fmt->interpreter);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 290/438] binfmt_misc: reject a flag character as the field delimiter
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (288 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 289/438] binfmt_misc: use exe_file_deny_write_access() for the interpreter clone Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 291/438] binfmt_misc: dont let an F entry pin its own instance Greg Kroah-Hartman
` (161 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
commit 8e85d50ba1117fd446bf9a250bd8a97d48384bdc upstream.
The registration string starts with a user chosen delimiter that
separates the individual fields. So that the field parsers terminate
even on a truncated string create_entry() pads the buffer with that
same delimiter:
memset(buf + count, del, 8);
Most fields are scanned for the delimiter with strchr()/scanarg() and
happily stop on the padding. The flags field is different: instead of
scanning for the delimiter check_special_flags() consumes the flag
characters 'P', 'O', 'C' and 'F' and stops at the first byte that is
none of them, relying on the trailing delimiter to end the scan.
If the delimiter is itself a flag character the padding no longer acts
as a terminator. The scan swallows all eight padding bytes and keeps
reading past the end of the allocation until it hits a byte that is
not a flag character. For example registering
PaPEPPxPPiP
with 'P' as the delimiter (name "a", type extension, magic "x",
interpreter "i", empty flags) leaves the flag scan running off the end
of the buffer. The registration is rejected in the end because the
parser does not stop exactly at buf + count, but only after the out of
bounds read has already happened. With an unlucky allocation layout the
scan can walk into an unmapped page; under KASAN it is reported as a
slab out of bounds read. binfmt_misc mounts are available to
unprivileged users in a user namespace so the read is reachable without
privileges.
Reject a delimiter that is one of the flag characters up front. Such a
registration was always rejected anyway, only after the out of bounds
read, so no valid registration string changes meaning.
Link: https://patch.msgid.link/20260710-work-binfmt_misc-locking-v3-3-a162f7cb58d6@kernel.org
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/binfmt_misc.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/fs/binfmt_misc.c
+++ b/fs/binfmt_misc.c
@@ -384,6 +384,10 @@ static Node *create_entry(const char __u
pr_debug("register: delim: %#x {%c}\n", del, del);
+ /* A flag-char delimiter runs the flag scan off the buffer. */
+ if (del == 'P' || del == 'O' || del == 'C' || del == 'F')
+ goto einval;
+
/* Pad the buffer with the delim to simplify parsing below. */
memset(buf + count, del, 8);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 291/438] binfmt_misc: dont let an F entry pin its own instance
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (289 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 290/438] binfmt_misc: reject a flag character as the field delimiter Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 292/438] binfmt_misc: dont leak the user namespace when the mount fails Greg Kroah-Hartman
` (160 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
commit 79055d82772b9584f259b747fe40ff56a076678d upstream.
An entry registered with 'F' opens its interpreter at registration time
and holds that file until the entry is freed. Any entry nobody removes
by hand only gets closed once the binfmt_misc superblock is shut down.
If the interpreter lives on a mount that keeps that superblock alive the
two pin each other:
binfmt_misc sb -> inode -> entry -> interp_file -> vfsmount -> binfmt_misc sb
TL;DR the file is never closed. Once the mount namespace is gone there
is nothing left to unregister through either.
There are two ways to trigger this bug:
- Point the interpreter at the instance itself. Its files are regular
files owned by the mounter and both bm_get_inode() and
simple_fill_super() leave i_op at empty_iops. So notify_change() falls
back to simple_setattr() and chmod +x works. We never set SB_I_NOEXEC
and so open_exec() accepts it.
- Use the instance as an overlayfs lower layer. The overlay superblock
holds a clone_private_mount() of every layer until it is destroyed and
that clone is in no namespace. So umount_tree() never reaches it.
That's a DoS. And it isn't only the superblock that leaks. It pins the
user namespace it was mounted in, so every iteration permanently eats
one of the caller's user namespace charges.
So let's just do the sane thing. SB_I_NOEXEC makes open_exec() fail on
the instance's own files and s_stack_depth makes overlayfs reject the
layer before it ever takes a clone. That also covers the ecryptfs and
fuse passthrough variants. What 'F' promises is unchanged.
The stable tag is narrower than the Fixes tags on purpose. Before
sandboxed mounts this needed global root against the single instance
everyone shares, and the change doesn't apply to those trees anyway.
Note that SB_I_NODEV is implicitly raised for userns mounts but raise it
explicitly here as well.
Link: https://patch.msgid.link/20260728-work-binfmt_misc-selfpin-v1-1-74df5daeca5b@kernel.org
Fixes: 948b701a607f ("binfmt_misc: add persistent opened binary handler for containers")
Fixes: 21ca59b365c0 ("binfmt_misc: enable sandboxed mounts")
Cc: stable@vger.kernel.org # v6.7+
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/binfmt_misc.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/fs/binfmt_misc.c
+++ b/fs/binfmt_misc.c
@@ -949,6 +949,10 @@ static int bm_fill_super(struct super_bl
if (WARN_ON(user_ns != current_user_ns()))
return -EINVAL;
+ /* Never exec off this instance and never let anything stack on it. */
+ sb->s_iflags |= SB_I_NOEXEC | SB_I_NODEV;
+ sb->s_stack_depth = FILESYSTEM_MAX_STACK_DEPTH;
+
/*
* Lazily allocate a new binfmt_misc instance for this namespace, i.e.
* do it here during the first mount of binfmt_misc. We don't need to
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 292/438] binfmt_misc: dont leak the user namespace when the mount fails
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (290 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 291/438] binfmt_misc: dont let an F entry pin its own instance Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 293/438] io_uring/net: initialize mshot_len for send Greg Kroah-Hartman
` (159 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable)
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
commit b8206f516fe7cbe785cf44bf09c17c438d7c3cad upstream.
bm_get_tree() takes a reference to the user namespace and hands it to
get_tree_keyed() as the sget key. sget_fc() moves that reference into
sb->s_fs_info and clears fc->s_fs_info, so from that point on the
superblock owns it and bm_free() doesn't see it anymore.
The superblock drops it in ->put_super(). But generic_shutdown_super()
only calls ->put_super() from inside the if (sb->s_root) branch, so
nothing releases it when bm_fill_super() fails:
- The kzalloc_obj() failure leaves s_root NULL and the whole branch is
skipped.
- A simple_fill_super() failure in the file loop leaves s_root set, but
s_op still points at simple_super_operations, which has no
->put_super(). bm_fill_super() installs s_ops only once
simple_fill_super() returned success, and installing it earlier
wouldn't help either because simple_fill_super() overwrites s_op.
Either way vfs_get_super() calls deactivate_locked_super() and the
reference is gone for good. binfmt_misc mounts are available in a user
namespace and both the inode and the dentry cache are SLAB_ACCOUNT, so
an unprivileged caller under a tight memory cgroup can fail
simple_fill_super() on demand and leak one user namespace per attempt.
Drop the reference in ->kill_sb() instead, which runs unconditionally,
the same way nfsd and rpc_pipefs release their keyed s_fs_info.
That also stops ->put_super() from clearing s_fs_info while the
superblock is still on @fs_supers. generic_shutdown_super() leaves it
there on purpose so that sget_fc() keeps finding it until kill_sb() has
run, but a NULL s_fs_info makes test_keyed_super() miss it, so a
concurrent mount for the same user namespace skips the grab_super()
wait and creates a second superblock for a namespace that is still
being torn down.
Link: https://patch.msgid.link/20260728-work-binfmt_misc-usernsleak-v1-1-dbd8d5e626e7@kernel.org
Fixes: 21ca59b365c0 ("binfmt_misc: enable sandboxed mounts")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/binfmt_misc.c | 32 +++++++++++++++-----------------
1 file changed, 15 insertions(+), 17 deletions(-)
--- a/fs/binfmt_misc.c
+++ b/fs/binfmt_misc.c
@@ -921,18 +921,9 @@ static const struct file_operations bm_s
/* Superblock handling */
-static void bm_put_super(struct super_block *sb)
-{
- struct user_namespace *user_ns = sb->s_fs_info;
-
- sb->s_fs_info = NULL;
- put_user_ns(user_ns);
-}
-
static const struct super_operations s_ops = {
.statfs = simple_statfs,
.evict_inode = bm_evict_inode,
- .put_super = bm_put_super,
};
static int bm_fill_super(struct super_block *sb, struct fs_context *fc)
@@ -990,13 +981,12 @@ static int bm_fill_super(struct super_bl
/*
* When the binfmt_misc superblock for this userns is shutdown
* ->enabled might have been set to false and we don't reinitialize
- * ->enabled again in put_super() as someone might already be mounting
- * binfmt_misc again. It also would be pointless since by the time
- * ->put_super() is called we know that the binary type list for this
- * bintfmt_misc mount is empty making load_misc_binary() return
- * -ENOEXEC independent of whether ->enabled is true. Instead, if
- * someone mounts binfmt_misc for the first time or again we simply
- * reset ->enabled to true.
+ * ->enabled again during shutdown as someone might already be mounting
+ * binfmt_misc again. It also would be pointless since by then we know
+ * that the binary type list for this binfmt_misc mount is empty making
+ * load_misc_binary() return -ENOEXEC independent of whether ->enabled
+ * is true. Instead, if someone mounts binfmt_misc for the first time or
+ * again we simply reset ->enabled to true.
*/
misc->enabled = true;
@@ -1022,6 +1012,14 @@ static const struct fs_context_operation
.get_tree = bm_get_tree,
};
+static void bm_kill_sb(struct super_block *sb)
+{
+ struct user_namespace *user_ns = sb->s_fs_info;
+
+ kill_anon_super(sb);
+ put_user_ns(user_ns);
+}
+
static int bm_init_fs_context(struct fs_context *fc)
{
fc->ops = &bm_context_ops;
@@ -1038,7 +1036,7 @@ static struct file_system_type bm_fs_typ
.name = "binfmt_misc",
.init_fs_context = bm_init_fs_context,
.fs_flags = FS_USERNS_MOUNT,
- .kill_sb = kill_anon_super,
+ .kill_sb = bm_kill_sb,
};
MODULE_ALIAS_FS("binfmt_misc");
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 293/438] io_uring/net: initialize mshot_len for send
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (291 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 292/438] binfmt_misc: dont leak the user namespace when the mount fails Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 294/438] io_uring: preserve task restrictions across exec Greg Kroah-Hartman
` (158 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sung Keum, Gabriel Krisman Bertazi,
Jens Axboe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
commit c77ffbc980efb337fd750c337d8157d532ea14e5 upstream.
Commit:
6a8afb9fff64 ("io_uring/net: allow multishot receive per-invocation cap")
changed how io_mshot_prep_retry() set sr->len, and added the same
initialization in io_mshot_prep_retry(). But it neglected to touch the
send path, which may also uses the mshot retry path. Ensure that
sr->mshot_len always gets initialized correctly.
Fixes: 6a8afb9fff64 ("io_uring/net: allow multishot receive per-invocation cap")
Cc: stable@vger.kernel.org
Reported-by: Sung Keum <kambodi127@gmail.com>
Reviewed-by: Gabriel Krisman Bertazi <krisman@suse.de>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
io_uring/net.c | 1 +
1 file changed, 1 insertion(+)
--- a/io_uring/net.c
+++ b/io_uring/net.c
@@ -436,6 +436,7 @@ int io_sendmsg_prep(struct io_kiocb *req
req->flags |= REQ_F_NOWAIT;
if (req->flags & REQ_F_BUFFER_SELECT)
sr->buf_group = req->buf_index;
+ sr->mshot_total_len = sr->mshot_len = 0;
if (sr->flags & IORING_RECVSEND_BUNDLE) {
if (req->opcode == IORING_OP_SENDMSG)
return -EINVAL;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 294/438] io_uring: preserve task restrictions across exec
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (292 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 293/438] io_uring/net: initialize mshot_len for send Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 295/438] mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios Greg Kroah-Hartman
` (157 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kyumin Lee, Jens Axboe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyumin Lee <fyonglkm@gmail.com>
commit bc0e8faf90e776a2f1f3967a04e8091e6bdb4977 upstream.
Per-task restrictions apply to all rings created by a task. Once
installed, they should not be dropped across exec.
For a task that has used io_uring, the exec cancellation path calls
__io_uring_free(). This frees both the task context and the per-task
restriction, so a ring created after exec is unrestricted.
Split task context cleanup into io_uring_free_tctx(), and use it from
the exec cancellation path. Keep __io_uring_free() for final task
cleanup, where both the context and restriction are released.
Fixes: ed82f35b926b ("io_uring: allow registration of per-task restrictions")
Cc: stable@vger.kernel.org # 7.1+
Signed-off-by: Kyumin Lee <fyonglkm@gmail.com>
Link: https://patch.msgid.link/20260730192734.459247-1-fyonglkm@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
io_uring/cancel.c | 2 +-
io_uring/tctx.c | 7 ++++++-
io_uring/tctx.h | 1 +
3 files changed, 8 insertions(+), 2 deletions(-)
--- a/io_uring/cancel.c
+++ b/io_uring/cancel.c
@@ -662,6 +662,6 @@ end_wait:
*/
atomic_dec(&tctx->in_cancel);
/* for exec all current's requests should be gone, kill tctx */
- __io_uring_free(current);
+ io_uring_free_tctx(current);
}
}
--- a/io_uring/tctx.c
+++ b/io_uring/tctx.c
@@ -43,7 +43,7 @@ static struct io_wq *io_init_wq_offload(
return io_wq_create(concurrency, &data);
}
-void __io_uring_free(struct task_struct *tsk)
+void io_uring_free_tctx(struct task_struct *tsk)
{
struct io_uring_task *tctx = tsk->io_uring;
struct io_tctx_node *node;
@@ -67,6 +67,11 @@ void __io_uring_free(struct task_struct
kfree(tctx);
tsk->io_uring = NULL;
}
+}
+
+void __io_uring_free(struct task_struct *tsk)
+{
+ io_uring_free_tctx(tsk);
if (tsk->io_uring_restrict) {
io_put_bpf_filters(tsk->io_uring_restrict);
kfree(tsk->io_uring_restrict);
--- a/io_uring/tctx.h
+++ b/io_uring/tctx.h
@@ -12,6 +12,7 @@ void io_uring_del_tctx_node(unsigned lon
int __io_uring_add_tctx_node(struct io_ring_ctx *ctx);
int __io_uring_add_tctx_node_from_submit(struct io_ring_ctx *ctx);
void io_uring_clean_tctx(struct io_uring_task *tctx);
+void io_uring_free_tctx(struct task_struct *tsk);
void io_uring_unreg_ringfd(void);
int io_ringfd_register(struct io_ring_ctx *ctx, void __user *__arg,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 295/438] mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (293 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 294/438] io_uring: preserve task restrictions across exec Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 296/438] mm/page_reporting: use system_freezable_wq to fix UAF during suspend Greg Kroah-Hartman
` (156 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kiryl Shutsemau (Meta), Hao Zhang,
David Hildenbrand (Arm), Zi Yan, Baolin Wang, Miaohe Lin,
Barry Song, Dev Jain, Lance Yang, Liam R. Howlett,
Lorenzo Stoakes, Naoya Horiguchi, Nico Pache, Ryan Roberts,
Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kiryl Shutsemau (Meta) <kas@kernel.org>
commit e923bd21058ea02fd0dcd3549d151d143fd036e5 upstream.
__folio_split() keeps dereferencing the mapping after the split:
shmem_uncharge(mapping->host) and remap_page() while the folios are still
frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the
after-split folios have been unlocked and freed.
Nothing holds an inode reference across that. The split relies on @folio
-- which the beyond-EOF drop loop never removes, as it starts at
folio_next(folio) -- staying locked and in the page cache to hold off
eviction. But the unlock loop unlocks @folio before i_mmap_unlock_read()
runs. If the caller's @lock_at is a tail beyond EOF, as memory_failure()
passes when splitting a poisoned tail of a shmem THP that reaches past
i_size during truncation, it too is gone from the page cache; so once
@folio is unlocked no locked, in-cache folio pins the inode, and a
concurrent final iput() can evict and RCU-free it before
i_mmap_unlock_read() touches i_mmap_rwsem:
BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790
i_mmap_unlock_read include/linux/fs.h:537 [inline]
__folio_split+0x732/0x1640 mm/huge_memory.c:4100
try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675
memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470
Freed by task 4601:
shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177
evict+0x57f/0xac0 fs/inode.c:870
Do every mapping dereference while @folio still pins the inode: drop
i_mmap_rwsem right after remap_page(), before the loop that unlocks and
frees the after-split folios, and clear @mapping so the exit path does not
unlock it again. shmem_uncharge() and remap_page() already run before
that point, so after this nothing past the unlock loop touches the inode
or the mapping.
This is now a rule the split depends on, alongside keeping @folio frozen
until the page cache is updated: no inode or mapping dereference once the
after-split folios start being unlocked.
Link: https://lore.kernel.org/20260716095424.471052-1-kirill@shutemov.name
Fixes: baa355fd3314 ("thp: file pages support for split_huge_page()")
Signed-off-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Reported-by: Hao Zhang <zhanghao1@kylinos.cn>
Closes: https://lore.kernel.org/linux-mm/20260710071344.GA106129@zh-pc
Co-developed-by: Hao Zhang <zhanghao1@kylinos.cn>
Signed-off-by: Hao Zhang <zhanghao1@kylinos.cn>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Zi Yan <ziy@nvidia.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Reviewed-by: Miaohe Lin <linmiaohe@huawei.com>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Lance Yang <lance.yang@linux.dev>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Naoya Horiguchi <nao.horiguchi@gmail.com>
Cc: Nico Pache <npache@redhat.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/huge_memory.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -4189,6 +4189,18 @@ fail:
remap_page(folio, 1 << old_order, ttu_flags);
/*
+ * Drop the mapping while the inode is still pinned. @folio stays
+ * locked and present in the page cache until the loop below, so
+ * eviction cannot free the inode yet; @lock_at is not enough, it may
+ * be a tail beyond EOF that the split already dropped from the page
+ * cache. Nothing past this point may touch the inode or the mapping.
+ */
+ if (mapping) {
+ i_mmap_unlock_read(mapping);
+ mapping = NULL;
+ }
+
+ /*
* Unlock all after-split folios except the one containing
* @lock_at page. If @folio is not split, it will be kept locked.
*/
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 296/438] mm/page_reporting: use system_freezable_wq to fix UAF during suspend
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (294 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 295/438] mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 297/438] mm: memcg: initialize *locked in memcg1_oom_prepare() stub Greg Kroah-Hartman
` (155 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Link Lin, David Hildenbrand (Arm),
Michael S. Tsirkin, David Rientjes, Alexander Duyck, Greg Thelen,
James Houghton, Jason Wang, Jiaqi Yan, Vlastimil Babka, Xuan Zhuo,
Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Link Lin <linkl@google.com>
commit 0b45f6927a14914ff685fe0e6f9d11232a1e03df upstream.
During PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like
virtio_balloon reset their underlying virtio devices and delete their
virtqueues via vdev->config->del_vqs().
However, page reporting work (page_reporting_process) was scheduled on the
global system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM
freezer skips it, leaving page_reporting_process active during suspend.
If pages are freed into the buddy allocator while suspending (for example,
when core MM invokes the balloon shrinker during S4 hibernation image
saving), page reporting triggers virtballoon_free_page_report() on deleted
virtqueues, resulting in a Use-After-Free / General Protection Fault:
[ 196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI
[ 196.825967] Workqueue: events page_reporting_process
[ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]
[ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]
[ 196.946943] page_reporting_process+0x370/0x4f0
Fix this by switching page reporting work to system_freezable_wq. This
ensures that the PM freezer pauses page_reporting_process before device
drivers destroy their reporting virtqueues. Because the reporting worker
is frozen, memory reclamation/freeing (e.g. via shrinker execution) can
safely return pages to MM during freeze without triggering unfrozen
reporting work on deleted virtqueues.
This aligns with the driver's existing design. The comment in
virtballoon_freeze() states:
/*
* The workqueue is already frozen by the PM core before this
* function is called.
*/
Testing:
I have verified these fixes using Google’s virtualization infrastructure
by running continuous suspend/resume iterations (40+ cycles) while
churning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60%
--timeout 1`) to constantly create free pages for the buddy allocator. We
also set the `page_reporting_order` parameter to 0 to make the page
reporting worker highly sensitive, forcing it to pick up any 4K free
pages. This confirmed that the UAF crashes are no longer reproducible.
Link: https://lore.kernel.org/20260721005603.1710551-1-linkl@google.com
Fixes: 36e66c554b5c ("mm: introduce Reported pages")
Signed-off-by: Link Lin <linkl@google.com>
Suggested-by: David Hildenbrand (Arm) <david@kernel.org>
Suggested-by: Michael S. Tsirkin <mst@redhat.com>
Acked-by: David Rientjes <rientjes@google.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Cc: Alexander Duyck <alexander.duyck@gmail.com>
Cc: Greg Thelen <gthelen@google.com>
Cc: James Houghton <jthoughton@google.com>
Cc: Jason Wang <jasowang@redhat.com>
Cc: Jiaqi Yan <jiaqiyan@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: Xuan Zhuo <xuanzhuo@linux.alibaba.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/page_reporting.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/mm/page_reporting.c
+++ b/mm/page_reporting.c
@@ -80,7 +80,8 @@ __page_reporting_request(struct page_rep
* now we are limiting this to running no more than once every
* couple of seconds.
*/
- schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
+ queue_delayed_work(system_freezable_wq, &prdev->work,
+ PAGE_REPORTING_DELAY);
}
/* notify prdev of free page reporting request */
@@ -343,7 +344,8 @@ err_out:
*/
state = atomic_cmpxchg(&prdev->state, state, PAGE_REPORTING_IDLE);
if (state == PAGE_REPORTING_REQUESTED)
- schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
+ queue_delayed_work(system_freezable_wq, &prdev->work,
+ PAGE_REPORTING_DELAY);
}
static DEFINE_MUTEX(page_reporting_mutex);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 297/438] mm: memcg: initialize *locked in memcg1_oom_prepare() stub
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (295 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 296/438] mm/page_reporting: use system_freezable_wq to fix UAF during suspend Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 298/438] net: bridge: stop fast-leave after deleting a port group Greg Kroah-Hartman
` (154 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Joshua Hahn,
Johannes Weiner, SeongJae Park, Shakeel Butt, Michal Hocko,
Muchun Song, Roman Gushchin, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
commit 1833ce36b35426504c64600c94f322437ea44bb2 upstream.
mem_cgroup_oom() passes an uninitialized "locked" to memcg1_oom_prepare()
and reads it back in memcg1_oom_finish():
bool locked, ret;
...
if (!memcg1_oom_prepare(memcg, &locked))
return false;
ret = mem_cgroup_out_of_memory(memcg, mask, order);
memcg1_oom_finish(memcg, locked);
This relies on memcg1_oom_prepare() setting *locked whenever it returns
true. The CONFIG_MEMCG_V1=y version does, but the stub used when
CONFIG_MEMCG_V1=n returns true without touching *locked, so
memcg1_oom_finish() consumes an uninitialized value. On a memcg OOM this
is reported by UBSAN:
UBSAN: invalid-load in mm/memcontrol.c:1932:27
load of value 0 is not a valid value for type 'bool' (aka '_Bool')
Initialize *locked to false in the stub; with cgroup v1 compiled out there
is no OOM lock to take.
Link: https://lore.kernel.org/20260716-memcg-oom-uninit-locked-v2-1-63631d878eb4@debian.org
Fixes: e93d4166b40a ("mm: memcg: put cgroup v1-specific code under a config option")
Signed-off-by: Breno Leitao <leitao@debian.org>
Reviewed-by: Joshua Hahn <joshua.hahnjy@gmail.com>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Reviewed-by: SeongJae Park <sj@kernel.org>
Acked-by: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/memcontrol-v1.h | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/mm/memcontrol-v1.h
+++ b/mm/memcontrol-v1.h
@@ -107,7 +107,11 @@ static inline void memcg1_remove_from_tr
static inline void memcg1_soft_limit_reset(struct mem_cgroup *memcg) {}
static inline void memcg1_css_offline(struct mem_cgroup *memcg) {}
-static inline bool memcg1_oom_prepare(struct mem_cgroup *memcg, bool *locked) { return true; }
+static inline bool memcg1_oom_prepare(struct mem_cgroup *memcg, bool *locked)
+{
+ *locked = false;
+ return true;
+}
static inline void memcg1_oom_finish(struct mem_cgroup *memcg, bool locked) {}
static inline void memcg1_oom_recover(struct mem_cgroup *memcg) {}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 298/438] net: bridge: stop fast-leave after deleting a port group
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (296 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 297/438] mm: memcg: initialize *locked in memcg1_oom_prepare() stub Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 299/438] net: ipv6: clear suppressed fib6 rule result Greg Kroah-Hartman
` (153 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Ren Wei,
Nikolay Aleksandrov, Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit a39789f211b8a4125f0c70e05b30cf715f4f187d upstream.
br_multicast_leave_group() iterates mp->ports with pp = &p->next in
its fast-leave path. After br_multicast_del_pg() removes p,
continuing the loop advances pp through the deleted entry.
If multicast-to-unicast was enabled, the bridge can hold multiple port
groups for the same port and group with different source MAC
addresses. Once multicast-to-unicast is disabled,
br_port_group_equal() matches those entries by port only. A fast leave
can then delete one entry and continue from its stale next pointer,
leaving mp->ports pointing at a deleted port group.
Fast leave only needs to remove one matching port group. Break after
br_multicast_del_pg() so the loop stops before dereferencing the
removed entry.
Fixes: 6db6f0eae605 ("bridge: multicast to unicast")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/1cf0898872ef7c72d5f4c0304414a192c6dac591.1784707712.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bridge/br_multicast.c | 1 +
1 file changed, 1 insertion(+)
--- a/net/bridge/br_multicast.c
+++ b/net/bridge/br_multicast.c
@@ -3686,6 +3686,7 @@ br_multicast_leave_group(struct net_brid
p->flags |= MDB_PG_FLAGS_FAST_LEAVE;
br_multicast_del_pg(mp, p, pp);
+ break;
}
goto out;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 299/438] net: ipv6: clear suppressed fib6 rule result
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (297 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 298/438] net: bridge: stop fast-leave after deleting a port group Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 300/438] net: pktgen: fix proc entry use-after-free Greg Kroah-Hartman
` (152 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Ren Wei,
Ido Schimmel, Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 6aea62e433fe1b586202a5fee8b5807ce635e1d7 upstream.
fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),
but leaves res->rt6 pointing at the released rt6_info.
If no later rule supplies a replacement, fib6_rule_lookup() still sees
res.rt6 and returns that stale dst to its caller. A suppressing rule can
therefore leak a released route back to rt6_lookup(), and the next put
hits rcuref_put_slowpath() from dst_release().
Clear res->rt6 when suppressing the route so suppressed lookups fall
through to the null dst instead of reusing the released one.
Fixes: cdef485217d3 ("ipv6: fix memory leak in fib6_rule_suppress")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/4b8acb7787d54e440155585dd32ebdf0bef7d122.1784710966.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/fib6_rules.c | 1 +
1 file changed, 1 insertion(+)
--- a/net/ipv6/fib6_rules.c
+++ b/net/ipv6/fib6_rules.c
@@ -308,6 +308,7 @@ INDIRECT_CALLABLE_SCOPE bool fib6_rule_s
suppress_route:
ip6_rt_put_flags(rt, flags);
+ res->rt6 = NULL;
return true;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 300/438] net: pktgen: fix proc entry use-after-free
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (298 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 299/438] net: ipv6: clear suppressed fib6 rule result Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 301/438] riscv/mm: use physical alignment for vmemmap_start_pfn Greg Kroah-Hartman
` (151 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Simon Horman,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 817ff6efdb7f484ea547218e11e17d8e43daa3b4 upstream.
pktgen_change_name() replaces pkt_dev->entry while holding t->if_lock.
pktgen_remove_device() removes the same entry before
_rem_dev_from_if_list() takes that lock.
This allows the following interleaving:
CPU 0 (NETDEV_CHANGENAME) CPU 1 (kpktgend)
if_lock(t)
proc_remove(pkt_dev->entry)
proc_remove(pkt_dev->entry)
pkt_dev->entry = proc_create_data(...)
if_unlock(t)
The kthread can pass the stale proc_dir_entry to proc_remove() after the
rename path has freed it. A reproducer with a widened race window reports:
BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80
Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67
Call Trace:
proc_remove+0x78/0x80
pktgen_remove_device.isra.0+0x11c/0x4c0
pktgen_thread_worker+0x1214/0x6bc0
kthread+0x2c6/0x3b0
Allocated by task 95:
__proc_create+0x204/0x790
proc_create_data+0x72/0xe0
pktgen_thread_write+0xd61/0x1510
Freed by task 28:
kmem_cache_free+0xcb/0x3d0
proc_free_inode+0x5b/0x80
rcu_core+0x50a/0x1850
The buggy address belongs to the object at ffff8881478fea00
which belongs to the cache proc_dir_entry of size 192
Move proc_remove() into the if_lock-protected list removal helper. Keep it
before list_del_rcu() to preserve the ordering required by add_device().
The rename path must then finish replacing the entry before removal, or
it observes that the device is no longer on the list.
Fixes: 39df232f1a9b ("[PKTGEN]: fix device name handling")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260719145740.2888967-1-nicoyip.dev@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/core/pktgen.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/net/core/pktgen.c
+++ b/net/core/pktgen.c
@@ -3972,6 +3972,7 @@ static void _rem_dev_from_if_list(struct
struct pktgen_dev *p;
if_lock(t);
+ proc_remove(pkt_dev->entry);
list_for_each_safe(q, n, &t->if_list) {
p = list_entry(q, struct pktgen_dev, list);
if (p == pkt_dev)
@@ -4001,9 +4002,6 @@ static int pktgen_remove_device(struct p
* list to determine if interface already exist, avoid race
* with proc_create_data()
*/
- proc_remove(pkt_dev->entry);
-
- /* And update the thread if_list */
_rem_dev_from_if_list(t, pkt_dev);
#ifdef CONFIG_XFRM
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 301/438] riscv/mm: use physical alignment for vmemmap_start_pfn
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (299 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 300/438] net: pktgen: fix proc entry use-after-free Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 302/438] powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() Greg Kroah-Hartman
` (150 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiakai Xu, Kiryl Shutsemau (Meta),
Albert Ou, Alexandre Ghiti, David Hildenbrand, Guo Ren,
Mike Rapoport, Muchun Song, Nam Cao, Palmer Dabbelt,
Vishal Moola (Oracle), Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiakai Xu <xujiakai2025@iscas.ac.cn>
commit 45ebe4540817cb540a59e4dc04014ac5dddc9990 upstream.
RISC-V computes vmemmap_start_pfn by rounding phys_ram_base down to
VMEMMAP_ADDR_ALIGN. That alignment must therefore be expressed in the
physical-address domain.
Commit 476849b0fba4 ("riscv/mm: align vmemmap to maximal folio size")
attempted to account for the maximal folio alignment by feeding
MAX_FOLIO_VMEMMAP_ALIGN directly into VMEMMAP_ADDR_ALIGN. However,
MAX_FOLIO_VMEMMAP_ALIGN is measured in bytes of struct page storage,
whereas VMEMMAP_ADDR_ALIGN is used to align a physical address.
The mask-based compound_info encoding requires pfn_to_page(0) to be
naturally aligned to MAX_FOLIO_VMEMMAP_ALIGN. Commit 9f94db4c7eaa
("mm/sparse: check memmap alignment for compound_info_has_mask()") added a
check for that requirement and exposed the unit mismatch on systems such
as QEMU virt, where the DRAM base is not aligned to MAX_FOLIO_NR_PAGES *
PAGE_SIZE.
Here is the log:
[ 0.000000][ C0] ------------[ cut here ]------------
[ 0.000000][ C0] WARNING: mm/sparse.c:365 at sparse_init+0x58a/0x6fe, CPU#0: swapper/0
[ 0.000000][ C0] Modules linked in:
[ 0.000000][ C0] CPU: 0 UID: 0 PID: 0 Comm: swapper Not tainted 7.2.0-rc3-g1d8304bdd65f #2 PREEMPT
[ 0.000000][ C0] Hardware name: riscv-virtio,qemu (DT)
[ 0.000000][ C0] epc : sparse_init+0x58a/0x6fe
[ 0.000000][ C0] ra : sparse_init+0x58a/0x6fe
[ 0.000000][ C0] epc : ffffffff86851c88 ra : ffffffff86851c88 sp : ffffffff88807a30
[ 0.000000][ C0] gp : ffffffff8a3bf240 tp : ffffffff88842080 t0 : ff600000ffab6000
[ 0.000000][ C0] t1 : 000000017fab6000 t2 : 65203a6573726363 s0 : ffffffff88807bc0
[ 0.000000][ C0] s1 : 000000000e000000 a0 : 0000000000000007 a1 : 0000000000000000
[ 0.000000][ C0] a2 : 0000000000000002 a3 : ffffffff86851c88 a4 : 0000000000000000
[ 0.000000][ C0] a5 : ffffffff88843080 a6 : 0000000000000003 a7 : 0000000000000000
[ 0.000000][ C0] s2 : ff60000000000000 s3 : 0040000000000000 s4 : 0004000000000000
[ 0.000000][ C0] s5 : ffffffff8a4d92e0 s6 : ff600000ffab55e0 s7 : ffffffff88384d00
[ 0.000000][ C0] s8 : 0000000000000003 s9 : ffffffff88384cc1 s10: ffffffff88384cc0
[ 0.000000][ C0] s11: ffffffff8a4daae0 t3 : ffffffff915e8b20 t4 : ffffffff915e8b20
[ 0.000000][ C0] t5 : ffffffff915e8b20 t6 : ffffffff915e8bc8 ssp : 0000000000000000
[ 0.000000][ C0] status: 0000000200000100 badaddr: ffffffff86851c88 cause: 0000000000000003
[ 0.000000][ C0] [<ffffffff86851c88>] sparse_init+0x58a/0x6fe
[ 0.000000][ C0] [<ffffffff8683d396>] mm_core_init_early+0x116/0x1e30
[ 0.000000][ C0] [<ffffffff86801edc>] start_kernel+0xd2/0x848
Convert MAX_FOLIO_VMEMMAP_ALIGN to the equivalent physical alignment
before using it in VMEMMAP_ADDR_ALIGN. This keeps the existing
round_down() logic while making the resulting vmemmap base satisfy the
mask-alignment requirement.
Link: https://lore.kernel.org/20260716115326.3466926-1-xujiakai2025@iscas.ac.cn
Fixes: 476849b0fba4 ("riscv/mm: align vmemmap to maximal folio size")
Signed-off-by: Jiakai Xu <xujiakai2025@iscas.ac.cn>
Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Cc: Albert Ou <aou@eecs.berkeley.edu>
Cc: Alexandre Ghiti <alex@ghiti.fr>
Cc: David Hildenbrand <david@kernel.org>
Cc: Guo Ren <guoren@kernel.org>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Nam Cao <namcao@linutronix.de>
Cc: Palmer Dabbelt <palmer@dabbelt.com>
Cc: Vishal Moola (Oracle) <vishal.moola@gmail.com>
Assisted-by: YuanSheng:DeepSeek-V4-Flash
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/mm/init.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/arch/riscv/mm/init.c
+++ b/arch/riscv/mm/init.c
@@ -61,7 +61,8 @@ EXPORT_SYMBOL(phys_ram_base);
#ifdef CONFIG_SPARSEMEM_VMEMMAP
#define VMEMMAP_ADDR_ALIGN max(1ULL << SECTION_SIZE_BITS, \
- MAX_FOLIO_VMEMMAP_ALIGN)
+ PFN_PHYS(MAX_FOLIO_VMEMMAP_ALIGN / \
+ sizeof(struct page)))
unsigned long vmemmap_start_pfn __ro_after_init;
EXPORT_SYMBOL(vmemmap_start_pfn);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 302/438] powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (300 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 301/438] riscv/mm: use physical alignment for vmemmap_start_pfn Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 303/438] um: vector: fix use-after-free in vector_mmsg_rx() Greg Kroah-Hartman
` (149 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Ritesh Harjani (IBM),
Geert Uytterhoeven, Madhavan Srinivasan
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
commit 0bb024f11d120abff3e8db9144a585b9d7fb8459 upstream.
If lv1_put_iopte() fails in dma_ioc0_map_pages(), the error path
decrements iopage but keeps using the failed mapping's offset. As a
result, it repeatedly tries to invalidate the failed IOPTE slot and
leaves the already installed IOPTEs valid.
Recompute offset and invalidate the installed IOPTEs instead.
Fixes: 6bb5cf102541 ("[POWERPC] PS3: System-bus rework")
Cc: stable@vger.kernel.org
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Reviewed-by: Geert Uytterhoeven <geert@linux-m68k.org>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260711130931.740719-3-thorsten.blum@linux.dev
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/powerpc/platforms/ps3/mm.c | 1 +
1 file changed, 1 insertion(+)
--- a/arch/powerpc/platforms/ps3/mm.c
+++ b/arch/powerpc/platforms/ps3/mm.c
@@ -615,6 +615,7 @@ static int dma_ioc0_map_pages(struct ps3
fail_map:
for (iopage--; 0 <= iopage; iopage--) {
+ offset = (1 << r->page_size) * iopage;
lv1_put_iopte(0,
c->bus_addr + offset,
c->lpar_addr + offset,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 303/438] um: vector: fix use-after-free in vector_mmsg_rx()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (301 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 302/438] powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 304/438] uprobes: Fix NULL pointer dereference in hprobe_expire() Greg Kroah-Hartman
` (148 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Michael Bommarito,
Richard Weinberger
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
commit af421e9aed3920c7ac88c24daa48606c7112feca upstream.
When vector_mmsg_rx() discards a packet whose overlay header fails
verify_header(), it frees the skb and continues the loop:
if (header_check < 0) {
dev_kfree_skb_irq(skb);
vp->estats.rx_encaps_errors++;
continue;
}
The normal and short-packet paths fall through to the bottom of the
loop body, which clears the consumed slot and advances the cursors:
(*skbuff_vector) = NULL;
mmsg_vector++;
skbuff_vector++;
The verify_header() < 0 path skips that via continue, so the freed skb
is left in skbuff_vector[] and the cursors do not advance. The next
iteration reads the same slot, gets the freed skb, and frees it again,
producing a refcount underflow / use-after-free in the RX path.
Discard the slot the same way the other paths do before continuing.
Only transports whose verify_header() can return negative are affected:
GRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not),
so any peer on such a transport can trigger it without authentication.
Fixes: 49da7e64f33e ("High Performance UML Vector Network Driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/um/drivers/vector_kern.c | 3 +++
1 file changed, 3 insertions(+)
--- a/arch/um/drivers/vector_kern.c
+++ b/arch/um/drivers/vector_kern.c
@@ -995,6 +995,9 @@ static int vector_mmsg_rx(struct vector_
*/
dev_kfree_skb_irq(skb);
vp->estats.rx_encaps_errors++;
+ (*skbuff_vector) = NULL;
+ mmsg_vector++;
+ skbuff_vector++;
continue;
}
if (header_check > 0) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 304/438] uprobes: Fix NULL pointer dereference in hprobe_expire()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (302 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 303/438] um: vector: fix use-after-free in vector_mmsg_rx() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 305/438] veth: convert frag_list skbs before running XDP Greg Kroah-Hartman
` (147 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Peter Zijlstra (Intel),
Oleg Nesterov, Andrii Nakryiko
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
commit cc679d7a6303e84d769f2afcde1fc51c51f127cd upstream.
Forking a task that has a pending uretprobe can oops the kernel with a
NULL pointer dereference in the clone() path:
BUG: kernel NULL pointer dereference, address: 0000000000000018
Oops: 0002 [#1] SMP NOPTI
RIP: 0010:hprobe_expire
CR2: 0000000000000018
Call Trace:
uprobe_copy_process
copy_process
kernel_clone
__x64_sys_clone
do_syscall_64
entry_SYSCALL_64_after_hwframe
This was found on real hosts on Meta fleet.
I've got the impression that this is what is happening:
CPU 1 CPU 2 (traced task)
----- -------------------
hit uprobe, prepare_uretprobe():
hprobe LEASED, refcount >= 1
uprobe_unregister()
put_uprobe(): refcount -> 0
fork() -> dup_utask()
hprobe_expire(hprobe, true)
try_get_uprobe() -> NULL
get_uprobe(NULL) <-- Oops
Only take the extra reference when the uprobe is non-NULL; a NULL means
it is gone and is the correct value to return.
Fixes: dd1a7567784e ("uprobes: SRCU-protect uretprobe lifetime (with timeout)")
Signed-off-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Oleg Nesterov <oleg@redhat.com>
Acked-by: Andrii Nakryiko <andrii@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260729-uprobe-v1-1-61896b87c867@debian.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/events/uprobes.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/kernel/events/uprobes.c
+++ b/kernel/events/uprobes.c
@@ -830,7 +830,7 @@ static struct uprobe *hprobe_expire(stru
if (try_cmpxchg(&hprobe->state, &hstate, uprobe ? HPROBE_STABLE : HPROBE_GONE)) {
/* We won the race, we are the ones to unlock SRCU */
__srcu_read_unlock(&uretprobes_srcu, hprobe->srcu_idx);
- return get ? get_uprobe(uprobe) : uprobe;
+ return get && uprobe ? get_uprobe(uprobe) : uprobe;
}
/*
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 305/438] veth: convert frag_list skbs before running XDP
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (303 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 304/438] uprobes: Fix NULL pointer dereference in hprobe_expire() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 306/438] vxlan: re-fetch eth header after route_shortcircuit() Greg Kroah-Hartman
` (146 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matt Fleming,
Toke Høiland-Jørgensen, Lorenzo Bianconi,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matt Fleming <mfleming@cloudflare.com>
commit d0d6415963040c401e7a7e4e482a698ba52448cb upstream.
A frag_list skb can reach veth with data_len set but nr_frags zero.
veth_convert_skb_to_xdp_buff() only converts skbs that are shared,
locked, have frags[], or do not have enough headroom. It later uses
skb_is_nonlinear() to decide whether to set XDP_FLAGS_HAS_FRAGS and
xdp_frags_size.
That exposes frag_list data to XDP as if it were stored in frags[], but
frags[] is empty. AF_XDP copy mode can then trust the bogus XDP fragment
metadata, walk an empty fragment entry, and crash in memcpy() from
__xsk_rcv().
Route non-linear skbs through skb_pp_cow_data() before exposing them to
XDP, and only advertise XDP frags when the resulting skb has frags[].
skb_copy_bits() already handles frag_list input, and skb_pp_cow_data()
builds frags[] output with skb_add_rx_frag(), which is the
representation XDP multi-buffer expects.
Fixes: 718a18a0c8a6 ("veth: Rework veth_xdp_rcv_skb in order to accept non-linear skb")
Cc: stable@vger.kernel.org
Signed-off-by: Matt Fleming <mfleming@cloudflare.com>
Reviewed-by: Toke Høiland-Jørgensen <toke@toke.dk>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260722191925.2192070-1-matt@readmodwrite.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/veth.c | 4 ++--
net/core/skbuff.c | 18 ++++++++++++------
2 files changed, 14 insertions(+), 8 deletions(-)
--- a/drivers/net/veth.c
+++ b/drivers/net/veth.c
@@ -756,7 +756,7 @@ static int veth_convert_skb_to_xdp_buff(
u32 frame_sz;
if (skb_shared(skb) || skb_head_is_locked(skb) ||
- skb_shinfo(skb)->nr_frags ||
+ skb_is_nonlinear(skb) ||
skb_headroom(skb) < XDP_PACKET_HEADROOM) {
if (skb_pp_cow_data(rq->page_pool, pskb, XDP_PACKET_HEADROOM))
goto drop;
@@ -771,7 +771,7 @@ static int veth_convert_skb_to_xdp_buff(
xdp_prepare_buff(xdp, skb->head, skb_headroom(skb),
skb_headlen(skb), true);
- if (skb_is_nonlinear(skb)) {
+ if (skb_shinfo(skb)->nr_frags) {
skb_shinfo(skb)->xdp_frags_size = skb->data_len;
xdp_buff_set_frags_flag(xdp);
} else {
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -925,6 +925,18 @@ static void skb_clone_fraglist(struct sk
skb_get(list);
}
+/**
+ * skb_pp_cow_data() - copy skb data into page-pool backed storage
+ * @pool: page pool to allocate from
+ * @pskb: pointer to skb pointer, replaced with the copied skb on success
+ * @headroom: headroom to reserve in the copied skb
+ *
+ * skb_copy_bits() handles both frags[] and frag_list input. If the copied
+ * skb remains non-linear, it uses frags[], which is the representation used
+ * by XDP multi-buffer.
+ *
+ * Return: 0 on success or a negative errno on failure.
+ */
int skb_pp_cow_data(struct page_pool *pool, struct sk_buff **pskb,
unsigned int headroom)
{
@@ -934,12 +946,6 @@ int skb_pp_cow_data(struct page_pool *po
int err, i, head_off;
void *data;
- /* XDP does not support fraglist so we need to linearize
- * the skb.
- */
- if (skb_has_frag_list(skb))
- return -EOPNOTSUPP;
-
max_head_size = SKB_WITH_OVERHEAD(PAGE_SIZE - headroom);
if (skb->len > max_head_size + MAX_SKB_FRAGS * PAGE_SIZE)
return -ENOMEM;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 306/438] vxlan: re-fetch eth header after route_shortcircuit()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (304 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 305/438] veth: convert frag_list skbs before running XDP Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 307/438] vxlan: unclone skb head before modifying eth header in route_shortcircuit() Greg Kroah-Hartman
` (145 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Vadim Fedorenko,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit 1395a676ec15a0a02a2a6d86602324f2d5fd41d5 upstream.
Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).
Inside route_shortcircuit(), pskb_may_pull() can be called, which may
reallocate skb->head.
In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to
freed memory, leading to a use-after-free when dereferencing eth->h_dest.
Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().
Fixes: ae8840825605 ("VXLAN: Allow L2 redirection with L3 switching")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260723144249.759100-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/vxlan/vxlan_core.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2797,6 +2797,7 @@ static netdev_tx_t vxlan_xmit(struct sk_
(ntohs(eth->h_proto) == ETH_P_IP ||
ntohs(eth->h_proto) == ETH_P_IPV6)) {
did_rsc = route_shortcircuit(dev, skb);
+ eth = eth_hdr(skb);
if (did_rsc)
f = vxlan_find_mac_tx(vxlan, eth->h_dest, vni);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 307/438] vxlan: unclone skb head before modifying eth header in route_shortcircuit()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (305 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 306/438] vxlan: re-fetch eth header after route_shortcircuit() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 308/438] vxlan: use neigh_ha_snapshot() " Greg Kroah-Hartman
` (144 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit 760d36e737f2b3867762f42af36c663f55babcc4 upstream.
When route_shortcircuit() performs L3 short-circuit routing, it modifies
the Ethernet header of the skb in-place:
memcpy(eth_hdr(skb)->h_source, eth_hdr(skb)->h_dest, dev->addr_len);
memcpy(eth_hdr(skb)->h_dest, n->ha, dev->addr_len);
If the incoming skb is cloned (for example by packet sockets, tcpdump, or
dev_queue_xmit), modifying the Ethernet header without uncloning can corrupt
the packet header for other readers holding a reference to the cloned skb.
Ensure the skb header is writable and unshared by calling skb_cow_head(skb, 0)
prior to updating the Ethernet header. If skb_cow_head() fails, abort short-circuiting
and return false to allow standard packet processing fallback.
Fixes: e4f67addf158 ("add DOVE extensions for VXLAN")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260723144249.759100-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/vxlan/vxlan_core.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2164,6 +2164,10 @@ static bool route_shortcircuit(struct ne
diff = !ether_addr_equal(eth_hdr(skb)->h_dest, n->ha);
if (diff) {
+ if (skb_cow_head(skb, 0)) {
+ neigh_release(n);
+ return false;
+ }
memcpy(eth_hdr(skb)->h_source, eth_hdr(skb)->h_dest,
dev->addr_len);
memcpy(eth_hdr(skb)->h_dest, n->ha, dev->addr_len);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 308/438] vxlan: use neigh_ha_snapshot() in route_shortcircuit()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (306 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 307/438] vxlan: unclone skb head before modifying eth header in route_shortcircuit() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 309/438] vxlan: use pskb_network_may_pull() for transmit path header pulls Greg Kroah-Hartman
` (143 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Vadim Fedorenko,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit 8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d upstream.
The neighbour hardware address n->ha can be updated asynchronously by the
neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without
holding the seqlock loop can lead to torn reads or reading a partially updated
MAC address.
Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under
read_seqbegin()/read_seqretry() lock protection before using it.
Note that arp_reduce() and neigh_reduce() seem to have the same issue
left for future patches.
Fixes: e4f67addf158 ("add DOVE extensions for VXLAN")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260723144249.759100-4-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/vxlan/vxlan_core.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2160,9 +2160,11 @@ static bool route_shortcircuit(struct ne
}
if (n) {
+ u8 haddr[ETH_ALEN];
bool diff;
- diff = !ether_addr_equal(eth_hdr(skb)->h_dest, n->ha);
+ neigh_ha_snapshot(haddr, n, dev);
+ diff = !ether_addr_equal_unaligned(eth_hdr(skb)->h_dest, haddr);
if (diff) {
if (skb_cow_head(skb, 0)) {
neigh_release(n);
@@ -2170,7 +2172,7 @@ static bool route_shortcircuit(struct ne
}
memcpy(eth_hdr(skb)->h_source, eth_hdr(skb)->h_dest,
dev->addr_len);
- memcpy(eth_hdr(skb)->h_dest, n->ha, dev->addr_len);
+ memcpy(eth_hdr(skb)->h_dest, haddr, dev->addr_len);
}
neigh_release(n);
return diff;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 309/438] vxlan: use pskb_network_may_pull() for transmit path header pulls
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (307 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 308/438] vxlan: use neigh_ha_snapshot() " Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 310/438] vxlan: use pskb_network_may_pull() in route_shortcircuit() Greg Kroah-Hartman
` (142 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Vadim Fedorenko,
Ido Schimmel, Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit b9553558b48db54ac9273e6b98d7263ef5c1a329 upstream.
In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was
being called to verify the availability of network layer headers (ARP, IPv6/ND,
IP/IPv6 MDB keys).
However, during transmit skb->data points to the MAC header, so skb_network_offset(skb)
is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data
rather than skb_network_offset(skb) + len, which can leave part of the network header
in non-linear frags.
Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly
account for the MAC header offset.
Fixes: e4f67addf158 ("add DOVE extensions for VXLAN")
Fixes: f564f45c4518 ("vxlan: add ipv6 proxy support")
Fixes: 0f83e69f44bf ("vxlan: Add MDB data path support")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260723144249.759100-6-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/vxlan/vxlan_core.c | 6 +++---
drivers/net/vxlan/vxlan_mdb.c | 4 ++--
2 files changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -1851,7 +1851,7 @@ static int arp_reduce(struct net_device
if (dev->flags & IFF_NOARP)
goto out;
- if (!pskb_may_pull(skb, arp_hdr_len(dev))) {
+ if (!pskb_network_may_pull(skb, arp_hdr_len(dev))) {
dev_dstats_tx_dropped(dev);
vxlan_vnifilter_count(vxlan, vni, NULL,
VXLAN_VNI_STATS_TX_DROPS, 0);
@@ -2764,8 +2764,8 @@ static netdev_tx_t vxlan_xmit(struct sk_
return arp_reduce(dev, skb, vni);
#if IS_ENABLED(CONFIG_IPV6)
else if (ntohs(eth->h_proto) == ETH_P_IPV6 &&
- pskb_may_pull(skb, sizeof(struct ipv6hdr) +
- sizeof(struct nd_msg)) &&
+ pskb_network_may_pull(skb, sizeof(struct ipv6hdr) +
+ sizeof(struct nd_msg)) &&
ipv6_hdr(skb)->nexthdr == IPPROTO_ICMPV6) {
struct nd_msg *m = (struct nd_msg *)(ipv6_hdr(skb) + 1);
--- a/drivers/net/vxlan/vxlan_mdb.c
+++ b/drivers/net/vxlan/vxlan_mdb.c
@@ -1631,7 +1631,7 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_
switch (skb->protocol) {
case htons(ETH_P_IP):
- if (!pskb_may_pull(skb, sizeof(struct iphdr)))
+ if (!pskb_network_may_pull(skb, sizeof(struct iphdr)))
return NULL;
group.dst.sa.sa_family = AF_INET;
group.dst.sin.sin_addr.s_addr = ip_hdr(skb)->daddr;
@@ -1640,7 +1640,7 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_
break;
#if IS_ENABLED(CONFIG_IPV6)
case htons(ETH_P_IPV6):
- if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
+ if (!pskb_network_may_pull(skb, sizeof(struct ipv6hdr)))
return NULL;
group.dst.sa.sa_family = AF_INET6;
group.dst.sin6.sin6_addr = ipv6_hdr(skb)->daddr;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 310/438] vxlan: use pskb_network_may_pull() in route_shortcircuit()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (308 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 309/438] vxlan: use pskb_network_may_pull() for transmit path header pulls Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 311/438] ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() Greg Kroah-Hartman
` (141 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Vadim Fedorenko,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit 26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb upstream.
route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr))
(or ipv6hdr), which checks if bytes are available starting from skb->data.
However, in vxlan_xmit(), skb->data points to the MAC header, so
skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20)
only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of
IP header), leaving the rest of the IP header potentially un-pulled in non-linear
frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled
linear buffer length.
Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to
the length check to ensure the full network header is present in the linear buffer.
Fixes: e4f67addf158 ("add DOVE extensions for VXLAN")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260723144249.759100-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/vxlan/vxlan_core.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2112,7 +2112,7 @@ static bool route_shortcircuit(struct ne
{
struct iphdr *pip;
- if (!pskb_may_pull(skb, sizeof(struct iphdr)))
+ if (!pskb_network_may_pull(skb, sizeof(struct iphdr)))
return false;
pip = ip_hdr(skb);
n = neigh_lookup(&arp_tbl, &pip->daddr, dev);
@@ -2138,7 +2138,7 @@ static bool route_shortcircuit(struct ne
*/
if (!ipv6_mod_enabled())
return false;
- if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
+ if (!pskb_network_may_pull(skb, sizeof(struct ipv6hdr)))
return false;
pip6 = ipv6_hdr(skb);
n = neigh_lookup(&nd_tbl, &pip6->daddr, dev);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 311/438] ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (309 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 310/438] vxlan: use pskb_network_may_pull() in route_shortcircuit() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 312/438] tracing: Check return value of __register_event() in trace_module_add_events() Greg Kroah-Hartman
` (140 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ming Lei, Caleb Sander Mateos,
Jens Axboe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ming Lei <tom.leiming@gmail.com>
commit e65848e4ce352bac9e3465099354c8b8f845391f upstream.
ublk_ctrl_add_dev() memcpy()s the userspace ublksrv_ctrl_dev_info into
ub->dev_info and then fixes up the fields the driver owns, but misses
->state and ->ublksrv_pid.
A device added with ->state = UBLK_S_DEV_LIVE passes the
"->state != UBLK_S_DEV_DEAD" test that ublk_stop_dev_unlocked() uses as its
proxy for "a disk is attached", while ->ub_disk is still NULL, so DEL_DEV
right after ADD_DEV oopses in del_gendisk(). UBLK_S_DEV_QUIESCED plus
UBLK_F_USER_RECOVERY dies one step earlier, in ublk_force_abort_dev(). A
poisoned ->state also gets START_USER_RECOVERY and the char device
read/write path onto a device that was never started, and wedges START_DEV
at -EEXIST. A poisoned ->ublksrv_pid just makes GET_DEV_INFO report an
unrelated task as the ublk server.
Reset both after the memcpy(), as ublk_detach_disk() does. Userspace only
ever reads these back, so correcting them silently breaks nothing.
ADD_DEV has copied ->state in unsanitized since ublk was merged, but back
then it was harmless: the gendisk was allocated during ADD_DEV, and both
teardown and the START_DEV -EEXIST check keyed off disk_live() rather than
->state. The oops became reachable once the disk allocation moved to
START_DEV and those checks switched to ->state.
Fixes: 6d9e6dfdf3b2 ("ublk: defer disk allocation")
Cc: stable@vger.kernel.org
Signed-off-by: Ming Lei <tom.leiming@gmail.com>
Reviewed-by: Caleb Sander Mateos <csander@purestorage.com>
Link: https://patch.msgid.link/20260726145025.1507383-1-tom.leiming@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/block/ublk_drv.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -4758,6 +4758,15 @@ static int ublk_ctrl_add_dev(const struc
ub->dev_info.dev_id = ub->ub_number;
/*
+ * ->state and ->ublksrv_pid are owned by the driver and only read back
+ * by userspace, but they come from the copied-in dev_info, so reset
+ * them. Otherwise a device added with ->state != DEAD looks live while
+ * ->ub_disk is still NULL.
+ */
+ ub->dev_info.state = UBLK_S_DEV_DEAD;
+ ub->dev_info.ublksrv_pid = -1;
+
+ /*
* 64bit flags will be copied back to userspace as feature
* negotiation result, so have to clear flags which driver
* doesn't support yet, then userspace can get correct flags
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 312/438] tracing: Check return value of __register_event() in trace_module_add_events()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (310 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 311/438] ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 313/438] tracing/filters: Fix false positive match in regex_match_full() Greg Kroah-Hartman
` (139 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Steven Rostedt
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
commit ac8719969e6c3c54e939834df812bc41f25453cf upstream.
trace_module_add_events() ignores the return value of __register_event()
and unconditionally calls __add_event_to_tracers() for each event.
If __register_event() fails (for example, if event_init() fails), the
trace_event_call is not added to ftrace_events list, but
__add_event_to_tracers() still creates a trace_event_file pointing to it.
If module loading subsequently fails and module memory is freed, tracing
state retains a stale trace_event_call pointer in trace_event_file,
leading to a use-after-free when tracefs or tracing subsystem operations
are later executed.
Fix this by checking the return value of __register_event() and only
calling __add_event_to_tracers() if event registration succeeded.
Fixes: ae63b31e4d0e ("tracing: Separate out trace events from global variables")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/178528487878.124250.14170824576025743236.stgit@devnote2
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/kernel/trace/trace_events.c
+++ b/kernel/trace/trace_events.c
@@ -3933,8 +3933,8 @@ static void trace_module_add_events(stru
end = mod->trace_events + mod->num_trace_events;
for_each_event(call, start, end) {
- __register_event(*call, mod);
- __add_event_to_tracers(*call);
+ if (!__register_event(*call, mod))
+ __add_event_to_tracers(*call);
}
update_cache_events(mod);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 313/438] tracing/filters: Fix false positive match in regex_match_full()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (311 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 312/438] tracing: Check return value of __register_event() in trace_module_add_events() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 314/438] spi: spi-qpic-snand: write the feature value before executing SET_FEATURE Greg Kroah-Hartman
` (138 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Steven Rostedt
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
commit c22c7b735f9810ad276014f788f9aa5c879ec238 upstream.
regex_match_full() calls strncmp(str, r->pattern, len) where len is the
target field buffer size. When len is smaller than r->len (the filter
pattern length), strncmp() checks only len bytes of r->pattern against
str. If those len bytes match, strncmp() returns 0, resulting in a
false-positive match where a shorter string in a fixed-size field
matches a longer filter pattern.
For example, a 4-byte static string field containing "abcd" matched the
filter pattern "abcdefgh" because strncmp("abcd", "abcdefgh", 4)
returned 0. In this case, @len does NOT include '\0' because it is
fixed-size array.
Fix this by returning 0 (no match) early when len < r->len.
Fixes: 1889d20922d1 ("tracing/filters: Provide basic regex support")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/178528488779.124250.5571741156199253769.stgit@devnote2
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events_filter.c | 3 +++
1 file changed, 3 insertions(+)
--- a/kernel/trace/trace_events_filter.c
+++ b/kernel/trace/trace_events_filter.c
@@ -1027,6 +1027,9 @@ static int regex_match_full(char *str, s
if (!len)
return strcmp(str, r->pattern) == 0;
+ if (len < r->len)
+ return 0;
+
return strncmp(str, r->pattern, len) == 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 314/438] spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (312 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 313/438] tracing/filters: Fix false positive match in regex_match_full() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 315/438] spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure Greg Kroah-Hartman
` (137 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislaw Pal, Md Sadre Alam,
Mark Brown
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Pal <kuncy7@gmail.com>
commit 8fd62901d6bf03f274a49dd0060793cc07dd51b0 upstream.
qcom_spi_send_cmdaddr() programs NAND_FLASH_CMD/NAND_EXEC_CMD and submits
the descriptors, which makes the controller execute the command
immediately. For SPINAND_SET_FEATURE the value to be written is only
placed into NAND_FLASH_FEATURES afterwards, by qcom_spi_io_op(), in a
second submission - so the chip is programmed with whatever that register
happened to hold from a previous operation, and the intended value is only
applied by the *next* SET_FEATURE.
Measured on a TP-Link Archer AX55 v1 (IPQ5018, ESMT F50L1G41LB): writing
0x40 to the configuration register (0xb0) leaves the chip at 0x00, and the
subsequent write of 0x00 leaves it at 0x40 - every write lands one
operation late.
This stayed unnoticed until v6.18 added SPI-NAND OTP support together
with OTP entries for ESMT chips. spinand_otp_rw() enables OTP mode,
reads, and disables it again, and mtd_otp_nvmem_add() does this during
MTD registration. With the off-by-one, the "disable" write actually
applies the previously requested value, so CFG_OTP_ENABLE ends up set:
the chip stays in OTP mode, every subsequent array read returns the OTP
area instead of the array (UBI reports an empty device) and all writes
fail with -EIO because the OTP area is write protected. On this board
that makes the whole flash unusable and the device unbootable.
Write the feature value into NAND_FLASH_FEATURES as part of the same
transaction, before NAND_EXEC_CMD. While at it, copy only the bytes the
operation actually carries - the previous code dereferenced a 4-byte
pointer on a one-byte buffer (spinand->scratchbuf).
With this patch the flash contents read back bit-identical to a
known-good dump of the same board taken under the vendor firmware
(md5-verified across partitions), and writes work.
Fixes: 7304d1909080 ("spi: spi-qpic: add driver for QCOM SPI NAND flash Interface")
Cc: stable@vger.kernel.org
Signed-off-by: Stanislaw Pal <kuncy7@gmail.com>
Reviewed-by: Md Sadre Alam <md.alam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260727163216.109938-1-kuncy7@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-qpic-snand.c | 22 ++++++++++++++++++----
1 file changed, 18 insertions(+), 4 deletions(-)
--- a/drivers/spi/spi-qpic-snand.c
+++ b/drivers/spi/spi-qpic-snand.c
@@ -1358,6 +1358,22 @@ static int qcom_spi_send_cmdaddr(struct
snandc->regs->addr0 = cpu_to_le32(op->addr.val);
snandc->regs->addr1 = cpu_to_le32(0);
+ /*
+ * The feature value has to reach NAND_FLASH_FEATURES before the
+ * command is executed, otherwise the controller programs the chip
+ * with whatever the register happened to hold from a previous
+ * operation.
+ */
+ if (opcode == SPINAND_SET_FEATURE) {
+ u32 ftr = 0;
+
+ memcpy(&ftr, op->data.buf.out,
+ min_t(size_t, op->data.nbytes, sizeof(ftr)));
+ snandc->regs->flash_feature = cpu_to_le32(ftr);
+ qcom_write_reg_dma(snandc, &snandc->regs->flash_feature,
+ NAND_FLASH_FEATURES, 1, NAND_BAM_NEXT_SGL);
+ }
+
qcom_write_reg_dma(snandc, &snandc->regs->cmd, NAND_FLASH_CMD, 3, NAND_BAM_NEXT_SGL);
qcom_write_reg_dma(snandc, &snandc->regs->exec, NAND_EXEC_CMD, 1, NAND_BAM_NEXT_SGL);
@@ -1395,10 +1411,8 @@ static int qcom_spi_io_op(struct qcom_na
copy_ftr = true;
break;
case SPINAND_SET_FEATURE:
- snandc->regs->flash_feature = cpu_to_le32(*(u32 *)op->data.buf.out);
- qcom_write_reg_dma(snandc, &snandc->regs->flash_feature,
- NAND_FLASH_FEATURES, 1, NAND_BAM_NEXT_SGL);
- break;
+ /* fully handled by qcom_spi_send_cmdaddr() */
+ return 0;
case SPINAND_PROGRAM_EXECUTE:
case SPINAND_WRITE_EN:
case SPINAND_RESET:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 315/438] spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (313 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 314/438] spi: spi-qpic-snand: write the feature value before executing SET_FEATURE Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 316/438] selftests/mm: fix potential wild pointer access of getline due to missing init Greg Kroah-Hartman
` (136 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vijaya Krishna Nivarthi, Mark Brown
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijaya Krishna Nivarthi <vijaya.nivarthi@oss.qualcomm.com>
commit 90ef2f2961c2dc55957dafe2f53b3efdb4675efc upstream.
The maximum size for a DMA data descriptor is 64KB-1 because the size
field in HW is 16 bits wide. For this reason, transfers fail at 64KB
and beyond.
Lower max_dma_len to 60KB so larger transfers are split into multiple
DMA blocks and do not hit the failing 64KB boundary. 60KB is chosen as
a safe round number below the 64KB-1 hardware limit while satisfying
alignment requirements.
Tested on x1e80100 (Hamoa) with SPI-NOR flash (/dev/mtd0):
Without patch:
dd if=/dev/mtd0 of=/tmp/spi_dump.bin bs=32768 count=2 # works
dd if=/dev/mtd0 of=/tmp/spi_dump.bin bs=65536 count=1 # fails
With patch:
dd if=/dev/mtd0 of=/tmp/spi_dump.bin bs=65536 count=1 # works
Fixes: b5762d95607e ("spi: spi-qcom-qspi: Add DMA mode support")
Cc: stable@vger.kernel.org
Signed-off-by: Vijaya Krishna Nivarthi <vijaya.nivarthi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260722092358.459943-1-vnivarth@qti.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-qcom-qspi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/spi/spi-qcom-qspi.c
+++ b/drivers/spi/spi-qcom-qspi.c
@@ -759,7 +759,8 @@ static int qcom_qspi_probe(struct platfo
return dev_err_probe(dev, ret, "could not set DMA mask\n");
host->max_speed_hz = 300000000;
- host->max_dma_len = 65536; /* as per HPG */
+ /* as per HPG, it is 64KB, limit to 60KB to avoid boundary condition failures */
+ host->max_dma_len = 0xf000;
host->dma_alignment = QSPI_ALIGN_REQ;
host->num_chipselect = QSPI_NUM_CS;
host->bus_num = -1;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 316/438] selftests/mm: fix potential wild pointer access of getline due to missing init
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (314 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 315/438] spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 317/438] selftests/clone3: fix " Greg Kroah-Hartman
` (135 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Gellermann,
David Hildenbrand (arm), Lorenzo Stoakes, Christian Brauner,
Liam R. Howlett, Michal Hocko, Mike Rapoport, Shuah Khan,
Suren Baghdasaryan, Vlastimil Babka, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Gellermann <christian.gellermann@codasip.com>
commit 9f1d75a4ce04095afdb63d8e540092ff8151dacf upstream.
This is another occurrence of using getline where the code assumes that
getline allocates memory to store the line, but the pointer passed to it
is uninitialized and potentially a non-null pointer. This violates the
Open Group Spec[1] and caused a segfault in a similar situation in
selftest/clone3/clone3_set_tid. Fix it by initializing the line pointer
to NULL.
The issue has been found by simply grepping through the selftest code
after running into the issue in clone3_set_tid. Whether it segfaults in
its current state is unknown to me. But it's good to be addressed due to
defensive reasons.
Link: https://lore.kernel.org/20260722130246.2135563-3-christian.gellermann@codasip.com
Link: https://pubs.opengroup.org/onlinepubs/9799919799/functions/getline.html [1]
Fixes: 26b4224d9961 ("selftests: expanding more mlock selftest")
Signed-off-by: Chris Gellermann <christian.gellermann@codasip.com>
Acked-by: David Hildenbrand (arm) <david@kernel.org>
Reviewed-by: Lorenzo Stoakes <ljs@kernel.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/mm/mlock-random-test.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/testing/selftests/mm/mlock-random-test.c
+++ b/tools/testing/selftests/mm/mlock-random-test.c
@@ -84,7 +84,7 @@ int get_proc_locked_vm_size(void)
int get_proc_page_size(unsigned long addr)
{
FILE *smaps;
- char *line;
+ char *line = NULL;
unsigned long mmupage_size = 0;
size_t size;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 317/438] selftests/clone3: fix wild pointer access of getline due to missing init
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (315 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 316/438] selftests/mm: fix potential wild pointer access of getline due to missing init Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 318/438] scsi: libsas: terminate deferred commands on time out Greg Kroah-Hartman
` (134 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Gellermann,
David Hildenbrand (arm), Lorenzo Stoakes, Christian Brauner,
Liam R. Howlett, Michal Hocko, Mike Rapoport, Shuah Khan,
Suren Baghdasaryan, Vlastimil Babka, Andrew Morton
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Gellermann <christian.gellermann@codasip.com>
commit 8f6f9fd93cd7a5dd607ad5cd910476dd68fff3ed upstream.
Patch series "selftests: Add missing initalization of pointer passed to
getline", v2.
This patch (of 2):
Clone3_set_tid uses getline(&line, ...) in a loop to read the child's
process status. The code expects that getline allocates the buffer for
the line on the first loop iteration. According to the Open Group
Spec[1], char *line has to be null pointer for this:
> ssize_t getline(char **restrict lineptr, ...);
> If *lineptr is a null pointer or if the object pointed to by *lineptr
> is of insufficient size, an object shall be allocated as if by
malloc()
> or the object shall be reallocated as if by realloc()[...].
However, char *line is only declared, leading to an undefined value that
is potentially non-null. In an example run with Musl v1.2.6, the realloc
call[2] of getdelim, which implements getline, triggers a segfault:
./run_kselftest.sh --test clone3:clone3_set_tid
[ 1366.165898] kselftest: Running tests in clone3
...
[ 1367.799244] clone3_set_tid[811]: unhandled signal 11 code 0x1 at
0x0000000000000000 in libc.so[68184,3fbf69f000+4c000]
[ 1367.802808] CPU: 0 UID: 0 PID: 811 Comm: clone3_set_tid Not tainted
..
[ 1367.804188] epc: 0x0000003fbf6b0184
[ 1367.804188] ra : 0x0000003fbf6d4664
[ 1367.804188] sp : 0x0000003fce5f2e40
[ 1367.805314] gp : 0x0000002aaab0dfb8
[ 1367.805314] tp : 0x0000003fbf6f14a8
[ 1367.805314] t0 : 0x0000003fbf63d000
...
Looking at the realloc implementation, Musl mallocs for a null pointer
memory. But for a non-null pointer, it assumes it's passed a valid
pointer to the heap and tries to access its meta-data. This leads to the
segfault we see:
void *realloc(void *p, size_t n)
{
if (!p) return malloc(n);
if (size_overflows(n)) return 0;
struct meta *g = get_meta(p);
...
}
Fix this by properly initializing the line pointer to NULL.
Link: https://lore.kernel.org/20260722130246.2135563-1-christian.gellermann@codasip.com
Link: https://lore.kernel.org/20260722130246.2135563-2-christian.gellermann@codasip.com
Link: https://pubs.opengroup.org/onlinepubs/9799919799/functions/getline.html [1]
Link: https://git.musl-libc.org/cgit/musl/tree/src/stdio/getdelim.c#n38 [2]
Fixes: 41585bbeeef9 ("selftests: add tests for clone3() with *set_tid")
Signed-off-by: Chris Gellermann <christian.gellermann@codasip.com>
Acked-by: David Hildenbrand (arm) <david@kernel.org>
Reviewed-by: Lorenzo Stoakes <ljs@kernel.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/clone3/clone3_set_tid.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/testing/selftests/clone3/clone3_set_tid.c
+++ b/tools/testing/selftests/clone3/clone3_set_tid.c
@@ -141,7 +141,7 @@ int main(int argc, char *argv[])
{
FILE *f;
char buf;
- char *line;
+ char *line = NULL;
int status;
int ret = -1;
size_t len = 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 318/438] scsi: libsas: terminate deferred commands on time out
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (316 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 317/438] selftests/clone3: fix " Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 319/438] scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write Greg Kroah-Hartman
` (133 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Igor Pylypiv, Damien Le Moal,
John Garry, Hannes Reinecke, Niklas Cassel, Martin K. Petersen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damien Le Moal <dlemoal@kernel.org>
commit de202d2251bc181c6019b1ad3c0ba8133e5ec68d upstream.
If a command times out while we have deferred non-NCQ commands waiting to
be issued, the SCSI EH task is not immediately woken up as the waiting
deferred commands are never issued nor completed, thus leaving the SCSI
host in a busy state (shost->host_failed != scsi_host_busy(shost)) which
prevents the SCSI EH task from being woken up. Eventually, when the
deferred commands also time out, the SCSI EH task is woken up and the
timeout processing occurs.
Avoid this unnecessary additional SCSI EH wake up time with the same
method as implemented in libata-scsi, using the eh_timed_out SCSI host
template operation. The function sas_eh_timed_out() implements this
operation and executes the function ata_scsi_retry_deferred_qc()
for SATA devices.
Co-developed-by: Igor Pylypiv <ipylypiv@google.com>
Signed-off-by: Igor Pylypiv <ipylypiv@google.com>
Fixes: 0ea84089dbf6 ("ata: libata-scsi: avoid Non-NCQ command starvation")
Cc: stable@vger.kernel.org
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Tested-by: Igor Pylypiv <ipylypiv@google.com>
Reviewed-by: Niklas Cassel <cassel@kernel.org>
Reviewed-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libata-scsi.c | 5 +++--
drivers/scsi/libsas/sas_scsi_host.c | 15 +++++++++++++++
include/linux/libata.h | 2 ++
include/scsi/libsas.h | 2 ++
4 files changed, 22 insertions(+), 2 deletions(-)
--- a/drivers/ata/libata-scsi.c
+++ b/drivers/ata/libata-scsi.c
@@ -1784,8 +1784,8 @@ static void ata_scsi_schedule_deferred_q
queue_work(system_highpri_wq, &link->deferred_qc_work);
}
-static enum scsi_timeout_action
-ata_scsi_retry_deferred_qc(struct ata_port *ap, struct scsi_cmnd *scmd)
+enum scsi_timeout_action ata_scsi_retry_deferred_qc(struct ata_port *ap,
+ struct scsi_cmnd *scmd)
{
enum scsi_timeout_action action;
unsigned long flags;
@@ -1796,6 +1796,7 @@ ata_scsi_retry_deferred_qc(struct ata_po
return action;
}
+EXPORT_SYMBOL_GPL(ata_scsi_retry_deferred_qc);
enum scsi_timeout_action ata_scsi_eh_timed_out(struct scsi_cmnd *scmd)
{
--- a/drivers/scsi/libsas/sas_scsi_host.c
+++ b/drivers/scsi/libsas/sas_scsi_host.c
@@ -502,6 +502,21 @@ int sas_eh_target_reset_handler(struct s
}
EXPORT_SYMBOL_GPL(sas_eh_target_reset_handler);
+/*
+ * Handle deferred QCs in case of a command timeout.
+ * See ata_scsi_eh_timed_out() for details.
+ */
+enum scsi_timeout_action sas_eh_timed_out(struct scsi_cmnd *cmd)
+{
+ struct domain_device *dev = cmd_to_domain_dev(cmd);
+
+ if (dev_is_sata(dev))
+ return ata_scsi_retry_deferred_qc(dev->sata_dev.ap, cmd);
+
+ return SCSI_EH_NOT_HANDLED;
+}
+EXPORT_SYMBOL_GPL(sas_eh_timed_out);
+
/* Try to reset a device */
static int try_to_reset_cmd_device(struct scsi_cmnd *cmd)
{
--- a/include/linux/libata.h
+++ b/include/linux/libata.h
@@ -1152,6 +1152,8 @@ extern int ata_scsi_ioctl(struct scsi_de
#endif
extern enum scsi_qc_status ata_scsi_queuecmd(struct Scsi_Host *h,
struct scsi_cmnd *cmd);
+enum scsi_timeout_action ata_scsi_retry_deferred_qc(struct ata_port *ap,
+ struct scsi_cmnd *scmd);
enum scsi_timeout_action ata_scsi_eh_timed_out(struct scsi_cmnd *cmd);
#if IS_REACHABLE(CONFIG_ATA)
bool ata_scsi_dma_need_drain(struct request *rq);
--- a/include/scsi/libsas.h
+++ b/include/scsi/libsas.h
@@ -704,6 +704,7 @@ void sas_task_abort(struct sas_task *);
int sas_eh_abort_handler(struct scsi_cmnd *cmd);
int sas_eh_device_reset_handler(struct scsi_cmnd *cmd);
int sas_eh_target_reset_handler(struct scsi_cmnd *cmd);
+enum scsi_timeout_action sas_eh_timed_out(struct scsi_cmnd *cmd);
extern void sas_target_destroy(struct scsi_target *);
extern int sas_sdev_init(struct scsi_device *);
@@ -742,6 +743,7 @@ void sas_notify_phy_event(struct asd_sas
.this_id = -1, \
.eh_device_reset_handler = sas_eh_device_reset_handler, \
.eh_target_reset_handler = sas_eh_target_reset_handler, \
+ .eh_timed_out = sas_eh_timed_out, \
.target_destroy = sas_target_destroy, \
.ioctl = sas_ioctl, \
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 319/438] scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (317 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 318/438] scsi: libsas: terminate deferred commands on time out Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 320/438] scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc Greg Kroah-Hartman
` (132 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Ibrahim Hashimov,
Bart Van Assche, Martin K. Petersen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ibrahim Hashimov <security@auditcode.ai>
commit 93dde0bf2f39a0f9f57fd610aa3201ce5b753433 upstream.
resp_report_zones() sizes the reply buffer from the CDB allocation
length. The v3 fix rounds alloc_len up with ALIGN() before deriving the
descriptor count:
rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -
RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);
arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);
For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to
0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit
and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which
passes the !arr check, and desc = arr + 64 is then dereferenced in the
loop -> out-of-bounds write / panic.
Clamp rep_max_zones to devip->nr_zones. The loop already stops at
sdebug_capacity (after nr_zones zones), so a report can never hold more
than nr_zones descriptors; the clamp does not change the report, it only
bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device
property that can never reach 0x100000000.
Fixes: 7db0e0c8190a ("scsi: scsi_debug: Fix buffer size of REPORT ZONES command")
Suggested-by: Damien Le Moal <dlemoal@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Assisted-by: AuditCode-AI:2026.07
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260712183739.83915-1-security@auditcode.ai
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/scsi_debug.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/scsi/scsi_debug.c
+++ b/drivers/scsi/scsi_debug.c
@@ -5898,6 +5898,7 @@ static int resp_report_zones(struct scsi
u32 alloc_len, rep_opts, rep_len;
bool partial;
u64 lba, zs_lba;
+ u64 arr_len;
u8 *arr = NULL, *desc;
u8 *cmd = scp->cmnd;
struct sdeb_zone_state *zsp = NULL;
@@ -5919,9 +5920,12 @@ static int resp_report_zones(struct scsi
return check_condition_result;
}
- rep_max_zones = (alloc_len - 64) >> ilog2(RZONES_DESC_HD);
+ rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >>
+ ilog2(RZONES_DESC_HD);
+ rep_max_zones = min_t(unsigned int, rep_max_zones, devip->nr_zones);
+ arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);
- arr = kzalloc(alloc_len, GFP_ATOMIC | __GFP_NOWARN);
+ arr = kzalloc(arr_len, GFP_ATOMIC | __GFP_NOWARN);
if (!arr) {
mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
INSUFF_RES_ASCQ);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 320/438] scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (318 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 319/438] scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 321/438] sctp: reject stale cookies with mismatched verification tags Greg Kroah-Hartman
` (131 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shawn Guo, Krzysztof Kozlowski,
Martin K. Petersen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shawn Guo <shengchao.guo@oss.qualcomm.com>
commit 4d5282c06ca198319c2de41b10511ddcb8068f42 upstream.
Qualcomm UFS controller found on SoCs SA8255P/SA8797P has a MCQ I/O address
space. It should be defined in the bindings even though Linux driver
currently doesn't utilize it. Fix the binding before it gets adopted by
DTS.
Fixes: e2725ed2a7fb ("scsi: ufs: dt-bindings: Document bindings for SA8255P UFS Host Controller")
Cc: stable@vger.kernel.org
Signed-off-by: Shawn Guo <shengchao.guo@oss.qualcomm.com>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://patch.msgid.link/20260720023552.2667237-1-shengchao.guo@oss.qualcomm.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Documentation/devicetree/bindings/ufs/qcom,sa8255p-ufshc.yaml | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
--- a/Documentation/devicetree/bindings/ufs/qcom,sa8255p-ufshc.yaml
+++ b/Documentation/devicetree/bindings/ufs/qcom,sa8255p-ufshc.yaml
@@ -14,7 +14,14 @@ properties:
const: qcom,sa8255p-ufshc
reg:
- maxItems: 1
+ minItems: 1
+ maxItems: 2
+
+ reg-names:
+ minItems: 1
+ items:
+ - const: std
+ - const: mcq
interrupts:
maxItems: 1
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 321/438] sctp: reject stale cookies with mismatched verification tags
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (319 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 320/438] scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 322/438] sctp: prevent peer transport count overflow Greg Kroah-Hartman
` (130 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuxiang Yang, Xin Long,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuxiang Yang <yangyx22@mails.tsinghua.edu.cn>
commit 9d8da8e0a9bce4a340af60dd0446bc7eb8d07587 upstream.
sctp_unpack_cookie() skips cookie expiration checks whenever an
association already exists. This is broader than the exception in
RFC 9260 Section 5.2.4.
For an existing association, Section 5.2.4 permits an expired State
Cookie only when both Verification Tags in the cookie match the current
association. Otherwise, the packet SHOULD be discarded and a Stale
Cookie ERROR MUST be sent.
The broad check lets an expired Action A restart cookie reach
sctp_sf_do_dupcook_a(). In a runtime test with the default 60 second
cookie lifetime, replaying such a cookie after 65 seconds returned a
COOKIE-ACK and restarted the association.
Check cookie expiration unless both Verification Tags match. This
preserves the Action D exception for a lost COOKIE ACK while rejecting
expired cookies in all other cases.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Yuxiang Yang <yangyx22@mails.tsinghua.edu.cn>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260723225623.2658868-1-yangyx22@mails.tsinghua.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sctp/sm_make_chunk.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@ -1802,9 +1802,9 @@ struct sctp_association *sctp_unpack_coo
goto fail;
}
- /* Check to see if the cookie is stale. If there is already
- * an association, there is no need to check cookie's expiration
- * for init collision case of lost COOKIE ACK.
+ /* Check to see if the cookie is stale. RFC 9260 Section 5.2.4
+ * exempts an expired cookie only when both Verification Tags match
+ * the current association.
* If skb has been timestamped, then use the stamp, otherwise
* use current time. This introduces a small possibility that
* a cookie may be considered expired, but this would only slow
@@ -1815,7 +1815,10 @@ struct sctp_association *sctp_unpack_coo
else
kt = ktime_get_real();
- if (!asoc && ktime_before(bear_cookie->expiration, kt)) {
+ if ((!asoc ||
+ asoc->c.my_vtag != bear_cookie->my_vtag ||
+ asoc->c.peer_vtag != bear_cookie->peer_vtag) &&
+ ktime_before(bear_cookie->expiration, kt)) {
suseconds_t usecs = ktime_to_us(ktime_sub(kt, bear_cookie->expiration));
__be32 n = htonl(usecs);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 322/438] sctp: prevent peer transport count overflow
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (320 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 321/438] sctp: reject stale cookies with mismatched verification tags Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 323/438] hwmon: (npcm750-pwm-fan): stop fan timer on device detach Greg Kroah-Hartman
` (129 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Asim Viladi Oglu Manizada, Xin Long,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Asim Viladi Oglu Manizada <manizada@pm.me>
commit bd0e9289e2642f6a5c54faad304ce0f41e926d22 upstream.
sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.
SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.
Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.
Fixes: 8f840e47f190 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sctp/associola.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -614,6 +614,9 @@ struct sctp_transport *sctp_assoc_add_pe
return peer;
}
+ if (asoc->peer.transport_count == U16_MAX)
+ return NULL;
+
peer = sctp_transport_new(asoc->base.net, addr, gfp);
if (!peer)
return NULL;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 323/438] hwmon: (npcm750-pwm-fan): stop fan timer on device detach
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (321 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 322/438] sctp: prevent peer transport count overflow Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 324/438] hwmon: (pmbus/core) notify on the hwmon device, not the i2c client Greg Kroah-Hartman
` (128 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hongyan Xu, Guenter Roeck
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongyan Xu <getshell@seu.edu.cn>
commit f27f6976ea269219c1259a7c2f8c6dfe782540a3 upstream.
When a fan tach channel is present, npcm7xx_pwm_fan_probe() starts
fan_timer. The timer callback polls tach state and rearms the timer, but
the driver has no remove callback or devm cleanup action to stop it. On
device detach, the devm-managed driver data and I/O mappings can be
released while the timer is still pending or running.
Register a devm cleanup action before starting the timer and shut the
timer down synchronously from that action.
This issue was found by a static analysis tool.
Fixes: f1fd4a4db777 ("hwmon: Add NPCM7xx PWM and Fan driver")
Cc: stable@vger.kernel.org
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Link: https://lore.kernel.org/r/20260729100116.790-1-getshell@seu.edu.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/npcm750-pwm-fan.c | 11 +++++++++++
1 file changed, 11 insertions(+)
--- a/drivers/hwmon/npcm750-pwm-fan.c
+++ b/drivers/hwmon/npcm750-pwm-fan.c
@@ -358,6 +358,11 @@ static void npcm7xx_fan_polling(struct t
add_timer(&data->fan_timer);
}
+static void npcm7xx_fan_cleanup(void *timer)
+{
+ timer_shutdown_sync(timer);
+}
+
static inline void npcm7xx_fan_compute(struct npcm7xx_pwm_fan_data *data,
u8 fan, u8 cmp, u8 fan_id, u8 flag_int,
u8 flag_mode, u8 flag_clear)
@@ -1018,6 +1023,12 @@ static int npcm7xx_pwm_fan_probe(struct
msecs_to_jiffies(NPCM7XX_FAN_POLL_TIMER_200MS);
timer_setup(&data->fan_timer,
npcm7xx_fan_polling, 0);
+ ret = devm_add_action_or_reset(dev,
+ npcm7xx_fan_cleanup,
+ &data->fan_timer);
+ if (ret)
+ return ret;
+
add_timer(&data->fan_timer);
break;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 324/438] hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (322 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 323/438] hwmon: (npcm750-pwm-fan): stop fan timer on device detach Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 325/438] i2c: amd-mp2: Unregister callback on adapter add failure Greg Kroah-Hartman
` (127 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vincent Jardin, Guenter Roeck
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Jardin <vjardin@free.fr>
commit a64a7e8a0b012ba81b0eadbd7afc84ab0dbfd70c upstream.
pmbus_notify() calls sysfs_notify() and kobject_uevent() on the i2c
client's kobject, but the alarm attributes live on the hwmon class
device registered by pmbus_do_probe(). Notifying the parent i2c device
is a no-op for both poll(POLLPRI) waiters and udev listeners: the named
attribute does not exist on that kobject.
Notify the hwmon device instead, so poll() wakes up and "change"
uevents fire on the inX_alarm/tempX_alarm attributes when SMBALERT#
reports a fault.
Fixes: f469bde9afd1 ("hwmon: (pmbus/core) Notify hwmon events")
Cc: stable@vger.kernel.org # v6.4+
Signed-off-by: Vincent Jardin <vjardin@free.fr>
Link: https://lore.kernel.org/r/20260723-fix_hwmon_notify_v1-v1-1-5a24c528686d@free.fr
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/pmbus_core.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/hwmon/pmbus/pmbus_core.c
+++ b/drivers/hwmon/pmbus/pmbus_core.c
@@ -2985,8 +2985,9 @@ static void pmbus_notify(struct pmbus_da
if (reg == sreg && page == spage && (smask & flags)) {
dev_dbg(data->dev, "sysfs notify: %s", da->attr.name);
- sysfs_notify(&data->dev->kobj, NULL, da->attr.name);
- kobject_uevent(&data->dev->kobj, KOBJ_CHANGE);
+ sysfs_notify(&data->hwmon_dev->kobj, NULL,
+ da->attr.name);
+ kobject_uevent(&data->hwmon_dev->kobj, KOBJ_CHANGE);
flags &= ~smask;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 325/438] i2c: amd-mp2: Unregister callback on adapter add failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (323 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 324/438] hwmon: (pmbus/core) notify on the hwmon device, not the i2c client Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound Greg Kroah-Hartman
` (126 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 82048795242f04275a3f49ffc66ad851b6120954 upstream.
amd_mp2_register_cb() stores the platform I2C context in the MP2 PCI
driver's callback table before the adapter is registered. If
i2c_add_adapter() fails, probe returns and devres frees the context,
but the PCI driver can still dereference the stale pointer from its IRQ
and system-sleep callbacks.
Unregister the callback before returning the adapter registration error.
Fixes: 529766e0a011 ("i2c: Add drivers for the AMD PCIe MP2 I2C controller")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Cc: <stable@vger.kernel.org> # v5.2+
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260721144147.31150-1-mhun512@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-amd-mp2-plat.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/i2c/busses/i2c-amd-mp2-plat.c
+++ b/drivers/i2c/busses/i2c-amd-mp2-plat.c
@@ -316,8 +316,10 @@ static int i2c_amd_probe(struct platform
amd_mp2_pm_runtime_put(mp2_dev);
- if (ret < 0)
+ if (ret < 0) {
dev_err(&pdev->dev, "i2c add adapter failed = %d\n", ret);
+ amd_mp2_unregister_cb(&i2c_dev->common);
+ }
return ret;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (324 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 325/438] i2c: amd-mp2: Unregister callback on adapter add failure Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-08 9:05 ` Thorsten Leemhuis
2026-08-07 14:38 ` [PATCH 7.1 327/438] gpiolib: tolerate gpio-hogs lacking a hogging state Greg Kroah-Hartman
` (125 subsequent siblings)
451 siblings, 1 reply; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello, Andy Shevchenko,
Hardik Prakash, Bartosz Golaszewski, Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hardik Prakash <hardikprakash.official@gmail.com>
commit 0a4bb2abc3e56d7be6e69b050c88ba52c87e22bf upstream.
I2C controllers may have child devices with GpioInt resources that
depend on GPIO controllers being fully initialized. If the I2C
controller probes and enumerates children before the referenced GPIO
controller has completed probe, GPIO interrupts may not be properly
configured, leading to device failures.
On Lenovo Yoga 7 14AGP11, the WACF2200 touchscreen (child of
AMDI0010:02) has a GpioInt resource pointing to GPIO 157 on the
pinctrl-amd controller (AMDI0030:00). When i2c-designware probes
AMDI0010:02 before pinctrl-amd finishes initializing, I2C transactions
fail with lost arbitration errors:
0.285952 amd_gpio_probe: registering gpiochip <- GPIO chip visible
0.287121 amd_gpio_probe: requesting parent IRQ <- probe still running
0.301454 AMDI0010:02 dw_i2c_plat_probe: start <- races here
2.348157 lost arbitration
Add a dependency check that walks ACPI child devices and defers probe
until any referenced GPIO controller is bound.
Fixes: 3812a9e84265 ("pinctrl-amd: enable IRQ for WACF2200 touchscreen on Lenovo Yoga 7 14AGP11")
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221494
Suggested-by: Mario Limonciello <mario.limonciello@amd.com>
Suggested-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Signed-off-by: Hardik Prakash <hardikprakash.official@gmail.com>
Assisted-by: Claude:claude-sonnet-5
Assisted-by: DeepSeek:deepseek-v4-pro
Cc: <stable@vger.kernel.org> # v7.1+
Acked-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260718054330.8975-2-hardikprakash.official@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-designware-platdrv.c | 80 ++++++++++++++++++++++++++++
1 file changed, 80 insertions(+)
--- a/drivers/i2c/busses/i2c-designware-platdrv.c
+++ b/drivers/i2c/busses/i2c-designware-platdrv.c
@@ -8,12 +8,14 @@
* Copyright (C) 2007 MontaVista Software Inc.
* Copyright (C) 2009 Provigent Ltd.
*/
+#include <linux/acpi.h>
#include <linux/clk-provider.h>
#include <linux/clk.h>
#include <linux/delay.h>
#include <linux/dmi.h>
#include <linux/err.h>
#include <linux/errno.h>
+#include <linux/gpio/driver.h>
#include <linux/i2c.h>
#include <linux/interrupt.h>
#include <linux/io.h>
@@ -130,6 +132,80 @@ static int i2c_dw_probe_lock_support(str
return 0;
}
+#if defined(CONFIG_ACPI) && defined(CONFIG_GPIOLIB)
+/*
+ * Check whether an ACPI GpioInt resource's referenced GPIO controller
+ * has finished probing. Resources with no named controller (resource
+ * source string) are skipped, since they can't be resolved to a
+ * struct device.
+ */
+static int check_gpioint_resource(struct acpi_resource *ares, void *data)
+{
+ struct acpi_resource_gpio *agpio;
+ struct acpi_device *gpio_adev;
+ struct device *gpio_dev;
+ acpi_handle handle;
+ acpi_status status;
+
+ if (!acpi_gpio_get_irq_resource(ares, &agpio))
+ return 1; /* not a GpioInt resource, skip */
+
+ if (!agpio->resource_source.string_length)
+ return 1; /* no named controller, skip */
+
+ status = acpi_get_handle(NULL, agpio->resource_source.string_ptr, &handle);
+ if (ACPI_FAILURE(status))
+ return 1;
+
+ gpio_adev = acpi_fetch_acpi_dev(handle);
+ if (!gpio_adev)
+ return 1;
+
+ struct gpio_device *gdev __free(gpio_device_put) =
+ gpio_device_find_by_fwnode(acpi_fwnode_handle(gpio_adev));
+ if (!gdev)
+ return -EPROBE_DEFER; /* controller not registered yet: abort walk */
+
+ gpio_dev = gpio_device_to_device(gdev)->parent;
+
+ guard(device)(gpio_dev);
+ if (!device_is_bound(gpio_dev))
+ return -EPROBE_DEFER; /* controller not bound yet: abort walk */
+
+ return 1; /* bound, skip adding to resource list, continue walk */
+}
+
+static int check_child_gpioint(struct acpi_device *adev, void *data)
+{
+ LIST_HEAD(res_list);
+ int ret;
+
+ ret = acpi_dev_get_resources(adev, &res_list, check_gpioint_resource, NULL);
+ if (ret < 0)
+ return ret;
+
+ acpi_dev_free_resource_list(&res_list);
+
+ return 0;
+}
+
+static int i2c_dw_check_gpio_dependencies(struct device *dev)
+{
+ struct acpi_device *adev;
+
+ adev = ACPI_COMPANION(dev);
+ if (!adev)
+ return 0;
+
+ return acpi_dev_for_each_child(adev, check_child_gpioint, NULL);
+}
+#else
+static int i2c_dw_check_gpio_dependencies(struct device *dev)
+{
+ return 0;
+}
+#endif /* CONFIG_ACPI && CONFIG_GPIOLIB */
+
static int dw_i2c_plat_probe(struct platform_device *pdev)
{
u32 flags = (uintptr_t)device_get_match_data(&pdev->dev);
@@ -138,6 +214,10 @@ static int dw_i2c_plat_probe(struct plat
struct dw_i2c_dev *dev;
int irq, ret;
+ ret = i2c_dw_check_gpio_dependencies(device);
+ if (ret)
+ return ret;
+
irq = platform_get_irq_optional(pdev, 0);
if (irq == -ENXIO)
flags |= ACCESS_POLLING;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 327/438] gpiolib: tolerate gpio-hogs lacking a hogging state
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (325 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 328/438] gpio: pca953x: fix cache_only and IRQ state on restore_context() failure Greg Kroah-Hartman
` (124 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Golle, Andy Shevchenko,
Bartosz Golaszewski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Golle <daniel@makrotopia.org>
commit e1cc8fa0fb9e5112d15f2c310b68ac316981c06c upstream.
Commit d1d564ec4992 ("gpio: move hogs into GPIO core") made
gpiochip_add_hog() return -EINVAL for hog nodes lacking any of the
'input', 'output-low' or 'output-high' properties. The error is
propagated by gpiochip_hog_lines() and fails registration of the
whole GPIO chip.
The previous OF-specific implementation tolerated such nodes:
of_parse_own_gpio() warned "no hogging state specified, bailing out"
and of_gpiochip_add_hog() stopped processing the node without failing
chip registration.
Some boards deliberately ship hog nodes without a hogging state in
their base devicetree and supply the state via overlay, e.g. the PCIe
slot key selection hogs on the BananaPi R4 Pro added in
commit e309fa232d12 ("arm64: dts: mediatek: mt7988a-bpi-r4pro: rework
pcie gpio-hog handling"), as the polarity set in the base devicetree
could not be overridden from an overlay.
Booting such a board without an overlay applied now fails to register
the gpiochip. On the BananaPi R4 Pro this means the MT7988A pinctrl
device fails to probe, all peripherals including the console UART
defer forever, and the board finally hangs when clk_disable_unused()
gates the clocks of the UART still in use by earlycon:
gpiochip_add_data_with_key: GPIOs 512..595 (pinctrl_moore) failed to register, -22
mt7988-pinctrl 1001f000.pinctrl: error -EINVAL: Failed to add gpio_chip
...
clk: Disabling unused clocks
(hangs)
Restore the previous behaviour by warning about hog nodes lacking a
hogging state and skipping them instead of failing the registration
of the whole GPIO chip.
Fixes: d1d564ec4992 ("gpio: move hogs into GPIO core")
Cc: stable@vger.kernel.org
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://patch.msgid.link/4c67cf0839ccf57db35a826df6d8fc779531509a.1783974733.git.daniel@makrotopia.org
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpiolib.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
--- a/drivers/gpio/gpiolib.c
+++ b/drivers/gpio/gpiolib.c
@@ -975,14 +975,17 @@ int gpiochip_add_hog(struct gpio_chip *g
if (ret < 0)
return ret;
- if (fwnode_property_present(fwnode, "input"))
+ if (fwnode_property_present(fwnode, "input")) {
dflags |= GPIOD_IN;
- else if (fwnode_property_present(fwnode, "output-low"))
+ } else if (fwnode_property_present(fwnode, "output-low")) {
dflags |= GPIOD_OUT_LOW;
- else if (fwnode_property_present(fwnode, "output-high"))
+ } else if (fwnode_property_present(fwnode, "output-high")) {
dflags |= GPIOD_OUT_HIGH;
- else
- return -EINVAL;
+ } else {
+ gpiochip_warn(gc, "%pfwP: no hogging state specified, bailing out\n",
+ fwnode);
+ return 0;
+ }
fwnode_property_read_string(fwnode, "line-name", &name);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 328/438] gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (326 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 327/438] gpiolib: tolerate gpio-hogs lacking a hogging state Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 329/438] gpio: pch: use raw_spinlock_t for the register lock Greg Kroah-Hartman
` (123 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linus Walleij, bui duc phuc,
Bartosz Golaszewski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: bui duc phuc <phucduc.bui@gmail.com>
commit d233087c19f6607ef926ac3f47d776e2406ffd1f upstream.
When pca953x_restore_context() fails, cache_only is left disabled and
the IRQ left enabled, even though register synchronization may not have
completed successfully. Restore cache_only and disable the IRQ again on
failure, matching the state set by pca953x_save_context().
Fixes: ec5bde62019b ("gpio: pca953x: Split pca953x_restore_context() and pca953x_save_context()")
Fixes: 3e38f946062b ("gpio: pca953x: fix IRQ storm on system wake up")
Cc: stable@vger.kernel.org
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: bui duc phuc <phucduc.bui@gmail.com>
Link: https://patch.msgid.link/20260727080205.16353-1-phucduc.bui@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-pca953x.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
--- a/drivers/gpio/gpio-pca953x.c
+++ b/drivers/gpio/gpio-pca953x.c
@@ -1373,9 +1373,20 @@ static int pca953x_restore_context(struc
regcache_mark_dirty(chip->regmap);
ret = pca953x_regcache_sync(chip);
if (ret)
- return ret;
+ goto err;
- return regcache_sync(chip->regmap);
+ ret = regcache_sync(chip->regmap);
+ if (ret)
+ goto err;
+
+ return 0;
+
+err:
+ if (chip->client->irq > 0)
+ disable_irq(chip->client->irq);
+ regcache_cache_only(chip->regmap, true);
+
+ return ret;
}
static void pca953x_save_context(struct pca953x_chip *chip)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 329/438] gpio: pch: use raw_spinlock_t for the register lock
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (327 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 328/438] gpio: pca953x: fix cache_only and IRQ state on restore_context() failure Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 330/438] cifs: add fscache_resize_cookie() to cifs_setsize() Greg Kroah-Hartman
` (122 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junjie Cao, Linus Walleij,
Bartosz Golaszewski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junjie Cao <junjie.cao@intel.com>
commit a02b8950d619123da64f69b70fe1dadef217dfe4 upstream.
pch_irq_type() is registered as the irq_chip .irq_set_type callback and
takes chip->spinlock with spin_lock_irqsave(). This callback is reached
from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while
the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.
That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is
an rtmutex-backed sleeping lock, so acquiring it there is invalid.
This was confirmed on a PREEMPT_RT kernel with lockdep
(PROVE_RAW_LOCK_NESTING and DEBUG_ATOMIC_SLEEP). A grounded PoC mirrored
pch_irq_type()'s locking and drove it through the real genirq carrier
irq_set_irq_type() -> __irq_set_trigger() -> chip->irq_set_type(), i.e.
the same __irq_set_trigger() edge that __setup_irq() takes for a
requested IRQ. With the original spin_lock_irqsave() edge lockdep
reported an invalid wait context, immediately followed by:
BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48
in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 95, name: insmod
hardirqs last disabled at (3784): _raw_spin_lock_irqsave+0x4f/0x60
rt_spin_lock+0x3a/0x1c0
repro_irq_set_type+0x64/0xa0 [pch_repro]
__irq_set_trigger+0x69/0x140
irq_set_irq_type+0x78/0xd0
Switching the mirrored lock to raw_spinlock_t made both splats go away.
Convert the register lock to raw_spinlock_t. The same lock also
serializes the GPIO direction/value callbacks and the suspend/resume
register save/restore, but all of those critical sections only perform
MMIO register accesses (ioread32()/iowrite32()) and
irq_set_handler_locked(); none of them contain sleepable operations.
Keeping this register lock non-sleeping is therefore appropriate for the
irqchip callbacks and does not change the GPIO-side locking contract.
This is the same class of issue and fix as recently addressed for other
GPIO controllers, e.g. commit 286533cb14a3 ("gpio: sch: use raw_spinlock_t
in the irq startup path") and commit 90f0109019e6 ("gpio: eic-sprd: use
raw_spinlock_t in the irq startup path").
Fixes: 38eb18a6f92d ("gpio-pch: Support interrupt function")
Cc: stable@vger.kernel.org
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260723014129.1129730-1-junjie.cao@intel.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-pch.c | 28 ++++++++++++++--------------
1 file changed, 14 insertions(+), 14 deletions(-)
--- a/drivers/gpio/gpio-pch.c
+++ b/drivers/gpio/gpio-pch.c
@@ -96,7 +96,7 @@ struct pch_gpio {
struct pch_gpio_reg_data pch_gpio_reg;
int irq_base;
enum pch_type_t ioh;
- spinlock_t spinlock;
+ raw_spinlock_t spinlock;
};
static int pch_gpio_set(struct gpio_chip *gpio, unsigned int nr, int val)
@@ -105,7 +105,7 @@ static int pch_gpio_set(struct gpio_chip
struct pch_gpio *chip = gpiochip_get_data(gpio);
unsigned long flags;
- spin_lock_irqsave(&chip->spinlock, flags);
+ raw_spin_lock_irqsave(&chip->spinlock, flags);
reg_val = ioread32(&chip->reg->po);
if (val)
reg_val |= BIT(nr);
@@ -113,7 +113,7 @@ static int pch_gpio_set(struct gpio_chip
reg_val &= ~BIT(nr);
iowrite32(reg_val, &chip->reg->po);
- spin_unlock_irqrestore(&chip->spinlock, flags);
+ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
return 0;
}
@@ -133,7 +133,7 @@ static int pch_gpio_direction_output(str
u32 reg_val;
unsigned long flags;
- spin_lock_irqsave(&chip->spinlock, flags);
+ raw_spin_lock_irqsave(&chip->spinlock, flags);
reg_val = ioread32(&chip->reg->po);
if (val)
@@ -147,7 +147,7 @@ static int pch_gpio_direction_output(str
pm |= BIT(nr);
iowrite32(pm, &chip->reg->pm);
- spin_unlock_irqrestore(&chip->spinlock, flags);
+ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
return 0;
}
@@ -158,12 +158,12 @@ static int pch_gpio_direction_input(stru
u32 pm;
unsigned long flags;
- spin_lock_irqsave(&chip->spinlock, flags);
+ raw_spin_lock_irqsave(&chip->spinlock, flags);
pm = ioread32(&chip->reg->pm);
pm &= BIT(gpio_pins[chip->ioh]) - 1;
pm &= ~BIT(nr);
iowrite32(pm, &chip->reg->pm);
- spin_unlock_irqrestore(&chip->spinlock, flags);
+ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
return 0;
}
@@ -265,7 +265,7 @@ static int pch_irq_type(struct irq_data
return 0;
}
- spin_lock_irqsave(&chip->spinlock, flags);
+ raw_spin_lock_irqsave(&chip->spinlock, flags);
/* Set interrupt mode */
im = ioread32(im_reg) & ~(PCH_IM_MASK << (im_pos * 4));
@@ -277,7 +277,7 @@ static int pch_irq_type(struct irq_data
else if (type & IRQ_TYPE_EDGE_BOTH)
irq_set_handler_locked(d, handle_edge_irq);
- spin_unlock_irqrestore(&chip->spinlock, flags);
+ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
return 0;
}
@@ -374,7 +374,7 @@ static int pch_gpio_probe(struct pci_dev
chip->ioh = id->driver_data;
chip->reg = chip->base;
pci_set_drvdata(pdev, chip);
- spin_lock_init(&chip->spinlock);
+ raw_spin_lock_init(&chip->spinlock);
pch_gpio_setup(chip);
ret = devm_gpiochip_add_data(dev, &chip->gpio, chip);
@@ -407,9 +407,9 @@ static int pch_gpio_suspend(struct devic
struct pch_gpio *chip = dev_get_drvdata(dev);
unsigned long flags;
- spin_lock_irqsave(&chip->spinlock, flags);
+ raw_spin_lock_irqsave(&chip->spinlock, flags);
pch_gpio_save_reg_conf(chip);
- spin_unlock_irqrestore(&chip->spinlock, flags);
+ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
return 0;
}
@@ -419,11 +419,11 @@ static int pch_gpio_resume(struct device
struct pch_gpio *chip = dev_get_drvdata(dev);
unsigned long flags;
- spin_lock_irqsave(&chip->spinlock, flags);
+ raw_spin_lock_irqsave(&chip->spinlock, flags);
iowrite32(0x01, &chip->reg->reset);
iowrite32(0x00, &chip->reg->reset);
pch_gpio_restore_reg_conf(chip);
- spin_unlock_irqrestore(&chip->spinlock, flags);
+ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
return 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 330/438] cifs: add fscache_resize_cookie() to cifs_setsize()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (328 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 329/438] gpio: pch: use raw_spinlock_t for the register lock Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 331/438] cpufreq: cppc: Sanitize lockless policy limit snapshots Greg Kroah-Hartman
` (121 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Howells, Paulo Alcantara,
Huiwen He, Frank Sorenson, Steve French
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit fa724e235cfdb0fb0bb427d0f9dfe864ae27403e upstream.
Several code paths update the VFS inode size by calling
netfs_resize_file() and cifs_setsize(), but omit the corresponding
fscache_resize_cookie() call, leaving the fscache cookie out of sync
with the actual file size:
- cifs_file_set_size() in inode.c: server-side truncation via setattr
- cifs_do_truncate() in file.c: truncates to zero on O_TRUNC open
- smb2_duplicate_extents() in smb2ops.c: file clone extending EOF
- smb3_simple_falloc() in smb2ops.c: two branches that extend EOF
via write-range and SMB2_set_eof respectively
Since every caller of cifs_setsize() must resize the fscache cookie,
add the call to cifs_setsize() itself, consistent with how
truncate_pagecache() is already consolidated there.
Fixes: 70431bfd825d ("cifs: Support fscache indexing rewrite")
Fixes: 93a43155127f ("cifs: Fix missing set of remote_i_size")
Fixes: 110fee6b9bb5 ("smb: client: fix missing timestamp updates with O_TRUNC")
Fixes: 7a06d3b816d7 ("smb/client: emulate small EOF-extending mode 0 fallocate ranges")
Cc: stable@vger.kernel.org
Cc: David Howells <dhowells@redhat.com>
Cc: Paulo Alcantara <pc@manguebit.org>
Cc: Huiwen He <hehuiwen@kylinos.cn>
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/inode.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/inode.c
+++ b/fs/smb/client/inode.c
@@ -3051,6 +3051,7 @@ void cifs_setsize(struct inode *inode, l
inode_set_mtime_to_ts(inode, inode_set_ctime_current(inode));
truncate_pagecache(inode, offset);
netfs_wait_for_outstanding_io(inode);
+ fscache_resize_cookie(cifs_inode_cookie(inode), offset);
}
int cifs_file_set_size(const unsigned int xid, struct dentry *dentry,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 331/438] cpufreq: cppc: Sanitize lockless policy limit snapshots
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (329 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 330/438] cifs: add fscache_resize_cookie() to cifs_setsize() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 332/438] cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() Greg Kroah-Hartman
` (120 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Loehle, Rafael J. Wysocki
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Loehle <christian.loehle@arm.com>
commit 9753c0ab89b7516aba4884dc3cc725ca33c2e3da upstream.
cppc_cpufreq_update_perf_limits() reads policy->min and policy->max
without holding the policy lock. The cpufreq core updates those fields
with separate stores, so a reader can observe the old minimum together
with the new maximum and construct MIN_PERF greater than MAX_PERF.
Read both fields once and, if the lockless snapshot is inconsistent,
reduce the minimum to the observed maximum. This matches the conservative
correction used by cpufreq_driver_resolve_freq() and ensures that CPPC
never receives an inverted limit pair.
Fixes: ea3db45ae476 ("cpufreq: cppc: Update MIN_PERF/MAX_PERF in target callbacks")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Loehle <christian.loehle@arm.com>
Link: https://patch.msgid.link/20260722093825.1030594-3-christian.loehle@arm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/cpufreq/cppc_cpufreq.c | 31 ++++++++++++++++++++++---------
1 file changed, 22 insertions(+), 9 deletions(-)
--- a/drivers/cpufreq/cppc_cpufreq.c
+++ b/drivers/cpufreq/cppc_cpufreq.c
@@ -290,19 +290,32 @@ static inline void cppc_freq_invariance_
}
#endif /* CONFIG_ACPI_CPPC_CPUFREQ_FIE */
-static void cppc_cpufreq_update_perf_limits(struct cppc_cpudata *cpu_data,
- struct cpufreq_policy *policy)
+static void cppc_cpufreq_get_perf_limits(struct cppc_cpudata *cpu_data,
+ struct cpufreq_policy *policy,
+ u32 *min_perf, u32 *max_perf)
{
struct cppc_perf_caps *caps = &cpu_data->perf_caps;
- u32 min_perf, max_perf;
+ unsigned int min_freq, max_freq;
+ u32 min, max;
+
+ min_freq = READ_ONCE(policy->min);
+ max_freq = READ_ONCE(policy->max);
+ if (unlikely(min_freq > max_freq))
+ min_freq = max_freq;
+
+ min = cppc_khz_to_perf(caps, min_freq);
+ max = cppc_khz_to_perf(caps, max_freq);
- min_perf = cppc_khz_to_perf(caps, policy->min);
- max_perf = cppc_khz_to_perf(caps, policy->max);
+ *min_perf = clamp_t(u32, min, caps->lowest_perf, caps->highest_perf);
+ *max_perf = clamp_t(u32, max, caps->lowest_perf, caps->highest_perf);
+}
- cpu_data->perf_ctrls.min_perf =
- clamp_t(u32, min_perf, caps->lowest_perf, caps->highest_perf);
- cpu_data->perf_ctrls.max_perf =
- clamp_t(u32, max_perf, caps->lowest_perf, caps->highest_perf);
+static void cppc_cpufreq_update_perf_limits(struct cppc_cpudata *cpu_data,
+ struct cpufreq_policy *policy)
+{
+ cppc_cpufreq_get_perf_limits(cpu_data, policy,
+ &cpu_data->perf_ctrls.min_perf,
+ &cpu_data->perf_ctrls.max_perf);
}
static int cppc_cpufreq_set_target(struct cpufreq_policy *policy,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 332/438] cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (330 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 331/438] cpufreq: cppc: Sanitize lockless policy limit snapshots Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 333/438] cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized Greg Kroah-Hartman
` (119 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Viresh Kumar,
Zhongqiu Han, Rafael J. Wysocki
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
commit d5f8e5f6040d052d44fcbf4f31dd35145c0c8d7d upstream.
The memory allocated for data->powernow_table inside
powernow_k8_cpu_init_acpi() or find_psb_table() is not freed in one of
the error paths in powernowk8_cpu_init(). Fix that by adding a kfree().
Fixes: 1ff6e97f1d99 ("[CPUFREQ] cpumask: avoid playing with cpus_allowed in powernow-k8.c")
Cc: stable@vger.kernel.org
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Acked-by: Viresh Kumar <viresh.kumar@linaro.org>
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Link: https://patch.msgid.link/20260727093553.98246-1-nihaal@cse.iitm.ac.in
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/cpufreq/powernow-k8.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/cpufreq/powernow-k8.c
+++ b/drivers/cpufreq/powernow-k8.c
@@ -1083,6 +1083,7 @@ static int powernowk8_cpu_init(struct cp
err_out_exit_acpi:
powernow_k8_cpu_exit_acpi(data);
+ kfree(data->powernow_table);
err_out:
kfree(data);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 333/438] cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (331 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 332/438] cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 334/438] power: supply: bq25890: fix the -10 C NTC lookup entry Greg Kroah-Hartman
` (118 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Christian Loehle,
Rafael J. Wysocki
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
commit f0a3f042293a8c5a2152346b3637ea60866c503a upstream.
Commit 16a03c71bba0 ("cpufreq: schedutil: Merge initialization code of
sg_cpu in single loop") merged the per-CPU initialization and the
utilization-hook registration into a single loop in sugov_start().
For a shared cpufreq policy this re-introduces the race originally fixed
by commit ab2f7cf141aa ("cpufreq: schedutil: Fix sugov_start() versus
sugov_update_shared() race").
The scheduler's util path reaches the hook under RCU-sched and never takes
policy->rwsem, so the rwsem held across sugov_start() cannot serialize the
two. Once the first CPU's hook is published, sugov_update_shared() may run
and, via sugov_next_freq_shared(), read/write each sibling sugov_cpu
(iowait_boost, util, bw_min, ...) concurrently with the memset() still
initializing them, with no lock common to both sides: the update side holds
sg_policy->update_lock while the init side holds only policy->rwsem, which
the scheduler's util path never takes.
The walk only accesses scalar members, never a pointer like ->sg_policy,
so it does not crash today; it merely uses stale (or zero on first start)
values that skew the frequency selection and tracepoints. It is still a
genuine data race, and a latent crash once any pointer member is
dereferenced there.
Restore the two-phase approach: initialize all per-CPU structures first,
and only then publish the per-CPU utilization update hooks.
Fixes: 16a03c71bba0 ("cpufreq: schedutil: Merge initialization code of sg_cpu in single loop")
Cc: stable@vger.kernel.org
Signed-off-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Reviewed-by: Christian Loehle <christian.loehle@arm.com>
Link: https://patch.msgid.link/20260716115159.848403-1-zhongqiu.han@oss.qualcomm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/sched/cpufreq_schedutil.c | 11 +++++++++++
1 file changed, 11 insertions(+)
--- a/kernel/sched/cpufreq_schedutil.c
+++ b/kernel/sched/cpufreq_schedutil.c
@@ -870,8 +870,19 @@ static int sugov_start(struct cpufreq_po
memset(sg_cpu, 0, sizeof(*sg_cpu));
sg_cpu->cpu = cpu;
sg_cpu->sg_policy = sg_policy;
+ }
+
+ /*
+ * Publish the hooks only after all per-CPU data is initialized, so a
+ * shared policy's sugov_update_shared() never reads an uninitialized
+ * sibling sugov_cpu.
+ */
+ for_each_cpu(cpu, policy->cpus) {
+ struct sugov_cpu *sg_cpu = &per_cpu(sugov_cpu, cpu);
+
cpufreq_add_update_util_hook(cpu, &sg_cpu->update_util, uu);
}
+
return 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 334/438] power: supply: bq25890: fix the -10 C NTC lookup entry
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (332 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 333/438] cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 335/438] power: supply: macsmc: Support macOS 27 SMC firmware Greg Kroah-Hartman
` (117 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Sebastian Reichel
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Rao <raoxu@uniontech.com>
commit 160a783aa65b74782bc17cb874af1a6d3f5fba3c upstream.
The TSPCT lookup table is monotonically decreasing except for ADC code
121, where the sequence reads -9.0 C, -1.0 C, -12.0 C. This makes the
reported battery temperature jump upward by eight degrees for one code
and then downward by eleven degrees for the next code.
The entry is a missing zero: use -10.0 C so the sequence remains
monotonic between -9.0 C and -12.0 C.
Fixes: 9652c02428f3 ("power: bq25890: add POWER_SUPPLY_PROP_TEMP")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Link: https://patch.msgid.link/0619C8BF15F43B7C+20260723065444.1796002-1-raoxu@uniontech.com
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/supply/bq25890_charger.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/power/supply/bq25890_charger.c
+++ b/drivers/power/supply/bq25890_charger.c
@@ -320,7 +320,7 @@ static const u32 bq25890_tspct_tbl[] = {
145, 140, 130, 120, 115, 110, 100, 90,
80, 70, 60, 50, 40, 30, 20, 10,
0, -10, -20, -30, -40, -60, -70, -80,
- -90, -10, -120, -140, -150, -170, -190, -210,
+ -90, -100, -120, -140, -150, -170, -190, -210,
};
#define BQ25890_TSPCT_TBL_SIZE ARRAY_SIZE(bq25890_tspct_tbl)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 335/438] power: supply: macsmc: Support macOS 27 SMC firmware
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (333 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 334/438] power: supply: bq25890: fix the -10 C NTC lookup entry Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 16:06 ` Joshua Peisach
2026-08-07 14:38 ` [PATCH 7.1 336/438] power: supply: max17040: handle missing status supplier Greg Kroah-Hartman
` (116 subsequent siblings)
451 siblings, 1 reply; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sven Peter, Joshua Peisach,
Janne Grunau, Sasha Finkelstein, Sebastian Reichel
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sasha Finkelstein <k@chaosmail.tech>
commit f7b253a6e217f71d754d70c525e9b4c1dcbd4414 upstream.
The SMC firmware included in macOS 27 changed the size of BCF0 key from
4 to 1 bytes. This key is used for indicating that battery state is
critically low. In addition, B0RM key has changed endianness.
Reviewed-by: Sven Peter <sven@kernel.org>
Reviewed-by: Joshua Peisach <jpeisach@ubuntu.com>
Reviewed-by: Janne Grunau <j@jannau.net>
Cc: stable@vger.kernel.org
Fixes: 0ebf821cf6c7 ("power: supply: Add macsmc-power driver for Apple Silicon")
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
Link: https://patch.msgid.link/20260712-gate-power-v4-1-aa59c6583247@chaosmail.tech
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/supply/macsmc-power.c | 52 +++++++++++++++++++++++++++++++-----
1 file changed, 45 insertions(+), 7 deletions(-)
--- a/drivers/power/supply/macsmc-power.c
+++ b/drivers/power/supply/macsmc-power.c
@@ -86,6 +86,11 @@ struct macsmc_power {
bool has_ch0i; /* Force discharge (Older firmware) */
bool has_ch0c; /* Inhibit charge (Older firmware) */
bool has_chte; /* Inhibit charge (Modern firmware) */
+ /*
+ * Battery critical key is 1 byte and charge key is little endian
+ * (Modern firmware)
+ */
+ bool fw_ge_27;
u8 num_cells;
int nominal_voltage_mv;
@@ -273,6 +278,20 @@ static int macsmc_battery_get_date(const
return 0;
}
+static int macsmc_battery_read_bcf0(struct macsmc_power *power, u32 *val)
+{
+ u8 tval = 0;
+ int ret;
+
+ if (power->fw_ge_27) {
+ ret = apple_smc_read_u8(power->smc, SMC_KEY(BCF0), &tval);
+ *val = tval;
+ return ret;
+ }
+
+ return apple_smc_read_u32(power->smc, SMC_KEY(BCF0), val);
+}
+
static int macsmc_battery_get_capacity_level(struct macsmc_power *power)
{
bool flag;
@@ -280,7 +299,7 @@ static int macsmc_battery_get_capacity_l
int ret;
/* Check for emergency shutdown condition */
- if (apple_smc_read_u32(power->smc, SMC_KEY(BCF0), &val) >= 0 && val)
+ if (macsmc_battery_read_bcf0(power, &val) >= 0 && val)
return POWER_SUPPLY_CAPACITY_LEVEL_CRITICAL;
/* Check AC status for whether we could boot in this state */
@@ -303,6 +322,12 @@ static int macsmc_battery_get_capacity_l
return POWER_SUPPLY_CAPACITY_LEVEL_NORMAL;
}
+static s16 macsmc_swap_b0rm(struct macsmc_power *power, s16 b0rm)
+{
+ /* B0RM was Big Endian, likely pass through from TI gas gauge */
+ return power->fw_ge_27 ? b0rm : (s16)swab16(b0rm);
+}
+
static int macsmc_battery_get_property(struct power_supply *psy,
enum power_supply_property psp,
union power_supply_propval *val)
@@ -397,8 +422,7 @@ static int macsmc_battery_get_property(s
break;
case POWER_SUPPLY_PROP_CHARGE_NOW:
ret = apple_smc_read_u16(power->smc, SMC_KEY(B0RM), &vu16);
- /* B0RM is Big Endian, likely pass through from TI gas gauge */
- val->intval = (s16)swab16(vu16) * 1000;
+ val->intval = macsmc_swap_b0rm(power, vu16) * 1000;
break;
case POWER_SUPPLY_PROP_ENERGY_FULL_DESIGN:
ret = apple_smc_read_u16(power->smc, SMC_KEY(B0DC), &vu16);
@@ -410,8 +434,7 @@ static int macsmc_battery_get_property(s
break;
case POWER_SUPPLY_PROP_ENERGY_NOW:
ret = apple_smc_read_u16(power->smc, SMC_KEY(B0RM), &vu16);
- /* B0RM is Big Endian, likely pass through from TI gas gauge */
- val->intval = (s16)swab16(vu16) * power->nominal_voltage_mv;
+ val->intval = macsmc_swap_b0rm(power, vu16) * power->nominal_voltage_mv;
break;
case POWER_SUPPLY_PROP_TEMP:
ret = apple_smc_read_u16(power->smc, SMC_KEY(B0AT), &vu16);
@@ -577,7 +600,7 @@ static void macsmc_power_critical_work(s
* Check if SMC flagged the battery as empty.
* We trigger a graceful shutdown to let the OS save data.
*/
- if (apple_smc_read_u32(power->smc, SMC_KEY(BCF0), &bcf0) == 0 && bcf0 != 0) {
+ if (macsmc_battery_read_bcf0(power, &bcf0) == 0 && bcf0 != 0) {
power->orderly_shutdown_triggered = true;
dev_crit(power->dev, "Battery critical (empty flag set). Triggering orderly shutdown.\n");
orderly_poweroff(true);
@@ -616,6 +639,7 @@ static int macsmc_power_probe(struct pla
struct device *dev = &pdev->dev;
struct apple_smc *smc = dev_get_drvdata(pdev->dev.parent);
struct power_supply_config psy_cfg = {};
+ struct apple_smc_key_info info;
struct macsmc_power *power;
bool has_battery = false;
bool has_ac_adapter = false;
@@ -714,6 +738,20 @@ static int macsmc_power_probe(struct pla
if (apple_smc_key_exists(smc, SMC_KEY(CH0I)))
power->has_ch0i = true;
+ ret = apple_smc_get_key_info(power->smc, SMC_KEY(BCF0), &info);
+ if (ret) {
+ dev_err(&pdev->dev, "Failed to determine BCF0 key size\n");
+ return ret;
+ }
+ if (info.size == 1)
+ power->fw_ge_27 = true;
+ else if (info.size == 4)
+ power->fw_ge_27 = false;
+ else {
+ dev_err(&pdev->dev, "Unexpected BCF0 key size %d\n", info.size);
+ return -EIO;
+ }
+
/* Reset "Optimised Battery Charging" flags to default state */
if (power->has_chte)
apple_smc_write_u32(smc, SMC_KEY(CHTE), 0);
@@ -766,7 +804,7 @@ static int macsmc_power_probe(struct pla
power->nominal_voltage_mv = MACSMC_NOMINAL_CELL_VOLTAGE_MV * power->num_cells;
/* Enable critical shutdown notifications by reading status once */
- apple_smc_read_u32(power->smc, SMC_KEY(BCF0), &val32);
+ macsmc_battery_read_bcf0(power, &val32);
psy_cfg.drv_data = power;
power->batt = devm_power_supply_register(dev, &power->batt_desc, &psy_cfg);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 336/438] power: supply: max17040: handle missing status supplier
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (334 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 335/438] power: supply: macsmc: Support macOS 27 SMC firmware Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 337/438] s390/pci: Fix s390_pci_mmio_write syscall error return without MIO Greg Kroah-Hartman
` (115 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jianing Li, Sebastian Reichel
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jianing Li <m13940358460@163.com>
commit 725668c6b6aa3971fe850659102c250d0d676e18 upstream.
MAX17040 does not report charger state itself, so the driver forwards
POWER_SUPPLY_PROP_STATUS to a supplier power supply. If no supplier is
registered, power_supply_get_property_from_supplier() returns -ENODEV and
leaves the output value untouched.
max17040_get_property() currently ignores that error and returns success,
so userspace can read an uninitialized status value from the battery power
supply. This happens on systems that use the fuel gauge without a charger
supplier relationship in firmware.
Return POWER_SUPPLY_STATUS_UNKNOWN when no supplier provides STATUS, and
propagate other supplier lookup errors.
Fixes: f4b782af61ae ("power: max17040: pass status property from supplier")
Cc: stable@vger.kernel.org # 6.7+
Signed-off-by: Jianing Li <m13940358460@163.com>
Link: https://patch.msgid.link/20260701061042.1008-1-m13940358460@163.com
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/supply/max17040_battery.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/power/supply/max17040_battery.c
+++ b/drivers/power/supply/max17040_battery.c
@@ -405,7 +405,11 @@ static int max17040_get_property(struct
val->intval = chip->low_soc_alert;
break;
case POWER_SUPPLY_PROP_STATUS:
- power_supply_get_property_from_supplier(psy, psp, val);
+ ret = power_supply_get_property_from_supplier(psy, psp, val);
+ if (ret == -ENODEV)
+ val->intval = POWER_SUPPLY_STATUS_UNKNOWN;
+ else if (ret)
+ return ret;
break;
case POWER_SUPPLY_PROP_TEMP:
if (!chip->channel_temp)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 337/438] s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (335 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 336/438] power: supply: max17040: handle missing status supplier Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 338/438] s390/qeth: Check CAP_NET_ADMIN for private ioctls Greg Kroah-Hartman
` (114 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Ruess, Farhan Ali,
Niklas Schnelle, Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Schnelle <schnelle@linux.ibm.com>
commit b7ab86bdc65eadcfc43a0e3faf682a3f750cfb96 upstream.
On a machine without PCI memory-I/O (MIO) support or when running with
pci=nomio the s390 specific PCI MMIO write syscall checks if the MMIO
cookie is above ZPCI_IOMAP_ADDR_BASE as a sanity check before even
trying to perform the MMIO. If this check fails the return value was
left unchanged and thus 0 from prior operations falsely indicating
success. This could potentially confuse user-space into falsely
believing the MMIO, on a mapping not valid for MMIO was successful.
Fix this by setting the return value to -EFAULT prior to the check
following the same pattern as elsewhere in the same function.
Cc: stable@vger.kernel.org
Reviewed-by: Julian Ruess <julianr@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Fixes: a67a88b0b8de ("s390/pci: remove races against pte updates")
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/pci/pci_mmio.c | 1 +
1 file changed, 1 insertion(+)
--- a/arch/s390/pci/pci_mmio.c
+++ b/arch/s390/pci/pci_mmio.c
@@ -188,6 +188,7 @@ SYSCALL_DEFINE3(s390_pci_mmio_write, uns
goto out_unlock_mmap;
}
+ ret = -EFAULT;
io_addr = (void __iomem *)((args.pfn << PAGE_SHIFT) |
(mmio_addr & ~PAGE_MASK));
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 338/438] s390/qeth: Check CAP_NET_ADMIN for private ioctls
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (336 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 337/438] s390/pci: Fix s390_pci_mmio_write syscall error return without MIO Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 339/438] s390/dasd: Fix potential NULL pointer dereference Greg Kroah-Hartman
` (113 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Alexandra Winter, Aswin Karuvally, Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aswin Karuvally <aswin@linux.ibm.com>
commit d211028bac1bd0fff0026bfa2a8328e5b78cd0e6 upstream.
Gate the SIOCDEVPRIVATE ioctl commands SIOC_QETH_ADP_SET_SNMP_CONTROL,
SIOC_QETH_GET_CARD_TYPE and SIOC_QETH_QUERY_OAT with CAP_NET_ADMIN
capable check to ensure unprivileged users cannot invoke them.
Fixes: 18787eeebd71 ("qeth: use ndo_siocdevprivate")
Cc: stable@vger.kernel.org
Suggested-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Signed-off-by: Aswin Karuvally <aswin@linux.ibm.com>
Link: https://patch.msgid.link/20260723140050.762991-1-aswin@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/net/qeth_core_main.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/s390/net/qeth_core_main.c
+++ b/drivers/s390/net/qeth_core_main.c
@@ -6525,6 +6525,9 @@ int qeth_siocdevprivate(struct net_devic
struct qeth_card *card = dev->ml_priv;
int rc = 0;
+ if (!capable(CAP_NET_ADMIN))
+ return -EPERM;
+
switch (cmd) {
case SIOC_QETH_ADP_SET_SNMP_CONTROL:
rc = qeth_snmp_command(card, data);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 339/438] s390/dasd: Fix potential NULL pointer dereference
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (337 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 338/438] s390/qeth: Check CAP_NET_ADMIN for private ioctls Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 340/438] s390/dasd: Fix undersized format-check buffer Greg Kroah-Hartman
` (112 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vasily Gorbik, Eduard Shishkin,
Stefan Haberland, Jan Höppner, Jens Axboe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Höppner <hoeppner@linux.ibm.com>
commit 9973026f572db6b67570cadc30942f3014e41079 upstream.
dasd_release_space() checks the implementation of the is_ese()
discipline function before calling it to determine if a given device is
an ESE DASD.
The current usage of the logical AND operator will lead to a NULL
pointer dereference as the function is called even if the function
pointer is NULL.
Fix this by using the logical OR operator.
Fixes: 91dc4a197569 ("s390/dasd: Add new ioctl to release space")
Cc: stable@vger.kernel.org # v5.3+
Reported-by: Vasily Gorbik <gor@linux.ibm.com>
Acked-by: Eduard Shishkin <edward6@linux.ibm.com>
Reviewed-by: Stefan Haberland <sth@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
Signed-off-by: Stefan Haberland <sth@linux.ibm.com>
Link: https://patch.msgid.link/20260727142840.567286-3-sth@linux.ibm.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/block/dasd_ioctl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/s390/block/dasd_ioctl.c
+++ b/drivers/s390/block/dasd_ioctl.c
@@ -324,7 +324,7 @@ out_err:
static int dasd_release_space(struct dasd_device *device,
struct format_data_t *rdata)
{
- if (!device->discipline->is_ese && !device->discipline->is_ese(device))
+ if (!device->discipline->is_ese || !device->discipline->is_ese(device))
return -ENOTSUPP;
if (!device->discipline->release_space)
return -ENOTSUPP;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 340/438] s390/dasd: Fix undersized format-check buffer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (338 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 339/438] s390/dasd: Fix potential NULL pointer dereference Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 341/438] s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs Greg Kroah-Hartman
` (111 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jan Höppner, Stefan Haberland,
Jens Axboe
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stefan Haberland <sth@linux.ibm.com>
commit 7f40b346462f563a0d6e841a77b5163d2a882a04 upstream.
fmt_buffer_size in dasd_eckd_check_device_format() is declared as
int, even though one of the multiplicands, sizeof(struct eckd_count),
is a size_t. The expression
trkcount * rpt_max * sizeof(struct eckd_count)
is therefore correctly evaluated at 64-bit width, but the result is
silently truncated when it is stored back into the 32-bit
fmt_buffer_size variable. For a sufficiently large track range
(start_unit/stop_unit are caller-controlled) this truncation
yields a buffer size far smaller than the number of tracks actually
requested. kzalloc() then succeeds with an undersized allocation,
while the subsequent channel program build still operates on the
untruncated track count and writes past the end of that buffer.
Compute the buffer size with check_mul_overflow() and keep it in a
size_t, so that a value that no longer fits results in -EINVAL
instead of a silently truncated allocation size.
Fixes: 8fd575200db5 ("s390/dasd: Add new ioctl BIODASDCHECKFMT")
Cc: stable@vger.kernel.org #4.7
Reviewed-by: Jan Höppner <hoeppner@linux.ibm.com>
Signed-off-by: Stefan Haberland <sth@linux.ibm.com>
Link: https://patch.msgid.link/20260727142840.567286-4-sth@linux.ibm.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/block/dasd_eckd.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
--- a/drivers/s390/block/dasd_eckd.c
+++ b/drivers/s390/block/dasd_eckd.c
@@ -20,6 +20,7 @@
#include <linux/seq_file.h>
#include <linux/uaccess.h>
#include <linux/io.h>
+#include <linux/overflow.h>
#include <asm/css_chars.h>
#include <asm/machine.h>
@@ -3475,11 +3476,11 @@ static int dasd_eckd_check_device_format
{
struct dasd_eckd_private *private = base->private;
struct eckd_count *fmt_buffer;
- struct irb irb;
+ size_t fmt_buffer_size;
+ unsigned int trkcount;
int rpt_max, rpt_exp;
- int fmt_buffer_size;
+ struct irb irb;
int trk_per_cyl;
- int trkcount;
int tpm = 0;
int rc;
@@ -3490,7 +3491,9 @@ static int dasd_eckd_check_device_format
rpt_exp = recs_per_track(&private->rdc_data, 0, cdata->expect.blksize);
trkcount = cdata->expect.stop_unit - cdata->expect.start_unit + 1;
- fmt_buffer_size = trkcount * rpt_max * sizeof(struct eckd_count);
+ if (check_mul_overflow(trkcount, rpt_max, &fmt_buffer_size) ||
+ check_mul_overflow(fmt_buffer_size, sizeof(struct eckd_count), &fmt_buffer_size))
+ return -EINVAL;
fmt_buffer = kzalloc(fmt_buffer_size, GFP_KERNEL | GFP_DMA);
if (!fmt_buffer)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 341/438] s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (339 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 340/438] s390/dasd: Fix undersized format-check buffer Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 342/438] s390/zcrypt: Close speculative mem read possibility Greg Kroah-Hartman
` (110 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Finn Callies, Harald Freudenberger,
Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harald Freudenberger <freude@linux.ibm.com>
commit 983279d7f86ade73db86f886e09172dd567031b5 upstream.
There is a wrong upper limit check for the domain value when an EP11
CPRB is processed for sending to a crypto card. This check is only
active on custom device nodes but may lead to access heap memory
behind perms->adm when an administrative CPRB is sent.
Add correct limit (AP_DOMAINS = 256) checking to fix this.
Fixes: cfd68b33094e ("s390/zcrypt: Filter admin CPRBs on custom devices")
Cc: stable@vger.kernel.org
Reviewed-by: Finn Callies <fcallies@linux.ibm.com>
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/zcrypt_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/s390/crypto/zcrypt_api.c
+++ b/drivers/s390/crypto/zcrypt_api.c
@@ -1077,7 +1077,7 @@ static long _zcrypt_send_ep11_cprb(u32 x
print_hex_dump_debug("ep11req: ", DUMP_PREFIX_ADDRESS, 16, 1,
ap_msg.msg, ap_msg.len, false);
- if (perms != &ap_perms && domain < AUTOSEL_DOM) {
+ if (perms != &ap_perms && domain < AP_DOMAINS) {
if (ap_msg.flags & AP_MSG_FLAG_ADMIN) {
if (!test_bit_inv(domain, perms->adm)) {
rc = -ENODEV;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 342/438] s390/zcrypt: Close speculative mem read possibility
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (340 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 341/438] s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 343/438] s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Greg Kroah-Hartman
` (109 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger, Finn Callies,
Harald Freudenberger, Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harald Freudenberger <freude@linux.ibm.com>
commit e935cd525af4c6ed2e2c6404aa27ca19c7f39ddb upstream.
The domain value is extracted from a given CCA or EP11 ioctl struct
when a CPRB is about to be sent. Thus this is a user controlled value.
Under some special conditions (custom device node used, administrative
load) this value is used as an array index after bounds checking, but
without speculation barrier.
Add the missing array_index_nospec() call to prevent speculative
execution where this domain value is used.
Fixes: cfd68b33094e ("s390/zcrypt: Filter admin CPRBs on custom devices")
Cc: stable@vger.kernel.org
Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Finn Callies <fcallies@linux.ibm.com>
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/zcrypt_api.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/s390/crypto/zcrypt_api.c
+++ b/drivers/s390/crypto/zcrypt_api.c
@@ -879,6 +879,7 @@ static long _zcrypt_send_cprb(u32 xflags
if (perms != &ap_perms && domain < AP_DOMAINS) {
if (ap_msg.flags & AP_MSG_FLAG_ADMIN) {
+ domain = array_index_nospec(domain, AP_DOMAINS);
if (!test_bit_inv(domain, perms->adm)) {
rc = -ENODEV;
goto out;
@@ -1079,6 +1080,7 @@ static long _zcrypt_send_ep11_cprb(u32 x
if (perms != &ap_perms && domain < AP_DOMAINS) {
if (ap_msg.flags & AP_MSG_FLAG_ADMIN) {
+ domain = array_index_nospec(domain, AP_DOMAINS);
if (!test_bit_inv(domain, perms->adm)) {
rc = -ENODEV;
goto out;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 343/438] s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (341 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 342/438] s390/zcrypt: Close speculative mem read possibility Greg Kroah-Hartman
@ 2026-08-07 14:38 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 344/438] s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() Greg Kroah-Hartman
` (108 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ingo Franzki, Harald Freudenberger,
Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harald Freudenberger <freude@linux.ibm.com>
commit 36b230835b8a008266aad22168ca52afacc8a58d upstream.
Add validation of both the actual key buffer size and token length
fields in all the cca_check_sec*token() functions. Additionally check
in cca_gencipherkey() for possible underflow with returned key size.
The CCA token structures contain user-controlled len fields that
were used in operations without proper validation against both the
actual buffer size and minimum token structure size. An attacker
could set this field larger than the actual buffer size, leading to
reading beyond buffer boundaries. This may result in a kernel crash or
exposure of memory via sending this as part of a request down to the
crypto card. Also an attacker could have used a very small len value
and thus enforce a buffer under-run which may produce similar effects
as a over-read.
So now a key must
- key buf length must be at least sizeof the token struct
- the key len field inside the token must fit into the range of
sizeof key token struct ... key buf length
Fixes: 4bc123b18ce6 ("s390/zcrypt: Add low level functions for CCA AES cipher keys")
Cc: stable@vger.kernel.org
Reviewed-by: Ingo Franzki <ifranzki@linux.ibm.com>
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/pkey_cca.c | 15 ++------
drivers/s390/crypto/zcrypt_ccamisc.c | 64 +++++++++++++++++++++++++++++------
drivers/s390/crypto/zcrypt_ccamisc.h | 6 +--
3 files changed, 62 insertions(+), 23 deletions(-)
--- a/drivers/s390/crypto/pkey_cca.c
+++ b/drivers/s390/crypto/pkey_cca.c
@@ -236,22 +236,16 @@ static int cca_key2protkey(const struct
if (hdr->type == TOKTYPE_CCA_INTERNAL &&
hdr->version == TOKVER_CCA_AES) {
/* CCA AES data key */
- if (keylen < sizeof(struct secaeskeytoken))
- return -EINVAL;
- if (cca_check_secaeskeytoken(pkey_dbf_info, 3, key, 0))
+ if (cca_check_secaeskeytoken(pkey_dbf_info, 3, key, keylen, 0))
return -EINVAL;
} else if (hdr->type == TOKTYPE_CCA_INTERNAL &&
hdr->version == TOKVER_CCA_VLSC) {
/* CCA AES cipher key */
- if (keylen < hdr->len)
- return -EINVAL;
if (cca_check_secaescipherkey(pkey_dbf_info,
- 3, key, 0, 1))
+ 3, key, keylen, 0, 1))
return -EINVAL;
} else if (hdr->type == TOKTYPE_CCA_INTERNAL_PKA) {
/* CCA ECC (private) key */
- if (keylen < sizeof(struct eccprivkeytoken))
- return -EINVAL;
if (cca_check_sececckeytoken(pkey_dbf_info, 3, key, keylen, 1))
return -EINVAL;
} else {
@@ -484,7 +478,7 @@ static int cca_verifykey(const u8 *key,
hdr->version == TOKVER_CCA_AES) {
struct secaeskeytoken *t = (struct secaeskeytoken *)key;
- rc = cca_check_secaeskeytoken(pkey_dbf_info, 3, key, 0);
+ rc = cca_check_secaeskeytoken(pkey_dbf_info, 3, key, keylen, 0);
if (rc)
goto out;
*keytype = PKEY_TYPE_CCA_DATA;
@@ -512,7 +506,8 @@ static int cca_verifykey(const u8 *key,
hdr->version == TOKVER_CCA_VLSC) {
struct cipherkeytoken *t = (struct cipherkeytoken *)key;
- rc = cca_check_secaescipherkey(pkey_dbf_info, 3, key, 0, 1);
+ rc = cca_check_secaescipherkey(pkey_dbf_info, 3,
+ key, keylen, 0, 1);
if (rc)
goto out;
*keytype = PKEY_TYPE_CCA_CIPHER;
--- a/drivers/s390/crypto/zcrypt_ccamisc.c
+++ b/drivers/s390/crypto/zcrypt_ccamisc.c
@@ -62,12 +62,18 @@ static DEFINE_MUTEX(dev_status_mem_mutex
* also checked. Returns 0 on success or errno value on failure.
*/
int cca_check_secaeskeytoken(debug_info_t *dbg, int dbflvl,
- const u8 *token, int keybitsize)
+ const u8 *token, u32 keysize, int keybitsize)
{
struct secaeskeytoken *t = (struct secaeskeytoken *)token;
#define DBF(...) debug_sprintf_event(dbg, dbflvl, ##__VA_ARGS__)
+ if (keysize < sizeof(*t)) {
+ if (dbg)
+ DBF("%s keysize %u < min token size %zu\n",
+ __func__, keysize, sizeof(*t));
+ return -EINVAL;
+ }
if (t->type != TOKTYPE_CCA_INTERNAL) {
if (dbg)
DBF("%s token check failed, type 0x%02x != 0x%02x\n",
@@ -101,14 +107,20 @@ EXPORT_SYMBOL(cca_check_secaeskeytoken);
* Returns 0 on success or errno value on failure.
*/
int cca_check_secaescipherkey(debug_info_t *dbg, int dbflvl,
- const u8 *token, int keybitsize,
- int checkcpacfexport)
+ const u8 *token, u32 keysize,
+ int keybitsize, int checkcpacfexport)
{
struct cipherkeytoken *t = (struct cipherkeytoken *)token;
bool keybitsizeok = true;
#define DBF(...) debug_sprintf_event(dbg, dbflvl, ##__VA_ARGS__)
+ if (keysize < sizeof(*t)) {
+ if (dbg)
+ DBF("%s keysize %u < min token size %zu\n",
+ __func__, keysize, sizeof(*t));
+ return -EINVAL;
+ }
if (t->type != TOKTYPE_CCA_INTERNAL) {
if (dbg)
DBF("%s token check failed, type 0x%02x != 0x%02x\n",
@@ -121,6 +133,18 @@ int cca_check_secaescipherkey(debug_info
__func__, (int)t->version, TOKVER_CCA_VLSC);
return -EINVAL;
}
+ if (t->len > keysize) {
+ if (dbg)
+ DBF("%s token check failed, len %d > keysize %u\n",
+ __func__, (int)t->len, keysize);
+ return -EINVAL;
+ }
+ if (t->len < sizeof(*t)) {
+ if (dbg)
+ DBF("%s token check failed, len %d < min token size %zu\n",
+ __func__, (int)t->len, sizeof(*t));
+ return -EINVAL;
+ }
if (t->algtype != 0x02) {
if (dbg)
DBF("%s token check failed, algtype 0x%02x != 0x02\n",
@@ -195,6 +219,12 @@ int cca_check_sececckeytoken(debug_info_
#define DBF(...) debug_sprintf_event(dbg, dbflvl, ##__VA_ARGS__)
+ if (keysize < sizeof(*t)) {
+ if (dbg)
+ DBF("%s keysize %u < min token size %zu\n",
+ __func__, keysize, sizeof(*t));
+ return -EINVAL;
+ }
if (t->type != TOKTYPE_CCA_INTERNAL_PKA) {
if (dbg)
DBF("%s token check failed, type 0x%02x != 0x%02x\n",
@@ -207,6 +237,12 @@ int cca_check_sececckeytoken(debug_info_
__func__, (int)t->len, keysize);
return -EINVAL;
}
+ if (t->len < sizeof(*t)) {
+ if (dbg)
+ DBF("%s token check failed, len %d < min token size %zu\n",
+ __func__, (int)t->len, sizeof(*t));
+ return -EINVAL;
+ }
if (t->secid != 0x20) {
if (dbg)
DBF("%s token check failed, secid 0x%02x != 0x20\n",
@@ -443,7 +479,8 @@ int cca_genseckey(u16 cardnr, u16 domain
/* check secure key token */
rc = cca_check_secaeskeytoken(zcrypt_dbf_info, DBF_ERR,
- prepparm->lv3.keyblock.tok, 8 * keysize);
+ prepparm->lv3.keyblock.tok,
+ seckeysize, 8 * keysize);
if (rc) {
rc = -EIO;
goto out;
@@ -582,7 +619,8 @@ int cca_clr2seckey(u16 cardnr, u16 domai
/* check secure key token */
rc = cca_check_secaeskeytoken(zcrypt_dbf_info, DBF_ERR,
- prepparm->lv3.keyblock.tok, 8 * keysize);
+ prepparm->lv3.keyblock.tok,
+ seckeysize, 8 * keysize);
if (rc) {
rc = -EIO;
goto out;
@@ -842,6 +880,7 @@ int cca_gencipherkey(u16 cardnr, u16 dom
} kb;
} __packed * prepparm;
struct cipherkeytoken *t;
+ u32 keybuflen;
/* get already prepared memory for 2 cprbs with param block each */
rc = alloc_and_prep_cprbmem(PARMBSIZE, &mem,
@@ -936,23 +975,28 @@ int cca_gencipherkey(u16 cardnr, u16 dom
}
/* and some checks on the generated key */
+ t = (struct cipherkeytoken *)prepparm->kb.tlv1.gen_key;
+ if (prepparm->kb.tlv1.len < 2 * sizeof(uint16_t) + sizeof(*t)) {
+ rc = -EIO;
+ goto out;
+ }
+ keybuflen = prepparm->kb.tlv1.len - 2 * sizeof(uint16_t);
rc = cca_check_secaescipherkey(zcrypt_dbf_info, DBF_ERR,
prepparm->kb.tlv1.gen_key,
- keybitsize, 1);
+ keybuflen, keybitsize, 1);
if (rc) {
rc = -EIO;
goto out;
}
/* copy the generated vlsc key token */
- t = (struct cipherkeytoken *)prepparm->kb.tlv1.gen_key;
if (keybuf) {
- if (*keybufsize >= t->len)
- memcpy(keybuf, t, t->len);
+ if (*keybufsize >= keybuflen)
+ memcpy(keybuf, t, keybuflen);
else
rc = -EINVAL;
}
- *keybufsize = t->len;
+ *keybufsize = keybuflen;
out:
free_cprbmem(mem, PARMBSIZE, false, xflags);
--- a/drivers/s390/crypto/zcrypt_ccamisc.h
+++ b/drivers/s390/crypto/zcrypt_ccamisc.h
@@ -136,7 +136,7 @@ struct eccprivkeytoken {
* also checked. Returns 0 on success or errno value on failure.
*/
int cca_check_secaeskeytoken(debug_info_t *dbg, int dbflvl,
- const u8 *token, int keybitsize);
+ const u8 *token, u32 keysize, int keybitsize);
/*
* Simple check if the token is a valid CCA secure AES cipher key
@@ -146,8 +146,8 @@ int cca_check_secaeskeytoken(debug_info_
* Returns 0 on success or errno value on failure.
*/
int cca_check_secaescipherkey(debug_info_t *dbg, int dbflvl,
- const u8 *token, int keybitsize,
- int checkcpacfexport);
+ const u8 *token, u32 keysize,
+ int keybitsize, int checkcpacfexport);
/*
* Simple check if the token is a valid CCA secure ECC private
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 344/438] s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (342 preceding siblings ...)
2026-08-07 14:38 ` [PATCH 7.1 343/438] s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 345/438] s390/zcrypt: Validate length for CCA AES cipher key requests Greg Kroah-Hartman
` (107 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Holger Dengler, Harald Freudenberger,
Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harald Freudenberger <freude@linux.ibm.com>
commit 01476391aecef36a3b789ee844357b22fbc90665 upstream.
The helper function _ip_cprb_helper() uses internal buffer memory for
building and processing CPRBs. After use this buffer was never
scrubbed which could lead to leaving for example clear key material in
memory which could be exposed via tricky reuse of this same memory.
Extend the _ip_cprb_helper() function with another parameter 'scrub'
used to steer scrubbing of this buffer. So now the caller has the
opportunity to decide if scrubbing is needed or not.
Extend the clear key to secure key token import process in function
cca_clr2cipherkey() to tell the helper function from above to scrub
the cprb buffer when the clear key value is part of the request data.
Add explicit scrubbing on return from function cca_clr2cipherkey() for
the random EXOR buffer and the cprb buffer.
Overall this cleans the internal used buffer in case of clear key
import to prevent sensitive data to get exposed.
Fixes: 4bc123b18ce6 ("s390/zcrypt: Add low level functions for CCA AES cipher keys")
Cc: stable@vger.kernel.org
Reviewed-by: Holger Dengler <dengler@linux.ibm.com>
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/zcrypt_ccamisc.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
--- a/drivers/s390/crypto/zcrypt_ccamisc.c
+++ b/drivers/s390/crypto/zcrypt_ccamisc.c
@@ -1015,7 +1015,8 @@ static int _ip_cprb_helper(u16 cardnr, u
int clr_key_bit_size,
u8 *key_token,
int *key_token_size,
- u32 xflags)
+ u32 xflags,
+ bool scrub)
{
int rc, n;
u8 *mem, *ptr;
@@ -1155,7 +1156,7 @@ static int _ip_cprb_helper(u16 cardnr, u
*key_token_size = t->len;
out:
- free_cprbmem(mem, PARMBSIZE, false, xflags);
+ free_cprbmem(mem, PARMBSIZE, scrub, xflags);
return rc;
}
@@ -1206,28 +1207,32 @@ int cca_clr2cipherkey(u16 card, u16 dom,
* 4/4 COMPLETE the secure cipher key import
*/
rc = _ip_cprb_helper(card, dom, "AES ", "FIRST ", "MIN3PART",
- exorbuf, keybitsize, token, &tokensize, xflags);
+ exorbuf, keybitsize, token, &tokensize,
+ xflags, true);
if (rc) {
ZCRYPT_DBF_ERR("%s clear key import 1/4 with CSNBKPI2 failed, rc=%d\n",
__func__, rc);
goto out;
}
rc = _ip_cprb_helper(card, dom, "AES ", "ADD-PART", NULL,
- clrkey, keybitsize, token, &tokensize, xflags);
+ clrkey, keybitsize, token, &tokensize,
+ xflags, true);
if (rc) {
ZCRYPT_DBF_ERR("%s clear key import 2/4 with CSNBKPI2 failed, rc=%d\n",
__func__, rc);
goto out;
}
rc = _ip_cprb_helper(card, dom, "AES ", "ADD-PART", NULL,
- exorbuf, keybitsize, token, &tokensize, xflags);
+ exorbuf, keybitsize, token, &tokensize,
+ xflags, true);
if (rc) {
ZCRYPT_DBF_ERR("%s clear key import 3/4 with CSNBKPI2 failed, rc=%d\n",
__func__, rc);
goto out;
}
rc = _ip_cprb_helper(card, dom, "AES ", "COMPLETE", NULL,
- NULL, keybitsize, token, &tokensize, xflags);
+ NULL, keybitsize, token, &tokensize,
+ xflags, true);
if (rc) {
ZCRYPT_DBF_ERR("%s clear key import 4/4 with CSNBKPI2 failed, rc=%d\n",
__func__, rc);
@@ -1244,6 +1249,8 @@ int cca_clr2cipherkey(u16 card, u16 dom,
*keybufsize = tokensize;
out:
+ memzero_explicit(exorbuf, sizeof(exorbuf));
+ memzero_explicit(mem, CPRB_MEMPOOL_ITEM_SIZE);
mempool_free(mem, cprb_mempool);
return rc;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 345/438] s390/zcrypt: Validate length for CCA AES cipher key requests
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (343 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 344/438] s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 346/438] s390/zcrypt: Validate length for CCA ECC private " Greg Kroah-Hartman
` (106 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Holger Dengler, Harald Freudenberger,
Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Holger Dengler <dengler@linux.ibm.com>
commit 06afe425d5283b9764303de47f554da5a808ce8a upstream.
cca_cipher2protkey() derives the copy length for the CPRB parameter
block directly from the length field in the key token. Reject the
request early if the token length exceeds the available space in the
parameter block.
Fixes: 4bc123b18ce6 ("s390/zcrypt: Add low level functions for CCA AES cipher keys")
Signed-off-by: Holger Dengler <dengler@linux.ibm.com>
Cc: stable@vger.kernel.org # 5.4+
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/zcrypt_ccamisc.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/s390/crypto/zcrypt_ccamisc.c
+++ b/drivers/s390/crypto/zcrypt_ccamisc.c
@@ -1312,6 +1312,9 @@ int cca_cipher2protkey(u16 cardnr, u16 d
} __packed * prepparm;
int keytoklen = ((struct cipherkeytoken *)ckey)->len;
+ if (keytoklen > PARMBSIZE - sizeof(struct aureqparm))
+ return -EINVAL;
+
/* get already prepared memory for 2 cprbs with param block each */
rc = alloc_and_prep_cprbmem(PARMBSIZE, &mem,
&preqcblk, &prepcblk, xflags);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 346/438] s390/zcrypt: Validate length for CCA ECC private key requests
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (344 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 345/438] s390/zcrypt: Validate length for CCA AES cipher key requests Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 347/438] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask Greg Kroah-Hartman
` (105 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Holger Dengler, Harald Freudenberger,
Vasily Gorbik
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Holger Dengler <dengler@linux.ibm.com>
commit a9ae0f6dd45c3ccc1d69363f7aea8af179122730 upstream.
cca_ecc2protkey() derives the copy length for the CPRB parameter
block directly from the length field in the key token. Reject the
request early if the token length exceeds the available space in the
parameter block.
Fixes: fa6999e326fe ("s390/pkey: support CCA and EP11 secure ECC private keys")
Signed-off-by: Holger Dengler <dengler@linux.ibm.com>
Cc: stable@vger.kernel.org # 5.10+
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/zcrypt_ccamisc.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/s390/crypto/zcrypt_ccamisc.c
+++ b/drivers/s390/crypto/zcrypt_ccamisc.c
@@ -1479,6 +1479,9 @@ int cca_ecc2protkey(u16 cardnr, u16 doma
} __packed * prepparm;
int keylen = ((struct eccprivkeytoken *)key)->len;
+ if (keylen > PARMBSIZE - sizeof(struct aureqparm))
+ return -EINVAL;
+
/* get already prepared memory for 2 cprbs with param block each */
rc = alloc_and_prep_cprbmem(PARMBSIZE, &mem,
&preqcblk, &prepcblk, xflags);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 347/438] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (345 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 346/438] s390/zcrypt: Validate length for CCA ECC private " Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 348/438] phy: zynqmp: use read-modify-write for SERDES scrambler bypass Greg Kroah-Hartman
` (104 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nava kishore Manne,
Radhey Shyam Pandey, Michal Simek, Vinod Koul
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nava kishore Manne <nava.kishore.manne@amd.com>
commit 6cb22477929489a412df8d153e550e77a012e701 upstream.
The L0_TX_DIG_61 register bit 2 is a reserved read-only field.
The previous mask value 0x0f incorrectly included bit 2, causing
unintended writes to a reserved bit on every scrambler bypass
operation.
Correct the mask to (BIT(3) | GENMASK(1, 0)) to cover only the
valid scramble bypass control bits.
Fixes: 4a33bea00314 ("phy: zynqmp: Add PHY driver for the Xilinx ZynqMP Gigabit Transceiver")
Cc: stable@vger.kernel.org
Signed-off-by: Nava kishore Manne <nava.kishore.manne@amd.com>
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Acked-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260627155229.2791113-2-radhey.shyam.pandey@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/phy/xilinx/phy-zynqmp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/phy/xilinx/phy-zynqmp.c
+++ b/drivers/phy/xilinx/phy-zynqmp.c
@@ -53,7 +53,7 @@
#define L0_TM_DIG_6 0x106c
#define L0_TM_DIS_DESCRAMBLE_DECODER 0x0f
#define L0_TX_DIG_61 0x00f4
-#define L0_TM_DISABLE_SCRAMBLE_ENCODER 0x0f
+#define L0_TM_DISABLE_SCRAMBLE_ENCODER (BIT(3) | GENMASK(1, 0))
/* PLL Test Mode register parameters */
#define L0_TM_PLL_DIG_37 0x2094
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 348/438] phy: zynqmp: use read-modify-write for SERDES scrambler bypass
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (346 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 347/438] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 349/438] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB Greg Kroah-Hartman
` (103 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nava kishore Manne,
Radhey Shyam Pandey, Michal Simek, Vinod Koul
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nava kishore Manne <nava.kishore.manne@amd.com>
commit 21e0749f931702765b9d52d05740092bc87fcd8d upstream.
xpsgtr_bypass_scrambler_8b10b() used xpsgtr_write_phy() which performs
a full register write, silently clearing any bits beyond the intended
bypass control fields.
Switch to xpsgtr_clr_set_phy() with clr=mask, set=mask to set only
the bypass bits while preserving the remaining bits in each register.
Fixes: 4a33bea00314 ("phy: zynqmp: Add PHY driver for the Xilinx ZynqMP Gigabit Transceiver")
Cc: stable@vger.kernel.org
Signed-off-by: Nava kishore Manne <nava.kishore.manne@amd.com>
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Acked-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260627155229.2791113-3-radhey.shyam.pandey@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/phy/xilinx/phy-zynqmp.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/phy/xilinx/phy-zynqmp.c
+++ b/drivers/phy/xilinx/phy-zynqmp.c
@@ -505,8 +505,12 @@ static void xpsgtr_lane_set_protocol(str
/* Bypass (de)scrambler and 8b/10b decoder and encoder. */
static void xpsgtr_bypass_scrambler_8b10b(struct xpsgtr_phy *gtr_phy)
{
- xpsgtr_write_phy(gtr_phy, L0_TM_DIG_6, L0_TM_DIS_DESCRAMBLE_DECODER);
- xpsgtr_write_phy(gtr_phy, L0_TX_DIG_61, L0_TM_DISABLE_SCRAMBLE_ENCODER);
+ xpsgtr_clr_set_phy(gtr_phy, L0_TM_DIG_6,
+ L0_TM_DIS_DESCRAMBLE_DECODER,
+ L0_TM_DIS_DESCRAMBLE_DECODER);
+ xpsgtr_clr_set_phy(gtr_phy, L0_TX_DIG_61,
+ L0_TM_DISABLE_SCRAMBLE_ENCODER,
+ L0_TM_DISABLE_SCRAMBLE_ENCODER);
}
/* DP-specific initialization. */
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 349/438] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (347 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 348/438] phy: zynqmp: use read-modify-write for SERDES scrambler bypass Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 350/438] net: openvswitch: fix potential UAF on meter attach failure Greg Kroah-Hartman
` (102 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nava kishore Manne,
Radhey Shyam Pandey, Michal Simek, Vinod Koul
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nava kishore Manne <nava.kishore.manne@amd.com>
commit 7eb61caf45607e1e1270f51f8f93f0ded53146da upstream.
USB Gen1 requires scrambling and 8b/10b encoding to be performed in the
physical layer. Do not bypass PHY-side scrambler or encoder/decoder for
USB operation, as mandated by the USB 3.x specification.
Scrambler and 8b/10b bypass remain restricted to SATA and SGMII
modes, where encoding is handled in the controller.
Fixes: 4a33bea00314 ("phy: zynqmp: Add PHY driver for the Xilinx ZynqMP Gigabit Transceiver")
Cc: stable@vger.kernel.org
Signed-off-by: Nava kishore Manne <nava.kishore.manne@amd.com>
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Acked-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260627155229.2791113-4-radhey.shyam.pandey@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/phy/xilinx/phy-zynqmp.c | 39 +++++++++++++++++++++++++++++----------
1 file changed, 29 insertions(+), 10 deletions(-)
--- a/drivers/phy/xilinx/phy-zynqmp.c
+++ b/drivers/phy/xilinx/phy-zynqmp.c
@@ -502,15 +502,30 @@ static void xpsgtr_lane_set_protocol(str
}
}
-/* Bypass (de)scrambler and 8b/10b decoder and encoder. */
-static void xpsgtr_bypass_scrambler_8b10b(struct xpsgtr_phy *gtr_phy)
+/**
+ * xpsgtr_bypass_scrambler_8b10b - Configure scrambler/encoder behavior
+ * @gtr_phy: pointer to lane context
+ * @bypass: true to enable scrambler/encoder bypass (SATA/SGMII),
+ * false to disable scrambler/encoder bypass (USB3)
+ *
+ * Uses RMW to preserve reserved and unrelated register fields.
+ */
+static void xpsgtr_bypass_scrambler_8b10b(struct xpsgtr_phy *gtr_phy,
+ bool bypass)
{
- xpsgtr_clr_set_phy(gtr_phy, L0_TM_DIG_6,
- L0_TM_DIS_DESCRAMBLE_DECODER,
- L0_TM_DIS_DESCRAMBLE_DECODER);
- xpsgtr_clr_set_phy(gtr_phy, L0_TX_DIG_61,
- L0_TM_DISABLE_SCRAMBLE_ENCODER,
- L0_TM_DISABLE_SCRAMBLE_ENCODER);
+ if (bypass) {
+ xpsgtr_clr_set_phy(gtr_phy, L0_TM_DIG_6,
+ L0_TM_DIS_DESCRAMBLE_DECODER,
+ L0_TM_DIS_DESCRAMBLE_DECODER);
+ xpsgtr_clr_set_phy(gtr_phy, L0_TX_DIG_61,
+ L0_TM_DISABLE_SCRAMBLE_ENCODER,
+ L0_TM_DISABLE_SCRAMBLE_ENCODER);
+ } else {
+ xpsgtr_clr_set_phy(gtr_phy, L0_TM_DIG_6,
+ L0_TM_DIS_DESCRAMBLE_DECODER, 0);
+ xpsgtr_clr_set_phy(gtr_phy, L0_TX_DIG_61,
+ L0_TM_DISABLE_SCRAMBLE_ENCODER, 0);
+ }
}
/* DP-specific initialization. */
@@ -531,7 +546,7 @@ static void xpsgtr_phy_init_sata(struct
{
struct xpsgtr_dev *gtr_dev = gtr_phy->dev;
- xpsgtr_bypass_scrambler_8b10b(gtr_phy);
+ xpsgtr_bypass_scrambler_8b10b(gtr_phy, true);
writel(gtr_phy->lane, gtr_dev->siou + SATA_CONTROL_OFFSET);
}
@@ -547,7 +562,7 @@ static void xpsgtr_phy_init_sgmii(struct
xpsgtr_clr_set(gtr_dev, TX_PROT_BUS_WIDTH, mask, val);
xpsgtr_clr_set(gtr_dev, RX_PROT_BUS_WIDTH, mask, val);
- xpsgtr_bypass_scrambler_8b10b(gtr_phy);
+ xpsgtr_bypass_scrambler_8b10b(gtr_phy, true);
}
/* Configure TX de-emphasis and margining for DP. */
@@ -708,6 +723,10 @@ static int xpsgtr_phy_init(struct phy *p
case ICM_PROTOCOL_SGMII:
xpsgtr_phy_init_sgmii(gtr_phy);
break;
+
+ case ICM_PROTOCOL_USB:
+ xpsgtr_bypass_scrambler_8b10b(gtr_phy, false);
+ break;
}
goto out;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 350/438] net: openvswitch: fix potential UAF on meter attach failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (348 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 349/438] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 351/438] net: openvswitch: fix skb leak on flow key update failure during recirculation Greg Kroah-Hartman
` (101 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Eelco Chaudron,
Paolo Abeni
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit a58a2b0ce354df531ebc71fc870058c2feb59f6b upstream.
While attaching a newly created meter attach_meter() function makes
the new meter visible to other CPUs but can still fail afterwards.
On failure, it detaches the meter back and returns an error.
However, this is an unexpected behavior for the ovs_meter_cmd_set()
that uses a plain kfree(meter) on attach failure without waiting for
RCU readers to stop using it, assuming it was never visible.
This is never a problem for ovs-vswitchd as it always creates meters
before creating any flows that use them. But the UAF can be triggered
with a custom application using uAPI:
BUG: KASAN: slab-use-after-free in ovs_meter_execute (net/openvswitch/meter.c:653)
Read of size 8 at addr ffff88810d152650 by task meter/2508
Call Trace:
ovs_meter_execute (net/openvswitch/meter.c:653)
do_execute_actions (net/openvswitch/actions.c:1407)
ovs_execute_actions (net/openvswitch/actions.c:1584)
ovs_packet_cmd_execute (net/openvswitch/datapath.c:703)
...
netlink_sendmsg (af_netlink.c:1900)
Allocated by task 2519:
__kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)
ovs_meter_cmd_set (net/openvswitch/meter.c:422)
...
netlink_sendmsg (af_netlink.c:1900)
Freed by task 2519:
kfree (mm/slub.c:2705 mm/slub.c:6405 mm/slub.c:6720)
ovs_meter_cmd_set (net/openvswitch/meter.c:479)
...
netlink_sendmsg (af_netlink.c:1900)
Fix that by making sure attach_meter() doesn't make the meter visible
until all the checks are done and the function can't fail anymore.
This also makes sure the "hash" value is calculated after the potential
re-sizing of the table.
Reported by Trend Micro's Zero Day Initiative as ZDI-CAN-31642.
Fixes: c7c4c44c9a95 ("net: openvswitch: expand the meters supported number")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Eelco Chaudron <echaudro@redhat.com>
Link: https://patch.msgid.link/20260727121022.198461-1-i.maximets@ovn.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/meter.c | 33 +++++++++++++++++++--------------
1 file changed, 19 insertions(+), 14 deletions(-)
--- a/net/openvswitch/meter.c
+++ b/net/openvswitch/meter.c
@@ -133,18 +133,10 @@ static void dp_meter_instance_remove(str
static int attach_meter(struct dp_meter_table *tbl, struct dp_meter *meter)
{
- struct dp_meter_instance *ti = rcu_dereference_ovsl(tbl->ti);
- u32 hash = meter_hash(ti, meter->id);
+ struct dp_meter_instance *ti;
+ u32 hash;
int err;
- /* In generally, slots selected should be empty, because
- * OvS uses id-pool to fetch a available id.
- */
- if (unlikely(rcu_dereference_ovsl(ti->dp_meters[hash])))
- return -EBUSY;
-
- dp_meter_instance_insert(ti, meter);
-
/* That function is thread-safe. */
tbl->count++;
if (tbl->count >= tbl->max_meters_allowed) {
@@ -152,16 +144,29 @@ static int attach_meter(struct dp_meter_
goto attach_err;
}
- if (tbl->count >= ti->n_meters &&
- dp_meter_instance_realloc(tbl, ti->n_meters * 2)) {
- err = -ENOMEM;
+ ti = rcu_dereference_ovsl(tbl->ti);
+ if (tbl->count >= ti->n_meters) {
+ err = dp_meter_instance_realloc(tbl, ti->n_meters * 2);
+ if (err)
+ goto attach_err;
+
+ ti = rcu_dereference_ovsl(tbl->ti);
+ }
+
+ hash = meter_hash(ti, meter->id);
+
+ /* In general, selected slots should be empty, because
+ * OvS uses id-pool to fetch available ids.
+ */
+ if (unlikely(rcu_dereference_ovsl(ti->dp_meters[hash]))) {
+ err = -EBUSY;
goto attach_err;
}
+ dp_meter_instance_insert(ti, meter);
return 0;
attach_err:
- dp_meter_instance_remove(ti, meter);
tbl->count--;
return err;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 351/438] net: openvswitch: fix skb leak on flow key update failure during recirculation
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (349 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 350/438] net: openvswitch: fix potential UAF on meter attach failure Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 352/438] net: openvswitch: fix skb leak on flow key update failure during ct Greg Kroah-Hartman
` (100 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Aaron Conole,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit e1cf066244dad576221b7123a0e5005967f25a20 upstream.
do_execute_actions() returns right away when execute_recirc() fails on
the last action as it assumes this function always takes ownership of
the skb when 'last' is true. But when the flow key update fails, the
function doesn't free the skb and it ends up leaked.
This is a very unlikely scenario as it requires the packet to become
unparseable by applying a set of actions on a previously parseable skb,
but should be fixed nevertheless.
Reported by Sashiko.
Fixes: 971427f353f3 ("openvswitch: Add recirc and hash action.")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260727181851.306076-2-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/actions.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
--- a/net/openvswitch/actions.c
+++ b/net/openvswitch/actions.c
@@ -1108,6 +1108,10 @@ static int execute_masked_set_action(str
return err;
}
+/* When 'last' is true, recirc() should always consume the 'skb'.
+ * Otherwise, recirc() should keep 'skb' intact regardless what
+ * actions are executed on recirculation.
+ */
static int execute_recirc(struct datapath *dp, struct sk_buff *skb,
struct sw_flow_key *key,
const struct nlattr *a, bool last)
@@ -1118,8 +1122,12 @@ static int execute_recirc(struct datapat
int err;
err = ovs_flow_key_update(skb, key);
- if (err)
+ if (err) {
+ if (last)
+ ovs_kfree_skb_reason(skb,
+ OVS_DROP_ACTION_ERROR);
return err;
+ }
}
BUG_ON(!is_flow_key_valid(key));
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 352/438] net: openvswitch: fix skb leak on flow key update failure during ct
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (350 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 351/438] net: openvswitch: fix skb leak on flow key update failure during recirculation Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 353/438] ice: wait for reset completion in ice_resume() Greg Kroah-Hartman
` (99 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Aaron Conole,
Jakub Kicinski
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit bc62e843bc48f933da765ce47079fd992e535794 upstream.
ovs_ct_execute() always steals or frees the skb on failure while
ovs_flow_key_update() does not. So, if it fails and we return right
away, the skb ends up leaked.
Fix that by breaking instead and letting the common error handling
code at the bottom of the loop to free the skb properly.
This is a very unlikely scenario as it requires the packet to become
unparseable by applying a set of actions on a previously parseable skb,
but should be fixed nevertheless.
Reported by Sashiko.
Fixes: ec0d043d05e6 ("openvswitch: Ensure flow is valid before executing ct")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260727181851.306076-3-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/actions.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/openvswitch/actions.c
+++ b/net/openvswitch/actions.c
@@ -1380,7 +1380,7 @@ static int do_execute_actions(struct dat
if (!is_flow_key_valid(key)) {
err = ovs_flow_key_update(skb, key);
if (err)
- return err;
+ break;
}
err = ovs_ct_execute(ovs_dp_get_net(dp), skb, key,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 353/438] ice: wait for reset completion in ice_resume()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (351 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 352/438] net: openvswitch: fix skb leak on flow key update failure during ct Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 354/438] ice: fix VF interrupts cleanup Greg Kroah-Hartman
` (98 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kohei Enju, Aleksandr Loktionov,
Przemek Kitszel, Aaron Ma, Alexander Nowlin, Tony Nguyen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaron Ma <aaron.ma@canonical.com>
commit c2816d613f388814d27bc9fd6dbd931a88056e19 upstream.
ice_resume() schedules an asynchronous PF reset and returns
immediately. The reset runs later in ice_service_task(). If
userspace tries to bring up the net device before the reset
finishes, ice_open() fails with -EBUSY:
ice_resume()
ice_schedule_reset() # sets ICE_PFR_REQ, returns
...
ice_open()
ice_is_reset_in_progress() # ICE_PFR_REQ still set, -EBUSY
...
ice_service_task()
ice_do_reset()
ice_rebuild() # clears ICE_PFR_REQ, too late
Reproduced on E800 series NICs during suspend/resume with irdma
enabled, where the aux device probe widens the race window.
ice 0000:81:00.0: can't open net device while reset is in progress
Add a best-effort wait (10s timeout, matching ice_devlink_info_get())
for the reset to complete before returning from ice_resume(). In
practice the reset completes in ~300ms.
Fixes: 769c500dcc1e ("ice: Add advanced power mgmt for WoL")
Cc: stable@vger.kernel.org
Reviewed-by: Kohei Enju <kohei@enjuk.jp>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Reviewed-by: Przemek Kitszel <przemyslaw.kitszel@intel.com>
Signed-off-by: Aaron Ma <aaron.ma@canonical.com>
Tested-by: Alexander Nowlin <alexander.nowlin@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/intel/ice/ice_main.c | 10 ++++++++++
1 file changed, 10 insertions(+)
--- a/drivers/net/ethernet/intel/ice/ice_main.c
+++ b/drivers/net/ethernet/intel/ice/ice_main.c
@@ -5637,6 +5637,16 @@ static int ice_resume(struct device *dev
/* Restart the service task */
mod_timer(&pf->serv_tmr, round_jiffies(jiffies + pf->serv_tmr_period));
+ /* Best-effort wait for the scheduled reset to finish so that the
+ * device is operational before returning. Without this, userspace
+ * (e.g. NetworkManager) may try to open the net device while the
+ * asynchronous reset is still in progress, hitting -EBUSY.
+ */
+ ret = ice_wait_for_reset(pf, secs_to_jiffies(10));
+ if (ret)
+ dev_err(dev, "Wait for reset timed out (10s) during resume: %d\n",
+ ret);
+
return 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 354/438] ice: fix VF interrupts cleanup
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (352 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 353/438] ice: wait for reset completion in ice_resume() Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 355/438] ice: fix memory leak in ice_lbtest_prepare_rings() Greg Kroah-Hartman
` (97 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Medvedkin,
Aleksandr Loktionov, Dawid Osuchowski, Simon Horman, Patryk Holda,
Tony Nguyen
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawid Osuchowski <dawid.osuchowski@linux.intel.com>
commit fb096882095e5a8d6b5159e43793d4a38a0c5b1f upstream.
When a virtual function sends an IRQ map command, the PF will set up
interrupts according to that request. However, because these interrupts are
never reset, the next time Virtual Function initializes, the interrupts are
still enabled for a given VF, which leads to performance degradation in
certain cases due to interrupts being unexpectedly enabled and thus causing
interrupt floods.
Cc: stable@vger.kernel.org
Fixes: 1071a8358a28 ("ice: Implement virtchnl commands for AVF support")
Suggested-by: Vladimir Medvedkin <vladimir.medvedkin@intel.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Signed-off-by: Dawid Osuchowski <dawid.osuchowski@linux.intel.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Tested-by: Patryk Holda <patryk.holda@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/intel/ice/ice_vf_lib.c | 27 ++++++++++++++++++++
drivers/net/ethernet/intel/ice/ice_vf_lib_private.h | 1
drivers/net/ethernet/intel/ice/virt/queues.c | 21 +++++++++++++++
3 files changed, 49 insertions(+)
--- a/drivers/net/ethernet/intel/ice/ice_vf_lib.c
+++ b/drivers/net/ethernet/intel/ice/ice_vf_lib.c
@@ -849,6 +849,30 @@ static void ice_notify_vf_reset(struct i
}
/**
+ * ice_reset_interrupts - clear all queue interrupt configuration for a VSI
+ * @vsi: the VSI whose interrupt registers should be cleared
+ *
+ * Zero the QINT_RQCTL and QINT_TQCTL registers for all allocated queues
+ * in the VSI. This clears the entire register including MSIX_INDX, ITR_INDX,
+ * CAUSE_ENA and NEXTQ fields, unlike ice_vf_dis_rxq_interrupt() which only
+ * clears the CAUSE_ENA bit.
+ */
+void ice_reset_interrupts(struct ice_vsi *vsi)
+{
+ struct ice_pf *pf = vsi->back;
+ struct ice_hw *hw = &pf->hw;
+ int i;
+
+ ice_for_each_alloc_rxq(vsi, i)
+ wr32(hw, QINT_RQCTL(vsi->rxq_map[i]), 0);
+
+ ice_for_each_alloc_txq(vsi, i)
+ wr32(hw, QINT_TQCTL(vsi->txq_map[i]), 0);
+
+ ice_flush(hw);
+}
+
+/**
* ice_reset_vf - Reset a particular VF
* @vf: pointer to the VF structure
* @flags: flags controlling behavior of the reset
@@ -919,6 +943,9 @@ int ice_reset_vf(struct ice_vf *vf, u32
ice_dis_vf_qs(vf);
+ /* cleanup interrupt registers */
+ ice_reset_interrupts(vsi);
+
/* Call Disable LAN Tx queue AQ whether or not queues are
* enabled. This is needed for successful completion of VFR.
*/
--- a/drivers/net/ethernet/intel/ice/ice_vf_lib_private.h
+++ b/drivers/net/ethernet/intel/ice/ice_vf_lib_private.h
@@ -26,6 +26,7 @@
void ice_initialize_vf_entry(struct ice_vf *vf);
void ice_deinitialize_vf_entry(struct ice_vf *vf);
void ice_dis_vf_qs(struct ice_vf *vf);
+void ice_reset_interrupts(struct ice_vsi *vsi);
int ice_check_vf_init(struct ice_vf *vf);
enum virtchnl_status_code ice_err_to_virt_err(int err);
struct ice_port_info *ice_vf_get_port_info(struct ice_vf *vf);
--- a/drivers/net/ethernet/intel/ice/virt/queues.c
+++ b/drivers/net/ethernet/intel/ice/virt/queues.c
@@ -225,6 +225,24 @@ void ice_vf_ena_rxq_interrupt(struct ice
}
/**
+ * ice_vf_dis_rxq_interrupt - disable Rx queue interrupt via QINT_RQCTL
+ * @vsi: VSI of the VF to configure
+ * @q_idx: VF queue index used to determine the queue in the PF's space
+ */
+static void ice_vf_dis_rxq_interrupt(struct ice_vsi *vsi, u32 q_idx)
+{
+ struct ice_hw *hw = &vsi->back->hw;
+ u32 pfq = vsi->rxq_map[q_idx];
+ u32 reg;
+
+ reg = rd32(hw, QINT_RQCTL(pfq));
+ reg &= ~QINT_RQCTL_CAUSE_ENA_M;
+ wr32(hw, QINT_RQCTL(pfq), reg);
+
+ ice_flush(hw);
+}
+
+/**
* ice_vc_ena_qs_msg
* @vf: pointer to the VF info
* @msg: pointer to the msg buffer
@@ -416,6 +434,8 @@ int ice_vc_dis_qs_msg(struct ice_vf *vf,
goto error_param;
}
+ for_each_set_bit(vf_q_id, &q_map, ICE_MAX_RSS_QS_PER_VF)
+ ice_vf_dis_rxq_interrupt(vsi, vf_q_id);
bitmap_zero(vf->rxq_ena, ICE_MAX_RSS_QS_PER_VF);
} else if (q_map) {
for_each_set_bit(vf_q_id, &q_map, ICE_MAX_RSS_QS_PER_VF) {
@@ -436,6 +456,7 @@ int ice_vc_dis_qs_msg(struct ice_vf *vf,
goto error_param;
}
+ ice_vf_dis_rxq_interrupt(vsi, vf_q_id);
/* Clear enabled queues flag */
clear_bit(vf_q_id, vf->rxq_ena);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 355/438] ice: fix memory leak in ice_lbtest_prepare_rings()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (353 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 354/438] ice: fix VF interrupts cleanup Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 356/438] i2c: spacemit: request IRQ after controller initialization Greg Kroah-Hartman
` (96 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dawei Feng, Jacob Keller,
Tony Nguyen, Rinitha S
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawei Feng <dawei.feng@seu.edu.cn>
commit 3a9de5590da4ffd9e9c541c4c4d492aa2b54cf6e upstream.
ice_lbtest_prepare_rings() frees Rx rings only when
ice_vsi_start_all_rx_rings() fails. If ice_vsi_setup_rx_rings() fails
after allocating some descriptors, or if ice_vsi_cfg_lan() fails after
the Rx rings were prepared, the function reaches the Tx cleanup path
without releasing the initialized Rx resources.
Fix this by adding separate unwind paths for Rx setup failure and LAN
configuration failure. The Rx setup failure path releases the partially
prepared Rx rings before freeing Tx rings, while later failures first
undo the LAN Tx configuration and then release the Rx rings in reverse
setup order.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc7.
An x86_64 allyesconfig build showed no new warnings. As we do not have an
Intel E800 Series adapter available to run the ethtool offline loopback
selftest, no runtime testing was able to be performed.
Fixes: 0e674aeb0b77 ("ice: Add handler for ethtool selftest")
Cc: stable@vger.kernel.org
Signed-off-by: Dawei Feng <dawei.feng@seu.edu.cn>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Tested-by: Rinitha S <sx.rinitha@intel.com> (A Contingent worker at Intel)
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/intel/ice/ice_ethtool.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/net/ethernet/intel/ice/ice_ethtool.c
+++ b/drivers/net/ethernet/intel/ice/ice_ethtool.c
@@ -1069,18 +1069,18 @@ static int ice_lbtest_prepare_rings(stru
status = ice_vsi_cfg_lan(vsi);
if (status)
- goto err_setup_rx_ring;
+ goto err_cfg_lan;
status = ice_vsi_start_all_rx_rings(vsi);
if (status)
- goto err_start_rx_ring;
+ goto err_cfg_lan;
return 0;
-err_start_rx_ring:
- ice_vsi_free_rx_rings(vsi);
-err_setup_rx_ring:
+err_cfg_lan:
ice_vsi_stop_lan_tx_rings(vsi, ICE_NO_RESET, 0);
+err_setup_rx_ring:
+ ice_vsi_free_rx_rings(vsi);
err_setup_tx_ring:
ice_vsi_free_tx_rings(vsi);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 356/438] i2c: spacemit: request IRQ after controller initialization
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (354 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 355/438] ice: fix memory leak in ice_lbtest_prepare_rings() Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 357/438] i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers Greg Kroah-Hartman
` (95 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linmao Li, Troy Mitchell, Alex Elder,
Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
commit cdac670237258c8ca063aa8a16998f680d81b80d upstream.
spacemit_i2c_probe() requests the IRQ before it enables the clocks, resets
the controller and runs init_completion(). If an interrupt is already
pending, the handler runs too early: it reads registers while the clocks
are still off and calls complete() on an uninitialized completion. Request
the IRQ after the controller and completion are initialized, but still
before the adapter is registered.
Fixes: 5ea558473fa3 ("i2c: spacemit: add support for SpacemiT K1 SoC")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Cc: <stable@vger.kernel.org> # v6.15+
Reviewed-by: Troy Mitchell <troy.mitchell@linux.spacemit.com>
Reviewed-by: Alex Elder <elder@riscstar.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260723021140.2293844-1-lilinmao@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-k1.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/i2c/busses/i2c-k1.c
+++ b/drivers/i2c/busses/i2c-k1.c
@@ -723,11 +723,6 @@ static int spacemit_i2c_probe(struct pla
if (i2c->irq < 0)
return dev_err_probe(dev, i2c->irq, "failed to get irq resource");
- ret = devm_request_irq(i2c->dev, i2c->irq, spacemit_i2c_irq_handler,
- IRQF_NO_SUSPEND, dev_name(i2c->dev), i2c);
- if (ret)
- return dev_err_probe(dev, ret, "failed to request irq");
-
clk = devm_clk_get_enabled(dev, "func");
if (IS_ERR(clk))
return dev_err_probe(dev, PTR_ERR(clk), "failed to enable func clock");
@@ -755,6 +750,11 @@ static int spacemit_i2c_probe(struct pla
init_completion(&i2c->complete);
+ ret = devm_request_irq(i2c->dev, i2c->irq, spacemit_i2c_irq_handler,
+ IRQF_NO_SUSPEND, dev_name(i2c->dev), i2c);
+ if (ret)
+ return dev_err_probe(dev, ret, "failed to request irq");
+
platform_set_drvdata(pdev, i2c);
ret = i2c_add_numbered_adapter(&i2c->adapt);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 357/438] i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (355 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 356/438] i2c: spacemit: request IRQ after controller initialization Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 358/438] i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock Greg Kroah-Hartman
` (94 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wenmeng Liu, Vladimir Zapolskiy,
Konrad Dybcio, Loic Poulain, Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>
commit b08c9857aa1f5f3a81d375d6d4bb1d8b92f22ebc upstream.
cci_resume() unconditionally calls cci_resume_runtime() regardless of
the runtime PM state.
If the device is already runtime-suspended before system suspend,
the clock is re-enabled while runtime_status remains RPM_SUSPENDED.
As a result, pm_request_autosuspend() does not arm the timer,
leaving the clock permanently enabled.
Fixes: e517526195de ("i2c: Add Qualcomm CCI I2C driver")
Signed-off-by: Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>
Cc: <stable@vger.kernel.org> # v5.8+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260625-cci-v1-1-a100cda673ce@oss.qualcomm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-cci.c | 18 +-----------------
1 file changed, 1 insertion(+), 17 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -493,24 +493,8 @@ static int __maybe_unused cci_resume_run
return 0;
}
-static int __maybe_unused cci_suspend(struct device *dev)
-{
- if (!pm_runtime_suspended(dev))
- return cci_suspend_runtime(dev);
-
- return 0;
-}
-
-static int __maybe_unused cci_resume(struct device *dev)
-{
- cci_resume_runtime(dev);
- pm_request_autosuspend(dev);
-
- return 0;
-}
-
static const struct dev_pm_ops qcom_cci_pm = {
- SET_SYSTEM_SLEEP_PM_OPS(cci_suspend, cci_resume)
+ SET_SYSTEM_SLEEP_PM_OPS(pm_runtime_force_suspend, pm_runtime_force_resume)
SET_RUNTIME_PM_OPS(cci_suspend_runtime, cci_resume_runtime, NULL)
};
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 358/438] i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (356 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 357/438] i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 359/438] i2c: iproc: reset bus after timeout if START_BUSY is stuck Greg Kroah-Hartman
` (93 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, H. Nikolaus Schaller, Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: H. Nikolaus Schaller <hns@goldelico.com>
commit d99607c888f26e8a4e9fe9772860cef4aff86bb4 upstream.
Fix a severe AB/BA deadlock between the Common Clock Framework (CCF)
and the I2C adapter lock, which triggers when an I2C-controlled clock
generator client (like the Si5351) is registered or modified under the CCF.
During an i2c client clock (generator) frequency change, the CCF acquires its global
'prepare_lock' mutex and the driver calls i2c_transfer() to update the client's
chip registers, stalling for the adapter's I2C bus lock.
Concurrently, an independent, parallel transfer on the same bus (e.g., a GPIO
expander handling LEDs) can hold the I2C adapter lock. Inside this parallel
transfer path, jz4780_i2c_set_speed() calls clk_get_rate() on the host
controller's input clock to calculate bus timings. This call attempts to acquire
the blocked CCF 'prepare_lock', creating a circular dependency that freezes
the system.
The jz4780 host controller clock itself is static and never changes at runtime.
However, calling clk_get_rate() inside the active transfer path introduces
an unnecessary dependency on the CCF internal locks.
Eliminate this synchronous clk_get_rate() call from the active transfer
path by caching the static host peripheral clock rate once - inside the private
jz4780_i2c structure during jz4780_i2c_probe(). Update jz4780_i2c_set_speed()
to use this cached value, safely decoupling active I2C transactions from the
CCF internal locks without any risk of stale timings.
Assisted-by web based Google AI (pinpointing the bug and writing the message).
Fixes: ba92222ed63a12 ("i2c: jz4780: Add i2c bus controller driver for Ingenic JZ4780")
Signed-off-by: H. Nikolaus Schaller <hns@goldelico.com>
Cc: <stable@vger.kernel.org> # v4.1+
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/2db6fd233aceb7238474e4833f4d25ca681c3ffb.1784492382.git.hns@goldelico.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-jz4780.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/i2c/busses/i2c-jz4780.c
+++ b/drivers/i2c/busses/i2c-jz4780.c
@@ -141,6 +141,7 @@ struct jz4780_i2c {
void __iomem *iomem;
int irq;
struct clk *clk;
+ unsigned long clk_rate_khz;
struct i2c_adapter adap;
const struct ingenic_i2c_config *cdata;
@@ -246,7 +247,7 @@ static int jz4780_i2c_set_target(struct
static int jz4780_i2c_set_speed(struct jz4780_i2c *i2c)
{
- int dev_clk_khz = clk_get_rate(i2c->clk) / 1000;
+ int dev_clk_khz = i2c->clk_rate_khz;
int cnt_high = 0; /* HIGH period count of the SCL clock */
int cnt_low = 0; /* LOW period count of the SCL clock */
int cnt_period = 0; /* period count of the SCL clock */
@@ -796,6 +797,8 @@ static int jz4780_i2c_probe(struct platf
if (IS_ERR(i2c->clk))
return PTR_ERR(i2c->clk);
+ i2c->clk_rate_khz = clk_get_rate(i2c->clk) / 1000;
+
ret = of_property_read_u32(pdev->dev.of_node, "clock-frequency",
&clk_freq);
if (ret) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 359/438] i2c: iproc: reset bus after timeout if START_BUSY is stuck
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (357 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 358/438] i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 360/438] i2c: imx: mark I2C adapter when hardware is powered down Greg Kroah-Hartman
` (92 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jonas Gorski, Ray Jui, Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonas Gorski <jonas.gorski@bisdn.de>
commit 98f2e9e6d6f91a6abb43f166b244b428ba85fa2b upstream.
If a transaction times out, the START_BUSY signal can stay up, and
subsequent transactaction attempts will fail as the bus is still
considered busy.
I can easily trigger this by attempting to read from an address with no
device, e.g. when running i2cdetect. After the first read times out, all
subsequent read attempts return busy.
To get to a working state again, the controller needs to be reset to
clear the START_BUSY signal. So check for START_BUSY still asserted on a
timeout, and do reset in case it is,
This is also done by the original non-upstream iproc-smbus driver
implementation [1].
Works around situations like:
bcm-iproc-2c 1803b000.i2c: transaction timed out
bcm-iproc-2c 1803b000.i2c: bus is busy
bcm-iproc-2c 1803b000.i2c: bus is busy
bcm-iproc-2c 1803b000.i2c: bus is busy
bcm-iproc-2c 1803b000.i2c: bus is busy
bcm-iproc-2c 1803b000.i2c: bus is busy
...
where the bus never recovers after a timeout.
[1] https://github.com/opencomputeproject/onie/blob/master/patches/kernel/3.2.69/driver-iproc-smbus.patch
Fixes: e6e5dd3566e0 ("i2c: iproc: Add Broadcom iProc I2C Driver")
Signed-off-by: Jonas Gorski <jonas.gorski@bisdn.de>
Cc: <stable@vger.kernel.org> # v4.0+
Acked-by: Ray Jui <ray.jui@broadcom.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260717085507.34209-1-jonas.gorski@bisdn.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-bcm-iproc.c | 11 +++++++++++
1 file changed, 11 insertions(+)
--- a/drivers/i2c/busses/i2c-bcm-iproc.c
+++ b/drivers/i2c/busses/i2c-bcm-iproc.c
@@ -803,6 +803,17 @@ static int bcm_iproc_i2c_xfer_wait(struc
}
if (!time_left && !iproc_i2c->xfer_is_done) {
+ /*
+ * The controller may fail to clear START_BUSY after a timeout,
+ * reset the controller to recover in that case.
+ */
+ if (!!(iproc_i2c_rd_reg(iproc_i2c, M_CMD_OFFSET) &
+ BIT(M_CMD_START_BUSY_SHIFT))) {
+ bcm_iproc_i2c_enable_disable(iproc_i2c, false);
+ bcm_iproc_i2c_init(iproc_i2c);
+ bcm_iproc_i2c_enable_disable(iproc_i2c, true);
+ }
+
/* flush both TX/RX FIFOs */
val = BIT(M_FIFO_RX_FLUSH_SHIFT) | BIT(M_FIFO_TX_FLUSH_SHIFT);
iproc_i2c_wr_reg(iproc_i2c, M_FIFO_CTRL_OFFSET, val);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 360/438] i2c: imx: mark I2C adapter when hardware is powered down
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (358 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 359/438] i2c: iproc: reset bus after timeout if START_BUSY is stuck Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 361/438] i2c: imx: Fix slave registration race and error handling Greg Kroah-Hartman
` (91 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Carlos Song, Frank Li,
Oleksij Rempel, Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carlos Song <carlos.song@nxp.com>
commit 00d86dd5c2034e0e139e4806137b3b43e07ddd83 upstream.
On some i.MX platforms, certain I2C client drivers keep a periodic
workqueue which continues to trigger I2C transfers.
During system suspend/resume, there exists a time window between:
- suspend_noirq and the system entering suspend
- the system starting to resume and resume_noirq
In this window, the I2C controller resources such as clock and pinctrl
may already be disabled or not yet restored.
If a workqueue triggers an I2C transfer in this period, the driver
attempts to access I2C registers while the hardware resources are
unavailable, which may lead to system hang.
Mark the I2C adapter as suspended during noirq suspend and block new
transfers until resume, ensuring that I2C transfers are only issued
when hardware resources are available.
Fixes: 358025ac091e ("i2c: imx: make controller available until system suspend_noirq() and from resume_noirq()")
Signed-off-by: Carlos Song <carlos.song@nxp.com>
Cc: <stable@vger.kernel.org> # v6.14+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Acked-by: Oleksij Rempel <o.rempel@pengutronix.de>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260525030400.3182911-1-carlos.song@oss.nxp.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 45 +++++++++++++++++++++++++++++++++++++++++--
1 file changed, 43 insertions(+), 2 deletions(-)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -1952,6 +1952,47 @@ static int i2c_imx_runtime_resume(struct
return 0;
}
+static int __maybe_unused i2c_imx_suspend_noirq(struct device *dev)
+{
+ struct imx_i2c_struct *i2c_imx = dev_get_drvdata(dev);
+ int ret;
+
+ i2c_mark_adapter_suspended(&i2c_imx->adapter);
+
+ /*
+ * Cancel the slave timer before powering down to prevent
+ * i2c_imx_slave_timeout() from accessing hardware registers
+ * while the clock is disabled.
+ */
+ hrtimer_cancel(&i2c_imx->slave_timer);
+
+ ret = pm_runtime_force_suspend(dev);
+ if (ret) {
+ i2c_mark_adapter_resumed(&i2c_imx->adapter);
+ if (i2c_imx->slave) {
+ hrtimer_forward_now(&i2c_imx->slave_timer, I2C_IMX_CHECK_DELAY);
+ hrtimer_restart(&i2c_imx->slave_timer);
+ }
+ return ret;
+ }
+
+ return 0;
+}
+
+static int __maybe_unused i2c_imx_resume_noirq(struct device *dev)
+{
+ struct imx_i2c_struct *i2c_imx = dev_get_drvdata(dev);
+ int ret;
+
+ ret = pm_runtime_force_resume(dev);
+ if (ret)
+ return ret;
+
+ i2c_mark_adapter_resumed(&i2c_imx->adapter);
+
+ return 0;
+}
+
static int i2c_imx_suspend(struct device *dev)
{
/*
@@ -1985,8 +2026,8 @@ static int i2c_imx_resume(struct device
}
static const struct dev_pm_ops i2c_imx_pm_ops = {
- NOIRQ_SYSTEM_SLEEP_PM_OPS(pm_runtime_force_suspend,
- pm_runtime_force_resume)
+ NOIRQ_SYSTEM_SLEEP_PM_OPS(i2c_imx_suspend_noirq,
+ i2c_imx_resume_noirq)
SYSTEM_SLEEP_PM_OPS(i2c_imx_suspend, i2c_imx_resume)
RUNTIME_PM_OPS(i2c_imx_runtime_suspend, i2c_imx_runtime_resume, NULL)
};
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 361/438] i2c: imx: Fix slave registration race and error handling
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (359 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 360/438] i2c: imx: mark I2C adapter when hardware is powered down Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 362/438] i2c: imx: Cancel hrtimer before clearing slave pointer Greg Kroah-Hartman
` (90 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Liem, Frank Li, Carlos Song,
Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liem <liem16213@gmail.com>
commit d64ec362c369bbc33833f7936d5f3a706b0d5c45 upstream.
In i2c_imx_reg_slave(), the slave pointer was assigned before
pm_runtime_resume_and_get(). If pm_runtime_resume_and_get() failed,
the error path returned without clearing i2c_imx->slave, leaving it
non-NULL and causing all subsequent registration attempts to fail
with -EBUSY.
Additionally, because this driver uses a shared IRQ, the interrupt
handler i2c_imx_isr() can execute concurrently and, after acquiring
slave_lock, dereference i2c_imx->slave. The previous fix attempt
added a lockless i2c_imx->slave = NULL on the error path, but that
could race with the ISR under the lock and still cause a NULL pointer
dereference.
Fix both issues by deferring the assignment of i2c_imx->slave and
i2c_imx->last_slave_event to after a successful resume, and by
performing the assignment inside the slave_lock critical section.
This guarantees that the slave pointer is never left stale on the
error path and is always valid when observed by the interrupt handler.
Fixes: f7414cd6923f ("i2c: imx: support slave mode for imx I2C driver")
Signed-off-by: Liem <liem16213@gmail.com>
Cc: <stable@vger.kernel.org> # v5.11+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Acked-by: Carlos Song <carlos.song@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260629023829.152651-2-liem16213@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -930,9 +930,6 @@ static int i2c_imx_reg_slave(struct i2c_
if (i2c_imx->slave)
return -EBUSY;
- i2c_imx->slave = client;
- i2c_imx->last_slave_event = I2C_SLAVE_STOP;
-
/* Resume */
ret = pm_runtime_resume_and_get(i2c_imx->adapter.dev.parent);
if (ret < 0) {
@@ -940,6 +937,11 @@ static int i2c_imx_reg_slave(struct i2c_
return ret;
}
+ scoped_guard(spinlock_irqsave, &i2c_imx->slave_lock) {
+ i2c_imx->slave = client;
+ i2c_imx->last_slave_event = I2C_SLAVE_STOP;
+ }
+
i2c_imx_slave_init(i2c_imx);
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 362/438] i2c: imx: Cancel hrtimer before clearing slave pointer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (360 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 361/438] i2c: imx: Fix slave registration race and error handling Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 363/438] can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured Greg Kroah-Hartman
` (89 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Liem, Carlos Song, Frank Li,
Andi Shyti
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liem <liem16213@gmail.com>
commit 6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f upstream.
In i2c_imx_unreg_slave(), the slave pointer is set to NULL after
disabling interrupts. However, a pending interrupt might already
have started the hrtimer (i2c_imx_slave_timeout) before the pointer
was cleared. If the hrtimer fires after i2c_imx->slave is set to
NULL, the timer callback i2c_imx_slave_finish_op() will call
i2c_imx_slave_event() with a NULL slave pointer, which results in a
use-after-free / NULL pointer dereference.
Fix by canceling the hrtimer and waiting for it to complete after
disabling interrupts, before clearing the slave pointer.
Fixes: f7414cd6923f ("i2c: imx: support slave mode for imx I2C driver")
Signed-off-by: Liem <liem16213@gmail.com>
Cc: <stable@vger.kernel.org> # v5.11+
Acked-by: Carlos Song <carlos.song@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260629023829.152651-3-liem16213@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -960,6 +960,7 @@ static int i2c_imx_unreg_slave(struct i2
i2c_imx_reset_regs(i2c_imx);
+ hrtimer_cancel(&i2c_imx->slave_timer);
i2c_imx->slave = NULL;
/* Suspend */
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 363/438] can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (361 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 362/438] i2c: imx: Cancel hrtimer before clearing slave pointer Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 364/438] can: ems_usb: validate CPC message lengths Greg Kroah-Hartman
` (88 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lucas Martins Alves, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lucas Martins Alves <lucas.alves@lumal21.com.br>
commit 26504844613fb44c7cab1c5f6fcff77861709baa upstream.
c_can_chip_config() was programming C_CAN_CTRL_REG without CONTROL_INIT,
which may allow the controller to become active before
c_can_set_bittiming() finishes.
That creates a short timing window where the peripheral can interact with
the bus using a different/default bitrate, potentially generating bus
errors and corrupting traffic.
Set CONTROL_INIT together with the control-mode writes in
c_can_chip_config() (normal, loopback and listen-only paths), so the
controller stays halted until bit timing is fully programmed.
This prevents transient bus disturbance during startup when the configured
bitrate differs from the active bus bitrate.
Signed-off-by: Lucas Martins Alves <lucas.alves@lumal21.com.br>
Link: https://patch.msgid.link/20260714164839.771123-1-lucas.alves@lumal21.com.br
Fixes: 881ff67ad450 ("can: c_can: Added support for Bosch C_CAN controller")
Cc: stable@kernel.org
[mkl: remove space before close parenthesis]
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/c_can/c_can_main.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/drivers/net/can/c_can/c_can_main.c
+++ b/drivers/net/can/c_can/c_can_main.c
@@ -597,20 +597,20 @@ static int c_can_chip_config(struct net_
return err;
/* enable automatic retransmission */
- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_ENABLE_AR);
+ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_ENABLE_AR | CONTROL_INIT);
if ((priv->can.ctrlmode & CAN_CTRLMODE_LISTENONLY) &&
(priv->can.ctrlmode & CAN_CTRLMODE_LOOPBACK)) {
/* loopback + silent mode : useful for hot self-test */
- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST);
+ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST | CONTROL_INIT);
priv->write_reg(priv, C_CAN_TEST_REG, TEST_LBACK | TEST_SILENT);
} else if (priv->can.ctrlmode & CAN_CTRLMODE_LOOPBACK) {
/* loopback mode : useful for self-test function */
- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST);
+ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST | CONTROL_INIT);
priv->write_reg(priv, C_CAN_TEST_REG, TEST_LBACK);
} else if (priv->can.ctrlmode & CAN_CTRLMODE_LISTENONLY) {
/* silent mode : bus-monitoring mode */
- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST);
+ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST | CONTROL_INIT);
priv->write_reg(priv, C_CAN_TEST_REG, TEST_SILENT);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 364/438] can: ems_usb: validate CPC message lengths
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (362 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 363/438] can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 365/438] can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure Greg Kroah-Hartman
` (87 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 02925f51377f2a42a6724f00549167499c9302e5 upstream.
ems_usb_read_bulk_callback() walks CPC messages packed in one USB
receive buffer.
Check that each declared message fits in the URB payload. Also require the
type-specific payload to cover the fields used by the CAN, state, error and
overrun handlers.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260706092752.79600-1-pengpeng@iscas.ac.cn
Fixes: 702171adeed3 ("ems_usb: Added support for EMS CPC-USB/ARM7 CAN/USB interface")
Cc: stable@vger.kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/ems_usb.c | 43 ++++++++++++++++++++++++++++++++++++++++++
1 file changed, 43 insertions(+)
--- a/drivers/net/can/usb/ems_usb.c
+++ b/drivers/net/can/usb/ems_usb.c
@@ -409,6 +409,40 @@ static void ems_usb_rx_err(struct ems_us
netif_rx(skb);
}
+static bool ems_usb_rx_msg_len_valid(struct ems_cpc_msg *msg)
+{
+ size_t len = msg->length;
+ size_t can_len;
+
+ switch (msg->type) {
+ case CPC_MSG_TYPE_CAN_STATE:
+ return len >= sizeof(msg->msg.can_state);
+
+ case CPC_MSG_TYPE_CAN_FRAME:
+ case CPC_MSG_TYPE_EXT_CAN_FRAME:
+ case CPC_MSG_TYPE_RTR_FRAME:
+ case CPC_MSG_TYPE_EXT_RTR_FRAME:
+ if (len < CPC_CAN_MSG_MIN_SIZE)
+ return false;
+
+ if (msg->type == CPC_MSG_TYPE_RTR_FRAME ||
+ msg->type == CPC_MSG_TYPE_EXT_RTR_FRAME)
+ return true;
+
+ can_len = can_cc_dlc2len(msg->msg.can_msg.length & 0xf);
+ return len >= CPC_CAN_MSG_MIN_SIZE + can_len;
+
+ case CPC_MSG_TYPE_CAN_FRAME_ERROR:
+ return len >= sizeof(msg->msg.error);
+
+ case CPC_MSG_TYPE_OVERRUN:
+ return len >= sizeof(msg->msg.overrun);
+
+ default:
+ return true;
+ }
+}
+
/*
* callback for bulk IN urb
*/
@@ -451,6 +485,15 @@ static void ems_usb_read_bulk_callback(s
}
msg = (struct ems_cpc_msg *)&ibuf[start];
+ if (msg->length >
+ urb->actual_length - start - CPC_MSG_HEADER_LEN) {
+ netdev_err(netdev, "format error\n");
+ break;
+ }
+ if (!ems_usb_rx_msg_len_valid(msg)) {
+ netdev_err(netdev, "format error\n");
+ break;
+ }
switch (msg->type) {
case CPC_MSG_TYPE_CAN_STATE:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 365/438] can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (363 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 364/438] can: ems_usb: validate CPC message lengths Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 366/438] can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure Greg Kroah-Hartman
` (86 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Vincent Mailhol,
stable, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 7a0cf2b2497c757c3cb1286eddf2986abb0d387b upstream.
es58x_read_bulk_callback() resubmits the RX URB after processing a received
packet. If the resubmit succeeds, the URB remains anchored and will be
handled by the normal RX path or by teardown.
However, if usb_submit_urb() fails, the callback unanchors the URB and then
returns directly. This skips the existing free_urb path, so the coherent
transfer buffer allocated with usb_alloc_coherent() is not released.
Reuse the existing free_urb path after a resubmit failure so that the RX
coherent buffer is freed before leaving the callback.
Fixes: 5eaad4f76826 ("can: usb: etas_es58x: correctly anchor the urb in the read bulk callback")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/20260706014601.415445-1-lgs201920130244@gmail.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/etas_es58x/es58x_core.c | 1 -
1 file changed, 1 deletion(-)
--- a/drivers/net/can/usb/etas_es58x/es58x_core.c
+++ b/drivers/net/can/usb/etas_es58x/es58x_core.c
@@ -1476,7 +1476,6 @@ static void es58x_read_bulk_callback(str
dev_err_ratelimited(dev,
"Failed resubmitting read bulk urb: %pe\n",
ERR_PTR(ret));
- return;
free_urb:
usb_free_coherent(urb->dev, urb->transfer_buffer_length,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 366/438] can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (364 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 365/438] can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 367/438] can: isotp: fix timer drain order, wakeup handling and tx_gen ordering Greg Kroah-Hartman
` (85 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marc Kleine-Budde <mkl@pengutronix.de>
commit 68c5724ecd159992f76edb7b57dc508a44c8b7da upstream.
If the allocation of the SKB in gs_usb_receive_bulk_callback() fails, the
driver returns from the callback without resubmitting the URB in order to
receive further USB in URBs.
This results in a silent performance degradation which, if it occurs
repeatedly, results in starvation of USB in traffic.
Instead of returning immediately, try to resend the URB. If this also
fails, this is logged as an info message.
Fixes: d08e973a77d1 ("can: gs_usb: Added support for the GS_USB CAN devices")
Fixes: 26949ac935e3 ("can: gs_usb: add CAN-FD support")
Link: https://patch.msgid.link/20260709-gs_usb-resubmit-urb-v1-1-4dd40030cc84@pengutronix.de
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/gs_usb.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/net/can/usb/gs_usb.c
+++ b/drivers/net/can/usb/gs_usb.c
@@ -674,7 +674,7 @@ static void gs_usb_receive_bulk_callback
if (hf->flags & GS_CAN_FLAG_FD) {
skb = alloc_canfd_skb(netdev, &cfd);
if (!skb)
- return;
+ goto resubmit_urb;
cfd->can_id = le32_to_cpu(hf->can_id);
cfd->len = data_length;
@@ -687,7 +687,7 @@ static void gs_usb_receive_bulk_callback
} else {
skb = alloc_can_skb(netdev, &cf);
if (!skb)
- return;
+ goto resubmit_urb;
cf->can_id = le32_to_cpu(hf->can_id);
can_frame_set_cc_len(cf, hf->can_dlc, dev->can.ctrlmode);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 367/438] can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (365 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 366/438] can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 368/438] can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Greg Kroah-Hartman
` (84 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Oliver Hartkopp, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oliver Hartkopp <socketcan@hartkopp.net>
commit 050f010f920da17c1044a4f174766ad553e770b6 upstream.
This patch is a follow-up to commit cf070fe33bfb ("can: isotp: serialize
TX state transitions under so->rx_lock") which addresses following
sashiko-bot findings:
- isotp_sendmsg(): drain so->txfrtimer first so a stale callback can't
re-arm echotimer after the claim
- isotp_release(): wake so->wait after forcing ISOTP_SHUTDOWN so a
sleeping sendmsg() claim isn't stranded
- isotp_sendmsg(): have both wait_event_interruptible() calls in
isotp_sendmsg() also wake on ISOTP_SHUTDOWN and do not return claim to
IDLE to avoid corrupting a concurrent isotp_release() process.
- isotp_sendmsg(): handle potential claim of a new transfer when
the wait_event_interruptible() call returns in CAN_ISOTP_WAIT_TX_DONE
mode. Don't touch timers and states of the new transfer if a new thread
incremented so->tx_gen before getting the lock at err_event_drop.
- isotp_sendmsg(): handle a stuck can_send() and omit timer and state
changes if a new transfer was claimed. wait_tx_done() returns the error
recorded in so->tx_result[], tagged with the caller's own generation.
- isotp_tx_timeout(): on a claimed timeout, record the ECOMM error for
the timed-out transfer's own generation in so->tx_result[]; sk->sk_err
is raised unconditionally, same as every other error path here.
- isotp_tx_gen_done()/isotp_tx_timeout(): always read tx.state (acquire)
before tx_gen - the reverse order let a weakly ordered CPU pair a fresh
tx.state with a stale tx_gen/tx_result slot.
- isotp_sendmsg(): wait_tx_done: drain sk_err via sock_error() once we
have read the result from so->tx_result[], so an already-reported error
doesn't stay latched for a later poll()/SO_ERROR.
Also align the remaining lock-free so->tx.state/rx.state/cfecho accesses
and use skb->hash as unique loopback echo frame indicator.
Fixes: cf070fe33bfb ("can: isotp: serialize TX state transitions under so->rx_lock")
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Link: https://patch.msgid.link/20260724181525.43556-1-socketcan@hartkopp.net
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/can/isotp.c | 317 ++++++++++++++++++++++++++++++++++++++++----------------
1 file changed, 230 insertions(+), 87 deletions(-)
--- a/net/can/isotp.c
+++ b/net/can/isotp.c
@@ -127,6 +127,15 @@ MODULE_PARM_DESC(max_pdu_size, "maximum
#define ISOTP_FC_TIMEOUT 1 /* 1 sec */
#define ISOTP_ECHO_TIMEOUT 2 /* 2 secs */
+/* so->tx_result[so->tx_gen % ISOTP_TX_RESULT_SLOTS] holds the packed value
+ * (err << ISOTP_TX_RESULT_GEN_BITS | gen) for each tx generation slot, so it
+ * can be handled with a single READ_ONCE()/WRITE_ONCE() access.
+ */
+#define ISOTP_TX_RESULT_SLOTS 4
+#define ISOTP_TX_RESULT_GEN_BITS 24
+#define ISOTP_TX_RESULT_GEN_MASK ((1U << ISOTP_TX_RESULT_GEN_BITS) - 1)
+#define ISOTP_TX_RESULT_ERR_MASK 0xFF
+
enum {
ISOTP_IDLE = 0,
ISOTP_WAIT_FIRST_FC,
@@ -166,7 +175,8 @@ struct isotp_sock {
u32 force_tx_stmin;
u32 force_rx_stmin;
u32 cfecho; /* consecutive frame echo tag */
- u32 tx_gen; /* generation, bumped per new tx transfer */
+ u32 tx_gen; /* transfer generation, increased per new tx transfer */
+ u32 tx_result[ISOTP_TX_RESULT_SLOTS]; /* per-generation result slots */
struct tpcon rx, tx;
struct list_head notifier;
wait_queue_head_t wait;
@@ -177,6 +187,65 @@ static LIST_HEAD(isotp_notifier_list);
static DEFINE_SPINLOCK(isotp_notifier_lock);
static struct isotp_sock *isotp_busy_notifier;
+/* increase (24 bit) tx generation value */
+static u32 isotp_inc_tx_gen(u32 gen)
+{
+ return (gen + 1) & ISOTP_TX_RESULT_GEN_MASK;
+}
+
+/* store 8 bit error and 24 bit tx generation values in packed u32 element */
+static u32 isotp_pack_tx_result(u32 gen, int err)
+{
+ return gen | ((u32)err << ISOTP_TX_RESULT_GEN_BITS);
+}
+
+/* get the 24 bit tx generation value from the tx result */
+static u32 isotp_get_tx_gen(u32 gen_err)
+{
+ return gen_err & ISOTP_TX_RESULT_GEN_MASK;
+}
+
+/* get the 8 bit error value from the tx result */
+static u32 isotp_get_tx_err(u32 gen_err)
+{
+ return (gen_err >> ISOTP_TX_RESULT_GEN_BITS) & ISOTP_TX_RESULT_ERR_MASK;
+}
+
+/* store transfer result in per-generation%4 so->tx_result[] slot */
+static void isotp_set_tx_result(struct isotp_sock *so, u32 gen, int err)
+{
+ WRITE_ONCE(so->tx_result[gen % ISOTP_TX_RESULT_SLOTS],
+ isotp_pack_tx_result(gen, err));
+}
+
+/* fetch the result recorded for 'gen', as a (negative) errno (0 for success) */
+static int isotp_get_tx_result(struct isotp_sock *so, u32 gen)
+{
+ u32 result = READ_ONCE(so->tx_result[gen % ISOTP_TX_RESULT_SLOTS]);
+
+ if (isotp_get_tx_gen(result) != gen) {
+ pr_notice_once("can-isotp: tx_result[] slot reused before read\n");
+
+ /* report failure rather than risk a false success */
+ return -ECOMM;
+ }
+
+ return -(isotp_get_tx_err(result));
+}
+
+/* true if done, shut down or superseded ('gen' is no longer the active
+ * transfer). Reads tx.state first (acquire) so tx_gen/tx_result reads
+ * below see at least what that state write published (common sequence).
+ */
+static bool isotp_tx_gen_done(struct isotp_sock *so, u32 gen)
+{
+ /* read tx.state first for the common sequence */
+ u32 state = smp_load_acquire(&so->tx.state);
+
+ return state == ISOTP_IDLE || state == ISOTP_SHUTDOWN ||
+ READ_ONCE(so->tx_gen) != gen;
+}
+
static inline struct isotp_sock *isotp_sk(const struct sock *sk)
{
return (struct isotp_sock *)sk;
@@ -199,7 +268,7 @@ static enum hrtimer_restart isotp_rx_tim
rxtimer);
struct sock *sk = &so->sk;
- if (so->rx.state == ISOTP_WAIT_DATA) {
+ if (READ_ONCE(so->rx.state) == ISOTP_WAIT_DATA) {
/* we did not get new data frames in time */
/* report 'connection timed out' */
@@ -208,7 +277,7 @@ static enum hrtimer_restart isotp_rx_tim
sk_error_report(sk);
/* reset rx state */
- so->rx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->rx.state, ISOTP_IDLE);
}
return HRTIMER_NORESTART;
@@ -372,20 +441,19 @@ static void isotp_send_cframe(struct iso
static int isotp_rcv_fc(struct isotp_sock *so, struct canfd_frame *cf, int ae)
{
struct sock *sk = &so->sk;
+ int tx_err = EBADMSG; /* default for unknown FC status */
- if (so->tx.state != ISOTP_WAIT_FC &&
- so->tx.state != ISOTP_WAIT_FIRST_FC)
+ if (READ_ONCE(so->tx.state) != ISOTP_WAIT_FC &&
+ READ_ONCE(so->tx.state) != ISOTP_WAIT_FIRST_FC)
return 0;
hrtimer_cancel(&so->txtimer);
/* isotp_tx_timeout() may have given up on this job while
- * hrtimer_cancel() above waited for it to finish; so->rx_lock
- * (held by our caller isotp_rcv()) rules out a concurrent claim,
- * so a plain recheck is enough here.
+ * hrtimer_cancel() above waited for it to finish => recheck
*/
- if (so->tx.state != ISOTP_WAIT_FC &&
- so->tx.state != ISOTP_WAIT_FIRST_FC)
+ if (READ_ONCE(so->tx.state) != ISOTP_WAIT_FC &&
+ READ_ONCE(so->tx.state) != ISOTP_WAIT_FIRST_FC)
return 1;
if ((cf->len < ae + FC_CONTENT_SZ) ||
@@ -396,13 +464,15 @@ static int isotp_rcv_fc(struct isotp_soc
if (!sock_flag(sk, SOCK_DEAD))
sk_error_report(sk);
- so->tx.state = ISOTP_IDLE;
+ isotp_set_tx_result(so, so->tx_gen, EBADMSG);
+ /* set to IDLE after publishing tx_result */
+ smp_store_release(&so->tx.state, ISOTP_IDLE);
wake_up_interruptible(&so->wait);
return 1;
}
/* get static/dynamic communication params from first/every FC frame */
- if (so->tx.state == ISOTP_WAIT_FIRST_FC ||
+ if (READ_ONCE(so->tx.state) == ISOTP_WAIT_FIRST_FC ||
so->opt.flags & CAN_ISOTP_DYN_FC_PARMS) {
so->txfc.bs = cf->data[ae + 1];
so->txfc.stmin = cf->data[ae + 2];
@@ -426,13 +496,13 @@ static int isotp_rcv_fc(struct isotp_soc
so->tx_gap = ktime_add_ns(so->tx_gap,
(so->txfc.stmin - 0xF0)
* 100000);
- so->tx.state = ISOTP_WAIT_FC;
+ WRITE_ONCE(so->tx.state, ISOTP_WAIT_FC);
}
switch (cf->data[ae] & 0x0F) {
case ISOTP_FC_CTS:
so->tx.bs = 0;
- so->tx.state = ISOTP_SENDING;
+ WRITE_ONCE(so->tx.state, ISOTP_SENDING);
/* send CF frame and enable echo timeout handling */
hrtimer_start(&so->echotimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
HRTIMER_MODE_REL_SOFT);
@@ -447,14 +517,19 @@ static int isotp_rcv_fc(struct isotp_soc
case ISOTP_FC_OVFLW:
/* overflow on receiver side - report 'message too long' */
- sk->sk_err = EMSGSIZE;
- if (!sock_flag(sk, SOCK_DEAD))
- sk_error_report(sk);
+ tx_err = EMSGSIZE;
fallthrough;
default:
- /* stop this tx job */
- so->tx.state = ISOTP_IDLE;
+ /* reserved/unknown flow status (tx_err defaults to EBADMSG) */
+
+ sk->sk_err = tx_err;
+ if (!sock_flag(sk, SOCK_DEAD))
+ sk_error_report(sk);
+
+ isotp_set_tx_result(so, so->tx_gen, tx_err);
+ /* set to IDLE after publishing tx_result */
+ smp_store_release(&so->tx.state, ISOTP_IDLE);
wake_up_interruptible(&so->wait);
}
return 0;
@@ -467,7 +542,7 @@ static int isotp_rcv_sf(struct sock *sk,
struct sk_buff *nskb;
hrtimer_cancel(&so->rxtimer);
- so->rx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->rx.state, ISOTP_IDLE);
if (!len || len > cf->len - pcilen)
return 1;
@@ -501,7 +576,7 @@ static int isotp_rcv_ff(struct sock *sk,
int ff_pci_sz;
hrtimer_cancel(&so->rxtimer);
- so->rx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->rx.state, ISOTP_IDLE);
/* get the used sender LL_DL from the (first) CAN frame data length */
so->rx.ll_dl = padlen(cf->len);
@@ -555,7 +630,7 @@ static int isotp_rcv_ff(struct sock *sk,
/* initial setup for this pdu reception */
so->rx.sn = 1;
- so->rx.state = ISOTP_WAIT_DATA;
+ WRITE_ONCE(so->rx.state, ISOTP_WAIT_DATA);
/* no creation of flow control frames */
if (so->opt.flags & CAN_ISOTP_LISTEN_MODE)
@@ -573,7 +648,7 @@ static int isotp_rcv_cf(struct sock *sk,
struct sk_buff *nskb;
int i;
- if (so->rx.state != ISOTP_WAIT_DATA)
+ if (READ_ONCE(so->rx.state) != ISOTP_WAIT_DATA)
return 0;
/* drop if timestamp gap is less than force_rx_stmin nano secs */
@@ -588,11 +663,9 @@ static int isotp_rcv_cf(struct sock *sk,
hrtimer_cancel(&so->rxtimer);
/* isotp_rx_timer_handler() may have raced us for so->rx.state
- * while hrtimer_cancel() above waited for it to finish, already
- * reporting ETIMEDOUT and resetting the reception; don't process
- * this CF into a reassembly that has already been given up on.
+ * while hrtimer_cancel() above waited for it to finish => recheck
*/
- if (so->rx.state != ISOTP_WAIT_DATA)
+ if (READ_ONCE(so->rx.state) != ISOTP_WAIT_DATA)
return 1;
/* CFs are never longer than the FF */
@@ -613,7 +686,7 @@ static int isotp_rcv_cf(struct sock *sk,
sk_error_report(sk);
/* reset rx state */
- so->rx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->rx.state, ISOTP_IDLE);
return 1;
}
so->rx.sn++;
@@ -627,7 +700,7 @@ static int isotp_rcv_cf(struct sock *sk,
if (so->rx.idx >= so->rx.len) {
/* we are done */
- so->rx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->rx.state, ISOTP_IDLE);
if ((so->opt.flags & ISOTP_CHECK_PADDING) &&
check_pad(so, cf, i + 1, so->opt.rxpad_content)) {
@@ -698,8 +771,10 @@ static void isotp_rcv(struct sk_buff *sk
if (so->opt.flags & CAN_ISOTP_HALF_DUPLEX) {
/* check rx/tx path half duplex expectations */
- if ((so->tx.state != ISOTP_IDLE && n_pci_type != N_PCI_FC) ||
- (so->rx.state != ISOTP_IDLE && n_pci_type == N_PCI_FC))
+ if ((READ_ONCE(so->tx.state) != ISOTP_IDLE &&
+ n_pci_type != N_PCI_FC) ||
+ (READ_ONCE(so->rx.state) != ISOTP_IDLE &&
+ n_pci_type == N_PCI_FC))
goto out_unlock;
}
@@ -794,6 +869,7 @@ static void isotp_send_cframe(struct iso
struct canfd_frame *cf;
int can_send_ret;
int ae = (so->opt.flags & CAN_ISOTP_EXTEND_ADDR) ? 1 : 0;
+ u32 old_cfecho;
dev = dev_get_by_index(sock_net(sk), so->ifindex);
if (!dev)
@@ -814,6 +890,9 @@ static void isotp_send_cframe(struct iso
csx->can_iif = dev->ifindex;
+ /* set uid in tx skb to identify CF echo frames */
+ can_set_skb_uid(skb);
+
cf = (struct canfd_frame *)skb->data;
skb_put_zero(skb, so->ll.mtu);
@@ -830,12 +909,15 @@ static void isotp_send_cframe(struct iso
skb->dev = dev;
can_skb_set_owner(skb, sk);
- /* cfecho should have been zero'ed by init/isotp_rcv_echo() */
- if (so->cfecho)
- pr_notice_once("can-isotp: cfecho is %08X != 0\n", so->cfecho);
+ /* zero'ed by init/isotp_rcv_echo(); reached lock-free via
+ * isotp_txfr_timer_handler() too, so use READ_ONCE()/WRITE_ONCE()
+ */
+ old_cfecho = READ_ONCE(so->cfecho);
+ if (old_cfecho)
+ pr_notice_once("can-isotp: cfecho is %08X != 0\n", old_cfecho);
/* set consecutive frame echo tag */
- so->cfecho = *(u32 *)cf->data;
+ WRITE_ONCE(so->cfecho, skb->hash);
/* send frame with local echo enabled */
can_send_ret = can_send(skb, 1);
@@ -887,7 +969,6 @@ static void isotp_rcv_echo(struct sk_buf
{
struct sock *sk = (struct sock *)data;
struct isotp_sock *so = isotp_sk(sk);
- struct canfd_frame *cf = (struct canfd_frame *)skb->data;
/* only handle my own local echo CF/SF skb's (no FF!) */
if (skb->sk != sk)
@@ -899,32 +980,35 @@ static void isotp_rcv_echo(struct sk_buf
spin_lock(&so->rx_lock);
/* so->cfecho may since belong to a new transfer; recheck under lock */
- if (so->cfecho != *(u32 *)cf->data)
+ if (READ_ONCE(so->cfecho) != skb->hash)
goto out_unlock;
/* cancel local echo timeout */
hrtimer_cancel(&so->echotimer);
/* local echo skb with consecutive frame has been consumed */
- so->cfecho = 0;
+ WRITE_ONCE(so->cfecho, 0);
/* claiming a transfer also takes so->rx_lock, so a plain recheck
* is enough: so->tx.state can't have flipped to ISOTP_SENDING for
* a new claim while we're still in here
*/
- if (so->tx.state != ISOTP_SENDING)
+ if (READ_ONCE(so->tx.state) != ISOTP_SENDING)
goto out_unlock;
if (so->tx.idx >= so->tx.len) {
/* we are done */
- so->tx.state = ISOTP_IDLE;
+
+ isotp_set_tx_result(so, so->tx_gen, 0);
+ /* set to IDLE after publishing tx_result */
+ smp_store_release(&so->tx.state, ISOTP_IDLE);
wake_up_interruptible(&so->wait);
goto out_unlock;
}
if (so->txfc.bs && so->tx.bs >= so->txfc.bs) {
/* stop and wait for FC with timeout */
- so->tx.state = ISOTP_WAIT_FC;
+ WRITE_ONCE(so->tx.state, ISOTP_WAIT_FC);
hrtimer_start(&so->txtimer, ktime_set(ISOTP_FC_TIMEOUT, 0),
HRTIMER_MODE_REL_SOFT);
goto out_unlock;
@@ -946,16 +1030,20 @@ out_unlock:
spin_unlock(&so->rx_lock);
}
-/* shared by so->txtimer's and so->echotimer's callbacks. Both timers get
- * cancelled under so->rx_lock elsewhere, so this must stay lock-free to
- * avoid deadlocking with that; uses so->tx_gen instead to avoid tainting
- * a new transfer with an error from the one that just timed out.
+/* isotp_tx_timeout: we did not get any flow control or echo frame in time
+ *
+ * Shared by so->txtimer's and so->echotimer's callbacks. Both timers get
+ * cancelled under so->rx_lock elsewhere, so this must stay lock-free.
+ *
+ * tx.state is acquired before tx_gen. Common sequence in isotp_tx_gen_done().
+ * cmpxchg() only orders itself, not the two preceding loads.
*/
static enum hrtimer_restart isotp_tx_timeout(struct isotp_sock *so)
{
struct sock *sk = &so->sk;
+ /* read tx.state first for the common sequence */
+ u32 old_state = smp_load_acquire(&so->tx.state);
u32 gen = READ_ONCE(so->tx_gen);
- u32 old_state = READ_ONCE(so->tx.state);
/* don't handle timeouts in IDLE or SHUTDOWN state */
if (old_state == ISOTP_IDLE || old_state == ISOTP_SHUTDOWN)
@@ -965,14 +1053,14 @@ static enum hrtimer_restart isotp_tx_tim
if (cmpxchg(&so->tx.state, old_state, ISOTP_IDLE) != old_state)
return HRTIMER_NORESTART;
- /* we did not get any flow control or echo frame in time */
+ /* detected timeout: report 'communication error on send' */
- if (READ_ONCE(so->tx_gen) == gen) {
- /* report 'communication error on send' */
- sk->sk_err = ECOMM;
- if (!sock_flag(sk, SOCK_DEAD))
- sk_error_report(sk);
- }
+ /* a stale read of this slot by a waiter still falls back to ECOMM */
+ isotp_set_tx_result(so, gen, ECOMM);
+
+ sk->sk_err = ECOMM;
+ if (!sock_flag(sk, SOCK_DEAD))
+ sk_error_report(sk);
wake_up_interruptible(&so->wait);
@@ -1007,7 +1095,7 @@ static enum hrtimer_restart isotp_txfr_t
HRTIMER_MODE_REL_SOFT);
/* cfecho should be consumed by isotp_rcv_echo() here */
- if (so->tx.state == ISOTP_SENDING && !so->cfecho)
+ if (READ_ONCE(so->tx.state) == ISOTP_SENDING && !READ_ONCE(so->cfecho))
isotp_send_cframe(so);
return HRTIMER_NORESTART;
@@ -1026,10 +1114,12 @@ static int isotp_sendmsg(struct socket *
s64 hrtimer_sec = ISOTP_ECHO_TIMEOUT;
struct hrtimer *tx_hrt = &so->echotimer;
u32 new_state = ISOTP_SENDING;
+ u32 my_gen;
+ u32 old_cfecho;
int off;
int err;
- if (!so->bound || so->tx.state == ISOTP_SHUTDOWN)
+ if (!so->bound || READ_ONCE(so->tx.state) == ISOTP_SHUTDOWN)
return -EADDRNOTAVAIL;
/* claim the socket under so->rx_lock: this serializes the claim
@@ -1046,29 +1136,33 @@ static int isotp_sendmsg(struct socket *
if (msg->msg_flags & MSG_DONTWAIT)
return -EAGAIN;
- if (so->tx.state == ISOTP_SHUTDOWN)
+ if (READ_ONCE(so->tx.state) == ISOTP_SHUTDOWN)
return -EADDRNOTAVAIL;
/* wait for complete transmission of current pdu */
err = wait_event_interruptible(so->wait,
- so->tx.state == ISOTP_IDLE);
+ READ_ONCE(so->tx.state) == ISOTP_IDLE ||
+ READ_ONCE(so->tx.state) == ISOTP_SHUTDOWN);
if (err)
return err;
}
- /* new transfer: bump so->tx_gen and drain the old one's timers,
- * still under the so->rx_lock we just claimed the socket with
- */
- WRITE_ONCE(so->tx.state, ISOTP_SENDING);
- WRITE_ONCE(so->tx_gen, READ_ONCE(so->tx_gen) + 1);
+ /* txfrtimer's callback re-arms echotimer lock-free: drain it first */
+ hrtimer_cancel(&so->txfrtimer);
hrtimer_cancel(&so->txtimer);
hrtimer_cancel(&so->echotimer);
- hrtimer_cancel(&so->txfrtimer);
- so->cfecho = 0;
+
+ /* new transfer: increment so->tx_gen and set tx.state after barrier */
+ my_gen = isotp_inc_tx_gen(READ_ONCE(so->tx_gen));
+ isotp_set_tx_result(so, my_gen, ECOMM); /* prevent stale slot matching */
+ WRITE_ONCE(so->tx_gen, my_gen);
+ smp_wmb(); /* see smp_load_acquire() in isotp_tx_[timeout|gen_done] */
+ WRITE_ONCE(so->tx.state, ISOTP_SENDING);
+ WRITE_ONCE(so->cfecho, 0);
spin_unlock_bh(&so->rx_lock);
/* so->bound is only checked once above - a wakeup may have
- * unbound/rebound the socket meanwhile, so re-validate it
+ * unbound/rebound the socket meanwhile => recheck
*/
if (!so->bound) {
err = -EADDRNOTAVAIL;
@@ -1127,6 +1221,9 @@ static int isotp_sendmsg(struct socket *
csx->can_iif = dev->ifindex;
+ /* set uid in tx skb to identify CF echo frames */
+ can_set_skb_uid(skb);
+
so->tx.len = size;
so->tx.idx = 0;
@@ -1134,8 +1231,9 @@ static int isotp_sendmsg(struct socket *
skb_put_zero(skb, so->ll.mtu);
/* cfecho should have been zero'ed by init / former isotp_rcv_echo() */
- if (so->cfecho)
- pr_notice_once("can-isotp: uninit cfecho %08X\n", so->cfecho);
+ old_cfecho = READ_ONCE(so->cfecho);
+ if (old_cfecho)
+ pr_notice_once("can-isotp: uninit cfecho %08X\n", old_cfecho);
/* check for single frame transmission depending on TX_DL */
if (size <= so->tx.ll_dl - SF_PCI_SZ4 - ae - off) {
@@ -1163,7 +1261,7 @@ static int isotp_sendmsg(struct socket *
cf->data[ae] |= size;
/* set CF echo tag for isotp_rcv_echo() (SF-mode) */
- so->cfecho = *(u32 *)cf->data;
+ WRITE_ONCE(so->cfecho, skb->hash);
} else {
/* send first frame */
@@ -1180,7 +1278,7 @@ static int isotp_sendmsg(struct socket *
so->txfc.bs = 0;
/* set CF echo tag for isotp_rcv_echo() (CF-mode) */
- so->cfecho = *(u32 *)cf->data;
+ WRITE_ONCE(so->cfecho, skb->hash);
} else {
/* standard flow control check */
new_state = ISOTP_WAIT_FIRST_FC;
@@ -1190,12 +1288,12 @@ static int isotp_sendmsg(struct socket *
tx_hrt = &so->txtimer;
/* no CF echo tag for isotp_rcv_echo() (FF-mode) */
- so->cfecho = 0;
+ WRITE_ONCE(so->cfecho, 0);
}
}
spin_lock_bh(&so->rx_lock);
- if (so->tx.state == ISOTP_SHUTDOWN) {
+ if (READ_ONCE(so->tx.state) == ISOTP_SHUTDOWN) {
/* isotp_release() has since taken over and already drained
* our timers - don't send into a socket that's going away
*/
@@ -1206,7 +1304,7 @@ static int isotp_sendmsg(struct socket *
return -EADDRNOTAVAIL;
}
/* WAIT_FIRST_FC for standard FF, else stays ISOTP_SENDING */
- so->tx.state = new_state;
+ WRITE_ONCE(so->tx.state, new_state);
hrtimer_start(tx_hrt, ktime_set(hrtimer_sec, 0),
HRTIMER_MODE_REL_SOFT);
spin_unlock_bh(&so->rx_lock);
@@ -1223,20 +1321,49 @@ static int isotp_sendmsg(struct socket *
__func__, ERR_PTR(err));
spin_lock_bh(&so->rx_lock);
+
+ /* new transfer already claimed by a concurrent completion,
+ * timeout or sendmsg() while we were stuck in can_send()?
+ */
+ if (READ_ONCE(so->tx_gen) != my_gen) {
+ /* don't touch timers and state of the new transfer */
+ spin_unlock_bh(&so->rx_lock);
+ return err;
+ }
+
/* no transmission -> no timeout monitoring */
hrtimer_cancel(tx_hrt);
goto err_out_drop_locked;
}
if (wait_tx_done) {
- /* wait for complete transmission of current pdu */
- err = wait_event_interruptible(so->wait, so->tx.state == ISOTP_IDLE);
+ /* wake up for:
+ * - concurrent sendmsg() claiming a new transfer
+ * - complete transmission of current PDU
+ * - shutdown state change in isotp_release()
+ * isotp_tx_gen_done() uses common tx.state/tx_gen read sequence
+ */
+ err = wait_event_interruptible(so->wait,
+ isotp_tx_gen_done(so, my_gen));
if (err)
goto err_event_drop;
- err = sock_error(sk);
- if (err)
- return err;
+ /* still our claim, but isotp_release() force-shut it down */
+ if (smp_load_acquire(&so->tx.state) == ISOTP_SHUTDOWN &&
+ READ_ONCE(so->tx_gen) == my_gen) {
+ err = -EADDRNOTAVAIL;
+ goto err_event_drop;
+ }
+
+ /* own completion, or tx_gen moved on - either way this is
+ * what isotp_get_tx_result() recorded for my_gen
+ */
+ err = isotp_get_tx_result(so, my_gen);
+
+ /* drain to avoid stale error for a later poll()/SO_ERROR */
+ sock_error(sk);
+
+ return err ? err : size;
}
return size;
@@ -1246,15 +1373,26 @@ err_out_drop:
spin_lock_bh(&so->rx_lock);
goto err_out_drop_locked;
err_event_drop:
- /* interrupted waiting on our own transfer - drain its timers */
+ /* interrupted or shut down while waiting on our own transfer */
spin_lock_bh(&so->rx_lock);
+
+ /* new transfer already started by concurrent sendmsg()? */
+ if (READ_ONCE(so->tx_gen) != my_gen) {
+ /* don't touch timers and states of the new transfer */
+ spin_unlock_bh(&so->rx_lock);
+ return err;
+ }
+
hrtimer_cancel(&so->txfrtimer);
hrtimer_cancel(&so->txtimer);
hrtimer_cancel(&so->echotimer);
err_out_drop_locked:
/* release the claim; so->rx_lock still held from above */
- so->cfecho = 0;
- so->tx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->cfecho, 0);
+
+ /* only claim to IDLE if isotp_release() has not taken over */
+ if (READ_ONCE(so->tx.state) != ISOTP_SHUTDOWN)
+ WRITE_ONCE(so->tx.state, ISOTP_IDLE);
spin_unlock_bh(&so->rx_lock);
wake_up_interruptible(&so->wait);
@@ -1320,8 +1458,9 @@ static int isotp_release(struct socket *
/* best-effort: wait for a running pdu to finish, but don't block on
* it forever - give up after the first signal
*/
- while (so->tx.state != ISOTP_IDLE &&
- wait_event_interruptible(so->wait, so->tx.state == ISOTP_IDLE) == 0)
+ while (READ_ONCE(so->tx.state) != ISOTP_IDLE &&
+ wait_event_interruptible(so->wait,
+ READ_ONCE(so->tx.state) == ISOTP_IDLE) == 0)
;
/* claim the socket under so->rx_lock like sendmsg() does, so its
@@ -1329,9 +1468,12 @@ static int isotp_release(struct socket *
* unconditionally, even when a signal cut the wait above short
*/
spin_lock_bh(&so->rx_lock);
- so->tx.state = ISOTP_SHUTDOWN;
+ WRITE_ONCE(so->tx.state, ISOTP_SHUTDOWN);
spin_unlock_bh(&so->rx_lock);
- so->rx.state = ISOTP_IDLE;
+ WRITE_ONCE(so->rx.state, ISOTP_IDLE);
+
+ /* forced SHUTDOWN may have skipped IDLE (gave up on a signal) */
+ wake_up_interruptible(&so->wait);
spin_lock(&isotp_notifier_lock);
while (isotp_busy_notifier == so) {
@@ -1447,7 +1589,8 @@ static int isotp_bind(struct socket *soc
* with so->bound in the same lock_sock() section above, so there is
* no window in which a concurrent isotp_notify() could be missed.
*/
- if (so->tx.state != ISOTP_IDLE || so->rx.state != ISOTP_IDLE) {
+ if (READ_ONCE(so->tx.state) != ISOTP_IDLE ||
+ READ_ONCE(so->rx.state) != ISOTP_IDLE) {
err = -EAGAIN;
goto out;
}
@@ -1481,7 +1624,7 @@ static int isotp_bind(struct socket *soc
isotp_rcv, sk, "isotp", sk);
/* no consecutive frame echo skb in flight */
- so->cfecho = 0;
+ WRITE_ONCE(so->cfecho, 0);
/* register for echo skb's */
can_rx_register(net, dev, tx_id, SINGLE_MASK(tx_id),
@@ -1847,7 +1990,7 @@ static __poll_t isotp_poll(struct file *
poll_wait(file, &so->wait, wait);
/* Check for false positives due to TX state */
- if ((mask & EPOLLWRNORM) && (so->tx.state != ISOTP_IDLE))
+ if ((mask & EPOLLWRNORM) && (READ_ONCE(so->tx.state) != ISOTP_IDLE))
mask &= ~(EPOLLOUT | EPOLLWRNORM);
return mask;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 368/438] can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (366 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 367/438] can: isotp: fix timer drain order, wakeup handling and tx_gen ordering Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 369/438] can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking Greg Kroah-Hartman
` (83 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jian Zhou, Oleksij Rempel, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oleksij Rempel <o.rempel@pengutronix.de>
commit eb96c58907922546e415e545fe9a14ea63b02719 upstream.
Zero the allocated buffer in j1939_session_fresh_new() to ensure it
contains no residual data.
While there is a potential performance impact if users allocate maximum
sized ETP buffers, most real-world use cases are not noticeably affected
since the maximum known buffer size is typically around 65K.
Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")
Reported-by: Ji'an Zhou <eilaimemedsnaimel@gmail.com>
Message-ID: <CAPAUci5dykCLjoijqkUtFqJFesgncrD7+S6y_V=gjbFkY2Tifg@mail.gmail.com>
Signed-off-by: Oleksij Rempel <o.rempel@pengutronix.de>
Link: https://patch.msgid.link/20260728055835.1151785-3-o.rempel@pengutronix.de
Cc: stable@kernel.org
[mkl: add Message-ID]
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/can/j1939/transport.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/can/j1939/transport.c
+++ b/net/can/j1939/transport.c
@@ -1579,7 +1579,7 @@ j1939_session *j1939_session_fresh_new(s
}
/* alloc data area */
- skb_put(skb, size);
+ skb_put_zero(skb, size);
/* skb is recounted in j1939_session_new() */
return session;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 369/438] can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (367 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 368/438] can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 370/438] can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() Greg Kroah-Hartman
` (82 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tetsuo Handa, Oleksij Rempel, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
commit d2fb981384b3a45f690616d550b29046e8ad16a4 upstream.
syzbot is still reporting
unregister_netdevice: waiting for vcan0 to become free. Usage count = 2
problem. A debug printk() patch in linux-next-20260508 identified that
there is dev_hold()/dev_put() imbalance in j1939_priv management.
Call trace for vcan0[26] +4 at
__dev_hold include/linux/netdevice.h:4470 [inline]
netdev_hold include/linux/netdevice.h:4513 [inline]
dev_hold include/linux/netdevice.h:4536 [inline]
j1939_priv_create net/can/j1939/main.c:140 [inline]
j1939_netdev_start+0x36b/0xc10 net/can/j1939/main.c:268
j1939_sk_bind+0x853/0xb30 net/can/j1939/socket.c:506
__sys_bind_socket net/socket.c:1948 [inline]
__sys_bind+0x2e9/0x410 net/socket.c:1979
Call trace for vcan0[28] -3 at
__dev_put include/linux/netdevice.h:4456 [inline]
netdev_put include/linux/netdevice.h:4523 [inline]
dev_put include/linux/netdevice.h:4548 [inline]
__j1939_priv_release net/can/j1939/main.c:166 [inline]
kref_put include/linux/kref.h:65 [inline]
j1939_priv_put+0x128/0x270 net/can/j1939/main.c:172
j1939_sk_sock_destruct+0x52/0x90 net/can/j1939/socket.c:388
__sk_destruct+0x8d/0x9d0 net/core/sock.c:2352
rcu_do_batch kernel/rcu/tree.c:2617 [inline]
rcu_core kernel/rcu/tree.c:2869 [inline]
rcu_cpu_kthread+0x99e/0x1470 kernel/rcu/tree.c:2957
smpboot_thread_fn+0x541/0xa50 kernel/smpboot.c:160
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
This refcount leak in j1939_priv might be caused by a refcount leak in
j1939_{session,ecu} because j1939_{session,ecu} holds a ref on j1939_priv.
For further investigation using upstream kernels, enable netdevice_tracker
in j1939_{priv,session,ecu} management.
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Acked-by: Oleksij Rempel <o.rempel@pengutronix.de>
Signed-off-by: Oleksij Rempel <o.rempel@pengutronix.de>
Link: https://patch.msgid.link/20260728055835.1151785-2-o.rempel@pengutronix.de
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/can/j1939/bus.c | 2 ++
net/can/j1939/j1939-priv.h | 3 +++
net/can/j1939/main.c | 8 ++++----
net/can/j1939/transport.c | 2 ++
4 files changed, 11 insertions(+), 4 deletions(-)
--- a/net/can/j1939/bus.c
+++ b/net/can/j1939/bus.c
@@ -20,6 +20,7 @@ static void __j1939_ecu_release(struct k
struct j1939_priv *priv = ecu->priv;
list_del(&ecu->list);
+ netdev_put(priv->ndev, &ecu->priv_dev_tracker);
kfree(ecu);
j1939_priv_put(priv);
}
@@ -155,6 +156,7 @@ struct j1939_ecu *j1939_ecu_create_locke
if (!ecu)
return ERR_PTR(-ENOMEM);
kref_init(&ecu->kref);
+ netdev_hold(priv->ndev, &ecu->priv_dev_tracker, gfp_any());
ecu->addr = J1939_IDLE_ADDR;
ecu->name = name;
--- a/net/can/j1939/j1939-priv.h
+++ b/net/can/j1939/j1939-priv.h
@@ -38,6 +38,7 @@ struct j1939_ecu {
struct hrtimer ac_timer;
struct kref kref;
struct j1939_priv *priv;
+ netdevice_tracker priv_dev_tracker;
/* count users, to help transport protocol decide for interaction */
int nusers;
@@ -60,6 +61,7 @@ struct j1939_priv {
rwlock_t lock;
struct net_device *ndev;
+ netdevice_tracker dev_tracker;
/* list of 256 ecu ptrs, that cache the claimed addresses.
* also protected by the above lock
@@ -230,6 +232,7 @@ enum j1939_session_state {
struct j1939_session {
struct j1939_priv *priv;
+ netdevice_tracker priv_dev_tracker;
struct list_head active_session_list_entry;
struct list_head sk_session_queue_entry;
struct kref kref;
--- a/net/can/j1939/main.c
+++ b/net/can/j1939/main.c
@@ -137,7 +137,7 @@ static struct j1939_priv *j1939_priv_cre
priv->ndev = ndev;
kref_init(&priv->kref);
kref_init(&priv->rx_kref);
- dev_hold(ndev);
+ netdev_hold(ndev, &priv->dev_tracker, GFP_KERNEL);
netdev_dbg(priv->ndev, "%s : 0x%p\n", __func__, priv);
@@ -163,7 +163,7 @@ static void __j1939_priv_release(struct
WARN_ON_ONCE(!list_empty(&priv->ecus));
WARN_ON_ONCE(!list_empty(&priv->j1939_socks));
- dev_put(ndev);
+ netdev_put(ndev, &priv->dev_tracker);
kfree(priv);
}
@@ -281,7 +281,7 @@ struct j1939_priv *j1939_netdev_start(st
*/
kref_get(&priv_new->rx_kref);
mutex_unlock(&j1939_netdev_lock);
- dev_put(ndev);
+ netdev_put(ndev, &priv->dev_tracker);
kfree(priv);
return priv_new;
}
@@ -298,7 +298,7 @@ struct j1939_priv *j1939_netdev_start(st
j1939_priv_set(ndev, NULL);
mutex_unlock(&j1939_netdev_lock);
- dev_put(ndev);
+ netdev_put(ndev, &priv->dev_tracker);
kfree(priv);
return ERR_PTR(ret);
--- a/net/can/j1939/transport.c
+++ b/net/can/j1939/transport.c
@@ -283,6 +283,7 @@ static void j1939_session_destroy(struct
kfree_skb(skb);
}
__j1939_session_drop(session);
+ netdev_put(session->priv->ndev, &session->priv_dev_tracker);
j1939_priv_put(session->priv);
kfree(session);
}
@@ -1526,6 +1527,7 @@ static struct j1939_session *j1939_sessi
INIT_LIST_HEAD(&session->active_session_list_entry);
INIT_LIST_HEAD(&session->sk_session_queue_entry);
kref_init(&session->kref);
+ netdev_hold(priv->ndev, &session->priv_dev_tracker, gfp_any());
j1939_priv_get(priv);
session->priv = priv;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 370/438] can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (368 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 369/438] can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 371/438] can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents Greg Kroah-Hartman
` (81 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
commit 941eaf9a6d3b33dea49f2c0a1da7546a03b6ff71 upstream.
The memory allocated for cmd is not freed after the call to
kvaser_usb_send_cmd() in both the normal and error paths.
Fix that by adding a kfree() immediately after the call.
Fixes: 39d3df6b0ea8 ("can: kvaser_usb: Compare requested bittiming parameters with actual parameters in do_set_{,data}_bittiming")
Cc: stable@vger.kernel.org
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Link: https://patch.msgid.link/20260722103906.108571-1-nihaal@cse.iitm.ac.in
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
+++ b/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
@@ -1626,6 +1626,7 @@ static int kvaser_usb_hydra_get_busparam
reinit_completion(&priv->get_busparams_comp);
err = kvaser_usb_send_cmd(dev, cmd, cmd_len);
+ kfree(cmd);
if (err)
return err;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 371/438] can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (369 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 370/438] can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 372/438] can: rcar_canfd: change the initializing flow for clocks and resets Greg Kroah-Hartman
` (80 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee upstream.
The wait and bulk receive paths walk variable-length commands from a
USB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be
dispatched, and the wait path copies a matching command into a fixed
caller-owned struct kvaser_cmd using the device-provided length.
Reject nonzero commands that do not contain the fixed header or that
extend beyond the current USB buffer item. In the wait path, also reject
a matching command that exceeds the destination before copying it.
Fixes: 080f40a6fa28 ("can: kvaser_usb: Add support for Kvaser CAN/USB devices")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260722042221.44066-1-pengpeng@iscas.ac.cn
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
--- a/drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
+++ b/drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
@@ -691,13 +691,22 @@ static int kvaser_usb_leaf_wait_cmd(cons
continue;
}
- if (pos + tmp->len > actual_len) {
+ if (tmp->len < CMD_HEADER_LEN ||
+ tmp->len > actual_len - pos) {
dev_err_ratelimited(&dev->intf->dev,
"Format error\n");
break;
}
if (tmp->id == id) {
+ if (tmp->len > sizeof(*cmd)) {
+ dev_err_ratelimited(&dev->intf->dev,
+ "Received command %u too large (%u)\n",
+ tmp->id, tmp->len);
+ err = -EIO;
+ goto end;
+ }
+
memcpy(cmd, tmp, tmp->len);
goto end;
}
@@ -1737,7 +1746,7 @@ static void kvaser_usb_leaf_read_bulk_ca
continue;
}
- if (pos + cmd->len > len) {
+ if (cmd->len < CMD_HEADER_LEN || cmd->len > len - pos) {
dev_err_ratelimited(&dev->intf->dev, "Format error\n");
break;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 372/438] can: rcar_canfd: change the initializing flow for clocks and resets
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (370 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 371/438] can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 373/438] can: softing: fw_parse(): validate firmware record spans Greg Kroah-Hartman
` (79 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tu Nguyen, Biju Das, Claudiu Beznea,
Geert Uytterhoeven, Vincent Mailhol, stable, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tu Nguyen <tu.nguyen.xg@renesas.com>
commit bef9004c5b91debfceaea2841855a4ebe81ff2b3 upstream.
Testing CANFD on RZ/G3E shows that many registers do not reset to their
initial values with the current flow of deasserting resets first and then
enabling clocks.
Based on the HW manual, clocks should be supplied first and the
resets deasserted afterward.
section 7.4.3 Procedure for Activating Modules: RZ/G2L
section 4.4.9.3 Procedure for Starting up Units: RZ/G3E
So, update the order of the initializing flow for resets and clocks
to match the hardware manual, resetting all CANFD registers to their
initial values. Also update rcar_canfd_global_deinit() to assert
resets before disabling clocks, so the teardown path mirrors the new
init ordering.
Fixes: 76e9353a80e9 ("can: rcar_canfd: Add support for RZ/G2L family")
Signed-off-by: Tu Nguyen <tu.nguyen.xg@renesas.com>
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Tested-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/20260625135216.130450-1-biju.das.jz@bp.renesas.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/rcar/rcar_canfd.c | 32 ++++++++++++++++----------------
1 file changed, 16 insertions(+), 16 deletions(-)
--- a/drivers/net/can/rcar/rcar_canfd.c
+++ b/drivers/net/can/rcar/rcar_canfd.c
@@ -2003,20 +2003,12 @@ static int rcar_canfd_global_init(struct
u32 ch, sts;
int err;
- err = reset_control_reset(gpriv->rstc1);
- if (err)
- return err;
-
- err = reset_control_reset(gpriv->rstc2);
- if (err)
- goto fail_reset1;
-
/* Enable peripheral clock for register access */
err = clk_prepare_enable(gpriv->clkp);
if (err) {
dev_err(dev, "failed to enable peripheral clock: %pe\n",
ERR_PTR(err));
- goto fail_reset2;
+ return err;
}
/* Enable RAM clock */
@@ -2027,10 +2019,18 @@ static int rcar_canfd_global_init(struct
goto fail_clk;
}
+ err = reset_control_reset(gpriv->rstc1);
+ if (err)
+ goto fail_ram_clk;
+
+ err = reset_control_reset(gpriv->rstc2);
+ if (err)
+ goto fail_reset1;
+
err = rcar_canfd_reset_controller(gpriv);
if (err) {
dev_err(dev, "reset controller failed: %pe\n", ERR_PTR(err));
- goto fail_ram_clk;
+ goto fail_reset2;
}
/* Controller in Global reset & Channel reset mode */
@@ -2068,14 +2068,14 @@ static int rcar_canfd_global_init(struct
fail_mode:
rcar_canfd_disable_global_interrupts(gpriv);
-fail_ram_clk:
- clk_disable_unprepare(gpriv->clk_ram);
-fail_clk:
- clk_disable_unprepare(gpriv->clkp);
fail_reset2:
reset_control_assert(gpriv->rstc2);
fail_reset1:
reset_control_assert(gpriv->rstc1);
+fail_ram_clk:
+ clk_disable_unprepare(gpriv->clk_ram);
+fail_clk:
+ clk_disable_unprepare(gpriv->clkp);
return err;
}
@@ -2090,10 +2090,10 @@ static void rcar_canfd_global_deinit(str
rcar_canfd_set_bit(gpriv->base, RCANFD_GCTR, RCANFD_GCTR_GSLPR);
}
- clk_disable_unprepare(gpriv->clk_ram);
- clk_disable_unprepare(gpriv->clkp);
reset_control_assert(gpriv->rstc2);
reset_control_assert(gpriv->rstc1);
+ clk_disable_unprepare(gpriv->clk_ram);
+ clk_disable_unprepare(gpriv->clkp);
}
static int rcar_canfd_probe(struct platform_device *pdev)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 373/438] can: softing: fw_parse(): validate firmware record spans
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (371 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 372/438] can: rcar_canfd: change the initializing flow for clocks and resets Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 374/438] can: peak_usb: add bounds check for USB channel index Greg Kroah-Hartman
` (78 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 856d6cb04e5407523566b075841dcd6423757d1c upstream.
fw_parse() reads a fixed record header, a firmware-provided payload,
and a trailing checksum without knowing the end of the firmware blob. A
truncated record can therefore make those reads exceed the blob.
The same record also supplies addresses and lengths for writes into
DPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its
bounds check, while the application loader does not bound the staging
copy at all.
Pass the firmware end to the parser and validate the full source record.
Use a signed wide offset for generic DPRAM records and validate the
application staging span against the mapped DPRAM before copying.
Fixes: 03fd3cf5a179 ("can: add driver for Softing card")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260722044347.2708-1-pengpeng@iscas.ac.cn
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/softing/softing_fw.c | 46 ++++++++++++++++++++++++-----------
1 file changed, 32 insertions(+), 14 deletions(-)
--- a/drivers/net/can/softing/softing_fw.c
+++ b/drivers/net/can/softing/softing_fw.c
@@ -91,12 +91,12 @@ int softing_bootloader_command(struct so
return ret;
}
-static int fw_parse(const uint8_t **pmem, uint16_t *ptype, uint32_t *paddr,
- uint16_t *plen, const uint8_t **pdat)
+static int fw_parse(const u8 **pmem, const u8 *limit, u16 *ptype,
+ u32 *paddr, u16 *plen, const u8 **pdat)
{
uint16_t checksum[2];
- const uint8_t *mem;
- const uint8_t *end;
+ const u8 *mem;
+ const u8 *record_end;
/*
* firmware records are a binary, unaligned stream composed of:
@@ -114,14 +114,21 @@ static int fw_parse(const uint8_t **pmem
* endianness & alignment.
*/
mem = *pmem;
+ /* A record needs an 8-byte prefix and a 2-byte checksum. */
+ if (mem > limit || limit - mem < 10)
+ return -EINVAL;
+
*ptype = le16_to_cpup((void *)&mem[0]);
*paddr = le32_to_cpup((void *)&mem[2]);
*plen = le16_to_cpup((void *)&mem[6]);
+ if (*plen > limit - mem - 10)
+ return -EINVAL;
+
*pdat = &mem[8];
/* verify checksum */
- end = &mem[8 + *plen];
- checksum[0] = le16_to_cpup((void *)end);
- for (checksum[1] = 0; mem < end; ++mem)
+ record_end = &mem[8 + *plen];
+ checksum[0] = le16_to_cpup((void *)record_end);
+ for (checksum[1] = 0; mem < record_end; ++mem)
checksum[1] += *mem;
if (checksum[0] != checksum[1])
return -EINVAL;
@@ -139,6 +146,7 @@ int softing_load_fw(const char *file, st
uint16_t type, len;
uint32_t addr;
uint8_t *buf = NULL, *new_buf;
+ s64 dpram_offset;
int buflen = 0;
int8_t type_end = 0;
@@ -153,7 +161,7 @@ int softing_load_fw(const char *file, st
mem = fw->data;
end = &mem[fw->size];
/* look for header record */
- ret = fw_parse(&mem, &type, &addr, &len, &dat);
+ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
if (ret < 0)
goto failed;
if (type != 0xffff)
@@ -164,7 +172,7 @@ int softing_load_fw(const char *file, st
}
/* ok, we had a header */
while (mem < end) {
- ret = fw_parse(&mem, &type, &addr, &len, &dat);
+ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
if (ret < 0)
goto failed;
if (type == 3) {
@@ -179,9 +187,13 @@ int softing_load_fw(const char *file, st
goto failed;
}
- if ((addr + len + offset) > size)
+ dpram_offset = (s64)addr + offset;
+ if (dpram_offset < 0 || dpram_offset > size ||
+ len > size - dpram_offset) {
+ ret = -EINVAL;
goto failed;
- memcpy_toio(&dpram[addr + offset], dat, len);
+ }
+ memcpy_toio(&dpram[dpram_offset], dat, len);
/* be sure to flush caches from IO space */
mb();
if (len > buflen) {
@@ -195,7 +207,7 @@ int softing_load_fw(const char *file, st
buf = new_buf;
}
/* verify record data */
- memcpy_fromio(buf, &dpram[addr + offset], len);
+ memcpy_fromio(buf, &dpram[dpram_offset], len);
if (memcmp(buf, dat, len)) {
/* is not ok */
dev_alert(&card->pdev->dev, "DPRAM readback failed\n");
@@ -237,7 +249,7 @@ int softing_load_app_fw(const char *file
mem = fw->data;
end = &mem[fw->size];
/* look for header record */
- ret = fw_parse(&mem, &type, &addr, &len, &dat);
+ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
if (ret)
goto failed;
ret = -EINVAL;
@@ -253,7 +265,7 @@ int softing_load_app_fw(const char *file
}
/* ok, we had a header */
while (mem < end) {
- ret = fw_parse(&mem, &type, &addr, &len, &dat);
+ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
if (ret)
goto failed;
@@ -279,6 +291,12 @@ int softing_load_app_fw(const char *file
/* work in 16bit (target) */
sum &= 0xffff;
+ if (card->pdat->app.offs > card->dpram_size ||
+ len > card->dpram_size - card->pdat->app.offs) {
+ ret = -EINVAL;
+ goto failed;
+ }
+
memcpy_toio(&card->dpram[card->pdat->app.offs], dat, len);
iowrite32(card->pdat->app.offs + card->pdat->app.addr,
&card->dpram[DPRAM_COMMAND + 2]);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 374/438] can: peak_usb: add bounds check for USB channel index
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (372 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 373/438] can: softing: fw_parse(): validate firmware record spans Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 375/438] can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error Greg Kroah-Hartman
` (77 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Gao, Vincent Mailhol, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Gao <jamesgao5@outlook.com>
commit 39132f166ca8ce00ae60d8a9068e06a60943cc4b upstream.
The channel control index ctrl_idx is derived from rx->len which comes
directly from a device USB payload. The mask 0x0f allows values 0-15, but
the array size of usb_if->dev[] is only 2. Values 2-15 cause heap
out-of-bounds read, eventually causing kernel panic in the IRQ context.
Add bounds checking for ctrl_idx before the array access in both
pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().
Fixes: d8a199355f8f ("can: usb: PEAK-System Technik PCAN-USB Pro specific part")
Signed-off-by: James Gao <jamesgao5@outlook.com>
Reviewed-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/TYWPR01MB8559DBAAAA6A7F410400329CF0012@TYWPR01MB8559.jpnprd01.prod.outlook.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/peak_usb/pcan_usb_pro.c | 20 ++++++++++++++++----
1 file changed, 16 insertions(+), 4 deletions(-)
--- a/drivers/net/can/usb/peak_usb/pcan_usb_pro.c
+++ b/drivers/net/can/usb/peak_usb/pcan_usb_pro.c
@@ -534,12 +534,18 @@ static int pcan_usb_pro_handle_canmsg(st
struct pcan_usb_pro_rxmsg *rx)
{
const unsigned int ctrl_idx = (rx->len >> 4) & 0x0f;
- struct peak_usb_device *dev = usb_if->dev[ctrl_idx];
- struct net_device *netdev = dev->netdev;
+ struct peak_usb_device *dev;
+ struct net_device *netdev;
struct can_frame *can_frame;
struct sk_buff *skb;
struct skb_shared_hwtstamps *hwts;
+ if (ctrl_idx >= ARRAY_SIZE(usb_if->dev))
+ return -EINVAL;
+
+ dev = usb_if->dev[ctrl_idx];
+ netdev = dev->netdev;
+
skb = alloc_can_skb(netdev, &can_frame);
if (!skb)
return -ENOMEM;
@@ -573,14 +579,20 @@ static int pcan_usb_pro_handle_error(str
{
const u16 raw_status = le16_to_cpu(er->status);
const unsigned int ctrl_idx = (er->channel >> 4) & 0x0f;
- struct peak_usb_device *dev = usb_if->dev[ctrl_idx];
- struct net_device *netdev = dev->netdev;
+ struct peak_usb_device *dev;
+ struct net_device *netdev;
struct can_frame *can_frame;
enum can_state new_state = CAN_STATE_ERROR_ACTIVE;
u8 err_mask = 0;
struct sk_buff *skb;
struct skb_shared_hwtstamps *hwts;
+ if (ctrl_idx >= ARRAY_SIZE(usb_if->dev))
+ return -EINVAL;
+
+ dev = usb_if->dev[ctrl_idx];
+ netdev = dev->netdev;
+
/* nothing should be sent while in BUS_OFF state */
if (dev->can.state == CAN_STATE_BUS_OFF)
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 375/438] can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (373 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 374/438] can: peak_usb: add bounds check for USB channel index Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 376/438] can: peak_usb: validate uCAN receive record lengths Greg Kroah-Hartman
` (76 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Vincent Mailhol,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
commit 9b3d5a6d952c38bbcf07f903cbeadefdb56b9bc9 upstream.
In peak_usb_start(), each RX URB transfer buffer is allocated with kmalloc()
and the URB is flagged URB_FREE_BUFFER so that the final usb_free_urb() also
frees the transfer buffer.
If usb_submit_urb() fails, the error path frees the buffer explicitly with
kfree(buf) and then calls usb_free_urb(urb). Because URB_FREE_BUFFER is set,
usb_free_urb() -> urb_destroy() frees the same buffer a second time, a double
free of the transfer buffer.
BUG: KASAN: double-free in usb_free_urb.part.0+0x91/0xb0
Free of addr ffff8881069ccb80 by task trigger.sh/285
Call Trace:
kfree+0x113/0x3c0
usb_free_urb.part.0+0x91/0xb0
Drop the redundant kfree(buf); usb_free_urb() already releases the transfer
buffer. This mirrors commit 03819abbeb11 ("net: usb: lan78xx: Fix double free
issue with interrupt buffer allocation").
Fixes: bb4785551f64 ("can: usb: PEAK-System Technik USB adapters driver core")
Closes: https://lore.kernel.org/linux-can/178159320216.2154888.16953451793788581739@maoyixie.com/T/#u
Cc: stable@vger.kernel.org
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Reviewed-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/178163373110.2507866.216458825145756798@maoyixie.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/peak_usb/pcan_usb_core.c | 1 -
1 file changed, 1 deletion(-)
--- a/drivers/net/can/usb/peak_usb/pcan_usb_core.c
+++ b/drivers/net/can/usb/peak_usb/pcan_usb_core.c
@@ -470,7 +470,6 @@ static int peak_usb_start(struct peak_us
netif_device_detach(dev->netdev);
usb_unanchor_urb(urb);
- kfree(buf);
usb_free_urb(urb);
break;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 376/438] can: peak_usb: validate uCAN receive record lengths
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (374 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 375/438] can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 377/438] can: ctucanfd: add missing MODULE_DEVICE_TABLE() Greg Kroah-Hartman
` (75 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 93fcab2c6968446316bbb49548848df604d6346f upstream.
pcan_usb_fd_decode_buf() walks uCAN records packed in one USB
receive buffer.
Require each record to contain the fixed header for its type, and verify
CAN payload bytes before copying them into the skb.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260706092836.79754-1-pengpeng@iscas.ac.cn
Fixes: 0a25e1f4f185 ("can: peak_usb: add support for PEAK new CANFD USB adapters")
Cc: stable@vger.kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/usb/peak_usb/pcan_usb_fd.c | 40 ++++++++++++++++++++++++++++-
1 file changed, 39 insertions(+), 1 deletion(-)
--- a/drivers/net/can/usb/peak_usb/pcan_usb_fd.c
+++ b/drivers/net/can/usb/peak_usb/pcan_usb_fd.c
@@ -566,6 +566,13 @@ static int pcan_usb_fd_decode_canmsg(str
dev->can.ctrlmode);
}
+ if (!(rx_msg_flags & PUCAN_MSG_RTR) &&
+ le16_to_cpu(rx_msg->size) - offsetof(struct pucan_rx_msg, d) <
+ cfd->len) {
+ kfree_skb(skb);
+ return -EBADMSG;
+ }
+
cfd->can_id = le32_to_cpu(rm->can_id);
if (rx_msg_flags & PUCAN_MSG_EXT_ID)
@@ -714,6 +721,24 @@ static void pcan_usb_fd_decode_ts(struct
peak_usb_set_ts_now(&usb_if->time_ref, le32_to_cpu(ts->ts_low));
}
+static size_t pcan_usb_fd_rx_msg_min_size(u16 rx_msg_type)
+{
+ switch (rx_msg_type) {
+ case PUCAN_MSG_CAN_RX:
+ return offsetof(struct pucan_rx_msg, d);
+ case PCAN_UFD_MSG_CALIBRATION:
+ return sizeof(struct pcan_ufd_ts_msg);
+ case PUCAN_MSG_ERROR:
+ return sizeof(struct pucan_error_msg);
+ case PUCAN_MSG_STATUS:
+ return sizeof(struct pucan_status_msg);
+ case PCAN_UFD_MSG_OVERRUN:
+ return sizeof(struct pcan_ufd_ovr_msg);
+ default:
+ return sizeof(struct pucan_msg);
+ }
+}
+
/* callback for bulk IN urb */
static int pcan_usb_fd_decode_buf(struct peak_usb_device *dev, struct urb *urb)
{
@@ -728,6 +753,12 @@ static int pcan_usb_fd_decode_buf(struct
msg_end = urb->transfer_buffer + urb->actual_length;
for (; msg_ptr < msg_end;) {
u16 rx_msg_type, rx_msg_size;
+ size_t rx_msg_min_size;
+
+ if (msg_end - msg_ptr < sizeof(*rx_msg)) {
+ err = -EBADMSG;
+ break;
+ }
rx_msg = (struct pucan_msg *)msg_ptr;
if (!rx_msg->size) {
@@ -739,12 +770,19 @@ static int pcan_usb_fd_decode_buf(struct
rx_msg_type = le16_to_cpu(rx_msg->type);
/* check if the record goes out of current packet */
- if (msg_ptr + rx_msg_size > msg_end) {
+ if (rx_msg_size > msg_end - msg_ptr) {
netdev_err(netdev,
"got frag rec: should inc usb rx buf sze\n");
err = -EBADMSG;
break;
}
+
+ rx_msg_min_size = pcan_usb_fd_rx_msg_min_size(rx_msg_type);
+ if (rx_msg_size < rx_msg_min_size) {
+ netdev_err(netdev, "got short rec\n");
+ err = -EBADMSG;
+ break;
+ }
switch (rx_msg_type) {
case PUCAN_MSG_CAN_RX:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 377/438] can: ctucanfd: add missing MODULE_DEVICE_TABLE()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (375 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 376/438] can: peak_usb: validate uCAN receive record lengths Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 378/438] can: ctucanfd: use self-test mode for PRESUME_ACK Greg Kroah-Hartman
` (74 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Pavel Pisa, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit d937bdb244a751fe5967052ea2d64a7b2c476cc0 upstream.
The driver has a match table for the pci bus wired into its driver
structure, but the table is not exported with MODULE_DEVICE_TABLE().
Add the missing MODULE_DEVICE_TABLE() entry so module alias information
is generated for automatic module loading.
This is a source-level fix. It does not claim dynamic hardware
reproduction; the evidence is the driver-owned match table, its use by
the driver registration structure, and the missing module alias
publication.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Acked-by: Pavel Pisa <pisa@fel.cvut.cz>
Link: https://patch.msgid.link/20260704151957.48194-1-pengpeng@iscas.ac.cn
Fixes: 792a5b678e81 ("can: ctucanfd: CTU CAN FD open-source IP core - PCI bus support.")
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/ctucanfd/ctucanfd_pci.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/can/ctucanfd/ctucanfd_pci.c
+++ b/drivers/net/can/ctucanfd/ctucanfd_pci.c
@@ -266,6 +266,7 @@ static const struct pci_device_id ctucan
CTUCAN_WITH_CTUCAN_ID)},
{},
};
+MODULE_DEVICE_TABLE(pci, ctucan_pci_tbl);
static struct pci_driver ctucan_pci_driver = {
.name = KBUILD_MODNAME,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 378/438] can: ctucanfd: use self-test mode for PRESUME_ACK
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (376 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 377/438] can: ctucanfd: add missing MODULE_DEVICE_TABLE() Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 379/438] can: ctucanfd: unmap BAR0 using base address Greg Kroah-Hartman
` (73 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Avi Weiss, Pavel Pisa, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Avi Weiss <thnkslprpt@gmail.com>
commit c31a435933f18be0f874302161333e9f16e200a0 upstream.
Use self-test mode for CAN_CTRLMODE_PRESUME_ACK so transmitted
frames can complete without receiving an ACK.
ACK forbidden mode prevents the controller from acknowledging
received frames and does not implement the presume-ack behavior.
Fixes: 2dcb8e8782d8 ("can: ctucanfd: add support for CTU CAN FD open-source IP core - bus independent part.")
Signed-off-by: Avi Weiss <thnkslprpt@gmail.com>
Acked-by: Pavel Pisa <pisa@fel.cvut.cz>
Link: https://patch.msgid.link/20260722192726.230729-1-thnkslprpt@gmail.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/ctucanfd/ctucanfd_base.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/net/can/ctucanfd/ctucanfd_base.c
+++ b/drivers/net/can/ctucanfd/ctucanfd_base.c
@@ -340,8 +340,8 @@ static void ctucan_set_mode(struct ctuca
(mode_reg & ~REG_MODE_FDE);
mode_reg = (mode->flags & CAN_CTRLMODE_PRESUME_ACK) ?
- (mode_reg | REG_MODE_ACF) :
- (mode_reg & ~REG_MODE_ACF);
+ (mode_reg | REG_MODE_STM) :
+ (mode_reg & ~REG_MODE_STM);
mode_reg = (mode->flags & CAN_CTRLMODE_FD_NON_ISO) ?
(mode_reg | REG_MODE_NISOFD) :
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 379/438] can: ctucanfd: unmap BAR0 using base address
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (377 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 378/438] can: ctucanfd: use self-test mode for PRESUME_ACK Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 380/438] can: ctucanfd: handle bus error interrupts Greg Kroah-Hartman
` (72 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Avi Weiss, Pavel Pisa, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Avi Weiss <thnkslprpt@gmail.com>
commit a6873910f983096746d1a2e0af94f36b8003e839 upstream.
BAR0 is mapped into bar0_base, while cra_addr points to an offset
within that mapping and is used for other purposes.
Pass bar0_base to pci_iounmap(), instead of cra_addr, on the probe error
path so the address returned by pci_iomap() is used for unmapping.
Fixes: 792a5b678e81 ("can: ctucanfd: CTU CAN FD open-source IP core - PCI bus support.")
Signed-off-by: Avi Weiss <thnkslprpt@gmail.com>
Acked-by: Pavel Pisa <pisa@fel.cvut.cz>
Link: https://patch.msgid.link/20260723095934.181042-1-thnkslprpt@gmail.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/ctucanfd/ctucanfd_pci.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/can/ctucanfd/ctucanfd_pci.c
+++ b/drivers/net/can/ctucanfd/ctucanfd_pci.c
@@ -194,7 +194,7 @@ err_free_board:
pci_set_drvdata(pdev, NULL);
kfree(bdata);
err_pci_iounmap_bar0:
- pci_iounmap(pdev, cra_addr);
+ pci_iounmap(pdev, bar0_base);
err_pci_iounmap_bar1:
pci_iounmap(pdev, addr);
err_release_regions:
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 380/438] can: ctucanfd: handle bus error interrupts
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (378 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 379/438] can: ctucanfd: unmap BAR0 using base address Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 381/438] can: ctucanfd: mark error-active controller status valid Greg Kroah-Hartman
` (71 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Avi Weiss, Pavel Pisa, stable,
Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Avi Weiss <thnkslprpt@gmail.com>
commit e74bae899529f49c0f375307983d12e8ecad7d4b upstream.
Include REG_INT_STAT_BEI in the top-level error interrupt condition.
BEI is enabled when CAN_CTRLMODE_BERR_REPORTING is requested and
ctucan_err_interrupt() already handles it. Without checking and
clearing BEI in the top-level handler, bus error interrupts are not
handled or acknowledged.
Fixes: 2dcb8e8782d8 ("can: ctucanfd: add support for CTU CAN FD open-source IP core - bus independent part.")
Signed-off-by: Avi Weiss <thnkslprpt@gmail.com>
Acked-by: Pavel Pisa <pisa@fel.cvut.cz>
Link: https://patch.msgid.link/20260723074403.131575-1-thnkslprpt@gmail.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/ctucanfd/ctucanfd_base.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/net/can/ctucanfd/ctucanfd_base.c
+++ b/drivers/net/can/ctucanfd/ctucanfd_base.c
@@ -1136,8 +1136,12 @@ static irqreturn_t ctucan_interrupt(int
/* Error interrupts */
if (FIELD_GET(REG_INT_STAT_EWLI, isr) ||
FIELD_GET(REG_INT_STAT_FCSI, isr) ||
- FIELD_GET(REG_INT_STAT_ALI, isr)) {
- icr = isr & (REG_INT_STAT_EWLI | REG_INT_STAT_FCSI | REG_INT_STAT_ALI);
+ FIELD_GET(REG_INT_STAT_ALI, isr) ||
+ FIELD_GET(REG_INT_STAT_BEI, isr)) {
+ icr = isr & (REG_INT_STAT_EWLI |
+ REG_INT_STAT_FCSI |
+ REG_INT_STAT_ALI |
+ REG_INT_STAT_BEI);
ctucan_netdev_dbg(ndev, "some ERR interrupt: clearing 0x%08x\n", icr);
ctucan_write32(priv, CTUCANFD_INT_STAT, icr);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 381/438] can: ctucanfd: mark error-active controller status valid
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (379 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 380/438] can: ctucanfd: handle bus error interrupts Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 382/438] drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs Greg Kroah-Hartman
` (70 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Avi Weiss, stable, Marc Kleine-Budde
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Avi Weiss <thnkslprpt@gmail.com>
commit 4e735cbe3affe88001428fdd9cae8e685ce92f21 upstream.
In the CAN_STATE_ERROR_ACTIVE case, cf->data[1] is set to
CAN_ERR_CRTL_ACTIVE, but cf->can_id is not set with CAN_ERR_CRTL in
that path.
Set CAN_ERR_CRTL so consumers know the controller-status information
in cf->data[1] is valid.
Fixes: 9bd24927e3ee ("can: ctucanfd: handle skb allocation failure")
Signed-off-by: Avi Weiss <thnkslprpt@gmail.com>
Link: https://patch.msgid.link/20260723155543.318414-1-thnkslprpt@gmail.com
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/can/ctucanfd/ctucanfd_base.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/can/ctucanfd/ctucanfd_base.c
+++ b/drivers/net/can/ctucanfd/ctucanfd_base.c
@@ -869,7 +869,7 @@ static void ctucan_err_interrupt(struct
break;
case CAN_STATE_ERROR_ACTIVE:
if (skb) {
- cf->can_id |= CAN_ERR_CNT;
+ cf->can_id |= CAN_ERR_CRTL | CAN_ERR_CNT;
cf->data[1] = CAN_ERR_CRTL_ACTIVE;
cf->data[6] = bec.txerr;
cf->data[7] = bec.rxerr;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 382/438] drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (380 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 381/438] can: ctucanfd: mark error-active controller status valid Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 383/438] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size Greg Kroah-Hartman
` (69 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ankit Nautiyal, Jani Nikula,
Maarten Lankhorst, dri-devel, Alexander Kaplan, Uma Shankar
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Kaplan <alexander.kaplan@sms-medipool.de>
commit e40e20ac089e32f1d910636155dc82e61e61dcf3 upstream.
The PCON max FRL bandwidth field lives in byte 2 of the DFP Detailed
Capability Info (DPCD 0x82 for the first DFP).
The DP standard defines the meaning of descriptor bytes 1-3 strictly
per DFP type, and for a DisplayPort type DFP all of them are
reserved, with "read all 0s" semantics (DP v2.0, section 2.12.3,
Table 2-183).
The FRL bandwidth field is an HDMI DFP extension added by the VESA
DP-to-HDMI PCON specification.
drm_dp_get_pcon_max_frl_bw() however parses the byte without checking
the DFP type, the branch presence or DETAILED_CAP_INFO_AVAILABLE.
Without the latter the port descriptors are one byte wide and
port_cap[2] is not even the right register.
All neighbouring helpers parsing the same descriptor are scoped by
the DFP type already, see for instance drm_dp_downstream_max_bpc()
reading the same byte and returning 0 for a DP type DFP.
amdgpu's DC parses the field only for HDMI(/DP++) detailed types as
well.
This is not theoretical.
A Synaptics VMM7100 based USB-C to HDMI adapter with a macOS targeted
firmware advertises a DisplayPort type DFP with the type byte
replicated across the whole descriptor (08 08 08 08).
i915 decodes that as "PCON limited to 18 Gbps FRL" and prunes every
mode above ~750 MHz dotclock, including all the 4k@100/120 modes the
sink EDID offers, while macOS drives 4k@120 through the same adapter
just fine via DP DSC (and amdgpu's type-scoped parser would ignore
the bogus field as well).
Only parse the field for an HDMI DFP behind a DPCD 1.1+ branch
device that reports detailed cap info, matching the type-scoped
field layout of the spec and the rest of the helpers.
Fixes: ce32a6239de6 ("drm/dp_helper: Add Helpers for FRL Link Training support for DP-HDMI2.1 PCON")
Cc: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Cc: Uma Shankar <uma.shankar@intel.com> (v2)
Cc: Jani Nikula <jani.nikula@intel.com>
Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
Cc: dri-devel@lists.freedesktop.org
Cc: <stable@vger.kernel.org> # v5.12+
Signed-off-by: Alexander Kaplan <alexander.kaplan@sms-medipool.de>
Reviewed-by: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Signed-off-by: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Link: https://patch.msgid.link/20260610193825.2933-1-alexander.kaplan@sms-medipool.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/display/drm_dp_helper.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--- a/drivers/gpu/drm/display/drm_dp_helper.c
+++ b/drivers/gpu/drm/display/drm_dp_helper.c
@@ -3651,6 +3651,18 @@ int drm_dp_get_pcon_max_frl_bw(const u8
int bw;
u8 buf;
+ if (!drm_dp_is_branch(dpcd))
+ return 0;
+
+ if (dpcd[DP_DPCD_REV] < 0x11)
+ return 0;
+
+ if ((dpcd[DP_DOWNSTREAMPORT_PRESENT] & DP_DETAILED_CAP_INFO_AVAILABLE) == 0)
+ return 0;
+
+ if ((port_cap[0] & DP_DS_PORT_TYPE_MASK) != DP_DS_PORT_TYPE_HDMI)
+ return 0;
+
buf = port_cap[2];
bw = buf & DP_PCON_MAX_FRL_BW;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 383/438] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (381 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 382/438] drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 384/438] drm/vc4: Zero the tile state data array before each BIN job Greg Kroah-Hartman
` (68 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jose Maria Casanova Crespo,
Maíra Canal, Iago Toral Quiroga
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jose Maria Casanova Crespo <jmcasanova@igalia.com>
commit 6395789e4739aa5177bbec0fa0f07ccc38d249b0 upstream.
vc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB
binner BO, but writes the size of the whole BO to BPOS. On every binner
out-of-memory event the PTB is therefore authorized to write tile lists
across all the other slots (which may hold the tile state, tile alloc and
overflow memory of in-flight jobs) and, for any slot but the first, past
the end of the binner BO into unrelated CMA memory.
Since CMA pages are recycled into page cache and user allocations, this
is arbitrary memory corruption by GPU DMA. In practice it shows up as GPU
hangs with corrupted control list pointers, userspace heap corruption, a
GPU that stays permanently wedged after the first hang, and occasional
full system crashes, whenever a job overflows the initial binner slot.
The bug dates back to the conversion from a dedicated overflow BO (where
writing the full BO size was correct) to the slotted binner BO.
Fixes: 553c942f8b2c ("drm/vc4: Allow using more than 256MB of CMA memory.")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Jose Maria Casanova Crespo <jmcasanova@igalia.com>
Reviewed-by: Maíra Canal <mcanal@igalia.com>
Reviewed-by: Iago Toral Quiroga <itoral@igalia.com>
Link: https://patch.msgid.link/20260727-vc4-bin-oom-fixes-v2-1-0d8a5eddc7c9@igalia.com
Signed-off-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vc4/vc4_irq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/vc4/vc4_irq.c
+++ b/drivers/gpu/drm/vc4/vc4_irq.c
@@ -105,7 +105,7 @@ vc4_overflow_mem_work(struct work_struct
vc4->bin_alloc_overflow = BIT(bin_bo_slot);
V3D_WRITE(V3D_BPOA, bo->base.dma_addr + bin_bo_slot * vc4->bin_alloc_size);
- V3D_WRITE(V3D_BPOS, bo->base.base.size);
+ V3D_WRITE(V3D_BPOS, vc4->bin_alloc_size);
V3D_WRITE(V3D_INTCTL, V3D_INT_OUTOMEM);
V3D_WRITE(V3D_INTENA, V3D_INT_OUTOMEM);
spin_unlock_irqrestore(&vc4->job_lock, irqflags);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 384/438] drm/vc4: Zero the tile state data array before each BIN job
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (382 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 383/438] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 385/438] drm/bridge: display-connector: Fix I2C adapter resource leak Greg Kroah-Hartman
` (67 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Iago Toral Quiroga, Maíra Canal
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maíra Canal <mcanal@igalia.com>
commit 48a570c964d8e37d353381e4195106277e17f5cb upstream.
The binner BO is a single 16MB buffer split into 512KB slots that are
handed out to jobs at submission time and recycled as jobs complete,
without ever being cleared. Each slot holds the job's Tile State Data
Array (TSDA) at its start, followed by the tile allocation pool.
While the tile allocation pool is only walked by the render thread
through branches the binner generated during the current job, the
TSDA is the PTB's own per-tile bookkeeping and is consumed by the
hardware itself. Although the kernel sets the "Auto-initialise Tile
State Data Array" flag in the tile binning mode configuration, the
PTB demonstrably still acts on stale tile state left by the slot's
previous user: the binner ends up creating invalid command streams
with invalid primitive streams and branches, which can cause GPU hangs
as observed in [1][2].
Zero the TSDA when the job's binning slot is configured. This clears
48 bytes per tile (~24KB for a 1080p frame) in the submission path, and
guarantees the PTB never sees another job's tile state.
The tile count is only checked for being non-zero today, so the 8-bit
fields it comes from can describe a tile state array almost six times
larger than the slot it has to live in. Bound it before the slot is
handed out, since such size decides how much of the slot is left for
the tile alloc pool.
Link: https://github.com/raspberrypi/linux/issues/3221 [1]
Link: https://github.com/raspberrypi/linux/issues/5780 [2]
Fixes: 553c942f8b2c ("drm/vc4: Allow using more than 256MB of CMA memory.")
Cc: stable@vger.kernel.org
Reviewed-by: Iago Toral Quiroga <itoral@igalia.com>
Link: https://patch.msgid.link/20260727-vc4-bin-oom-fixes-v2-2-0d8a5eddc7c9@igalia.com
Signed-off-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vc4/vc4_validate.c | 29 +++++++++++++++++++++++------
1 file changed, 23 insertions(+), 6 deletions(-)
--- a/drivers/gpu/drm/vc4/vc4_validate.c
+++ b/drivers/gpu/drm/vc4/vc4_validate.c
@@ -386,6 +386,23 @@ validate_tile_binning_config(VALIDATE_AR
return -EINVAL;
}
+ /* The tile state data array is 48 bytes per tile, and we put it at
+ * the start of a BO containing both it and the tile alloc.
+ */
+ tile_state_size = 48 * tile_count;
+
+ /* Since the tile alloc array will follow us, align. */
+ tile_state_size = roundup(tile_state_size, 4096);
+
+ /* Reject configurations whose tile state would leave no room for
+ * the tile alloc pool that follows it in the slot.
+ */
+ if (tile_state_size >= vc4->bin_alloc_size) {
+ DRM_DEBUG("Tile binning config of %dx%d too large\n",
+ exec->bin_tiles_x, exec->bin_tiles_y);
+ return -EINVAL;
+ }
+
bin_slot = vc4_v3d_get_bin_slot(vc4);
if (bin_slot < 0) {
if (bin_slot != -EINTR && bin_slot != -ERESTARTSYS) {
@@ -401,13 +418,13 @@ validate_tile_binning_config(VALIDATE_AR
exec->bin_slots |= BIT(bin_slot);
bin_addr = vc4->bin_bo->base.dma_addr + bin_slot * vc4->bin_alloc_size;
- /* The tile state data array is 48 bytes per tile, and we put it at
- * the start of a BO containing both it and the tile alloc.
- */
- tile_state_size = 48 * tile_count;
+ exec->tile_alloc_offset = bin_addr + tile_state_size;
- /* Since the tile alloc array will follow us, align. */
- exec->tile_alloc_offset = bin_addr + roundup(tile_state_size, 4096);
+ /* The TSDA area must be zeroed out before use, otherwise the PTB might
+ * consume a stale tile state.
+ */
+ memset(vc4->bin_bo->base.vaddr + bin_slot * vc4->bin_alloc_size, 0,
+ tile_state_size);
*(uint8_t *)(validated + 14) =
((flags & ~(VC4_BIN_CONFIG_ALLOC_INIT_BLOCK_SIZE_MASK |
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 385/438] drm/bridge: display-connector: Fix I2C adapter resource leak
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (383 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 384/438] drm/vc4: Zero the tile state data array before each BIN job Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 386/438] drm/panthor: reject firmware sections with oversized data Greg Kroah-Hartman
` (66 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Laurent Pinchart, Johan Hovold,
Luca Ceresoli
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
commit 6a39ca1286dd97ad02bb8e03bbb65ee05368d778 upstream.
If the probe function returns an error after getting the I2C adapter for
DDC, the reference to the adapter is never released. Fix it by releasing
it in the bridge .destroy() handler.
There is no need to test the ddc pointer with !IS_ERR(), as
of_get_i2c_adapter_by_node() returns NULL on error.
Fixes: 2e2bf3a5584d ("drm/bridge: display-connector: add DP support")
Cc: stable@vger.kernel.org
Signed-off-by: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
Reviewed-by: Johan Hovold <johan@kernel.org>
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Link: https://patch.msgid.link/20260717184836.2017386-1-laurent.pinchart+renesas@ideasonboard.com
Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/bridge/display-connector.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/drivers/gpu/drm/bridge/display-connector.c
+++ b/drivers/gpu/drm/bridge/display-connector.c
@@ -40,6 +40,13 @@ static int display_connector_attach(stru
return flags & DRM_BRIDGE_ATTACH_NO_CONNECTOR ? 0 : -EINVAL;
}
+static void display_connector_destroy(struct drm_bridge *bridge)
+{
+ struct display_connector *conn = to_display_connector(bridge);
+
+ i2c_put_adapter(conn->bridge.ddc);
+}
+
static enum drm_connector_status display_connector_detect(struct drm_bridge *bridge)
{
struct display_connector *conn = to_display_connector(bridge);
@@ -177,6 +184,7 @@ static u32 *display_connector_get_input_
static const struct drm_bridge_funcs display_connector_bridge_funcs = {
.attach = display_connector_attach,
+ .destroy = display_connector_destroy,
.detect = display_connector_bridge_detect,
.edid_read = display_connector_edid_read,
.atomic_get_output_bus_fmts = display_connector_get_output_bus_fmts,
@@ -403,9 +411,6 @@ static void display_connector_remove(str
regulator_disable(conn->supply);
drm_bridge_remove(&conn->bridge);
-
- if (!IS_ERR(conn->bridge.ddc))
- i2c_put_adapter(conn->bridge.ddc);
}
static const struct of_device_id display_connector_match[] = {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 386/438] drm/panthor: reject firmware sections with oversized data
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (384 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 385/438] drm/bridge: display-connector: Fix I2C adapter resource leak Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 387/438] drm/panthor: validate firmware interface structure sizes Greg Kroah-Hartman
` (65 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Osama Abdelkader, Steven Price,
Boris Brezillon
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Osama Abdelkader <osama.abdelkader@gmail.com>
commit a3caaa06809248b996254be5b47e10804a3494e2 upstream.
In panthor_fw_load_section_entry(), the data size to copy is calculated
without validating it against the allocated section_size:
section->data.size = hdr.data.end - hdr.data.start;
If a crafted firmware sets data.size larger than the allocated memory,
this could cause a heap buffer overflow in panthor_fw_init_section_mem()
memcpy(section->mem->kmap, section->data.buf, section->data.size);
Additionally, if the section->data.size exceeds the BO size, could this
memset underflow the size calculation, leading to a massive out-of-bounds
zeroing of kernel memory?
memset(section->mem->kmap + section->data.size, 0,
panthor_kernel_bo_size(section->mem) - section->data.size);
Reject section entries whose initial data is larger than the section size.
Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Reviewed-by: Boris Brezillon <boris.brezillon@collabora.com>
Link: https://patch.msgid.link/20260716143939.21903-1-osama.abdelkader@gmail.com
Signed-off-by: Steven Price <steven.price@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/panthor/panthor_fw.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -542,6 +542,7 @@ static int panthor_fw_load_section_entry
struct panthor_fw_binary_section_entry_hdr hdr;
struct panthor_fw_section *section;
u32 section_size;
+ u32 data_size;
u32 name_len;
int ret;
@@ -592,6 +593,13 @@ static int panthor_fw_load_section_entry
return -EINVAL;
}
+ section_size = hdr.va.end - hdr.va.start;
+ data_size = hdr.data.end - hdr.data.start;
+ if (data_size > section_size) {
+ drm_err(&ptdev->base, "Firmware corrupted, section data exceeds section size\n");
+ return -EINVAL;
+ }
+
name_len = iter->size - iter->offset;
section = drmm_kzalloc(&ptdev->base, sizeof(*section), GFP_KERNEL);
@@ -600,7 +608,7 @@ static int panthor_fw_load_section_entry
list_add_tail(§ion->node, &ptdev->fw->sections);
section->flags = hdr.flags;
- section->data.size = hdr.data.end - hdr.data.start;
+ section->data.size = data_size;
if (section->data.size > 0) {
void *data = drmm_kmalloc(&ptdev->base, section->data.size, GFP_KERNEL);
@@ -623,7 +631,6 @@ static int panthor_fw_load_section_entry
section->name = name;
}
- section_size = hdr.va.end - hdr.va.start;
if (section_size) {
u32 cache_mode = hdr.flags & CSF_FW_BINARY_IFACE_ENTRY_CACHE_MODE_MASK;
struct panthor_gem_object *bo;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 387/438] drm/panthor: validate firmware interface structure sizes
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (385 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 386/438] drm/panthor: reject firmware sections with oversized data Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 388/438] drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2 Greg Kroah-Hartman
` (64 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Osama Abdelkader, Steven Price
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Osama Abdelkader <osama.abdelkader@gmail.com>
commit b921b8613790a3f9e78ab64017fa7149ef0b750c upstream.
iface_fw_to_cpu_addr() only checks that the firmware-provided MCU virtual
address points inside the shared section. The returned pointer is later
used as a full firmware interface structure, so accepting an address near
the end of the shared section can still lead to out-of-bounds accesses.
Pass the expected object size to iface_fw_to_cpu_addr() and reject ranges
that do not fit entirely in the shared section.
Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Signed-off-by: Steven Price <steven.price@arm.com>
Link: https://patch.msgid.link/20260720114918.15973-1-osama.abdelkader@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/panthor/panthor_fw.c | 36 +++++++++++++++++++++++------------
1 file changed, 24 insertions(+), 12 deletions(-)
--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -859,18 +859,24 @@ out:
* iface_fw_to_cpu_addr() - Turn an MCU address into a CPU address
* @ptdev: Device.
* @mcu_va: MCU address.
+ * @size: Size of the object pointed to by @mcu_va.
*
- * Return: NULL if the address is not part of the shared section, non-NULL otherwise.
+ * Return: NULL if the object is not part of the shared section, non-NULL otherwise.
*/
-static void *iface_fw_to_cpu_addr(struct panthor_device *ptdev, u32 mcu_va)
+static void *iface_fw_to_cpu_addr(struct panthor_device *ptdev, u32 mcu_va, size_t size)
{
u64 shared_mem_start = panthor_kernel_bo_gpuva(ptdev->fw->shared_section->mem);
- u64 shared_mem_end = shared_mem_start +
- panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
- if (mcu_va < shared_mem_start || mcu_va >= shared_mem_end)
+ size_t shared_mem_size = panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
+ u64 offset;
+
+ if (mcu_va < shared_mem_start)
+ return NULL;
+
+ offset = mcu_va - shared_mem_start;
+ if (offset > shared_mem_size || size > shared_mem_size - offset)
return NULL;
- return ptdev->fw->shared_section->mem->kmap + (mcu_va - shared_mem_start);
+ return ptdev->fw->shared_section->mem->kmap + offset;
}
static int panthor_init_cs_iface(struct panthor_device *ptdev,
@@ -892,8 +898,10 @@ static int panthor_init_cs_iface(struct
spin_lock_init(&cs_iface->lock);
cs_iface->control = ptdev->fw->shared_section->mem->kmap + iface_offset;
- cs_iface->input = iface_fw_to_cpu_addr(ptdev, cs_iface->control->input_va);
- cs_iface->output = iface_fw_to_cpu_addr(ptdev, cs_iface->control->output_va);
+ cs_iface->input = iface_fw_to_cpu_addr(ptdev, cs_iface->control->input_va,
+ sizeof(*cs_iface->input));
+ cs_iface->output = iface_fw_to_cpu_addr(ptdev, cs_iface->control->output_va,
+ sizeof(*cs_iface->output));
if (!cs_iface->input || !cs_iface->output) {
drm_err(&ptdev->base, "Invalid stream control interface input/output VA");
@@ -943,8 +951,10 @@ static int panthor_init_csg_iface(struct
spin_lock_init(&csg_iface->lock);
csg_iface->control = ptdev->fw->shared_section->mem->kmap + iface_offset;
- csg_iface->input = iface_fw_to_cpu_addr(ptdev, csg_iface->control->input_va);
- csg_iface->output = iface_fw_to_cpu_addr(ptdev, csg_iface->control->output_va);
+ csg_iface->input = iface_fw_to_cpu_addr(ptdev, csg_iface->control->input_va,
+ sizeof(*csg_iface->input));
+ csg_iface->output = iface_fw_to_cpu_addr(ptdev, csg_iface->control->output_va,
+ sizeof(*csg_iface->output));
if (csg_iface->control->stream_num < MIN_CS_PER_CSG ||
csg_iface->control->stream_num > MAX_CS_PER_CSG)
@@ -1001,8 +1011,10 @@ static int panthor_fw_init_ifaces(struct
return -EINVAL;
}
- glb_iface->input = iface_fw_to_cpu_addr(ptdev, glb_iface->control->input_va);
- glb_iface->output = iface_fw_to_cpu_addr(ptdev, glb_iface->control->output_va);
+ glb_iface->input = iface_fw_to_cpu_addr(ptdev, glb_iface->control->input_va,
+ sizeof(*glb_iface->input));
+ glb_iface->output = iface_fw_to_cpu_addr(ptdev, glb_iface->control->output_va,
+ sizeof(*glb_iface->output));
if (!glb_iface->input || !glb_iface->output) {
drm_err(&ptdev->base, "Invalid global control interface input/output VA");
return -EINVAL;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 388/438] drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (386 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 387/438] drm/panthor: validate firmware interface structure sizes Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 389/438] drm/mediatek: ovl_adaptor: balance component registrations Greg Kroah-Hartman
` (63 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johan Hovold, Guangshuo Li, CK Hu,
Chun-Kuang Hu
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit d19d8542808c3be5f4af849da6509e877b74d811 upstream.
mtk_hdmi_common_probe() gets the DDC adapter with
of_find_i2c_adapter_by_node() and registers a devm action to release the
adapter device reference with put_device().
The HDMI v2 remove callback also calls i2c_put_adapter() on the same DDC
adapter. This is not paired with of_find_i2c_adapter_by_node(): it drops
the adapter device reference before the devm action drops it again, and
it also puts a module reference that was never taken.
Remove the extra i2c_put_adapter() call and drop the now-empty HDMI v2
remove callback. The common devm action releases the adapter device
reference.
Fixes: 8d0f79886273 ("drm/mediatek: Introduce HDMI/DDC v2 for MT8195/MT8188")
Cc: stable@vger.kernel.org
Reviewed-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: CK Hu <ck.hu@mediatek.com>
Link: https://patchwork.kernel.org/project/linux-mediatek/patch/20260713112957.884640-1-lgs201920130244@gmail.com/
Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/mediatek/mtk_hdmi_v2.c | 8 --------
1 file changed, 8 deletions(-)
--- a/drivers/gpu/drm/mediatek/mtk_hdmi_v2.c
+++ b/drivers/gpu/drm/mediatek/mtk_hdmi_v2.c
@@ -1499,13 +1499,6 @@ static int mtk_hdmi_v2_probe(struct plat
return 0;
}
-static void mtk_hdmi_v2_remove(struct platform_device *pdev)
-{
- struct mtk_hdmi *hdmi = platform_get_drvdata(pdev);
-
- i2c_put_adapter(hdmi->ddc_adpt);
-}
-
static const struct of_device_id mtk_drm_hdmi_v2_of_ids[] = {
{ .compatible = "mediatek,mt8188-hdmi-tx", .data = &mtk_hdmi_conf_mt8188 },
{ .compatible = "mediatek,mt8195-hdmi-tx", .data = &mtk_hdmi_conf_mt8195 },
@@ -1515,7 +1508,6 @@ MODULE_DEVICE_TABLE(of, mtk_drm_hdmi_v2_
static struct platform_driver mtk_hdmi_v2_driver = {
.probe = mtk_hdmi_v2_probe,
- .remove = mtk_hdmi_v2_remove,
.driver = {
.name = "mediatek-drm-hdmi-v2",
.of_match_table = mtk_drm_hdmi_v2_of_ids,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 389/438] drm/mediatek: ovl_adaptor: balance component registrations
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (387 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 388/438] drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2 Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 390/438] drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini Greg Kroah-Hartman
` (62 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, CK Hu,
Chun-Kuang Hu
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 533e3469a57996905cdb95f178e7efe38c21aeb2 upstream.
The OVL adaptor registers both an aggregate driver for its child devices
and a component for the main DRM aggregate. Probe currently ignores an
error from registering the child aggregate and leaves that aggregate
registered if registering the DRM component fails. The remove callback
also leaves the DRM component registered.
These imbalances can leave component framework entries referring to a
device whose probe failed or whose driver has been detached. The aggregate
unbind callback also fails to undo component_bind_all(), leaving its child
components marked as bound when the aggregate is removed.
Check the aggregate registration result, unwind it when the component
registration fails, and unregister the component before the aggregate on
remove. Keep runtime PM enabled until both framework registrations have
been removed, and unbind all child components from the aggregate unbind
callback.
Fixes: 453c3364632a ("drm/mediatek: Add ovl_adaptor support for MT8195")
Cc: stable@vger.kernel.org # 6.4+
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: CK Hu <ck.hu@mediatek.com>
Link: https://patchwork.kernel.org/project/linux-mediatek/patch/20260721152242.47138-1-mhun512@gmail.com/
Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/mediatek/mtk_disp_ovl_adaptor.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/mediatek/mtk_disp_ovl_adaptor.c
+++ b/drivers/gpu/drm/mediatek/mtk_disp_ovl_adaptor.c
@@ -625,6 +625,7 @@ static void mtk_disp_ovl_adaptor_master_
struct mtk_disp_ovl_adaptor *priv = dev_get_drvdata(dev);
priv->children_bound = false;
+ component_unbind_all(dev, priv->mmsys_dev);
}
static const struct component_master_ops mtk_disp_ovl_adaptor_master_ops = {
@@ -651,12 +652,15 @@ static int mtk_disp_ovl_adaptor_probe(st
priv->mmsys_dev = pdev->dev.platform_data;
- component_master_add_with_match(dev, &mtk_disp_ovl_adaptor_master_ops, match);
+ ret = component_master_add_with_match(dev, &mtk_disp_ovl_adaptor_master_ops, match);
+ if (ret)
+ return dev_err_probe(dev, ret, "Failed to add component master\n");
pm_runtime_enable(dev);
ret = component_add(dev, &mtk_disp_ovl_adaptor_comp_ops);
if (ret != 0) {
+ component_master_del(dev, &mtk_disp_ovl_adaptor_master_ops);
pm_runtime_disable(dev);
return dev_err_probe(dev, ret, "Failed to add component\n");
}
@@ -666,6 +670,7 @@ static int mtk_disp_ovl_adaptor_probe(st
static void mtk_disp_ovl_adaptor_remove(struct platform_device *pdev)
{
+ component_del(&pdev->dev, &mtk_disp_ovl_adaptor_comp_ops);
component_master_del(&pdev->dev, &mtk_disp_ovl_adaptor_master_ops);
pm_runtime_disable(&pdev->dev);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 390/438] drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (388 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 389/438] drm/mediatek: ovl_adaptor: balance component registrations Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 391/438] drm/amdgpu: restore UMD profile pstate after runtime resume Greg Kroah-Hartman
` (61 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pierre-Eric Pelloux-Prayer,
Christian König, Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
commit d8726ef11512754a68c0ab53c57634a569b8feff upstream.
The commit referenced below restarts the CS if the validation is
still in progress. When debug_vm is enabled, all BOs from the CS
are invalidated so we will hit an infinite loop.
To avoid that, defer BO invalidation to amdgpu_cs_parser_fini.
Fixes: 59720bfd8c6d ("drm/amdgpu: restart the CS if some parts of the VM are still invalidated")
Signed-off-by: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 8c990ee9daa295462df24982ce6878db997a380a)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c | 30 ++++++++++++++++--------------
1 file changed, 16 insertions(+), 14 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c
@@ -1182,19 +1182,6 @@ static int amdgpu_cs_vm_handling(struct
job->vm_pd_addr = amdgpu_gmc_pd_addr(vm->root.bo);
}
- if (adev->debug_vm) {
- /* Invalidate all BOs to test for userspace bugs */
- amdgpu_bo_list_for_each_entry(e, p->bo_list) {
- struct amdgpu_bo *bo = e->bo;
-
- /* ignore duplicates */
- if (!bo)
- continue;
-
- amdgpu_vm_bo_invalidate(bo, false);
- }
- }
-
return 0;
}
@@ -1384,6 +1371,8 @@ static int amdgpu_cs_submit(struct amdgp
/* Cleanup the parser structure */
static void amdgpu_cs_parser_fini(struct amdgpu_cs_parser *parser)
{
+ struct amdgpu_device *adev = parser->adev;
+ struct amdgpu_bo_list_entry *e;
unsigned int i;
amdgpu_sync_free(&parser->sync);
@@ -1399,8 +1388,21 @@ static void amdgpu_cs_parser_fini(struct
if (parser->ctx)
amdgpu_ctx_put(parser->ctx);
- if (parser->bo_list)
+ if (parser->bo_list) {
+ if (adev->debug_vm) {
+ /* Invalidate all BOs to test for userspace bugs */
+ amdgpu_bo_list_for_each_entry(e, parser->bo_list) {
+ struct amdgpu_bo *bo = e->bo;
+
+ /* ignore duplicates */
+ if (!bo)
+ continue;
+
+ amdgpu_vm_bo_invalidate(bo, false);
+ }
+ }
amdgpu_bo_list_put(parser->bo_list);
+ }
for (i = 0; i < parser->nchunks; i++)
kvfree(parser->chunks[i].kdata);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 391/438] drm/amdgpu: restore UMD profile pstate after runtime resume
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (389 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 390/438] drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 392/438] drm/amdgpu: cap GTT size to physical RAM on APUs Greg Kroah-Hartman
` (60 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Candice Li, Hawking Zhang, Yang Wang,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Candice Li <candice.li@amd.com>
commit f931c54b241ce2f36bfc34955aec43a188276b8d upstream.
Runtime suspend runs GFX hw_fini and clears perfmon clock gating while
the UMD profile DPM level remains set in software. Re-apply stable
pstate after a successful runtime resume when a profile mode is active.
Signed-off-by: Candice Li <candice.li@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Reviewed-by: Yang Wang <kevinyang.wang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 138531c8850cc247aa12b104bb29ea387bcdcbb1)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
@@ -2876,6 +2876,19 @@ static int amdgpu_pmops_runtime_suspend(
return 0;
}
+static void amdgpu_restore_umd_profile_pstate_after_runpm(struct amdgpu_device *adev)
+{
+ enum amd_dpm_forced_level level;
+ uint32_t profile_mode_mask = AMD_DPM_FORCED_LEVEL_PROFILE_STANDARD |
+ AMD_DPM_FORCED_LEVEL_PROFILE_MIN_SCLK |
+ AMD_DPM_FORCED_LEVEL_PROFILE_MIN_MCLK |
+ AMD_DPM_FORCED_LEVEL_PROFILE_PEAK;
+
+ level = amdgpu_dpm_get_performance_level(adev);
+ if (level & profile_mode_mask)
+ amdgpu_asic_update_umd_stable_pstate(adev, true);
+}
+
static int amdgpu_pmops_runtime_resume(struct device *dev)
{
struct pci_dev *pdev = to_pci_dev(dev);
@@ -2920,6 +2933,8 @@ static int amdgpu_pmops_runtime_resume(s
if (adev->pm.rpm_mode == AMDGPU_RUNPM_PX)
drm_dev->switch_power_state = DRM_SWITCH_POWER_ON;
+
+ amdgpu_restore_umd_profile_pstate_after_runpm(adev);
adev->in_runpm = false;
return 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 392/438] drm/amdgpu: cap GTT size to physical RAM on APUs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (390 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 391/438] drm/amdgpu: restore UMD profile pstate after runtime resume Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 393/438] drm/amd/pm: fix torn gpu metrics reads Greg Kroah-Hartman
` (59 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Harkirat Gill, David Francis,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harkirat Gill <harkirat.gill@amd.com>
commit 5e70f6804b4d6256058c360b10e044ee04ea4a4e upstream.
On APUs, the GTT pool is backed by system RAM, but its size is not bound
to the non-carveout memory that actually backs it. A user can end up
with GTT + VRAM exceeding total physical memory through the following
sequence:
- Have a large non-carveout memory space (~128GB) and accordingly set a
large GTT (~100GB) via the ttm module parameter.
- Lower the non-carveout memory space in BIOS by increasing the UMA
Frame Buffer Size (VRAM) to 64GB.
- The previously set GTT value (~100GB) persists, even though the new
non-carveout space (64GB) can no longer back it.
This leads to a case where kernel reports GTT (100GB) + VRAM (64GB)
despite the sum being greater than total physical memory (128GB).
Cap the GTT size to totalram_pages() on APUs. totalram_pages() already
excludes the VRAM carveout, so the resulting GTT can never exceed the
system RAM that actually backs it.
Signed-off-by: Harkirat Gill <harkirat.gill@amd.com>
Reviewed-by: David Francis <David.Francis@amd.com>
Assisted-by: Claude:claude-opus-4
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 5dafdd649280c7dc6c22c8f877da3f54fcc441e1)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
@@ -2174,6 +2174,18 @@ int amdgpu_ttm_init(struct amdgpu_device
gtt_size = configured_size;
}
+ /* Cap GTT so that it does not exceed total physical RAM. */
+ if (adev->flags & AMD_IS_APU) {
+ u64 phys_ram = (u64)totalram_pages() << PAGE_SHIFT;
+
+ if (gtt_size > phys_ram) {
+ gtt_size = phys_ram;
+ dev_info(adev->dev,
+ "Capping GTT to %uM to not exceed available system memory\n",
+ (unsigned int)(gtt_size / (1024 * 1024)));
+ }
+ }
+
/* Initialize GTT memory pool */
r = amdgpu_gtt_mgr_init(adev, gtt_size);
if (r) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 393/438] drm/amd/pm: fix torn gpu metrics reads
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (391 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 392/438] drm/amdgpu: cap GTT size to physical RAM on APUs Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 394/438] drm/amd/pm: fix pptable use-after-free Greg Kroah-Hartman
` (58 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yang Wang, Kenneth Feng,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yang Wang <kevinyang.wang@amd.com>
commit 048f4541b71fb19645fb79d6e62e6e4da23a4035 upstream.
amdgpu_dpm_get_gpu_metrics() returns a pointer to the shared metrics cache
after dropping adev->pm.mutex. The sysfs path then copies from that pointer.
Another reader can refresh the cache in place during the copy and return a
snapshot containing data from two generations.
Pass caller-provided storage through the DPM interface and copy the metrics
while the mutex is held. This keeps the cache pointer private and makes each
sysfs read observe one complete sample.
Fixes: 25c933b1c4fc ("drm/amd/powerplay: add new sysfs interface for retrieving gpu metrics(V2)")
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Kenneth Feng <kenneth.feng@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 862333bb48693ecafcae25af0c9d9ec31015ac77)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/pm/amdgpu_dpm.c | 12 +++++++++---
drivers/gpu/drm/amd/pm/amdgpu_pm.c | 8 +-------
drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h | 3 ++-
3 files changed, 12 insertions(+), 11 deletions(-)
--- a/drivers/gpu/drm/amd/pm/amdgpu_dpm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_dpm.c
@@ -1426,17 +1426,23 @@ int amdgpu_dpm_set_power_profile_mode(st
return ret;
}
-int amdgpu_dpm_get_gpu_metrics(struct amdgpu_device *adev, void **table)
+ssize_t amdgpu_dpm_get_gpu_metrics(struct amdgpu_device *adev, void *buf,
+ size_t size)
{
const struct amd_pm_funcs *pp_funcs = adev->powerplay.pp_funcs;
- int ret = 0;
+ void *table;
+ ssize_t ret;
if (!pp_funcs->get_gpu_metrics)
return 0;
mutex_lock(&adev->pm.mutex);
ret = pp_funcs->get_gpu_metrics(adev->powerplay.pp_handle,
- table);
+ &table);
+ if (ret > 0) {
+ ret = min_t(ssize_t, ret, size);
+ memcpy(buf, table, ret);
+ }
mutex_unlock(&adev->pm.mutex);
return ret;
--- a/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
@@ -1773,7 +1773,6 @@ static ssize_t amdgpu_get_gpu_metrics(st
{
struct drm_device *ddev = dev_get_drvdata(dev);
struct amdgpu_device *adev = drm_to_adev(ddev);
- void *gpu_metrics;
ssize_t size = 0;
int ret;
@@ -1781,15 +1780,10 @@ static ssize_t amdgpu_get_gpu_metrics(st
if (ret)
return ret;
- size = amdgpu_dpm_get_gpu_metrics(adev, &gpu_metrics);
+ size = amdgpu_dpm_get_gpu_metrics(adev, buf, PAGE_SIZE - 1);
if (size <= 0)
goto out;
- if (size >= PAGE_SIZE)
- size = PAGE_SIZE - 1;
-
- memcpy(buf, gpu_metrics, size);
-
out:
amdgpu_pm_put_access(adev);
--- a/drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h
+++ b/drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h
@@ -517,7 +517,8 @@ int amdgpu_dpm_get_power_profile_mode(st
char *buf);
int amdgpu_dpm_set_power_profile_mode(struct amdgpu_device *adev,
long *input, uint32_t size);
-int amdgpu_dpm_get_gpu_metrics(struct amdgpu_device *adev, void **table);
+ssize_t amdgpu_dpm_get_gpu_metrics(struct amdgpu_device *adev, void *buf,
+ size_t size);
ssize_t amdgpu_dpm_get_xcp_metrics(struct amdgpu_device *adev, int xcp_id,
void *table);
ssize_t amdgpu_dpm_get_temp_metrics(struct amdgpu_device *adev,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 394/438] drm/amd/pm: fix pptable use-after-free
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (392 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 393/438] drm/amd/pm: fix torn gpu metrics reads Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 395/438] drm/amd/pm: hide pp_table sysfs on APUs Greg Kroah-Hartman
` (57 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yang Wang, Kenneth Feng,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yang Wang <kevinyang.wang@amd.com>
commit bb493058c35c8676e48269ab6732688ea733d23c upstream.
amdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table
after dropping adev->pm.mutex. The sysfs path then copies from that pointer.
A concurrent pp_table write can replace and free the allocation during the
copy, causing a use-after-free.
Change the DPM interface to copy into caller-provided storage while the mutex
is held. Keep the size-only query for attribute discovery without exposing
the driver-owned pointer.
Fixes: 1684d3ba4885 ("drm/amd/amdgpu: change pptable output format from ASCII to binary")
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Kenneth Feng <kenneth.feng@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/pm/amdgpu_dpm.c | 14 +++++++++++---
drivers/gpu/drm/amd/pm/amdgpu_pm.c | 13 +++----------
drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h | 3 ++-
3 files changed, 16 insertions(+), 14 deletions(-)
--- a/drivers/gpu/drm/amd/pm/amdgpu_dpm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_dpm.c
@@ -1183,12 +1183,14 @@ int amdgpu_dpm_dispatch_task(struct amdg
return ret;
}
-int amdgpu_dpm_get_pp_table(struct amdgpu_device *adev, char **table)
+int amdgpu_dpm_get_pp_table(struct amdgpu_device *adev, char *table,
+ size_t size)
{
const struct amd_pm_funcs *pp_funcs = adev->powerplay.pp_funcs;
+ char *pptable = NULL;
int ret = 0;
- if (!table)
+ if ((!table && size) || (table && !size))
return -EINVAL;
if (amdgpu_sriov_vf(adev) || !pp_funcs->get_pp_table || adev->scpm_enabled)
@@ -1196,7 +1198,13 @@ int amdgpu_dpm_get_pp_table(struct amdgp
mutex_lock(&adev->pm.mutex);
ret = pp_funcs->get_pp_table(adev->powerplay.pp_handle,
- table);
+ &pptable);
+ if (ret > 0 && !pptable) {
+ ret = -EINVAL;
+ } else if (ret > 0 && table) {
+ ret = min_t(size_t, ret, size);
+ memcpy(table, pptable, ret);
+ }
mutex_unlock(&adev->pm.mutex);
return ret;
--- a/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
@@ -564,25 +564,19 @@ static ssize_t amdgpu_get_pp_table(struc
{
struct drm_device *ddev = dev_get_drvdata(dev);
struct amdgpu_device *adev = drm_to_adev(ddev);
- char *table = NULL;
int size, ret;
ret = amdgpu_pm_get_access_if_active(adev);
if (ret)
return ret;
- size = amdgpu_dpm_get_pp_table(adev, &table);
+ size = amdgpu_dpm_get_pp_table(adev, buf, PAGE_SIZE - 1);
amdgpu_pm_put_access(adev);
if (size <= 0)
return size;
- if (size >= PAGE_SIZE)
- size = PAGE_SIZE - 1;
-
- memcpy(buf, table, size);
-
return size;
}
@@ -2704,10 +2698,9 @@ static int default_attr_update(struct am
*states = ATTR_STATE_UNSUPPORTED;
} else if (DEVICE_ATTR_IS(pp_table)) {
int ret;
- char *tmp = NULL;
- ret = amdgpu_dpm_get_pp_table(adev, &tmp);
- if (ret == -EOPNOTSUPP || !tmp)
+ ret = amdgpu_dpm_get_pp_table(adev, NULL, 0);
+ if (ret <= 0)
*states = ATTR_STATE_UNSUPPORTED;
else
*states = ATTR_STATE_SUPPORTED;
--- a/drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h
+++ b/drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h
@@ -487,7 +487,8 @@ int amdgpu_dpm_get_pp_num_states(struct
int amdgpu_dpm_dispatch_task(struct amdgpu_device *adev,
enum amd_pp_task task_id,
enum amd_pm_state_type *user_state);
-int amdgpu_dpm_get_pp_table(struct amdgpu_device *adev, char **table);
+int amdgpu_dpm_get_pp_table(struct amdgpu_device *adev, char *table,
+ size_t size);
int amdgpu_dpm_set_fine_grain_clk_vol(struct amdgpu_device *adev,
uint32_t type,
long *input,
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 395/438] drm/amd/pm: hide pp_table sysfs on APUs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (393 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 394/438] drm/amd/pm: fix pptable use-after-free Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 396/438] drm/amd/pm: use milliwatts for GPU power sensors Greg Kroah-Hartman
` (56 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yang Wang, Kenneth Feng, Asad Kamal,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yang Wang <kevinyang.wang@amd.com>
commit a65f5179d3f0c93da31b450aeb416eaa22f1912b upstream.
APUs use firmware-owned DPM tables and do not support replacement through
pp_table. Generic callbacks can nevertheless expose the sysfs file and
accept an upload before resetting the power management stack.
Treat pp_table as unsupported on APUs. Use the same platform check in the
get and set paths to hide the file and reject uploads.
Fixes: 289921b03fe5 ("drm/amd/powerplay: implement sysfs of pp_table for smu11 (v2)")
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Kenneth Feng <kenneth.feng@amd.com>
Reviewed-by: Asad Kamal <asad.kamal@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 74f28db2db69777cd2f059d50fe34e365ddd5add)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/pm/amdgpu_dpm.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/amd/pm/amdgpu_dpm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_dpm.c
@@ -1183,6 +1183,13 @@ int amdgpu_dpm_dispatch_task(struct amdg
return ret;
}
+static bool amdgpu_dpm_is_pp_table_allowed(struct amdgpu_device *adev)
+{
+ return !amdgpu_sriov_vf(adev) &&
+ !(adev->flags & AMD_IS_APU) &&
+ !adev->scpm_enabled;
+}
+
int amdgpu_dpm_get_pp_table(struct amdgpu_device *adev, char *table,
size_t size)
{
@@ -1193,7 +1200,8 @@ int amdgpu_dpm_get_pp_table(struct amdgp
if ((!table && size) || (table && !size))
return -EINVAL;
- if (amdgpu_sriov_vf(adev) || !pp_funcs->get_pp_table || adev->scpm_enabled)
+ if (!amdgpu_dpm_is_pp_table_allowed(adev) ||
+ !pp_funcs->get_pp_table)
return -EOPNOTSUPP;
mutex_lock(&adev->pm.mutex);
@@ -1717,7 +1725,8 @@ int amdgpu_dpm_set_pp_table(struct amdgp
if (!buf || !size)
return -EINVAL;
- if (amdgpu_sriov_vf(adev) || !pp_funcs->set_pp_table || adev->scpm_enabled)
+ if (!amdgpu_dpm_is_pp_table_allowed(adev) ||
+ !pp_funcs->set_pp_table)
return -EOPNOTSUPP;
mutex_lock(&adev->pm.mutex);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 396/438] drm/amd/pm: use milliwatts for GPU power sensors
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (394 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 395/438] drm/amd/pm: hide pp_table sysfs on APUs Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 397/438] drm/amd/display: check if dml21_add_phantom_plane() is successful Greg Kroah-Hartman
` (55 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yang Wang, Kenneth Feng,
Lars Nieradzik, Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yang Wang <kevinyang.wang@amd.com>
commit 1849a64165ccc23d3e5fc22b8be19227c21c1871 upstream.
GPU average and input power backends report a mix of whole watts,
milliwatts, Q24.8 watts and decimal-packed fractions. Q24.8 is inherited
from the legacy PowerPlay sensor format. Milliwatts are a more natural unit
for the hwmon and pm_info consumers in amdgpu_pm.c. A common decoder cannot
distinguish these formats, and converting native milliwatts through Q24.8
also loses precision.
Use milliwatts as the internal unit across all PPT and PowerPlay backends.
Decode Q24.8 only at the legacy smu7 input boundary and encode it only for
the raw amdgpu_sensors debugfs interface. This gives hwmon, pm_info and the
sensor ioctl one unambiguous unit while preserving the format used by UMR.
Fixes: 5b79d0482f3c ("drm/amd/pp: Remove struct pp_gpu_power")
Fixes: 01992b121fb6 ("drm/amd/pm: fix amdgpu_pm_info power display units")
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Kenneth Feng <kenneth.feng@amd.com>
Reported-by: Lars Nieradzik <l.nieradzik@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 757ba0790bafec47a507e9662bf380f2e027d420)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 9 +++++++++
drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c | 4 ++--
drivers/gpu/drm/amd/include/kgd_pp_interface.h | 6 ++++--
drivers/gpu/drm/amd/pm/amdgpu_pm.c | 8 +++-----
drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c | 4 ++--
drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c | 4 ++--
drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega12_hwmgr.c | 2 +-
drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega20_hwmgr.c | 5 +++--
drivers/gpu/drm/amd/pm/powerplay/inc/hwmgr.h | 5 +++++
drivers/gpu/drm/amd/pm/swsmu/smu11/arcturus_ppt.c | 2 +-
drivers/gpu/drm/amd/pm/swsmu/smu11/cyan_skillfish_ppt.c | 6 ++----
drivers/gpu/drm/amd/pm/swsmu/smu11/navi10_ppt.c | 8 ++++----
drivers/gpu/drm/amd/pm/swsmu/smu11/sienna_cichlid_ppt.c | 7 ++++---
drivers/gpu/drm/amd/pm/swsmu/smu11/vangogh_ppt.c | 9 +++------
drivers/gpu/drm/amd/pm/swsmu/smu12/renoir_ppt.c | 5 +++--
drivers/gpu/drm/amd/pm/swsmu/smu13/aldebaran_ppt.c | 3 ++-
drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_0_ppt.c | 2 +-
drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_12_ppt.c | 3 ++-
drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_4_ppt.c | 4 ++--
drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_5_ppt.c | 2 +-
drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_6_ppt.c | 3 ++-
drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_7_ppt.c | 2 +-
drivers/gpu/drm/amd/pm/swsmu/smu13/yellow_carp_ppt.c | 2 +-
drivers/gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_0_ppt.c | 3 +--
drivers/gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_2_ppt.c | 2 +-
drivers/gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_0_ppt.c | 3 +--
drivers/gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_8_ppt.c | 3 ++-
27 files changed, 65 insertions(+), 51 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
@@ -43,6 +43,11 @@
#if defined(CONFIG_DEBUG_FS)
+/* Encode milliwatts in the raw Q24.8 sensor report format used by UMR. */
+#define AMDGPU_DEBUGFS_PWR_MW_TO_Q24_8(power_mw) \
+ DIV_ROUND_CLOSEST_ULL((u64)(power_mw) * BIT(8), \
+ MILLIWATT_PER_WATT)
+
/**
* amdgpu_debugfs_process_reg_op - Handle MMIO register reads/writes
*
@@ -1104,6 +1109,10 @@ static ssize_t amdgpu_debugfs_sensor_rea
return r;
}
+ if (idx == AMDGPU_PP_SENSOR_GPU_AVG_POWER ||
+ idx == AMDGPU_PP_SENSOR_GPU_INPUT_POWER)
+ values[0] = AMDGPU_DEBUGFS_PWR_MW_TO_Q24_8(values[0]);
+
if (size > valuesize) {
amdgpu_virt_disable_access_debugfs(adev);
return -EINVAL;
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c
@@ -1210,7 +1210,7 @@ int amdgpu_info_ioctl(struct drm_device
return -EINVAL;
}
}
- ui32 >>= 8;
+ ui32 /= MILLIWATT_PER_WATT;
break;
case AMDGPU_INFO_SENSOR_GPU_INPUT_POWER:
/* get input GPU power */
@@ -1219,7 +1219,7 @@ int amdgpu_info_ioctl(struct drm_device
(void *)&ui32, &ui32_size)) {
return -EINVAL;
}
- ui32 >>= 8;
+ ui32 /= MILLIWATT_PER_WATT;
break;
case AMDGPU_INFO_SENSOR_VDDNB:
/* get VDDNB in millivolts */
--- a/drivers/gpu/drm/amd/include/kgd_pp_interface.h
+++ b/drivers/gpu/drm/amd/include/kgd_pp_interface.h
@@ -24,6 +24,8 @@
#ifndef __KGD_PP_INTERFACE_H__
#define __KGD_PP_INTERFACE_H__
+#include <linux/units.h>
+
extern const struct amdgpu_ip_block_version pp_smu_ip_block;
extern const struct amdgpu_ip_block_version smu_v11_0_ip_block;
extern const struct amdgpu_ip_block_version smu_v12_0_ip_block;
@@ -150,8 +152,8 @@ enum amd_pp_sensors {
AMDGPU_PP_SENSOR_MEM_TEMP,
AMDGPU_PP_SENSOR_VCE_POWER,
AMDGPU_PP_SENSOR_UVD_POWER,
- AMDGPU_PP_SENSOR_GPU_AVG_POWER,
- AMDGPU_PP_SENSOR_GPU_INPUT_POWER,
+ AMDGPU_PP_SENSOR_GPU_AVG_POWER, /* milliwatts */
+ AMDGPU_PP_SENSOR_GPU_INPUT_POWER, /* milliwatts */
AMDGPU_PP_SENSOR_SS_APU_SHARE,
AMDGPU_PP_SENSOR_SS_DGPU_SHARE,
AMDGPU_PP_SENSOR_STABLE_PSTATE_SCLK,
--- a/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
@@ -41,8 +41,6 @@
#define DEVICE_ATTR_IS(_name) (attr_id == device_attr_id__##_name)
-#define power_2_mwatt(power) (((power) >> 8) * 1000 + ((power) & 0xff))
-
struct od_attribute {
struct kobj_attribute attribute;
struct list_head entry;
@@ -3335,7 +3333,7 @@ static int amdgpu_hwmon_get_power(struct
return r;
/* convert to microwatts */
- return power_2_mwatt(query) * 1000;
+ return query * 1000;
}
static ssize_t amdgpu_hwmon_show_power_avg(struct device *dev,
@@ -4898,7 +4896,7 @@ static int amdgpu_debugfs_pm_info_pp(str
seq_printf(m, "\t%u mV (VDDNB)\n", value);
size = sizeof(uint32_t);
if (!amdgpu_dpm_read_sensor(adev, AMDGPU_PP_SENSOR_GPU_AVG_POWER, (void *)&query, &size)) {
- mwatt = power_2_mwatt(query);
+ mwatt = query;
centiwatt = DIV_ROUND_CLOSEST(mwatt, 10);
if (adev->flags & AMD_IS_APU)
seq_printf(m, "\t%u.%02u W (average SoC including CPU)\n", centiwatt / 100, centiwatt % 100);
@@ -4907,7 +4905,7 @@ static int amdgpu_debugfs_pm_info_pp(str
}
size = sizeof(uint32_t);
if (!amdgpu_dpm_read_sensor(adev, AMDGPU_PP_SENSOR_GPU_INPUT_POWER, (void *)&query, &size)) {
- mwatt = power_2_mwatt(query);
+ mwatt = query;
centiwatt = DIV_ROUND_CLOSEST(mwatt, 10);
if (adev->flags & AMD_IS_APU)
seq_printf(m, "\t%u.%02u W (current SoC including CPU)\n", centiwatt / 100, centiwatt % 100);
--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c
@@ -4062,7 +4062,7 @@ static int smu7_get_gpu_power(struct pp_
(adev->asic_type != CHIP_FIJI) &&
(adev->asic_type != CHIP_TONGA)) {
smum_send_msg_to_smc_with_parameter(hwmgr, PPSMC_MSG_GetCurrPkgPwr, 0, &tmp);
- *query = tmp;
+ *query = PP_PWR_Q24_8_TO_MW(tmp);
if (tmp != 0)
return 0;
@@ -4081,7 +4081,7 @@ static int smu7_get_gpu_power(struct pp_
if (tmp != 0)
break;
}
- *query = tmp;
+ *query = PP_PWR_Q24_8_TO_MW(tmp);
return 0;
}
--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c
@@ -3937,8 +3937,8 @@ static int vega10_get_gpu_power(struct p
if (ret)
return ret;
- /* SMC returning actual watts, keep consistent with legacy asics, low 8 bit as 8 fractional bits */
- *query = value << 8;
+ /* SMC returns whole Watts, while power sensors use milliwatts. */
+ *query = value * MILLIWATT_PER_WATT;
return 0;
}
--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega12_hwmgr.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega12_hwmgr.c
@@ -1419,7 +1419,7 @@ static int vega12_get_gpu_power(struct p
if (ret)
return ret;
- *query = metrics_table.CurrSocketPower << 8;
+ *query = metrics_table.CurrSocketPower * MILLIWATT_PER_WATT;
return ret;
}
--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega20_hwmgr.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega20_hwmgr.c
@@ -2154,12 +2154,13 @@ static int vega20_get_gpu_power(struct p
switch (idx) {
case AMDGPU_PP_SENSOR_GPU_AVG_POWER:
if (hwmgr->smu_version == 0x282e00)
- *query = metrics_table.AverageSocketPower << 8;
+ *query = metrics_table.AverageSocketPower *
+ MILLIWATT_PER_WATT;
else
ret = -EOPNOTSUPP;
break;
case AMDGPU_PP_SENSOR_GPU_INPUT_POWER:
- *query = metrics_table.CurrSocketPower << 8;
+ *query = metrics_table.CurrSocketPower * MILLIWATT_PER_WATT;
break;
}
--- a/drivers/gpu/drm/amd/pm/powerplay/inc/hwmgr.h
+++ b/drivers/gpu/drm/amd/pm/powerplay/inc/hwmgr.h
@@ -35,6 +35,11 @@ struct pp_hwmgr;
struct phm_fan_speed_info;
struct pp_atomctrl_voltage_table;
+/* Decode legacy unsigned Q24.8 watts to internal milliwatts. */
+#define PP_PWR_Q24_8_TO_MW(power) \
+ DIV_ROUND_CLOSEST_ULL((u64)(power) * MILLIWATT_PER_WATT, \
+ BIT(8))
+
#define VOLTAGE_SCALE 4
#define VOLTAGE_VID_OFFSET_SCALE1 625
#define VOLTAGE_VID_OFFSET_SCALE2 100
--- a/drivers/gpu/drm/amd/pm/swsmu/smu11/arcturus_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu11/arcturus_ppt.c
@@ -658,7 +658,7 @@ static int arcturus_get_smu_metrics_data
*value = metrics->VcnActivityPercentage;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->TemperatureEdge *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu11/cyan_skillfish_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu11/cyan_skillfish_ppt.c
@@ -158,12 +158,10 @@ cyan_skillfish_get_smu_metrics_data(stru
*value = metrics->Current.MemclkFrequency;
break;
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->Current.CurrentSocketPower << 8) /
- 1000;
+ *value = metrics->Current.CurrentSocketPower;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = (metrics->Average.CurrentSocketPower << 8) /
- 1000;
+ *value = metrics->Average.CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->Current.GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu11/navi10_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu11/navi10_ppt.c
@@ -602,7 +602,7 @@ static int navi10_get_legacy_smu_metrics
*value = metrics->AverageUclkActivity;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->TemperatureEdge *
@@ -691,7 +691,7 @@ static int navi10_get_smu_metrics_data(s
*value = metrics->AverageUclkActivity;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->TemperatureEdge *
@@ -777,7 +777,7 @@ static int navi12_get_legacy_smu_metrics
*value = metrics->AverageUclkActivity;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->TemperatureEdge *
@@ -866,7 +866,7 @@ static int navi12_get_smu_metrics_data(s
*value = metrics->AverageUclkActivity;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->TemperatureEdge *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu11/sienna_cichlid_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu11/sienna_cichlid_ppt.c
@@ -855,9 +855,10 @@ static int sienna_cichlid_get_smu_metric
metrics->AverageUclkActivity;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = use_metrics_v3 ? metrics_v3->AverageSocketPower << 8 :
- use_metrics_v2 ? metrics_v2->AverageSocketPower << 8 :
- metrics->AverageSocketPower << 8;
+ *value = use_metrics_v3 ? metrics_v3->AverageSocketPower :
+ use_metrics_v2 ? metrics_v2->AverageSocketPower :
+ metrics->AverageSocketPower;
+ *value *= MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = (use_metrics_v3 ? metrics_v3->TemperatureEdge :
--- a/drivers/gpu/drm/amd/pm/swsmu/smu11/vangogh_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu11/vangogh_ppt.c
@@ -310,8 +310,7 @@ static int vangogh_get_legacy_smu_metric
*value = metrics->UvdActivity / 100;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = (metrics->CurrentSocketPower << 8) /
- 1000 ;
+ *value = metrics->CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->GfxTemperature / 100 *
@@ -379,12 +378,10 @@ static int vangogh_get_smu_metrics_data(
*value = metrics->Current.UvdActivity;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = (metrics->Average.CurrentSocketPower << 8) /
- 1000;
+ *value = metrics->Average.CurrentSocketPower;
break;
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->Current.CurrentSocketPower << 8) /
- 1000;
+ *value = metrics->Current.CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->Current.GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu12/renoir_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu12/renoir_ppt.c
@@ -1215,9 +1215,10 @@ static int renoir_get_smu_metrics_data(s
((amdgpu_ip_version(adev, MP1_HWIP, 0) ==
IP_VERSION(12, 0, 0)) &&
(adev->pm.fw_version >= 0x373200)))
- *value = metrics->CurrentSocketPower << 8;
+ *value = metrics->CurrentSocketPower *
+ MILLIWATT_PER_WATT;
else
- *value = (metrics->CurrentSocketPower << 8) / 1000;
+ *value = metrics->CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = (metrics->GfxTemperature / 100) *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/aldebaran_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/aldebaran_ppt.c
@@ -677,7 +677,8 @@ static int aldebaran_get_smu_metrics_dat
case METRICS_AVERAGE_SOCKETPOWER:
/* Valid power data is available only from primary die */
if (aldebaran_is_primary(smu))
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower *
+ MILLIWATT_PER_WATT;
else
ret = -EOPNOTSUPP;
break;
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_0_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_0_ppt.c
@@ -807,7 +807,7 @@ static int smu_v13_0_0_get_smu_metrics_d
metrics->Vcn1ActivityPercentage);
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->AvgTemperature[TEMP_EDGE] *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_12_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_12_ppt.c
@@ -434,7 +434,8 @@ int smu_v13_0_12_get_smu_metrics_data(st
*value = SMUQ10_ROUND(metrics->DramBandwidthUtilization);
break;
case METRICS_CURR_SOCKETPOWER:
- *value = SMUQ10_ROUND(metrics->SocketPower) << 8;
+ *value = SMUQ10_ROUND(metrics->SocketPower) *
+ MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_HOTSPOT:
*value = SMUQ10_ROUND(metrics->MaxSocketTemperature) *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_4_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_4_ppt.c
@@ -338,10 +338,10 @@ static int smu_v13_0_4_get_smu_metrics_d
*value = metrics->UvdActivity / 100;
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = (metrics->AverageSocketPower << 8) / 1000;
+ *value = metrics->AverageSocketPower;
break;
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->CurrentSocketPower << 8) / 1000;
+ *value = metrics->CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_5_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_5_ppt.c
@@ -295,7 +295,7 @@ static int smu_v13_0_5_get_smu_metrics_d
*value = metrics->UvdActivity / 100;
break;
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->CurrentSocketPower << 8) / 1000;
+ *value = metrics->CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_6_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_6_ppt.c
@@ -1317,7 +1317,8 @@ static int smu_v13_0_6_get_smu_metrics_d
*value = SMUQ10_ROUND(GET_METRIC_FIELD(DramBandwidthUtilization, version));
break;
case METRICS_CURR_SOCKETPOWER:
- *value = SMUQ10_ROUND(GET_METRIC_FIELD(SocketPower, version)) << 8;
+ *value = SMUQ10_ROUND(GET_METRIC_FIELD(SocketPower, version)) *
+ MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_HOTSPOT:
*value = SMUQ10_ROUND(GET_METRIC_FIELD(MaxSocketTemperature, version)) *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_7_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/smu_v13_0_7_ppt.c
@@ -817,7 +817,7 @@ static int smu_v13_0_7_get_smu_metrics_d
*value = smu_safe_u16_nn(metrics->AverageUclkActivity);
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->AvgTemperature[TEMP_EDGE] *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu13/yellow_carp_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu13/yellow_carp_ppt.c
@@ -372,7 +372,7 @@ static int yellow_carp_get_smu_metrics_d
*value = metrics->UvdActivity / 100;
break;
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->CurrentSocketPower << 8) / 1000;
+ *value = metrics->CurrentSocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_0_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_0_ppt.c
@@ -312,8 +312,7 @@ static int smu_v14_0_0_get_smu_metrics_d
break;
case METRICS_AVERAGE_SOCKETPOWER:
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->SocketPower / 1000 << 8) +
- (metrics->SocketPower % 1000 / 10);
+ *value = metrics->SocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_2_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu14/smu_v14_0_2_ppt.c
@@ -695,7 +695,7 @@ static int smu_v14_0_2_get_smu_metrics_d
metrics->Vcn1ActivityPercentage);
break;
case METRICS_AVERAGE_SOCKETPOWER:
- *value = metrics->AverageSocketPower << 8;
+ *value = metrics->AverageSocketPower * MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->AvgTemperature[TEMP_EDGE] *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_0_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_0_ppt.c
@@ -383,8 +383,7 @@ static int smu_v15_0_0_get_smu_metrics_d
break;
case METRICS_AVERAGE_SOCKETPOWER:
case METRICS_CURR_SOCKETPOWER:
- *value = (metrics->SocketPower / 1000 << 8) +
- (metrics->SocketPower % 1000 / 10);
+ *value = metrics->SocketPower;
break;
case METRICS_TEMPERATURE_EDGE:
*value = metrics->GfxTemperature / 100 *
--- a/drivers/gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_8_ppt.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/smu15/smu_v15_0_8_ppt.c
@@ -402,7 +402,8 @@ static int smu_v15_0_8_get_smu_metrics_d
*value = SMUQ10_ROUND(metrics->DramBandwidthUtilization);
break;
case METRICS_CURR_SOCKETPOWER:
- *value = SMUQ10_ROUND(metrics->SocketPower) << 8;
+ *value = SMUQ10_ROUND(metrics->SocketPower) *
+ MILLIWATT_PER_WATT;
break;
case METRICS_TEMPERATURE_HOTSPOT:
*value = SMUQ10_ROUND(metrics->MaxSocketTemperature) *
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 397/438] drm/amd/display: check if dml21_add_phantom_plane() is successful
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (395 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 396/438] drm/amd/pm: use milliwatts for GPU power sensors Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 398/438] drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport Greg Kroah-Hartman
` (54 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dillon Varone, Fangzhi Zuo,
Dan Wheeler, Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Deucher <alexander.deucher@amd.com>
commit 000acb4ce7fb9feba3072ce468ad681f6585cd5d upstream.
Verify that the phantom plane was allocated to avoid a later
segfault.
Closes: https://gitlab.freedesktop.org/drm/amd/-/issues/4970
Fixes: 70839da63605 ("drm/amd/display: Add new DCN401 sources")
Reviewed-by: Dillon Varone <dillon.varone@amd.com>
Signed-off-by: Fangzhi Zuo <jerry.zuo@amd.com>
Tested-by: Dan Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 5adb54abe5a8e82cbff7f8806db30a5f4924329f)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/dml2_0/dml21/dml21_utils.c | 15 ++++++--------
1 file changed, 7 insertions(+), 8 deletions(-)
--- a/drivers/gpu/drm/amd/display/dc/dml2_0/dml21/dml21_utils.c
+++ b/drivers/gpu/drm/amd/display/dc/dml2_0/dml21/dml21_utils.c
@@ -359,14 +359,13 @@ void dml21_handle_phantom_streams_planes
main_plane = main_stream_status->plane_states[dc_plane_index];
/* create phantom planes for subvp enabled plane */
- dml21_add_phantom_plane(dml_ctx,
- dc,
- context,
- phantom_stream,
- main_plane,
- &dml_ctx->v21.mode_programming.programming->plane_programming[dml_plane_index]);
-
- phantoms_added = true;
+ if (dml21_add_phantom_plane(dml_ctx,
+ dc,
+ context,
+ phantom_stream,
+ main_plane,
+ &dml_ctx->v21.mode_programming.programming->plane_programming[dml_plane_index]))
+ phantoms_added = true;
}
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 398/438] drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (396 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 397/438] drm/amd/display: check if dml21_add_phantom_plane() is successful Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 399/438] drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames Greg Kroah-Hartman
` (53 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sun peng (Leo) Li, Dillon Varone,
George Zhang, Fangzhi Zuo, Dan Wheeler, Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: George Zhang <george.zhang@amd.com>
commit f327e389c07cfc3a2f6ff54f6214e1a52d457edc upstream.
If a plane reaches calculate_mcache_setting with a zero-area viewport,
calculate_mcache_setting exits early with num_mcaches == 0 and
mvmpg_width/height == 0. This will cause a divide-by-zero panic and can
also cause an underflow on num_mcaches.
Fix this by changing calculate_mcache_setting to bool and adding guards
after each calculate_mcache_row_bytes call. If num_mcaches or
mvmpg_width/height is zero, return a false. Callers will propagate the
failure as a rejected mode, which prevents the panic.
Closes: https://gitlab.freedesktop.org/drm/amd/-/issues/5302
Reviewed-by: Sun peng (Leo) Li <sunpeng.li@amd.com>
Reviewed-by: Dillon Varone <dillon.varone@amd.com>
Signed-off-by: George Zhang <george.zhang@amd.com>
Signed-off-by: Fangzhi Zuo <jerry.zuo@amd.com>
Tested-by: Dan Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 29c0f7c655f47bcbd575ff75e58480df6ec3c9da)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/dml2_0/dml21/src/dml2_core/dml2_core_dcn4_calcs.c | 31 ++++++++--
1 file changed, 25 insertions(+), 6 deletions(-)
--- a/drivers/gpu/drm/amd/display/dc/dml2_0/dml21/src/dml2_core/dml2_core_dcn4_calcs.c
+++ b/drivers/gpu/drm/amd/display/dc/dml2_0/dml21/src/dml2_core/dml2_core_dcn4_calcs.c
@@ -2425,7 +2425,7 @@ static void calculate_mcache_row_bytes(
DML_ASSERT(*p->num_mcaches > 0);
}
-static void calculate_mcache_setting(
+static bool calculate_mcache_setting(
struct dml2_core_internal_scratch *scratch,
struct dml2_core_calcs_calculate_mcache_setting_params *p)
{
@@ -2451,7 +2451,7 @@ static void calculate_mcache_setting(
*p->lc_comb_mcache = 0;
if (!p->dcc_enable)
- return;
+ return true;
l->is_dual_plane = dml_is_420(p->source_format) || p->source_format == dml2_rgbe_alpha;
@@ -2488,7 +2488,14 @@ static void calculate_mcache_setting(
l->l_p.mvmpg_per_mcache_lb = &l->mvmpg_per_mcache_lb_l;
calculate_mcache_row_bytes(scratch, &l->l_p);
- DML_ASSERT(*p->num_mcaches_l > 0);
+ if (*p->num_mcaches_l == 0 ||
+ (p->surf_vert ? l->mvmpg_height_l : l->mvmpg_width_l) == 0) {
+ DML_LOG_VERBOSE("DML::%s: degenerate luma viewport (num_mcaches_l=%u mvmpg_%s_l=%u) — mode not supported\n",
+ __func__, *p->num_mcaches_l,
+ p->surf_vert ? "height" : "width",
+ p->surf_vert ? l->mvmpg_height_l : l->mvmpg_width_l);
+ return false;
+ }
if (l->is_dual_plane) {
l->c_p.num_chans = p->num_chans;
@@ -2524,7 +2531,14 @@ static void calculate_mcache_setting(
l->c_p.mvmpg_per_mcache_lb = &l->mvmpg_per_mcache_lb_c;
calculate_mcache_row_bytes(scratch, &l->c_p);
- DML_ASSERT(*p->num_mcaches_c > 0);
+ if (*p->num_mcaches_c == 0 ||
+ (p->surf_vert ? l->mvmpg_height_c : l->mvmpg_width_c) == 0) {
+ DML_LOG_VERBOSE("DML::%s: degenerate chroma viewport (num_mcaches_c=%u mvmpg_%s_c=%u) — mode not supported\n",
+ __func__, *p->num_mcaches_c,
+ p->surf_vert ? "height" : "width",
+ p->surf_vert ? l->mvmpg_height_c : l->mvmpg_width_c);
+ return false;
+ }
}
// Sharing for iMALL access
@@ -2634,6 +2648,7 @@ static void calculate_mcache_setting(
*p->mcache_shift_granularity_l = l->mvmpg_access_width_l;
*p->mcache_shift_granularity_c = l->mvmpg_access_width_c;
+ return true;
}
static void calculate_mall_bw_overhead_factor(
@@ -9430,7 +9445,10 @@ static bool dml_core_mode_support(struct
calculate_mcache_setting_params->mall_comb_mcache_c = &mode_lib->ms.mall_comb_mcache_c[k];
calculate_mcache_setting_params->lc_comb_mcache = &mode_lib->ms.lc_comb_mcache[k];
- calculate_mcache_setting(&mode_lib->scratch, calculate_mcache_setting_params);
+ if (!calculate_mcache_setting(&mode_lib->scratch, calculate_mcache_setting_params)) {
+ mode_lib->ms.support.ModeSupport = false;
+ return false;
+ }
}
calculate_mall_bw_overhead_factor(
@@ -10906,7 +10924,8 @@ static bool dml_core_mode_programming(st
calculate_mcache_setting_params->mall_comb_mcache_l = &mode_lib->mp.mall_comb_mcache_l[k];
calculate_mcache_setting_params->mall_comb_mcache_c = &mode_lib->mp.mall_comb_mcache_c[k];
calculate_mcache_setting_params->lc_comb_mcache = &mode_lib->mp.lc_comb_mcache[k];
- calculate_mcache_setting(&mode_lib->scratch, calculate_mcache_setting_params);
+ if (!calculate_mcache_setting(&mode_lib->scratch, calculate_mcache_setting_params))
+ return false;
}
calculate_mall_bw_overhead_factor(
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 399/438] drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (397 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 398/438] drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 400/438] drm/amd/display: Silence link_dpms I2C retimer failures Greg Kroah-Hartman
` (52 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wayne Lin, Ray Wu, Dan Wheeler,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ray Wu <ray.wu@amd.com>
commit c216b39fbbc4b007fd6984cffd85039d49a55154 upstream.
Some HDMI sinks need additional GCP packets to properly process the
mute state before the timing generator is disabled, especially after
link re-establishment with HDMI 2.0 scrambling enabled. Waiting for
only 2 frames is insufficient for certain monitor firmware, resulting
in garbled display output on resume from suspend.
Increase the AV mute wait in dcn30_set_avmute() from 2 to 3 frames
to ensure the sink receives enough GCP packets.
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5167
Assisted-by: Cursor:Claude-Opus-4.6
Reviewed-by: Wayne Lin <wayne.lin@amd.com>
Signed-off-by: Ray Wu <ray.wu@amd.com>
Tested-by: Dan Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 0c0d5174b09640d8b560764aa5a177630e076e93)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
--- a/drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c
+++ b/drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c
@@ -841,13 +841,19 @@ void dcn30_set_avmute(struct pipe_ctx *p
pipe_ctx->stream_res.stream_enc,
enable);
- /* Wait for two frame to make sure AV mute is sent out */
+ /* Wait for three frames to make sure AV mute is sent out.
+ * Some HDMI sinks need additional GCP packets to properly
+ * process the mute state, especially after link re-establishment
+ * with HDMI 2.0 scrambling enabled.
+ */
if (enable && pipe_ctx->stream_res.tg->funcs->is_tg_enabled(pipe_ctx->stream_res.tg)) {
+ int i;
+
pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VACTIVE);
- pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VBLANK);
- pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VACTIVE);
- pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VBLANK);
- pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VACTIVE);
+ for (i = 0; i < 3; i++) {
+ pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VBLANK);
+ pipe_ctx->stream_res.tg->funcs->wait_for_state(pipe_ctx->stream_res.tg, CRTC_STATE_VACTIVE);
+ }
}
}
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 400/438] drm/amd/display: Silence link_dpms I2C retimer failures
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (398 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 399/438] drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 401/438] drm/amd/display: use proper context for logging Greg Kroah-Hartman
` (51 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alan Swanson, Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alan Swanson <reiver@improbability.net>
commit 8ccb87b1c9be594fc2c36b0a4006a66f08dee1c8 upstream.
Commit a4f01bf729b2 ("drm/amd/display: Refactor and fix link_dpms I2C")
had also changed the "Set retimer failed" messages from DC_LOG_DEBUG()
to DC_LOG_ERROR(). This unfortunately can create log spam.
Change those back to DC_LOG_DEBUG() only.
Fixes: a4f01bf729b2 ("drm/amd/display: Refactor and fix link_dpms I2C")
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5520
Signed-off-by: Alan Swanson <reiver@improbability.net>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit da8609eef18b0a3490d0e1fa9440659fadc8194d)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
--- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
@@ -379,7 +379,7 @@ static bool write_i2c_retimer_vga(
for (size_t i = 0; i < ARRAY_SIZE(vga_data); i++) {
if (!write_i2c_retimer_offset_value(link, address, vga_data[i][0], vga_data[i][1])) {
- DC_LOG_ERROR("Set retimer failed, vga index: %zu\n", i);
+ DC_LOG_DEBUG("Set retimer failed, vga index: %zu\n", i);
return false;
}
}
@@ -400,7 +400,7 @@ static bool write_i2c_retimer_byte(
return true;
if (!write_i2c_retimer_offset_value(link, address, index, value)) {
- DC_LOG_ERROR("Set retimer failed, 3g index: 0x%x, value: 0x%x\n", index, value);
+ DC_LOG_DEBUG("Set retimer failed, 3g index: 0x%x, value: 0x%x\n", index, value);
return false;
}
@@ -416,14 +416,14 @@ static bool write_i2c_retimer_byte(
if (!link_query_ddc_data(
link->ddc, address, &offset, 1, &value, 1
)) {
- DC_LOG_ERROR("Set retimer failed, link_query_ddc_data\n");
+ DC_LOG_DEBUG("Set retimer failed, link_query_ddc_data\n");
return false;
}
}
value |= apply_rx_tx_change;
if (!write_i2c_retimer_offset_value(link, address, offset, value)) {
- DC_LOG_ERROR("Set retimer failed, 3g offset: 0x%x, value: 0x%x\n", offset, value);
+ DC_LOG_DEBUG("Set retimer failed, 3g offset: 0x%x, value: 0x%x\n", offset, value);
return false;
}
}
@@ -444,7 +444,7 @@ static bool write_i2c_retimer_setting(
uint8_t value = settings->reg_settings[i].i2c_reg_val;
if (!write_i2c_retimer_byte(link, address, index, value)) {
- DC_LOG_ERROR("Set retimer failed, index: %zu\n", i);
+ DC_LOG_DEBUG("Set retimer failed, index: %zu\n", i);
return false;
}
}
@@ -455,7 +455,7 @@ static bool write_i2c_retimer_setting(
uint8_t value = settings->reg_settings_6g[i].i2c_reg_val;
if (!write_i2c_retimer_byte(link, address, index, value)) {
- DC_LOG_ERROR("Set retimer failed, 6g index: %zu\n", i);
+ DC_LOG_DEBUG("Set retimer failed, 6g index: %zu\n", i);
return false;
}
}
@@ -487,7 +487,7 @@ static bool write_i2c_default_retimer_se
for (size_t i = 0; i < ARRAY_SIZE(data); i++) {
if (!write_i2c_retimer_offset_value(link, address, data[i][0], data[i][1])) {
- DC_LOG_ERROR("Set default retimer failed, index: %zu\n", i);
+ DC_LOG_DEBUG("Set default retimer failed, index: %zu\n", i);
return false;
}
}
@@ -519,7 +519,7 @@ static bool write_i2c_redriver_setting(
);
if (!success)
- DC_LOG_ERROR("Set redriver failed");
+ DC_LOG_DEBUG("Set redriver failed");
return success;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 401/438] drm/amd/display: use proper context for logging
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (399 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 400/438] drm/amd/display: Silence link_dpms I2C retimer failures Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 402/438] drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE Greg Kroah-Hartman
` (50 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bhawanpreet Lakha, Jiri Slaby (SUSE),
Lakha, Bhawanpreet, Harry Wentland, Leo Li, Rodrigo Siqueira,
Alex Deucher, Christian König, David Airlie, Simona Vetter,
amd-gfx
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Slaby (SUSE) <jirislaby@kernel.org>
commit 114b42507b6a23d9d24e24e4ef165233332c64d4 upstream.
The same as the rest of the code, get_ss_info_from_atombios() uses
calc_pll_cs->ctx->logger for logging. But calc_pll_cs->ctx is
initialized only later in calc_pll_max_vco_construct(). Therefore, any
output using DC_LOG_SYNC() leads to a NULL pointer deference in
get_ss_info_from_atombios().
According to Sashiko, the very same problem exists in
dce112_get_pix_clk_dividers() and dcn3_get_pix_clk_dividers() too.
To avoid accessing the NULL context, use clk_src->base.ctx->logger
everywhere. That context in base is initialized earlier in
dce110_clk_src_construct() and dce112_clk_src_construct(). Before
get_ss_info_from_atombios() or Sashiko's get_pix_clk_dividers functions
above are actually called. This is done by redefining DC_LOGGER to
CTX->logger.
Before:
dce110_clk_src_construct() did:
-> sets clk_src->base.ctx = ctx;
-> ss_info_from_atombios_create()
-> get_ss_info_from_atombios() <- uses calc_pll_cs->ctx # BOOM
-> calc_pll_max_vco_construct() <- sets calc_pll_cs->ctx
After:
dce110_clk_src_construct() does:
-> sets clk_src->base.ctx = ctx;
-> ss_info_from_atombios_create()
-> get_ss_info_from_atombios() <- uses clk_src->base.ctx
Closes: https://bugzilla.suse.com/show_bug.cgi?id=1271175
Closes: https://lore.kernel.org/all/a9ee54e6-2413-4156-9bde-d528ae3c63a3@kernel.org/
Fixes: 1296423bf23c ("drm/amd/display: define DC_LOGGER for logger")
Reviewed-by: Bhawanpreet Lakha <bhawanpreet.lakha@amd.com>
Signed-off-by: Jiri Slaby (SUSE) <jirislaby@kernel.org>
Cc: Lakha, Bhawanpreet <Bhawanpreet.Lakha@amd.com>
Cc: Harry Wentland <harry.wentland@amd.com>
Cc: Leo Li <sunpeng.li@amd.com>
Cc: Rodrigo Siqueira <siqueira@igalia.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Cc: "Christian König" <christian.koenig@amd.com>
Cc: David Airlie <airlied@gmail.com>
Cc: Simona Vetter <simona@ffwll.ch>
Cc: amd-gfx@lists.freedesktop.org
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 6f16fcbb0c46a87e3d9685407e906573d60104b0)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c | 20 ++++++++----------
1 file changed, 9 insertions(+), 11 deletions(-)
--- a/drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c
+++ b/drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c
@@ -45,9 +45,7 @@
clk_src->base.ctx
#define DC_LOGGER \
- calc_pll_cs->ctx->logger
-#define DC_LOGGER_INIT() \
- struct calc_pll_clock_source *calc_pll_cs = &clk_src->calc_pll
+ CTX->logger
#undef FN
#define FN(reg_name, field_name) \
@@ -289,6 +287,7 @@ static bool calc_pll_dividers_in_range(
}
static uint32_t calculate_pixel_clock_pll_dividers(
+ struct dce110_clk_src *clk_src,
struct calc_pll_clock_source *calc_pll_cs,
struct pll_settings *pll_settings)
{
@@ -477,7 +476,7 @@ static uint32_t dce110_get_pix_clk_divid
{
uint32_t field = 0;
uint32_t pll_calc_error = MAX_PLL_CALC_ERROR;
- DC_LOGGER_INIT();
+
/* Check if reference clock is external (not pcie/xtalin)
* HW Dce80 spec:
* 00 - PCIE_REFCLK, 01 - XTALIN, 02 - GENERICA, 03 - GENERICB
@@ -520,12 +519,14 @@ static uint32_t dce110_get_pix_clk_divid
/*Calculate Dividers by HDMI object, no SS case or SS case */
pll_calc_error =
calculate_pixel_clock_pll_dividers(
+ clk_src,
&clk_src->calc_pll_hdmi,
pll_settings);
else
/*Calculate Dividers by default object, no SS case or SS case */
pll_calc_error =
calculate_pixel_clock_pll_dividers(
+ clk_src,
&clk_src->calc_pll,
pll_settings);
@@ -571,7 +572,6 @@ static uint32_t dce110_get_pix_clk_divid
{
struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs);
uint32_t pll_calc_error = MAX_PLL_CALC_ERROR;
- DC_LOGGER_INIT();
if (pix_clk_params == NULL || pll_settings == NULL
|| pix_clk_params->requested_pix_clk_100hz == 0) {
@@ -603,7 +603,6 @@ static uint32_t dce112_get_pix_clk_divid
struct pll_settings *pll_settings)
{
struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs);
- DC_LOGGER_INIT();
if (pix_clk_params == NULL || pll_settings == NULL
|| pix_clk_params->requested_pix_clk_100hz == 0) {
@@ -1372,8 +1371,6 @@ static uint32_t dcn3_get_pix_clk_divider
unsigned long long actual_pix_clk_100Hz = pix_clk_params ? pix_clk_params->requested_pix_clk_100hz : 0;
struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs);
- DC_LOGGER_INIT();
-
if (pix_clk_params == NULL || pll_settings == NULL
|| pix_clk_params->requested_pix_clk_100hz == 0) {
DC_LOG_ERROR(
@@ -1443,7 +1440,6 @@ static const struct clock_source_funcs d
.get_pixel_clk_frequency_100hz = get_pixel_clk_frequency_100hz
};
-
static void get_ss_info_from_atombios(
struct dce110_clk_src *clk_src,
enum as_signal_type as_signal,
@@ -1456,7 +1452,7 @@ static void get_ss_info_from_atombios(
struct spread_spectrum_info *ss_info_cur;
struct spread_spectrum_data *ss_data_cur;
uint32_t i;
- DC_LOGGER_INIT();
+
if (ss_entries_num == NULL) {
DC_LOG_SYNC(
"Invalid entry !!!\n");
@@ -1587,6 +1583,7 @@ static void ss_info_from_atombios_create
}
static bool calc_pll_max_vco_construct(
+ struct dce110_clk_src *clk_src,
struct calc_pll_clock_source *calc_pll_cs,
struct calc_pll_clock_source_init_data *init_data)
{
@@ -1738,6 +1735,7 @@ bool dce110_clk_src_construct(
ss_info_from_atombios_create(clk_src);
if (!calc_pll_max_vco_construct(
+ clk_src,
&clk_src->calc_pll,
&calc_pll_cs_init_data)) {
ASSERT_CRITICAL(false);
@@ -1752,7 +1750,7 @@ bool dce110_clk_src_construct(
if (!calc_pll_max_vco_construct(
- &clk_src->calc_pll_hdmi, &calc_pll_cs_init_data_hdmi)) {
+ clk_src, &clk_src->calc_pll_hdmi, &calc_pll_cs_init_data_hdmi)) {
ASSERT_CRITICAL(false);
goto unexpected_failure;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 402/438] drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (400 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 401/438] drm/amd/display: use proper context for logging Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 403/438] drm/amdkfd: fix QID bit leak in pqm_create_queue() Greg Kroah-Hartman
` (49 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gang Ba, Kent Russell, Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gang Ba <Gang.Ba@amd.com>
commit 99b2fe4f19e3be0a8d0a0b5ea98d855970889653 upstream.
Prevent unauthorized termination of active GPU debug sessions.
Previously, users with /dev/kfd access could terminate another process's
debug session without proper ownership or ptrace authorization.
Signed-off-by: Gang Ba <Gang.Ba@amd.com>
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
@@ -3038,10 +3038,14 @@ static int kfd_ioctl_set_debug_trap(stru
goto out;
}
- /* Check if target is still PTRACED. */
+ /*
+ * Verify debugger has permission to debug target process.
+ * For cross-process debugging, require active ptrace relationship.
+ * This applies to ALL operations to prevent unauthorized interference.
+ */
rcu_read_lock();
- if (target != p && args->op != KFD_IOC_DBG_TRAP_DISABLE
- && ptrace_parent(target->lead_thread) != current) {
+ if (target != p && ptrace_parent(target->lead_thread) != current
+ && target->debugger_process != p) {
pr_err("PID %i is not PTRACED and cannot be debugged\n", args->pid);
r = -EPERM;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 403/438] drm/amdkfd: fix QID bit leak in pqm_create_queue()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (401 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 402/438] drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE Greg Kroah-Hartman
@ 2026-08-07 14:39 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 404/438] drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment Greg Kroah-Hartman
` (48 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Deucher, Alexander,
Vladimir Marioukhine, Kent Russell
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
commit 38b73293f38658a4685ffcea666462024f858ad9 upstream.
When MES is enabled and amdgpu_amdkfd_alloc_kernel_mem() fails during
the first queue creation for a process, pqm_create_queue() returns
early via 'return retval' without going through the err_create_queue
cleanup label.
This means clear_bit(*qid, pqm->queue_slot_bitmap) is never called,
leaving the reserved QID bit permanently set in queue_slot_bitmap.
Over time this leaks QID slots, potentially exhausting all available
queue slots.
Fix this by replacing 'return retval' with 'goto err_allocate_pqn'
so that clear_bit() is always called on the error path without
touching the uninitialized pqn pointer.
AILIKFD-813
Reported-by: Deucher, Alexander <alexander.deucher@amd.com>
Signed-off-by: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit a107f74c38edbb80d6ab64dcaeeb292c14e9779f)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c
@@ -378,7 +378,7 @@ int pqm_create_queue(struct process_queu
false);
if (retval) {
dev_err(dev->adev->dev, "failed to allocate process context bo\n");
- return retval;
+ goto err_allocate_pqn;
}
memset(pdd->proc_ctx_cpu_ptr, 0, AMDGPU_MES_PROC_CTX_SIZE);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 404/438] drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (402 preceding siblings ...)
2026-08-07 14:39 ` [PATCH 7.1 403/438] drm/amdkfd: fix QID bit leak in pqm_create_queue() Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 405/438] drm/amdkfd: Handle invalid event type in CRIU event restore Greg Kroah-Hartman
` (47 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Palacek, Alysa Liu,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: William Palacek <William.Palacek@amd.com>
commit 83463a96ea3c7d8ae636a4d6a0ba63c9ce410724 upstream.
eop_ring_buffer_size in struct queue_properties is a u32. In
kfd_queue_acquire_buffers() the expected EOP buffer size is computed as
ALIGN(eop_ring_buffer_size, PAGE_SIZE); ALIGN uses typeof(x), so the
addition is done in 32-bit. A user-supplied size of 0xFFFFF001 wraps to
0, causing kfd_queue_buffer_get() to skip its exact-size check (gated on
size != 0) and accept any BO mapped at the address. On GFX8/GFX9 the MQD
cp_hqd_eop_control is then programmed for an 8KB EOP ring backed by a 4KB
BO, so CP EOP writes can land past the buffer and fault the GPU.
Cast the operand to u64 so the alignment is computed in 64-bit; the size
check in kfd_queue_buffer_get() then rejects the oversized request.
Fixes: 42ea9cf2f16b ("drm/amdkfd: Relax size checking during queue buffer get")
Signed-off-by: William Palacek <William.Palacek@amd.com>
Reviewed-by: Alysa Liu <Alysa.Liu@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit ae443117b742c357bfef3a7bddabf76fcf86e9ef)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_queue.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_queue.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_queue.c
@@ -288,7 +288,7 @@ int kfd_queue_acquire_buffers(struct kfd
}
err = kfd_queue_buffer_get(vm, (void *)properties->eop_ring_buffer_address,
&properties->eop_buf_bo,
- ALIGN(properties->eop_ring_buffer_size, PAGE_SIZE));
+ ALIGN((u64)properties->eop_ring_buffer_size, PAGE_SIZE));
if (err)
goto out_err_unreserve;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 405/438] drm/amdkfd: Handle invalid event type in CRIU event restore
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (403 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 404/438] drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 406/438] drm/amdkfd: hold event_mutex while checkpointing CRIU events Greg Kroah-Hartman
` (46 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Francis, Kent Russell,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Francis <David.Francis@amd.com>
commit a9cdc85839e4fe2c760aa4ca6cc341c31ad1918a upstream.
In kfd_criu_restore_event, there was no handling for
the event priv data having an invalid event type. The priv
data here is untrusted and can be invalid.
In that case, fail with EINVAL.
Signed-off-by: David Francis <David.Francis@amd.com>
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 2e8e9963cd5c41aa14fd5316bf9ec92e7a0e3097)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_events.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
@@ -524,6 +524,9 @@ int kfd_criu_restore_event(struct file *
ret = create_other_event(p, ev, &ev_priv->event_id);
break;
+ default:
+ ret = -EINVAL;
+ break;
}
mutex_unlock(&p->event_mutex);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 406/438] drm/amdkfd: hold event_mutex while checkpointing CRIU events
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (404 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 405/438] drm/amdkfd: Handle invalid event type in CRIU event restore Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 407/438] drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size Greg Kroah-Hartman
` (45 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Palacek, Alysa Liu,
Alex Deucher
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: William Palacek <William.Palacek@amd.com>
commit ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2 upstream.
kfd_criu_checkpoint_events() counts the entries in p->event_idr via
kfd_get_num_events(), allocates an array sized to that count, and then
walks the same IDR to fill it. Neither the count nor the walk holds
p->event_mutex.
The CRIU checkpoint caller holds only p->mutex. Event create and destroy
(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not
take p->mutex, so a second thread in the same process can insert or remove
events between the count and the walk. If an event is inserted, the walk
iterates more entries than were counted and writes past the end of the
ev_privs allocation; if an event is removed, the walk dereferences an
entry that is being freed.
Hold p->event_mutex across the count and the walk so both observe a
consistent view of p->event_idr. The lock is released before
copy_to_user(), which only touches the local buffer. The caller already
holds p->mutex and the create/destroy paths never take p->mutex, so the
p->mutex -> p->event_mutex order is not inverted and no deadlock is
introduced.
Fixes: 40e8a766a761 ("drm/amdkfd: CRIU checkpoint and restore events")
Signed-off-by: William Palacek <William.Palacek@amd.com>
Reviewed-by: Alysa Liu <Alysa.Liu@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_events.c | 22 ++++++++++++++++++----
1 file changed, 18 insertions(+), 4 deletions(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
@@ -548,15 +548,27 @@ int kfd_criu_checkpoint_events(struct kf
int ret = 0;
struct kfd_event *ev;
uint32_t ev_id;
+ uint32_t num_events;
- uint32_t num_events = kfd_get_num_events(p);
-
- if (!num_events)
+ /* Serialize the count and the walk below against concurrent event
+ * create/destroy. Those paths take only p->event_mutex, not the
+ * p->mutex held by the CRIU checkpoint caller, so without this the
+ * event_idr can grow between kfd_get_num_events() and the loop and the
+ * walk writes past the ev_privs allocation.
+ */
+ mutex_lock(&p->event_mutex);
+
+ num_events = kfd_get_num_events(p);
+ if (!num_events) {
+ mutex_unlock(&p->event_mutex);
return 0;
+ }
ev_privs = kvzalloc(num_events * sizeof(*ev_privs), GFP_KERNEL);
- if (!ev_privs)
+ if (!ev_privs) {
+ mutex_unlock(&p->event_mutex);
return -ENOMEM;
+ }
idr_for_each_entry(&p->event_idr, ev, ev_id) {
@@ -597,6 +609,8 @@ int kfd_criu_checkpoint_events(struct kf
i++;
}
+ mutex_unlock(&p->event_mutex);
+
ret = copy_to_user(user_priv_data + *priv_data_offset,
ev_privs, num_events * sizeof(*ev_privs));
if (ret) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 407/438] drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (405 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 406/438] drm/amdkfd: hold event_mutex while checkpointing CRIU events Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 408/438] drm/vmwgfx: reject DX_BIND_QUERY without a DX context Greg Kroah-Hartman
` (44 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 83195b778f2d109a3a4f3ffaba4dce7e4cdb58aa upstream.
Two sites in vmwgfx_resource.c assign boolean literals to
res->guest_memory_size, which is an unsigned long allocation-size
field; the intended target is the adjacent res->guest_memory_dirty
bitfield. After the assignments the field holds 0 or 1 instead of
the resource's MOB allocation size:
- vmw_resource_release() writes 0 (false), and
- vmw_resource_unbind_list() writes 1 (true).
Subsequent revalidation paths read guest_memory_size when computing
the dirty page range (vmw_bo_dirty_transfer_to_res()) and the buffer
allocation size (vmw_resource_buf_alloc()), producing zero-length
walks or wrap-around ranges that read or write past the MOB bitmap.
The dirty-tracking intent of the original code (mark the resource as
dirtied since the last sync) is also lost, since guest_memory_dirty
is never updated.
Rename both assignments to guest_memory_dirty.
Fixes: 668b206601c5 ("drm/vmwgfx: Stop using raw ttm_buffer_object's")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-2-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_resource.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_resource.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_resource.c
@@ -136,7 +136,7 @@ static void vmw_resource_release(struct
val_buf.num_shared = 0;
res->func->unbind(res, false, &val_buf);
}
- res->guest_memory_size = false;
+ res->guest_memory_dirty = false;
vmw_resource_mob_detach(res);
if (res->dirty)
res->func->dirty_free(res);
@@ -773,7 +773,7 @@ void vmw_resource_unbind_list(struct vmw
if (!WARN_ON_ONCE(!res->func->unbind))
(void) res->func->unbind(res, res->res_dirty, &val_buf);
- res->guest_memory_size = true;
+ res->guest_memory_dirty = true;
res->res_dirty = false;
vmw_resource_mob_detach(res);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 408/438] drm/vmwgfx: reject DX_BIND_QUERY without a DX context
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (406 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 407/438] drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 409/438] drm/vmwgfx: clamp dirty-page range with min, not max Greg Kroah-Hartman
` (43 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db upstream.
vmw_cmd_dx_bind_query() unconditionally dereferences
sw_context->dx_ctx_node->ctx. Userspace can trigger a NULL pointer
dereference from any render-node fd by submitting an execbuf with
dx_context_handle == SVGA3D_INVALID_ID and a SVGA_3D_CMD_DX_BIND_QUERY
opcode in the command stream: dx_ctx_node is left NULL and the kernel
oopses on the assignment. The same NULL is then re-read in
vmw_resources_reserve() via vmw_context_get_dx_query_mob().
All sibling DX handlers fail-close on a missing dx_ctx_node using
VMW_GET_CTX_NODE(). Use the same pattern here, returning -EINVAL up
front before any relocation state is published.
Fixes: 9c079b8ce8bf ("drm/vmwgfx: Adapt execbuf to the new validation api")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-3-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
@@ -1272,9 +1272,13 @@ static int vmw_cmd_dx_bind_query(struct
SVGA3dCmdHeader *header)
{
VMW_DECLARE_CMD_VAR(*cmd, SVGA3dCmdDXBindQuery);
+ struct vmw_ctx_validation_info *ctx_node = VMW_GET_CTX_NODE(sw_context);
struct vmw_bo *vmw_bo;
int ret;
+ if (!ctx_node)
+ return -EINVAL;
+
cmd = container_of(header, typeof(*cmd), header);
/*
@@ -1288,7 +1292,7 @@ static int vmw_cmd_dx_bind_query(struct
return ret;
sw_context->dx_query_mob = vmw_bo;
- sw_context->dx_query_ctx = sw_context->dx_ctx_node->ctx;
+ sw_context->dx_query_ctx = ctx_node->ctx;
return 0;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 409/438] drm/vmwgfx: clamp dirty-page range with min, not max
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (407 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 408/438] drm/vmwgfx: reject DX_BIND_QUERY without a DX context Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 410/438] drm/vmwgfx: take fman->lock around fence list mutation in fifo_down Greg Kroah-Hartman
` (42 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit f47d542d5912f236273399d7139b522f6950e2e4 upstream.
vmw_bo_dirty_transfer_to_res() and vmw_bo_dirty_clear() compute the
intersection of a resource's page range with the BO's tracked dirty
range, but clamp res_end against dirty->end with max() instead of
min(). When dirty->end exceeds the resource end, the loop walks past
the resource's pages, calls vmw_resource_dirty_update() for ranges
owned by other resources sharing the same backing MOB and clears
their pending dirty bits via bitmap_clear(). The result is silent
loss of writeback for unrelated resources whenever two resources
share a MOB.
Use min() in both functions so the loop is bounded to the
intersection of the resource and dirty ranges.
Fixes: b7468b15d271 ("drm/vmwgfx: Implement an infrastructure for write-coherent resources")
Fixes: 965544150d1c ("drm/vmwgfx: Refactor cursor handling")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-4-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_page_dirty.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_page_dirty.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_page_dirty.c
@@ -311,7 +311,7 @@ void vmw_bo_dirty_transfer_to_res(struct
return;
cur = max(res_start, dirty->start);
- res_end = max(res_end, dirty->end);
+ res_end = min(res_end, dirty->end);
while (cur < res_end) {
unsigned long num;
@@ -347,7 +347,7 @@ void vmw_bo_dirty_clear(struct vmw_bo *v
return;
cur = max(res_start, dirty->start);
- res_end = max(res_end, dirty->end);
+ res_end = min(res_end, dirty->end);
while (cur < res_end) {
unsigned long num;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 410/438] drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (408 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 409/438] drm/vmwgfx: clamp dirty-page range with min, not max Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 411/438] drm/vmwgfx: drop dma_buf reference on foreign-fd prime import Greg Kroah-Hartman
` (41 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 250af2e8c3e90dc978e062a936b633870a22e660 upstream.
vmw_fence_fifo_down() drops fman->lock to wait on a fence and, on
timeout, mutates fman->fence_list via list_del_init() and signals
the fence without re-acquiring the lock. __vmw_fences_update() walks
and removes entries from the same list under fman->lock from any
other waiter, the fence-IRQ thread, or vmw_fences_update(), so the
unlocked list_del_init() can corrupt the list head.
Re-take fman->lock before manipulating fence->head and use
dma_fence_signal_locked(). Wrap the locked signalling in
dma_fence_begin_signalling() / dma_fence_end_signalling() so the
lockdep annotation that dma_fence_signal() previously provided is
preserved (the same pattern as __vmw_fences_update()).
dma_fence_put() is moved outside the lock to avoid a recursive
acquire from vmw_fence_obj_destroy(), which also takes fman->lock.
Fixes: ae2a104058e2 ("vmwgfx: Implement fence objects")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-5-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_fence.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_fence.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_fence.c
@@ -367,13 +367,24 @@ void vmw_fence_fifo_down(struct vmw_fenc
ret = vmw_fence_obj_wait(fence, false, false,
VMW_FENCE_WAIT_TIMEOUT);
+ spin_lock(&fman->lock);
if (unlikely(ret != 0)) {
+ bool cookie = dma_fence_begin_signalling();
+
list_del_init(&fence->head);
- dma_fence_signal(&fence->base);
+ if (fence->waiter_added) {
+ vmw_seqno_waiter_remove(fman->dev_priv);
+ fence->waiter_added = false;
+ }
+ dma_fence_signal_locked(&fence->base);
+ dma_fence_end_signalling(cookie);
}
BUG_ON(!list_empty(&fence->head));
+ spin_unlock(&fman->lock);
+
dma_fence_put(&fence->base);
+
spin_lock(&fman->lock);
}
spin_unlock(&fman->lock);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 411/438] drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (409 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 410/438] drm/vmwgfx: take fman->lock around fence list mutation in fifo_down Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 412/438] drm/vmwgfx: validate DRAW_PRIMITIVES header size before division Greg Kroah-Hartman
` (40 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit f739416dc555fa205a785e5135d73fa39b26f35d upstream.
ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's
dma_buf->ops do not match the ttm_object_device's ops, but does so
without releasing the reference acquired by dma_buf_get(). Any
unprivileged renderD client passing a non-vmwgfx prime fd through the
DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per
call and indefinitely pins the foreign exporter's GEM resources.
Funnel the error path through the existing dma_buf_put() so the
reference is always dropped.
Fixes: 65981f7681ab ("drm/ttm: Add a minimal prime implementation for ttm base objects")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-6-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/ttm_object.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/ttm_object.c
+++ b/drivers/gpu/drm/vmwgfx/ttm_object.c
@@ -547,14 +547,17 @@ int ttm_prime_fd_to_handle(struct ttm_ob
if (IS_ERR(dma_buf))
return PTR_ERR(dma_buf);
- if (dma_buf->ops != &tdev->ops)
- return -ENOSYS;
+ if (dma_buf->ops != &tdev->ops) {
+ ret = -ENOSYS;
+ goto out;
+ }
prime = (struct ttm_prime_object *) dma_buf->priv;
base = &prime->base;
*handle = base->handle;
ret = ttm_ref_object_add(tfile, base, NULL, false);
+out:
dma_buf_put(dma_buf);
return ret;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 412/438] drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (410 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 411/438] drm/vmwgfx: drop dma_buf reference on foreign-fd prime import Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 413/438] drm/vmwgfx: bound DMA command body size against suffix pointer Greg Kroah-Hartman
` (39 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 85891d174707d8bddcec7a888fb4e1d17def34f3 upstream.
vmw_cmd_draw() computes
maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);
where header->size is u32 and is taken straight from the user-supplied
command stream. When header->size is less than sizeof(cmd->body) the
unsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum.
Any user-controlled cmd->body.numVertexDecls then passes the bound and
the loop dereferences decl[i] far past the end of the kernel command
bounce buffer, producing an out-of-bounds read of kernel memory.
Reject undersized headers up front.
Fixes: 7a73ba7469cb ("drm/vmwgfx: Use TTM handles instead of SIDs as user-space surface handles.")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-7-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
@@ -1571,11 +1571,17 @@ static int vmw_cmd_draw(struct vmw_priva
uint32_t maxnum;
int ret;
+ cmd = container_of(header, typeof(*cmd), header);
+
+ if (unlikely(header->size < sizeof(cmd->body))) {
+ VMW_DEBUG_USER("Illegal DRAW_PRIMITIVES header size.\n");
+ return -EINVAL;
+ }
+
ret = vmw_cmd_cid_check(dev_priv, sw_context, header);
if (unlikely(ret != 0))
return ret;
- cmd = container_of(header, typeof(*cmd), header);
maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);
if (unlikely(cmd->body.numVertexDecls > maxnum)) {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 413/438] drm/vmwgfx: bound DMA command body size against suffix pointer
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (411 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 412/438] drm/vmwgfx: validate DRAW_PRIMITIVES header size before division Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 414/438] drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure Greg Kroah-Hartman
` (38 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit f4f1db96bfd68b81053693ba53405b6f510ac16c upstream.
vmw_cmd_dma() locates the DMA suffix at
(unsigned long) &cmd->body + header->size - sizeof(*suffix)
without checking that header->size is large enough to contain both
cmd->body and the suffix. An undersized header makes the suffix
pointer underflow back into the previous command in the bounce
buffer. The verifier later writes suffix->maximumOffset, clobbering
verified fields of an already-relocated earlier command -- a TOCTOU
on the device-visible command stream that lets one command rewrite
another's GMR id, surface id, or other authenticated fields.
Reject the command if the body is too small for the suffix to fit.
Fixes: 4e4ddd477743 ("drm/vmwgfx: Fix queries if no dma buffer thrashing is occuring.")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-8-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
@@ -1510,6 +1510,12 @@ static int vmw_cmd_dma(struct vmw_privat
bool dirty;
cmd = container_of(header, typeof(*cmd), header);
+
+ if (unlikely(header->size < sizeof(cmd->body) + sizeof(*suffix))) {
+ VMW_DEBUG_USER("Illegal SVGA_3D_CMD_SURFACE_DMA size.\n");
+ return -EINVAL;
+ }
+
suffix = (SVGA3dCmdSurfaceDMASuffix *)((unsigned long) &cmd->body +
header->size - sizeof(*suffix));
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 414/438] drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (412 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 413/438] drm/vmwgfx: bound DMA command body size against suffix pointer Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 415/438] drm/vmwgfx: enforce cursor size limits for MOB cursors Greg Kroah-Hartman
` (37 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 05eaa887e7b4f40fba425f8a1d7a5a8a043092a6 upstream.
Two paths through vmw_vkms_init() can leave vmw->crc_workq NULL while
still leaving the rest of the driver in a state that calls
vmw_vkms_cleanup() at module unload:
1. vmw_host_get_guestinfo(GUESTINFO_VBLANK, ...) failing or
returning an oversized buffer -- the common case on hosts
without a VBLANK guestinfo entry -- early-returned before the
workqueue allocation.
2. alloc_ordered_workqueue() returning NULL on memory pressure.
vmw_vkms_cleanup() then calls destroy_workqueue(NULL), which
dereferences wq->name and panics.
Fix the first case by removing the early return: vmw->vkms_enabled
is already false on the rpci-failure path so no work will ever be
queued, and allocating the workqueue unconditionally keeps the
control flow simple. Fix the second case by guarding the cleanup
with a NULL check, since alloc_ordered_workqueue() can still fail
under low memory.
Fixes: 7b0062036c3b ("drm/vmwgfx: Implement virtual crc generation")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-9-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_vkms.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_vkms.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_vkms.c
@@ -214,14 +214,14 @@ vmw_vkms_init(struct vmw_private *vmw)
vmw->vkms_enabled = false;
ret = vmw_host_get_guestinfo(GUESTINFO_VBLANK, buffer, &buf_len);
- if (ret || buf_len > max_buf_len)
- return;
- buffer[buf_len] = '\0';
+ if (!ret && buf_len <= max_buf_len) {
+ buffer[buf_len] = '\0';
- ret = kstrtobool(buffer, &vmw->vkms_enabled);
- if (!ret && vmw->vkms_enabled) {
- ret = drm_vblank_init(&vmw->drm, VMWGFX_NUM_DISPLAY_UNITS);
- vmw->vkms_enabled = (ret == 0);
+ ret = kstrtobool(buffer, &vmw->vkms_enabled);
+ if (!ret && vmw->vkms_enabled) {
+ ret = drm_vblank_init(&vmw->drm, VMWGFX_NUM_DISPLAY_UNITS);
+ vmw->vkms_enabled = (ret == 0);
+ }
}
vmw->crc_workq = alloc_ordered_workqueue("vmwgfx_crc_generator", 0);
@@ -236,7 +236,8 @@ vmw_vkms_init(struct vmw_private *vmw)
void
vmw_vkms_cleanup(struct vmw_private *vmw)
{
- destroy_workqueue(vmw->crc_workq);
+ if (vmw->crc_workq)
+ destroy_workqueue(vmw->crc_workq);
}
bool
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 415/438] drm/vmwgfx: enforce cursor size limits for MOB cursors
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (413 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 414/438] drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 416/438] drm/vmwgfx: use check_add_overflow for shader size+offset bound Greg Kroah-Hartman
` (36 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit d5ed8749168ad13c0dbaa8300f68d854b6076966 upstream.
vmw_cursor_plane_atomic_check() bounds cursor width and height only
on the legacy update path; the SVGA_CAP2_CURSOR_MOB path -- the
default on modern hosts -- accepts any size. When the requested size
exceeds SVGA_REG_CURSOR_MAX_DIMENSION or SVGA_REG_MOB_MAX_SIZE,
vmw_cursor_mob_get() returns -EINVAL and leaves vps->cursor.mob NULL.
Its return value is then discarded in vmw_cursor_plane_prepare_fb(),
so the subsequent vmw_cursor_update_mob() calls
vmw_bo_map_and_cache(NULL) and oopses inside
vmw_bo_map_and_cache_size() on the tbo.base.size load.
Reachable from any DRM master via DRM_IOCTL_MODE_CURSOR2 with a
sufficiently large width or height (e.g. cursor_max_dim + 1).
Reject oversized cursors in atomic_check for both MOB-backed cursor
update types. The MOB byte-size limit only applies to the
SVGA_CAP2_CURSOR_MOB path (vmw_cursor_mob_size() returns 0 for
GB_ONLY); compute the required MOB size in 64-bit to avoid overflow
when very large dimensions are requested.
In prepare_fb only call vmw_cursor_mob_get()/_map() for
VMW_CURSOR_UPDATE_MOB -- the GB_ONLY path uses bo->map.virtual
directly and would otherwise be silently downgraded to NONE on hosts
without SVGA_CAP2_CURSOR_MOB (where vmw_cursor_mob_get() always
returns -EINVAL). Degrade the update to NONE if vmw_cursor_mob_get()
or vmw_cursor_mob_map() fails so the update path does not run with a
NULL backing MOB.
Fixes: 965544150d1c ("drm/vmwgfx: Refactor cursor handling")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-10-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c | 49 ++++++++++++++++++++++++---
1 file changed, 44 insertions(+), 5 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c
@@ -432,6 +432,7 @@ vmw_cursor_mob_map(struct vmw_plane_stat
u32 size = vmw_cursor_mob_size(vps->cursor.update_type,
vps->base.crtc_w, vps->base.crtc_h);
struct vmw_bo *vbo = vps->cursor.mob;
+ void *map;
if (!vbo)
return -EINVAL;
@@ -446,11 +447,15 @@ vmw_cursor_mob_map(struct vmw_plane_stat
if (unlikely(ret != 0))
return -ENOMEM;
- vmw_bo_map_and_cache(vbo);
+ map = vmw_bo_map_and_cache(vbo);
+ if (!map) {
+ vmw_bo_unmap(vbo);
+ ret = -ENOMEM;
+ }
ttm_bo_unreserve(&vbo->tbo);
- return 0;
+ return ret;
}
/**
@@ -663,9 +668,15 @@ int vmw_cursor_plane_prepare_fb(struct d
!vmw_cursor_buffer_changed(vps, old_vps)) {
vps->cursor.update_type =
VMW_CURSOR_UPDATE_NONE;
- } else {
- vmw_cursor_mob_get(vcp, vps);
- vmw_cursor_mob_map(vps);
+ } else if (vps->cursor.update_type ==
+ VMW_CURSOR_UPDATE_MOB &&
+ (vmw_cursor_mob_get(vcp, vps) ||
+ vmw_cursor_mob_map(vps))) {
+ /*
+ * Reset the cursor to avoid crashes later.
+ */
+ vps->cursor.update_type =
+ VMW_CURSOR_UPDATE_NONE;
}
}
}
@@ -732,6 +743,34 @@ int vmw_cursor_plane_atomic_check(struct
"surface not suitable for cursor\n");
return -EINVAL;
}
+ } else if (update_type == VMW_CURSOR_UPDATE_GB_ONLY ||
+ update_type == VMW_CURSOR_UPDATE_MOB) {
+ u32 cursor_max_dim =
+ vmw_read(vmw, SVGA_REG_CURSOR_MAX_DIMENSION);
+
+ if (new_state->crtc_w > cursor_max_dim ||
+ new_state->crtc_h > cursor_max_dim) {
+ drm_warn(&vmw->drm,
+ "Cursor dimensions (%d, %d) exceed device max %u\n",
+ new_state->crtc_w, new_state->crtc_h,
+ cursor_max_dim);
+ return -EINVAL;
+ }
+
+ if (update_type == VMW_CURSOR_UPDATE_MOB) {
+ u32 mob_max_size =
+ vmw_read(vmw, SVGA_REG_MOB_MAX_SIZE);
+ u64 mob_size = (u64)new_state->crtc_w *
+ new_state->crtc_h * sizeof(u32) +
+ sizeof(SVGAGBCursorHeader);
+
+ if (mob_size > mob_max_size) {
+ drm_warn(&vmw->drm,
+ "Cursor MOB size %llu exceeds device max %u\n",
+ mob_size, mob_max_size);
+ return -EINVAL;
+ }
+ }
}
return 0;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 416/438] drm/vmwgfx: use check_add_overflow for shader size+offset bound
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (414 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 415/438] drm/vmwgfx: enforce cursor size limits for MOB cursors Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 417/438] drm/vmwgfx: validate external BO copy bounds for both stride paths Greg Kroah-Hartman
` (35 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 54d56d5b42d2e4c72ba6e365e9774da90698aa22 upstream.
vmw_shader_define() validates the user-supplied shader window against
its backing buffer with
(u64)buffer->tbo.base.size < (u64)size + (u64)offset
drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is
near U64_MAX the unsigned addition wraps and the resulting tiny value
passes the check. The unbounded offset is then stored in
res->guest_memory_offset and forwarded to host SVGA shader-create
commands.
Use check_add_overflow() to detect the wrap and compare the resulting
endpoint against the buffer size.
Fixes: 668b206601c5 ("drm/vmwgfx: Stop using raw ttm_buffer_object's")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-12-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_shader.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_shader.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_shader.c
@@ -25,6 +25,8 @@
*
**************************************************************************/
+#include <linux/overflow.h>
+
#include <drm/ttm/ttm_placement.h>
#include "vmwgfx_binding.h"
@@ -685,7 +687,7 @@ int vmw_shader_destroy_ioctl(struct drm_
static int vmw_user_shader_alloc(struct vmw_private *dev_priv,
struct vmw_bo *buffer,
size_t shader_size,
- size_t offset,
+ u64 offset,
SVGA3dShaderType shader_type,
uint8_t num_input_sig,
uint8_t num_output_sig,
@@ -739,7 +741,7 @@ out:
static struct vmw_resource *vmw_shader_alloc(struct vmw_private *dev_priv,
struct vmw_bo *buffer,
size_t shader_size,
- size_t offset,
+ u64 offset,
SVGA3dShaderType shader_type)
{
struct vmw_shader *shader;
@@ -768,7 +770,7 @@ out_err:
static int vmw_shader_define(struct drm_device *dev, struct drm_file *file_priv,
enum drm_vmw_shader_type shader_type_drm,
- u32 buffer_handle, size_t size, size_t offset,
+ u32 buffer_handle, size_t size, u64 offset,
uint8_t num_input_sig, uint8_t num_output_sig,
uint32_t *shader_handle)
{
@@ -779,13 +781,16 @@ static int vmw_shader_define(struct drm_
int ret;
if (buffer_handle != SVGA3D_INVALID_ID) {
+ u64 end;
+
ret = vmw_user_bo_lookup(file_priv, buffer_handle, &buffer);
if (unlikely(ret != 0)) {
VMW_DEBUG_USER("Couldn't find buffer for shader creation.\n");
return ret;
}
- if ((u64)buffer->tbo.base.size < (u64)size + (u64)offset) {
+ if (check_add_overflow((u64)size, (u64)offset, &end) ||
+ end > buffer->tbo.base.size) {
VMW_DEBUG_USER("Illegal buffer- or shader size.\n");
ret = -EINVAL;
goto out_bad_arg;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 417/438] drm/vmwgfx: validate external BO copy bounds for both stride paths
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (415 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 416/438] drm/vmwgfx: use check_add_overflow for shader size+offset bound Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 418/438] drm/xe/rtp: Maintain OA whitelists separately Greg Kroah-Hartman
` (34 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zack Rusin, Ian Forbes
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zack Rusin <zack.rusin@broadcom.com>
commit 706c93c5813caabbb0d0a576c017d15aeec2c113 upstream.
vmw_external_bo_copy() trusts caller-supplied offsets, strides, and
heights and operates on imported dma-buf vmaps:
- The equal-stride memcpy() bound was clamped after subtracting the
offsets from dst_size and src_size; an offset larger than the BO
size wraps the unsigned subtraction to a huge value and the
resulting memcpy() runs off the end of the vmap. dst_stride *
height is also a u32 multiplication that can overflow.
- The non-equal-stride row-by-row path had no bound at all. The
loop touches bytes through offset + (height - 1) * stride +
width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes),
and could likewise step past the end of either mapping.
The offsets and strides are derived from STDU/SOU plane state, so a
configured CRTC submitting a crafted atomic commit on an imported
framebuffer can reach this path.
Validate the exact row-copy endpoint against each BO's size up front
using check_mul_overflow() and check_add_overflow(). Use the bulk
memcpy() path only when width_in_bytes covers the whole stride;
otherwise copy one row at a time so partial-row updates near the bottom
of a framebuffer remain valid. Also reject zero strides and stride <
width_in_bytes, both of which the row-by-row path cannot represent
safely.
Fixes: 50f119925091 ("drm/vmwgfx: Fix prime with external buffers")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-13-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/vmwgfx/vmwgfx_blit.c | 39 +++++++++++++++++++++++++++--------
1 file changed, 31 insertions(+), 8 deletions(-)
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_blit.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_blit.c
@@ -30,6 +30,7 @@
#include "vmwgfx_bo.h"
#include <linux/highmem.h>
+#include <linux/overflow.h>
/*
* Template that implements find_first_diff() for a generic
@@ -463,19 +464,42 @@ static int vmw_external_bo_copy(struct v
container_of(dst->tbo.bdev, struct vmw_private, bdev);
size_t dst_size = dst->tbo.resource->size;
size_t src_size = src->tbo.resource->size;
+ size_t dst_end, src_end;
struct iosys_map dst_map = {0};
struct iosys_map src_map = {0};
+ bool dst_mapped = false;
+ bool src_mapped = false;
int ret, i;
int x_in_bytes;
u8 *vsrc;
u8 *vdst;
+ if (!height || !width_in_bytes)
+ return 0;
+
+ if (!dst_stride || !src_stride)
+ return -EINVAL;
+ if (dst_stride < width_in_bytes || src_stride < width_in_bytes)
+ return -EINVAL;
+ if (check_mul_overflow((size_t)dst_stride, (size_t)height - 1, &dst_end) ||
+ check_add_overflow(dst_end, (size_t)width_in_bytes, &dst_end) ||
+ check_add_overflow((size_t)dst_offset, dst_end, &dst_end) ||
+ dst_end > dst_size ||
+ check_mul_overflow((size_t)src_stride, (size_t)height - 1, &src_end) ||
+ check_add_overflow(src_end, (size_t)width_in_bytes, &src_end) ||
+ check_add_overflow((size_t)src_offset, src_end, &src_end) ||
+ src_end > src_size) {
+ drm_dbg_driver(&vmw->drm, "Out-of-bounds external BO copy\n");
+ return -EINVAL;
+ }
+
vsrc = map_external(src, &src_map);
if (!vsrc) {
drm_dbg_driver(&vmw->drm, "Wasn't able to map src\n");
ret = -ENOMEM;
goto out;
}
+ src_mapped = true;
vdst = map_external(dst, &dst_map);
if (!vdst) {
@@ -483,16 +507,13 @@ static int vmw_external_bo_copy(struct v
ret = -ENOMEM;
goto out;
}
+ dst_mapped = true;
vsrc += src_offset;
vdst += dst_offset;
- if (src_stride == dst_stride) {
- dst_size -= dst_offset;
- src_size -= src_offset;
- memcpy(vdst, vsrc,
- min(dst_stride * height, min(dst_size, src_size)));
+ if (src_stride == dst_stride && width_in_bytes == dst_stride) {
+ memcpy(vdst, vsrc, dst_stride * (size_t)height);
} else {
- WARN_ON(dst_stride < width_in_bytes);
for (i = 0; i < height; ++i) {
memcpy(vdst, vsrc, width_in_bytes);
vsrc += src_stride;
@@ -508,8 +529,10 @@ static int vmw_external_bo_copy(struct v
ret = 0;
out:
- unmap_external(src, &src_map);
- unmap_external(dst, &dst_map);
+ if (src_mapped)
+ unmap_external(src, &src_map);
+ if (dst_mapped)
+ unmap_external(dst, &dst_map);
return ret;
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 418/438] drm/xe/rtp: Maintain OA whitelists separately
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (416 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 417/438] drm/vmwgfx: validate external BO copy bounds for both stride paths Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 419/438] drm/xe/rtp: Keep track of non-OA nonpriv slots Greg Kroah-Hartman
` (33 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Umesh Nerlige Ramappa,
Thomas Hellström, Sasha Levin, Ashutosh Dixit
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit 31e2437561621b4867c08efc890bf629d017df03 ]
OA registers are dynamically whitelisted (and again dewhitelisted) on OA
stream open/close. Maintaining OA whitelists separately from non-OA
register whitlists simplifies this management of OA register
whitelisting/dewhitelisting.
(cherry picked from commit c478244a9e2d14b3f1f92e8bd293919e554622a5)
[ adapted RTP table from struct wrapper macro `XE_RTP_TABLE_SR()` back to plain `struct xe_rtp_entry_sr[]` array and restored the 5-arg `xe_rtp_process_to_sr()` call with `ARRAY_SIZE()` ]
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-3-ashutosh.dixit@intel.com
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_gt_debugfs.c | 4 +++-
drivers/gpu/drm/xe/xe_hw_engine.c | 2 ++
drivers/gpu/drm/xe/xe_hw_engine_types.h | 8 ++++++++
drivers/gpu/drm/xe/xe_reg_whitelist.c | 6 ++++++
4 files changed, 19 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/xe/xe_gt_debugfs.c b/drivers/gpu/drm/xe/xe_gt_debugfs.c
index f45306308cd66..c38bcacb27e4a 100644
--- a/drivers/gpu/drm/xe/xe_gt_debugfs.c
+++ b/drivers/gpu/drm/xe/xe_gt_debugfs.c
@@ -149,8 +149,10 @@ static int register_save_restore(struct xe_gt *gt, struct drm_printer *p)
drm_printf(p, "\n");
drm_printf(p, "Whitelist\n");
- for_each_hw_engine(hwe, gt, id)
+ for_each_hw_engine(hwe, gt, id) {
xe_reg_whitelist_dump(&hwe->reg_whitelist, p);
+ xe_reg_whitelist_dump(&hwe->oa_whitelist, p);
+ }
return 0;
}
diff --git a/drivers/gpu/drm/xe/xe_hw_engine.c b/drivers/gpu/drm/xe/xe_hw_engine.c
index a7441a66e94c2..b5a869c720af7 100644
--- a/drivers/gpu/drm/xe/xe_hw_engine.c
+++ b/drivers/gpu/drm/xe/xe_hw_engine.c
@@ -575,6 +575,8 @@ static void hw_engine_init_early(struct xe_gt *gt, struct xe_hw_engine *hwe,
hw_engine_setup_default_state(hwe);
xe_reg_sr_init(&hwe->reg_whitelist, hwe->name, gt_to_xe(gt));
+ xe_reg_sr_init(&hwe->oa_whitelist, hwe->name, gt_to_xe(gt));
+ xe_reg_sr_init(&hwe->oa_sr, hwe->name, gt_to_xe(gt));
xe_reg_whitelist_process_engine(hwe);
}
diff --git a/drivers/gpu/drm/xe/xe_hw_engine_types.h b/drivers/gpu/drm/xe/xe_hw_engine_types.h
index e4191a7a2c318..04ca7545d22c3 100644
--- a/drivers/gpu/drm/xe/xe_hw_engine_types.h
+++ b/drivers/gpu/drm/xe/xe_hw_engine_types.h
@@ -128,6 +128,14 @@ struct xe_hw_engine {
* @reg_whitelist: table with registers to be whitelisted
*/
struct xe_reg_sr reg_whitelist;
+ /**
+ * @oa_whitelist: oa registers to be whitelisted
+ */
+ struct xe_reg_sr oa_whitelist;
+ /**
+ * @oa_sr: oa nonpriv whitelist registers, changed on oa stream open/close
+ */
+ struct xe_reg_sr oa_sr;
/**
* @reg_lrc: LRC workaround registers
*/
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index 506501d77f389..a0bbf4b745a1f 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -89,6 +89,9 @@ static const struct xe_rtp_entry_sr register_whitelist[] = {
WHITELIST(VFLSKPD,
RING_FORCE_TO_NONPRIV_ACCESS_RW))
},
+};
+
+static const struct xe_rtp_entry_sr oa_whitelist[] = {
#define WHITELIST_DENY(r, f) WHITELIST(r, (f) | RING_FORCE_TO_NONPRIV_DENY)
@@ -193,6 +196,9 @@ void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe)
xe_rtp_process_to_sr(&ctx, register_whitelist, ARRAY_SIZE(register_whitelist),
&hwe->reg_whitelist, false);
whitelist_apply_to_hwe(hwe);
+
+ xe_rtp_process_to_sr(&ctx, oa_whitelist, ARRAY_SIZE(oa_whitelist),
+ &hwe->oa_whitelist, false);
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 419/438] drm/xe/rtp: Keep track of non-OA nonpriv slots
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (417 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 418/438] drm/xe/rtp: Maintain OA whitelists separately Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 420/438] drm/xe/rtp: Generalize whitelist_apply_to_hwe Greg Kroah-Hartman
` (32 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit 60d49ea28bb190a640bd8dc3f4c946e0811a948c ]
In order to dynamically whitelist/dewhitelist OA registers on OA stream
open/close, we need to keep track of nonpriv slots occupied by non-OA
register whitelists.
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-4-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_reg_whitelist.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index a0bbf4b745a1f..00f00002afcef 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -147,7 +147,7 @@ static const struct xe_rtp_entry_sr oa_whitelist[] = {
},
};
-static void whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
+static int whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
{
struct xe_reg_sr *sr = &hwe->reg_whitelist;
struct xe_reg_sr_entry *entry;
@@ -179,6 +179,8 @@ static void whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
slot++;
}
+
+ return slot;
}
/**
@@ -192,10 +194,11 @@ static void whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe)
{
struct xe_rtp_process_ctx ctx = XE_RTP_PROCESS_CTX_INITIALIZER(hwe);
+ int first_oa_slot;
xe_rtp_process_to_sr(&ctx, register_whitelist, ARRAY_SIZE(register_whitelist),
&hwe->reg_whitelist, false);
- whitelist_apply_to_hwe(hwe);
+ first_oa_slot = whitelist_apply_to_hwe(hwe);
xe_rtp_process_to_sr(&ctx, oa_whitelist, ARRAY_SIZE(oa_whitelist),
&hwe->oa_whitelist, false);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 420/438] drm/xe/rtp: Generalize whitelist_apply_to_hwe
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (418 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 419/438] drm/xe/rtp: Keep track of non-OA nonpriv slots Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 421/438] drm/xe/rtp: Save OA nonpriv registers to register save/restore lists Greg Kroah-Hartman
` (31 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit 4fe2844b0f0c7cdc45ca4c4c62ca56b7f26c514c ]
Generalize whitelist_apply_to_hwe to construct both non-OA and OA
whitelist nonpriv registers.
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-5-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_reg_whitelist.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index 00f00002afcef..1a7d69ef4fe82 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -147,9 +147,10 @@ static const struct xe_rtp_entry_sr oa_whitelist[] = {
},
};
-static int whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
+static int whitelist_apply_to_hwe(struct xe_hw_engine *hwe, struct xe_reg_sr *in,
+ struct xe_reg_sr *out, int first_slot)
{
- struct xe_reg_sr *sr = &hwe->reg_whitelist;
+ struct xe_reg_sr *sr = in;
struct xe_reg_sr_entry *entry;
struct drm_printer p;
unsigned long reg;
@@ -158,7 +159,7 @@ static int whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
xe_gt_dbg(hwe->gt, "Add %s whitelist to engine\n", sr->name);
p = xe_gt_dbg_printer(hwe->gt);
- slot = 0;
+ slot = first_slot;
xa_for_each(&sr->xa, reg, entry) {
struct xe_reg_sr_entry hwe_entry = {
.reg = RING_FORCE_TO_NONPRIV(hwe->mmio_base, slot),
@@ -175,7 +176,7 @@ static int whitelist_apply_to_hwe(struct xe_hw_engine *hwe)
}
xe_reg_whitelist_print_entry(&p, 0, reg, entry);
- xe_reg_sr_add(&hwe->reg_sr, &hwe_entry, hwe->gt);
+ xe_reg_sr_add(out, &hwe_entry, hwe->gt);
slot++;
}
@@ -198,7 +199,7 @@ void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe)
xe_rtp_process_to_sr(&ctx, register_whitelist, ARRAY_SIZE(register_whitelist),
&hwe->reg_whitelist, false);
- first_oa_slot = whitelist_apply_to_hwe(hwe);
+ first_oa_slot = whitelist_apply_to_hwe(hwe, &hwe->reg_whitelist, &hwe->reg_sr, 0);
xe_rtp_process_to_sr(&ctx, oa_whitelist, ARRAY_SIZE(oa_whitelist),
&hwe->oa_whitelist, false);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 421/438] drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (419 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 420/438] drm/xe/rtp: Generalize whitelist_apply_to_hwe Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 422/438] drm/xe/rtp: Toggle deny bit to (de-)whitelist OA regs Greg Kroah-Hartman
` (30 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit a19a83721a28ccaddace846da70da5c53d7dd052 ]
Now we can save OA whitelisting nonpriv registers to register save/restore
lists. OA nonpriv registers are saved to both hwe->oa_sr as well as
hwe->reg_sr.
During probe, resume and gt-reset flows KMD will apply hwe->reg_sr,
ensuring OA registers are de-whitelisted after these events. For
engine-reset, hwe->reg_sr is registered with GuC and GuC will apply these
registers, ensuring OA registers are de-whitelisted after engine resets.
hwe->oa_sr is used for whitelisting or de-whitelisting OA registers during
OA operation, by toggling the 'deny' bit on oa stream open/close.
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-6-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_reg_whitelist.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index 1a7d69ef4fe82..dbaa387a35613 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -203,6 +203,17 @@ void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe)
xe_rtp_process_to_sr(&ctx, oa_whitelist, ARRAY_SIZE(oa_whitelist),
&hwe->oa_whitelist, false);
+ /*
+ * Save oa nonpriv registers to hwe->oa_sr, from which oa registers are whitelisted
+ * or de-whitelisted, by toggling the 'deny' bit on oa stream open/close
+ */
+ whitelist_apply_to_hwe(hwe, &hwe->oa_whitelist, &hwe->oa_sr, first_oa_slot);
+
+ /*
+ * Also save oa nonpriv registers to hwe->reg_sr, to ensure oa registers are not
+ * whitelisted by default after probe, gt reset, resume and engine reset
+ */
+ whitelist_apply_to_hwe(hwe, &hwe->oa_whitelist, &hwe->reg_sr, first_oa_slot);
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 422/438] drm/xe/rtp: Toggle deny bit to (de-)whitelist OA regs
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (420 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 421/438] drm/xe/rtp: Save OA nonpriv registers to register save/restore lists Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 423/438] drm/xe/rtp: (De-)whitelist OA registers for all hwes for a gt Greg Kroah-Hartman
` (29 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit b422babd77fac2c96b92db484050e460899bddaf ]
Whitelist or de-whitelist OA registers by setting or resetting the 'deny'
bit in OA nonpriv registers and writing new register values to HW.
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-7-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_reg_whitelist.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index dbaa387a35613..1a53abbd9a74f 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -216,6 +216,21 @@ void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe)
whitelist_apply_to_hwe(hwe, &hwe->oa_whitelist, &hwe->reg_sr, first_oa_slot);
}
+__maybe_unused static void __whitelist_oa_regs(struct xe_hw_engine *hwe, bool whitelist)
+{
+ struct xe_reg_sr_entry *entry;
+ unsigned long reg;
+
+ xa_for_each(&hwe->oa_sr.xa, reg, entry) {
+ if (whitelist)
+ entry->set_bits &= ~RING_FORCE_TO_NONPRIV_DENY;
+ else
+ entry->set_bits |= RING_FORCE_TO_NONPRIV_DENY;
+ }
+
+ xe_reg_sr_apply_mmio(&hwe->oa_sr, hwe->gt);
+}
+
/**
* xe_reg_whitelist_print_entry - print one whitelist entry
* @p: DRM printer
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 423/438] drm/xe/rtp: (De-)whitelist OA registers for all hwes for a gt
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (421 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 422/438] drm/xe/rtp: Toggle deny bit to (de-)whitelist OA regs Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 424/438] drm/xe/oa: (De-)whitelist OA registers on OA stream open/release Greg Kroah-Hartman
` (28 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit ebba7ce65252a4ab0e3794ff14854df2afca5c08 ]
Whitelist or de-whitelist OA registers for all hwe's on the gt on which the
OA stream is opened. This simplifies the case where an oa unit has 0
attached hwe's (but which monitors OA events on the associated GT).
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-8-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_reg_whitelist.c | 34 +++++++++++++++++++++++++--
drivers/gpu/drm/xe/xe_reg_whitelist.h | 4 ++++
2 files changed, 36 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index 1a53abbd9a74f..2ecf273c5f401 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -9,7 +9,7 @@
#include "regs/xe_gt_regs.h"
#include "regs/xe_oa_regs.h"
#include "xe_device.h"
-#include "xe_gt_types.h"
+#include "xe_gt.h"
#include "xe_gt_printk.h"
#include "xe_platform_types.h"
#include "xe_reg_sr.h"
@@ -216,7 +216,7 @@ void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe)
whitelist_apply_to_hwe(hwe, &hwe->oa_whitelist, &hwe->reg_sr, first_oa_slot);
}
-__maybe_unused static void __whitelist_oa_regs(struct xe_hw_engine *hwe, bool whitelist)
+static void __whitelist_oa_regs(struct xe_hw_engine *hwe, bool whitelist)
{
struct xe_reg_sr_entry *entry;
unsigned long reg;
@@ -231,6 +231,36 @@ __maybe_unused static void __whitelist_oa_regs(struct xe_hw_engine *hwe, bool wh
xe_reg_sr_apply_mmio(&hwe->oa_sr, hwe->gt);
}
+/**
+ * xe_reg_whitelist_oa_regs - whitelist oa registers for gt
+ * @gt: gt to whitelist oa registers for
+ *
+ * Whitelist OA registers by resetting RING_FORCE_TO_NONPRIV_DENY
+ */
+void xe_reg_whitelist_oa_regs(struct xe_gt *gt)
+{
+ struct xe_hw_engine *hwe;
+ enum xe_hw_engine_id id;
+
+ for_each_hw_engine(hwe, gt, id)
+ __whitelist_oa_regs(hwe, true);
+}
+
+/**
+ * xe_reg_dewhitelist_oa_regs - dewhitelist oa registers for gt
+ * @gt: gt to dewhitelist oa registers for
+ *
+ * Dewhitelist OA registers by setting RING_FORCE_TO_NONPRIV_DENY
+ */
+void xe_reg_dewhitelist_oa_regs(struct xe_gt *gt)
+{
+ struct xe_hw_engine *hwe;
+ enum xe_hw_engine_id id;
+
+ for_each_hw_engine(hwe, gt, id)
+ __whitelist_oa_regs(hwe, false);
+}
+
/**
* xe_reg_whitelist_print_entry - print one whitelist entry
* @p: DRM printer
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.h b/drivers/gpu/drm/xe/xe_reg_whitelist.h
index 69b121d377da0..f243b6ac60b7e 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.h
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.h
@@ -9,12 +9,16 @@
#include <linux/types.h>
struct drm_printer;
+struct xe_gt;
struct xe_hw_engine;
struct xe_reg_sr;
struct xe_reg_sr_entry;
void xe_reg_whitelist_process_engine(struct xe_hw_engine *hwe);
+void xe_reg_whitelist_oa_regs(struct xe_gt *gt);
+void xe_reg_dewhitelist_oa_regs(struct xe_gt *gt);
+
void xe_reg_whitelist_print_entry(struct drm_printer *p, unsigned int indent,
u32 reg, struct xe_reg_sr_entry *entry);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 424/438] drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (422 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 423/438] drm/xe/rtp: (De-)whitelist OA registers for all hwes for a gt Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 425/438] drm/xe/rtp: Ensure locking/ref counting for OA whitelists Greg Kroah-Hartman
` (27 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit 63ddb3ad08ff4e89c108499dfec5e9be5ddc25c9 ]
Whitelist OA registers on stream open and de-whitelist on stream
close/release. Whitelisting is only done when 'stream->sample' is
true. 'stream->sample' is only true when (a) xe_observation_paranoid is set
to false by system admin, or (b) the process is perfmon_capable(). This
therefore enforces the OA register whitelisting security requirements.
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-9-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_oa.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_oa.c b/drivers/gpu/drm/xe/xe_oa.c
index d908f4e039063..5111c6519c6db 100644
--- a/drivers/gpu/drm/xe/xe_oa.c
+++ b/drivers/gpu/drm/xe/xe_oa.c
@@ -35,6 +35,7 @@
#include "xe_oa.h"
#include "xe_observation.h"
#include "xe_pm.h"
+#include "xe_reg_whitelist.h"
#include "xe_sched_job.h"
#include "xe_sriov.h"
#include "xe_sync.h"
@@ -866,6 +867,9 @@ static void xe_oa_stream_destroy(struct xe_oa_stream *stream)
mutex_destroy(&stream->stream_lock);
+ if (stream->sample)
+ xe_reg_dewhitelist_oa_regs(stream->gt);
+
xe_oa_disable_metric_set(stream);
xe_exec_queue_put(stream->k_exec_q);
@@ -1871,6 +1875,9 @@ static int xe_oa_stream_open_ioctl_locked(struct xe_oa *oa,
goto err_disable;
}
+ if (stream->sample)
+ xe_reg_whitelist_oa_regs(stream->gt);
+
/* Hold a reference on the drm device till stream_fd is released */
drm_dev_get(&stream->oa->xe->drm);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 425/438] drm/xe/rtp: Ensure locking/ref counting for OA whitelists
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (423 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 424/438] drm/xe/oa: (De-)whitelist OA registers on OA stream open/release Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 426/438] usb: typec: ucsi: split connector lock classes Greg Kroah-Hartman
` (26 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ashutosh Dixit,
Umesh Nerlige Ramappa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ashutosh Dixit <ashutosh.dixit@intel.com>
[ Upstream commit ef78e2a22f72c892fd6663f0760abd208d49a3e2 ]
Since multiple OA streams might be open in parallel on a gt, ensure that
proper locking is in place. Also ensure that OA registers are whitelisted
when the first OA stream is open and de-whitelisted after the last OA
stream is closed.
Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support")
Cc: stable@vger.kernel.org # v6.12+
Signed-off-by: Ashutosh Dixit <ashutosh.dixit@intel.com>
Reviewed-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Link: https://patch.msgid.link/20260615224227.34880-10-ashutosh.dixit@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_oa_types.h | 3 +++
drivers/gpu/drm/xe/xe_reg_whitelist.c | 9 +++++++++
2 files changed, 12 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_oa_types.h b/drivers/gpu/drm/xe/xe_oa_types.h
index b03ffd5134834..c0ddfae755b6a 100644
--- a/drivers/gpu/drm/xe/xe_oa_types.h
+++ b/drivers/gpu/drm/xe/xe_oa_types.h
@@ -126,6 +126,9 @@ struct xe_oa_gt {
/** @oa_unit: array of oa_units */
struct xe_oa_unit *oa_unit;
+
+ /** @whitelist_count: number of open streams for which oa registers are whitelisted */
+ u32 whitelist_count;
};
/**
diff --git a/drivers/gpu/drm/xe/xe_reg_whitelist.c b/drivers/gpu/drm/xe/xe_reg_whitelist.c
index 2ecf273c5f401..dad47988bdf6d 100644
--- a/drivers/gpu/drm/xe/xe_reg_whitelist.c
+++ b/drivers/gpu/drm/xe/xe_reg_whitelist.c
@@ -242,6 +242,10 @@ void xe_reg_whitelist_oa_regs(struct xe_gt *gt)
struct xe_hw_engine *hwe;
enum xe_hw_engine_id id;
+ lockdep_assert_held(>->oa.gt_lock);
+ if (gt->oa.whitelist_count++)
+ return;
+
for_each_hw_engine(hwe, gt, id)
__whitelist_oa_regs(hwe, true);
}
@@ -257,6 +261,11 @@ void xe_reg_dewhitelist_oa_regs(struct xe_gt *gt)
struct xe_hw_engine *hwe;
enum xe_hw_engine_id id;
+ lockdep_assert_held(>->oa.gt_lock);
+ xe_assert(gt_to_xe(gt), gt->oa.whitelist_count);
+ if (--gt->oa.whitelist_count)
+ return;
+
for_each_hw_engine(hwe, gt, id)
__whitelist_oa_regs(hwe, false);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 426/438] usb: typec: ucsi: split connector lock classes
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (424 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 425/438] drm/xe/rtp: Ensure locking/ref counting for OA whitelists Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 427/438] usb: typec: ucsi: Fix race condition and ordering in port unregistration Greg Kroah-Hartman
` (25 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sergey Senozhatsky, Heikki Krogerus,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sergey Senozhatsky <senozhatsky@chromium.org>
[ Upstream commit 8c22256bbafad3dc5fdbe9f684d045b67ff06a68 ]
Lockdep detects a possible recursive locking scenario during
ucsi init:
[ 5.418616] ============================================
[ 5.418634] WARNING: possible recursive locking detected
[ 5.418706] --------------------------------------------
[ 5.418725] kworker/4:1/82 is trying to acquire lock:
[ 5.418759] ffff888119a34648 (&con->lock){+.+.}-{3:3}, at: ucsi_init_work+0x1a78/0x2eb0 [typec_ucsi]
[ 5.418801]
but task is already holding lock:
[ 5.418835] ffff888119a34080 (&con->lock){+.+.}-{3:3}, at: ucsi_init_work+0x1a78/0x2eb0 [typec_ucsi]
[ 5.418884]
other info that might help us debug this:
[ 5.418904] Possible unsafe locking scenario:
[ 5.418937] CPU0
[ 5.418956] ----
[ 5.418991] lock(&con->lock);
[ 5.419013] lock(&con->lock);
[ 5.419033]
*** DEADLOCK ***
[ 5.419387] Call Trace:
[ 5.419406] <TASK>
[ 5.419425] dump_stack_lvl+0x61/0xa0
[ 5.419448] print_deadlock_bug+0x4a6/0x650
[ 5.419483] __lock_acquire+0x62b6/0x7f50
[ 5.419507] lock_acquire+0x11b/0x390
[ 5.419654] __mutex_lock+0xbc/0xcd0
[ 5.419741] ucsi_init_work+0x1a78/0x2eb0
[ 5.419785] ? worker_thread+0xf53/0x2bc0
[ 5.419819] worker_thread+0xff4/0x2bc0
[ 5.419842] kthread+0x2a7/0x330
[ 5.419863] ? __pfx_worker_thread+0x10/0x10
[ 5.419896] ? __pfx_kthread+0x10/0x10
[ 5.419916] ret_from_fork+0x38/0x70
[ 5.419936] ? __pfx_kthread+0x10/0x10
[ 5.419969] ret_from_fork_asm+0x1b/0x30
[ 5.419991] </TASK>
[ 5.420009] ---[ end trace 0000000000000000 ]---
The problem is that all connector locks belong to the same
lockdep lock class, so the following loop:
for (i = 0; i < ucsi->cap.num_connectors; i++)
ucsi_register_port(connector[i])
mutex_lock(&connector[i]->lock)
looks like a recursive acquire of the same mutex. Put each connector
lock into a dedicated lock class so that lockdep doesn't see it as a
possible recursion.
Signed-off-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260515060042.136083-1-senozhatsky@chromium.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 7aa7d4bf9d3f ("usb: typec: ucsi: Fix race condition and ordering in port unregistration")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/typec/ucsi/ucsi.c | 8 ++++++++
drivers/usb/typec/ucsi/ucsi.h | 1 +
2 files changed, 9 insertions(+)
--- a/drivers/usb/typec/ucsi/ucsi.c
+++ b/drivers/usb/typec/ucsi/ucsi.c
@@ -1796,6 +1796,7 @@ static int ucsi_register_port(struct ucs
INIT_WORK(&con->work, ucsi_handle_connector_change);
init_completion(&con->complete);
mutex_init(&con->lock);
+ lockdep_set_class(&con->lock, &con->lock_key);
INIT_LIST_HEAD(&con->partner_tasks);
con->ucsi = ucsi;
@@ -2041,6 +2042,9 @@ static int ucsi_init(struct ucsi *ucsi)
goto err_reset;
}
+ for (i = 0; i < ucsi->cap.num_connectors; i++)
+ lockdep_register_key(&connector[i].lock_key);
+
/* Register all connectors */
for (i = 0; i < ucsi->cap.num_connectors; i++) {
connector[i].num = i + 1;
@@ -2070,6 +2074,9 @@ static int ucsi_init(struct ucsi *ucsi)
return 0;
err_unregister:
+ for (i = 0; i < ucsi->cap.num_connectors; i++)
+ lockdep_unregister_key(&connector[i].lock_key);
+
for (con = connector; con->port; con++) {
if (con->wq)
destroy_workqueue(con->wq);
@@ -2340,6 +2347,7 @@ void ucsi_unregister(struct ucsi *ucsi)
usb_power_delivery_unregister(ucsi->connector[i].pd);
ucsi->connector[i].pd = NULL;
typec_unregister_port(ucsi->connector[i].port);
+ lockdep_unregister_key(&ucsi->connector[i].lock_key);
}
kfree(ucsi->connector);
--- a/drivers/usb/typec/ucsi/ucsi.h
+++ b/drivers/usb/typec/ucsi/ucsi.h
@@ -517,6 +517,7 @@ struct ucsi_connector {
struct ucsi *ucsi;
struct mutex lock; /* port lock */
+ struct lock_class_key lock_key;
struct work_struct work;
struct completion complete;
struct workqueue_struct *wq;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 427/438] usb: typec: ucsi: Fix race condition and ordering in port unregistration
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (425 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 426/438] usb: typec: ucsi: split connector lock classes Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 428/438] drm/xe: Drop unused param from xe_device_create() Greg Kroah-Hartman
` (24 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable, Andrei Kuchynski,
Benson Leung, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrei Kuchynski <akuchynski@chromium.org>
[ Upstream commit 7aa7d4bf9d3fa9a6a47b640ad103ab433b7ff261 ]
A synchronization issue exists during port unregistration where pending
partner work items can race against workqueue destruction, leading to
use-after-free conditions:
cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:__queue_work+0x83/0x4a0
Call Trace:
<IRQ>
__cfi_delayed_work_timer_fn+0x10/0x10
run_timer_softirq+0x3b6/0xbd0
sched_clock_cpu+0xc/0x110
irq_exit_rcu+0x18d/0x330
fred_sysvec_apic_timer_interrupt+0x5e/0x80
Fix this by ensuring strict ordering and proper serialization during
teardown:
1. Move ucsi_unregister_partner() to the beginning of the teardown
sequence and protect it under the connector mutex lock.
2. Ensure all pending partner tasks are explicitly flushed and finished
before the workqueue is destroyed.
3. Switch from mod_delayed_work() to a cancel_delayed_work() and
queue_delayed_work() sequence. This guarantees that items currently marked
as pending won't be scheduled an additional time, preventing a double
release of resources which leads to the following crash:
Oops: general protection fault, probably for non-canonical address
0xdead000000000122: 0000 [#1] SMP NOPTI
Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker
RIP: 0010:ucsi_poll_worker+0x65/0x1e0
Call Trace:
<TASK>
process_scheduled_works+0x218/0x6d0
worker_thread+0x188/0x3f0
__cfi_worker_thread+0x10/0x10
kthread+0x226/0x2a0
To ensure these rules are applied identically across both the normal
teardown and the ucsi_init() error paths, consolidate the cleanup logic
into a new helper, ucsi_unregister_port().
Cc: stable <stable@kernel.org>
Fixes: b9aa02ca39a4 ("usb: typec: ucsi: Add polling mechanism for partner tasks like alt mode checking")
Fixes: b13abcb7ddd8 ("usb: typec: ucsi: Fix NULL pointer access")
Fixes: fac4b8633fd6 ("usb: ucsi: Ensure connector delayed work items are flushed")
Signed-off-by: Andrei Kuchynski <akuchynski@chromium.org>
Reviewed-by: Benson Leung <bleung@chromium.org>
Link: https://patch.msgid.link/20260707141736.1635698-1-akuchynski@chromium.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/typec/ucsi/ucsi.c | 82 +++++++++++++++++++-----------------------
1 file changed, 39 insertions(+), 43 deletions(-)
--- a/drivers/usb/typec/ucsi/ucsi.c
+++ b/drivers/usb/typec/ucsi/ucsi.c
@@ -1951,6 +1951,42 @@ out_unlock:
return ret;
}
+static void ucsi_unregister_port(struct ucsi_connector *con)
+{
+ struct ucsi_work *uwork;
+
+ if (con->wq) {
+ mutex_lock(&con->lock);
+ ucsi_unregister_partner(con);
+ /*
+ * queue delayed items immediately so they can execute
+ * and free themselves before the wq is destroyed
+ */
+ list_for_each_entry(uwork, &con->partner_tasks, node) {
+ if (cancel_delayed_work(&uwork->work))
+ queue_delayed_work(con->wq, &uwork->work, 0);
+ }
+ mutex_unlock(&con->lock);
+
+ destroy_workqueue(con->wq);
+ con->wq = NULL;
+ } else {
+ ucsi_unregister_partner(con);
+ }
+
+ ucsi_unregister_altmodes(con, UCSI_RECIPIENT_CON);
+ ucsi_unregister_port_psy(con);
+
+ usb_power_delivery_unregister_capabilities(con->port_sink_caps);
+ con->port_sink_caps = NULL;
+ usb_power_delivery_unregister_capabilities(con->port_source_caps);
+ con->port_source_caps = NULL;
+ usb_power_delivery_unregister(con->pd);
+ con->pd = NULL;
+ typec_unregister_port(con->port);
+ con->port = NULL;
+}
+
static u64 ucsi_get_supported_notifications(struct ucsi *ucsi)
{
u16 features = ucsi->cap.features;
@@ -2077,22 +2113,8 @@ err_unregister:
for (i = 0; i < ucsi->cap.num_connectors; i++)
lockdep_unregister_key(&connector[i].lock_key);
- for (con = connector; con->port; con++) {
- if (con->wq)
- destroy_workqueue(con->wq);
- ucsi_unregister_partner(con);
- ucsi_unregister_altmodes(con, UCSI_RECIPIENT_CON);
- ucsi_unregister_port_psy(con);
-
- usb_power_delivery_unregister_capabilities(con->port_sink_caps);
- con->port_sink_caps = NULL;
- usb_power_delivery_unregister_capabilities(con->port_source_caps);
- con->port_source_caps = NULL;
- usb_power_delivery_unregister(con->pd);
- con->pd = NULL;
- typec_unregister_port(con->port);
- con->port = NULL;
- }
+ for (con = connector; con->port; con++)
+ ucsi_unregister_port(con);
kfree(connector);
err_reset:
memset(&ucsi->cap, 0, sizeof(ucsi->cap));
@@ -2320,33 +2342,7 @@ void ucsi_unregister(struct ucsi *ucsi)
for (i = 0; i < ucsi->cap.num_connectors; i++) {
cancel_work_sync(&ucsi->connector[i].work);
-
- if (ucsi->connector[i].wq) {
- struct ucsi_work *uwork;
-
- mutex_lock(&ucsi->connector[i].lock);
- /*
- * queue delayed items immediately so they can execute
- * and free themselves before the wq is destroyed
- */
- list_for_each_entry(uwork, &ucsi->connector[i].partner_tasks, node)
- mod_delayed_work(ucsi->connector[i].wq, &uwork->work, 0);
- mutex_unlock(&ucsi->connector[i].lock);
- destroy_workqueue(ucsi->connector[i].wq);
- }
-
- ucsi_unregister_partner(&ucsi->connector[i]);
- ucsi_unregister_altmodes(&ucsi->connector[i],
- UCSI_RECIPIENT_CON);
- ucsi_unregister_port_psy(&ucsi->connector[i]);
-
- usb_power_delivery_unregister_capabilities(ucsi->connector[i].port_sink_caps);
- ucsi->connector[i].port_sink_caps = NULL;
- usb_power_delivery_unregister_capabilities(ucsi->connector[i].port_source_caps);
- ucsi->connector[i].port_source_caps = NULL;
- usb_power_delivery_unregister(ucsi->connector[i].pd);
- ucsi->connector[i].pd = NULL;
- typec_unregister_port(ucsi->connector[i].port);
+ ucsi_unregister_port(&ucsi->connector[i]);
lockdep_unregister_key(&ucsi->connector[i].lock_key);
}
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 428/438] drm/xe: Drop unused param from xe_device_create()
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (426 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 427/438] usb: typec: ucsi: Fix race condition and ordering in port unregistration Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 429/438] drm/xe: Move xe->info.force_execlist initialization Greg Kroah-Hartman
` (23 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michal Wajdeczko, Raag Jadav,
Gustavo Sousa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michal Wajdeczko <michal.wajdeczko@intel.com>
[ Upstream commit 8a09097b11ca4d436691f64c3cc0958006f36e33 ]
We never used or need anything from the struct pci_device_id there.
And while around, add simple kernel-doc for this function.
Signed-off-by: Michal Wajdeczko <michal.wajdeczko@intel.com>
Reviewed-by: Raag Jadav <raag.jadav@intel.com>
Reviewed-by: Gustavo Sousa <gustavo.sousa@intel.com>
Link: https://patch.msgid.link/20260526195452.20545-3-michal.wajdeczko@intel.com
Stable-dep-of: ba7fd1634228 ("drm/xe: Set TTM device beneficial_order to 9 (2M)")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_device.c | 11 +++++++++--
drivers/gpu/drm/xe/xe_device.h | 3 +--
drivers/gpu/drm/xe/xe_pci.c | 2 +-
3 files changed, 11 insertions(+), 5 deletions(-)
--- a/drivers/gpu/drm/xe/xe_device.c
+++ b/drivers/gpu/drm/xe/xe_device.c
@@ -435,8 +435,15 @@ static void xe_device_destroy(struct drm
ttm_device_fini(&xe->ttm);
}
-struct xe_device *xe_device_create(struct pci_dev *pdev,
- const struct pci_device_id *ent)
+/**
+ * xe_device_create() - Create a new &xe_device instance
+ * @pdev: the parent &pci_dev
+ *
+ * Allocate and initialize a device managed Xe device structure.
+ *
+ * Return: pointer to new &xe_device on success, or ERR_PTR on failure.
+ */
+struct xe_device *xe_device_create(struct pci_dev *pdev)
{
struct xe_device *xe;
int err;
--- a/drivers/gpu/drm/xe/xe_device.h
+++ b/drivers/gpu/drm/xe/xe_device.h
@@ -43,8 +43,7 @@ static inline struct xe_device *ttm_to_x
return container_of(ttm, struct xe_device, ttm);
}
-struct xe_device *xe_device_create(struct pci_dev *pdev,
- const struct pci_device_id *ent);
+struct xe_device *xe_device_create(struct pci_dev *pdev);
int xe_device_probe_early(struct xe_device *xe);
int xe_device_probe(struct xe_device *xe);
void xe_device_remove(struct xe_device *xe);
--- a/drivers/gpu/drm/xe/xe_pci.c
+++ b/drivers/gpu/drm/xe/xe_pci.c
@@ -1091,7 +1091,7 @@ static int xe_pci_probe(struct pci_dev *
if (err)
return err;
- xe = xe_device_create(pdev, ent);
+ xe = xe_device_create(pdev);
if (IS_ERR(xe))
return PTR_ERR(xe);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 429/438] drm/xe: Move xe->info.force_execlist initialization
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (427 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 428/438] drm/xe: Drop unused param from xe_device_create() Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 430/438] drm/xe: Move xe->info.devid|revid initialization Greg Kroah-Hartman
` (22 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michal Wajdeczko, Gustavo Sousa,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michal Wajdeczko <michal.wajdeczko@intel.com>
[ Upstream commit f1d581bb50ed54b71a8121d3d46fe2627fddd147 ]
The xe_info_init_early() is a place where we initialize those of
the xe->info fields that do not require any additional hardware
probes. Move the initialization of the force_execlist flag there.
Signed-off-by: Michal Wajdeczko <michal.wajdeczko@intel.com>
Reviewed-by: Gustavo Sousa <gustavo.sousa@intel.com>
Link: https://patch.msgid.link/20260526195452.20545-4-michal.wajdeczko@intel.com
Stable-dep-of: ba7fd1634228 ("drm/xe: Set TTM device beneficial_order to 9 (2M)")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_device.c | 1 -
drivers/gpu/drm/xe/xe_pci.c | 1 +
2 files changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/xe/xe_device.c
+++ b/drivers/gpu/drm/xe/xe_device.c
@@ -475,7 +475,6 @@ struct xe_device *xe_device_create(struc
xe->info.devid = pdev->device;
xe->info.revid = pdev->revision;
- xe->info.force_execlist = xe_modparam.force_execlist;
xe->atomic_svm_timeslice_ms = 5;
xe->min_run_period_lr_ms = 5;
--- a/drivers/gpu/drm/xe/xe_pci.c
+++ b/drivers/gpu/drm/xe/xe_pci.c
@@ -774,6 +774,7 @@ static int xe_info_init_early(struct xe_
xe->info.probe_display = IS_ENABLED(CONFIG_DRM_XE_DISPLAY) &&
xe_modparam.probe_display &&
desc->has_display;
+ xe->info.force_execlist = xe_modparam.force_execlist;
xe_assert(xe, desc->max_gt_per_tile > 0);
xe_assert(xe, desc->max_gt_per_tile <= XE_MAX_GT_PER_TILE);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 430/438] drm/xe: Move xe->info.devid|revid initialization
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (428 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 429/438] drm/xe: Move xe->info.force_execlist initialization Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 431/438] drm/xe: Separate early xe_device initialization Greg Kroah-Hartman
` (21 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michal Wajdeczko, Gustavo Sousa,
Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michal Wajdeczko <michal.wajdeczko@intel.com>
[ Upstream commit c03d9fbe77ec5002a2345b9be464683e0b157709 ]
The xe_info_init_early() is a place where we initialize those of
the xe->info fields that do not require any additional hardware
probes. Move the initialization of the devid/revid also there, but
to avoid breaking the kunit helper, which also calls this function,
keep their initialization separate in sub-function so we can easily
stub it when running the kunit test.
Signed-off-by: Michal Wajdeczko <michal.wajdeczko@intel.com>
Cc: Gustavo Sousa <gustavo.sousa@intel.com>
Reviewed-by: Gustavo Sousa <gustavo.sousa@intel.com>
Link: https://patch.msgid.link/20260526195452.20545-5-michal.wajdeczko@intel.com
Stable-dep-of: ba7fd1634228 ("drm/xe: Set TTM device beneficial_order to 9 (2M)")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/tests/xe_pci.c | 6 ++++++
drivers/gpu/drm/xe/xe_device.c | 2 --
drivers/gpu/drm/xe/xe_pci.c | 12 ++++++++++++
3 files changed, 18 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/xe/tests/xe_pci.c
+++ b/drivers/gpu/drm/xe/tests/xe_pci.c
@@ -310,6 +310,11 @@ const void *xe_pci_id_gen_param(struct k
}
EXPORT_SYMBOL_IF_KUNIT(xe_pci_id_gen_param);
+static void fake_init_devid(struct xe_device *xe)
+{
+ /* Nothing to do, just keep zero. */
+}
+
static int fake_read_gmdid(struct xe_device *xe, enum xe_gmdid_type type,
u32 *ver, u32 *revid)
{
@@ -368,6 +373,7 @@ done:
xe->sriov.__mode = data && data->sriov_mode ?
data->sriov_mode : XE_SRIOV_MODE_NONE;
+ kunit_activate_static_stub(test, init_devid, fake_init_devid);
kunit_activate_static_stub(test, read_gmdid, fake_read_gmdid);
kunit_activate_static_stub(test, xe_info_probe_tile_count,
fake_xe_info_probe_tile_count);
--- a/drivers/gpu/drm/xe/xe_device.c
+++ b/drivers/gpu/drm/xe/xe_device.c
@@ -473,8 +473,6 @@ struct xe_device *xe_device_create(struc
if (err)
return ERR_PTR(err);
- xe->info.devid = pdev->device;
- xe->info.revid = pdev->revision;
xe->atomic_svm_timeslice_ms = 5;
xe->min_run_period_lr_ms = 5;
--- a/drivers/gpu/drm/xe/xe_pci.c
+++ b/drivers/gpu/drm/xe/xe_pci.c
@@ -723,6 +723,16 @@ static int handle_gmdid(struct xe_device
return 0;
}
+static void init_devid(struct xe_device *xe)
+{
+ struct pci_dev *pdev = to_pci_dev(xe->drm.dev);
+
+ KUNIT_STATIC_STUB_REDIRECT(init_devid, xe);
+
+ xe->info.devid = pdev->device;
+ xe->info.revid = pdev->revision;
+}
+
/*
* Initialize device info content that only depends on static driver_data
* passed to the driver at probe time from PCI ID table.
@@ -738,6 +748,8 @@ static int xe_info_init_early(struct xe_
xe->info.subplatform = subplatform_desc ?
subplatform_desc->subplatform : XE_SUBPLATFORM_NONE;
+ init_devid(xe);
+
xe->info.dma_mask_size = desc->dma_mask_size;
xe->info.va_bits = desc->va_bits;
xe->info.vm_max_level = desc->vm_max_level;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 431/438] drm/xe: Separate early xe_device initialization
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (429 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 430/438] drm/xe: Move xe->info.devid|revid initialization Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 432/438] drm/xe: Set TTM device beneficial_order to 9 (2M) Greg Kroah-Hartman
` (20 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michal Wajdeczko, Raag Jadav,
Gustavo Sousa, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michal Wajdeczko <michal.wajdeczko@intel.com>
[ Upstream commit 2841cea001b983db79dc1fdf160e65318dfda3cd ]
We would like to initialize more of the xe_device struct also from
the kunit code, as it should be safe to use most of the generic drm
or xe components without doing any additional tweaks. Separate early
xe initialization code to a new function, so it can be reused.
Signed-off-by: Michal Wajdeczko <michal.wajdeczko@intel.com>
Reviewed-by: Raag Jadav <raag.jadav@intel.com>
Reviewed-by: Gustavo Sousa <gustavo.sousa@intel.com>
Link: https://patch.msgid.link/20260526195452.20545-6-michal.wajdeczko@intel.com
Stable-dep-of: ba7fd1634228 ("drm/xe: Set TTM device beneficial_order to 9 (2M)")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_device.c | 39 ++++++++++++++++++++++++++++-----------
drivers/gpu/drm/xe/xe_device.h | 1 +
2 files changed, 29 insertions(+), 11 deletions(-)
--- a/drivers/gpu/drm/xe/xe_device.c
+++ b/drivers/gpu/drm/xe/xe_device.c
@@ -458,27 +458,45 @@ struct xe_device *xe_device_create(struc
if (IS_ERR(xe))
return xe;
+ err = xe_device_init_early(xe);
+ if (err)
+ return ERR_PTR(err);
+
+ return xe;
+}
+ALLOW_ERROR_INJECTION(xe_device_create, ERRNO); /* See xe_pci_probe() */
+
+/**
+ * xe_device_init_early() - Initialize a new &xe_device instance
+ * @xe: the &xe_device to initialize
+ *
+ * Return: 0 on success or a negative error code on failure.
+ */
+int xe_device_init_early(struct xe_device *xe)
+{
+ int err;
+
err = ttm_device_init(&xe->ttm, &xe_ttm_funcs, xe->drm.dev,
xe->drm.anon_inode->i_mapping,
xe->drm.vma_offset_manager, 0);
- if (WARN_ON(err))
- return ERR_PTR(err);
+ if (err)
+ return err;
xe_bo_dev_init(&xe->bo_device);
err = drmm_add_action_or_reset(&xe->drm, xe_device_destroy, NULL);
if (err)
- return ERR_PTR(err);
+ return err;
err = xe_shrinker_create(xe);
if (err)
- return ERR_PTR(err);
+ return err;
xe->atomic_svm_timeslice_ms = 5;
xe->min_run_period_lr_ms = 5;
err = xe_irq_init(xe);
if (err)
- return ERR_PTR(err);
+ return err;
xe_validation_device_init(&xe->val);
@@ -488,7 +506,7 @@ struct xe_device *xe_device_create(struc
err = xe_pagemap_shrinker_create(xe);
if (err)
- return ERR_PTR(err);
+ return err;
xa_init_flags(&xe->usm.asid_to_vm, XA_FLAGS_ALLOC);
@@ -507,7 +525,7 @@ struct xe_device *xe_device_create(struc
err = xe_bo_pinned_init(xe);
if (err)
- return ERR_PTR(err);
+ return err;
xe->preempt_fence_wq = alloc_ordered_workqueue("xe-preempt-fence-wq",
WQ_MEM_RECLAIM);
@@ -521,16 +539,15 @@ struct xe_device *xe_device_create(struc
* drmm_add_action_or_reset register above
*/
drm_err(&xe->drm, "Failed to allocate xe workqueues\n");
- return ERR_PTR(-ENOMEM);
+ return -ENOMEM;
}
err = drmm_mutex_init(&xe->drm, &xe->pmt.lock);
if (err)
- return ERR_PTR(err);
+ return err;
- return xe;
+ return 0;
}
-ALLOW_ERROR_INJECTION(xe_device_create, ERRNO); /* See xe_pci_probe() */
static bool xe_driver_flr_disabled(struct xe_device *xe)
{
--- a/drivers/gpu/drm/xe/xe_device.h
+++ b/drivers/gpu/drm/xe/xe_device.h
@@ -44,6 +44,7 @@ static inline struct xe_device *ttm_to_x
}
struct xe_device *xe_device_create(struct pci_dev *pdev);
+int xe_device_init_early(struct xe_device *xe);
int xe_device_probe_early(struct xe_device *xe);
int xe_device_probe(struct xe_device *xe);
void xe_device_remove(struct xe_device *xe);
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 432/438] drm/xe: Set TTM device beneficial_order to 9 (2M)
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (430 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 431/438] drm/xe: Separate early xe_device initialization Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 433/438] drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] Greg Kroah-Hartman
` (19 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Brost, Andi Shyti,
Thomas Hellström, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Brost <matthew.brost@intel.com>
[ Upstream commit ba7fd163422877ad5a5cf31306a38c07d3932b0c ]
Set the TTM device beneficial_order to 9 (2M), which is the sweet
spot for Xe when attempting reclaim on system memory BOs, as it matches
the large GPU page size. This ensures reclaim is attempted at the most
effective order for the driver.
This fixes an issue where an order-10 (4M) allocation cannot be found
despite an abundance of memory. The 4M allocation triggers reclaim,
unnecessarily evicting the working set and hurting performance. Since
the TTM infrastructure was introduced recently, we are tagging the TTM
patch as the Fixes target, even though this resolves an Xe-side problem.
Fixes: 7e9c548d3709 ("drm/ttm: Allow drivers to specify maximum beneficial TTM pool size")
Cc: stable@vger.kernel.org
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Andi Shyti <andi.shyti@linux.intel.com>
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Link: https://patch.msgid.link/20260611235844.3725147-1-matthew.brost@intel.com
(cherry picked from commit 0d81db90d364cb3d733410829118759f28957c5a)
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_device.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/xe/xe_device.c
+++ b/drivers/gpu/drm/xe/xe_device.c
@@ -478,7 +478,8 @@ int xe_device_init_early(struct xe_devic
err = ttm_device_init(&xe->ttm, &xe_ttm_funcs, xe->drm.dev,
xe->drm.anon_inode->i_mapping,
- xe->drm.vma_offset_manager, 0);
+ xe->drm.vma_offset_manager,
+ TTM_ALLOCATION_POOL_BENEFICIAL_ORDER(get_order(SZ_2M)));
if (err)
return err;
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 433/438] drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (431 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 432/438] drm/xe: Set TTM device beneficial_order to 9 (2M) Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 434/438] drm/xe: Wait on external BO kernel fences in exec IOCTL Greg Kroah-Hartman
` (18 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Hellström,
Christian König, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Hellström <thomas.hellstrom@linux.intel.com>
[ Upstream commit ce44b78512e9102aea54ff6b6e521d6c8de9f31c ]
Nobody makes any use of it. Possible internal future users can
instead use the _index variable. External users shouldn't use
it since the array it's pointing into is internal drm_exec state.
v2:
- Use a unique id for the loop variable (Christian)
Assisted-by: GitHub Copilot:claude-sonnet-4.6
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Link: https://patch.msgid.link/20260520101616.41284-2-thomas.hellstrom@linux.intel.com
Stable-dep-of: af80e2bfde93 ("drm/xe: Wait on external BO kernel fences in exec IOCTL")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c | 9 +++------
drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c | 3 +--
drivers/gpu/drm/drm_exec.c | 6 ++----
drivers/gpu/drm/drm_gpuvm.c | 3 +--
drivers/gpu/drm/xe/xe_vm.c | 3 +--
include/drm/drm_exec.h | 20 ++++++++++++--------
6 files changed, 20 insertions(+), 24 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c
@@ -854,7 +854,6 @@ static int amdgpu_cs_parser_bos(struct a
struct amdgpu_vm *vm = &fpriv->vm;
struct amdgpu_bo_list_entry *e;
struct drm_gem_object *obj;
- unsigned long index;
unsigned int i;
int r;
@@ -965,7 +964,7 @@ static int amdgpu_cs_parser_bos(struct a
goto out_free_user_pages;
}
- drm_exec_for_each_locked_object(&p->exec, index, obj) {
+ drm_exec_for_each_locked_object(&p->exec, obj) {
r = amdgpu_cs_bo_validate(p, gem_to_amdgpu_bo(obj));
if (unlikely(r))
goto out_free_user_pages;
@@ -1191,7 +1190,6 @@ static int amdgpu_cs_sync_rings(struct a
struct drm_gpu_scheduler *sched;
struct drm_gem_object *obj;
struct dma_fence *fence;
- unsigned long index;
unsigned int i;
int r;
@@ -1202,7 +1200,7 @@ static int amdgpu_cs_sync_rings(struct a
return r;
}
- drm_exec_for_each_locked_object(&p->exec, index, obj) {
+ drm_exec_for_each_locked_object(&p->exec, obj) {
struct amdgpu_bo *bo = gem_to_amdgpu_bo(obj);
struct dma_resv *resv = bo->tbo.base.resv;
@@ -1271,7 +1269,6 @@ static int amdgpu_cs_submit(struct amdgp
struct amdgpu_vm *vm = &fpriv->vm;
struct amdgpu_bo_list_entry *e;
struct drm_gem_object *gobj;
- unsigned long index;
unsigned int i;
uint64_t seq;
int r;
@@ -1322,7 +1319,7 @@ static int amdgpu_cs_submit(struct amdgp
}
p->fence = dma_fence_get(&leader->base.s_fence->finished);
- drm_exec_for_each_locked_object(&p->exec, index, gobj) {
+ drm_exec_for_each_locked_object(&p->exec, gobj) {
ttm_bo_move_to_lru_tail_unlocked(&gem_to_amdgpu_bo(gobj)->tbo);
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c
@@ -121,7 +121,6 @@ int amdgpu_evf_mgr_rearm(struct amdgpu_e
{
struct amdgpu_eviction_fence *ev_fence;
struct drm_gem_object *obj;
- unsigned long index;
/* Create and initialize a new eviction fence */
ev_fence = kzalloc_obj(*ev_fence);
@@ -140,7 +139,7 @@ int amdgpu_evf_mgr_rearm(struct amdgpu_e
evf_mgr->ev_fence = &ev_fence->base;
/* And add it to all existing BOs */
- drm_exec_for_each_locked_object(exec, index, obj) {
+ drm_exec_for_each_locked_object(exec, obj) {
struct amdgpu_bo *bo = gem_to_amdgpu_bo(obj);
amdgpu_evf_mgr_attach_fence(evf_mgr, bo);
--- a/drivers/gpu/drm/drm_exec.c
+++ b/drivers/gpu/drm/drm_exec.c
@@ -24,7 +24,6 @@
*
* struct drm_gem_object *obj;
* struct drm_exec exec;
- * unsigned long index;
* int ret;
*
* drm_exec_init(&exec, DRM_EXEC_INTERRUPTIBLE_WAIT);
@@ -40,7 +39,7 @@
* goto error;
* }
*
- * drm_exec_for_each_locked_object(&exec, index, obj) {
+ * drm_exec_for_each_locked_object(&exec, obj) {
* dma_resv_add_fence(obj->resv, fence, DMA_RESV_USAGE_READ);
* ...
* }
@@ -56,9 +55,8 @@
static void drm_exec_unlock_all(struct drm_exec *exec)
{
struct drm_gem_object *obj;
- unsigned long index;
- drm_exec_for_each_locked_object_reverse(exec, index, obj) {
+ drm_exec_for_each_locked_object_reverse(exec, obj) {
dma_resv_unlock(obj->resv);
drm_gem_object_put(obj);
}
--- a/drivers/gpu/drm/drm_gpuvm.c
+++ b/drivers/gpu/drm/drm_gpuvm.c
@@ -1557,9 +1557,8 @@ drm_gpuvm_resv_add_fence(struct drm_gpuv
enum dma_resv_usage extobj_usage)
{
struct drm_gem_object *obj;
- unsigned long index;
- drm_exec_for_each_locked_object(exec, index, obj) {
+ drm_exec_for_each_locked_object(exec, obj) {
dma_resv_assert_held(obj->resv);
dma_resv_add_fence(obj->resv, fence,
drm_gpuvm_is_extobj(gpuvm, obj) ?
--- a/drivers/gpu/drm/xe/xe_vm.c
+++ b/drivers/gpu/drm/xe/xe_vm.c
@@ -373,7 +373,6 @@ int xe_vm_validate_rebind(struct xe_vm *
unsigned int num_fences)
{
struct drm_gem_object *obj;
- unsigned long index;
int ret;
do {
@@ -386,7 +385,7 @@ int xe_vm_validate_rebind(struct xe_vm *
return ret;
} while (!list_empty(&vm->gpuvm.evict.list));
- drm_exec_for_each_locked_object(exec, index, obj) {
+ drm_exec_for_each_locked_object(exec, obj) {
ret = dma_resv_reserve_fences(obj->resv, num_fences);
if (ret)
return ret;
--- a/include/drm/drm_exec.h
+++ b/include/drm/drm_exec.h
@@ -65,31 +65,35 @@ drm_exec_obj(struct drm_exec *exec, unsi
return index < exec->num_objects ? exec->objects[index] : NULL;
}
+/* Helper for drm_exec_for_each_locked_object(). Internal use only. */
+#define __drm_exec_for_each_locked_object(exec, obj, __index) \
+ for (unsigned long __index = 0; ((obj) = drm_exec_obj(exec, __index)); ++__index)
/**
* drm_exec_for_each_locked_object - iterate over all the locked objects
* @exec: drm_exec object
- * @index: unsigned long index for the iteration
* @obj: the current GEM object
*
* Iterate over all the locked GEM objects inside the drm_exec object.
*/
-#define drm_exec_for_each_locked_object(exec, index, obj) \
- for ((index) = 0; ((obj) = drm_exec_obj(exec, index)); ++(index))
+#define drm_exec_for_each_locked_object(exec, obj) \
+ __drm_exec_for_each_locked_object(exec, obj, __UNIQUE_ID(drm_exec))
+/* Helper for drm_exec_for_each_locked_object_reverse(). Internal use only. */
+#define __drm_exec_for_each_locked_object_reverse(exec, obj, __index) \
+ for (unsigned long __index = (exec)->num_objects - 1; \
+ ((obj) = drm_exec_obj(exec, __index)); --__index)
/**
* drm_exec_for_each_locked_object_reverse - iterate over all the locked
* objects in reverse locking order
* @exec: drm_exec object
- * @index: unsigned long index for the iteration
* @obj: the current GEM object
*
* Iterate over all the locked GEM objects inside the drm_exec object in
- * reverse locking order. Note that @index may go below zero and wrap,
+ * reverse locking order. Note that the internal index may wrap around,
* but that will be caught by drm_exec_obj(), returning a NULL object.
*/
-#define drm_exec_for_each_locked_object_reverse(exec, index, obj) \
- for ((index) = (exec)->num_objects - 1; \
- ((obj) = drm_exec_obj(exec, index)); --(index))
+#define drm_exec_for_each_locked_object_reverse(exec, obj) \
+ __drm_exec_for_each_locked_object_reverse(exec, obj, __UNIQUE_ID(drm_exec))
/**
* drm_exec_until_all_locked - loop until all GEM objects are locked
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 434/438] drm/xe: Wait on external BO kernel fences in exec IOCTL
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (432 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 433/438] drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 435/438] media: chips-media: wave5: Support CBP profile Greg Kroah-Hartman
` (17 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Brost, Matthew Auld,
Thomas Hellström, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Brost <matthew.brost@intel.com>
[ Upstream commit af80e2bfde9312c76b60cf9274248dce0410b30d ]
Before arming a user job, xe_exec_ioctl() only added the VM's
dma-resv KERNEL slot as a dependency. That slot covers rebinds and
the kernel operations of the VM's private BOs, but not external BOs
(bo->vm == NULL), which carry their kernel operations (evictions,
moves, ...) in their own dma-resv KERNEL slot.
The DMA_RESV_USAGE_KERNEL slot is the cross-driver contract for
memory management operations that must complete before the BO or its
backing store may be used: any accessor is required to wait on the
KERNEL fences before touching the resv. By skipping the external BOs'
KERNEL slots, the exec path violated that contract and could schedule
a user job while a kernel operation on an external BO mapped by the VM
was still in flight, racing against it and potentially reading or
writing memory that was being moved.
Replace the VM-only dependency with an iteration over every object
locked by the exec, adding each object's KERNEL slot as a job
dependency. This covers the VM resv (rebinds and private BOs) as well
as every external BO, mirroring the drm_gpuvm_resv_add_fence() call
that later publishes the job fence to the same set of objects.
Long-running mode continues to skip this, as before.
Fixes: dd08ebf6c352 ("drm/xe: Introduce a new DRM driver for Intel GPUs")
Cc: stable@vger.kernel.org
Assisted-by: GitHub_Copilot:claude-opus-4.8
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260702215805.4011228-1-matthew.brost@intel.com
(cherry picked from commit a6b842acf3ddd1efc53a56de9260cfa718fb35e7)
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_exec.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
--- a/drivers/gpu/drm/xe/xe_exec.c
+++ b/drivers/gpu/drm/xe/xe_exec.c
@@ -292,13 +292,23 @@ retry:
goto err_exec;
}
- /* Wait behind rebinds */
+ /*
+ * Wait behind rebinds and any kernel operations (evictions, defrag
+ * moves, ...) on the VM and all external BOs. The VM's private BOs
+ * carry their kernel ops in the VM dma-resv KERNEL slot, while each
+ * external BO carries them in its own dma-resv KERNEL slot; both are
+ * covered by iterating every object locked by the exec, mirroring the
+ * drm_gpuvm_resv_add_fence() below.
+ */
if (!xe_vm_in_lr_mode(vm)) {
- err = xe_sched_job_add_deps(job,
- xe_vm_resv(vm),
- DMA_RESV_USAGE_KERNEL);
- if (err)
- goto err_put_job;
+ struct drm_gem_object *obj;
+
+ drm_exec_for_each_locked_object(exec, obj) {
+ err = xe_sched_job_add_deps(job, obj->resv,
+ DMA_RESV_USAGE_KERNEL);
+ if (err)
+ goto err_put_job;
+ }
}
for (i = 0; i < num_syncs && !err; i++)
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 435/438] media: chips-media: wave5: Support CBP profile
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (433 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 434/438] drm/xe: Wait on external BO kernel fences in exec IOCTL Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 436/438] drm/amd/display: check GRPH_FLIP status before sending event Greg Kroah-Hartman
` (16 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
Brandon Brnich, Nicolas Dufresne, Hans Verkuil, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jackson Lee <jackson.lee@chipsnmedia.com>
[ Upstream commit f8505f9d6b223a26854003bfdba1a0772457886d ]
Constrained Baseline Profile (CBP) and Baseline Profile (BP) have been
treated as the same.
Introduce the ability to differentiate between the two.
Fixes: 9707a6254a8a ("media: chips-media: wave5: Add the v4l2 layer")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Tested-by: Brandon Brnich <b-brnich@ti.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/media/platform/chips-media/wave5/wave5-hw.c | 3 +++
drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c | 5 ++++-
drivers/media/platform/chips-media/wave5/wave5-vpuapi.h | 1 +
3 files changed, 8 insertions(+), 1 deletion(-)
--- a/drivers/media/platform/chips-media/wave5/wave5-hw.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-hw.c
@@ -1762,6 +1762,9 @@ int wave5_vpu_enc_init_seq(struct vpu_in
(p_param->skip_intra_trans << 25) |
(p_param->strong_intra_smooth_enable << 27) |
(p_param->en_still_picture << 30);
+ else if (inst->std == W_AVC_ENC)
+ reg_val |= (p_param->constraint_set1_flag << 29);
+
vpu_write_reg(inst->dev, W5_CMD_ENC_SEQ_SPS_PARAM, reg_val);
reg_val = (p_param->lossless_enable) |
--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c
@@ -915,6 +915,8 @@ static int wave5_vpu_enc_s_ctrl(struct v
case V4L2_MPEG_VIDEO_H264_PROFILE_CONSTRAINED_BASELINE:
inst->enc_param.profile = H264_PROFILE_BP;
inst->bit_depth = 8;
+ if (ctrl->val == V4L2_MPEG_VIDEO_H264_PROFILE_CONSTRAINED_BASELINE)
+ inst->enc_param.constraint_set1_flag = 1;
break;
case V4L2_MPEG_VIDEO_H264_PROFILE_MAIN:
inst->enc_param.profile = H264_PROFILE_MP;
@@ -1190,6 +1192,7 @@ static int wave5_set_enc_openparam(struc
open_param->wave_param.intra_period = input.avc_idr_period;
}
} else {
+ open_param->wave_param.constraint_set1_flag = input.constraint_set1_flag;
open_param->wave_param.avc_idr_period = input.avc_idr_period;
}
open_param->wave_param.entropy_coding_mode = input.entropy_coding_mode;
@@ -1662,7 +1665,7 @@ static int wave5_vpu_open_enc(struct fil
-6, 6, 1, 0);
v4l2_ctrl_new_std(v4l2_ctrl_hdl, &wave5_vpu_enc_ctrl_ops,
V4L2_CID_MPEG_VIDEO_H264_8X8_TRANSFORM,
- 0, 1, 1, 1);
+ 0, 1, 1, 0);
v4l2_ctrl_new_std(v4l2_ctrl_hdl, &wave5_vpu_enc_ctrl_ops,
V4L2_CID_MPEG_VIDEO_H264_CONSTRAINED_INTRA_PREDICTION,
0, 1, 1, 0);
--- a/drivers/media/platform/chips-media/wave5/wave5-vpuapi.h
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpuapi.h
@@ -570,6 +570,7 @@ struct enc_wave_param {
u32 transform8x8_enable: 1; /* enable 8x8 intra prediction and 8x8 transform */
u32 mb_level_rc_enable: 1; /* enable MB-level rate control */
u32 forced_idr_header_enable: 1; /* enable header encoding before IDR frame */
+ u32 constraint_set1_flag: 1; /* enable CBP */
};
struct enc_open_param {
^ permalink raw reply [flat|nested] 456+ messages in thread
* [PATCH 7.1 436/438] drm/amd/display: check GRPH_FLIP status before sending event
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (434 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 435/438] media: chips-media: wave5: Support CBP profile Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 437/438] drm/amd/display: Exit idle optimizations before programming Greg Kroah-Hartman
` (15 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Leo Li,
Alex Deucher, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Li <sunpeng.li@amd.com>
[ Upstream commit 48ab86360af117123eb1b15e38f068acf3826400 ]
[Why]
After unifying DCN interrupt sources under VUPDATE_NO_LOCK, we have two
remaining issues to clean up:
1. On DCN, flip completion is now delivered from VUPDATE_NO_LOCK
(dm_crtc_high_irq_handler) instead of GRPH_PFLIP. But VUPDATE_NO_LOCK
fires every frame, regardless of whether a flip has latched.
2. There is a window during commit where a flip is armed (pflip_status =
SUBMITTED) but not yet programmed into HW. If the VUPDATE_NO_LOCK
fires in that window, its handler would deliver a flip event to
userspace before HW has latched to it. If userspace then renders to
what it believes is now the back buffer (but HW is still latched to
it!), it will cause display corruption. This issue seemed to have
been introduced by:
commit 1159898a88db ("drm/amd/display: Handle commit plane with no FB.")
Enabling replay or psr extended the duration of this window, and
hence made corruption more likely to be observed.
[How]
* Move acrtc->event/pflip_status arming to after
update_planes_and_stream_adapter() has programmed the flip into HW.
This closes the window where pflip_status is SUBMITTED but the flip is
not yet programmed.
* Add dc_get_flip_pending_on_otg(), which reads the HUBP flip-pending
status straight from HW for the pipe(s) bound to an OTG instance. It
is keyed only by otg_inst and does not take or mutate a
dc_plane_state, so it is safe to call from the OTG interrupt handler
without racing a concurrent commit that may be modifying plane state.
* Optimistically query for flip-pending after programming, in the event
that HW latched to the new fb between programming start and arming
event. If it latched, send the vblank event immediately, rather than
wait for the next vblank IRQ.
* In the VUPDATE_NO_LOCK handler, only deliver flip completion once
dc_get_flip_pending_on_otg() reports the flip is no longer pending.
Otherwise leave the flip armed and retry on the next vupdate.
* For DCE, maintain the existing behavior of arming flips before
programming, and relying on GRPH_FLIP to fire at HW latch.
v2:
* Drop flip_programmed completion object, instead move
event/pflip_status arming after programming.
* For DCN, optimistically query for flip pending immediately after
programming, and if it latched, send event right away.
v3:
* Fix event timestamps on optimistic flip latch detection, where it's
possible for it to run *before* the vupdate IRQ updates the timestamp.
* Add more docstrings for DCN vblank handling.
* Clean up if conditions in dm_arm_vblank_event().
* Code style cleanup on braces surrounding multi-line statements.
Fixes: 9b47278cec98 ("drm/amd/display: temp w/a for dGPU to enter idle optimizations")
Link: https://gitlab.freedesktop.org/drm/amd/-/work_items/3787
Link: https://gitlab.freedesktop.org/drm/amd/-/work_items/4141
Assisted-by: Copilot:claude-opus-4.8
Tested-by: Mario Limonciello (AMD) <superm1@kernel.org>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Leo Li <sunpeng.li@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f64a9be5653689ff43e148cd8a6483077488c8e5)
Cc: stable@vger.kernel.org # 8382cd234981: drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
Cc: stable@vger.kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 191 ++++++++++++++----
drivers/gpu/drm/amd/display/dc/core/dc.c | 45 +++++
drivers/gpu/drm/amd/display/dc/dc.h | 1 +
3 files changed, 197 insertions(+), 40 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index 93cd70183c188..11affddbb2650 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -677,13 +677,30 @@ static void dm_crtc_high_irq_handler(struct amdgpu_device *adev,
* Deliver pageflip completion events (DCN only).
*
* Since GRPH_PFLIP is not used, VUPDATE_NO_LOCK is the flip latch
- * point. Deliver any pending pageflip completion event from here.
+ * point. Deliver any pending pageflip completion event from here,
+ * once HW has consumed the new address (the OTG no longer reports a
+ * pending flip).
*
- * NOTE: This can deliver an event for a flip that was armed but not yet
- * programmed into HW; that race is closed in a follow-up change by
- * checking the programmed flip status.
+ * Also handle the case here where there aren't any active planes and
+ * DCN HUBP may be clock-gated, so the flip-pending status may be
+ * undefined.
*/
- if (is_dcn && acrtc->pflip_status == AMDGPU_FLIP_SUBMITTED) {
+ if (is_dcn && acrtc->pflip_status == AMDGPU_FLIP_SUBMITTED &&
+ acrtc->event) {
+
+ if (!dc_get_flip_pending_on_otg(adev->dm.dc, acrtc->otg_inst)) {
+ drm_crtc_send_vblank_event(&acrtc->base, acrtc->event);
+ acrtc->event = NULL;
+ drm_crtc_vblank_put(&acrtc->base);
+ acrtc->pflip_status = AMDGPU_FLIP_NONE;
+ }
+ /*
+ * If the flip is still pending, leave it armed and
+ * retry on the next vupdate.
+ */
+ } else if (is_dcn && acrtc->pflip_status == AMDGPU_FLIP_SUBMITTED &&
+ acrtc->dm_irq_params.active_planes == 0) {
+
if (acrtc->event) {
drm_crtc_send_vblank_event(&acrtc->base, acrtc->event);
acrtc->event = NULL;
@@ -9995,6 +10012,28 @@ static void amdgpu_dm_enable_self_refresh(struct amdgpu_crtc *acrtc_attach,
}
}
+static void dm_arm_vblank_event(struct amdgpu_crtc *acrtc,
+ struct dm_crtc_state *acrtc_state,
+ bool pflip_update,
+ bool cursor_update)
+{
+ assert_spin_locked(&acrtc->base.dev->event_lock);
+
+ if (!acrtc->base.state->event || acrtc_state->active_planes == 0)
+ return;
+
+ if (pflip_update) {
+ drm_crtc_vblank_get(&acrtc->base);
+ WARN_ON(acrtc->pflip_status != AMDGPU_FLIP_NONE);
+ /* Arm flip completion handling and event delivery after programming. */
+ prepare_flip_isr(acrtc);
+ } else if (cursor_update) {
+ drm_crtc_vblank_get(&acrtc->base);
+ acrtc->event = acrtc->base.state->event;
+ acrtc->base.state->event = NULL;
+ }
+}
+
static void amdgpu_dm_commit_planes(struct drm_atomic_state *state,
struct drm_device *dev,
struct amdgpu_display_manager *dm,
@@ -10018,6 +10057,7 @@ static void amdgpu_dm_commit_planes(struct drm_atomic_state *state,
bool cursor_update = false;
bool pflip_present = false;
bool immediate_flip = false;
+ bool flip_latched_during_prog = false;
bool dirty_rects_changed = false;
bool updated_planes_and_streams = false;
struct {
@@ -10254,39 +10294,24 @@ static void amdgpu_dm_commit_planes(struct drm_atomic_state *state,
usleep_range(1000, 1100);
}
- /**
- * Prepare the flip event for the pageflip interrupt to handle.
- *
- * This only works in the case where we've already turned on the
- * appropriate hardware blocks (eg. HUBP) so in the transition case
- * from 0 -> n planes we have to skip a hardware generated event
- * and rely on sending it from software.
- */
- if (acrtc_attach->base.state->event &&
- acrtc_state->active_planes > 0) {
- drm_crtc_vblank_get(pcrtc);
-
- spin_lock_irqsave(&pcrtc->dev->event_lock, flags);
-
- WARN_ON(acrtc_attach->pflip_status != AMDGPU_FLIP_NONE);
- prepare_flip_isr(acrtc_attach);
-
- spin_unlock_irqrestore(&pcrtc->dev->event_lock, flags);
- }
-
if (acrtc_state->stream) {
if (acrtc_state->freesync_vrr_info_changed)
bundle->stream_update.vrr_infopacket =
&acrtc_state->stream->vrr_infopacket;
}
- } else if (cursor_update && acrtc_state->active_planes > 0) {
- spin_lock_irqsave(&pcrtc->dev->event_lock, flags);
- if (acrtc_attach->base.state->event) {
- drm_crtc_vblank_get(pcrtc);
- acrtc_attach->event = acrtc_attach->base.state->event;
- acrtc_attach->base.state->event = NULL;
+ }
+
+ /*
+ * DCE depends on a combination of GRPH_FLIP, VLINE0, and VUPDATE for
+ * event delivery. Only GRPH_FLIP handler can send pflip events, and it
+ * only fires if HW latched to the flip. Maintain legacy behavior by
+ * arming event before programming.
+ */
+ if (amdgpu_ip_version(dm->adev, DCE_HWIP, 0) == 0) {
+ scoped_guard(spinlock_irqsave, &pcrtc->dev->event_lock) {
+ dm_arm_vblank_event(acrtc_attach, acrtc_state,
+ pflip_present, cursor_update);
}
- spin_unlock_irqrestore(&pcrtc->dev->event_lock, flags);
}
/* Update the planes if changed or disable if we don't have any. */
@@ -10388,17 +10413,103 @@ static void amdgpu_dm_commit_planes(struct drm_atomic_state *state,
amdgpu_dm_commit_cursors(state);
/*
- * On DCN, flip completion is normally delivered from VUPDATE_NO_LOCK.
- * However, an immediate (tearing / async) flip is latched by HW right
- * away and does not wait for the next vupdate, so deliver its
- * completion event here after programming.
+ * DCN specific vblank handling
+ * ============================
+ *
+ * With the event_lock held, arm the vblank event, and determine whether
+ * deliver it immediately, or in VUPDATE_NO_LOCK IRQ (i.e. HW latch
+ * point) handler. Do this *after* programming so that the IRQ handler
+ * will not deliver the event before HW laches onto the programmed
+ * values:
+ *
+ * Commit thread IRQ handler HW
+ * -----------------------------------------------------------------
+ * arm_vblank_event()
+ * vupdate()
+ * vupdate_handler()
+ * cook_timestamp()
+ * # prev flip already latched,
+ * # so flip_latched == true.
+ * if event_armed && flip_latched:
+ * send_vblank_event()
+ * # sent before latch, **BAD!**
+ * hw_program()
+ * vupdate()
+ * **latch**
+ *
+ * There's a consequence of arming after: it's possible for HW to latch
+ * between start of HW programming and acrtc->event/pflip_status arming.
+ * When this happens, the IRQ handler will send the event on the next
+ * immediate latch point, even though HW has already latched. This is
+ * handled by optimistically checking for HW latch after programming,
+ * and if latched, send the event immediately:
*
- * On DCE, GRPH_PFLIP already fires immediately for immediate flips, so
- * this is DCN-only.
+ * Commit thread IRQ handler HW
+ * -----------------------------------------------------------------
+ * hw_program()
+ * vupdate()
+ * **latch**
+ * vupdate_handler()
+ * cook_timestamp()
+ * # event_armed == false
+ * # **no event sent!**
+ * arm_vblank_event()
+ * if flip_latched:
+ * **send_vblank_event()**
+ * disarm_vblank_event()
+ *
+ * The IRQ handler is expected to cook the timestamp, but we need to
+ * cook the timestamp before optimistic sending as well. That's because
+ * the following sequence is possible:
+ *
+ * Commit thread IRQ handler HW
+ * -----------------------------------------------------------------
+ * hw_program()
+ * arm_vblank_event()
+ * vupdate()
+ * **latch**
+ * if flip_latched:
+ * # Need cook before send!
+ * **cook_timestamp()**
+ * send_vblank_event()
+ * disarm_vblank_event()
+ * vupdate_handler()
+ * cook_timestamp()
+ * # event_armed == false
+ * # no event sent!
+ *
+ * Cooking twice is OK, since DRM scanout accurate timestamps report A)
+ * the previous vactive start if currently in vactive, or B) the next
+ * vactive start if currently in vblank (see &get_vblank_counter). 'A)'
+ * is what we want for the optimistic send, and for 'B)', we'll cook a
+ * timestamp no later than the next IRQ handler run.
+ *
+ * The more correct fix is to wrap programming and arming with the
+ * event_lock and thus serializing it with the IRQ handler. However,
+ * there are various sleep-waits within
+ * update_planes_and_stream_adapter() that makes spin locking illegal.
+ * And on full updates, it can take 1-2 frame-times to return (see
+ * commit_planes_for_stream).
+ *
+ * On DCE, GRPH_PFLIP IRQ is used and takes care of this.
*/
- if (immediate_flip && amdgpu_ip_version(dm->adev, DCE_HWIP, 0) != 0) {
+ if (amdgpu_ip_version(dm->adev, DCE_HWIP, 0) != 0) {
spin_lock_irqsave(&pcrtc->dev->event_lock, flags);
- if (acrtc_attach->pflip_status == AMDGPU_FLIP_SUBMITTED &&
+
+ if (updated_planes_and_streams) {
+ flip_latched_during_prog =
+ !dc_get_flip_pending_on_otg(dm->dc, acrtc_attach->otg_inst);
+ }
+
+ dm_arm_vblank_event(acrtc_attach, acrtc_state,
+ pflip_present, cursor_update);
+
+ /*
+ * Deliver the event immediately on immediate flip, or on a
+ * update that has already latched.
+ */
+ if ((immediate_flip || flip_latched_during_prog) &&
+ acrtc_attach->pflip_status == AMDGPU_FLIP_SUBMITTED &&
acrtc_attach->event) {
drm_crtc_accurate_vblank_count(&acrtc_attach->base);
drm_crtc_send_vblank_event(&acrtc_attach->base,
diff --git a/drivers/gpu/drm/amd/display/dc/core/dc.c b/drivers/gpu/drm/amd/display/dc/core/dc.c
index ec194dd3b7985..b58ea80a97659 100644
--- a/drivers/gpu/drm/amd/display/dc/core/dc.c
+++ b/drivers/gpu/drm/amd/display/dc/core/dc.c
@@ -5628,6 +5628,51 @@ void dc_interrupt_ack(struct dc *dc, enum dc_irq_source src)
dal_irq_service_ack(dc->res_pool->irqs, src);
}
+/*
+ * dc_get_flip_pending_on_otg() - Check if a GRPH_FLIP is still pending on OTG
+ *
+ * @dc: display core context @otg_inst: OTG instance to query
+ *
+ * Reads the HUBP flip-pending status for the pipe(s) bound to @otg_inst,
+ * returning true if any of them has not yet latched its programmed surface
+ * address.
+ *
+ * Unlike dc_plane_get_status(), this does not take or mutate a dc_plane_state,
+ * so it is safe to call from interrupt context without racing a concurrent
+ * commit that may be updating plane state.
+ *
+ * Return: true if a flip is still pending on the OTG, false otherwise.
+ */
+bool dc_get_flip_pending_on_otg(struct dc *dc, int otg_inst)
+{
+ bool flip_pending = false;
+ int i;
+
+ if (!dc || !dc->current_state)
+ return false;
+
+ dc_exit_ips_for_hw_access(dc);
+
+ for (i = 0; i < dc->res_pool->pipe_count; i++) {
+ struct pipe_ctx *pipe_ctx = &dc->current_state->res_ctx.pipe_ctx[i];
+ struct hubp *hubp = pipe_ctx->plane_res.hubp;
+
+ if (!pipe_ctx->plane_state || !pipe_ctx->stream_res.tg)
+ continue;
+
+ if (pipe_ctx->stream_res.tg->inst != otg_inst)
+ continue;
+
+ if (hubp && hubp->funcs->hubp_is_flip_pending &&
+ hubp->funcs->hubp_is_flip_pending(hubp)) {
+ flip_pending = true;
+ break;
+ }
+ }
+
+ return flip_pending;
+}
+
void dc_power_down_on_boot(struct dc *dc)
{
if (dc->ctx->dce_environment != DCE_ENV_VIRTUAL_HW &&
diff --git a/drivers/gpu/drm/amd/display/dc/dc.h b/drivers/gpu/drm/amd/display/dc/dc.h
index 61a28e287c1b9..65388a6926b63 100644
--- a/drivers/gpu/drm/amd/display/dc/dc.h
+++ b/drivers/gpu/drm/amd/display/dc/dc.h
@@ -2738,6 +2738,7 @@ enum dc_irq_source dc_interrupt_to_irq_source(
uint32_t ext_id);
bool dc_interrupt_set(struct dc *dc, enum dc_irq_source src, bool enable);
void dc_interrupt_ack(struct dc *dc, enum dc_irq_source src);
+bool dc_get_flip_pending_on_otg(struct dc *dc, int otg_inst);
enum dc_irq_source dc_get_hpd_irq_source_at_index(
struct dc *dc, uint32_t link_index);
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 437/438] drm/amd/display: Exit idle optimizations before programming
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (435 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 436/438] drm/amd/display: check GRPH_FLIP status before sending event Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 438/438] usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path Greg Kroah-Hartman
` (14 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Weber, Leo Li,
Mario Limonciello (AMD), Alex Deucher, Sasha Levin
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Li <sunpeng.li@amd.com>
[ Upstream commit 8419331e64d92a8de5fc4feef0e305f201fb8b33 ]
[Why]
We need to exit PSR/IPS before programming. Before calling DC for
programming in amdgpu_dm_commit_planes(), there's a
vblank_control_workqueue flush. This waits for IPS and PSR exit. (See
drm_vblank_on/off() > amdgpu_dm_crtc_set_vblank() --queue_work()->
amdgpu_dm_crtc_vblank_control_worker())
Prior to the tagged "Fixes:" change, drm_vblank_get() was called before
the workqueue flush. This ordering ensures that PSR exit occurred before
programming. After the "Fixes:" change, drm_vblank_get() is called after
the workqueue flush, leading to programming while idle optimizations are
still active. This can lead to incorrect flip_pending detection used by
vblank event delivery.
[How]
Split the vblank_get() component of `dm_arm_vblank_event()` into
`dm_arm_vblank_event_pre_programming()`, which is called before
programming. Call it before the vblank_control_workqueue flush.
Includes a drive-by cleanup of prepare_flip_isr(): the only caller is
dm_arm_vblank_event() and it's simple enough to roll-in.
v2: Fix checkpatch formatting warning on
drm_arm_vblank_event_pre_programming() arg alignment.
Fixes: 48ab86360af1 ("drm/amd/display: check GRPH_FLIP status before sending event")
Cc: stable@vger.kernel.org
Link: https://gitlab.freedesktop.org/drm/amd/-/work_items/4141#note_3583205
Link: https://gitlab.freedesktop.org/drm/amd/-/work_items/5527
Assisted-by: Codex:gpt-5.6-sol
Assisted-by: Claude:opus-5
Suggested-by: David Weber <weber.aulendorf@gmail.com>
Signed-off-by: Leo Li <sunpeng.li@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 05984e29520a28c27f5a2388742c957a6a87ee7a)
(cherry picked from commit 8419331e64d92a8de5fc4feef0e305f201fb8b33)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 78 +++++++++++--------
1 file changed, 46 insertions(+), 32 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index 11affddbb2650..40d82a3eeec05 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -9656,25 +9656,6 @@ static void remove_stream(struct amdgpu_device *adev,
acrtc->enabled = false;
}
-static void prepare_flip_isr(struct amdgpu_crtc *acrtc)
-{
-
- assert_spin_locked(&acrtc->base.dev->event_lock);
- WARN_ON(acrtc->event);
-
- acrtc->event = acrtc->base.state->event;
-
- /* Set the flip status */
- acrtc->pflip_status = AMDGPU_FLIP_SUBMITTED;
-
- /* Mark this event as consumed */
- acrtc->base.state->event = NULL;
-
- drm_dbg_state(acrtc->base.dev,
- "crtc:%d, pflip_stat:AMDGPU_FLIP_SUBMITTED\n",
- acrtc->crtc_id);
-}
-
static void update_freesync_state_on_stream(
struct amdgpu_display_manager *dm,
struct dm_crtc_state *new_crtc_state,
@@ -10023,17 +10004,47 @@ static void dm_arm_vblank_event(struct amdgpu_crtc *acrtc,
return;
if (pflip_update) {
- drm_crtc_vblank_get(&acrtc->base);
WARN_ON(acrtc->pflip_status != AMDGPU_FLIP_NONE);
- /* Arm flip completion handling and event delivery after programming. */
- prepare_flip_isr(acrtc);
+ WARN_ON(acrtc->event);
+
+ acrtc->pflip_status = AMDGPU_FLIP_SUBMITTED;
+ acrtc->event = acrtc->base.state->event;
+ acrtc->base.state->event = NULL;
+
+ drm_dbg_state(acrtc->base.dev,
+ "crtc:%d, pflip_stat:AMDGPU_FLIP_SUBMITTED\n",
+ acrtc->crtc_id);
} else if (cursor_update) {
- drm_crtc_vblank_get(&acrtc->base);
acrtc->event = acrtc->base.state->event;
acrtc->base.state->event = NULL;
}
}
+/**
+ * dm_arm_vblank_event_pre_programming - Prepare for programming
+ * @acrtc: The amdgpu CRTC to prepare
+ * @acrtc_state: The new CRTC state
+ * @pflip_update: Whether a page flip is being programmed
+ * @cursor_update: Whether a cursor update is being programmed
+ *
+ * Grab a reference on the vblank counter if a page flip or cursor update is to
+ * be programmed. Do this before programming so the HW is not in any
+ * idle-optimized state (such as PSR).
+ */
+static void dm_arm_vblank_event_pre_programming(struct amdgpu_crtc *acrtc,
+ struct dm_crtc_state *acrtc_state,
+ bool pflip_update,
+ bool cursor_update)
+{
+ assert_spin_locked(&acrtc->base.dev->event_lock);
+
+ if (!acrtc->base.state->event || acrtc_state->active_planes == 0)
+ return;
+
+ if (pflip_update || cursor_update)
+ drm_crtc_vblank_get(&acrtc->base);
+}
+
static void amdgpu_dm_commit_planes(struct drm_atomic_state *state,
struct drm_device *dev,
struct amdgpu_display_manager *dm,
@@ -10301,16 +10312,19 @@ static void amdgpu_dm_commit_planes(struct drm_atomic_state *state,
}
}
- /*
- * DCE depends on a combination of GRPH_FLIP, VLINE0, and VUPDATE for
- * event delivery. Only GRPH_FLIP handler can send pflip events, and it
- * only fires if HW latched to the flip. Maintain legacy behavior by
- * arming event before programming.
- */
- if (amdgpu_ip_version(dm->adev, DCE_HWIP, 0) == 0) {
- scoped_guard(spinlock_irqsave, &pcrtc->dev->event_lock) {
+ scoped_guard(spinlock_irqsave, &pcrtc->dev->event_lock) {
+ dm_arm_vblank_event_pre_programming(acrtc_attach, acrtc_state,
+ pflip_present,
+ cursor_update);
+ /*
+ * DCE depends on a combination of GRPH_FLIP, VLINE0, and
+ * VUPDATE for event delivery. Only GRPH_FLIP handler can send
+ * pflip events, and it only fires if HW latched to the flip.
+ * Maintain legacy behavior by arming event before programming.
+ */
+ if (amdgpu_ip_version(dm->adev, DCE_HWIP, 0) == 0) {
dm_arm_vblank_event(acrtc_attach, acrtc_state,
- pflip_present, cursor_update);
+ pflip_present, cursor_update);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 456+ messages in thread
* [PATCH 7.1 438/438] usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (436 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 437/438] drm/amd/display: Exit idle optimizations before programming Greg Kroah-Hartman
@ 2026-08-07 14:40 ` Greg Kroah-Hartman
2026-08-07 17:24 ` [PATCH 7.1 000/438] 7.1.8-rc1 review Ronald Warsow
` (13 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-07 14:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Borah, Chaitanya Kumar,
Andrei Kuchynski, Heikki Krogerus
7.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrei Kuchynski <akuchynski@chromium.org>
commit fb0bf289f5d529336ef490c8273e88a8a8b29f69 upstream.
The commit 7aa7d4bf9d3f ("usb: typec: ucsi: Fix race condition and
ordering in port unregistration") consolidated port teardown into the
ucsi_unregister_port() helper. However, it introduced an ordering problem
in the ucsi_init() error path.
Fix this by ensuring ucsi_unregister_port() is called before we unregister
their corresponding lockdep keys.
Cc: stable@vger.kernel.org
Fixes: 7aa7d4bf9d3f ("usb: typec: ucsi: Fix race condition and ordering in port unregistration")
Reported-by: "Borah, Chaitanya Kumar" <chaitanya.kumar.borah@intel.com>
Closes: https://lore.kernel.org/all/22064276-6c56-411a-9f20-6917ceeb865f@intel.com/
Signed-off-by: Andrei Kuchynski <akuchynski@chromium.org>
Tested-by: Chaitanya Kumar Borah <chaitanya.kumar.borah@intel.com>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260717104614.325250-1-akuchynski@chromium.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/typec/ucsi/ucsi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/usb/typec/ucsi/ucsi.c
+++ b/drivers/usb/typec/ucsi/ucsi.c
@@ -2110,11 +2110,11 @@ static int ucsi_init(struct ucsi *ucsi)
return 0;
err_unregister:
+ for (con = connector; con->port; con++)
+ ucsi_unregister_port(con);
for (i = 0; i < ucsi->cap.num_connectors; i++)
lockdep_unregister_key(&connector[i].lock_key);
- for (con = connector; con->port; con++)
- ucsi_unregister_port(con);
kfree(connector);
err_reset:
memset(&ucsi->cap, 0, sizeof(ucsi->cap));
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 335/438] power: supply: macsmc: Support macOS 27 SMC firmware
2026-08-07 14:38 ` [PATCH 7.1 335/438] power: supply: macsmc: Support macOS 27 SMC firmware Greg Kroah-Hartman
@ 2026-08-07 16:06 ` Joshua Peisach
0 siblings, 0 replies; 456+ messages in thread
From: Joshua Peisach @ 2026-08-07 16:06 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, Sven Peter, Joshua Peisach, Janne Grunau,
Sasha Finkelstein, Sebastian Reichel
On Fri Aug 7, 2026 at 10:38 AM EDT, Greg Kroah-Hartman wrote:
> 7.1-stable review patch. If anyone has any objections, please let me know.
>
Not an objection, but this did fix my problems with emergency
shutdowns. I'm not sure if you can promote from Reviewed -> Tested by
but if you would like so for the record:
on a M1 MBP, after applying patch following macOS 27 update:
Tested-by: Joshua Peisach <jpeisach@ubuntu.com>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (437 preceding siblings ...)
2026-08-07 14:40 ` [PATCH 7.1 438/438] usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path Greg Kroah-Hartman
@ 2026-08-07 17:24 ` Ronald Warsow
2026-08-07 18:31 ` Pavel Machek
` (12 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Ronald Warsow @ 2026-08-07 17:24 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
conor, hargar, broonie, achill, sr
Hi
kernel build / boot test on x86_64 (Intel).
No regressions here.
Thanks
Tested-by: Ronald Warsow <rwarsow@gmx.de>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (438 preceding siblings ...)
2026-08-07 17:24 ` [PATCH 7.1 000/438] 7.1.8-rc1 review Ronald Warsow
@ 2026-08-07 18:31 ` Pavel Machek
2026-08-08 0:29 ` Shuah Khan
` (11 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Pavel Machek @ 2026-08-07 18:31 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
[-- Attachment #1: Type: text/plain, Size: 501 bytes --]
Hi!
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
CIP testing did not find any problems here:
https://gitlab.com/cip-project/cip-testing/linux-stable-rc-ci/-/tree/linux-7.1.y
Tested-by: Pavel Machek (CIP) <pavel@nabladev.com>
Best regards,
Pavel
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (439 preceding siblings ...)
2026-08-07 18:31 ` Pavel Machek
@ 2026-08-08 0:29 ` Shuah Khan
2026-08-08 10:22 ` Brett A C Sheffield
` (10 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Shuah Khan @ 2026-08-08 0:29 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr, Shuah Khan
On 8/7/26 08:33, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
>
Compiled and booted on my test system. No dmesg regressions.
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
thanks,
-- Shuah
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound
2026-08-07 14:38 ` [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound Greg Kroah-Hartman
@ 2026-08-08 9:05 ` Thorsten Leemhuis
2026-08-08 14:59 ` Greg Kroah-Hartman
0 siblings, 1 reply; 456+ messages in thread
From: Thorsten Leemhuis @ 2026-08-08 9:05 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, Mario Limonciello, Andy Shevchenko, Hardik Prakash,
Bartosz Golaszewski, Andi Shyti
On 8/7/26 16:38, Greg Kroah-Hartman wrote:
> 7.1-stable review patch. If anyone has any objections, please let me know.
>
> ------------------
>
> From: Hardik Prakash <hardikprakash.official@gmail.com>
>
> commit 0a4bb2abc3e56d7be6e69b050c88ba52c87e22bf upstream.
>
> I2C controllers may have child devices with GpioInt resources that
> depend on GPIO controllers being fully initialized. If the I2C
> controller probes and enumerates children before the referenced GPIO
> controller has completed probe, GPIO interrupts may not be properly
> configured, leading to device failures.> [...]
Hi Greg, just noticed yesterday with mainline that this change broke the
touchpad of my ThinkPad T14s Gen 4 (AMD), so you might want to consider
not backporting it for now:
https://lore.kernel.org/all/b4a4eadb-282f-464c-843a-19d415a34d0c@leemhuis.info/
Ciao, Thorsten
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (440 preceding siblings ...)
2026-08-08 0:29 ` Shuah Khan
@ 2026-08-08 10:22 ` Brett A C Sheffield
2026-08-08 11:58 ` Takeshi Ogasawara
` (9 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Brett A C Sheffield @ 2026-08-08 10:22 UTC (permalink / raw)
To: gregkh
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr,
Brett A C Sheffield
# Librecast Test Results
020/020 [ OK ] liblcrq
010/010 [ OK ] libmld
120/120 [ OK ] liblibrecast
CPU/kernel: Linux auntie 7.1.8-rc1-g91bb55d1d234 #1 SMP PREEMPT_DYNAMIC Sat Aug 8 10:19:35 -00 2026 x86_64 AMD Ryzen 9 9950X 16-Core Processor AuthenticAMD GNU/Linux
Tested-by: Brett A C Sheffield <bacs@librecast.net>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (441 preceding siblings ...)
2026-08-08 10:22 ` Brett A C Sheffield
@ 2026-08-08 11:58 ` Takeshi Ogasawara
2026-08-08 12:33 ` Benjamin Boortz
` (8 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Takeshi Ogasawara @ 2026-08-08 11:58 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
Hi Greg
On Sat, Aug 8, 2026 at 2:15 AM Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Linux version 7.1.8-rc1 tested.
Build successfully completed.
Boot successfully completed.
No dmesg regressions.
Video output normal.
Sound output normal.
Lenovo ThinkPad X1 Carbon Gen10(Intel i7-1260P(x86_64) arch linux)
[ 0.000000] Linux version 7.1.8-rc1rv-g91bb55d1d234
(takeshi@ThinkPadX1Gen10J0764) (gcc (GCC) 16.1.1 20260728, GNU ld (GNU
Binutils) 2.47) #1 SMP PREEMPT_DYNAMIC Sat Aug 8 20:30:10 JST 2026
Thanks
Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (442 preceding siblings ...)
2026-08-08 11:58 ` Takeshi Ogasawara
@ 2026-08-08 12:33 ` Benjamin Boortz
2026-08-08 17:43 ` Justin Forbes
` (7 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Benjamin Boortz @ 2026-08-08 12:33 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
On Fri, Aug 07, 2026 at 04:33:16PM +0200, Greg Kroah-Hartman wrote:
>This is the start of the stable review cycle for the 7.1.8 release.
>There are 438 patches in this series, all will be posted as a response
>to this one. If anyone has any issues with these being applied, please
>let me know.
Build and boot tested with QEMU for x86_64, i386, arm64, and riscv
across multiple configurations, and boots on AMD Ryzen 7 5800H.
No regressions observed.
Tested-by: Benjamin Boortz <bennib@mailbox.org>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound
2026-08-08 9:05 ` Thorsten Leemhuis
@ 2026-08-08 14:59 ` Greg Kroah-Hartman
0 siblings, 0 replies; 456+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-08 14:59 UTC (permalink / raw)
To: Thorsten Leemhuis
Cc: stable, patches, Mario Limonciello, Andy Shevchenko,
Hardik Prakash, Bartosz Golaszewski, Andi Shyti
On Sat, Aug 08, 2026 at 11:05:09AM +0200, Thorsten Leemhuis wrote:
> On 8/7/26 16:38, Greg Kroah-Hartman wrote:
> > 7.1-stable review patch. If anyone has any objections, please let me know.
> >
> > ------------------
> >
> > From: Hardik Prakash <hardikprakash.official@gmail.com>
> >
> > commit 0a4bb2abc3e56d7be6e69b050c88ba52c87e22bf upstream.
> >
> > I2C controllers may have child devices with GpioInt resources that
> > depend on GPIO controllers being fully initialized. If the I2C
> > controller probes and enumerates children before the referenced GPIO
> > controller has completed probe, GPIO interrupts may not be properly
> > configured, leading to device failures.> [...]
>
> Hi Greg, just noticed yesterday with mainline that this change broke the
> touchpad of my ThinkPad T14s Gen 4 (AMD), so you might want to consider
> not backporting it for now:
> https://lore.kernel.org/all/b4a4eadb-282f-464c-843a-19d415a34d0c@leemhuis.info/
Now dropped, thanks.
greg k-h
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (443 preceding siblings ...)
2026-08-08 12:33 ` Benjamin Boortz
@ 2026-08-08 17:43 ` Justin Forbes
2026-08-08 18:02 ` Peter Schneider
` (6 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Justin Forbes @ 2026-08-08 17:43 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
On Fri, Aug 07, 2026 at 04:33:16PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Tested rc1 against the Fedora build system (aarch64, ppc64le, s390x,
x86_64), and boot tested x86_64. No regressions noted.
Tested-by: Justin M. Forbes <jforbes@fedoraproject.org>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (444 preceding siblings ...)
2026-08-08 17:43 ` Justin Forbes
@ 2026-08-08 18:02 ` Peter Schneider
2026-08-08 20:34 ` Markus Reichelt
` (5 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Peter Schneider @ 2026-08-08 18:02 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
Am 07.08.2026 um 16:33 schrieb Greg Kroah-Hartman:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
Builds, boots and works on my 2-socket Ivy Bridge Xeon E5-2697 v2 server. No dmesg oddities or regressions found.
Tested-by: Peter Schneider <pschneider1968@googlemail.com>
Beste Grüße,
Peter Schneider
--
Climb the mountain not to plant your flag, but to embrace the challenge,
enjoy the air and behold the view. Climb it so you can see the world,
not so the world can see you. -- David McCullough Jr.
OpenPGP: 0xA3828BD796CCE11A8CADE8866E3A92C92C3FF244
Download: https://www.peters-netzplatz.de/download/pschneider1968_pub.asc
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@googlemail.com
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@gmail.com
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (445 preceding siblings ...)
2026-08-08 18:02 ` Peter Schneider
@ 2026-08-08 20:34 ` Markus Reichelt
2026-08-08 22:42 ` Ron Economos
` (4 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Markus Reichelt @ 2026-08-08 20:34 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
* Greg Kroah-Hartman <gregkh@linuxfoundation.org> wrote:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
Hi Greg
7.1.8-rc1 compiles on x86_64 (Xeon E5-1620 v2, Slackware64-15.0),
and boots & runs on x86_64 (AMD Ryzen 5 7520U, Slackware64-current).
No regressions observed during boot & my custom tests.
Tested-by: Markus Reichelt <lkt+2023@mareichelt.com>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (446 preceding siblings ...)
2026-08-08 20:34 ` Markus Reichelt
@ 2026-08-08 22:42 ` Ron Economos
2026-08-09 8:27 ` Barry K. Nathan
` (3 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Ron Economos @ 2026-08-08 22:42 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 8/7/26 07:33, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Built and booted successfully on RISC-V RV64 (HiFive Unmatched).
Tested-by: Ron Economos <re@w6rz.net>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (447 preceding siblings ...)
2026-08-08 22:42 ` Ron Economos
@ 2026-08-09 8:27 ` Barry K. Nathan
2026-08-09 8:35 ` Miguel Ojeda
` (2 subsequent siblings)
451 siblings, 0 replies; 456+ messages in thread
From: Barry K. Nathan @ 2026-08-09 8:27 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 8/7/26 7:33 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Tested on 3 amd64 systems and an arm64 virtual machine. Working well,
no regressions observed.
Tested-by: Barry K. Nathan <barryn@pobox.com>
--
-Barry K. Nathan <barryn@pobox.com>
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (448 preceding siblings ...)
2026-08-09 8:27 ` Barry K. Nathan
@ 2026-08-09 8:35 ` Miguel Ojeda
2026-08-09 10:34 ` Jeffrin Thalakkottoor
2026-08-09 11:51 ` Mark Brown
451 siblings, 0 replies; 456+ messages in thread
From: Miguel Ojeda @ 2026-08-09 8:35 UTC (permalink / raw)
To: gregkh
Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
linux-kernel, linux, lkft-triage, patches, patches, pavel,
rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
Miguel Ojeda
On Fri, 07 Aug 2026 16:33:16 +0200 Greg Kroah-Hartman <gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Sun, 09 Aug 2026 14:33:46 +0000.
> Anything received after that time might be too late.
Boot-tested under QEMU for Rust x86_64, arm64 and riscv64; built-tested
for loongarch64 and arm32:
Tested-by: Miguel Ojeda <ojeda@kernel.org>
Thanks!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (449 preceding siblings ...)
2026-08-09 8:35 ` Miguel Ojeda
@ 2026-08-09 10:34 ` Jeffrin Thalakkottoor
2026-08-09 11:51 ` Mark Brown
451 siblings, 0 replies; 456+ messages in thread
From: Jeffrin Thalakkottoor @ 2026-08-09 10:34 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
hello,
Compiled and booted 7.1.8-rc1 (using qemu-system-amd64)
No new typical dmesg regressions .
Tested-by: Jeffrin Jose T <jeffrin@rajagiritech.edu.in>
--
software engineer
rajagiri school of engineering and technology
^ permalink raw reply [flat|nested] 456+ messages in thread
* Re: [PATCH 7.1 000/438] 7.1.8-rc1 review
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
` (450 preceding siblings ...)
2026-08-09 10:34 ` Jeffrin Thalakkottoor
@ 2026-08-09 11:51 ` Mark Brown
451 siblings, 0 replies; 456+ messages in thread
From: Mark Brown @ 2026-08-09 11:51 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, achill, sr
[-- Attachment #1: Type: text/plain, Size: 344 bytes --]
On Fri, Aug 07, 2026 at 04:33:16PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.1.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
Tested-by: Mark Brown <broonie@kernel.org>
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 456+ messages in thread
end of thread, other threads:[~2026-08-09 11:51 UTC | newest]
Thread overview: 456+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-07 14:33 [PATCH 7.1 000/438] 7.1.8-rc1 review Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 001/438] net: mpls: initialize rtm_tos in mpls_getroute() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 002/438] mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 003/438] lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 004/438] mm/slab: prevent unbounded recursion in free path with new kmalloc type Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 005/438] ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05) Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 006/438] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 007/438] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 008/438] dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 009/438] pinctrl: qcom: Unconditionally mark gpio as wakeup enable Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 010/438] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 011/438] dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 012/438] dmaengine: idxd: fix double free of wq, engine, and group structs Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 013/438] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 014/438] iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 015/438] gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 016/438] selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 017/438] selftests/seccomp: Fix pointer type mismatch build error Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 018/438] ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 019/438] ata: sata_mv: accept 1 or 2 resources in platform probe Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 020/438] ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 021/438] phy: qcom: m31-eusb2: Fix return value of init call Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 022/438] ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 023/438] ASoC: max98090: " Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 024/438] of: reserved_mem: prevent OOB when too many dynamic regions are defined Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 025/438] btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 026/438] btrfs: zoned: fix deadlock between metadata writeback and transaction commit Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 027/438] btrfs: zoned: reset meta_write_pointer on zone reset Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 028/438] btrfs: warn about extent buffer that can not be released Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 029/438] btrfs: skip global block reserve accounting for rescue mounts Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 030/438] btrfs: raid56: fix an incorrect csum skip during scrub Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 031/438] btrfs: zoned: skip fully truncated ordered extents at zone finish Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 032/438] ntfs: harden runlist realloc size calculations Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 033/438] ntfs: drop stale page-cache when shrinking a non-resident attr Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 034/438] rtla/timerlat_top: Fix on-threshold actions firing on signal Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 035/438] phy: zynqmp: fix clock error handling in xpsgtr_phy_init() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 036/438] phy: zynqmp: fix runtime PM leak on probe allocation failure Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 037/438] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 038/438] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 039/438] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 040/438] drm/mediatek: Check CRTC state before freeing Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 041/438] mshv_vtl: fix fd leak in mshv_ioctl_create_vtl() Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 042/438] Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation Greg Kroah-Hartman
2026-08-07 14:33 ` [PATCH 7.1 043/438] mshv: Fix duplicate GSI detection for GSI 0 Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 044/438] mshv: Fix sleeping under spinlock in mshv_portid_alloc Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 045/438] KVM: arm64: vgic: Fix race between LPI release and re-registration Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 046/438] KVM: arm64: vgic: Mitigate potential LPI registration failure Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 047/438] KVM: arm64: Fix hyp_trace clock disabling Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 048/438] KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 049/438] KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 050/438] KVM: arm64: Add missing hyp_enter when trapping sysreg Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 051/438] KVM: arm64: Reject guest_memfd memslots when the VM has MTE Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 052/438] KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 053/438] keys: fix out-of-bounds read in keyring_get_key_chunk() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 054/438] keys: make keyring key-chunk byte order agree with keyring_diff_objects() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 055/438] assoc_array: trim the final shortcut word using the current chunk end Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 056/438] ipvs: adjust double hashing when fwd method changes Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 057/438] netfilter: nf_tables: make nft_object rhltable per table Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 058/438] netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 059/438] ipvs: fix the checksum validations Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 060/438] ipvs: fix places with wrong packet offsets Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 061/438] ipvs: do not mangle ICMP replies for non-first fragments Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 062/438] ipvs: clear the nfct flag under lock Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 063/438] netfilter: nft_payload: fix mask build for partial field offload Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 064/438] ASoC: SDCA: Correct pointer passed to devm_acpi_table_put Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 065/438] ASoC: SDCA: Always free firmware in FDL path Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 066/438] ASoC: SDCA: Make UMP message size check more robust Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 067/438] ASoC: SDCA: Ensure that Control Range is large enough for header Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 068/438] rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 069/438] nexthop: take nh->lock for f6i_list walks in replace check and notify Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 070/438] nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 071/438] af_unix: fix listen() succeeding on sockets in the wrong state Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 072/438] selftests/net/af_unix: test listen() rejects wrong socket states Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 073/438] xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 074/438] xsk: drain continuation descs after overflow in xsk_build_skb() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 075/438] xsk: provide sufficient space in pool->tx_descs Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 076/438] xsk: reclaim invalid Tx descriptors in ZC batch path Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 077/438] net/sched: sch_cake: skip clearing unused tins during rate adjustment Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 078/438] pinctrl-amd: Dont clear S4 wake bits at probe Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 079/438] scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 080/438] scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 081/438] scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 082/438] smb: client: fix buffer leaks in SMB1 read and write Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 083/438] erofs: clean up erofs_ishare_fill_inode() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 084/438] erofs: remove fscache backend entirely Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 085/438] erofs: ensure valid f_path for page cache sharing Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 086/438] gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 087/438] ACPI: CPPC: Skip writes to unsupported performance controls Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 088/438] wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 089/438] ASoC: tas2781: Use correct calibration data for SINEGAIN2 register Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 090/438] spi: spi-cadence: Move TX FIFO full busy-wait into FIFO Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 091/438] hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 092/438] hwmon: (ina2xx) Fix various overflow issues Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 093/438] hwmon: (ltc4282) Fix reading the minimum alarm voltage Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 094/438] hwmon: (sht3x) Fix unaligned accesses Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 095/438] hwmon: (lm90) Only report alarms if driver is ready Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 096/438] hwmon: (nzxt-smart2) DMA-align output buffer Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 097/438] net: do not send ICMP/NDISC Redirects when peer allocation fails Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 098/438] hwmon: (nct6775-core) Prevent access to unsupported weight registers Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 099/438] net: bridge: mrp: fix Option TLV length in MRP_Test frames Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 100/438] ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set() Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 101/438] forcedeth: fix UAF of txrx_stats in nv_remove Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 102/438] hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors Greg Kroah-Hartman
2026-08-07 14:34 ` [PATCH 7.1 103/438] hwmon: (adt7470) Fix cache updated before hardware write on I2C error Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 104/438] hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 105/438] hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 106/438] hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 107/438] hwmon: (adt7470) Use cached PWM frequency value Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 108/438] hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 109/438] hwmon: (adt7470) Fix PWM auto temp state array and bounds check Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 110/438] rtase: fix double free of multi-frag skb on DMA map failure Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 111/438] ethtool: Embed FEC hist ranges as buffer in struct Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 112/438] powerpc/boot: Fix simpleboot CPU node lookup check Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 113/438] powerpc/boot: Fix treeboot-currituck " Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 114/438] powerpc/boot: Fix treeboot-akebono " Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 115/438] net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 116/438] net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 117/438] wifi: mac80211: validate individual TWT params before driver setup Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 118/438] netfs: clear PG_private_2 on copy-to-cache append failure Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 119/438] netfs: handle single writeback rolling buffer allocation failure Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 120/438] netfs: release readahead folios on iterator preparation failure Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 121/438] netfs: Fix folio_queue ENOMEM in writeback by adding a mempool Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 122/438] net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 123/438] hwmon: (pmbus) Fix return value from pmbus_update_byte_data() Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 124/438] idpf: bound interrupt-vector register fill to the allocated array Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 125/438] idpf: adjust TxQ ring count minimum Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 126/438] idpf: Fix mailbox IRQ name leak on request failure Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 127/438] ice: suppress DPLL errors during reset recovery Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 128/438] Bluetooth: ISO: clear iso_data always when detaching conn from hcon Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 129/438] Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 130/438] Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 131/438] Bluetooth: ISO: lock sk in iso_sock_getname Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 132/438] Bluetooth: ISO: lock sk in iso_connect_ind Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 133/438] Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 134/438] Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 135/438] Bluetooth: ISO: hold sk properly in iso_conn_ready Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 136/438] Bluetooth: ISO: fix leaking sk after socket release Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 137/438] Bluetooth: ISO: avoid deadlocks in iso_sock_timeout Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 138/438] Bluetooth: ISO: ensure no dangling hcon references in iso_conn Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 139/438] Bluetooth: ISO: fix refcounting of iso_conn Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 140/438] Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 141/438] Bluetooth: btintel: Validate length before parsing diagnostics TLV Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 142/438] Bluetooth: hci_conn: hold conn reference in abort_conn_sync() Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 143/438] Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 144/438] Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 145/438] Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 146/438] Bluetooth: hci_sync: hold conn in hci_past_sync() callback Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 147/438] Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 148/438] Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 149/438] x86/boot: Add volatile, clobbers and zero-length test in memcmp() Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 150/438] net: phylink: put link_gpio if phylink_create fails Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 151/438] scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 152/438] scsi: ufs: core: Cancel RTC work in active-active suspend Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 153/438] scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler" Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 154/438] scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 155/438] scsi: target: Clear cmd_cnt when initial counter enrollment fails Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 156/438] octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 157/438] octeontx2-af: Block VFs from clobbering special CGX PKIND state Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 158/438] scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 159/438] scsi: ufs: core: Initialize hba->rpmbs list in ufshcd Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 160/438] net: sxgbe: free TX rings on RX allocation failure Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 161/438] net: sxgbe: check descriptor ring allocation failures Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 162/438] can: isotp: check register_netdevice_notifier() error in module init Greg Kroah-Hartman
2026-08-07 14:35 ` [PATCH 7.1 163/438] drm/i915/dp: Ignore the sinks DSC max FRL rate without a PCON DSC encoder Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 164/438] drm/xe/pt: check no-DMA huge-pte cases before DMA segment test Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 165/438] fprobe: Fix module reference count leak on error in register_fprobe() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 166/438] tracing/mmiotrace: Reset dropped_count in mmio_reset_data() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 167/438] tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 168/438] riscv: drop __init from vec_check_unaligned_access_speed_all_cpus Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 169/438] accel/qaic: use sizeof(*trans_hdr) for transaction length check Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 170/438] riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 171/438] ring-buffer: Fix reader page read offset for remote buffers Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 172/438] ipv6: release fib6_null_entry on subtree failure Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 173/438] riscv: vdso: Only try to install vDSO when present Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 174/438] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 175/438] net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 176/438] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 177/438] net: stmmac: Fix E2E delay mechanism Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 178/438] net: mana: Create separate EQs for each vPort Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 179/438] net: mana: Return error code from mana_create_rxq() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 180/438] ptp: netc: fix potential interrupt storm caused by incorrect unbind order Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 181/438] net: libwx: fix FDIR ATR queue mismatch for software VLAN packets Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 182/438] octeontx2-pf: Set correct sequence for carrier off and tx queue stop Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 183/438] sched/deadline: Use revised wakeup rule only for running dl_server Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 184/438] spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 185/438] qede: sync udp_tunnel ports outside qede_lock in the recovery path Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 186/438] drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 187/438] ksmbd: return success for deferred final close Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 188/438] ksmbd: fix use-after-free in __close_file_table_ids() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 189/438] ksmbd: use memcmp() to compare ClientGUIDs Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 190/438] iomap: add a separate bio_set for iomap_split_ioend Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 191/438] mshv: Fix race in mshv_irqfd_deassign Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 192/438] mshv: Fix level-triggered check on uninitialized data Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 193/438] mshv: Fix missing error code on VP allocation failure Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 194/438] mshv: Order pt_vp_array publish against irqfd assertion path Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 195/438] mshv: Publish VP to pt_vp_array before installing the file descriptor Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 196/438] ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 197/438] iommufd/viommu: Release the igroup lock on the vdevice_size " Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 198/438] iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 199/438] iommufd: Reject DMABUF pages from the access pin path Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 200/438] iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 201/438] iommu/iommufd: Fix IOPF group ownership UAF Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 202/438] kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 203/438] ACPI: CPPC: Check all controls for fast switching Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 204/438] mm: mglru: fix stale batch updates after memcg reparenting Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 205/438] mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 206/438] pinctrl: microchip-sgpio: add missing select REGMAP_MMIO Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 207/438] pinctrl: devicetree: dont free uninitialized dev_name on error path Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 208/438] btrfs: raid56: fix scrub read assembly submitting no reads Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 209/438] erofs: cap LZMA stream pool size Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 210/438] pinctrl: bm1880: add missing select GENERIC_PINCONF Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 211/438] fortify: Disable -Wstringop-overread in tests Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 212/438] lib: test_hmm: use device devt for coherent device range selection Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 213/438] btrfs: zoned: fix missing chunk metadata reservation Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 214/438] ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 215/438] mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 216/438] mm/util: dont read __page_2 for order-1 folios in snapshot_page() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 217/438] selftest: fix headers in fclog.c Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 218/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 219/438] fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 220/438] mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 221/438] mm/hugetlb: fix list corruption in allocate_file_region_entries() Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 222/438] userfaultfd: wait on source PMD during UFFDIO_MOVE Greg Kroah-Hartman
2026-08-07 14:36 ` [PATCH 7.1 223/438] mm/vmstat: fold stranded per-cpu node stats when a node comes online Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 224/438] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 225/438] tracing/probes: Reject $arg0 in meta argument expansion Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 226/438] tracing/fprobe: Roll back on enable_trace_fprobe() failure Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 227/438] KVM: VMX: add memory clobber to asm for VMX instructions Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 228/438] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 229/438] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 230/438] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 231/438] KVM: s390: pci: Fix missing error codes and memory unaccounting Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 232/438] KVM: s390: pci: Fix resource leak on IRQ registration failure Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 233/438] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 234/438] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 235/438] dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 236/438] sctp: validate Adaptation Indication parameter length Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 237/438] audit: fix potential integer overflow in audit_log_n_string() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 238/438] audit: fix potential use-after-free in audit_del_rule() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 239/438] Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 240/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 241/438] Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 242/438] Bluetooth: mgmt: fix pending command UAF in EIR updates Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 243/438] Bluetooth: SCO: give the socket its own sco_conn reference Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 244/438] Bluetooth: mgmt: fix UAF in pair command cancellation Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 245/438] Bluetooth: hci_sync: Fix advertising data UAFs Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 246/438] Bluetooth: HIDP: reject frames without a transaction header Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 247/438] Bluetooth: HIDP: validate numbered report payloads Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 248/438] bpf: lwt: Fix dst reference leak on reroute failure Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 249/438] afs: Fix afs_fs_fetch_data() to set call->async Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 250/438] afs: Fix afs_fs_fetch_data() to subtract transferred from len Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 251/438] afs: Fix UAF when sending a message Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 252/438] ALSA: 6fire: Fix UAF at error handling during probe Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 253/438] ALSA: hda/realtek: Add quirk for TongFang X6SP45xU Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 254/438] ALSA: lx6464es: fix period byte count for 16-bit streams Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 255/438] ALSA: pcm: wake linked drain waiters on unlink Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 256/438] ALSA: seq: Fix division by zero in initialize_timer() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 257/438] ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 258/438] ALSA: ump: fix double free of out_cvts on rawmidi error Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 259/438] ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 260/438] ASoC: fsl_easrc: " Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 261/438] ASoC: tas2562: fix DVC coefficient write order Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 262/438] ASoC: tas2562: fix broken entries in the volume lookup table Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 263/438] ata: libata-eh: Increase STANDBY IMMEDIATE timeout Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 264/438] ata: libata-sata: fix ata_scsi_lpm_supported() iteration Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 265/438] ata: libata-scsi: terminate deferred commands on time out Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 266/438] ata: libata-scsi: schedule deferred atapi command Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 267/438] ALSA: usb-audio: fix use-after-free in ump_to_endpoint() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 268/438] ALSA: usb-audio: fix stack info leak in RME Digiface status Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 269/438] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 270/438] ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 271/438] ALSA: usb-audio: Clamp frame size in implicit-feedback mode Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 272/438] dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 273/438] e1000: fix memory leak in e1000_probe() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 274/438] fou: Fix use-after-free in fou_create() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 275/438] igbvf: Fix leak in TX DMA error cleanup Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 276/438] igc: remove napi_synchronize() in igc_down() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 277/438] ipvs: do not propagate one-packet flag to synced conns Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 278/438] ksmbd: reject repeated SMB2 NEGOTIATE requests Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 279/438] mshv: fix hv_input_get_system_property struct Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 280/438] net/smc: fix socket use-after-free during link group termination Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 281/438] netfilter: ipset: do not update comments from kernel-side hash adds Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 282/438] of/address: Fix NULL bus dereference in of_pci_range_parser_one() Greg Kroah-Hartman
2026-08-07 14:37 ` [PATCH 7.1 283/438] PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 284/438] tipc: avoid use-after-free in poll trace queue dumps Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 285/438] x86/CPU/AMD: Carve out a Zen5 models range Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 286/438] wifi: mac80211: fix tid_tx use-after-free on BA session stop Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 287/438] wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 288/438] binfmt_misc: restore write access when removing an entry Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 289/438] binfmt_misc: use exe_file_deny_write_access() for the interpreter clone Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 290/438] binfmt_misc: reject a flag character as the field delimiter Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 291/438] binfmt_misc: dont let an F entry pin its own instance Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 292/438] binfmt_misc: dont leak the user namespace when the mount fails Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 293/438] io_uring/net: initialize mshot_len for send Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 294/438] io_uring: preserve task restrictions across exec Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 295/438] mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 296/438] mm/page_reporting: use system_freezable_wq to fix UAF during suspend Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 297/438] mm: memcg: initialize *locked in memcg1_oom_prepare() stub Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 298/438] net: bridge: stop fast-leave after deleting a port group Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 299/438] net: ipv6: clear suppressed fib6 rule result Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 300/438] net: pktgen: fix proc entry use-after-free Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 301/438] riscv/mm: use physical alignment for vmemmap_start_pfn Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 302/438] powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 303/438] um: vector: fix use-after-free in vector_mmsg_rx() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 304/438] uprobes: Fix NULL pointer dereference in hprobe_expire() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 305/438] veth: convert frag_list skbs before running XDP Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 306/438] vxlan: re-fetch eth header after route_shortcircuit() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 307/438] vxlan: unclone skb head before modifying eth header in route_shortcircuit() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 308/438] vxlan: use neigh_ha_snapshot() " Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 309/438] vxlan: use pskb_network_may_pull() for transmit path header pulls Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 310/438] vxlan: use pskb_network_may_pull() in route_shortcircuit() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 311/438] ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 312/438] tracing: Check return value of __register_event() in trace_module_add_events() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 313/438] tracing/filters: Fix false positive match in regex_match_full() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 314/438] spi: spi-qpic-snand: write the feature value before executing SET_FEATURE Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 315/438] spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 316/438] selftests/mm: fix potential wild pointer access of getline due to missing init Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 317/438] selftests/clone3: fix " Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 318/438] scsi: libsas: terminate deferred commands on time out Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 319/438] scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 320/438] scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 321/438] sctp: reject stale cookies with mismatched verification tags Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 322/438] sctp: prevent peer transport count overflow Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 323/438] hwmon: (npcm750-pwm-fan): stop fan timer on device detach Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 324/438] hwmon: (pmbus/core) notify on the hwmon device, not the i2c client Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 325/438] i2c: amd-mp2: Unregister callback on adapter add failure Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 326/438] i2c: designware: defer probe if child GpioInt controllers are not bound Greg Kroah-Hartman
2026-08-08 9:05 ` Thorsten Leemhuis
2026-08-08 14:59 ` Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 327/438] gpiolib: tolerate gpio-hogs lacking a hogging state Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 328/438] gpio: pca953x: fix cache_only and IRQ state on restore_context() failure Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 329/438] gpio: pch: use raw_spinlock_t for the register lock Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 330/438] cifs: add fscache_resize_cookie() to cifs_setsize() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 331/438] cpufreq: cppc: Sanitize lockless policy limit snapshots Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 332/438] cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 333/438] cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 334/438] power: supply: bq25890: fix the -10 C NTC lookup entry Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 335/438] power: supply: macsmc: Support macOS 27 SMC firmware Greg Kroah-Hartman
2026-08-07 16:06 ` Joshua Peisach
2026-08-07 14:38 ` [PATCH 7.1 336/438] power: supply: max17040: handle missing status supplier Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 337/438] s390/pci: Fix s390_pci_mmio_write syscall error return without MIO Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 338/438] s390/qeth: Check CAP_NET_ADMIN for private ioctls Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 339/438] s390/dasd: Fix potential NULL pointer dereference Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 340/438] s390/dasd: Fix undersized format-check buffer Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 341/438] s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 342/438] s390/zcrypt: Close speculative mem read possibility Greg Kroah-Hartman
2026-08-07 14:38 ` [PATCH 7.1 343/438] s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 344/438] s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 345/438] s390/zcrypt: Validate length for CCA AES cipher key requests Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 346/438] s390/zcrypt: Validate length for CCA ECC private " Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 347/438] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 348/438] phy: zynqmp: use read-modify-write for SERDES scrambler bypass Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 349/438] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 350/438] net: openvswitch: fix potential UAF on meter attach failure Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 351/438] net: openvswitch: fix skb leak on flow key update failure during recirculation Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 352/438] net: openvswitch: fix skb leak on flow key update failure during ct Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 353/438] ice: wait for reset completion in ice_resume() Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 354/438] ice: fix VF interrupts cleanup Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 355/438] ice: fix memory leak in ice_lbtest_prepare_rings() Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 356/438] i2c: spacemit: request IRQ after controller initialization Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 357/438] i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 358/438] i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 359/438] i2c: iproc: reset bus after timeout if START_BUSY is stuck Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 360/438] i2c: imx: mark I2C adapter when hardware is powered down Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 361/438] i2c: imx: Fix slave registration race and error handling Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 362/438] i2c: imx: Cancel hrtimer before clearing slave pointer Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 363/438] can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 364/438] can: ems_usb: validate CPC message lengths Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 365/438] can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 366/438] can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 367/438] can: isotp: fix timer drain order, wakeup handling and tx_gen ordering Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 368/438] can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 369/438] can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 370/438] can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 371/438] can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 372/438] can: rcar_canfd: change the initializing flow for clocks and resets Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 373/438] can: softing: fw_parse(): validate firmware record spans Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 374/438] can: peak_usb: add bounds check for USB channel index Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 375/438] can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 376/438] can: peak_usb: validate uCAN receive record lengths Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 377/438] can: ctucanfd: add missing MODULE_DEVICE_TABLE() Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 378/438] can: ctucanfd: use self-test mode for PRESUME_ACK Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 379/438] can: ctucanfd: unmap BAR0 using base address Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 380/438] can: ctucanfd: handle bus error interrupts Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 381/438] can: ctucanfd: mark error-active controller status valid Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 382/438] drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 383/438] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 384/438] drm/vc4: Zero the tile state data array before each BIN job Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 385/438] drm/bridge: display-connector: Fix I2C adapter resource leak Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 386/438] drm/panthor: reject firmware sections with oversized data Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 387/438] drm/panthor: validate firmware interface structure sizes Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 388/438] drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2 Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 389/438] drm/mediatek: ovl_adaptor: balance component registrations Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 390/438] drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 391/438] drm/amdgpu: restore UMD profile pstate after runtime resume Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 392/438] drm/amdgpu: cap GTT size to physical RAM on APUs Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 393/438] drm/amd/pm: fix torn gpu metrics reads Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 394/438] drm/amd/pm: fix pptable use-after-free Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 395/438] drm/amd/pm: hide pp_table sysfs on APUs Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 396/438] drm/amd/pm: use milliwatts for GPU power sensors Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 397/438] drm/amd/display: check if dml21_add_phantom_plane() is successful Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 398/438] drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 399/438] drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 400/438] drm/amd/display: Silence link_dpms I2C retimer failures Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 401/438] drm/amd/display: use proper context for logging Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 402/438] drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE Greg Kroah-Hartman
2026-08-07 14:39 ` [PATCH 7.1 403/438] drm/amdkfd: fix QID bit leak in pqm_create_queue() Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 404/438] drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 405/438] drm/amdkfd: Handle invalid event type in CRIU event restore Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 406/438] drm/amdkfd: hold event_mutex while checkpointing CRIU events Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 407/438] drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 408/438] drm/vmwgfx: reject DX_BIND_QUERY without a DX context Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 409/438] drm/vmwgfx: clamp dirty-page range with min, not max Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 410/438] drm/vmwgfx: take fman->lock around fence list mutation in fifo_down Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 411/438] drm/vmwgfx: drop dma_buf reference on foreign-fd prime import Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 412/438] drm/vmwgfx: validate DRAW_PRIMITIVES header size before division Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 413/438] drm/vmwgfx: bound DMA command body size against suffix pointer Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 414/438] drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 415/438] drm/vmwgfx: enforce cursor size limits for MOB cursors Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 416/438] drm/vmwgfx: use check_add_overflow for shader size+offset bound Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 417/438] drm/vmwgfx: validate external BO copy bounds for both stride paths Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 418/438] drm/xe/rtp: Maintain OA whitelists separately Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 419/438] drm/xe/rtp: Keep track of non-OA nonpriv slots Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 420/438] drm/xe/rtp: Generalize whitelist_apply_to_hwe Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 421/438] drm/xe/rtp: Save OA nonpriv registers to register save/restore lists Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 422/438] drm/xe/rtp: Toggle deny bit to (de-)whitelist OA regs Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 423/438] drm/xe/rtp: (De-)whitelist OA registers for all hwes for a gt Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 424/438] drm/xe/oa: (De-)whitelist OA registers on OA stream open/release Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 425/438] drm/xe/rtp: Ensure locking/ref counting for OA whitelists Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 426/438] usb: typec: ucsi: split connector lock classes Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 427/438] usb: typec: ucsi: Fix race condition and ordering in port unregistration Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 428/438] drm/xe: Drop unused param from xe_device_create() Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 429/438] drm/xe: Move xe->info.force_execlist initialization Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 430/438] drm/xe: Move xe->info.devid|revid initialization Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 431/438] drm/xe: Separate early xe_device initialization Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 432/438] drm/xe: Set TTM device beneficial_order to 9 (2M) Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 433/438] drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 434/438] drm/xe: Wait on external BO kernel fences in exec IOCTL Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 435/438] media: chips-media: wave5: Support CBP profile Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 436/438] drm/amd/display: check GRPH_FLIP status before sending event Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 437/438] drm/amd/display: Exit idle optimizations before programming Greg Kroah-Hartman
2026-08-07 14:40 ` [PATCH 7.1 438/438] usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path Greg Kroah-Hartman
2026-08-07 17:24 ` [PATCH 7.1 000/438] 7.1.8-rc1 review Ronald Warsow
2026-08-07 18:31 ` Pavel Machek
2026-08-08 0:29 ` Shuah Khan
2026-08-08 10:22 ` Brett A C Sheffield
2026-08-08 11:58 ` Takeshi Ogasawara
2026-08-08 12:33 ` Benjamin Boortz
2026-08-08 17:43 ` Justin Forbes
2026-08-08 18:02 ` Peter Schneider
2026-08-08 20:34 ` Markus Reichelt
2026-08-08 22:42 ` Ron Economos
2026-08-09 8:27 ` Barry K. Nathan
2026-08-09 8:35 ` Miguel Ojeda
2026-08-09 10:34 ` Jeffrin Thalakkottoor
2026-08-09 11:51 ` Mark Brown
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.