* [PATCH 6.1 001/982] drm/gem: Consider GEM object reclaimable if shrinking fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 002/982] bus: fsl-mc: wait for the MC firmware to complete its boot Greg Kroah-Hartman
` (987 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Liviu Dudau, Steven Price,
Boris Brezillon, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Boris Brezillon <boris.brezillon@collabora.com>
[ Upstream commit 71c8224a18825102ee1e5e70498f96f6c2d2a81d ]
If the object wasn't moved to a different LRU after the shrink callback
returns, it means the buffer is still reclaimable. Update the remaining
counter to reflect that.
v2:
- Collect R-b
v3:
- Collect R-b
v4:
- No changes
v5:
- No changes
v6:
- No changes
v7:
- No changes
Reviewed-by: Liviu Dudau <liviu.dudau@arm.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Link: https://patch.msgid.link/20260401134854.2275433-2-boris.brezillon@collabora.com
Signed-off-by: Boris Brezillon <boris.brezillon@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_gem.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
index ebf60c8d98ed8..e9be1d590f4ac 100644
--- a/drivers/gpu/drm/drm_gem.c
+++ b/drivers/gpu/drm/drm_gem.c
@@ -1419,6 +1419,16 @@ drm_gem_lru_scan(struct drm_gem_lru *lru,
*/
WARN_ON(obj->lru == &still_in_lru);
WARN_ON(obj->lru == lru);
+ } else if (obj->lru == &still_in_lru) {
+ /*
+ * If the object wasn't moved and wasn't shrunk either,
+ * it's still remaining as reclaimable. Note that
+ * obj->lru is supposed to be checked with the LRU lock
+ * held for an accurate result, but we don't care about
+ * accuracy here. Worst thing that could happen is an
+ * extra scan.
+ */
+ *remaining += obj->size >> PAGE_SHIFT;
}
dma_resv_unlock(obj->resv);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 002/982] bus: fsl-mc: wait for the MC firmware to complete its boot
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 001/982] drm/gem: Consider GEM object reclaimable if shrinking fails Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 003/982] ALSA: usb-audio: Propagate write errors in generic mixer put callbacks Greg Kroah-Hartman
` (986 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ioana Ciornei,
Christophe Leroy (CS GROUP), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ioana Ciornei <ioana.ciornei@nxp.com>
[ Upstream commit 208858b1b48eba83d073542372329cf8ed606526 ]
There are use cases in which the Management Complex firmware boot
process is started by the bootloader which does not wait for the boot to
complete. This is mainly done in order to reduce the overall boot time
of a DPAA2 based SoC.
In this kind of circumstance, the fsl-mc bus driver needs to make sure
that the MC firmware boot process is finished before proceeding to the
usual operations such as interrogating the firmware to gather all
existent DPAA2 objects, creating the fsl-mc devices on the bus etc.
Add this kind of check early in the boot process of the fsl-mc bus and
defer the probe in case the firmware is still in its boot process.
Signed-off-by: Ioana Ciornei <ioana.ciornei@nxp.com>
Link: https://lore.kernel.org/r/20260401144508.3062019-1-ioana.ciornei@nxp.com
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/fsl-mc/fsl-mc-bus.c | 46 +++++++++++++++++++++++++++++++++
1 file changed, 46 insertions(+)
diff --git a/drivers/bus/fsl-mc/fsl-mc-bus.c b/drivers/bus/fsl-mc/fsl-mc-bus.c
index 6f8e9b40371a2..512026036c578 100644
--- a/drivers/bus/fsl-mc/fsl-mc-bus.c
+++ b/drivers/bus/fsl-mc/fsl-mc-bus.c
@@ -66,6 +66,13 @@ struct fsl_mc_addr_translation_range {
#define GCR1_P1_STOP BIT(31)
#define GCR1_P2_STOP BIT(30)
+#define FSL_MC_GSR 0x8
+#define FSL_MC_GSR_BOOT_DONE BIT(0)
+#define FSL_MC_GSR_MCS_MASK GENMASK(7, 0)
+#define FSL_MC_GSR_MCS_ERR_MASK GENMASK(7, 1)
+#define FSL_MC_GSR_BC_MASK GENMASK(15, 8)
+#define FSL_MC_GSR_BC_SHIFT 8
+
#define FSL_MC_FAPR 0x28
#define MC_FAPR_PL BIT(18)
#define MC_FAPR_BMT BIT(17)
@@ -1104,6 +1111,41 @@ static int get_mc_addr_translation_ranges(struct device *dev,
return 0;
}
+static u32 fsl_mc_read_gsr(struct fsl_mc *mc)
+{
+ return readl(mc->fsl_mc_regs + FSL_MC_GSR);
+}
+
+static int fsl_mc_firmware_check(struct platform_device *pdev)
+{
+ struct fsl_mc *mc = platform_get_drvdata(pdev);
+ u32 gsr, boot_done, boot_code, mcs;
+
+ gsr = fsl_mc_read_gsr(mc);
+ boot_code = (gsr & FSL_MC_GSR_BC_MASK) >> FSL_MC_GSR_BC_SHIFT;
+ if (boot_code == 0xDD) {
+ dev_err(&pdev->dev,
+ "fsl-mc: DPL processing was not started, DPAA2 will not work!\n");
+ return -EOPNOTSUPP;
+ }
+
+ boot_done = gsr & FSL_MC_GSR_BOOT_DONE;
+ if (!boot_done) {
+ dev_dbg(&pdev->dev,
+ "fsl-mc: DPL processing in progress, defer probe\n");
+ return -EPROBE_DEFER;
+ }
+
+ mcs = gsr & FSL_MC_GSR_MCS_MASK;
+ if (mcs & FSL_MC_GSR_MCS_ERR_MASK) {
+ dev_err(&pdev->dev,
+ "fsl-mc: MC boot completed with error 0x%x\n", mcs);
+ return -EINVAL;
+ }
+
+ return 0;
+}
+
/*
* fsl_mc_bus_probe - callback invoked when the root MC bus is being
* added
@@ -1168,6 +1210,10 @@ static int fsl_mc_bus_probe(struct platform_device *pdev)
mc->fsl_mc_regs + FSL_MC_GCR1);
}
+ error = fsl_mc_firmware_check(pdev);
+ if (error)
+ return error;
+
/*
* Get physical address of MC portal for the root DPRC:
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 003/982] ALSA: usb-audio: Propagate write errors in generic mixer put callbacks
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 001/982] drm/gem: Consider GEM object reclaimable if shrinking fails Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 002/982] bus: fsl-mc: wait for the MC firmware to complete its boot Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 004/982] ima: return error early if file xattr cannot be changed Greg Kroah-Hartman
` (985 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cássio Gabriel <cassiogabrielcontato@gmail.com>
[ Upstream commit 87a6f2fa6e6c69bb649fa327635a0bd977724603 ]
mixer_ctl_feature_put(), mixer_ctl_procunit_put(), and
mixer_ctl_selector_put() ignore failures from their SET_CUR helper
routines and report the control as changed whenever the requested
value differs from the current one.
If the device rejects the write, userspace still sees success although
the hardware state did not change. Propagate write failures instead,
using filter_error() so ignore_ctl_error keeps the same semantics as
the existing get paths.
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260419-usb-write-error-propagation-v1-1-5a3bd4a673ae@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/mixer.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)
diff --git a/sound/usb/mixer.c b/sound/usb/mixer.c
index 21543ed58453b..45a4a8c7a697d 100644
--- a/sound/usb/mixer.c
+++ b/sound/usb/mixer.c
@@ -1463,7 +1463,10 @@ static int mixer_ctl_feature_put(struct snd_kcontrol *kcontrol,
return -EINVAL;
val = get_abs_value(cval, val);
if (oval != val) {
- snd_usb_set_cur_mix_value(cval, c + 1, cnt, val);
+ err = snd_usb_set_cur_mix_value(cval, c + 1,
+ cnt, val);
+ if (err < 0)
+ return filter_error(cval, err);
changed = 1;
}
cnt++;
@@ -1478,7 +1481,9 @@ static int mixer_ctl_feature_put(struct snd_kcontrol *kcontrol,
return -EINVAL;
val = get_abs_value(cval, val);
if (val != oval) {
- snd_usb_set_cur_mix_value(cval, 0, 0, val);
+ err = snd_usb_set_cur_mix_value(cval, 0, 0, val);
+ if (err < 0)
+ return filter_error(cval, err);
changed = 1;
}
}
@@ -2345,7 +2350,9 @@ static int mixer_ctl_procunit_put(struct snd_kcontrol *kcontrol,
return -EINVAL;
val = get_abs_value(cval, val);
if (val != oval) {
- set_cur_ctl_value(cval, cval->control << 8, val);
+ err = set_cur_ctl_value(cval, cval->control << 8, val);
+ if (err < 0)
+ return filter_error(cval, err);
return 1;
}
return 0;
@@ -2709,7 +2716,9 @@ static int mixer_ctl_selector_put(struct snd_kcontrol *kcontrol,
return -EINVAL;
val = get_abs_value(cval, val);
if (val != oval) {
- set_cur_ctl_value(cval, cval->control << 8, val);
+ err = set_cur_ctl_value(cval, cval->control << 8, val);
+ if (err < 0)
+ return filter_error(cval, err);
return 1;
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 004/982] ima: return error early if file xattr cannot be changed
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 003/982] ALSA: usb-audio: Propagate write errors in generic mixer put callbacks Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 005/982] usb: gadget: udc: skip pullup() if already connected Greg Kroah-Hartman
` (984 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Goldwyn Rodrigues, Mimi Zohar,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Goldwyn Rodrigues <rgoldwyn@suse.de>
[ Upstream commit 69fc6474236d9edda6983623e4282f2bdfd8e3d8 ]
During early boot, the filesystem is read-only and any changes
to xattrs are not allowed. This fails in case of ext4 because
changing xattr starts an ext4 transaction which fails with the
following warning.
WARNING: fs/ext4/ext4_jbd2.c:75 at ext4_journal_check_start+0x63/0xa0 [ext4], CPU#1: systemd-sysroot/561
CPU: 1 UID: 0 PID: 561 Comm: systemd-sysroot Not tainted 6.19.12-1-default #1 PREEMPT(voluntary) openSUSE Tumbleweed c2dfc3c9d9f6f1233251c5d4410574fe82a348ee
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022
RIP: 0010:ext4_journal_check_start+0x63/0xa0 [ext4]
Call Trace:
__ext4_journal_start_sb+0x3e/0x180 [ext4 6d025f3bc52c89a957b89a89d211fadf5e9434e1]
ext4_xattr_set+0x104/0x150 [ext4 6d025f3bc52c89a957b89a89d211fadf5e9434e1]
__vfs_setxattr+0x9a/0xd0
__vfs_setxattr_noperm+0x76/0x1f0
ima_appraise_measurement+0x23e/0xe40
ima_d_path+0x5a/0xd0
process_measurement+0xb29/0xc40
? copy_from_kernel_nofault+0x21/0xe0
? fscrypt_file_open+0xc0/0xe0
? ext4_file_open+0x60/0x490 [ext4 6d025f3bc52c89a957b89a89d211fadf5e9434e1]
? bpf_prog_31efb7c56239148b_restrict_filesystems+0xab/0x126
? __bpf_prog_exit+0x23/0xd0
? __bpf_tramp_exit+0xd/0x50
? bpf_trampoline_6442530367+0x9f/0xea
ima_file_check+0x57/0x80
security_file_post_open+0x50/0xf0
path_openat+0x493/0x1650
do_filp_open+0xc7/0x170
Detect the state of the file early and return the error.
Signed-off-by: Goldwyn Rodrigues <rgoldwyn@suse.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/integrity/ima/ima_appraise.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c
index 1b45873ae4844..f9d0bd4d3613b 100644
--- a/security/integrity/ima/ima_appraise.c
+++ b/security/integrity/ima/ima_appraise.c
@@ -90,6 +90,11 @@ static int ima_fix_xattr(struct dentry *dentry,
int rc, offset;
u8 algo = iint->ima_hash->algo;
+ if (IS_RDONLY(d_inode(dentry)))
+ return -EROFS;
+ if (IS_IMMUTABLE(d_inode(dentry)))
+ return -EPERM;
+
if (algo <= HASH_ALGO_SHA1) {
offset = 1;
iint->ima_hash->xattr.sha1.type = IMA_XATTR_DIGEST;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 005/982] usb: gadget: udc: skip pullup() if already connected
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 004/982] ima: return error early if file xattr cannot be changed Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 006/982] tee: optee: Allow MT_NORMAL_TAGGED shared memory Greg Kroah-Hartman
` (983 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Yang, Alan Stern, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Yang <xu.yang_2@nxp.com>
[ Upstream commit 62911bc82b0332aee7546156800d3516500fa1e1 ]
The device controller may update vbus status via usb_udc_vbus_handler(),
which tries to connect the gadget even though gadget_bind_driver() has
already called usb_udc_connect_control_locked(). This causes pullup() to
be called twice. Avoid this by checking if gadget->connected is true.
This also set gadget->connected as false in usb_gadget_activate() if it
became connected while it was being deactivated. Otherwise,
usb_gadget_connect_locked will return early and pullup() won't be called.
Signed-off-by: Xu Yang <xu.yang_2@nxp.com>
Reviewed-by: Alan Stern <stern@rowland.harvard.edu>
Link: https://patch.msgid.link/20260423095355.2673035-1-xu.yang_2@nxp.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/udc/core.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/usb/gadget/udc/core.c b/drivers/usb/gadget/udc/core.c
index 577f7945cc303..addcff2f77110 100644
--- a/drivers/usb/gadget/udc/core.c
+++ b/drivers/usb/gadget/udc/core.c
@@ -714,6 +714,9 @@ static int usb_gadget_connect_locked(struct usb_gadget *gadget)
goto out;
}
+ if (gadget->connected)
+ goto out;
+
if (gadget->deactivated || !gadget->udc->allow_connect || !gadget->udc->started) {
/*
* If the gadget isn't usable (because it is deactivated,
@@ -887,8 +890,10 @@ int usb_gadget_activate(struct usb_gadget *gadget)
* If gadget has been connected before deactivation, or became connected
* while it was being deactivated, we call usb_gadget_connect().
*/
- if (gadget->connected)
+ if (gadget->connected) {
+ gadget->connected = false;
ret = usb_gadget_connect_locked(gadget);
+ }
unlock:
mutex_unlock(&gadget->udc->connect_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 006/982] tee: optee: Allow MT_NORMAL_TAGGED shared memory
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 005/982] usb: gadget: udc: skip pullup() if already connected Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 007/982] PCI: Stop setting cached power state to unknown on unbind Greg Kroah-Hartman
` (982 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hirokazu Honda, Sumit Garg,
Jens Wiklander, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hirokazu Honda <hiroh@chromium.org>
[ Upstream commit 1a6e94a8ff32e7879effd1e4a45bf112e506edc1 ]
On ARM64, shared memory can have MT_NORMAL_TAGGED attribute when using
the Memory Tagging Extension (MTE). The OP-TEE driver needs to
recognize this as normal memory to allow sharing such buffers with the
Secure World.
Signed-off-by: Hirokazu Honda <hiroh@chromium.org>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Signed-off-by: Jens Wiklander <jens.wiklander@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tee/optee/call.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/tee/optee/call.c b/drivers/tee/optee/call.c
index 290b1bb0e9cd7..5d4b8d75305f6 100644
--- a/drivers/tee/optee/call.c
+++ b/drivers/tee/optee/call.c
@@ -486,7 +486,8 @@ static bool is_normal_memory(pgprot_t p)
return (((pgprot_val(p) & L_PTE_MT_MASK) == L_PTE_MT_WRITEALLOC) ||
((pgprot_val(p) & L_PTE_MT_MASK) == L_PTE_MT_WRITEBACK));
#elif defined(CONFIG_ARM64)
- return (pgprot_val(p) & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL);
+ return ((pgprot_val(p) & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL)) ||
+ ((pgprot_val(p) & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL_TAGGED));
#else
#error "Unuspported architecture"
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 007/982] PCI: Stop setting cached power state to unknown on unbind
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 006/982] tee: optee: Allow MT_NORMAL_TAGGED shared memory Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 008/982] hfsplus: fix issue of direct writes beyond end-of-file Greg Kroah-Hartman
` (981 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lukas Wunner, Bjorn Helgaas,
Mario Limonciello (AMD), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lukas Wunner <lukas@wunner.de>
[ Upstream commit d462c8e89e84bfb6417e6b4c88e0cb7cc747ba41 ]
When a PCI device is unbound from its driver, pci_device_remove() sets the
cached power state in pci_dev->current_state to PCI_UNKNOWN. This was
introduced by commit 2449e06a5696 ("PCI: reset pci device state to unknown
state for resume") to invalidate the cached power state in case the system
is subsequently put to sleep.
For bound devices, the cached power state is set to PCI_UNKNOWN in
pci_pm_suspend_noirq(), immediately before entering system sleep.
Extend to unbound devices for consistency.
This obviates the need to change the cached power state on unbind, so stop
doing so.
Signed-off-by: Lukas Wunner <lukas@wunner.de>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/af7d11d3ceb231acc90829f7a5c8400c2446744f.1776415510.git.lukas@wunner.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/pci-driver.c | 10 ++--------
1 file changed, 2 insertions(+), 8 deletions(-)
diff --git a/drivers/pci/pci-driver.c b/drivers/pci/pci-driver.c
index fe6e5f716543a..fa3165e5b921b 100644
--- a/drivers/pci/pci-driver.c
+++ b/drivers/pci/pci-driver.c
@@ -490,13 +490,6 @@ static void pci_device_remove(struct device *dev)
/* Undo the runtime PM settings in local_pci_probe() */
pm_runtime_put_sync(dev);
- /*
- * If the device is still on, set the power state as "unknown",
- * since it might change by the next time we load the driver.
- */
- if (pci_dev->current_state == PCI_D0)
- pci_dev->current_state = PCI_UNKNOWN;
-
/*
* We would love to complain here if pci_dev->is_enabled is set, that
* the driver should have called pci_disable_device(), but the
@@ -874,7 +867,7 @@ static int pci_pm_suspend_noirq(struct device *dev)
if (!pm) {
pci_save_state(pci_dev);
- goto Fixup;
+ goto set_unknown;
}
if (pm->suspend_noirq) {
@@ -926,6 +919,7 @@ static int pci_pm_suspend_noirq(struct device *dev)
goto Fixup;
}
+set_unknown:
pci_pm_set_unknown_state(pci_dev);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 008/982] hfsplus: fix issue of direct writes beyond end-of-file
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 007/982] PCI: Stop setting cached power state to unknown on unbind Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 009/982] wifi: nl80211: reject beacons with bad HE operation Greg Kroah-Hartman
` (980 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Yangtao Li, linux-fsdevel, Viacheslav Dubeyko, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viacheslav Dubeyko <slava@dubeyko.com>
[ Upstream commit 5f63ac80aef2ee6bb58eab62e98c264774872da6 ]
The xfstests' test-case generic/729 fails with error:
sudo ./check generic/729
FSTYP -- hfsplus
PLATFORM -- Linux/x86_64 hfsplus-testing-0001 7.0.0-rc1+ #36 SMP PREEMPT_DYNAMIC Fri Apr 17 12:40:51 PDT 2026
MKFS_OPTIONS -- /dev/loop51
MOUNT_OPTIONS -- /dev/loop51 /mnt/scratch
generic/729 23s ... [failed, exit status 1]- output mismatch
mmap-rw-fault: /mnt/test/mmap-rw-fault.tmp: Input/output error
The hfsplus_get_block() only allows creating the next
sequential block. It returns -EIO for direct writes
beyond EOF. This patch waits for any in-flight DIO on the inode
to finish. Then, it extends the file by calling
generic_cont_expand_simple() with the goal to guarantee
that blockdev_direct_IO() finds all needed blocks
already reachable sequentially. And, finally, it flushes and
invalidates the DIO range again so the page cache is clean
before the direct write begins.
sudo ./check generic/729
FSTYP -- hfsplus
PLATFORM -- Linux/x86_64 hfsplus-testing-0001 7.0.0-rc1+ #40 SMP PREEMPT_DYNAMIC Thu Apr 16 15:41:03 PDT 2026
MKFS_OPTIONS -- /dev/loop51
MOUNT_OPTIONS -- /dev/loop51 /mnt/scratch
generic/729 23s ... 32s
Ran: generic/729
Passed all 1 tests
Closes: https://github.com/hfs-linux-kernel/hfs-linux-kernel/issues/210
cc: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
cc: Yangtao Li <frank.li@vivo.com>
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/20260417214940.2735557-2-slava@dubeyko.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/hfsplus/inode.c | 38 ++++++++++++++++++++++++++++++++++++--
1 file changed, 36 insertions(+), 2 deletions(-)
diff --git a/fs/hfsplus/inode.c b/fs/hfsplus/inode.c
index f065015f237c4..caf36ed7f590a 100644
--- a/fs/hfsplus/inode.c
+++ b/fs/hfsplus/inode.c
@@ -129,9 +129,44 @@ static ssize_t hfsplus_direct_IO(struct kiocb *iocb, struct iov_iter *iter)
struct file *file = iocb->ki_filp;
struct address_space *mapping = file->f_mapping;
struct inode *inode = mapping->host;
+ loff_t isize;
size_t count = iov_iter_count(iter);
+ loff_t end = iocb->ki_pos + count;
ssize_t ret;
+ /*
+ * The hfsplus_get_block() only allows creating the next sequential block.
+ * For direct writes beyond EOF, expand the file first.
+ */
+ if (iov_iter_rw(iter) == WRITE && iocb->ki_pos > i_size_read(inode)) {
+ loff_t start_off, end_off;
+ loff_t start_page, end_page;
+
+ isize = i_size_read(inode);
+
+ /*
+ * Wait for any in-flight DIO on this inode to finish before
+ * calling generic_cont_expand_simple().
+ */
+ inode_dio_wait(inode);
+
+ ret = generic_cont_expand_simple(inode, iocb->ki_pos);
+ if (ret)
+ return ret;
+
+ start_off = isize;
+ end_off = (end > 0) ? end - 1 : end;
+
+ ret = filemap_write_and_wait_range(mapping, start_off, end_off);
+ if (ret)
+ return ret;
+
+ start_page = start_off >> PAGE_SHIFT;
+ end_page = end_off >> PAGE_SHIFT;
+
+ invalidate_inode_pages2_range(mapping, start_page, end_page);
+ }
+
ret = blockdev_direct_IO(iocb, inode, iter, hfsplus_get_block);
/*
@@ -139,8 +174,7 @@ static ssize_t hfsplus_direct_IO(struct kiocb *iocb, struct iov_iter *iter)
* blocks outside i_size. Trim these off again.
*/
if (unlikely(iov_iter_rw(iter) == WRITE && ret < 0)) {
- loff_t isize = i_size_read(inode);
- loff_t end = iocb->ki_pos + count;
+ isize = i_size_read(inode);
if (end > isize)
hfsplus_write_failed(mapping, end);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 009/982] wifi: nl80211: reject beacons with bad HE operation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 008/982] hfsplus: fix issue of direct writes beyond end-of-file Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 010/982] wifi: mac80211: always allow transmitting null-data on TXQs Greg Kroah-Hartman
` (979 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Miriam Rachel Korenblit,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 8b9a100e1a76c52988b31099b349fd95a58c8768 ]
The HE operation element not only needs to be longer than
the fixed part, but also have an appropriate size for the
variable part inside of it. Check this.
Reviewed-by: Miriam Rachel Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260415144514.6217f5974fb5.Iff7ff6bcb159584e756d0f825c65860cdd53c6ea@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/nl80211.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index bb2d19057480b..069b04c29b64e 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -5805,8 +5805,12 @@ static int nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
if (cap && cap->datalen >= sizeof(*params->he_cap) + 1)
params->he_cap = (void *)(cap->data + 1);
cap = cfg80211_find_ext_elem(WLAN_EID_EXT_HE_OPERATION, ies, ies_len);
- if (cap && cap->datalen >= sizeof(*params->he_oper) + 1)
+ if (cap && cap->datalen >= sizeof(*params->he_oper) + 1) {
params->he_oper = (void *)(cap->data + 1);
+ /* takes extension ID into account */
+ if (cap->datalen < ieee80211_he_oper_size((void *)params->he_oper))
+ return -EINVAL;
+ }
cap = cfg80211_find_ext_elem(WLAN_EID_EXT_EHT_CAPABILITY, ies, ies_len);
if (cap) {
if (!cap->datalen)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 010/982] wifi: mac80211: always allow transmitting null-data on TXQs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 009/982] wifi: nl80211: reject beacons with bad HE operation Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 011/982] wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() Greg Kroah-Hartman
` (978 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jouni Malinen, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 51129a2ca0482b006d0e12a0aa025ff1e1cad2cb ]
Jouni reported that certain sequences of tests caused some
WDS tests to fail after applying the upcoming hwsim changes
for NAN. I bisected that down to converting hwsim to TXQs,
and after a long debug session found that the 4-addr NDP was
getting dropped, because it goes out via a (management) TXQ
and is a data frame.
It's unclear to me now why this only happens in some test
sequences (e.g. "sigma_dut_sae_h2e_ap_loop ap_wds_sta" and
"sigma_dut_eap_ttls_all_akm_suites ap_wds_sta_open"), maybe
that affects timing and the frame is otherwise delayed in
some way.
Correct the check to only drop frames that actually carry
data, not NDPs.
Reported-by: Jouni Malinen <j@w1.fi>
Link: https://patch.msgid.link/20260417141601.851ddf4adb59.I3d668c0e1bdca9cd98f2fc46f84a066e68cc7a62@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index 31f000aa22309..0cd02bd3fae30 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -3805,7 +3805,7 @@ struct sk_buff *ieee80211_tx_dequeue(struct ieee80211_hw *hw,
* injected frames or EAPOL frames from the local station.
*/
if (unlikely(!(info->flags & IEEE80211_TX_CTL_INJECTED) &&
- ieee80211_is_data(hdr->frame_control) &&
+ ieee80211_is_data_present(hdr->frame_control) &&
!ieee80211_vif_is_mesh(&tx.sdata->vif) &&
tx.sdata->vif.type != NL80211_IFTYPE_OCB &&
!is_multicast_ether_addr(hdr->addr1) &&
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 011/982] wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 010/982] wifi: mac80211: always allow transmitting null-data on TXQs Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 012/982] kcsan: Silence -Wmaybe-uninitialized when calling __kcsan_check_access() Greg Kroah-Hartman
` (977 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Oleksandr Havrylov,
Panagiotis Petrakopoulos, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Panagiotis Petrakopoulos <npetrakopoulos2003@gmail.com>
[ Upstream commit d5e6f353ce1e1c25b8458ea390ed09d2377412c5 ]
It was recently reported that rtw_fw_adaptivity_result()
in fw.c dereferences rtwdev->chip->edcca_th without
a NULL check. The issue is that devices with the
8821CE chip don't define edcca_th in their chip
info. As a result, when rtw_fw_adaptivity_result()
tries to dereference it, the kernel triggers an oops.
Add a NULL check for edcca_th before dereferencing
it in rtw_fw_adaptivity_result() in fw.c. Placing
the check at the function entry avoids logging any
garbage values.
This change does not address the root cause for
this behavior, but it prevents the NULL dereference
and the resulting oops while a more permanent solution
is developed.
Tested on a 8822CE chip which defines edcca_th, so
this issue is not present on it, but it still uses
this driver and I can verify there are no regressions.
Suggested-by: Ping-Ke Shih <pkshih@realtek.com>
Reported-by: Oleksandr Havrylov <goainwo@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221286
Signed-off-by: Panagiotis Petrakopoulos <npetrakopoulos2003@gmail.com>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Tested-by: Oleksandr Havrylov <goainwo@gmail.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260415052959.14844-1-npetrakopoulos2003@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw88/fw.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw88/fw.c b/drivers/net/wireless/realtek/rtw88/fw.c
index 0b5f903c0f366..28a37dcba223f 100644
--- a/drivers/net/wireless/realtek/rtw88/fw.c
+++ b/drivers/net/wireless/realtek/rtw88/fw.c
@@ -197,6 +197,9 @@ static void rtw_fw_adaptivity_result(struct rtw_dev *rtwdev, u8 *payload,
struct rtw_hw_reg_offset *edcca_th = rtwdev->chip->edcca_th;
struct rtw_c2h_adaptivity *result = (struct rtw_c2h_adaptivity *)payload;
+ if (!edcca_th)
+ return;
+
rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY,
"Adaptivity: density %x igi %x l2h_th_init %x l2h %x h2l %x option %x\n",
result->density, result->igi, result->l2h_th_init, result->l2h,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 012/982] kcsan: Silence -Wmaybe-uninitialized when calling __kcsan_check_access()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 011/982] wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 013/982] firmware: stratix10-svc: change get provision data to async SMC call Greg Kroah-Hartman
` (976 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Marco Elver,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Elver <elver@google.com>
[ Upstream commit 07a1a6562ce29e2e0c134a57882d6e52e8758492 ]
Some subsystems enable -Wmaybe-uninitialized [1], which can trigger
false positives when KCSAN is enabled. Specifically, passing an
uninitialized variable to functions that instrument accesses (e.g.,
copy_from_user()) results in calls to __kcsan_check_access().
Because __kcsan_check_access() takes a `const volatile void *ptr`, GCC
infers that the function may only read the memory location, and thus
warns if the passed variable is uninitialized.
However, KCSAN is a dynamic analysis tool for data race detection; while
it does read the memory location to detect concurrent modifications, the
"initialized'ness" of the memory location is irrelevant for its analysis.
Use absolute_pointer() in __kcsan_check_write(), kcsan_check_write(),
and kcsan_check_atomic_write() to hide the pointer from the compiler,
preventing it from concluding that the pointer passed points to
uninitialized memory.
This fixes warnings like:
| CC fs/ntfs3/file.o
| In file included from include/asm-generic/rwonce.h:27,
| from arch/arm64/include/asm/rwonce.h:81,
| from include/linux/compiler.h:369,
| from include/linux/array_size.h:5,
| from include/linux/kernel.h:16,
| from include/linux/backing-dev.h:12,
| from fs/ntfs3/file.c:10:
| In function 'instrument_copy_from_user_before',
| inlined from '_inline_copy_from_user' at include/linux/uaccess.h:184:2,
| inlined from 'copy_from_user' at include/linux/uaccess.h:221:9,
| inlined from 'ntfs_ioctl_fitrim' at fs/ntfs3/file.c:77:6,
| inlined from 'ntfs_ioctl' at fs/ntfs3/file.c:164:10:
| include/linux/kcsan-checks.h:220:28: error: 'range' may be used uninitialized [-Werror=maybe-uninitialized]
| 220 | #define kcsan_check_access __kcsan_check_access
| | ^
| include/linux/kcsan-checks.h:311:9: note: in expansion of macro 'kcsan_check_access'
| 311 | kcsan_check_access(ptr, size, KCSAN_ACCESS_WRITE)
| | ^~~~~~~~~~~~~~~~~~
| include/linux/instrumented.h:147:9: note: in expansion of macro 'kcsan_check_write'
| 147 | kcsan_check_write(to, n);
| | ^~~~~~~~~~~~~~~~~
| include/linux/kcsan-checks.h: In function 'ntfs_ioctl':
| include/linux/kcsan-checks.h:37:6: note: by argument 1 of type 'const volatile void *' to '__kcsan_check_access' declared here
| 37 | void __kcsan_check_access(const volatile void *ptr, size_t size, int type);
| | ^~~~~~~~~~~~~~~~~~~~
| fs/ntfs3/file.c:65:29: note: 'range' declared here
| 65 | struct fstrim_range range;
| | ^~~~~
Link: https://lore.kernel.org/all/5da10cca-875b-418d-b54e-6be3ea32c266@app.fastmail.com/ [1]
Reported-by: Arnd Bergmann <arnd@arndb.de>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Tested-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Marco Elver <elver@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/kcsan-checks.h | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/include/linux/kcsan-checks.h b/include/linux/kcsan-checks.h
index 92f3843d9ebb8..e135dacaa90f3 100644
--- a/include/linux/kcsan-checks.h
+++ b/include/linux/kcsan-checks.h
@@ -282,7 +282,7 @@ static inline void __kcsan_disable_current(void) { }
* @size: size of access
*/
#define __kcsan_check_write(ptr, size) \
- __kcsan_check_access(ptr, size, KCSAN_ACCESS_WRITE)
+ __kcsan_check_access(absolute_pointer(ptr), size, KCSAN_ACCESS_WRITE)
/**
* __kcsan_check_read_write - check regular read-write access for races
@@ -308,7 +308,7 @@ static inline void __kcsan_disable_current(void) { }
* @size: size of access
*/
#define kcsan_check_write(ptr, size) \
- kcsan_check_access(ptr, size, KCSAN_ACCESS_WRITE)
+ kcsan_check_access(absolute_pointer(ptr), size, KCSAN_ACCESS_WRITE)
/**
* kcsan_check_read_write - check regular read-write access for races
@@ -331,7 +331,7 @@ static inline void __kcsan_disable_current(void) { }
#define kcsan_check_atomic_read(ptr, size) \
kcsan_check_access(ptr, size, KCSAN_ACCESS_ATOMIC)
#define kcsan_check_atomic_write(ptr, size) \
- kcsan_check_access(ptr, size, KCSAN_ACCESS_ATOMIC | KCSAN_ACCESS_WRITE)
+ kcsan_check_access(absolute_pointer(ptr), size, KCSAN_ACCESS_ATOMIC | KCSAN_ACCESS_WRITE)
#define kcsan_check_atomic_read_write(ptr, size) \
kcsan_check_access(ptr, size, KCSAN_ACCESS_ATOMIC | KCSAN_ACCESS_WRITE | KCSAN_ACCESS_COMPOUND)
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 013/982] firmware: stratix10-svc: change get provision data to async SMC call
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 012/982] kcsan: Silence -Wmaybe-uninitialized when calling __kcsan_check_access() Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 014/982] bridge: Do not suppress ARP probes and DAD NS unconditionally Greg Kroah-Hartman
` (975 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Gong, Siew Chin Lim,
Dinh Nguyen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Siew Chin Lim <elly.siew.chin.lim@intel.com>
[ Upstream commit 4b0a32016347bfd6ae9849f21b1b767905f68d14 ]
Change INTEL_SIP_SMC_FCS_GET_PROVISION_DATA's SMC call to async from sync
to avoid long runtime which may cause the watchdog timeout issue.
Signed-off-by: Richard Gong <richard.gong@intel.com>
Signed-off-by: Siew Chin Lim <elly.siew.chin.lim@intel.com>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/stratix10-svc.c | 4 ++--
include/linux/firmware/intel/stratix10-smc.h | 12 ++++--------
2 files changed, 6 insertions(+), 10 deletions(-)
diff --git a/drivers/firmware/stratix10-svc.c b/drivers/firmware/stratix10-svc.c
index c4a709f2bbc7a..5966f09e73fc7 100644
--- a/drivers/firmware/stratix10-svc.c
+++ b/drivers/firmware/stratix10-svc.c
@@ -339,6 +339,7 @@ static void svc_thread_recv_status_ok(struct stratix10_svc_data *p_data,
case COMMAND_FCS_SEND_CERTIFICATE:
case COMMAND_FCS_DATA_ENCRYPTION:
case COMMAND_FCS_DATA_DECRYPTION:
+ case COMMAND_FCS_GET_PROVISION_DATA:
cb_data->status = BIT(SVC_STATUS_OK);
break;
case COMMAND_RECONFIG_DATA_SUBMIT:
@@ -365,7 +366,6 @@ static void svc_thread_recv_status_ok(struct stratix10_svc_data *p_data,
cb_data->kaddr2 = &res.a2;
break;
case COMMAND_FCS_RANDOM_NUMBER_GEN:
- case COMMAND_FCS_GET_PROVISION_DATA:
case COMMAND_POLL_SERVICE_STATUS:
cb_data->status = BIT(SVC_STATUS_OK);
cb_data->kaddr1 = &res.a1;
@@ -525,7 +525,7 @@ static int svc_normal_to_secure_thread(void *data)
break;
case COMMAND_FCS_GET_PROVISION_DATA:
a0 = INTEL_SIP_SMC_FCS_GET_PROVISION_DATA;
- a1 = (unsigned long)pdata->paddr;
+ a1 = 0;
a2 = 0;
break;
diff --git a/include/linux/firmware/intel/stratix10-smc.h b/include/linux/firmware/intel/stratix10-smc.h
index a718f853d4578..4ae295c4e9cc1 100644
--- a/include/linux/firmware/intel/stratix10-smc.h
+++ b/include/linux/firmware/intel/stratix10-smc.h
@@ -575,24 +575,20 @@ INTEL_SIP_SMC_FAST_CALL_VAL(INTEL_SIP_SMC_FUNCID_FPGA_CONFIG_COMPLETED_WRITE)
/**
* Request INTEL_SIP_SMC_FCS_GET_PROVISION_DATA
- * Sync call to dump all the fuses and key hashes
+ * Async call to dump all the fuses and key hashes
*
* Call register usage:
* a0 INTEL_SIP_SMC_FCS_GET_PROVISION_DATA
- * a1 the physical address for firmware to write structure of fuse and
- * key hashes
- * a2-a7 not used
+ * a1-a7 not used
*
* Return status:
* a0 INTEL_SIP_SMC_STATUS_OK, INTEL_SIP_SMC_FCS_ERROR or
* INTEL_SIP_SMC_FCS_REJECTED
- * a1 mailbox error
- * a2 physical address for the structure of fuse and key hashes
- * a3 the size of structure
+ * a1-a3 not used
*
*/
#define INTEL_SIP_SMC_FUNCID_FCS_GET_PROVISION_DATA 94
#define INTEL_SIP_SMC_FCS_GET_PROVISION_DATA \
- INTEL_SIP_SMC_FAST_CALL_VAL(INTEL_SIP_SMC_FUNCID_FCS_GET_PROVISION_DATA)
+ INTEL_SIP_SMC_STD_CALL_VAL(INTEL_SIP_SMC_FUNCID_FCS_GET_PROVISION_DATA)
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 014/982] bridge: Do not suppress ARP probes and DAD NS unconditionally
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 013/982] firmware: stratix10-svc: change get provision data to async SMC call Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 015/982] soundwire: validate DT compatible before parsing it Greg Kroah-Hartman
` (974 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Danielle Ratson,
Nikolay Aleksandrov, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Danielle Ratson <danieller@nvidia.com>
[ Upstream commit fee1fc1d5a5475f5516d406a03e443348cd0f06c ]
When neighbor suppression is enabled on a VXLAN port, the bridge is
expected to reply to ARP/NS messages on behalf of remote hosts when both
FDB and neighbor entries exist. This allows the bridge to suppress
flooding of these messages to the VXLAN overlay.
According to RFC 9161 ("Operational Aspects of Proxy ARP/ND in Ethernet
Virtual Private Networks"):
"A PE SHOULD reply to broadcast/multicast address resolution messages,
i.e., ARP Requests, ARP probes, NS messages, as well as DAD NS messages.
An ARP probe is an ARP Request constructed with an all-zero sender IP
address that may be used by hosts for IPv4 Address Conflict Detection as
specified in [RFC5227]".
However, the current implementation unconditionally suppresses ARP probes
and DAD Neighbor Solicitations, which breaks Duplicate Address Detection
(DAD) over EVPN.
For DAD to work correctly over the VXLAN fabric:
- When the bridge does not know the answer:
flood the probe/DAD packet to allow remote VTEPs to respond.
- When the bridge knows the answer:
reply to indicate the address is in use.
Fix by adjusting the early suppression checks to exclude ARP probes and
DAD NS from unconditional suppression.
When replying to a DAD NS, br_nd_send() is adjusted to set the NA
destination to the all-nodes multicast address (ff02::1) and clear the
Solicited flag, in accordance with RFC 4861 section 7.2.4.
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Danielle Ratson <danieller@nvidia.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260429062405.1386417-2-danieller@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_arp_nd_proxy.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/net/bridge/br_arp_nd_proxy.c b/net/bridge/br_arp_nd_proxy.c
index 1914027e8bb3c..97d0349189aaf 100644
--- a/net/bridge/br_arp_nd_proxy.c
+++ b/net/bridge/br_arp_nd_proxy.c
@@ -162,7 +162,7 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br,
return;
if (parp->ar_op != htons(ARPOP_RREQUEST) &&
parp->ar_op != htons(ARPOP_RREPLY) &&
- (ipv4_is_zeronet(sip) || sip == tip)) {
+ sip == tip) {
/* prevent flooding to neigh suppress ports */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return;
@@ -260,6 +260,7 @@ static void br_nd_send(struct net_bridge *br, struct net_bridge_port *p,
int ns_olen;
int i, len;
u8 *daddr;
+ bool dad;
u16 pvid;
if (!dev || skb_linearize(request))
@@ -298,8 +299,13 @@ static void br_nd_send(struct net_bridge *br, struct net_bridge_port *p,
}
}
+ dad = ipv6_addr_any(&ipv6_hdr(request)->saddr);
+
/* Ethernet header */
- ether_addr_copy(eth_hdr(reply)->h_dest, daddr);
+ if (dad)
+ ipv6_eth_mc_map(&in6addr_linklocal_allnodes, eth_hdr(reply)->h_dest);
+ else
+ ether_addr_copy(eth_hdr(reply)->h_dest, daddr);
ether_addr_copy(eth_hdr(reply)->h_source, n->ha);
eth_hdr(reply)->h_proto = htons(ETH_P_IPV6);
reply->protocol = htons(ETH_P_IPV6);
@@ -315,7 +321,7 @@ static void br_nd_send(struct net_bridge *br, struct net_bridge_port *p,
pip6->priority = ipv6_hdr(request)->priority;
pip6->nexthdr = IPPROTO_ICMPV6;
pip6->hop_limit = 255;
- pip6->daddr = ipv6_hdr(request)->saddr;
+ pip6->daddr = dad ? in6addr_linklocal_allnodes : ipv6_hdr(request)->saddr;
pip6->saddr = *(struct in6_addr *)n->primary_key;
skb_pull(reply, sizeof(struct ipv6hdr));
@@ -328,7 +334,7 @@ static void br_nd_send(struct net_bridge *br, struct net_bridge_port *p,
na->icmph.icmp6_type = NDISC_NEIGHBOUR_ADVERTISEMENT;
na->icmph.icmp6_router = (n->flags & NTF_ROUTER) ? 1 : 0;
na->icmph.icmp6_override = 1;
- na->icmph.icmp6_solicited = 1;
+ na->icmph.icmp6_solicited = dad ? 0 : 1;
na->target = ns->target;
ether_addr_copy(&na->opt[2], n->ha);
na->opt[0] = ND_OPT_TARGET_LL_ADDR;
@@ -429,7 +435,7 @@ void br_do_suppress_nd(struct sk_buff *skb, struct net_bridge *br,
saddr = &iphdr->saddr;
daddr = &iphdr->daddr;
- if (ipv6_addr_any(saddr) || !ipv6_addr_cmp(saddr, daddr)) {
+ if (!ipv6_addr_cmp(saddr, daddr)) {
/* prevent flooding to neigh suppress ports */
BR_INPUT_SKB_CB(skb)->proxyarp_replied = 1;
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 015/982] soundwire: validate DT compatible before parsing it
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 014/982] bridge: Do not suppress ARP probes and DAD NS unconditionally Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 016/982] media: rc: mceusb: Add support for 04eb:e033 Greg Kroah-Hartman
` (973 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Vinod Koul,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 45c7bda7b7440183850012153988e40b300f40d0 ]
`sdw_of_find_slaves()` fetches raw `"compatible"` bytes with
`of_get_property()` and then immediately parses them with
`sscanf("sdw%01x%04hx%04hx%02hhx", ...)`.
Live-tree OF properties are stored as raw bytes plus a separate length;
they are not globally guaranteed to be NUL-terminated. Validate the
first compatible string before parsing it.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260403183504.4-soundwire-compatible-pengpeng@iscas.ac.cn
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/slave.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/soundwire/slave.c b/drivers/soundwire/slave.c
index 28b0d7b6d780c..60a80904e75bb 100644
--- a/drivers/soundwire/slave.c
+++ b/drivers/soundwire/slave.c
@@ -233,8 +233,8 @@ int sdw_of_find_slaves(struct sdw_bus *bus)
struct sdw_slave_id id;
const __be32 *addr;
- compat = of_get_property(node, "compatible", NULL);
- if (!compat)
+ ret = of_property_read_string(node, "compatible", &compat);
+ if (ret)
continue;
ret = sscanf(compat, "sdw%01x%04hx%04hx%02hhx", &sdw_version,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 016/982] media: rc: mceusb: Add support for 04eb:e033
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 015/982] soundwire: validate DT compatible before parsing it Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 017/982] s390/cio: Purge based on the cdevs online status Greg Kroah-Hartman
` (972 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Riccardo Boninsegna, Sean Young,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Riccardo Boninsegna <rboninsegna2@gmail.com>
[ Upstream commit 0692c2602e4cd410aa045f8991bd1c142b2e56f9 ]
This is a Sonix SN8P2202XG microcontroller with firmware compatible with
the already supported Northstar 04eb:e004, implementing an MCE IR receiver
(PCB seems to be tracked for a transmitter too but missing related parts).
Found in a Skintek SK-CR-IN+IR ( http://www.skintek.it/SK-CR-IN+IR.php )
internal 3.5 inch USB card reader and MCE receiver combo
(implemented by, and wired as, separate USB devices)
PCB marking: AU6475 966816 STIR REV:A02 MCE
Signed-off-by: Riccardo Boninsegna <rboninsegna2@gmail.com>
Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/rc/mceusb.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/media/rc/mceusb.c b/drivers/media/rc/mceusb.c
index c76ba24c1f559..e74ca24a149b8 100644
--- a/drivers/media/rc/mceusb.c
+++ b/drivers/media/rc/mceusb.c
@@ -398,6 +398,8 @@ static const struct usb_device_id mceusb_dev_table[] = {
{ USB_DEVICE(VENDOR_COMPRO, 0x3082) },
/* Northstar Systems, Inc. eHome Infrared Transceiver */
{ USB_DEVICE(VENDOR_NORTHSTAR, 0xe004) },
+ /* Northstar Systems, Inc. eHome Infrared Transceiver - variant */
+ { USB_DEVICE(VENDOR_NORTHSTAR, 0xe033) },
/* TiVo PC IR Receiver */
{ USB_DEVICE(VENDOR_TIVO, 0x2000),
.driver_info = TIVO_KIT },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 017/982] s390/cio: Purge based on the cdevs online status
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 016/982] media: rc: mceusb: Add support for 04eb:e033 Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 018/982] thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() Greg Kroah-Hartman
` (971 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vineeth Vijayan, Peter Oberparleiter,
Alexander Gordeev, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
[ Upstream commit 58d50cad63e85daae032924ecc3d457fb1ec02fb ]
Ensure that all devices currently offline are purged correctly.
Previously, purging logic relied on the internal FSM state to
determine whether a device was offline. However, devices with a
target state of offline could be skipped if CIO internal
processing was still ongoing during the purge operation.
Update the purge decision logic to rely on the online variable
in the cdev structure instead of the internal FSM state,
providing a more reliable indication of actual device
availability.
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Signed-off-by: Alexander Gordeev <agordeev@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/cio/device.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/s390/cio/device.c b/drivers/s390/cio/device.c
index 1873c865b4d6c..bfecf08aeb894 100644
--- a/drivers/s390/cio/device.c
+++ b/drivers/s390/cio/device.c
@@ -1322,7 +1322,7 @@ static int purge_fn(struct subchannel *sch, void *data)
cdev = sch_get_cdev(sch);
if (cdev) {
- if (cdev->private->state != DEV_STATE_OFFLINE)
+ if (cdev->online)
goto unlock;
if (atomic_cmpxchg(&cdev->private->onoff, 0, 1) != 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 018/982] thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 017/982] s390/cio: Purge based on the cdevs online status Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 019/982] thunderbolt: Keep XDomain reference during the lifetime of a service Greg Kroah-Hartman
` (970 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mika Westerberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mika Westerberg <mika.westerberg@linux.intel.com>
[ Upstream commit 4c63f29872cb444b33665348bbd2f45cab06afcd ]
If tb_cfg_request() fails setting up the request (for example the
control channel is shut down already) it returns an error without
calling the callback. To avoid leaking that memory, call
tb_cfg_request_put() if tb_cfg_request() fails.
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thunderbolt/xdomain.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/thunderbolt/xdomain.c b/drivers/thunderbolt/xdomain.c
index 371911e2ae428..6a003316b878b 100644
--- a/drivers/thunderbolt/xdomain.c
+++ b/drivers/thunderbolt/xdomain.c
@@ -138,6 +138,7 @@ static int __tb_xdomain_response(struct tb_ctl *ctl, const void *response,
size_t size, enum tb_cfg_pkg_type type)
{
struct tb_cfg_request *req;
+ int ret;
req = tb_cfg_request_alloc();
if (!req)
@@ -149,7 +150,11 @@ static int __tb_xdomain_response(struct tb_ctl *ctl, const void *response,
req->request_size = size;
req->request_type = type;
- return tb_cfg_request(ctl, req, response_ready, req);
+ ret = tb_cfg_request(ctl, req, response_ready, req);
+ if (ret)
+ tb_cfg_request_put(req);
+
+ return ret;
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 019/982] thunderbolt: Keep XDomain reference during the lifetime of a service
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 018/982] thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 020/982] thunderbolt: Keep the domain reference while processing hotplug Greg Kroah-Hartman
` (969 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mika Westerberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mika Westerberg <mika.westerberg@linux.intel.com>
[ Upstream commit 8b4060998637f06975fceee9b73845d8672d411e ]
This is needed because we release the service ID in tb_service_release()
and the ID array is owned by the parent XDomain.
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thunderbolt/xdomain.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/thunderbolt/xdomain.c b/drivers/thunderbolt/xdomain.c
index 6a003316b878b..58c91423e4f07 100644
--- a/drivers/thunderbolt/xdomain.c
+++ b/drivers/thunderbolt/xdomain.c
@@ -1026,6 +1026,7 @@ static void tb_service_release(struct device *dev)
ida_simple_remove(&xd->service_ids, svc->id);
kfree(svc->key);
kfree(svc);
+ tb_xdomain_put(xd);
}
struct device_type tb_service_type = {
@@ -1134,7 +1135,7 @@ static void enumerate_services(struct tb_xdomain *xd)
svc->id = id;
svc->dev.bus = &tb_bus_type;
svc->dev.type = &tb_service_type;
- svc->dev.parent = &xd->dev;
+ svc->dev.parent = get_device(&xd->dev);
dev_set_name(&svc->dev, "%s.%d", dev_name(&xd->dev), svc->id);
tb_service_debugfs_init(svc);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 020/982] thunderbolt: Keep the domain reference while processing hotplug
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 019/982] thunderbolt: Keep XDomain reference during the lifetime of a service Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 021/982] thunderbolt: Set tb->root_switch to NULL when domain is stopped Greg Kroah-Hartman
` (968 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mika Westerberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mika Westerberg <mika.westerberg@linux.intel.com>
[ Upstream commit 138ec65b2c761f065b19d115aed2b8246fc272f5 ]
We process hotplug events in a workqueue that may run after the domain
has been removed by tb_domain_remove(). For example if user unloads the
driver while at the same time plugging a device router we may have
scheduled tb_handle_hotplug() to run. Avoid possible UAF in this case by
taking the domain reference before scheduling the hotplug handler in
tb_queue_hotplug().
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thunderbolt/tb.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c
index f417ce477d4a0..3c993a40c2313 100644
--- a/drivers/thunderbolt/tb.c
+++ b/drivers/thunderbolt/tb.c
@@ -59,7 +59,7 @@ static void tb_queue_hotplug(struct tb *tb, u64 route, u8 port, bool unplug)
if (!ev)
return;
- ev->tb = tb;
+ ev->tb = tb_domain_get(tb);
ev->route = route;
ev->port = port;
ev->unplug = unplug;
@@ -1464,6 +1464,9 @@ static void tb_handle_hotplug(struct work_struct *work)
pm_runtime_mark_last_busy(&tb->dev);
pm_runtime_put_autosuspend(&tb->dev);
+ /* Undo the refcount increased in tb_queue_hotplug() */
+ tb_domain_put(tb);
+
kfree(ev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 021/982] thunderbolt: Set tb->root_switch to NULL when domain is stopped
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 020/982] thunderbolt: Keep the domain reference while processing hotplug Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 022/982] thunderbolt: Dont create multiple DMA tunnels on firmware connection manager Greg Kroah-Hartman
` (967 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mika Westerberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mika Westerberg <mika.westerberg@linux.intel.com>
[ Upstream commit e56249d8a68e712f3b60e1f3fdbb5b4fea146468 ]
Similarly what we do with the firmware connection manager. This makes
tb_xdp_handle_request() return error to the remote host. However, we
need to make sure we keep the uuid alive so that we can reply until the
whole domain is released.
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thunderbolt/tb.c | 1 +
drivers/thunderbolt/xdomain.c | 6 +++++-
2 files changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c
index 3c993a40c2313..00cedf7c24725 100644
--- a/drivers/thunderbolt/tb.c
+++ b/drivers/thunderbolt/tb.c
@@ -1515,6 +1515,7 @@ static void tb_stop(struct tb *tb)
tb_tunnel_free(tunnel);
}
tb_switch_remove(tb->root_switch);
+ tb->root_switch = NULL;
tcm->hotplug_active = false; /* signal tb_handle_hotplug to quit */
}
diff --git a/drivers/thunderbolt/xdomain.c b/drivers/thunderbolt/xdomain.c
index 58c91423e4f07..f0753a0d5b72e 100644
--- a/drivers/thunderbolt/xdomain.c
+++ b/drivers/thunderbolt/xdomain.c
@@ -755,7 +755,7 @@ static void tb_xdp_handle_request(struct work_struct *work)
mutex_lock(&tb->lock);
if (tb->root_switch)
- uuid = tb->root_switch->uuid;
+ uuid = kmemdup(tb->root_switch->uuid, sizeof(*uuid), GFP_KERNEL);
else
uuid = NULL;
mutex_unlock(&tb->lock);
@@ -869,6 +869,7 @@ static void tb_xdp_handle_request(struct work_struct *work)
}
out:
+ kfree(uuid);
kfree(xw->pkg);
kfree(xw);
@@ -2223,6 +2224,9 @@ static struct tb_xdomain *switch_find_xdomain(struct tb_switch *sw,
{
struct tb_port *port;
+ if (!sw)
+ return NULL;
+
tb_switch_for_each_port(sw, port) {
struct tb_xdomain *xd;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 022/982] thunderbolt: Dont create multiple DMA tunnels on firmware connection manager
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 021/982] thunderbolt: Set tb->root_switch to NULL when domain is stopped Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 023/982] media: dm1105: fix missing error check for dma_alloc_coherent Greg Kroah-Hartman
` (966 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alan Borzeszkowski, Mika Westerberg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alan Borzeszkowski <alan.borzeszkowski@linux.intel.com>
[ Upstream commit cf0c38ee554c3e9062408cc3a38325483d52ecd0 ]
Firmware connection manager supports only one DMA tunnel per XDomain
connection. Firmware prior Intel Titan Ridge failed the operation
directly but the same does not happen anymore on Titan Ridge and
forward. For this reason add an explicit check, and fail the operation
accordingly in the driver.
Signed-off-by: Alan Borzeszkowski <alan.borzeszkowski@linux.intel.com>
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thunderbolt/icm.c | 10 ++++++++++
drivers/thunderbolt/xdomain.c | 25 +++++++++++++++++++------
include/linux/thunderbolt.h | 2 ++
3 files changed, 31 insertions(+), 6 deletions(-)
diff --git a/drivers/thunderbolt/icm.c b/drivers/thunderbolt/icm.c
index 6d354392fcbc4..090388d71f46f 100644
--- a/drivers/thunderbolt/icm.c
+++ b/drivers/thunderbolt/icm.c
@@ -565,6 +565,11 @@ static int icm_fr_approve_xdomain_paths(struct tb *tb, struct tb_xdomain *xd,
struct icm_fr_pkg_approve_xdomain request;
int ret;
+ if (atomic_read(&xd->ntunnels) >= 1) {
+ tb_warn(tb, "only one tunnel is supported by the firmware\n");
+ return -EOPNOTSUPP;
+ }
+
memset(&request, 0, sizeof(request));
request.hdr.code = ICM_APPROVE_XDOMAIN;
request.link_info = xd->depth << ICM_LINK_INFO_DEPTH_SHIFT | xd->link;
@@ -1134,6 +1139,11 @@ static int icm_tr_approve_xdomain_paths(struct tb *tb, struct tb_xdomain *xd,
struct icm_tr_pkg_approve_xdomain request;
int ret;
+ if (atomic_read(&xd->ntunnels) >= 1) {
+ tb_warn(tb, "only one tunnel is supported by the firmware\n");
+ return -EOPNOTSUPP;
+ }
+
memset(&request, 0, sizeof(request));
request.hdr.code = ICM_APPROVE_XDOMAIN;
request.route_hi = upper_32_bits(xd->route);
diff --git a/drivers/thunderbolt/xdomain.c b/drivers/thunderbolt/xdomain.c
index f0753a0d5b72e..6dac354de4bb8 100644
--- a/drivers/thunderbolt/xdomain.c
+++ b/drivers/thunderbolt/xdomain.c
@@ -1920,6 +1920,7 @@ struct tb_xdomain *tb_xdomain_alloc(struct tb *tb, struct device *parent,
INIT_DELAYED_WORK(&xd->state_work, tb_xdomain_state_work);
INIT_DELAYED_WORK(&xd->properties_changed_work,
tb_xdomain_properties_changed);
+ atomic_set(&xd->ntunnels, 0);
xd->local_uuid = kmemdup(local_uuid, sizeof(uuid_t), GFP_KERNEL);
if (!xd->local_uuid)
@@ -2181,9 +2182,15 @@ int tb_xdomain_enable_paths(struct tb_xdomain *xd, int transmit_path,
int transmit_ring, int receive_path,
int receive_ring)
{
- return tb_domain_approve_xdomain_paths(xd->tb, xd, transmit_path,
- transmit_ring, receive_path,
- receive_ring);
+ int ret;
+
+ ret = tb_domain_approve_xdomain_paths(xd->tb, xd, transmit_path,
+ transmit_ring, receive_path,
+ receive_ring);
+ if (ret)
+ return ret;
+ atomic_inc(&xd->ntunnels);
+ return 0;
}
EXPORT_SYMBOL_GPL(tb_xdomain_enable_paths);
@@ -2206,9 +2213,15 @@ int tb_xdomain_disable_paths(struct tb_xdomain *xd, int transmit_path,
int transmit_ring, int receive_path,
int receive_ring)
{
- return tb_domain_disconnect_xdomain_paths(xd->tb, xd, transmit_path,
- transmit_ring, receive_path,
- receive_ring);
+ int ret;
+
+ ret = tb_domain_disconnect_xdomain_paths(xd->tb, xd, transmit_path,
+ transmit_ring, receive_path,
+ receive_ring);
+ if (ret)
+ return ret;
+ atomic_dec(&xd->ntunnels);
+ return 0;
}
EXPORT_SYMBOL_GPL(tb_xdomain_disable_paths);
diff --git a/include/linux/thunderbolt.h b/include/linux/thunderbolt.h
index 98af9ad04cac1..fbeab0ec165ca 100644
--- a/include/linux/thunderbolt.h
+++ b/include/linux/thunderbolt.h
@@ -210,6 +210,7 @@ void tb_unregister_property_dir(const char *key, struct tb_property_dir *dir);
* changed notification
* @bonding_possible: True if lane bonding is possible on local side
* @target_link_width: Target link width from the remote host
+ * @ntunnels: Keeps track of how many tunnels go through this XDomain
* @link: Root switch link the remote domain is connected (ICM only)
* @depth: Depth in the chain the remote domain is connected (ICM only)
*
@@ -256,6 +257,7 @@ struct tb_xdomain {
int properties_changed_retries;
bool bonding_possible;
u8 target_link_width;
+ atomic_t ntunnels;
u8 link;
u8 depth;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 023/982] media: dm1105: fix missing error check for dma_alloc_coherent
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 022/982] thunderbolt: Dont create multiple DMA tunnels on firmware connection manager Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 024/982] net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family Greg Kroah-Hartman
` (965 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhaoyang Yu, Hans Verkuil,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhaoyang Yu <2426767509@qq.com>
[ Upstream commit 3eaac9e02d8591d3c790db572ef1c8fa5a841fdb ]
The return value of dm1105_dma_map(), which handles DMA memory allocation,
is ignored in dm1105_hw_init(). If dma_alloc_coherent() fails, the driver
will proceed using a NULL pointer for DMA transfers, leading to a kernel
oops or invalid hardware access.
Fix this by checking the return value and propagating -ENOMEM on failure.
Signed-off-by: Zhaoyang Yu <2426767509@qq.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/pci/dm1105/dm1105.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/media/pci/dm1105/dm1105.c b/drivers/media/pci/dm1105/dm1105.c
index 57f7e4df41b22..f20bea8623af7 100644
--- a/drivers/media/pci/dm1105/dm1105.c
+++ b/drivers/media/pci/dm1105/dm1105.c
@@ -767,6 +767,8 @@ static void dm1105_ir_exit(struct dm1105_dev *dm1105)
static int dm1105_hw_init(struct dm1105_dev *dev)
{
+ int ret;
+
dm1105_disable_irqs(dev);
dm_writeb(DM1105_HOST_CTR, 0);
@@ -777,7 +779,10 @@ static int dm1105_hw_init(struct dm1105_dev *dev)
dm_writew(DM1105_TSCTR, 0xc10a);
/* map DMA and set address */
- dm1105_dma_map(dev);
+ ret = dm1105_dma_map(dev);
+ if (ret)
+ return -ENOMEM;
+
dm1105_set_dma_addr(dev);
/* big buffer */
dm_writel(DM1105_RLEN, 5 * DM1105_DMA_BYTES);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 024/982] net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 023/982] media: dm1105: fix missing error check for dma_alloc_coherent Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 025/982] PCI: switchtec: Add Gen6 Device IDs Greg Kroah-Hartman
` (964 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Behún, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marek Behún <kabel@kernel.org>
[ Upstream commit d201c2612e5aada0c931cd55115175e0a5141023 ]
The 6320 family has 9 global1 interrupt, not 8. Fix it.
Signed-off-by: Marek Behún <kabel@kernel.org>
Link: https://patch.msgid.link/20260504153227.1390546-2-kabel@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mv88e6xxx/chip.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 29e4c94c84051..783d7035f065e 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -6228,7 +6228,7 @@ static const struct mv88e6xxx_info mv88e6xxx_table[] = {
.global1_addr = 0x1b,
.global2_addr = 0x1c,
.age_time_coeff = 15000,
- .g1_irqs = 8,
+ .g1_irqs = 9,
.g2_irqs = 10,
.atu_move_port_mask = 0xf,
.pvt = true,
@@ -6255,7 +6255,7 @@ static const struct mv88e6xxx_info mv88e6xxx_table[] = {
.global1_addr = 0x1b,
.global2_addr = 0x1c,
.age_time_coeff = 15000,
- .g1_irqs = 8,
+ .g1_irqs = 9,
.g2_irqs = 10,
.atu_move_port_mask = 0xf,
.pvt = true,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 025/982] PCI: switchtec: Add Gen6 Device IDs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 024/982] net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 026/982] net: dsa: mv88e6xxx: define .pot_clear() for 6321 Greg Kroah-Hartman
` (963 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ben Reed, Logan Gunthorpe,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ben Reed <Ben.Reed@microchip.com>
[ Upstream commit 5e6c21c56998e1e58d2f314e70779989ea0fee5d ]
Add device IDs for the next generation of switchtec products.
No changes to the driver were required with the new version of the
hardware.
[logang: rewrote commit message]
Signed-off-by: Ben Reed <Ben.Reed@microchip.com>
Signed-off-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260505161633.67454-1-logang@deltatee.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/switch/switchtec.c | 16 ++++++++++++++++
include/linux/switchtec.h | 1 +
2 files changed, 17 insertions(+)
diff --git a/drivers/pci/switch/switchtec.c b/drivers/pci/switch/switchtec.c
index 9011518b1d132..37c5ba40d959f 100644
--- a/drivers/pci/switch/switchtec.c
+++ b/drivers/pci/switch/switchtec.c
@@ -1853,6 +1853,22 @@ static const struct pci_device_id switchtec_pci_tbl[] = {
SWITCHTEC_PCI_DEVICE(0x5552, SWITCHTEC_GEN5), /* PAXA 52XG5 */
SWITCHTEC_PCI_DEVICE(0x5536, SWITCHTEC_GEN5), /* PAXA 36XG5 */
SWITCHTEC_PCI_DEVICE(0x5528, SWITCHTEC_GEN5), /* PAXA 28XG5 */
+ SWITCHTEC_PCI_DEVICE(0x6048, SWITCHTEC_GEN6), /* PFXs 48XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6064, SWITCHTEC_GEN6), /* PFXs 64XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6044, SWITCHTEC_GEN6), /* PFXs 144XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6060, SWITCHTEC_GEN6), /* PFXs 160XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6148, SWITCHTEC_GEN6), /* PSXs 48XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6164, SWITCHTEC_GEN6), /* PSXs 64XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6144, SWITCHTEC_GEN6), /* PSXs 144XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6160, SWITCHTEC_GEN6), /* PSXs 160XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6248, SWITCHTEC_GEN6), /* PFX 48XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6264, SWITCHTEC_GEN6), /* PFX 64XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6244, SWITCHTEC_GEN6), /* PFX 144XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6260, SWITCHTEC_GEN6), /* PFX 160XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6348, SWITCHTEC_GEN6), /* PSX 48XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6364, SWITCHTEC_GEN6), /* PSX 64XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6344, SWITCHTEC_GEN6), /* PSX 144XG6 */
+ SWITCHTEC_PCI_DEVICE(0x6360, SWITCHTEC_GEN6), /* PSX 160XG6 */
SWITCHTEC_PCI100X_DEVICE(0x1001, SWITCHTEC_GEN4), /* PCI1001 16XG4 */
SWITCHTEC_PCI100X_DEVICE(0x1002, SWITCHTEC_GEN4), /* PCI1002 12XG4 */
SWITCHTEC_PCI100X_DEVICE(0x1003, SWITCHTEC_GEN4), /* PCI1003 16XG4 */
diff --git a/include/linux/switchtec.h b/include/linux/switchtec.h
index 8d8fac1626bd9..32980f2f76e09 100644
--- a/include/linux/switchtec.h
+++ b/include/linux/switchtec.h
@@ -42,6 +42,7 @@ enum switchtec_gen {
SWITCHTEC_GEN3,
SWITCHTEC_GEN4,
SWITCHTEC_GEN5,
+ SWITCHTEC_GEN6,
};
struct mrpc_regs {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 026/982] net: dsa: mv88e6xxx: define .pot_clear() for 6321
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 025/982] PCI: switchtec: Add Gen6 Device IDs Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 027/982] net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family Greg Kroah-Hartman
` (962 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Behún, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marek Behún <kabel@kernel.org>
[ Upstream commit 17826d9708a57d27011d0a6efdebb628d6f8299a ]
Commit 9e907d739cc3 ("net: dsa: mv88e6xxx: add POT operation") did not
add the .pot_clear() method to the 6321 switch operations structure.
Add them now.
Signed-off-by: Marek Behún <kabel@kernel.org>
Link: https://patch.msgid.link/20260504153227.1390546-4-kabel@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mv88e6xxx/chip.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 783d7035f065e..ac325b3abcae9 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -5245,6 +5245,7 @@ static const struct mv88e6xxx_ops mv88e6321_ops = {
.set_egress_port = mv88e6095_g1_set_egress_port,
.watchdog_ops = &mv88e6390_watchdog_ops,
.mgmt_rsvd2cpu = mv88e6352_g2_mgmt_rsvd2cpu,
+ .pot_clear = mv88e6xxx_g2_pot_clear,
.hardware_reset_pre = mv88e6xxx_g2_eeprom_wait,
.hardware_reset_post = mv88e6xxx_g2_eeprom_wait,
.reset = mv88e6352_g1_reset,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 027/982] net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 026/982] net: dsa: mv88e6xxx: define .pot_clear() for 6321 Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 028/982] media: em28xx-video: fix missing res_free() on init_usb_xfer failure Greg Kroah-Hartman
` (961 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Behún, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marek Behún <kabel@kernel.org>
[ Upstream commit e0fdb4157a85056bd256a7aebac4a3a2f580b201 ]
Commit 9e5baf9b3636 ("net: dsa: mv88e6xxx: add RMU disable op") did not
add the .rmu_disable() method for the 6320 family. Add it now.
Signed-off-by: Marek Behún <kabel@kernel.org>
Link: https://patch.msgid.link/20260504153227.1390546-5-kabel@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mv88e6xxx/chip.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index ac325b3abcae9..17390a004c0e9 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -5198,6 +5198,7 @@ static const struct mv88e6xxx_ops mv88e6320_ops = {
.hardware_reset_pre = mv88e6xxx_g2_eeprom_wait,
.hardware_reset_post = mv88e6xxx_g2_eeprom_wait,
.reset = mv88e6352_g1_reset,
+ .rmu_disable = mv88e6352_g1_rmu_disable,
.vtu_getnext = mv88e6352_g1_vtu_getnext,
.vtu_loadpurge = mv88e6352_g1_vtu_loadpurge,
.stu_getnext = mv88e6352_g1_stu_getnext,
@@ -5249,6 +5250,7 @@ static const struct mv88e6xxx_ops mv88e6321_ops = {
.hardware_reset_pre = mv88e6xxx_g2_eeprom_wait,
.hardware_reset_post = mv88e6xxx_g2_eeprom_wait,
.reset = mv88e6352_g1_reset,
+ .rmu_disable = mv88e6352_g1_rmu_disable,
.vtu_getnext = mv88e6352_g1_vtu_getnext,
.vtu_loadpurge = mv88e6352_g1_vtu_loadpurge,
.stu_getnext = mv88e6352_g1_stu_getnext,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 028/982] media: em28xx-video: fix missing res_free() on init_usb_xfer failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 027/982] net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 029/982] crypto: ixp4xx - fix buffer chain unwind on allocation failure Greg Kroah-Hartman
` (960 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Hans Verkuil,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haoxiang Li <lihaoxiang@isrc.iscas.ac.cn>
[ Upstream commit cc20e81da6d99926f94fad7af21f75c07e865769 ]
res_get() is called before em28xx_init_usb_xfer(), but the error
path of em28xx_init_usb_xfer() does not release the resource,
leading to a persistent busy state.
Signed-off-by: Haoxiang Li <lihaoxiang@isrc.iscas.ac.cn>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/usb/em28xx/em28xx-video.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/media/usb/em28xx/em28xx-video.c b/drivers/media/usb/em28xx/em28xx-video.c
index 81fff2fe8c19b..a520bec031248 100644
--- a/drivers/media/usb/em28xx/em28xx-video.c
+++ b/drivers/media/usb/em28xx/em28xx-video.c
@@ -1105,8 +1105,10 @@ int em28xx_start_analog_streaming(struct vb2_queue *vq, unsigned int count)
dev->max_pkt_size,
dev->packet_multiplier,
em28xx_urb_data_copy);
- if (rc < 0)
+ if (rc < 0) {
+ res_free(dev, vq->type);
return rc;
+ }
/*
* djh: it's not clear whether this code is still needed. I'm
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 029/982] crypto: ixp4xx - fix buffer chain unwind on allocation failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 028/982] media: em28xx-video: fix missing res_free() on init_usb_xfer failure Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 030/982] clk: renesas: cpg-mssr: Add number of clock cells check Greg Kroah-Hartman
` (959 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Linus Walleij,
Herbert Xu, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 25056329384010a8672552b134f609601dc4f80e ]
chainup_buffers() builds a linked list of buffer descriptors for a
scatterlist. If dma_pool_alloc() fails while constructing the list, the
current code sets buf to NULL and later dereferences it unconditionally
at the end of the function:
buf->next = NULL;
buf->phys_next = 0;
This can lead to a null-pointer dereference on allocation failure.
If the failure happens after part of the descriptor chain has already
been allocated and DMA-mapped, the partially constructed chain also
needs to be released.
Fix this by terminating the partially constructed chain on allocation
failure and letting the callers unwind it via their existing cleanup
paths. Also fix ablk_perform() to preserve the hook pointers before
checking for failure, so partially built chains can be freed correctly.
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Acked-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/ixp4xx_crypto.c | 25 ++++++++++++++-----------
1 file changed, 14 insertions(+), 11 deletions(-)
diff --git a/drivers/crypto/ixp4xx_crypto.c b/drivers/crypto/ixp4xx_crypto.c
index cfb149302e0a9..c3e2a816476dc 100644
--- a/drivers/crypto/ixp4xx_crypto.c
+++ b/drivers/crypto/ixp4xx_crypto.c
@@ -882,8 +882,9 @@ static struct buffer_desc *chainup_buffers(struct device *dev,
ptr = sg_virt(sg);
next_buf = dma_pool_alloc(buffer_pool, flags, &next_buf_phys);
if (!next_buf) {
- buf = NULL;
- break;
+ buf->next = NULL;
+ buf->phys_next = 0;
+ return NULL;
}
sg_dma_address(sg) = dma_map_single(dev, ptr, len, dir);
buf->next = next_buf;
@@ -981,7 +982,7 @@ static int ablk_perform(struct skcipher_request *req, int encrypt)
unsigned int nbytes = req->cryptlen;
enum dma_data_direction src_direction = DMA_BIDIRECTIONAL;
struct ablk_ctx *req_ctx = skcipher_request_ctx(req);
- struct buffer_desc src_hook;
+ struct buffer_desc *buf, src_hook;
struct device *dev = &pdev->dev;
unsigned int offset;
gfp_t flags = req->base.flags & CRYPTO_TFM_REQ_MAY_SLEEP ?
@@ -1023,22 +1024,24 @@ static int ablk_perform(struct skcipher_request *req, int encrypt)
/* This was never tested by Intel
* for more than one dst buffer, I think. */
req_ctx->dst = NULL;
- if (!chainup_buffers(dev, req->dst, nbytes, &dst_hook,
- flags, DMA_FROM_DEVICE))
- goto free_buf_dest;
- src_direction = DMA_TO_DEVICE;
+ buf = chainup_buffers(dev, req->dst, nbytes, &dst_hook,
+ flags, DMA_FROM_DEVICE);
req_ctx->dst = dst_hook.next;
crypt->dst_buf = dst_hook.phys_next;
+ if (!buf)
+ goto free_buf_dest;
+ src_direction = DMA_TO_DEVICE;
} else {
req_ctx->dst = NULL;
}
req_ctx->src = NULL;
- if (!chainup_buffers(dev, req->src, nbytes, &src_hook, flags,
- src_direction))
- goto free_buf_src;
-
+ buf = chainup_buffers(dev, req->src, nbytes, &src_hook, flags,
+ src_direction);
req_ctx->src = src_hook.next;
crypt->src_buf = src_hook.phys_next;
+ if (!buf)
+ goto free_buf_src;
+
crypt->ctl_flags |= CTL_FLAG_PERFORM_ABLK;
qmgr_put_entry(send_qid, crypt_virt2phys(crypt));
BUG_ON(qmgr_stat_overflow(send_qid));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 030/982] clk: renesas: cpg-mssr: Add number of clock cells check
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 029/982] crypto: ixp4xx - fix buffer chain unwind on allocation failure Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 031/982] drm/bridge: tc358768: Set pre_enable_prev_first for reverse order Greg Kroah-Hartman
` (958 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geert Uytterhoeven, Biju Das,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geert Uytterhoeven <geert+renesas@glider.be>
[ Upstream commit 7f0c422c7fbfd9294ff9321ada0c63561e5c6ea0 ]
The number of clock cells is not validated in the clock provider's
clk_src_get() callback. Add the missing check.
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/46e010659ffdffd5e3541369f3b65d43ebe236ec.1777562043.git.geert+renesas@glider.be
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/renesas/renesas-cpg-mssr.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/clk/renesas/renesas-cpg-mssr.c b/drivers/clk/renesas/renesas-cpg-mssr.c
index d6137379510c1..77365962a15a9 100644
--- a/drivers/clk/renesas/renesas-cpg-mssr.c
+++ b/drivers/clk/renesas/renesas-cpg-mssr.c
@@ -285,6 +285,9 @@ struct clk *cpg_mssr_clk_src_twocell_get(struct of_phandle_args *clkspec,
struct clk *clk;
int range_check;
+ if (clkspec->args_count != 2)
+ return ERR_PTR(-EINVAL);
+
switch (clkspec->args[0]) {
case CPG_CORE:
type = "core";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 031/982] drm/bridge: tc358768: Set pre_enable_prev_first for reverse order
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 030/982] clk: renesas: cpg-mssr: Add number of clock cells check Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 032/982] ASoC: ti: omap3pandora: update board check to use DT compatible Greg Kroah-Hartman
` (957 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Parth Pancholi, Francesco Dolcini,
Tomi Valkeinen, Sasha Levin, João Paulo Gonçalves
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Parth Pancholi <parth.pancholi@toradex.com>
[ Upstream commit 6b2bb5438bcfd7bad868665cd2aed1caf9ba3f2b ]
Enable the pre_enable_prev_first flag on the tc358768 bridge to reverse
the pre-enable order, calling bridge pre_enable before panel prepare.
This ensures the bridge is ready before sending panel init commands in
the case of panels sending init commands in panel prepare function.
Signed-off-by: Parth Pancholi <parth.pancholi@toradex.com>
Tested-by: João Paulo Gonçalves <joao.goncalves@toradex.com> # Toradex Verdin AM62
Reviewed-by: Francesco Dolcini <francesco.dolcini@toradex.com>
Link: https://patch.msgid.link/20260311-tc358768-v2-2-e75a99131bd5@ideasonboard.com
Signed-off-by: Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/tc358768.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/bridge/tc358768.c b/drivers/gpu/drm/bridge/tc358768.c
index ed8094b2a7ff4..acbbf1e79fb78 100644
--- a/drivers/gpu/drm/bridge/tc358768.c
+++ b/drivers/gpu/drm/bridge/tc358768.c
@@ -449,6 +449,8 @@ static int tc358768_dsi_host_attach(struct mipi_dsi_host *host,
DRM_MODE_CONNECTOR_DSI);
if (IS_ERR(bridge))
return PTR_ERR(bridge);
+
+ bridge->pre_enable_prev_first = true;
}
priv->output.dev = dev;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 032/982] ASoC: ti: omap3pandora: update board check to use DT compatible
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 031/982] drm/bridge: tc358768: Set pre_enable_prev_first for reverse order Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 033/982] mmc: core: Add validation for host-provided max_segs Greg Kroah-Hartman
` (956 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ethan Nelson-Moore, Jarkko Nikula,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ethan Nelson-Moore <enelsonmoore@gmail.com>
[ Upstream commit 45efb8fbdae303539e7fb5562e147583d4ed63ad ]
The omap3pandora driver contains a check for the ARM machine ID via the
machine_is_omap3_pandora() macro. The board concerned now supports
only FDT booting, which does not use machine IDs, and therefore the
code should be updated to check the DT compatible property instead. The
legacy board file for this machine was removed in commit 7fcf7e061edd
("ARM: OMAP2+: Remove legacy booting support for Pandora").
The presence of this machine ID check prevents the removal of machine
IDs no longer used by the kernel from arch/arm/tools/mach-types,
because the machine_is_*() macros are generated from mach-types. To
resolve this issue, use of_machine_is_compatible() instead.
Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Acked-by: Jarkko Nikula <jarkko.nikula@bitmer.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ti/omap3pandora.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/sound/soc/ti/omap3pandora.c b/sound/soc/ti/omap3pandora.c
index a287e9747c2a1..3cec2eaafe62f 100644
--- a/sound/soc/ti/omap3pandora.c
+++ b/sound/soc/ti/omap3pandora.c
@@ -11,12 +11,12 @@
#include <linux/delay.h>
#include <linux/regulator/consumer.h>
#include <linux/module.h>
+#include <linux/of.h>
#include <sound/core.h>
#include <sound/pcm.h>
#include <sound/soc.h>
-#include <asm/mach-types.h>
#include <linux/platform_data/asoc-ti-mcbsp.h>
#include "omap-mcbsp.h"
@@ -224,7 +224,8 @@ static int __init omap3pandora_soc_init(void)
{
int ret;
- if (!machine_is_omap3_pandora())
+ if (!of_machine_is_compatible("openpandora,omap3-pandora-600mhz") &&
+ !of_machine_is_compatible("openpandora,omap3-pandora-1ghz"))
return -ENODEV;
pr_info("OMAP3 Pandora SoC init\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 033/982] mmc: core: Add validation for host-provided max_segs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 032/982] ASoC: ti: omap3pandora: update board check to use DT compatible Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 034/982] mmc: davinci: avoid NULL deref of host->data in IRQ handler Greg Kroah-Hartman
` (955 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shawn Lin, Ulf Hansson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shawn Lin <shawn.lin@rock-chips.com>
[ Upstream commit 3e0483e93a8be320f70a1ff68d835f7f015af311 ]
The max_segs field is of type unsigned short, and if a host driver
sets an excessively large value, it may be truncated to zero. This
can cause mmc_alloc_sg() to call kmalloc_objs() with a zero size
allocation request, which leads to undefined behavior.
Under the SLUB allocator, kmalloc(0) returns a special pointer
(ZERO_SIZE_PTR). The subsequent 'if (sg)' check will evaluate to
true, and sg_init_table() will then attempt to access invalid memory,
resulting in a crash:
dwmmc_rockchip 2a310000.mmc: Successfully tuned phase to 133
mmc1: new UHS-I speed SDR104 SDHC card at address aaaa
Unable to handle kernel paging request at virtual address 0000001ffffffff0
Mem abort info:
ESR = 0x0000000096000004
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x04: level 0 translation fault
Data abort info:
ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
CM = 0, WnR = 0, TnD = 0, TagAccess = 0
GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
user pgtable: 4k pages, 48-bit VAs, pgdp=0000000102c88000
[0000001ffffffff0] pgd=0000000000000000, p4d=0000000000000000
Internal error: Oops: 0000000096000004 [#1] SMP
Modules linked in:
CPU: 2 UID: 0 PID: 102 Comm: kworker/2:1 Not tainted 7.0.0-rc6-next-20260331-00013-g4d93c25963c5-dirty #80 PREEMPT
Hardware name: Rockchip RK3576 EVB V10 Board (DT)
Workqueue: events_freezable mmc_rescan
pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : sg_init_table+0x2c/0x50
lr : sg_init_table+0x24/0x50
sp : ffff8000837db710
x29: ffff8000837db710 x28: 000000000000c000 x27: 0000000000000300
x26: 0000000000000000 x25: 0000000000000040 x24: ffff0000c46a0000
x23: 0000000000000000 x22: ffff0000c0c73c00 x21: 0000000000000010
x20: 0000000000000010 x19: 0000000000000000 x18: 000000000000002c
x17: 0000000000000000 x16: 0000000000000001 x15: 0000000000000000
x14: 0000000000000400 x13: ffff8000837dc000 x12: 0000000000000000
x11: ffff0000c0c73ca0 x10: 0000000000000040 x9 : 459ec1f0abbdbb00
x8 : 0000001fffffffe0 x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000035579 x4 : 0000000000000901 x3 : 0000000000000000
x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000010
Call trace:
sg_init_table+0x2c/0x50 (P)
mmc_mq_init_request+0x64/0x90
blk_mq_alloc_map_and_rqs+0x3ac/0x480
blk_mq_alloc_set_map_and_rqs+0x98/0x1e0
blk_mq_alloc_tag_set+0x1c0/0x290
mmc_init_queue+0x120/0x370
mmc_blk_alloc_req+0x150/0x420
To prevent this, add a validation check in mmc_mq_init_request() to
detect when sg_len (derived from max_segs) is zero. If sg_len is zero,
we return an error and print an error message, allowing host driver
developers to identify and fix incorrect max_segs configuration.
This is a defensive measure that ensures the MMC core fails gracefully
when host drivers provide invalid max_segs values, rather than crashing
with a page fault.
Signed-off-by: Shawn Lin <shawn.lin@rock-chips.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mmc/core/queue.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/mmc/core/queue.c b/drivers/mmc/core/queue.c
index b396e39007177..5f05d997a6af9 100644
--- a/drivers/mmc/core/queue.c
+++ b/drivers/mmc/core/queue.c
@@ -207,8 +207,14 @@ static int mmc_mq_init_request(struct blk_mq_tag_set *set, struct request *req,
struct mmc_queue *mq = set->driver_data;
struct mmc_card *card = mq->card;
struct mmc_host *host = card->host;
+ u16 sg_len = mmc_get_max_segments(host);
- mq_rq->sg = mmc_alloc_sg(mmc_get_max_segments(host), GFP_KERNEL);
+ if (!sg_len) {
+ dev_err(mmc_dev(host), "Wrong max_segs assigned\n");
+ return -EINVAL;
+ }
+
+ mq_rq->sg = mmc_alloc_sg(sg_len, GFP_KERNEL);
if (!mq_rq->sg)
return -ENOMEM;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 034/982] mmc: davinci: avoid NULL deref of host->data in IRQ handler
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 033/982] mmc: core: Add validation for host-provided max_segs Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 035/982] drm/amd/display: Fix CRC open failure during active rendering Greg Kroah-Hartman
` (954 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stepan Ionichev, Bartosz Golaszewski,
Ulf Hansson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stepan Ionichev <sozdayvek@gmail.com>
[ Upstream commit 4f28846aaf8db9668e338b8987973f8935edff34 ]
mmc_davinci_irq() returns early only when both host->cmd and
host->data are NULL:
if (host->cmd == NULL && host->data == NULL) {
...
return IRQ_NONE;
}
So we may legitimately reach the rest of the handler with
host->data == NULL (and therefore data == NULL). The DATDNE branch
already guards against this with an explicit "if (data != NULL)"
check, but the subsequent TOUTRD ("read data timeout") and
CRCWR/CRCRD ("data CRC error") branches dereference data
unconditionally:
if (qstatus & MMCST0_TOUTRD) {
data->error = -ETIMEDOUT; <-- NULL deref
...
davinci_abort_data(host, data);
}
if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) {
data->error = -EILSEQ; <-- NULL deref
...
}
If either bit is set in qstatus while host->data is NULL, the kernel
will crash inside the IRQ handler. smatch flags this:
drivers/mmc/host/davinci_mmc.c:933 mmc_davinci_irq() error: we
previously assumed 'data' could be null (see line 914)
Gate both branches on a non-NULL data, matching the existing pattern
used by the DATDNE branch.
No functional change for callers where data is non-NULL, which is
the only case in which these branches did meaningful work before
this change.
Signed-off-by: Stepan Ionichev <sozdayvek@gmail.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mmc/host/davinci_mmc.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/mmc/host/davinci_mmc.c b/drivers/mmc/host/davinci_mmc.c
index e89a97b415154..b744651f3b625 100644
--- a/drivers/mmc/host/davinci_mmc.c
+++ b/drivers/mmc/host/davinci_mmc.c
@@ -934,7 +934,7 @@ static irqreturn_t mmc_davinci_irq(int irq, void *dev_id)
}
}
- if (qstatus & MMCST0_TOUTRD) {
+ if (data && (qstatus & MMCST0_TOUTRD)) {
/* Read data timeout */
data->error = -ETIMEDOUT;
end_transfer = 1;
@@ -946,7 +946,7 @@ static irqreturn_t mmc_davinci_irq(int irq, void *dev_id)
davinci_abort_data(host, data);
}
- if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) {
+ if (data && (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD))) {
/* Data CRC error */
data->error = -EILSEQ;
end_transfer = 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 035/982] drm/amd/display: Fix CRC open failure during active rendering
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 034/982] mmc: davinci: avoid NULL deref of host->data in IRQ handler Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 036/982] PCI: intel-gw: Enable clock before PHY init Greg Kroah-Hartman
` (953 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ray Wu, Tom Chung, James Lin,
Daniel Wheeler, Alex Deucher, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tom Chung <chiahsuan.chung@amd.com>
[ Upstream commit 5eb2fdafeb6f4a442643b77a21a4c9e70586a146 ]
[Why]
Opening the CRC data file during active rendering can fail with -EINVAL.
The wait for commit->hw_done returns remaining jiffies on success, but
the CRC path was treating that as an error.
[How]
Handle wait_for_completion_interruptible_timeout() correctly:
positive return as success, 0 as timeout, and negative as error.
Reviewed-by: Ray Wu <ray.wu@amd.com>
Signed-off-by: Tom Chung <chiahsuan.chung@amd.com>
Signed-off-by: James Lin <pinglei.lin@amd.com>
Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c
index 8a441a22c46ec..0c17877a6c5c8 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c
@@ -261,8 +261,13 @@ int amdgpu_dm_crtc_set_crc_source(struct drm_crtc *crtc, const char *src_name)
*/
ret = wait_for_completion_interruptible_timeout(
&commit->hw_done, 10 * HZ);
- if (ret)
+ if (ret < 0)
+ goto cleanup;
+
+ if (ret == 0) {
+ ret = -ETIMEDOUT;
goto cleanup;
+ }
}
enable = amdgpu_dm_is_valid_crc_source(source);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 036/982] PCI: intel-gw: Enable clock before PHY init
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 035/982] drm/amd/display: Fix CRC open failure during active rendering Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 037/982] hfsplus: rework hfsplus_readdir() logic Greg Kroah-Hartman
` (952 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Eckert,
Manivannan Sadhasivam, Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Eckert <fe@dev.tdt.de>
[ Upstream commit febf9ed3c35e5eec7ea384ebbd55a5296e3ca5e9 ]
To ensure that the boot sequence is correct, the DWC PCIe core clock must
be switched on before PHY init call [1]. This changes are based on patched
kernel sources of the MaxLinear SDK.
The reason why the MaxLinear SDK is used as a reference here is, that this
PCIe DWC IP is used in the URX851 and URX850 SoC. This SoC was originally
developed by Intel when they acquired Lantiq’s home networking division in
2015 [2]. In 2020 the home network division was sold to MaxLinear [3].
Since then, this SoC belongs to MaxLinear. They use their own SDK, which
runs on kernel version '5.15.x'.
[1] https://github.com/maxlinear/linux/blob/updk_9.1.90/drivers/pci/controller/dwc/pcie-intel-gw.c#L544
[2] https://www.intc.com/news-events/press-releases/detail/364/intel-to-acquire-lantiq-advancing-the-connected-home
[3] https://investors.maxlinear.com/press-releases/detail/395/maxlinear-to-acquire-intels-home-gateway-platform
Signed-off-by: Florian Eckert <fe@dev.tdt.de>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260417-pcie-intel-gw-v5-4-0a2b933fe04f@dev.tdt.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/dwc/pcie-intel-gw.c | 19 ++++++++++---------
1 file changed, 10 insertions(+), 9 deletions(-)
diff --git a/drivers/pci/controller/dwc/pcie-intel-gw.c b/drivers/pci/controller/dwc/pcie-intel-gw.c
index 333c33d98a701..7b21628a6a63e 100644
--- a/drivers/pci/controller/dwc/pcie-intel-gw.c
+++ b/drivers/pci/controller/dwc/pcie-intel-gw.c
@@ -284,13 +284,9 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
intel_pcie_core_rst_assert(pcie);
intel_pcie_device_rst_assert(pcie);
-
- ret = phy_init(pcie->phy);
- if (ret)
- return ret;
-
intel_pcie_core_rst_deassert(pcie);
+ /* Controller clock must be provided earlier than PHY */
ret = clk_prepare_enable(pcie->core_clk);
if (ret) {
dev_err(pcie->pci.dev, "Core clock enable failed: %d\n", ret);
@@ -299,13 +295,17 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
pci->atu_base = pci->dbi_base + 0xC0000;
+ ret = phy_init(pcie->phy);
+ if (ret)
+ goto phy_err;
+
intel_pcie_ltssm_disable(pcie);
intel_pcie_link_setup(pcie);
intel_pcie_init_n_fts(pci);
ret = dw_pcie_setup_rc(&pci->pp);
if (ret)
- goto app_init_err;
+ goto err;
dw_pcie_upconfig_setup(pci);
@@ -314,7 +314,7 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
ret = dw_pcie_wait_for_link(pci);
if (ret)
- goto app_init_err;
+ goto err;
/* Enable integrated interrupts */
pcie_app_wr_mask(pcie, PCIE_APP_IRNEN, PCIE_APP_IRN_INT,
@@ -322,11 +322,12 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
return 0;
-app_init_err:
+err:
+ phy_exit(pcie->phy);
+phy_err:
clk_disable_unprepare(pcie->core_clk);
clk_err:
intel_pcie_core_rst_assert(pcie);
- phy_exit(pcie->phy);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 037/982] hfsplus: rework hfsplus_readdir() logic
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 036/982] PCI: intel-gw: Enable clock before PHY init Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 038/982] drm/gud: Add RCade Display Adapter VID/PID pair Greg Kroah-Hartman
` (951 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Yangtao Li, linux-fsdevel, Viacheslav Dubeyko, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viacheslav Dubeyko <slava@dubeyko.com>
[ Upstream commit 4b0496432844628ad05a5b1efce329a3340174d2 ]
The xfstests' test-case generic/637 fails with error:
FSTYP -- hfsplus
PLATFORM -- Linux/x86_64 hfsplus-testing-0001 6.15.0-rc4+ #8 SMP PREEMPT_DYNAMIC Thu May 1 16:43:22 PDT 2025
MKFS_OPTIONS -- /dev/loop51
MOUNT_OPTIONS -- /dev/loop51 /mnt/scratch
QA output created by 637
entries 7 and 8 have duplicate d_off 8
Found unlinked files in open dir (see xfstests-dev/results//generic/637.full for details)
Debugging of the hfsplus_readdir() logic showed this:
hfsplus: hfsplus_readdir(): 163 ctx->pos 0
hfsplus: hfsplus_readdir(): 189 ctx->pos 1
hfsplus: hfsplus_readdir(): 264 ctx->pos 2, ino 18
hfsplus: hfsplus_readdir(): 264 ctx->pos 3, ino 19
hfsplus: hfsplus_readdir(): 264 ctx->pos 4, ino 28
hfsplus: hfsplus_readdir(): 264 ctx->pos 5, ino 118
hfsplus: hfsplus_readdir(): 264 ctx->pos 6, ino 29
hfsplus: hfsplus_readdir(): 264 ctx->pos 7, ino 30
hfsplus: hfsplus_readdir(): 264 ctx->pos 8, ino 31
hfsplus: hfsplus_readdir(): 304 ctx->pos 8
hfsplus: hfsplus_unlink():420 dir->i_ino 17, inode->i_ino 28
hfsplus: hfsplus_readdir(): 141 ctx->pos 7
hfsplus: hfsplus_readdir(): 264 ctx->pos 7, ino 31
hfsplus: hfsplus_readdir(): 264 ctx->pos 8, ino 32
hfsplus: hfsplus_readdir(): 264 ctx->pos 9, ino 33
It means that hfsplus_readdir() stopped the processing of
folder's items on ctx->pos 8, then, item with ino 28 has
been deleted and hfsplus_readdir() re-started the logic
from ctx->pos 7. As a result, previous and new sets of
folder's items have overlapping values for the case of
d_off 8.
Currently, HFS+ has very complicated and fragile logic
of rd->file->f_pos correction in hfsplus_delete_cat().
This patch removes this logic and it stores the current
pos into hfsplus_readdir_data. Finally, if rd->pos == ctx->pos
then hfsplus_readdir() tries to find the position in
b-tree's node by means of hfsplus_cat_key. This position is
used to re-start the folder's content traversal.
sudo ./check generic/637
FSTYP -- hfsplus
PLATFORM -- Linux/x86_64 hfsplus-testing-0001 7.1.0-rc1+ #44 SMP PREEMPT_DYNAMIC Mon May 4 15:58:45 PDT 2026
MKFS_OPTIONS -- /dev/loop51
MOUNT_OPTIONS -- /dev/loop51 /mnt/scratch
generic/637 22s ... 22s
Ran: generic/637
Passed all 1 tests
Closes: https://github.com/hfs-linux-kernel/hfs-linux-kernel/issues/198
cc: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
cc: Yangtao Li <frank.li@vivo.com>
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/20260505220051.2854696-2-slava@dubeyko.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/hfsplus/catalog.c | 11 -----------
fs/hfsplus/dir.c | 28 +++++++++++-----------------
fs/hfsplus/hfsplus_fs.h | 5 +----
fs/hfsplus/inode.c | 2 --
fs/hfsplus/super.c | 2 --
5 files changed, 12 insertions(+), 36 deletions(-)
diff --git a/fs/hfsplus/catalog.c b/fs/hfsplus/catalog.c
index 9a82bdf4caf24..2db185c67b2c3 100644
--- a/fs/hfsplus/catalog.c
+++ b/fs/hfsplus/catalog.c
@@ -332,7 +332,6 @@ int hfsplus_delete_cat(u32 cnid, struct inode *dir, const struct qstr *str)
struct super_block *sb = dir->i_sb;
struct hfs_find_data fd;
struct hfsplus_fork_raw fork;
- struct list_head *pos;
int err, off;
u16 type;
@@ -390,16 +389,6 @@ int hfsplus_delete_cat(u32 cnid, struct inode *dir, const struct qstr *str)
hfsplus_free_fork(sb, cnid, &fork, HFSPLUS_TYPE_RSRC);
}
- /* we only need to take spinlock for exclusion with ->release() */
- spin_lock(&HFSPLUS_I(dir)->open_dir_lock);
- list_for_each(pos, &HFSPLUS_I(dir)->open_dir_list) {
- struct hfsplus_readdir_data *rd =
- list_entry(pos, struct hfsplus_readdir_data, list);
- if (fd.tree->keycmp(fd.search_key, (void *)&rd->key) < 0)
- rd->file->f_pos--;
- }
- spin_unlock(&HFSPLUS_I(dir)->open_dir_lock);
-
err = hfs_brec_remove(&fd);
if (err)
goto out;
diff --git a/fs/hfsplus/dir.c b/fs/hfsplus/dir.c
index 578da2528bee8..0d6f42d91e55e 100644
--- a/fs/hfsplus/dir.c
+++ b/fs/hfsplus/dir.c
@@ -185,7 +185,15 @@ static int hfsplus_readdir(struct file *file, struct dir_context *ctx)
}
if (ctx->pos >= inode->i_size)
goto out;
- err = hfs_brec_goto(&fd, ctx->pos - 1);
+ rd = file->private_data;
+ if (rd && rd->pos == ctx->pos) {
+ memcpy(fd.search_key, &rd->key, sizeof(struct hfsplus_cat_key));
+ err = hfs_brec_find(&fd, hfs_find_rec_by_key);
+ if (err == -ENOENT)
+ err = hfs_brec_goto(&fd, 1);
+ } else {
+ err = hfs_brec_goto(&fd, ctx->pos - 1);
+ }
if (err)
goto out;
for (;;) {
@@ -261,7 +269,6 @@ static int hfsplus_readdir(struct file *file, struct dir_context *ctx)
if (err)
goto out;
}
- rd = file->private_data;
if (!rd) {
rd = kmalloc(sizeof(struct hfsplus_readdir_data), GFP_KERNEL);
if (!rd) {
@@ -269,15 +276,8 @@ static int hfsplus_readdir(struct file *file, struct dir_context *ctx)
goto out;
}
file->private_data = rd;
- rd->file = file;
- spin_lock(&HFSPLUS_I(inode)->open_dir_lock);
- list_add(&rd->list, &HFSPLUS_I(inode)->open_dir_list);
- spin_unlock(&HFSPLUS_I(inode)->open_dir_lock);
}
- /*
- * Can be done after the list insertion; exclusion with
- * hfsplus_delete_cat() is provided by directory lock.
- */
+ rd->pos = ctx->pos;
memcpy(&rd->key, fd.key, sizeof(struct hfsplus_cat_key));
out:
kfree(strbuf);
@@ -287,13 +287,7 @@ static int hfsplus_readdir(struct file *file, struct dir_context *ctx)
static int hfsplus_dir_release(struct inode *inode, struct file *file)
{
- struct hfsplus_readdir_data *rd = file->private_data;
- if (rd) {
- spin_lock(&HFSPLUS_I(inode)->open_dir_lock);
- list_del(&rd->list);
- spin_unlock(&HFSPLUS_I(inode)->open_dir_lock);
- kfree(rd);
- }
+ kfree(file->private_data);
return 0;
}
diff --git a/fs/hfsplus/hfsplus_fs.h b/fs/hfsplus/hfsplus_fs.h
index 9192637ed739e..8c18b79c0056e 100644
--- a/fs/hfsplus/hfsplus_fs.h
+++ b/fs/hfsplus/hfsplus_fs.h
@@ -246,8 +246,6 @@ struct hfsplus_inode_info {
sector_t fs_blocks;
u8 userflags; /* BSD user file flags */
u32 subfolders; /* Subfolder count (HFSX only) */
- struct list_head open_dir_list;
- spinlock_t open_dir_lock;
loff_t phys_size;
struct inode vfs_inode;
@@ -297,8 +295,7 @@ struct hfs_find_data {
};
struct hfsplus_readdir_data {
- struct list_head list;
- struct file *file;
+ loff_t pos;
struct hfsplus_cat_key key;
};
diff --git a/fs/hfsplus/inode.c b/fs/hfsplus/inode.c
index caf36ed7f590a..a006db2699c4f 100644
--- a/fs/hfsplus/inode.c
+++ b/fs/hfsplus/inode.c
@@ -449,8 +449,6 @@ struct inode *hfsplus_new_inode(struct super_block *sb, struct inode *dir,
inode->i_mtime = inode->i_atime = inode->i_ctime = current_time(inode);
hip = HFSPLUS_I(inode);
- INIT_LIST_HEAD(&hip->open_dir_list);
- spin_lock_init(&hip->open_dir_lock);
mutex_init(&hip->extents_lock);
atomic_set(&hip->opencnt, 0);
hip->extent_state = 0;
diff --git a/fs/hfsplus/super.c b/fs/hfsplus/super.c
index 0d15e440d6869..1e4e5c3003de3 100644
--- a/fs/hfsplus/super.c
+++ b/fs/hfsplus/super.c
@@ -90,8 +90,6 @@ struct inode *hfsplus_iget(struct super_block *sb, unsigned long ino)
HFSPLUS_I(inode)->fs_blocks = 0;
HFSPLUS_I(inode)->userflags = 0;
HFSPLUS_I(inode)->subfolders = 0;
- INIT_LIST_HEAD(&HFSPLUS_I(inode)->open_dir_list);
- spin_lock_init(&HFSPLUS_I(inode)->open_dir_lock);
HFSPLUS_I(inode)->phys_size = 0;
if (inode->i_ino >= HFSPLUS_FIRSTUSER_CNID ||
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 038/982] drm/gud: Add RCade Display Adapter VID/PID pair
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 037/982] hfsplus: rework hfsplus_readdir() logic Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 039/982] media: video-i2c: use vb2_video_unregister_device on driver removal Greg Kroah-Hartman
` (950 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sophie D, Thomas Zimmermann,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sophie D <patches@scd31.com>
[ Upstream commit ac5ac0acf11df04295eb1811066097b7022d6c7f ]
The RCade Display Adapter is a hardware device that allows driving an
Arcade CRT display via the GUD protocol. Currently it spoofs an
existing GUD VID/PID pair. However, now that it has its own pair
assigned, it makes sense to add this to the list of pairs that GUD
supports natively.
More information can be found in the project repositories:
https://gitlab.scd31.com/stephen/stm32-usb-vga-adapter-hardware
https://gitlab.scd31.com/stephen/stm32-usb-vga-rcade-adapter
Link: https://pid.codes/1209/4FB3/
Signed-off-by: Sophie D <patches@scd31.com>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260509025405.4143956-1-patches@scd31.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/gud/gud_drv.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/gud/gud_drv.c b/drivers/gpu/drm/gud/gud_drv.c
index 8d1630b8edac1..2a382be27fd4c 100644
--- a/drivers/gpu/drm/gud/gud_drv.c
+++ b/drivers/gpu/drm/gud/gud_drv.c
@@ -668,6 +668,7 @@ static int gud_resume(struct usb_interface *intf)
static const struct usb_device_id gud_id_table[] = {
{ USB_DEVICE_INTERFACE_CLASS(0x1d50, 0x614d, USB_CLASS_VENDOR_SPEC) },
{ USB_DEVICE_INTERFACE_CLASS(0x16d0, 0x10a9, USB_CLASS_VENDOR_SPEC) },
+ { USB_DEVICE_INTERFACE_CLASS(0x1209, 0x4fb3, USB_CLASS_VENDOR_SPEC) },
{ }
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 039/982] media: video-i2c: use vb2_video_unregister_device on driver removal
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 038/982] drm/gud: Add RCade Display Adapter VID/PID pair Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 040/982] net: dsa: realtek: rtl8365mb: add support for RTL8367SB Greg Kroah-Hartman
` (949 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Arash Golgol, Hans Verkuil,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arash Golgol <arash.golgol@gmail.com>
[ Upstream commit 56384b486b80ce4a2bc93689aae49995f908f90d ]
The driver uses vb2_fop_release() as its file release operation, so
vb2_video_unregister_device() should be used instead of
video_unregister_device() during driver removal.
This ensures that the vb2 queue is properly disconnected before the
video device is unregistered.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/i2c/video-i2c.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/media/i2c/video-i2c.c b/drivers/media/i2c/video-i2c.c
index 685e4d5d174f4..83a4fc95252fa 100644
--- a/drivers/media/i2c/video-i2c.c
+++ b/drivers/media/i2c/video-i2c.c
@@ -911,7 +911,7 @@ static void video_i2c_remove(struct i2c_client *client)
if (data->chip->set_power)
data->chip->set_power(data, false);
- video_unregister_device(&data->vdev);
+ vb2_video_unregister_device(&data->vdev);
}
#ifdef CONFIG_PM
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 040/982] net: dsa: realtek: rtl8365mb: add support for RTL8367SB
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 039/982] media: video-i2c: use vb2_video_unregister_device on driver removal Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 041/982] integrity: Check for NULL returned by asymmetric_key_public_key Greg Kroah-Hartman
` (948 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Angelo Daros de Luca,
Mieczyslaw Nalewaj, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mieczyslaw Nalewaj <namiltd@yahoo.com>
[ Upstream commit 28702a215c96917d85558ad6309a57ab224808c0 ]
Add chip info entry for the Realtek RTL8367SB switch. This device has
chip ID 0x6367 and version 0x0010. It exposes two external interfaces:
port 6 supports MII, TMII, RMII, RGMII, SGMII and HSGMII, while port 7
supports MII, TMII, RMII and RGMII. Use the existing 8365MB-VC jam table
for initialization.
Reviewed-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>
Signed-off-by: Mieczyslaw Nalewaj <namiltd@yahoo.com>
Link: https://patch.msgid.link/3c6d822b-0e85-4173-86ba-2badb140bbf1@yahoo.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/realtek/rtl8365mb.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/drivers/net/dsa/realtek/rtl8365mb.c b/drivers/net/dsa/realtek/rtl8365mb.c
index 97673ccb7ac79..f622e724e01f6 100644
--- a/drivers/net/dsa/realtek/rtl8365mb.c
+++ b/drivers/net/dsa/realtek/rtl8365mb.c
@@ -539,6 +539,20 @@ static const struct rtl8365mb_chip_info rtl8365mb_chip_infos[] = {
.jam_table = rtl8365mb_init_jam_8365mb_vc,
.jam_size = ARRAY_SIZE(rtl8365mb_init_jam_8365mb_vc),
},
+ {
+ .name = "RTL8367SB",
+ .chip_id = 0x6367,
+ .chip_ver = 0x0010,
+ .extints = {
+ { 6, 1, PHY_INTF(MII) | PHY_INTF(TMII) |
+ PHY_INTF(RMII) | PHY_INTF(RGMII) |
+ PHY_INTF(SGMII) | PHY_INTF(HSGMII) },
+ { 7, 2, PHY_INTF(MII) | PHY_INTF(TMII) |
+ PHY_INTF(RMII) | PHY_INTF(RGMII) },
+ },
+ .jam_table = rtl8365mb_init_jam_8365mb_vc,
+ .jam_size = ARRAY_SIZE(rtl8365mb_init_jam_8365mb_vc),
+ },
{
.name = "RTL8367RB-VB",
.chip_id = 0x6367,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 041/982] integrity: Check for NULL returned by asymmetric_key_public_key
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 040/982] net: dsa: realtek: rtl8365mb: add support for RTL8367SB Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 042/982] clk: samsung: exynos850: mark APM I3C clocks as critical Greg Kroah-Hartman
` (947 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefan Berger, Kamlesh Kumar,
Mimi Zohar, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stefan Berger <stefanb@linux.ibm.com>
[ Upstream commit c93a5f038ccc11ed8558ce642f62d5ede701a348 ]
Check for a NULL pointer returned by asymmetric_key_public_key and return
-ENOKEY in this case.
Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
Tested-by: Kamlesh Kumar <kam@juniper.net>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/integrity/digsig_asymmetric.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/security/integrity/digsig_asymmetric.c b/security/integrity/digsig_asymmetric.c
index 895f4b9ce8c6b..b6b66f34cbf93 100644
--- a/security/integrity/digsig_asymmetric.c
+++ b/security/integrity/digsig_asymmetric.c
@@ -108,6 +108,10 @@ int asymmetric_verify(struct key *keyring, const char *sig,
pks.hash_algo = hash_algo_name[hdr->hash_algo];
pk = asymmetric_key_public_key(key);
+ if (!pk) {
+ ret = -ENOKEY;
+ goto out;
+ }
pks.pkey_algo = pk->pkey_algo;
if (!strcmp(pk->pkey_algo, "rsa")) {
pks.encoding = "pkcs1";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 042/982] clk: samsung: exynos850: mark APM I3C clocks as critical
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 041/982] integrity: Check for NULL returned by asymmetric_key_public_key Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:12 ` [PATCH 6.1 043/982] scsi: pm8001: Reject firmware update in fatal error state Greg Kroah-Hartman
` (946 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sam Protsenko, Tudor Ambarus,
Alexey Klimov, Krzysztof Kozlowski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Klimov <alexey.klimov@linaro.org>
[ Upstream commit 44984aaf1aa727ff944dd4b72fcf069d08b0056d ]
The Exynos850 APM co-processor relies on the I3C bus to communicate with
the PMIC. Currently, there is no dedicated PMIC consumer driver managing
these clocks, so the clock subsystem automatically gates them during the
initialisation. Once gated, any subsequent ACPM communication with APM
results in timeouts.
As a temporary workaround (and let's hope it doesn't become permanent),
mark both `gout_i3c_pclk` and `gout_i3c_sclk` as CLK_IS_CRITICAL ones to
prevent the clock subsystem from disabling them. This makes the ACPM
communication functional. This workaround should be reverted once a
proper ACPM PMIC driver is implemented to manage these clocks.
Cc: Sam Protsenko <semen.protsenko@linaro.org>
Cc: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Alexey Klimov <alexey.klimov@linaro.org>
Reviewed-by: Sam Protsenko <semen.protsenko@linaro.org>
Reviewed-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Link: https://patch.msgid.link/20260430-exynos850-i3c-criticalclocks-v1-1-6e1fd8dfa21b@linaro.org
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/samsung/clk-exynos850.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/samsung/clk-exynos850.c b/drivers/clk/samsung/clk-exynos850.c
index 87e463ad42741..8d1205de7fd9a 100644
--- a/drivers/clk/samsung/clk-exynos850.c
+++ b/drivers/clk/samsung/clk-exynos850.c
@@ -580,10 +580,11 @@ static const struct samsung_gate_clock apm_gate_clks[] __initconst = {
CLK_CON_GAT_GOUT_APM_APBIF_RTC_PCLK, 21, 0, 0),
GATE(CLK_GOUT_TOP_RTC_PCLK, "gout_top_rtc_pclk", "dout_apm_bus",
CLK_CON_GAT_GOUT_APM_APBIF_TOP_RTC_PCLK, 21, 0, 0),
+ /* TODO: Should be dealt with or enabled in PMIC ACPM driver */
GATE(CLK_GOUT_I3C_PCLK, "gout_i3c_pclk", "dout_apm_bus",
- CLK_CON_GAT_GOUT_APM_I3C_APM_PMIC_I_PCLK, 21, 0, 0),
+ CLK_CON_GAT_GOUT_APM_I3C_APM_PMIC_I_PCLK, 21, CLK_IS_CRITICAL, 0),
GATE(CLK_GOUT_I3C_SCLK, "gout_i3c_sclk", "mout_apm_i3c",
- CLK_CON_GAT_GOUT_APM_I3C_APM_PMIC_I_SCLK, 21, 0, 0),
+ CLK_CON_GAT_GOUT_APM_I3C_APM_PMIC_I_SCLK, 21, CLK_IS_CRITICAL, 0),
GATE(CLK_GOUT_SPEEDY_PCLK, "gout_speedy_pclk", "dout_apm_bus",
CLK_CON_GAT_GOUT_APM_SPEEDY_APM_PCLK, 21, 0, 0),
/* TODO: Should be enabled in GPIO driver (or made CLK_IS_CRITICAL) */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 043/982] scsi: pm8001: Reject firmware update in fatal error state
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 042/982] clk: samsung: exynos850: mark APM I3C clocks as critical Greg Kroah-Hartman
@ 2026-09-30 15:12 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 044/982] scsi: pm8001: Reject non-fatal dump when controller is crashed Greg Kroah-Hartman
` (945 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:12 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kumar Meiyappan, Sagar Biradar,
Martin K. Petersen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Meiyappan <kumar.meiyappan@microchip.com>
[ Upstream commit 2a8fbcfb04aa9db189bfa3842d4f586aecd0e631 ]
pm8001_store_update_fw() allows a firmware update request even when the
controller has already entered a fatal error state.
Firmware update is not valid once the controller is in that state, and
attempting it can lead to a call trace. Reject the request early by
checking controller_fatal_error, set the firmware status to
FAIL_PARAMETERS, and return -EINVAL.
Signed-off-by: Kumar Meiyappan <kumar.meiyappan@microchip.com>
Signed-off-by: Sagar Biradar <sagar.biradar@microchip.com>
Link: https://patch.msgid.link/20260416153757.414896-1-sagar.biradar@microchip.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/pm8001/pm8001_ctl.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/scsi/pm8001/pm8001_ctl.c b/drivers/scsi/pm8001/pm8001_ctl.c
index 8113045f7cb93..0158e0353fe0d 100644
--- a/drivers/scsi/pm8001/pm8001_ctl.c
+++ b/drivers/scsi/pm8001/pm8001_ctl.c
@@ -827,6 +827,14 @@ static ssize_t pm8001_store_update_fw(struct device *cdev,
goto out;
}
+ if (pm8001_ha->controller_fatal_error) {
+ pm8001_dbg(pm8001_ha, FAIL,
+ "controller in fatal error state, firmware update rejected\n");
+ pm8001_ha->fw_status = FAIL_PARAMETERS;
+ ret = -EINVAL;
+ goto out;
+ }
+
for (i = 0; flash_command_table[i].code != FLASH_CMD_NONE; i++) {
if (!memcmp(flash_command_table[i].command,
cmd_ptr, strlen(cmd_ptr))) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 044/982] scsi: pm8001: Reject non-fatal dump when controller is crashed
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-09-30 15:12 ` [PATCH 6.1 043/982] scsi: pm8001: Reject firmware update in fatal error state Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 045/982] crypto: ecc - Unbreak the build on arm with CONFIG_KASAN_STACK=y Greg Kroah-Hartman
` (944 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kumar Meiyappan, Sagar Biradar,
Martin K. Petersen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Meiyappan <kumar.meiyappan@microchip.com>
[ Upstream commit aa3b8f56ef27ed72394a752820abdec4608b731c ]
pm80xx_get_non_fatal_dump() can be called even after the controller has
entered a fatal error state. In that case the forensic memory contents
are not safe to access for a non-fatal dump request, and attempting to
do so can trigger a call trace.
Check controller_fatal_error before reading the non-fatal dump buffer
and return -EINVAL when the controller is already in a crashed state.
This prevents non-fatal dump collection from running in an invalid
controller state.
Signed-off-by: Kumar Meiyappan <kumar.meiyappan@microchip.com>
Signed-off-by: Sagar Biradar <sagar.biradar@microchip.com>
Link: https://patch.msgid.link/20260416154650.415624-1-sagar.biradar@microchip.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/pm8001/pm80xx_hwi.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/scsi/pm8001/pm80xx_hwi.c b/drivers/scsi/pm8001/pm80xx_hwi.c
index 2bf293e8f7472..371a33bab4c73 100644
--- a/drivers/scsi/pm8001/pm80xx_hwi.c
+++ b/drivers/scsi/pm8001/pm80xx_hwi.c
@@ -401,6 +401,13 @@ ssize_t pm80xx_get_non_fatal_dump(struct device *cdev,
char *buf_copy = buf;
temp = (u32 *)pm8001_ha->memoryMap.region[FORENSIC_MEM].virt_ptr;
+
+ if (pm8001_ha->controller_fatal_error) {
+ pm8001_dbg(pm8001_ha, FAIL,
+ "non-fatal dump not available in fatal error state\n");
+ return -EINVAL;
+ }
+
if (++pm8001_ha->non_fatal_count == 1) {
if (pm8001_ha->chip_id == chip_8001) {
snprintf(pm8001_ha->forensic_info.data_buf.direct_data,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 045/982] crypto: ecc - Unbreak the build on arm with CONFIG_KASAN_STACK=y
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 044/982] scsi: pm8001: Reject non-fatal dump when controller is crashed Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 046/982] crypto: atmel-ecc - add support for atecc608b Greg Kroah-Hartman
` (943 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lukas Wunner, Andy Shevchenko,
Herbert Xu, Sasha Levin, Andrew Morton
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lukas Wunner <lukas@wunner.de>
[ Upstream commit c64ba13e2033c3c6dc1a097bf35f9f1fe457c3f7 ]
Andrew reports build breakage of arm allmodconfig, reproducible with gcc
14.2.0 and 15.2.0:
crypto/ecc.c: In function 'ecc_point_mult':
crypto/ecc.c:1380:1: error: the frame size of 1360 bytes is larger than 1280 bytes [-Werror=frame-larger-than=]
gcc aggressively inlines functions called by ecc_point_mult() (without
there being any explicit inline declarations), which pushes stack usage
close to the limit imposed by CONFIG_FRAME_WARN. allmodconfig implies
CONFIG_KASAN_STACK=y, which increases the stack above that limit.
In the bugzilla entry linked below, gcc maintainers explain that gcc
estimates extra stack usage caused by inlining, but ASAN instrumentation
is added in post-IPA passes and thus the inlining heuristics cannot
account for it.
It could be argued that -Werror=frame-larger-than=1280 instructs the
compiler to avoid inlining beyond that limit lest the build breaks,
which would imply gcc behaves incorrectly. But gcc maintainers reject
this notion and believe that a warning switch should never affect code
generation, even if it is promoted to an error.
One way to unbreak the build is to limit inlining via -finline-limit=100
or by explicitly declaring some functions noinline. However while it
does keep stack usage of individual functions below the limit, *total*
stack usage increases.
A longterm solution is to refactor ecc.c for reduced stack usage. It
currently performs ECC point multiplication with a Montgomery ladder
which uses co-Z (conjugate) addition to trade off memory for speed.
The algorithm is susceptible to timing attacks and needs to be replaced
with a constant time Montgomery ladder, which should consume less memory
and thus resolve the stack usage issue as a side effect.
In the interim, raise the limit for ecc.c, as is already done for
several other files in the source tree.
Constrain to gcc because clang 19.1.7 does not exhibit the issue. It
makes do with a 724 bytes stack frame even though it inlines almost the
same functions as gcc.
Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=124949
Reported-by: Andrew Morton <akpm@linux-foundation.org> # off-list
Signed-off-by: Lukas Wunner <lukas@wunner.de>
Acked-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
crypto/Makefile | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/crypto/Makefile b/crypto/Makefile
index 303b21c43df05..f92458db8fe9f 100644
--- a/crypto/Makefile
+++ b/crypto/Makefile
@@ -186,6 +186,11 @@ obj-$(CONFIG_CRYPTO_ECC) += ecc.o
obj-$(CONFIG_CRYPTO_ESSIV) += essiv.o
obj-$(CONFIG_CRYPTO_CURVE25519) += curve25519-generic.o
+# https://gcc.gnu.org/bugzilla/show_bug.cgi?id=124949
+ifeq ($(CONFIG_ARM)$(CONFIG_KASAN_STACK)$(CONFIG_CC_IS_GCC),yyy)
+CFLAGS_ecc.o += $(call cc-option,-Wframe-larger-than=1536)
+endif
+
ecdh_generic-y += ecdh.o
ecdh_generic-y += ecdh_helper.o
obj-$(CONFIG_CRYPTO_ECDH) += ecdh_generic.o
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 046/982] crypto: atmel-ecc - add support for atecc608b
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 045/982] crypto: ecc - Unbreak the build on arm with CONFIG_KASAN_STACK=y Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 047/982] media: imon: Add iMON VFD HID OEM v1.2 key mappings Greg Kroah-Hartman
` (942 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Herbert Xu,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit b668edaf8dcc8d09f6f1e71797422b44d4bd22a3 ]
Tested on hardware with an ATECC608B at 0x60. The device binds
successfully, passes the driver's sanity check, and registers the
ecdh-nist-p256 KPP algorithm.
The hardware ECDH path was also exercised using a minimal KPP test
module, covering private key generation, public key derivation, and
shared secret computation.
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/atmel-ecc.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/crypto/atmel-ecc.c b/drivers/crypto/atmel-ecc.c
index d2c830cb20eed..b9c5832cf6fcc 100644
--- a/drivers/crypto/atmel-ecc.c
+++ b/drivers/crypto/atmel-ecc.c
@@ -366,6 +366,8 @@ static void atmel_ecc_remove(struct i2c_client *client)
static const struct of_device_id atmel_ecc_dt_ids[] = {
{
.compatible = "atmel,atecc508a",
+ }, {
+ .compatible = "atmel,atecc608b",
}, {
/* sentinel */
}
@@ -375,6 +377,7 @@ MODULE_DEVICE_TABLE(of, atmel_ecc_dt_ids);
static const struct i2c_device_id atmel_ecc_id[] = {
{ "atecc508a" },
+ { "atecc608b" },
{ }
};
MODULE_DEVICE_TABLE(i2c, atmel_ecc_id);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 047/982] media: imon: Add iMON VFD HID OEM v1.2 key mappings
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 046/982] crypto: atmel-ecc - add support for atecc608b Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 048/982] RDMA/mlx5: Use QP port when decoding responder CQEs Greg Kroah-Hartman
` (941 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alessandro Baldi, Sean Young,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alessandro Baldi <baldovic@virgilio.it>
[ Upstream commit d97d13c24d7893abcfb80d38630ce74daaa1434c ]
Add Vol+/Vol-/Mute panel button mappings for iMON VFD HID OEM v1.2.
This version differs in the codes that generate the
KEY_VOLUMEUP, KEY_VOLUMEDOWN and KEY_MUTE events.
Signed-off-by: Alessandro Baldi <baldovic@virgilio.it>
Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/rc/imon.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/media/rc/imon.c b/drivers/media/rc/imon.c
index bb4aabb08c06e..c6ef6d25871ad 100644
--- a/drivers/media/rc/imon.c
+++ b/drivers/media/rc/imon.c
@@ -295,6 +295,10 @@ static const struct imon_usb_dev_descr imon_OEM_VFD = {
{ 0x000100000000ffeell, KEY_VOLUMEUP },
{ 0x010000000000ffeell, KEY_VOLUMEDOWN },
{ 0x000000000100ffeell, KEY_MUTE },
+ /* iMON VFD HID OEM v1.2 */
+ { 0x000000000a00ffeell, KEY_VOLUMEUP },
+ { 0x000000000b00ffeell, KEY_VOLUMEDOWN },
+ { 0x000000000c00ffeell, KEY_MUTE },
/* 0xffdc iMON MCE VFD */
{ 0x00010000ffffffeell, KEY_VOLUMEUP },
{ 0x01000000ffffffeell, KEY_VOLUMEDOWN },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 048/982] RDMA/mlx5: Use QP port when decoding responder CQEs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 047/982] media: imon: Add iMON VFD HID OEM v1.2 key mappings Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 049/982] mailbox: Make mbox_send_message() return error code when tx fails Greg Kroah-Hartman
` (940 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chenguang Zhao, Leon Romanovsky,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chenguang Zhao <zhaochenguang@kylinos.cn>
[ Upstream commit 194762e6e436acde0f8f6aef44200b0058c36791 ]
The responder CQE path determines the link layer via
rdma_port_get_link_layer(). Use qp->port instead of
hardcoding port 1, which can mis-decode completions on
multi-port devices.
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Link: https://patch.msgid.link/20260410074046.2044595-1-zhaochenguang@kylinos.cn
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/cq.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/mlx5/cq.c b/drivers/infiniband/hw/mlx5/cq.c
index a34bbe27bb76a..886e9560e913e 100644
--- a/drivers/infiniband/hw/mlx5/cq.c
+++ b/drivers/infiniband/hw/mlx5/cq.c
@@ -166,7 +166,8 @@ enum {
static void handle_responder(struct ib_wc *wc, struct mlx5_cqe64 *cqe,
struct mlx5_ib_qp *qp)
{
- enum rdma_link_layer ll = rdma_port_get_link_layer(qp->ibqp.device, 1);
+ enum rdma_link_layer ll =
+ rdma_port_get_link_layer(qp->ibqp.device, qp->port);
struct mlx5_ib_dev *dev = to_mdev(qp->ibqp.device);
struct mlx5_ib_srq *srq = NULL;
struct mlx5_ib_wq *wq;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 049/982] mailbox: Make mbox_send_message() return error code when tx fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 048/982] RDMA/mlx5: Use QP port when decoding responder CQEs Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 050/982] PCI: Wait for device readiness after D3hot -> D0uninitialized transition Greg Kroah-Hartman
` (939 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joonwon Kang, Sudeep Holla,
Jassi Brar, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joonwon Kang <joonwonkang@google.com>
[ Upstream commit 96a3d2f3167f5644b30e60171898e67123c3c2c6 ]
When the mailbox controller failed transmitting message, the error code
was only passed to the client's tx done handler and not to
mbox_send_message() in blocking mode. For this reason, the function could
return a false success. This commit resolves the issue by introducing the
tx status and checking it before mbox_send_message() returns.
This commit works with the premise that the multi-threads' access to a
channel in blocking mode is serialized by clients, not by the mailbox
APIs, since the current mbox_send_message() in blocking mode does not
support multi-threads.
Signed-off-by: Joonwon Kang <joonwonkang@google.com>
Reviewed-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mailbox/mailbox.c | 6 +++++-
include/linux/mailbox_controller.h | 2 ++
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/mailbox/mailbox.c b/drivers/mailbox/mailbox.c
index c5b9d24efb69c..a00a02b6709c7 100644
--- a/drivers/mailbox/mailbox.c
+++ b/drivers/mailbox/mailbox.c
@@ -110,8 +110,10 @@ static void tx_tick(struct mbox_chan *chan, int r)
if (chan->cl->tx_done)
chan->cl->tx_done(chan->cl, mssg, r);
- if (r != -ETIME && chan->cl->tx_block)
+ if (r != -ETIME && chan->cl->tx_block) {
+ chan->tx_status = r;
complete(&chan->tx_complete);
+ }
}
static enum hrtimer_restart txdone_hrtimer(struct hrtimer *hrtimer)
@@ -281,6 +283,8 @@ int mbox_send_message(struct mbox_chan *chan, void *mssg)
if (ret == 0) {
t = -ETIME;
tx_tick(chan, t);
+ } else if (chan->tx_status < 0) {
+ t = chan->tx_status;
}
}
diff --git a/include/linux/mailbox_controller.h b/include/linux/mailbox_controller.h
index 6fee33cb52f58..02e54ac37a6c0 100644
--- a/include/linux/mailbox_controller.h
+++ b/include/linux/mailbox_controller.h
@@ -108,6 +108,7 @@ struct mbox_controller {
* @txdone_method: Way to detect TXDone chosen by the API
* @cl: Pointer to the current owner of this channel
* @tx_complete: Transmission completion
+ * @tx_status: Transmission status
* @active_req: Currently active request hook
* @msg_count: No. of mssg currently queued
* @msg_free: Index of next available mssg slot
@@ -120,6 +121,7 @@ struct mbox_chan {
unsigned txdone_method;
struct mbox_client *cl;
struct completion tx_complete;
+ int tx_status;
void *active_req;
unsigned msg_count, msg_free;
void *msg_data[MBOX_TX_QUEUE_LEN];
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 050/982] PCI: Wait for device readiness after D3hot -> D0uninitialized transition
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 049/982] mailbox: Make mbox_send_message() return error code when tx fails Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 051/982] drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id Greg Kroah-Hartman
` (938 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjorn Helgaas,
Rafael J. Wysocki (Intel), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjorn Helgaas <helgaas@kernel.org>
[ Upstream commit 41167a1e98536b4baf0846fd259c8124bd1c4e1b ]
For a device that advertises No_Soft_Reset == 0, a transition from D3hot to
D0uninitialized is a soft reset, and the resulting internal device state is
undefined.
Per PCIe r7.0, sec 2.3.1, a transition from D3hot to D0uninitialized
mandates a minimum 10 ms delay before accessing the device. Following this
delay, the device is permitted to respond to initial configuration requests
with a Request Retry Status (RRS) completion status if it needs more time
to initialize.
Call pci_dev_wait() after pci_power_up() performs a D3hot->D0uninitialized
transition to ensure the device is ready to accept config accesses, as is
done after the similar transition in pci_pm_reset().
If the device is already ready, this is essentially a no-op except for one
additional config read.
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Rafael J. Wysocki (Intel) <rafael@kernel.org>
Link: https://patch.msgid.link/20260518191220.636213-3-bhelgaas@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/pci.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/pci.c b/drivers/pci/pci.c
index c87a5e9f75684..b0d4c3bc205bf 100644
--- a/drivers/pci/pci.c
+++ b/drivers/pci/pci.c
@@ -1274,7 +1274,18 @@ int pci_power_up(struct pci_dev *dev)
bool need_restore;
pci_power_t state;
u16 pmcsr;
+ int ret;
+ /*
+ * When setting power state to D0, platform_pci_set_power_state()
+ * ensures main power is on. If it puts the device in D0, it also
+ * completes any required delays after the transition; if it leaves
+ * the device in D1, D2, or D3hot, we use the PM Capability to
+ * transition to D0.
+ *
+ * In all cases, the device is either Configuration-Ready or
+ * inaccessible upon return.
+ */
platform_pci_set_power_state(dev, PCI_D0);
if (!dev->pm_cap) {
@@ -1315,10 +1326,19 @@ int pci_power_up(struct pci_dev *dev)
pci_write_config_word(dev, dev->pm_cap + PCI_PM_CTRL, 0);
/* Mandatory transition delays; see PCI PM 1.2. */
- if (state == PCI_D3hot)
+ if (state == PCI_D3hot) {
pci_dev_d3_sleep(dev);
- else if (state == PCI_D2)
+ if (!(pmcsr & PCI_PM_CTRL_NO_SOFT_RESET)) {
+ ret = pci_dev_wait(dev, "power up D3hot->D0uninitialized",
+ PCIE_RESET_READY_POLL_MS);
+ if (ret) {
+ dev->current_state = PCI_D3cold;
+ return -EIO;
+ }
+ }
+ } else if (state == PCI_D2) {
udelay(PCI_PM_D2_DELAY);
+ }
end:
dev->current_state = PCI_D0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 051/982] drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 050/982] PCI: Wait for device readiness after D3hot -> D0uninitialized transition Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 052/982] drm/amdkfd: Check bounds on allocate_doorbell Greg Kroah-Hartman
` (937 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Francis,
Harish Kasiviswanathan, Alex Deucher, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Francis <David.Francis@amd.com>
[ Upstream commit bfe9a7545b2a7be1c543f1741e16f2d5ec4116ae ]
allocate_sdma_queue has an option where the sdma queue id can be
specified (used by CRIU). We weren't bounds-checking that
value.
Confirm it's less than the maximum number of queues.
Signed-off-by: David Francis <David.Francis@amd.com>
Reviewed-by: Harish Kasiviswanathan <Harish.Kasiviswanathan@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
index 4e754e47bff36..89e3c37e6c56f 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
@@ -1348,6 +1348,9 @@ static int allocate_sdma_queue(struct device_queue_manager *dqm,
}
if (restore_sdma_id) {
+ if (*restore_sdma_id >= get_num_sdma_queues(dqm))
+ return -EINVAL;
+
/* Re-use existing sdma_id */
if (!(dqm->sdma_bitmap & (1ULL << *restore_sdma_id))) {
pr_err("SDMA queue already in use\n");
@@ -1372,6 +1375,9 @@ static int allocate_sdma_queue(struct device_queue_manager *dqm,
return -ENOMEM;
}
if (restore_sdma_id) {
+ if (*restore_sdma_id >= get_num_xgmi_sdma_queues(dqm))
+ return -EINVAL;
+
/* Re-use existing sdma_id */
if (!(dqm->xgmi_sdma_bitmap & (1ULL << *restore_sdma_id))) {
pr_err("SDMA queue already in use\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 052/982] drm/amdkfd: Check bounds on allocate_doorbell
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 051/982] drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 053/982] ALSA: usx2y: Drain pending US-428 pipe-4 output commands Greg Kroah-Hartman
` (936 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Francis,
Harish Kasiviswanathan, Alex Deucher, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Francis <David.Francis@amd.com>
[ Upstream commit 1f087bb8cf9e8797633da35c85435e557ef74d06 ]
allocated_doorbell has an option to set the doorbell id
to a specific value (used by CRIU). This value was not
bounds checked.
Check to confirm it's less than KFD_MAX_NUM_OF_QUEUES_PER_PROCESS.
Signed-off-by: David Francis <David.Francis@amd.com>
Reviewed-by: Harish Kasiviswanathan <Harish.Kasiviswanathan@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
index 89e3c37e6c56f..689abc3d3a395 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
@@ -361,6 +361,9 @@ static int allocate_doorbell(struct qcm_process_device *qpd,
} else {
/* For CP queues on SOC15 */
if (restore_id) {
+ if (*restore_id >= KFD_MAX_NUM_OF_QUEUES_PER_PROCESS)
+ return -EINVAL;
+
/* make sure that ID is free */
if (__test_and_set_bit(*restore_id, qpd->doorbell_bitmap))
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 053/982] ALSA: usx2y: Drain pending US-428 pipe-4 output commands
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 052/982] drm/amdkfd: Check bounds on allocate_doorbell Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 054/982] 9p: invalidate readdir buffer on seek Greg Kroah-Hartman
` (935 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cássio Gabriel <cassiogabrielcontato@gmail.com>
[ Upstream commit 18977c0dd722f52217027ff75de2811c53cce2cc ]
The US-428 pipe-4 output path submits at most one pending p4out
entry from the shared-memory ring per input interrupt. If userspace
queues more than one command before the interrupt handler runs, later
commands remain pending until later input interrupts, even when async
pipe-4 URBs are available.
Drain pending entries while idle async URBs are available. Copy each
command into the existing per-URB async buffer before submission, so the
submitted transfer does not depend on a userspace-mapped ring slot
remaining unchanged after p4out_sent is advanced.
Also update p4out_sent only after usb_submit_urb() succeeds, so a
failed submission is not reported as sent.
This keeps the shared-memory ABI unchanged and fixes only the local
queue-draining behavior.
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260519-alsa-usx2y-p4out-drain-v1-1-8f0a4550bae2@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/usx2y/usbusx2y.c | 39 ++++++++++++++++++++++----------------
1 file changed, 23 insertions(+), 16 deletions(-)
diff --git a/sound/usb/usx2y/usbusx2y.c b/sound/usb/usx2y/usbusx2y.c
index 0fe989a633769..e4385b18edfbe 100644
--- a/sound/usb/usx2y/usbusx2y.c
+++ b/sound/usb/usx2y/usbusx2y.c
@@ -180,7 +180,7 @@ static void i_usx2y_in04_int(struct urb *urb)
struct usx2ydev *usx2y = urb->context;
struct us428ctls_sharedmem *us428ctls = usx2y->us428ctls_sharedmem;
struct us428_p4out *p4out;
- int i, j, n, diff, send;
+ int i, j, n, diff, send, len;
usx2y->in04_int_calls++;
@@ -223,24 +223,31 @@ static void i_usx2y_in04_int(struct urb *urb)
} while (!err && usx2y->us04->submitted < usx2y->us04->len);
}
} else {
- if (us428ctls && us428ctls->p4out_last >= 0 && us428ctls->p4out_last < N_US428_P4OUT_BUFS) {
- if (us428ctls->p4out_last != us428ctls->p4out_sent) {
- send = us428ctls->p4out_sent + 1;
- if (send >= N_US428_P4OUT_BUFS)
- send = 0;
- for (j = 0; j < URBS_ASYNC_SEQ && !err; ++j) {
- if (!usx2y->as04.urb[j]->status) {
- p4out = us428ctls->p4out + send; // FIXME if more than 1 p4out is new, 1 gets lost.
- usb_fill_bulk_urb(usx2y->as04.urb[j], usx2y->dev,
- usb_sndbulkpipe(usx2y->dev, 0x04), &p4out->val.vol,
- p4out->type == ELT_LIGHT ? sizeof(struct us428_lights) : 5,
- i_usx2y_out04_int, usx2y);
- err = usb_submit_urb(usx2y->as04.urb[j], GFP_ATOMIC);
+ while (us428ctls &&
+ us428ctls->p4out_last >= 0 &&
+ us428ctls->p4out_last < N_US428_P4OUT_BUFS &&
+ us428ctls->p4out_last != us428ctls->p4out_sent) {
+ for (j = 0; j < URBS_ASYNC_SEQ && !err; ++j) {
+ if (!usx2y->as04.urb[j]->status) {
+ send = us428ctls->p4out_sent + 1;
+ if (send >= N_US428_P4OUT_BUFS)
+ send = 0;
+
+ p4out = us428ctls->p4out + send;
+ len = p4out->type == ELT_LIGHT ?
+ sizeof(struct us428_lights) : 5;
+ memcpy(usx2y->as04.urb[j]->transfer_buffer,
+ &p4out->val.vol, len);
+ usx2y->as04.urb[j]->transfer_buffer_length = len;
+ err = usb_submit_urb(usx2y->as04.urb[j], GFP_ATOMIC);
+ if (!err)
us428ctls->p4out_sent = send;
- break;
- }
+
+ break;
}
}
+ if (j >= URBS_ASYNC_SEQ || err)
+ break;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 054/982] 9p: invalidate readdir buffer on seek
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 053/982] ALSA: usx2y: Drain pending US-428 pipe-4 output commands Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 055/982] arm64/daifflags: Make local_daif_*() helpers __always_inline Greg Kroah-Hartman
` (934 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pierre Barre, Dominique Martinet,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pierre Barre <pierre@barre.sh>
[ Upstream commit e661e17ddbed524b5fbda789a091b48b6b677067 ]
The per-fid readdir buffer (fid->rdir) is populated lazily and only
refilled when fully drained (rdir->head == rdir->tail). userspace
lseek() on a directory fd updates file->f_pos via generic_file_llseek()
but does not touch the cached buffer, so the next getdents() iterates
the stale cache and emits entries from the previous position instead
of the one the caller asked for.
Track the file position the cached data corresponds to in
struct p9_rdir, and drop the cache on entry to iterate_shared when it
no longer matches ctx->pos. The 9p protocol's Tread/Treaddir already
take an arbitrary offset on every request, so a refill at the new
position is always legal; no .llseek override or seek restriction is
needed.
Reported-by: Pierre Barre <pierre@barre.sh>
Link: https://lore.kernel.org/v9fs/496d10b9-40fe-4f81-8014-37497c37ff63@app.fastmail.com/
Signed-off-by: Pierre Barre <pierre@barre.sh>
Message-ID: <20260512132032.369281-2-pierre@barre.sh>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/9p/vfs_dir.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/fs/9p/vfs_dir.c b/fs/9p/vfs_dir.c
index 3bb95adc9619d..dd36dce582839 100644
--- a/fs/9p/vfs_dir.c
+++ b/fs/9p/vfs_dir.c
@@ -29,6 +29,7 @@
* struct p9_rdir - readdir accounting
* @head: start offset of current dirread buffer
* @tail: end offset of current dirread buffer
+ * @offset: file position the data at @head corresponds to
* @buf: dirread buffer
*
* private structure for keeping track of readdir
@@ -38,6 +39,7 @@
struct p9_rdir {
int head;
int tail;
+ loff_t offset;
uint8_t buf[];
};
@@ -104,6 +106,9 @@ static int v9fs_dir_readdir(struct file *file, struct dir_context *ctx)
kvec.iov_base = rdir->buf;
kvec.iov_len = buflen;
+ if (rdir->head < rdir->tail && rdir->offset != ctx->pos)
+ rdir->head = rdir->tail = 0;
+
while (1) {
if (rdir->tail == rdir->head) {
struct iov_iter to;
@@ -119,6 +124,7 @@ static int v9fs_dir_readdir(struct file *file, struct dir_context *ctx)
rdir->head = 0;
rdir->tail = n;
+ rdir->offset = ctx->pos;
}
while (rdir->head < rdir->tail) {
err = p9stat_read(fid->clnt, rdir->buf + rdir->head,
@@ -136,6 +142,7 @@ static int v9fs_dir_readdir(struct file *file, struct dir_context *ctx)
rdir->head += err;
ctx->pos += err;
+ rdir->offset = ctx->pos;
}
}
}
@@ -163,6 +170,9 @@ static int v9fs_dir_readdir_dotl(struct file *file, struct dir_context *ctx)
if (!rdir)
return -ENOMEM;
+ if (rdir->head < rdir->tail && rdir->offset != ctx->pos)
+ rdir->head = rdir->tail = 0;
+
while (1) {
if (rdir->tail == rdir->head) {
err = p9_client_readdir(fid, rdir->buf, buflen,
@@ -172,6 +182,7 @@ static int v9fs_dir_readdir_dotl(struct file *file, struct dir_context *ctx)
rdir->head = 0;
rdir->tail = err;
+ rdir->offset = ctx->pos;
}
while (rdir->head < rdir->tail) {
@@ -192,6 +203,7 @@ static int v9fs_dir_readdir_dotl(struct file *file, struct dir_context *ctx)
ctx->pos = curdirent.d_off;
rdir->head += err;
+ rdir->offset = ctx->pos;
}
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 055/982] arm64/daifflags: Make local_daif_*() helpers __always_inline
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 054/982] 9p: invalidate readdir buffer on seek Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 056/982] 9p: use kvzalloc for readdir buffer Greg Kroah-Hartman
` (933 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Leonardo Bras,
Will Deacon, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leonardo Bras <leo.bras@arm.com>
[ Upstream commit 827ce94e0897a70241abf810b1d3d7d083053a39 ]
Make sure those helpers are always inlined and instrumentation safe.
Suggested-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Leonardo Bras <leo.bras@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/include/asm/daifflags.h | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/arch/arm64/include/asm/daifflags.h b/arch/arm64/include/asm/daifflags.h
index 55f57dfa8e2fe..e2ad84c2f32bc 100644
--- a/arch/arm64/include/asm/daifflags.h
+++ b/arch/arm64/include/asm/daifflags.h
@@ -19,7 +19,7 @@
/* mask/save/unmask/restore all exceptions, including interrupts. */
-static inline void local_daif_mask(void)
+static __always_inline void local_daif_mask(void)
{
WARN_ON(system_has_prio_mask_debugging() &&
(read_sysreg_s(SYS_ICC_PMR_EL1) == (GIC_PRIO_IRQOFF |
@@ -38,7 +38,7 @@ static inline void local_daif_mask(void)
trace_hardirqs_off();
}
-static inline unsigned long local_daif_save_flags(void)
+static __always_inline unsigned long local_daif_save_flags(void)
{
unsigned long flags;
@@ -53,7 +53,7 @@ static inline unsigned long local_daif_save_flags(void)
return flags;
}
-static inline unsigned long local_daif_save(void)
+static __always_inline unsigned long local_daif_save(void)
{
unsigned long flags;
@@ -64,7 +64,7 @@ static inline unsigned long local_daif_save(void)
return flags;
}
-static inline void local_daif_restore(unsigned long flags)
+static __always_inline void local_daif_restore(unsigned long flags)
{
bool irq_disabled = flags & PSR_I_BIT;
@@ -124,7 +124,7 @@ static inline void local_daif_restore(unsigned long flags)
* Called by synchronous exception handlers to restore the DAIF bits that were
* modified by taking an exception.
*/
-static inline void local_daif_inherit(struct pt_regs *regs)
+static __always_inline void local_daif_inherit(struct pt_regs *regs)
{
unsigned long flags = regs->pstate & DAIF_MASK;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 056/982] 9p: use kvzalloc for readdir buffer
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 055/982] arm64/daifflags: Make local_daif_*() helpers __always_inline Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 057/982] firmware: arm_scmi: Validate SENSOR_UPDATE payload size Greg Kroah-Hartman
` (932 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pierre Barre, Dominique Martinet,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pierre Barre <pierre@barre.sh>
[ Upstream commit b4d71bea144550ff4a0917f8c4b06d4063eb27a6 ]
The readdir buffer is sized to msize, so kzalloc() can fail under
fragmentation with a page allocation failure in v9fs_alloc_rdir_buf()
/ v9fs_dir_readdir_dotl().
The buffer is only a response sink and is never pack_sg_list()'d,
so kvzalloc() is safe for all transports, unlike the fcall buffers
fixed in e21d451a82f3 ("9p: Use kvmalloc for message buffers on
supported transports").
Signed-off-by: Pierre Barre <pierre@barre.sh>
Message-ID: <20260512132032.369281-1-pierre@barre.sh>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/9p/vfs_dir.c | 2 +-
net/9p/client.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/9p/vfs_dir.c b/fs/9p/vfs_dir.c
index dd36dce582839..3be09b94a8e24 100644
--- a/fs/9p/vfs_dir.c
+++ b/fs/9p/vfs_dir.c
@@ -74,7 +74,7 @@ static struct p9_rdir *v9fs_alloc_rdir_buf(struct file *filp, int buflen)
struct p9_fid *fid = filp->private_data;
if (!fid->rdir)
- fid->rdir = kzalloc(sizeof(struct p9_rdir) + buflen, GFP_KERNEL);
+ fid->rdir = kvzalloc(sizeof(struct p9_rdir) + buflen, GFP_KERNEL);
return fid->rdir;
}
diff --git a/net/9p/client.c b/net/9p/client.c
index 70c2cf23128fb..1a65c51636188 100644
--- a/net/9p/client.c
+++ b/net/9p/client.c
@@ -880,7 +880,7 @@ static void p9_fid_destroy(struct p9_fid *fid)
spin_lock_irqsave(&clnt->lock, flags);
idr_remove(&clnt->fids, fid->fid);
spin_unlock_irqrestore(&clnt->lock, flags);
- kfree(fid->rdir);
+ kvfree(fid->rdir);
kfree(fid);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 057/982] firmware: arm_scmi: Validate SENSOR_UPDATE payload size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 056/982] 9p: use kvzalloc for readdir buffer Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 058/982] firmware: arm_scmi: Validate BASE_ERROR_EVENT " Greg Kroah-Hartman
` (931 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Marussi, Sudeep Holla,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 32bc5496b48174dbca1f187f710955ee4d9527a1 ]
SENSOR_UPDATE carries one or more sensor readings after the fixed
notification header. The parser derives the expected reading count
from the sensor description, but it did not verify that the received
payload contains those entries before parsing them.
Reject truncated update notifications before reading the variable
array.
Link: https://patch.msgid.link/20260517-scmi_fixes-v1-3-d86daec4defd@kernel.org
Reviewed-by: Cristian Marussi <cristian.marussi@arm.com>
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/sensors.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/firmware/arm_scmi/sensors.c b/drivers/firmware/arm_scmi/sensors.c
index 4e3e937cb92c1..900ee86a2c662 100644
--- a/drivers/firmware/arm_scmi/sensors.c
+++ b/drivers/firmware/arm_scmi/sensors.c
@@ -1037,12 +1037,15 @@ scmi_sensor_fill_custom_report(const struct scmi_protocol_handle *ph,
case SCMI_EVENT_SENSOR_UPDATE:
{
int i;
+ size_t expected_sz;
struct scmi_sensor_info *s;
const struct scmi_sensor_update_notify_payld *p = payld;
struct scmi_sensor_update_report *r = report;
struct sensors_info *sinfo = ph->get_priv(ph);
- /* payld_sz is variable for this event */
+ if (payld_sz < sizeof(*p))
+ break;
+
r->sensor_id = le32_to_cpu(p->sensor_id);
if (r->sensor_id >= sinfo->num_sensors)
break;
@@ -1056,6 +1059,11 @@ scmi_sensor_fill_custom_report(const struct scmi_protocol_handle *ph,
* readings defined for this sensor or 1 for scalar sensors.
*/
r->readings_count = s->num_axis ?: 1;
+ expected_sz = sizeof(*p) + r->readings_count *
+ sizeof(p->readings[0]);
+ if (payld_sz < expected_sz)
+ break;
+
for (i = 0; i < r->readings_count; i++)
scmi_parse_sensor_readings(&r->readings[i],
&p->readings[i]);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 058/982] firmware: arm_scmi: Validate BASE_ERROR_EVENT payload size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 057/982] firmware: arm_scmi: Validate SENSOR_UPDATE payload size Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 059/982] wifi: mac80211: dont call ieee80211_handle_reconfig_failure when not needed Greg Kroah-Hartman
` (930 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sudeep Holla, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 56e7e64cdd0e7209a58c8ec66028d63387402919 ]
BASE_ERROR_EVENT carries a variable number of message reports,
with the count encoded in error_status. The notification parser used
that count without checking whether the received payload contained all
reported entries.
Reject truncated payloads before copying the report array.
Link: https://patch.msgid.link/20260517-scmi_fixes-v1-2-d86daec4defd@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/base.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scmi/base.c b/drivers/firmware/arm_scmi/base.c
index a52f084a6a87b..f455165a81bcd 100644
--- a/drivers/firmware/arm_scmi/base.c
+++ b/drivers/firmware/arm_scmi/base.c
@@ -324,6 +324,8 @@ static void *scmi_base_fill_custom_report(const struct scmi_protocol_handle *ph,
void *report, u32 *src_id)
{
int i;
+ u32 error_status;
+ size_t expected_sz;
const struct scmi_base_error_notify_payld *p = payld;
struct scmi_base_error_report *r = report;
@@ -337,10 +339,19 @@ static void *scmi_base_fill_custom_report(const struct scmi_protocol_handle *ph,
if (evt_id != SCMI_EVENT_BASE_ERROR_EVENT || sizeof(*p) < payld_sz)
return NULL;
+ expected_sz = offsetof(typeof(*p), msg_reports);
+ if (payld_sz < expected_sz)
+ return NULL;
+
r->timestamp = timestamp;
r->agent_id = le32_to_cpu(p->agent_id);
- r->fatal = IS_FATAL_ERROR(le32_to_cpu(p->error_status));
- r->cmd_count = ERROR_CMD_COUNT(le32_to_cpu(p->error_status));
+ error_status = le32_to_cpu(p->error_status);
+ r->fatal = IS_FATAL_ERROR(error_status);
+ r->cmd_count = ERROR_CMD_COUNT(error_status);
+ expected_sz += r->cmd_count * sizeof(p->msg_reports[0]);
+ if (payld_sz < expected_sz)
+ return NULL;
+
for (i = 0; i < r->cmd_count; i++)
r->reports[i] = le64_to_cpu(p->msg_reports[i]);
*src_id = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 059/982] wifi: mac80211: dont call ieee80211_handle_reconfig_failure when not needed
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 058/982] firmware: arm_scmi: Validate BASE_ERROR_EVENT " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 060/982] bitfield: wire __bf_shf to __builtin_ctzll Greg Kroah-Hartman
` (929 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Miri Korenblit, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miri Korenblit <miriam.rachel.korenblit@intel.com>
[ Upstream commit 7a8a3ff2815501f78f494808355ddf37e08647d0 ]
In case reconfiguration of NAN fails, we call
ieee80211_handle_reconfig_failure, that marks all interfaces as not in
the driver.
Then, at the error path of the reconfig, cfg80211_shutdown_all_interfaces
is called to destroy all the interfaces.
If we have any other interface but the NAN one, for example a BSS
station, then when its state (links, stations) will be removed, we
won't tell the driver about this, because we will think that the
interfaces are not in the driver, and then drivers might remain with
dangling pointers to objects like stations and links (at least for
iwlwifi this is the case).
ieee80211_handle_reconfig_failure is meant to be called after we cleaned
up the state in the driver, there is no reason to call it for NAN
reconfiguration failure.
Fix the code to just warn in such a case, as we do in other error paths
in reconfig where it is too complicated to rewind.
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260513182548.6a25f3a0a6ec.I83d1f2a7eed20200a78a62757c6b193e3bab892b@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/util.c | 6 +-----
1 file changed, 1 insertion(+), 5 deletions(-)
diff --git a/net/mac80211/util.c b/net/mac80211/util.c
index 116a3e70582be..73116ed609e1f 100644
--- a/net/mac80211/util.c
+++ b/net/mac80211/util.c
@@ -2617,11 +2617,7 @@ int ieee80211_reconfig(struct ieee80211_local *local)
}
break;
case NL80211_IFTYPE_NAN:
- res = ieee80211_reconfig_nan(sdata);
- if (res < 0) {
- ieee80211_handle_reconfig_failure(local);
- return res;
- }
+ WARN_ON(ieee80211_reconfig_nan(sdata));
break;
case NL80211_IFTYPE_AP_VLAN:
case NL80211_IFTYPE_MONITOR:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 060/982] bitfield: wire __bf_shf to __builtin_ctzll
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 059/982] wifi: mac80211: dont call ieee80211_handle_reconfig_failure when not needed Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 061/982] nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl Greg Kroah-Hartman
` (928 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Matt Coster, Yury Norov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yury Norov <ynorov@nvidia.com>
[ Upstream commit 09472f591aa0b72c2dd6c693f48b2d6fea66c7ba ]
__bf_shf() is currently based on built-in ffsll. It's more
straightforward to wire it to __builtin_ctzll, which makes it a pure
rename.
Worth to notice that __builtin_ffsll() is buggy on GCC before 14.1:
int main() {
sizeof(struct {
int t : !(__builtin_ffsll(~0ULL) + 1 < 0);
});
}
test.c: In function 'main':
test.c:3:21: error: bit-field 't' width not an integer constant
3 | int t : !(__builtin_ffsll(~0ULL) + 1 < 0);
| ^
Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=124699
Reported-by: Matt Coster <matt.coster@imgtec.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202603222211.A2XiR1YU-lkp@intel.com/
Signed-off-by: Yury Norov <ynorov@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/bitfield.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/include/linux/bitfield.h b/include/linux/bitfield.h
index 35622ff2c9951..65646d4917658 100644
--- a/include/linux/bitfield.h
+++ b/include/linux/bitfield.h
@@ -43,7 +43,7 @@
* reg |= FIELD_PREP(REG_FIELD_C, c);
*/
-#define __bf_shf(x) (__builtin_ffsll(x) - 1)
+#define __bf_shf __builtin_ctzll
#define __scalar_type_to_unsigned_cases(type) \
unsigned type: (unsigned type)0, \
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 061/982] nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 060/982] bitfield: wire __bf_shf to __builtin_ctzll Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 062/982] net: usb: qmi_wwan: add MeiG SRM813Q Greg Kroah-Hartman
` (927 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Hannes Reinecke,
Sagi Grimberg, Daniel Wagner, Maurizio Lombardi, Keith Busch,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maurizio Lombardi <mlombard@redhat.com>
[ Upstream commit f702badaf7d31dc3dea6c66da92b5f35fadd89dc ]
Currently, the final reference for the fabrics admin queue (fabrics_q)
is dropped inside nvme_remove_admin_tag_set(). However, the primary admin
queue (admin_q) defers dropping its final reference until
nvme_free_ctrl().
Move the blk_put_queue() call for fabrics_q from
nvme_remove_admin_tag_set() to nvme_free_ctrl(). This aligns the
lifecycle management of both admin queues, ensuring they are freed
symmetrically when the controller is finally torn down.
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Sagi Grimberg <sagi@grimberg.me>
Reviewed-by: Daniel Wagner <dwagner@suse.de>
Signed-off-by: Maurizio Lombardi <mlombard@redhat.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/core.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/nvme/host/core.c b/drivers/nvme/host/core.c
index f7695aba66cc4..66600341bd6aa 100644
--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -5050,10 +5050,8 @@ EXPORT_SYMBOL_GPL(nvme_alloc_admin_tag_set);
void nvme_remove_admin_tag_set(struct nvme_ctrl *ctrl)
{
blk_mq_destroy_queue(ctrl->admin_q);
- if (ctrl->ops->flags & NVME_F_FABRICS) {
+ if (ctrl->fabrics_q)
blk_mq_destroy_queue(ctrl->fabrics_q);
- blk_put_queue(ctrl->fabrics_q);
- }
blk_mq_free_tag_set(ctrl->admin_tagset);
}
EXPORT_SYMBOL_GPL(nvme_remove_admin_tag_set);
@@ -5194,6 +5192,8 @@ static void nvme_free_ctrl(struct device *dev)
if (ctrl->admin_q)
blk_put_queue(ctrl->admin_q);
+ if (ctrl->fabrics_q)
+ blk_put_queue(ctrl->fabrics_q);
if (!subsys || ctrl->instance != subsys->instance)
ida_free(&nvme_instance_ida, ctrl->instance);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 062/982] net: usb: qmi_wwan: add MeiG SRM813Q
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 061/982] nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 063/982] net: bridge: remove stale rcu_barrier() in br_multicast_dev_del() Greg Kroah-Hartman
` (926 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jan Volckaert, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Volckaert <janvolck@gmail.com>
[ Upstream commit 9758c11fc6c138a79a28a5659feeaa3abde7aa6a ]
Add support for the Qualcomm Technology Snapdragon X35-based MeiG SRM813Q
module.
The module can be put in different modes via AT commands
to enable/disable GPS functionality:
MODEM - PPP mode(2dee:4d63): AT+SER=1,1
If#= 0: RMNET
If#= 1: DIAG/ADB
If#= 2: MODEM
If#= 3: AT
P: Vendor=2dee ProdID=4d63 Rev=05.15
S: Manufacturer=MEIG
S: Product=LTE-A Module
S: SerialNumber=1bd51f0e
C: #Ifs= 4 Cfg#= 1 Atr=80 MxPwr=500mA
I: If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E: Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=82(I) Atr=03(Int.) MxPS= 8 Ivl=32ms
I: If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E: Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I: If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E: Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=84(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=85(I) Atr=03(Int.) MxPS= 10 Ivl=32ms
I: If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E: Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=86(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=87(I) Atr=03(Int.) MxPS= 10 Ivl=32ms
NMEA mode(2dee:4d64): AT+SER=51,1
If#= 0: RMNET
If#= 1: DIAG/ADB
If#= 2: NMEA
If#= 3: AT
P: Vendor=2dee ProdID=4d64 Rev=05.15
S: Manufacturer=MEIG
S: Product=LTE-A Module
S: SerialNumber=1bd51f0e
C: #Ifs= 4 Cfg#= 1 Atr=80 MxPwr=500mA
I: If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E: Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=82(I) Atr=03(Int.) MxPS= 8 Ivl=32ms
I: If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E: Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I: If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=60 Driver=option
E: Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=84(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=85(I) Atr=03(Int.) MxPS= 10 Ivl=32ms
I: If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E: Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=86(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E: Ad=87(I) Atr=03(Int.) MxPS= 10 Ivl=32ms
Signed-off-by: Jan Volckaert <janvolck@gmail.com>
Link: https://patch.msgid.link/20260517153237.55995-2-janvolck@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/qmi_wwan.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/usb/qmi_wwan.c b/drivers/net/usb/qmi_wwan.c
index d1ac454d17d5d..8ed86bdefb8d6 100644
--- a/drivers/net/usb/qmi_wwan.c
+++ b/drivers/net/usb/qmi_wwan.c
@@ -1455,6 +1455,8 @@ static const struct usb_device_id products[] = {
{QMI_QUIRK_SET_DTR(0x1546, 0x1342, 4)}, /* u-blox LARA-L6 */
{QMI_QUIRK_SET_DTR(0x33f8, 0x0104, 4)}, /* Rolling RW101 RMNET */
{QMI_FIXED_INTF(0x2dee, 0x4d22, 5)}, /* MeiG Smart SRM825L */
+ {QMI_QUIRK_SET_DTR(0x2dee, 0x4d63, 0)}, /* MeiG SRM813Q w/ Modem(PPP) */
+ {QMI_QUIRK_SET_DTR(0x2dee, 0x4d64, 0)}, /* MeiG SRM813Q w/ NMEA */
/* 4. Gobi 1000 devices */
{QMI_GOBI1K_DEVICE(0x05c6, 0x9212)}, /* Acer Gobi Modem Device */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 063/982] net: bridge: remove stale rcu_barrier() in br_multicast_dev_del()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 062/982] net: usb: qmi_wwan: add MeiG SRM813Q Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 064/982] net/sched: sch_drr: make cl->quantum lockless Greg Kroah-Hartman
` (925 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Sitnicki,
Ido Schimmel, Nikolay Aleksandrov, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 25ae123db10ba9ab890b56bcdb0a4363aee8529a ]
This rcu_barrier() came from a time call_rcu() calls were used in
net/bridge/br_multicast.c.
Now kfree_rcu() is there, we can remove this problematic rcu_barrier()
which causes extreme RTNL pressure in many syzbot reports.
INFO: task syz-executor:77945 is blocked on a mutex likely owned by task kworker/u1024:5:36537.
task:kworker/u1024:5 state:D stack:24616 pid:36537 tgid:36537 ppid:2 task_flags:0x4208060 flags:0x00080000 last_sleep:612797637337
Workqueue: netns cleanup_net
Call Trace:
<TASK>
[<ffffffff81914eaa>] context_switch+0xf2a/0x1730 kernel/sched/core.c:6483
[<ffffffff81201143>] __schedule+0x1133/0x43a0 kernel/sched/core.c:8411
[<ffffffff8120446b>] __schedule_loop kernel/sched/core.c:8514 [inline]
[<ffffffff8120446b>] schedule+0xab/0x260 kernel/sched/core.c:8529
[<ffffffff8121a093>] schedule_timeout+0xc3/0x2b0 kernel/time/sleep_timeout.c:75
[<ffffffff81205347>] do_wait_for_common kernel/sched/completion.c:100 [inline]
[<ffffffff81205347>] __wait_for_common kernel/sched/completion.c:121 [inline]
[<ffffffff81205347>] wait_for_common kernel/sched/completion.c:132 [inline]
[<ffffffff81205347>] wait_for_completion+0x2c7/0x5d0 kernel/sched/completion.c:153
[<ffffffff81b8f27f>] rcu_barrier+0x49f/0x620 kernel/rcu/tree.c:3888
[<ffffffff860091b3>] br_multicast_dev_del+0x303/0x350 net/bridge/br_multicast.c:4459
[<ffffffff85fb5dbc>] br_dev_uninit+0x1c/0x40 net/bridge/br_device.c:157
[<ffffffff8568058c>] unregister_netdevice_many_notify+0x1c1c/0x2300 net/core/dev.c:12599
[<ffffffff8562be43>] ops_exit_rtnl_list net/core/net_namespace.c:187 [inline]
[<ffffffff8562be43>] ops_undo_list+0x3d3/0x940 net/core/net_namespace.c:248
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260519095540.2643318-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_multicast.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/net/bridge/br_multicast.c b/net/bridge/br_multicast.c
index f5f6da322227e..4245d8d7767d8 100644
--- a/net/bridge/br_multicast.c
+++ b/net/bridge/br_multicast.c
@@ -4284,8 +4284,6 @@ void br_multicast_dev_del(struct net_bridge *br)
br_multicast_ctx_deinit(&br->multicast_ctx);
br_multicast_gc(&deleted_head);
cancel_work_sync(&br->mcast_gc_work);
-
- rcu_barrier();
}
int br_multicast_set_router(struct net_bridge_mcast *brmctx, unsigned long val)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 064/982] net/sched: sch_drr: make cl->quantum lockless
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 063/982] net: bridge: remove stale rcu_barrier() in br_multicast_dev_del() Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 065/982] net/rds: Dont sleep inside rds_ib_conn_path_shutdown Greg Kroah-Hartman
` (924 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit a4d880b85089e12a5f2e8e2fee386310cec5b99a ]
cl->quantum does not need to be protected by RTNL or qdisc spinlock.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260519094618.2632073-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_drr.c | 10 ++++------
1 file changed, 4 insertions(+), 6 deletions(-)
diff --git a/net/sched/sch_drr.c b/net/sched/sch_drr.c
index f6048a2eddce4..437b09acef123 100644
--- a/net/sched/sch_drr.c
+++ b/net/sched/sch_drr.c
@@ -98,10 +98,8 @@ static int drr_change_class(struct Qdisc *sch, u32 classid, u32 parentid,
}
}
- sch_tree_lock(sch);
if (tb[TCA_DRR_QUANTUM])
- cl->quantum = quantum;
- sch_tree_unlock(sch);
+ WRITE_ONCE(cl->quantum, quantum);
return 0;
}
@@ -250,7 +248,7 @@ static int drr_dump_class(struct Qdisc *sch, unsigned long arg,
nest = nla_nest_start_noflag(skb, TCA_OPTIONS);
if (nest == NULL)
goto nla_put_failure;
- if (nla_put_u32(skb, TCA_DRR_QUANTUM, cl->quantum))
+ if (nla_put_u32(skb, TCA_DRR_QUANTUM, READ_ONCE(cl->quantum)))
goto nla_put_failure;
return nla_nest_end(skb, nest);
@@ -361,7 +359,7 @@ static int drr_enqueue(struct sk_buff *skb, struct Qdisc *sch,
if (!cl_is_active(cl)) {
list_add_tail(&cl->alist, &q->active);
- WRITE_ONCE(cl->deficit, cl->quantum);
+ WRITE_ONCE(cl->deficit, READ_ONCE(cl->quantum));
}
sch->qstats.backlog += len;
@@ -402,7 +400,7 @@ static struct sk_buff *drr_dequeue(struct Qdisc *sch)
return skb;
}
- WRITE_ONCE(cl->deficit, cl->deficit + cl->quantum);
+ WRITE_ONCE(cl->deficit, cl->deficit + READ_ONCE(cl->quantum));
list_move_tail(&cl->alist, &q->active);
}
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 065/982] net/rds: Dont sleep inside rds_ib_conn_path_shutdown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 064/982] net/sched: sch_drr: make cl->quantum lockless Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 066/982] befs: handle set_blocksize failures Greg Kroah-Hartman
` (923 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 16f48efaeb6991193fb7775c577f06f5b20b0c90 ]
New rds rdma self tests exposed a hang when tearing down
the ib network configs. This is caused by the shutdown worker
thread sleeping on the wait_event call, which blocks other work
items in the queue. Fix this by changing wait_event to
wait_event timeout, and looping until the wait check succeeds.
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260518012443.2629206-2-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/ib_cm.c | 25 ++++++++++++++++++++-----
1 file changed, 20 insertions(+), 5 deletions(-)
diff --git a/net/rds/ib_cm.c b/net/rds/ib_cm.c
index e50e01abb0799..d9b6c9d2f6791 100644
--- a/net/rds/ib_cm.c
+++ b/net/rds/ib_cm.c
@@ -1043,6 +1043,19 @@ int rds_ib_conn_path_connect(struct rds_conn_path *cp)
return ret;
}
+static unsigned long rds_ib_conn_path_shutdown_check_wait(struct rds_conn_path *cp)
+{
+ struct rds_connection *conn = cp->cp_conn;
+ struct rds_ib_connection *ic = conn->c_transport_data;
+
+ return (!ic->i_cm_id ||
+ (rds_ib_ring_empty(&ic->i_recv_ring) &&
+ (atomic_read(&ic->i_signaled_sends) == 0) &&
+ (atomic_read(&ic->i_fastreg_inuse_count)) == 0 &&
+ (atomic_read(&ic->i_fastreg_wrs) == RDS_IB_DEFAULT_FR_WR))) ? 0
+ : msecs_to_jiffies(1000);
+}
+
/*
* This is so careful about only cleaning up resources that were built up
* so that it can be called at any point during startup. In fact it
@@ -1083,11 +1096,13 @@ void rds_ib_conn_path_shutdown(struct rds_conn_path *cp)
* sends to complete we're ensured that there will be no
* more tx processing.
*/
- wait_event(rds_ib_ring_empty_wait,
- rds_ib_ring_empty(&ic->i_recv_ring) &&
- (atomic_read(&ic->i_signaled_sends) == 0) &&
- (atomic_read(&ic->i_fastreg_inuse_count) == 0) &&
- (atomic_read(&ic->i_fastreg_wrs) == RDS_IB_DEFAULT_FR_WR));
+ while (!wait_event_timeout(rds_ib_ring_empty_wait,
+ rds_ib_conn_path_shutdown_check_wait(cp) == 0,
+ msecs_to_jiffies(1000))) {
+ tasklet_schedule(&ic->i_send_tasklet);
+ tasklet_schedule(&ic->i_recv_tasklet);
+ }
+
tasklet_kill(&ic->i_send_tasklet);
tasklet_kill(&ic->i_recv_tasklet);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 066/982] befs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 065/982] net/rds: Dont sleep inside rds_ib_conn_path_shutdown Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 067/982] affs: " Greg Kroah-Hartman
` (922 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 7597d42a25332617a3dfe596758d780ec6c028d7 ]
befs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting we will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-6-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/befs/linuxvfs.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/befs/linuxvfs.c b/fs/befs/linuxvfs.c
index 32749fcee090a..3646d82271474 100644
--- a/fs/befs/linuxvfs.c
+++ b/fs/befs/linuxvfs.c
@@ -890,7 +890,8 @@ befs_fill_super(struct super_block *sb, void *data, int silent)
*/
sb->s_magic = BEFS_SUPER_MAGIC;
/* Set real blocksize of fs */
- sb_set_blocksize(sb, (ulong) befs_sb->block_size);
+ if (!sb_set_blocksize(sb, (ulong) befs_sb->block_size))
+ goto unacquire_priv_sbp;
sb->s_op = &befs_sops;
sb->s_export_op = &befs_export_operations;
sb->s_time_min = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 067/982] affs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 066/982] befs: handle set_blocksize failures Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 068/982] bfs: " Greg Kroah-Hartman
` (921 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 0861182af5983a39bd2a891966436c5679b74a45 ]
affs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting we will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-7-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/affs/affs.h | 5 -----
fs/affs/super.c | 6 ++++--
2 files changed, 4 insertions(+), 7 deletions(-)
diff --git a/fs/affs/affs.h b/fs/affs/affs.h
index bfa89e131ead0..af34fc78a9fb5 100644
--- a/fs/affs/affs.h
+++ b/fs/affs/affs.h
@@ -226,11 +226,6 @@ static inline bool affs_validblock(struct super_block *sb, int block)
block < AFFS_SB(sb)->s_partition_size);
}
-static inline void
-affs_set_blocksize(struct super_block *sb, int size)
-{
- sb_set_blocksize(sb, size);
-}
static inline struct buffer_head *
affs_bread(struct super_block *sb, int block)
{
diff --git a/fs/affs/super.c b/fs/affs/super.c
index 58b391446ae1f..6159ba45c843a 100644
--- a/fs/affs/super.c
+++ b/fs/affs/super.c
@@ -392,7 +392,8 @@ static int affs_fill_super(struct super_block *sb, void *data, int silent)
size = bdev_nr_sectors(sb->s_bdev);
pr_debug("initial blocksize=%d, #blocks=%d\n", 512, size);
- affs_set_blocksize(sb, PAGE_SIZE);
+ if (!sb_set_blocksize(sb, PAGE_SIZE))
+ return -EINVAL;
/* Try to find root block. Its location depends on the block size. */
i = bdev_logical_block_size(sb->s_bdev);
@@ -407,7 +408,8 @@ static int affs_fill_super(struct super_block *sb, void *data, int silent)
if (root_block < 0)
sbi->s_root_block = (reserved + size - 1) / 2;
pr_debug("setting blocksize to %d\n", blocksize);
- affs_set_blocksize(sb, blocksize);
+ if (!sb_set_blocksize(sb, blocksize))
+ return -EINVAL;
sbi->s_partition_size = size;
/* The root block location that was calculated above is not
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 068/982] bfs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 067/982] affs: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 069/982] minix: " Greg Kroah-Hartman
` (920 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 2430e3380936df0b648af720cae624eef035a2d1 ]
bfs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-2-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/bfs/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/bfs/inode.c b/fs/bfs/inode.c
index 07f7929d07fd8..c2dadba110c49 100644
--- a/fs/bfs/inode.c
+++ b/fs/bfs/inode.c
@@ -343,7 +343,8 @@ static int bfs_fill_super(struct super_block *s, void *data, int silent)
s->s_time_min = 0;
s->s_time_max = U32_MAX;
- sb_set_blocksize(s, BFS_BSIZE);
+ if (!sb_set_blocksize(s, BFS_BSIZE))
+ goto out;
sbh = sb_bread(s, 0);
if (!sbh)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 069/982] minix: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 068/982] bfs: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 070/982] qnx4: " Greg Kroah-Hartman
` (919 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 38a03dc2bc71e7e0746cdb9ef5e9947f72470c67 ]
minix uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting we will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-9-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/minix/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/minix/inode.c b/fs/minix/inode.c
index fbbc4ef1b7a2e..99ba8a1bf9394 100644
--- a/fs/minix/inode.c
+++ b/fs/minix/inode.c
@@ -270,7 +270,8 @@ static int minix_fill_super(struct super_block *s, void *data, int silent)
sbi->s_namelen = 60;
sbi->s_version = MINIX_V3;
sbi->s_mount_state = MINIX_VALID_FS;
- sb_set_blocksize(s, m3s->s_blocksize);
+ if (!sb_set_blocksize(s, m3s->s_blocksize))
+ goto out;
s->s_max_links = MINIX2_LINK_MAX;
} else
goto out_no_fs;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 070/982] qnx4: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 069/982] minix: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 071/982] jfs: " Greg Kroah-Hartman
` (918 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Anders Larsen,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit c7d911ea1cc9a63b07e52f5e75b263be0615b289 ]
qnx4 uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-4-hch@lst.de
Acked-by: Anders Larsen <al@alarsen.net>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/qnx4/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/qnx4/inode.c b/fs/qnx4/inode.c
index 391ea402920d9..b921e56b36e68 100644
--- a/fs/qnx4/inode.c
+++ b/fs/qnx4/inode.c
@@ -195,7 +195,8 @@ static int qnx4_fill_super(struct super_block *s, void *data, int silent)
return -ENOMEM;
s->s_fs_info = qs;
- sb_set_blocksize(s, QNX4_BLOCK_SIZE);
+ if (!sb_set_blocksize(s, QNX4_BLOCK_SIZE))
+ return -EINVAL;
s->s_op = &qnx4_sops;
s->s_magic = QNX4_SUPER_MAGIC;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 071/982] jfs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 070/982] qnx4: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 072/982] hpfs: " Greg Kroah-Hartman
` (917 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 05107f5602751fcfd3d108c1f579eb45aabead52 ]
jfs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting we will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-5-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/jfs/super.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/jfs/super.c b/fs/jfs/super.c
index 85d4f44f2ac4d..698470a2480c2 100644
--- a/fs/jfs/super.c
+++ b/fs/jfs/super.c
@@ -524,7 +524,8 @@ static int jfs_fill_super(struct super_block *sb, void *data, int silent)
/*
* Initialize blocksize to 4K.
*/
- sb_set_blocksize(sb, PSIZE);
+ if (!sb_set_blocksize(sb, PSIZE))
+ goto out_unload;
/*
* Set method vectors.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 072/982] hpfs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 071/982] jfs: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 073/982] omfs: " Greg Kroah-Hartman
` (916 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit a405996f23e04942aad064ab8d50c55827482872 ]
hpfs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-3-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/hpfs/super.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/hpfs/super.c b/fs/hpfs/super.c
index 1cb89595b8756..c66f859ec9a9b 100644
--- a/fs/hpfs/super.c
+++ b/fs/hpfs/super.c
@@ -584,7 +584,8 @@ static int hpfs_fill_super(struct super_block *s, void *options, int silent)
}
/*sbi->sb_mounting = 1;*/
- sb_set_blocksize(s, 512);
+ if (!sb_set_blocksize(s, 512))
+ goto bail0;
sbi->sb_fs_size = -1;
if (!(bootblock = hpfs_map_sector(s, 0, &bh0, 0))) goto bail1;
if (!(superblock = hpfs_map_sector(s, 16, &bh1, 1))) goto bail2;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 073/982] omfs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 072/982] hpfs: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 074/982] isofs: " Greg Kroah-Hartman
` (915 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 18c3d6fcb557f920c9143711497625e70153874c ]
omfs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting we will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-11-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/omfs/inode.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/fs/omfs/inode.c b/fs/omfs/inode.c
index 9773846daa4bc..760f675a73d92 100644
--- a/fs/omfs/inode.c
+++ b/fs/omfs/inode.c
@@ -480,7 +480,8 @@ static int omfs_fill_super(struct super_block *sb, void *data, int silent)
sb->s_time_min = 0;
sb->s_time_max = U64_MAX / MSEC_PER_SEC;
- sb_set_blocksize(sb, 0x200);
+ if (!sb_set_blocksize(sb, 0x200))
+ goto end;
bh = sb_bread(sb, 0);
if (!bh)
@@ -532,7 +533,8 @@ static int omfs_fill_super(struct super_block *sb, void *data, int silent)
* Use sys_blocksize as the fs block since it is smaller than a
* page while the fs blocksize can be larger.
*/
- sb_set_blocksize(sb, sbi->s_sys_blocksize);
+ if (!sb_set_blocksize(sb, sbi->s_sys_blocksize))
+ goto out_brelse_bh;
/*
* ...and the difference goes into a shift. sys_blocksize is always
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 074/982] isofs: handle set_blocksize failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 073/982] omfs: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 075/982] HID: bpf: Add Huion Inspiroy Frego M button quirk Greg Kroah-Hartman
` (914 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 25ef4c4d9f0e96fb89c0ae0d7127c3f12a31bc32 ]
isofs uses buffer_heads, which don't handle block size > PAGE_SIZE well.
Without this, mounting we will hit the
BUG_ON(offset >= folio_size(folio));
in folio_set_bh on the first __bread_gfp call.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260511071701.2456211-8-hch@lst.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/isofs/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/isofs/inode.c b/fs/isofs/inode.c
index e3052d3fe5dcd..8fd91f09086f1 100644
--- a/fs/isofs/inode.c
+++ b/fs/isofs/inode.c
@@ -859,7 +859,8 @@ static int isofs_fill_super(struct super_block *s, void *data, int silent)
* entries. By forcing the blocksize in this way, we ensure
* that we will never be required to do this.
*/
- sb_set_blocksize(s, orig_zonesize);
+ if (!sb_set_blocksize(s, orig_zonesize))
+ goto out_freesbi;
sbi->s_nls_iocharset = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 075/982] HID: bpf: Add Huion Inspiroy Frego M button quirk
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 074/982] isofs: " Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 076/982] usbip: vhci_hcd: fix NULL deref in status_show_vhci Greg Kroah-Hartman
` (913 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikhil Chatterjee,
Benjamin Tissoires, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikhil Chatterjee <nikhilc1527@gmail.com>
[ Upstream commit 857e71cb0a538b1660743a4267a1e789575f7966 ]
The Huion Inspiroy Frego M pen report descriptor exposes the second
side button as Secondary Tip Switch instead of Secondary Barrel Switch.
This makes userspace see the control as the wrong pen button.
Add a HID-BPF report descriptor fixup for the Bluetooth 256c:8251
device and USB 256c:2012 L610 variant. The fixup matches the expected
pen descriptor and rewrites the offending usage from Secondary Tip
Switch to Secondary Barrel Switch.
Tested by building the HID-BPF object with:
make -C drivers/hid/bpf/progs Huion__Inspiroy-Frego-M.bpf.o
Signed-off-by: Nikhil Chatterjee <nikhilc1527@gmail.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../bpf/progs/Huion__Inspiroy-Frego-M.bpf.c | 87 +++++++++++++++++++
1 file changed, 87 insertions(+)
create mode 100644 drivers/hid/bpf/progs/Huion__Inspiroy-Frego-M.bpf.c
diff --git a/drivers/hid/bpf/progs/Huion__Inspiroy-Frego-M.bpf.c b/drivers/hid/bpf/progs/Huion__Inspiroy-Frego-M.bpf.c
new file mode 100644
index 0000000000000..e6ba2295dc775
--- /dev/null
+++ b/drivers/hid/bpf/progs/Huion__Inspiroy-Frego-M.bpf.c
@@ -0,0 +1,87 @@
+// SPDX-License-Identifier: GPL-2.0-only
+#include "vmlinux.h"
+#include "hid_bpf.h"
+#include "hid_bpf_helpers.h"
+#include <bpf/bpf_tracing.h>
+
+/*
+ * Huion Inspiroy Frego M Pen Tablet
+ * Model L610
+ * 256c:8251 (Bluetooth)
+ * 256c:2012 (USB)
+ */
+#define VID_HUION 0x256C
+#define PID_INSPIROY_FREGO_M 0x8251
+#define PID_L610 0x2012
+
+#define PEN_RDESC_SIZE 125
+#define SECONDARY_SWITCH_OFFSET 17
+
+HID_BPF_CONFIG(
+ HID_DEVICE(BUS_BLUETOOTH, HID_GROUP_GENERIC, VID_HUION, PID_INSPIROY_FREGO_M),
+ HID_DEVICE(BUS_USB, HID_GROUP_GENERIC, VID_HUION, PID_L610)
+);
+
+/*
+ * The pen descriptor reports the second side button as Secondary Tip Switch
+ * instead of Secondary Barrel Switch.
+ *
+ * Relevant part of the original pen report descriptor:
+ *
+ * 0x09, 0x42, // Usage (Tip Switch) 12
+ * 0x09, 0x44, // Usage (Barrel Switch) 14
+ * 0x09, 0x43, // Usage (Secondary Tip Switch) 16 <- change to 0x5a
+ * 0x09, 0x3c, // Usage (Invert) 18
+ * 0x09, 0x45, // Usage (Eraser) 20
+ * 0x15, 0x00, // Logical Minimum (0) 22
+ * 0x25, 0x01, // Logical Maximum (1) 24
+ */
+SEC(HID_BPF_RDESC_FIXUP)
+int BPF_PROG(fix_secondary_barrel_rdesc, struct hid_bpf_ctx *hctx)
+{
+ __u8 *data = hid_bpf_get_data(hctx, 0 /* offset */, HID_MAX_DESCRIPTOR_SIZE /* size */);
+
+ if (!data)
+ return 0; /* EPERM check */
+
+ if (hctx->size != PEN_RDESC_SIZE)
+ return 0;
+
+ if (data[0] != 0x05 || data[1] != 0x0d || /* Usage Page (Digitizers) */
+ data[2] != 0x09 || data[3] != 0x02 || /* Usage (Pen) */
+ data[16] != 0x09 ||
+ data[SECONDARY_SWITCH_OFFSET] != 0x43) /* Secondary Tip Switch */
+ return 0;
+
+ data[SECONDARY_SWITCH_OFFSET] = 0x5a;
+
+ return 0;
+}
+
+HID_BPF_OPS(fix_secondary_barrel) = {
+ .hid_rdesc_fixup = (void *)fix_secondary_barrel_rdesc,
+};
+
+SEC("syscall")
+int probe(struct hid_bpf_probe_args *ctx)
+{
+ ctx->retval = ctx->rdesc_size != PEN_RDESC_SIZE;
+ if (ctx->retval) {
+ ctx->retval = -EINVAL;
+ return 0;
+ }
+
+ if (ctx->rdesc[0] != 0x05 || ctx->rdesc[1] != 0x0d || /* Usage Page (Digitizers) */
+ ctx->rdesc[2] != 0x09 || ctx->rdesc[3] != 0x02 || /* Usage (Pen) */
+ ctx->rdesc[16] != 0x09 ||
+ ctx->rdesc[SECONDARY_SWITCH_OFFSET] != 0x43) { /* Secondary Tip Switch */
+ ctx->retval = -EINVAL;
+ return 0;
+ }
+
+ ctx->retval = 0;
+
+ return 0;
+}
+
+char _license[] SEC("license") = "GPL";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 076/982] usbip: vhci_hcd: fix NULL deref in status_show_vhci
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 075/982] HID: bpf: Add Huion Inspiroy Frego M button quirk Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 077/982] usb: core: hcd: fix possible deadlock in rh control transfers Greg Kroah-Hartman
` (912 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Adrian Wowk, Shuah Khan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Wowk <dev@adrianwowk.com>
[ Upstream commit bc150783542ba2e7c1257d1299c6f3269bdba270 ]
platform_get_drvdata() can return NULL if a VHCI host controller's
probe failed (e.g. due to USB bus number exhaustion). status_show_vhci()
checked for a NULL pdev but not for a NULL hcd returned by
platform_get_drvdata(). Passing NULL to hcd_to_vhci_hcd() does not
return NULL - it returns a pointer offset of 0x260, causing a NULL
pointer dereference when that value is subsequently dereferenced.
Add a NULL check on hcd before calling hcd_to_vhci_hcd(). Move
status_show_not_ready() above status_show_vhci() to make it callable
from the new error path without a forward declaration.
Signed-off-by: Adrian Wowk <dev@adrianwowk.com>
Reviewed-by: Shuah Khan <skhan@linuxfoundation.org>
Link: https://patch.msgid.link/20260414010050.158064-2-dev@adrianwowk.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/usbip/vhci_sysfs.c | 52 +++++++++++++++++++---------------
1 file changed, 29 insertions(+), 23 deletions(-)
diff --git a/drivers/usb/usbip/vhci_sysfs.c b/drivers/usb/usbip/vhci_sysfs.c
index e2847cd3e6e36..7dd6465ee4358 100644
--- a/drivers/usb/usbip/vhci_sysfs.c
+++ b/drivers/usb/usbip/vhci_sysfs.c
@@ -59,6 +59,29 @@ static void port_show_vhci(char **out, int hub, int port, struct vhci_device *vd
*out += sprintf(*out, "\n");
}
+static ssize_t status_show_not_ready(int pdev_nr, char *out)
+{
+ char *s = out;
+ int i = 0;
+
+ for (i = 0; i < VHCI_HC_PORTS; i++) {
+ out += sprintf(out, "hs %04u %03u ",
+ (pdev_nr * VHCI_PORTS) + i,
+ VDEV_ST_NOTASSIGNED);
+ out += sprintf(out, "000 00000000 0000000000000000 0-0");
+ out += sprintf(out, "\n");
+ }
+
+ for (i = 0; i < VHCI_HC_PORTS; i++) {
+ out += sprintf(out, "ss %04u %03u ",
+ (pdev_nr * VHCI_PORTS) + VHCI_HC_PORTS + i,
+ VDEV_ST_NOTASSIGNED);
+ out += sprintf(out, "000 00000000 0000000000000000 0-0");
+ out += sprintf(out, "\n");
+ }
+ return out - s;
+}
+
/* Sysfs entry to show port status */
static ssize_t status_show_vhci(int pdev_nr, char *out)
{
@@ -76,6 +99,12 @@ static ssize_t status_show_vhci(int pdev_nr, char *out)
}
hcd = platform_get_drvdata(pdev);
+
+ if (!hcd) {
+ usbip_dbg_vhci_sysfs("show status error (hcd is NULL)\n");
+ return status_show_not_ready(pdev_nr, out);
+ }
+
vhci_hcd = hcd_to_vhci_hcd(hcd);
vhci = vhci_hcd->vhci;
@@ -104,29 +133,6 @@ static ssize_t status_show_vhci(int pdev_nr, char *out)
return out - s;
}
-static ssize_t status_show_not_ready(int pdev_nr, char *out)
-{
- char *s = out;
- int i = 0;
-
- for (i = 0; i < VHCI_HC_PORTS; i++) {
- out += sprintf(out, "hs %04u %03u ",
- (pdev_nr * VHCI_PORTS) + i,
- VDEV_ST_NOTASSIGNED);
- out += sprintf(out, "000 00000000 0000000000000000 0-0");
- out += sprintf(out, "\n");
- }
-
- for (i = 0; i < VHCI_HC_PORTS; i++) {
- out += sprintf(out, "ss %04u %03u ",
- (pdev_nr * VHCI_PORTS) + VHCI_HC_PORTS + i,
- VDEV_ST_NOTASSIGNED);
- out += sprintf(out, "000 00000000 0000000000000000 0-0");
- out += sprintf(out, "\n");
- }
- return out - s;
-}
-
static int status_name_to_id(const char *name)
{
char *c;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 077/982] usb: core: hcd: fix possible deadlock in rh control transfers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 076/982] usbip: vhci_hcd: fix NULL deref in status_show_vhci Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 078/982] usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log Greg Kroah-Hartman
` (911 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Oliver Neukum, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oliver Neukum <oneukum@suse.com>
[ Upstream commit d5559f43d76b398392b26a15cbc16d731969cd1c ]
>From within the SCSI error handler memory allocations must not
trigger IO. Handling errors in UAS and the storage driver may
involve resetting a device. The thread doing the reset itself
relies on VM magic. However, that is insufficient, as resetting
a device involves resuming it. Resumption as well as resetting
involves conrol transfers to the parent of the device to be reset.
That may be a root hub. Hence usbcore must heed the flags passed
to usb_submit_urb() processing control transfers to root hubs.
The problem exist since the storage driver has been merged.
Signed-off-by: Oliver Neukum <oneukum@suse.com>
Link: https://patch.msgid.link/20260429094413.181038-1-oneukum@suse.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/core/hcd.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
diff --git a/drivers/usb/core/hcd.c b/drivers/usb/core/hcd.c
index 980e09f793a6a..f0a637dab11f9 100644
--- a/drivers/usb/core/hcd.c
+++ b/drivers/usb/core/hcd.c
@@ -473,7 +473,8 @@ rh_string(int id, struct usb_hcd const *hcd, u8 *data, unsigned len)
/* Root hub control transfers execute synchronously */
-static int rh_call_control (struct usb_hcd *hcd, struct urb *urb)
+static int rh_call_control(struct usb_hcd *hcd,
+ struct urb *urb, gfp_t mem_flags)
{
struct usb_ctrlrequest *cmd;
u16 typeReq, wValue, wIndex, wLength;
@@ -508,8 +509,8 @@ static int rh_call_control (struct usb_hcd *hcd, struct urb *urb)
* tbuf should be at least as big as the
* USB hub descriptor.
*/
- tbuf_size = max_t(u16, sizeof(struct usb_hub_descriptor), wLength);
- tbuf = kzalloc(tbuf_size, GFP_KERNEL);
+ tbuf_size = max_t(u16, sizeof(struct usb_hub_descriptor), wLength);
+ tbuf = kzalloc(tbuf_size, mem_flags);
if (!tbuf) {
status = -ENOMEM;
goto err_alloc;
@@ -838,12 +839,13 @@ static int rh_queue_status (struct usb_hcd *hcd, struct urb *urb)
return retval;
}
-static int rh_urb_enqueue (struct usb_hcd *hcd, struct urb *urb)
+static int rh_urb_enqueue(struct usb_hcd *hcd,
+ struct urb *urb, gfp_t mem_flags)
{
if (usb_endpoint_xfer_int(&urb->ep->desc))
return rh_queue_status (hcd, urb);
if (usb_endpoint_xfer_control(&urb->ep->desc))
- return rh_call_control (hcd, urb);
+ return rh_call_control(hcd, urb, mem_flags);
return -EINVAL;
}
@@ -1551,7 +1553,7 @@ int usb_hcd_submit_urb (struct urb *urb, gfp_t mem_flags)
*/
if (is_root_hub(urb->dev)) {
- status = rh_urb_enqueue(hcd, urb);
+ status = rh_urb_enqueue(hcd, urb, mem_flags);
} else {
status = map_urb_for_dma(hcd, urb, mem_flags);
if (likely(status == 0)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 078/982] usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 077/982] usb: core: hcd: fix possible deadlock in rh control transfers Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 079/982] USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set Greg Kroah-Hartman
` (910 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Stepan Ionichev, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stepan Ionichev <sozdayvek@gmail.com>
[ Upstream commit 5bf5e3fba9bc7dfd69701521dbe9809f8ccbdb02 ]
goku_irq() handles a number of bus events under a single ep0 path.
It already guards the gadget driver suspend/resume callbacks against a
NULL ->driver:
if (dev->gadget.speed != USB_SPEED_UNKNOWN
&& dev->driver
&& dev->driver->resume) {
spin_unlock(&dev->lock);
dev->driver->resume(&dev->gadget);
...
}
but the very next branch unconditionally dereferences dev->driver
when an INT_USBRESET arrives:
if (stat & INT_USBRESET) {
ACK(INT_USBRESET);
INFO(dev, "USB reset done, gadget %s\n",
dev->driver->driver.name);
}
If the controller raises INT_USBRESET before any gadget driver has
been bound (or after one has been unbound), dev->driver is NULL and
the printk dereferences NULL.
smatch flags the inconsistency:
drivers/usb/gadget/udc/goku_udc.c:1618 goku_irq() error:
we previously assumed 'dev->driver' could be null (see line 1607)
Fall back to a placeholder when the gadget driver is not bound.
No functional change while a gadget driver is bound.
Signed-off-by: Stepan Ionichev <sozdayvek@gmail.com>
Link: https://patch.msgid.link/20260509110636.19762-1-sozdayvek@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/udc/goku_udc.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/usb/gadget/udc/goku_udc.c b/drivers/usb/gadget/udc/goku_udc.c
index 5ffb3d5c635be..f9b094b04847e 100644
--- a/drivers/usb/gadget/udc/goku_udc.c
+++ b/drivers/usb/gadget/udc/goku_udc.c
@@ -1616,7 +1616,8 @@ static irqreturn_t goku_irq(int irq, void *_dev)
if (stat & INT_USBRESET) { /* hub reset done */
ACK(INT_USBRESET);
INFO(dev, "USB reset done, gadget %s\n",
- dev->driver->driver.name);
+ dev->driver ? dev->driver->driver.name :
+ "<not bound>");
}
// and INT_ERR on some endpoint's crc/bitstuff/... problem
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 079/982] USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 078/982] usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 080/982] usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue Greg Kroah-Hartman
` (909 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dave Carey, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Carey <carvsdriver@gmail.com>
[ Upstream commit e5ab27ddd74e2d67a94c51c6f2ad87b1ff13912b ]
The INGENIC 17EF:6161 touchscreen composite device has a ~55-second
watchdog that resets the USB device if the bulk-IN endpoint on the CDC
data interface goes unread. The existing ALWAYS_POLL_CTRL quirk keeps
the notification endpoint (ctrlurb / EP 0x82) polling continuously, but
that alone is insufficient: the firmware monitors bulk-IN activity, not
just notification-endpoint activity.
Add acm_submit_read_urbs() calls to the two ALWAYS_POLL_CTRL paths that
already restart the ctrlurb:
1. acm_probe(): start bulk reads at probe time alongside the ctrlurb,
so the watchdog is satisfied from first bind without requiring a
userspace process to open /dev/ttyACMn.
2. acm_port_shutdown(): restart bulk reads after port close alongside
the ctrlurb restart, so the watchdog keeps running when the last
TTY user closes the port.
acm_read_bulk_callback() already resubmits each URB unconditionally on
normal completion, so once submitted the reads remain active until an
explicit kill (disconnect, suspend). acm_submit_read_urb() is a no-op
for URBs that are already in flight (read_urbs_free bit clear), so the
existing acm_port_activate() call remains correct and races are avoided.
Tested on Lenovo Yoga Book 9 14IAH10 (83KJ): without this patch the
device resets every ~55 s when no TTY is open; with it the device
remains stable indefinitely.
Signed-off-by: Dave Carey <carvsdriver@gmail.com>
Link: https://patch.msgid.link/20260515141940.751397-1-carvsdriver@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/class/cdc-acm.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c
index d1c8f620596d8..9ff5feceadad4 100644
--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -786,6 +786,9 @@ static void acm_port_shutdown(struct tty_port *port)
"ctrl polling restart failed after port close\n");
/* port_shutdown() cleared DTR/RTS; restore them */
acm_set_control(acm, USB_CDC_CTRL_DTR | USB_CDC_CTRL_RTS);
+ if (acm_submit_read_urbs(acm, GFP_KERNEL))
+ dev_dbg(&acm->control->dev,
+ "read urb restart failed after port close\n");
}
}
@@ -1539,6 +1542,9 @@ static int acm_probe(struct usb_interface *intf,
if (usb_submit_urb(acm->ctrlurb, GFP_KERNEL))
dev_warn(&intf->dev,
"failed to start persistent ctrl polling\n");
+ if (acm_submit_read_urbs(acm, GFP_KERNEL))
+ dev_warn(&intf->dev,
+ "failed to start persistent bulk read polling\n");
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 080/982] usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 079/982] USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 081/982] serial: 8250: fix possible ISR soft lockup Greg Kroah-Hartman
` (908 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alan Stern, Andrew Jeffery,
Maoyi Xie, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
[ Upstream commit e2ffaac1884b921b8ec2b3a964c6a8b5d610bf4b ]
ast_udc_ep_dequeue() declares the loop cursor `req` outside the
list_for_each_entry(). After the loop it tests `&req->req != _req`
to decide whether the request was found. If the queue holds no
match, `req` is past-the-end. It then aliases
container_of(&ep->queue, struct ast_udc_request, queue) via offset
cancellation. Whether that synthetic address equals `_req` depends
on heap layout. The function can return 0 without dequeueing
anything.
Default `rc` to -EINVAL and set it to 0 only inside the match
branch. `req` is no longer read after the loop, so the past-the-end
dereference goes away. No extra cursor variable or post-loop test
is needed.
Suggested-by: Alan Stern <stern@rowland.harvard.edu>
Suggested-by: Andrew Jeffery <andrew@codeconstruct.com.au>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://patch.msgid.link/20260521065428.3261238-1-maoyixie.tju@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/udc/aspeed_udc.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/usb/gadget/udc/aspeed_udc.c b/drivers/usb/gadget/udc/aspeed_udc.c
index d2944648d3d9c..2d8e22dc4861b 100644
--- a/drivers/usb/gadget/udc/aspeed_udc.c
+++ b/drivers/usb/gadget/udc/aspeed_udc.c
@@ -694,7 +694,7 @@ static int ast_udc_ep_dequeue(struct usb_ep *_ep, struct usb_request *_req)
struct ast_udc_dev *udc = ep->udc;
struct ast_udc_request *req;
unsigned long flags;
- int rc = 0;
+ int rc = -EINVAL;
spin_lock_irqsave(&udc->lock, flags);
@@ -704,14 +704,11 @@ static int ast_udc_ep_dequeue(struct usb_ep *_ep, struct usb_request *_req)
list_del_init(&req->queue);
ast_udc_done(ep, req, -ESHUTDOWN);
_req->status = -ECONNRESET;
+ rc = 0;
break;
}
}
- /* dequeue request not found */
- if (&req->req != _req)
- rc = -EINVAL;
-
spin_unlock_irqrestore(&udc->lock, flags);
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 081/982] serial: 8250: fix possible ISR soft lockup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 080/982] usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 082/982] usb: host: add ARCH_AIROHA in XHCI MTK dependency Greg Kroah-Hartman
` (907 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Marco Felsch, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Felsch <m.felsch@pengutronix.de>
[ Upstream commit 0c6bf45e5a345cc3b9ffbeaf9083ecac3c2293eb ]
There are rare cases in which the host gets stuck in the ISR because it
is flooded with messages during the startup phase.
The reason for the soft lockup in the ISR is the missing FIFO error IRQ
(FIFOE) handling. Not handling it and reporting IRQ_HANDLED triggers
the IRQ immediately again.
Fix this by adding a check for the FIFOE status and clearing the FIFO
if no data is ready (DR).
This behavior was observed on an AM62L device which uses the OMAP 8250
driver. Fix it for all 8250 drivers, since the OMAP driver's special
IRQ setup handling may trigger this behavior more frequently, but it
is not ensured that other 8250 drivers aren't affected.
Signed-off-by: Marco Felsch <m.felsch@pengutronix.de>
Link: https://patch.msgid.link/20260519-v7-1-topic-serial-8250-v1-1-56b04293a246@pengutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/8250/8250_port.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/tty/serial/8250/8250_port.c b/drivers/tty/serial/8250/8250_port.c
index a1fce56100254..fbb65cb6a0cc9 100644
--- a/drivers/tty/serial/8250/8250_port.c
+++ b/drivers/tty/serial/8250/8250_port.c
@@ -1933,6 +1933,13 @@ int serial8250_handle_irq(struct uart_port *port, unsigned int iir)
status = serial_lsr_in(up);
+ /*
+ * Recover from no-data-ready and FIFO error condition to avoid getting
+ * stuck in the ISR.
+ */
+ if (!(status & UART_LSR_DR) && (status & UART_LSR_FIFOE))
+ serial8250_clear_and_reinit_fifos(up);
+
/*
* If port is stopped and there are no error conditions in the
* FIFO, then don't drain the FIFO, as this may lead to TTY buffer
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 082/982] usb: host: add ARCH_AIROHA in XHCI MTK dependency
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 081/982] serial: 8250: fix possible ISR soft lockup Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 083/982] char/nvram: Remove redundant nvram_mutex Greg Kroah-Hartman
` (906 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Marangi, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Marangi <ansuelsmth@gmail.com>
[ Upstream commit ffeaf31f05d664581aa436d9cb92b4d1d8d301ce ]
Airoha SoC use the same register map and logic of the Mediatek xHCI
driver, hence add it to the dependency list to permit compilation also
on this ARCH.
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
Link: https://patch.msgid.link/20260519164903.31258-1-ansuelsmth@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/host/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/usb/host/Kconfig b/drivers/usb/host/Kconfig
index 247568bc17a2b..9878adf8ae5e2 100644
--- a/drivers/usb/host/Kconfig
+++ b/drivers/usb/host/Kconfig
@@ -72,7 +72,7 @@ config USB_XHCI_HISTB
config USB_XHCI_MTK
tristate "xHCI support for MediaTek SoCs"
select MFD_SYSCON
- depends on (MIPS && SOC_MT7621) || ARCH_MEDIATEK || COMPILE_TEST
+ depends on (MIPS && SOC_MT7621) || ARCH_MEDIATEK || ARCH_AIROHA || COMPILE_TEST
help
Say 'Y' to enable the support for the xHCI host controller
found in MediaTek SoCs.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 083/982] char/nvram: Remove redundant nvram_mutex
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 082/982] usb: host: add ARCH_AIROHA in XHCI MTK dependency Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 084/982] wifi: rtw89: pci: enable LTR based on pcie control register Greg Kroah-Hartman
` (905 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann,
Tellakula Yeswanth Krishna, Venkat Rao Bagalkote,
Ritesh Harjani (IBM), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
[ Upstream commit e8c715f3a7dae43fabae261493a26474fec11863 ]
The global nvram_mutex in drivers/char/nvram.c is redundant and unused,
and this triggers compiler warnings on some configurations.
All platform-specific nvram operations already provide their own internal
synchronization, meaning the wrapper-level mutex does not provide any
additional safety.
Remove the nvram_mutex definition along with all remaining lock/unlock
users across PPC32, x86, and m68k code paths, and rely entirely on the
per-architecture nvram implementations for locking.
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Suggested-by: Arnd Bergmann <arnd@arndb.de>
Tested-by: Tellakula Yeswanth Krishna <yeswanth@linux.ibm.com>
Signed-off-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
Tested-by: yeswanth <yeswanth@linux.ibm.com>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Link: https://patch.msgid.link/20260428061540.73668-1-venkat88@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/nvram.c | 16 +++-------------
1 file changed, 3 insertions(+), 13 deletions(-)
diff --git a/drivers/char/nvram.c b/drivers/char/nvram.c
index e9f694b368719..bd7510abdc076 100644
--- a/drivers/char/nvram.c
+++ b/drivers/char/nvram.c
@@ -53,7 +53,6 @@
#include <asm/nvram.h>
#endif
-static DEFINE_MUTEX(nvram_mutex);
static DEFINE_SPINLOCK(nvram_state_lock);
static int nvram_open_cnt; /* #times opened */
static int nvram_open_mode; /* special open modes */
@@ -310,11 +309,8 @@ static long nvram_misc_ioctl(struct file *file, unsigned int cmd,
break;
#ifdef CONFIG_PPC32
case IOC_NVRAM_SYNC:
- if (ppc_md.nvram_sync != NULL) {
- mutex_lock(&nvram_mutex);
+ if (ppc_md.nvram_sync)
ppc_md.nvram_sync();
- mutex_unlock(&nvram_mutex);
- }
ret = 0;
break;
#endif
@@ -324,11 +320,8 @@ static long nvram_misc_ioctl(struct file *file, unsigned int cmd,
if (!capable(CAP_SYS_ADMIN))
return -EACCES;
- if (arch_nvram_ops.initialize != NULL) {
- mutex_lock(&nvram_mutex);
+ if (arch_nvram_ops.initialize)
ret = arch_nvram_ops.initialize();
- mutex_unlock(&nvram_mutex);
- }
break;
case NVRAM_SETCKS:
/* just set checksum, contents unchanged (maybe useful after
@@ -336,11 +329,8 @@ static long nvram_misc_ioctl(struct file *file, unsigned int cmd,
if (!capable(CAP_SYS_ADMIN))
return -EACCES;
- if (arch_nvram_ops.set_checksum != NULL) {
- mutex_lock(&nvram_mutex);
+ if (arch_nvram_ops.set_checksum)
ret = arch_nvram_ops.set_checksum();
- mutex_unlock(&nvram_mutex);
- }
break;
#endif /* CONFIG_X86 || CONFIG_M68K */
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 084/982] wifi: rtw89: pci: enable LTR based on pcie control register
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 083/982] char/nvram: Remove redundant nvram_mutex Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 085/982] netlabel: fix IPv6 unlabeled address add error handling Greg Kroah-Hartman
` (904 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dian-Syuan Yang, Ping-Ke Shih,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dian-Syuan Yang <dian_syuan0116@realtek.com>
[ Upstream commit 779bbe1902f29d0ef131249ddd42a8dfbe21d0fb ]
Originally, driver always transmits LTR (Latency Tolerance Reporting) to
pcie host, but it may cause pcie link down on some platforms because
LTR is not supported. As a result, driver will check the control
register of LTR setting to decide whether to enable LTR feature.
This applies to Wi-Fi 6 chips only. For Wi-Fi 7 chips, although the
driver still issues LTR, the hardware has its own internal logic
to determine whether to actually transmit it to pcie host.
Signed-off-by: Dian-Syuan Yang <dian_syuan0116@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260515014433.16168-5-pkshih@realtek.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/pci.c | 16 +++++++++++++++-
1 file changed, 15 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw89/pci.c b/drivers/net/wireless/realtek/rtw89/pci.c
index cc553ca287d62..ac76697dc4627 100644
--- a/drivers/net/wireless/realtek/rtw89/pci.c
+++ b/drivers/net/wireless/realtek/rtw89/pci.c
@@ -2432,6 +2432,17 @@ static int rtw89_pci_mode_op(struct rtw89_dev *rtwdev)
return 0;
}
+static bool rtw89_pci_dev_ltr_enabled(struct rtw89_dev *rtwdev)
+{
+ struct rtw89_pci *rtwpci = (struct rtw89_pci *)rtwdev->priv;
+ struct pci_dev *pdev = rtwpci->pdev;
+ u16 cap;
+
+ pcie_capability_read_word(pdev, PCI_EXP_DEVCTL2, &cap);
+
+ return !!(cap & PCI_EXP_DEVCTL2_LTR_EN);
+}
+
static int rtw89_pci_ops_deinit(struct rtw89_dev *rtwdev)
{
const struct rtw89_pci_info *info = rtwdev->pci_info;
@@ -2526,7 +2537,7 @@ int rtw89_pci_ltr_set(struct rtw89_dev *rtwdev, bool en)
{
u32 val;
- if (!en)
+ if (!en || !rtw89_pci_dev_ltr_enabled(rtwdev))
return 0;
val = rtw89_read32(rtwdev, R_AX_LTR_CTRL_0);
@@ -2562,6 +2573,9 @@ int rtw89_pci_ltr_set_v1(struct rtw89_dev *rtwdev, bool en)
u32 dec_ctrl;
u32 val32;
+ if (!rtw89_pci_dev_ltr_enabled(rtwdev))
+ return 0;
+
val32 = rtw89_read32(rtwdev, R_AX_LTR_CTRL_0);
if (rtw89_pci_ltr_is_err_reg_val(val32))
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 085/982] netlabel: fix IPv6 unlabeled address add error handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 084/982] wifi: rtw89: pci: enable LTR based on pcie control register Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 086/982] rds: filter RDS_INFO_* getsockopt by callers netns Greg Kroah-Hartman
` (903 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chenguang Zhao, Paul Moore,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chenguang Zhao <zhaochenguang@kylinos.cn>
[ Upstream commit 56872b930feee7ae07b9720ca950dd9fa65596ee ]
netlbl_unlhsh_add_addr6() always returned zero after
netlbl_af6list_add(), masking failures such as duplicate
IPv6 static label entries.
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Acked-by: Paul Moore <paul@paul-moore.com>
Link: https://patch.msgid.link/20260522022910.398416-1-zhaochenguang@kylinos.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netlabel/netlabel_unlabeled.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netlabel/netlabel_unlabeled.c b/net/netlabel/netlabel_unlabeled.c
index 6007cb000da67..c9684ddc2395d 100644
--- a/net/netlabel/netlabel_unlabeled.c
+++ b/net/netlabel/netlabel_unlabeled.c
@@ -295,7 +295,7 @@ static int netlbl_unlhsh_add_addr6(struct netlbl_unlhsh_iface *iface,
if (ret_val != 0)
kfree(entry);
- return 0;
+ return ret_val;
}
#endif /* IPv6 */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 086/982] rds: filter RDS_INFO_* getsockopt by callers netns
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 085/982] netlabel: fix IPv6 unlabeled address add error handling Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 087/982] rds: annotate data-race around rs_seen_congestion Greg Kroah-Hartman
` (902 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Simon Horman,
Praveen Kakkolangara, Maoyi Xie, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
[ Upstream commit c96a5209dda666004b8ee1ed7f0d493d09a4f200 ]
The RDS_INFO_* family of getsockopt(2) options reads several
file-scope global lists that are not per-netns:
rds_sock_info / rds6_sock_info,
rds_sock_inc_info / rds6_sock_inc_info -> rds_sock_list
rds_tcp_tc_info / rds6_tcp_tc_info -> rds_tcp_tc_list
rds_conn_info / rds6_conn_info,
rds_conn_message_info_cmn (for the *_SEND_MESSAGES and
*_RETRANS_MESSAGES variants),
rds_for_each_conn_info (for RDS_INFO_IB_CONNECTIONS)
-> rds_conn_hash[]
The handlers do not filter by the caller's network namespace.
rds_info_getsockopt() has no netns or capable() check, and
rds_create() has no capable() check, so AF_RDS is reachable from
an unprivileged user namespace. As a result, an unprivileged
caller in a fresh user_ns plus netns can read the bound address
and sock inode of every RDS socket on the host, the peer address
of incoming messages on every RDS socket on the host, the peer
address and TCP sequence numbers of every rds-tcp connection on
the host, and the peer address and RDS sequence numbers of every
RDS connection on the host.
The rds-tcp transport is reachable from a non-initial netns (see
rds_set_transport()), so a one-shot init_net gate at
rds_info_getsockopt() would deny legitimate per-netns visibility
to rds-tcp callers. Instead, filter at each handler by comparing
the netns of the caller's socket to the netns of the list entry,
or to rds_conn_net(conn) for connection paths. Only copy entries
whose netns matches the caller. Counters (RDS_INFO_COUNTERS) are
aggregate statistics and remain global.
Reproducer (KASAN VM, rds and rds_tcp loaded): an AF_RDS socket
binds 127.0.0.1:4242 in init_net as root. A child process enters
a fresh user_ns plus netns and opens AF_RDS there, then calls
getsockopt(SOL_RDS, RDS_INFO_SOCKETS). Before this change, the
child sees the init_net socket. After this change, the child
sees zero entries.
Drop the rds_sock_count, rds_tcp_tc_count, and rds6_tcp_tc_count
globals. v2 used them for the size precheck and lens->nr; v3
replaced the precheck with a per-ns count from a first pass over
the list, so the globals have no remaining readers. The matching
increments and decrements in rds_create()/rds_destroy_sock() and
rds_tcp_set_callbacks()/rds_tcp_restore_callbacks() go away with
them. Reported by the kernel test robot under clang W=1.
Suggested-by: Allison Henderson <achender@kernel.org>
Suggested-by: Simon Horman <horms@kernel.org>
Reviewed-by: Allison Henderson <achender@kernel.org>
Co-developed-by: Praveen Kakkolangara <praveen.kakkolangara@aumovio.com>
Signed-off-by: Praveen Kakkolangara <praveen.kakkolangara@aumovio.com>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://patch.msgid.link/20260520084236.2724349-1-maoyixie.tju@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/af_rds.c | 59 ++++++++++++++++++++++++++++++++++-------
net/rds/connection.c | 13 +++++++++
net/rds/tcp.c | 63 ++++++++++++++++++++++++++++----------------
3 files changed, 104 insertions(+), 31 deletions(-)
diff --git a/net/rds/af_rds.c b/net/rds/af_rds.c
index 752ae3fbc2e7a..a8004e8a78175 100644
--- a/net/rds/af_rds.c
+++ b/net/rds/af_rds.c
@@ -43,7 +43,6 @@
/* this is just used for stats gathering :/ */
static DEFINE_SPINLOCK(rds_sock_lock);
-static unsigned long rds_sock_count;
static LIST_HEAD(rds_sock_list);
DECLARE_WAIT_QUEUE_HEAD(rds_poll_waitq);
@@ -82,7 +81,6 @@ static int rds_release(struct socket *sock)
spin_lock_bh(&rds_sock_lock);
list_del_init(&rs->rs_item);
- rds_sock_count--;
spin_unlock_bh(&rds_sock_lock);
rds_trans_put(rs->rs_transport);
@@ -695,7 +693,6 @@ static int __rds_create(struct socket *sock, struct sock *sk, int protocol)
spin_lock_bh(&rds_sock_lock);
list_add_tail(&rs->rs_item, &rds_sock_list);
- rds_sock_count++;
spin_unlock_bh(&rds_sock_lock);
return 0;
@@ -736,6 +733,7 @@ static void rds_sock_inc_info(struct socket *sock, unsigned int len,
struct rds_info_iterator *iter,
struct rds_info_lengths *lens)
{
+ struct net *net = sock_net(sock->sk);
struct rds_sock *rs;
struct rds_incoming *inc;
unsigned int total = 0;
@@ -745,6 +743,9 @@ static void rds_sock_inc_info(struct socket *sock, unsigned int len,
spin_lock_bh(&rds_sock_lock);
list_for_each_entry(rs, &rds_sock_list, rs_item) {
+ /* Only show sockets in the caller's netns. */
+ if (!net_eq(sock_net(rds_rs_to_sk(rs)), net))
+ continue;
/* This option only supports IPv4 sockets. */
if (!ipv6_addr_v4mapped(&rs->rs_bound_addr))
continue;
@@ -775,6 +776,7 @@ static void rds6_sock_inc_info(struct socket *sock, unsigned int len,
struct rds_info_iterator *iter,
struct rds_info_lengths *lens)
{
+ struct net *net = sock_net(sock->sk);
struct rds_incoming *inc;
unsigned int total = 0;
struct rds_sock *rs;
@@ -784,6 +786,9 @@ static void rds6_sock_inc_info(struct socket *sock, unsigned int len,
spin_lock_bh(&rds_sock_lock);
list_for_each_entry(rs, &rds_sock_list, rs_item) {
+ /* Only show sockets in the caller's netns. */
+ if (!net_eq(sock_net(rds_rs_to_sk(rs)), net))
+ continue;
read_lock(&rs->rs_recv_lock);
list_for_each_entry(inc, &rs->rs_recv_queue, i_item) {
@@ -807,7 +812,9 @@ static void rds_sock_info(struct socket *sock, unsigned int len,
struct rds_info_iterator *iter,
struct rds_info_lengths *lens)
{
+ struct net *net = sock_net(sock->sk);
struct rds_info_socket sinfo;
+ unsigned int copied = 0;
unsigned int cnt = 0;
struct rds_sock *rs;
@@ -815,12 +822,24 @@ static void rds_sock_info(struct socket *sock, unsigned int len,
spin_lock_bh(&rds_sock_lock);
- if (len < rds_sock_count) {
- cnt = rds_sock_count;
- goto out;
+ /* First pass: count entries visible in the caller's netns. */
+ list_for_each_entry(rs, &rds_sock_list, rs_item) {
+ if (!net_eq(sock_net(rds_rs_to_sk(rs)), net))
+ continue;
+ if (!ipv6_addr_v4mapped(&rs->rs_bound_addr))
+ continue;
+ cnt++;
}
+ if (len < cnt)
+ goto out;
+
list_for_each_entry(rs, &rds_sock_list, rs_item) {
+ if (copied >= cnt)
+ break;
+ /* Only show sockets in the caller's netns. */
+ if (!net_eq(sock_net(rds_rs_to_sk(rs)), net))
+ continue;
/* This option only supports IPv4 sockets. */
if (!ipv6_addr_v4mapped(&rs->rs_bound_addr))
continue;
@@ -833,8 +852,13 @@ static void rds_sock_info(struct socket *sock, unsigned int len,
sinfo.inum = sock_i_ino(rds_rs_to_sk(rs));
rds_info_copy(iter, &sinfo, sizeof(sinfo));
- cnt++;
+ copied++;
}
+ /* A concurrent rds_bind() can change rs_bound_addr between the
+ * two passes without holding rds_sock_lock, so copied may be
+ * less than cnt. Report what was actually copied.
+ */
+ cnt = copied;
out:
lens->nr = cnt;
@@ -848,17 +872,32 @@ static void rds6_sock_info(struct socket *sock, unsigned int len,
struct rds_info_iterator *iter,
struct rds_info_lengths *lens)
{
+ struct net *net = sock_net(sock->sk);
struct rds6_info_socket sinfo6;
+ unsigned int copied = 0;
+ unsigned int cnt = 0;
struct rds_sock *rs;
len /= sizeof(struct rds6_info_socket);
spin_lock_bh(&rds_sock_lock);
- if (len < rds_sock_count)
+ /* First pass: count entries visible in the caller's netns. */
+ list_for_each_entry(rs, &rds_sock_list, rs_item) {
+ if (!net_eq(sock_net(rds_rs_to_sk(rs)), net))
+ continue;
+ cnt++;
+ }
+
+ if (len < cnt)
goto out;
list_for_each_entry(rs, &rds_sock_list, rs_item) {
+ if (copied >= cnt)
+ break;
+ /* Only show sockets in the caller's netns. */
+ if (!net_eq(sock_net(rds_rs_to_sk(rs)), net))
+ continue;
sinfo6.sndbuf = rds_sk_sndbuf(rs);
sinfo6.rcvbuf = rds_sk_rcvbuf(rs);
sinfo6.bound_addr = rs->rs_bound_addr;
@@ -868,10 +907,12 @@ static void rds6_sock_info(struct socket *sock, unsigned int len,
sinfo6.inum = sock_i_ino(rds_rs_to_sk(rs));
rds_info_copy(iter, &sinfo6, sizeof(sinfo6));
+ copied++;
}
+ cnt = copied;
out:
- lens->nr = rds_sock_count;
+ lens->nr = cnt;
lens->each = sizeof(struct rds6_info_socket);
spin_unlock_bh(&rds_sock_lock);
diff --git a/net/rds/connection.c b/net/rds/connection.c
index cd41f83863c89..beecd408e93ab 100644
--- a/net/rds/connection.c
+++ b/net/rds/connection.c
@@ -540,6 +540,7 @@ static void rds_conn_message_info_cmn(struct socket *sock, unsigned int len,
struct rds_info_lengths *lens,
int want_send, bool isv6)
{
+ struct net *net = sock_net(sock->sk);
struct hlist_head *head;
struct list_head *list;
struct rds_connection *conn;
@@ -562,6 +563,9 @@ static void rds_conn_message_info_cmn(struct socket *sock, unsigned int len,
struct rds_conn_path *cp;
int npaths;
+ /* Only show connections in the caller's netns. */
+ if (!net_eq(rds_conn_net(conn), net))
+ continue;
if (!isv6 && conn->c_isv6)
continue;
@@ -660,6 +664,7 @@ void rds_for_each_conn_info(struct socket *sock, unsigned int len,
u64 *buffer,
size_t item_len)
{
+ struct net *net = sock_net(sock->sk);
struct hlist_head *head;
struct rds_connection *conn;
size_t i;
@@ -672,6 +677,9 @@ void rds_for_each_conn_info(struct socket *sock, unsigned int len,
for (i = 0, head = rds_conn_hash; i < ARRAY_SIZE(rds_conn_hash);
i++, head++) {
hlist_for_each_entry_rcu(conn, head, c_hash_node) {
+ /* Only show connections in the caller's netns. */
+ if (!net_eq(rds_conn_net(conn), net))
+ continue;
/* Zero the per-item buffer before handing it to the
* visitor so any field the visitor does not write -
@@ -705,6 +713,7 @@ static void rds_walk_conn_path_info(struct socket *sock, unsigned int len,
u64 *buffer,
size_t item_len)
{
+ struct net *net = sock_net(sock->sk);
struct hlist_head *head;
struct rds_connection *conn;
size_t i;
@@ -719,6 +728,10 @@ static void rds_walk_conn_path_info(struct socket *sock, unsigned int len,
hlist_for_each_entry_rcu(conn, head, c_hash_node) {
struct rds_conn_path *cp;
+ /* Only show connections in the caller's netns. */
+ if (!net_eq(rds_conn_net(conn), net))
+ continue;
+
/* XXX We only copy the information from the first
* path for now. The problem is that if there are
* more than one underlying paths, we cannot report
diff --git a/net/rds/tcp.c b/net/rds/tcp.c
index 323fa5ed5c3ea..74ad2b5abb3ab 100644
--- a/net/rds/tcp.c
+++ b/net/rds/tcp.c
@@ -46,14 +46,6 @@
static DEFINE_SPINLOCK(rds_tcp_tc_list_lock);
static LIST_HEAD(rds_tcp_tc_list);
-/* rds_tcp_tc_count counts only IPv4 connections.
- * rds6_tcp_tc_count counts both IPv4 and IPv6 connections.
- */
-static unsigned int rds_tcp_tc_count;
-#if IS_ENABLED(CONFIG_IPV6)
-static unsigned int rds6_tcp_tc_count;
-#endif
-
/* Track rds_tcp_connection structs so they can be cleaned up */
static DEFINE_SPINLOCK(rds_tcp_conn_lock);
static LIST_HEAD(rds_tcp_conn_list);
@@ -109,11 +101,6 @@ void rds_tcp_restore_callbacks(struct socket *sock,
/* done under the callback_lock to serialize with write_space */
spin_lock(&rds_tcp_tc_list_lock);
list_del_init(&tc->t_list_item);
-#if IS_ENABLED(CONFIG_IPV6)
- rds6_tcp_tc_count--;
-#endif
- if (!tc->t_cpath->cp_conn->c_isv6)
- rds_tcp_tc_count--;
spin_unlock(&rds_tcp_tc_list_lock);
tc->t_sock = NULL;
@@ -200,11 +187,6 @@ void rds_tcp_set_callbacks(struct socket *sock, struct rds_conn_path *cp)
/* done under the callback_lock to serialize with write_space */
spin_lock(&rds_tcp_tc_list_lock);
list_add_tail(&tc->t_list_item, &rds_tcp_tc_list);
-#if IS_ENABLED(CONFIG_IPV6)
- rds6_tcp_tc_count++;
-#endif
- if (!tc->t_cpath->cp_conn->c_isv6)
- rds_tcp_tc_count++;
spin_unlock(&rds_tcp_tc_list_lock);
/* accepted sockets need our listen data ready undone */
@@ -232,20 +214,37 @@ static void rds_tcp_tc_info(struct socket *rds_sock, unsigned int len,
struct rds_info_iterator *iter,
struct rds_info_lengths *lens)
{
+ struct net *net = sock_net(rds_sock->sk);
struct rds_info_tcp_socket tsinfo;
struct rds_tcp_connection *tc;
+ unsigned int copied = 0;
+ unsigned int cnt = 0;
unsigned long flags;
spin_lock_irqsave(&rds_tcp_tc_list_lock, flags);
- if (len / sizeof(tsinfo) < rds_tcp_tc_count)
+ /* First pass: count entries visible in the caller's netns. */
+ list_for_each_entry(tc, &rds_tcp_tc_list, t_list_item) {
+ if (tc->t_cpath->cp_conn->c_isv6)
+ continue;
+ if (!net_eq(rds_conn_net(tc->t_cpath->cp_conn), net))
+ continue;
+ cnt++;
+ }
+
+ if (len / sizeof(tsinfo) < cnt)
goto out;
list_for_each_entry(tc, &rds_tcp_tc_list, t_list_item) {
struct inet_sock *inet = inet_sk(tc->t_sock->sk);
+ if (copied >= cnt)
+ break;
if (tc->t_cpath->cp_conn->c_isv6)
continue;
+ /* Only show connections in the caller's netns. */
+ if (!net_eq(rds_conn_net(tc->t_cpath->cp_conn), net))
+ continue;
tsinfo.local_addr = inet->inet_saddr;
tsinfo.local_port = inet->inet_sport;
@@ -260,10 +259,12 @@ static void rds_tcp_tc_info(struct socket *rds_sock, unsigned int len,
tsinfo.tos = tc->t_cpath->cp_conn->c_tos;
rds_info_copy(iter, &tsinfo, sizeof(tsinfo));
+ copied++;
}
+ cnt = copied;
out:
- lens->nr = rds_tcp_tc_count;
+ lens->nr = cnt;
lens->each = sizeof(tsinfo);
spin_unlock_irqrestore(&rds_tcp_tc_list_lock, flags);
@@ -278,19 +279,35 @@ static void rds6_tcp_tc_info(struct socket *sock, unsigned int len,
struct rds_info_iterator *iter,
struct rds_info_lengths *lens)
{
+ struct net *net = sock_net(sock->sk);
struct rds6_info_tcp_socket tsinfo6;
struct rds_tcp_connection *tc;
+ unsigned int copied = 0;
+ unsigned int cnt = 0;
unsigned long flags;
spin_lock_irqsave(&rds_tcp_tc_list_lock, flags);
- if (len / sizeof(tsinfo6) < rds6_tcp_tc_count)
+ /* First pass: count entries visible in the caller's netns. */
+ list_for_each_entry(tc, &rds_tcp_tc_list, t_list_item) {
+ if (!net_eq(rds_conn_net(tc->t_cpath->cp_conn), net))
+ continue;
+ cnt++;
+ }
+
+ if (len / sizeof(tsinfo6) < cnt)
goto out;
list_for_each_entry(tc, &rds_tcp_tc_list, t_list_item) {
struct sock *sk = tc->t_sock->sk;
struct inet_sock *inet = inet_sk(sk);
+ if (copied >= cnt)
+ break;
+ /* Only show connections in the caller's netns. */
+ if (!net_eq(rds_conn_net(tc->t_cpath->cp_conn), net))
+ continue;
+
tsinfo6.local_addr = sk->sk_v6_rcv_saddr;
tsinfo6.local_port = inet->inet_sport;
tsinfo6.peer_addr = sk->sk_v6_daddr;
@@ -303,10 +320,12 @@ static void rds6_tcp_tc_info(struct socket *sock, unsigned int len,
tsinfo6.last_seen_una = tc->t_last_seen_una;
rds_info_copy(iter, &tsinfo6, sizeof(tsinfo6));
+ copied++;
}
+ cnt = copied;
out:
- lens->nr = rds6_tcp_tc_count;
+ lens->nr = cnt;
lens->each = sizeof(tsinfo6);
spin_unlock_irqrestore(&rds_tcp_tc_list_lock, flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 087/982] rds: annotate data-race around rs_seen_congestion
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 086/982] rds: filter RDS_INFO_* getsockopt by callers netns Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 088/982] s390/zcore: Removed unused variables Greg Kroah-Hartman
` (901 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+fbf3648ae7f5bdb05c59,
Jiayuan Chen, Allison Henderson, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 67636cab273ed0c0b0f2adab6c9369a471cb7966 ]
rs_seen_congestion is read in rds_poll() and written in rds_sendmsg()
and rds_poll() without any lock. Use READ_ONCE()/WRITE_ONCE() to
annotate these lockless accesses and silence KCSAN.
Reported-by: syzbot+fbf3648ae7f5bdb05c59@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a0f8d94.050a0220.6b33c.0000.GAE@google.com/
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Allison Henderson <achender@kernel.org>
Tested-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260522011621.304470-1-jiayuan.chen@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/af_rds.c | 4 ++--
net/rds/send.c | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/rds/af_rds.c b/net/rds/af_rds.c
index a8004e8a78175..b166ac1f599e6 100644
--- a/net/rds/af_rds.c
+++ b/net/rds/af_rds.c
@@ -217,7 +217,7 @@ static __poll_t rds_poll(struct file *file, struct socket *sock,
poll_wait(file, sk_sleep(sk), wait);
- if (rs->rs_seen_congestion)
+ if (READ_ONCE(rs->rs_seen_congestion))
poll_wait(file, &rds_poll_waitq, wait);
read_lock_irqsave(&rs->rs_recv_lock, flags);
@@ -245,7 +245,7 @@ static __poll_t rds_poll(struct file *file, struct socket *sock,
/* clear state any time we wake a seen-congested socket */
if (mask)
- rs->rs_seen_congestion = 0;
+ WRITE_ONCE(rs->rs_seen_congestion, 0);
return mask;
}
diff --git a/net/rds/send.c b/net/rds/send.c
index 8aa06f7e4640c..2cedcb837b8f3 100644
--- a/net/rds/send.c
+++ b/net/rds/send.c
@@ -1340,7 +1340,7 @@ int rds_sendmsg(struct socket *sock, struct msghdr *msg, size_t payload_len)
ret = rds_cong_wait(conn->c_fcong, dport, nonblock, rs);
if (ret) {
- rs->rs_seen_congestion = 1;
+ WRITE_ONCE(rs->rs_seen_congestion, 1);
goto out;
}
while (!rds_send_queue_rm(rs, conn, cpath, rm, rs->rs_bound_port,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 088/982] s390/zcore: Removed unused variables
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 087/982] rds: annotate data-race around rs_seen_congestion Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 089/982] clk: socfpga: agilex: implement l3_main_free_clk Greg Kroah-Hartman
` (900 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Heiko Carstens, Alexander Gordeev, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heiko Carstens <hca@linux.ibm.com>
[ Upstream commit 0a2aa995c0a1d363b5f0803862e84834e3876ae2 ]
allmodconfig with clang W=1 points out unused global variables:
drivers/s390/char/zcore.c:49:23: error: variable
'zcore_reipl_file' set but not used [-Werror,-Wunused-but-set-global]
drivers/s390/char/zcore.c:50:23: error: variable
'zcore_hsa_file' set but not used [-Werror,-Wunused-but-set-global]
Remove both of them, since there is no point in keeping them.
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Alexander Gordeev <agordeev@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/char/zcore.c | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
diff --git a/drivers/s390/char/zcore.c b/drivers/s390/char/zcore.c
index a41833557d550..166c0b04fe713 100644
--- a/drivers/s390/char/zcore.c
+++ b/drivers/s390/char/zcore.c
@@ -48,8 +48,6 @@ struct ipib_info {
static struct debug_info *zcore_dbf;
static int hsa_available;
static struct dentry *zcore_dir;
-static struct dentry *zcore_reipl_file;
-static struct dentry *zcore_hsa_file;
static struct ipl_parameter_block *zcore_ipl_block;
static DEFINE_MUTEX(hsa_buf_mutex);
@@ -314,10 +312,8 @@ static int __init zcore_init(void)
goto fail;
zcore_dir = debugfs_create_dir("zcore" , NULL);
- zcore_reipl_file = debugfs_create_file("reipl", S_IRUSR, zcore_dir,
- NULL, &zcore_reipl_fops);
- zcore_hsa_file = debugfs_create_file("hsa", S_IRUSR|S_IWUSR, zcore_dir,
- NULL, &zcore_hsa_fops);
+ debugfs_create_file("reipl", S_IRUSR, zcore_dir, NULL, &zcore_reipl_fops);
+ debugfs_create_file("hsa", S_IRUSR|S_IWUSR, zcore_dir, NULL, &zcore_hsa_fops);
register_reboot_notifier(&zcore_reboot_notifier);
atomic_notifier_chain_register(&panic_notifier_list, &zcore_on_panic_notifier);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 089/982] clk: socfpga: agilex: implement l3_main_free_clk
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 088/982] s390/zcore: Removed unused variables Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 090/982] thermal/drivers/tegra/soctherma: Switch to devm cooling device registration Greg Kroah-Hartman
` (899 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Ng Ho Yin, Dinh Nguyen,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Ng Ho Yin <adrian.ho.yin.ng@altera.com>
[ Upstream commit 1e7f56205813a2c48cdb3e9a4b0a24f49fd9a548 ]
The AGILEX_L3_MAIN_FREE_CLK is defined in the dt-bindings header but
was never implemented in the clock driver. Per the Agilex TRM,
l3_main_free_clk has no divider or mux and is a fixed 1:1 derivative
of noc_free_clk that clocks most of the interconnect datapath.
Signed-off-by: Adrian Ng Ho Yin <adrian.ho.yin.ng@altera.com>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/socfpga/clk-agilex.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/clk/socfpga/clk-agilex.c b/drivers/clk/socfpga/clk-agilex.c
index 74d21bd82710e..2408f9f33312f 100644
--- a/drivers/clk/socfpga/clk-agilex.c
+++ b/drivers/clk/socfpga/clk-agilex.c
@@ -260,6 +260,8 @@ static const struct stratix10_perip_cnt_clock agilex_main_perip_cnt_clks[] = {
0, 0x3C, 0, 0, 0},
{ AGILEX_NOC_FREE_CLK, "noc_free_clk", NULL, noc_free_mux, ARRAY_SIZE(noc_free_mux),
0, 0x40, 0, 0, 0},
+ { AGILEX_L3_MAIN_FREE_CLK, "l3_main_free_clk", "noc_free_clk", NULL,
+ 1, 0, 0, 1, 0, 0},
{ AGILEX_L4_SYS_FREE_CLK, "l4_sys_free_clk", NULL, noc_mux, ARRAY_SIZE(noc_mux), 0,
0, 4, 0x30, 1},
{ AGILEX_EMAC_A_FREE_CLK, "emaca_free_clk", NULL, emaca_free_mux, ARRAY_SIZE(emaca_free_mux),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 090/982] thermal/drivers/tegra/soctherma: Switch to devm cooling device registration
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 089/982] clk: socfpga: agilex: implement l3_main_free_clk Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 091/982] drm/panel: simple: Add AM-1280800W8TZQW-T00H Greg Kroah-Hartman
` (898 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Lezcano, Daniel Lezcano,
Lukasz Luba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Lezcano <daniel.lezcano@oss.qualcomm.com>
[ Upstream commit ee126267bc04bfb03816ae9d71ca24c5bf99e739 ]
Use devm_thermal_of_cooling_device_register() to simplify resource
management and avoid manual cleanup in error paths.
As a side effect this change has the benefit of solving an existing
issue. Before, the function tegra_soctherm_remove() only called
debugfs_remove_recursive() and never called thermal_cooling_device_unregister()
for any of the cooling devices registered here.
After the driver removal, the thermal framework's cdev list would
still hold references to thermal_cooling_device objects whose devdata
pointer (ts) pointed to memory already freed by the platform device's
devm cleanup.
With this change, the cooling device is unregistered when the driver
is removed, thus fixing the issue above.
Signed-off-by: Daniel Lezcano <daniel.lezcano@oss.qualcomm.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Reviewed-by: Lukasz Luba <lukasz.luba@arm.com>
Link: https://patch.msgid.link/20260424160019.41710-2-daniel.lezcano@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/tegra/soctherm.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/thermal/tegra/soctherm.c b/drivers/thermal/tegra/soctherm.c
index 1efe470f31e9a..0af9958073ffb 100644
--- a/drivers/thermal/tegra/soctherm.c
+++ b/drivers/thermal/tegra/soctherm.c
@@ -1704,9 +1704,9 @@ static void soctherm_init_hw_throt_cdev(struct platform_device *pdev)
stc->init = true;
} else {
- tcd = thermal_of_cooling_device_register(np_stcc,
- (char *)name, ts,
- &throt_cooling_ops);
+ tcd = devm_thermal_of_cooling_device_register(dev, np_stcc,
+ (char *)name, ts,
+ &throt_cooling_ops);
if (IS_ERR_OR_NULL(tcd)) {
dev_err(dev,
"throttle-cfg: %s: failed to register cooling device\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 091/982] drm/panel: simple: Add AM-1280800W8TZQW-T00H
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 090/982] thermal/drivers/tegra/soctherma: Switch to devm cooling device registration Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 092/982] mips: cps: Assemble jr.hb with an R2 ISA level Greg Kroah-Hartman
` (897 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Trimarchi, Dario Binacchi,
Dmitry Baryshkov, Neil Armstrong, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dario Binacchi <dario.binacchi@amarulasolutions.com>
[ Upstream commit 6acb810ebc5d8dea5c250326c14dc44e32dc8e92 ]
Add Ampire, AM-1280800W8TZQW-T00H 10.1" TFT LCD panel timings.
Co-developed-by: Michael Trimarchi <michael@amarulasolutions.com>
Signed-off-by: Michael Trimarchi <michael@amarulasolutions.com>
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260515082232.1766586-2-dario.binacchi@amarulasolutions.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/panel/panel-simple.c | 28 ++++++++++++++++++++++++++++
1 file changed, 28 insertions(+)
diff --git a/drivers/gpu/drm/panel/panel-simple.c b/drivers/gpu/drm/panel/panel-simple.c
index 316961a86b042..f7787d6c97fe3 100644
--- a/drivers/gpu/drm/panel/panel-simple.c
+++ b/drivers/gpu/drm/panel/panel-simple.c
@@ -741,6 +741,31 @@ static const struct panel_desc ampire_am_1280800n3tzqw_t00h = {
.connector_type = DRM_MODE_CONNECTOR_LVDS,
};
+static const struct drm_display_mode ampire_am_1280800w8tzqw_t00h_mode = {
+ .clock = 72400,
+ .hdisplay = 1280,
+ .hsync_start = 1280 + 40,
+ .hsync_end = 1280 + 40 + 80,
+ .htotal = 1280 + 40 + 80 + 40,
+ .vdisplay = 800,
+ .vsync_start = 800 + 10,
+ .vsync_end = 800 + 10 + 18,
+ .vtotal = 800 + 10 + 18 + 10,
+};
+
+static const struct panel_desc ampire_am_1280800w8tzqw_t00h = {
+ .modes = &ire_am_1280800w8tzqw_t00h_mode,
+ .num_modes = 1,
+ .bpc = 8,
+ .size = {
+ .width = 217,
+ .height = 136,
+ },
+ .bus_flags = DRM_BUS_FLAG_DE_HIGH,
+ .bus_format = MEDIA_BUS_FMT_RGB888_1X7X4_SPWG,
+ .connector_type = DRM_MODE_CONNECTOR_LVDS,
+};
+
static const struct drm_display_mode ampire_am_480272h3tmqw_t01h_mode = {
.clock = 9000,
.hdisplay = 480,
@@ -3965,6 +3990,9 @@ static const struct of_device_id platform_of_match[] = {
{
.compatible = "ampire,am-1280800n3tzqw-t00h",
.data = &ire_am_1280800n3tzqw_t00h,
+ }, {
+ .compatible = "ampire,am-1280800w8tzqw-t00h",
+ .data = &ire_am_1280800w8tzqw_t00h,
}, {
.compatible = "ampire,am-480272h3tmqw-t01h",
.data = &ire_am_480272h3tmqw_t01h,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 092/982] mips: cps: Assemble jr.hb with an R2 ISA level
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 091/982] drm/panel: simple: Add AM-1280800W8TZQW-T00H Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 093/982] iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind Greg Kroah-Hartman
` (896 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev, Maciej W. Rozycki,
Thomas Bogendoerfer, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit e5d64f868e484da06f5c141c18c32c01c269625e ]
A MIPS allmodconfig built with LLVM can select CPU_MIPS32_R1 together
with MIPS_MT_SMP. In that configuration clang invokes the integrated
assembler with -march=mips32, and the MIPS MT path in cps-vec.S fails
to assemble two jr.hb instructions:
arch/mips/kernel/cps-vec.S:376:2: error: instruction requires
a CPU feature not currently enabled
arch/mips/kernel/cps-vec.S:490:4: error: instruction requires
a CPU feature not currently enabled
The earlier jr.hb in the same file is already assembled inside a .set
MIPS_ISA_LEVEL_RAW scope. The two failing sites are reached after
popping back to the file's base ISA level, so LLVM correctly rejects
them for an R1 target.
Wrap those jr.hb instructions in the same ISA-level push/pop used by
the working site. This keeps the MT code unchanged while making the
required R2 hazard-branch encoding explicit to the assembler.
Assisted-by: Codex:GPT-5.5
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Maciej W. Rozycki <macro@orcam.me.uk>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/kernel/cps-vec.S | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/arch/mips/kernel/cps-vec.S b/arch/mips/kernel/cps-vec.S
index 9753432401487..156abad9c3249 100644
--- a/arch/mips/kernel/cps-vec.S
+++ b/arch/mips/kernel/cps-vec.S
@@ -394,8 +394,11 @@ LEAF(mips_cps_boot_vpes)
.set pop
PTR_LA t1, 1f
+ .set push
+ .set MIPS_ISA_LEVEL_RAW
jr.hb t1
nop
+ .set pop
1: mfc0 t1, CP0_MVPCONTROL
ori t1, t1, MVPCONTROL_VPC
mtc0 t1, CP0_MVPCONTROL
@@ -508,8 +511,11 @@ LEAF(mips_cps_boot_vpes)
li t0, TCHALT_H
mtc0 t0, CP0_TCHALT
PTR_LA t0, 1f
+ .set push
+ .set MIPS_ISA_LEVEL_RAW
1: jr.hb t0
nop
+ .set pop
2:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 093/982] iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 092/982] mips: cps: Assemble jr.hb with an R2 ISA level Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 094/982] irqchip/gic-v4: Dont advertise VLPIs if no ITS is probed Greg Kroah-Hartman
` (895 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stepan Ionichev, Jonathan Cameron,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stepan Ionichev <sozdayvek@gmail.com>
[ Upstream commit 929fec2964f71d4b1ac664ee963d8226c5cf01c6 ]
iadc_probe() calls enable_irq_wake() after a successful
devm_request_irq(), but the driver has no remove callback or
matching disable_irq_wake(), so the wake reference count on the
IRQ is leaked on module unload or driver unbind.
Check the IRQ request error first, then register a devm action
that calls disable_irq_wake() so the wake reference is released
in the same scope as the enable. While here, drop the inverted
"if (!ret) ... else return ret" in favour of the standard
"if (ret) return ret;" pattern.
Signed-off-by: Stepan Ionichev <sozdayvek@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/adc/qcom-spmi-iadc.c | 18 +++++++++++++++---
1 file changed, 15 insertions(+), 3 deletions(-)
diff --git a/drivers/iio/adc/qcom-spmi-iadc.c b/drivers/iio/adc/qcom-spmi-iadc.c
index acbda6636dc58..c57c50aeeffd7 100644
--- a/drivers/iio/adc/qcom-spmi-iadc.c
+++ b/drivers/iio/adc/qcom-spmi-iadc.c
@@ -482,6 +482,11 @@ static const struct iio_chan_spec iadc_channels[] = {
},
};
+static void iadc_disable_irq_wake(void *data)
+{
+ disable_irq_wake((unsigned long)data);
+}
+
static int iadc_probe(struct platform_device *pdev)
{
struct device_node *node = pdev->dev.of_node;
@@ -539,9 +544,16 @@ static int iadc_probe(struct platform_device *pdev)
if (!iadc->poll_eoc) {
ret = devm_request_irq(dev, irq_eoc, iadc_isr, 0,
"spmi-iadc", iadc);
- if (!ret)
- enable_irq_wake(irq_eoc);
- else
+ if (ret)
+ return ret;
+
+ ret = enable_irq_wake(irq_eoc);
+ if (ret)
+ return ret;
+
+ ret = devm_add_action_or_reset(dev, iadc_disable_irq_wake,
+ (void *)(unsigned long)irq_eoc);
+ if (ret)
return ret;
} else {
device_init_wakeup(iadc->dev, 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 094/982] irqchip/gic-v4: Dont advertise VLPIs if no ITS is probed
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 093/982] iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 095/982] ALSA: usb-audio: Add quirk for Novation Mininova Greg Kroah-Hartman
` (894 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marc Zyngier, Mostafa Saleh,
Thomas Gleixner, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mostafa Saleh <smostafa@google.com>
[ Upstream commit e61654fbc3bc5d07ec9fafe29f33e19b2b5d0fd5 ]
When accidentally setting “kvm-arm.vgic_v4_enable=1” on a system that has
no MSI controller device tree node and GICv4, it results a panic as
“gic_domain” is NULL and the kernel attempts to access it.
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000028
Mem abort info:
ESR = 0x0000000096000006
CPU: 1 UID: 0 PID: 295 Comm: lkvm-static Not tainted 7.1.0-rc4-ge3f15ad3970e #5 PREEMPT
Hardware name: linux,dummy-virt (DT)
pstate: 81402005 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
pc : __irq_domain_instantiate+0x1d4/0x578
lr : __irq_domain_instantiate+0x1cc/0x578
Set vLPI support to false at init time if the host has no ITS, so it
propagates properly to kvm_vgic_global_state.has_gicv4.
Suggested-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Mostafa Saleh <smostafa@google.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Acked-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260526125317.3672297-1-smostafa@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/irqchip/irq-gic-v3-its.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
index 84b00e14860eb..105b8e24905ed 100644
--- a/drivers/irqchip/irq-gic-v3-its.c
+++ b/drivers/irqchip/irq-gic-v3-its.c
@@ -5583,6 +5583,7 @@ int __init its_init(struct fwnode_handle *handle, struct rdists *rdists,
its_acpi_probe();
if (list_empty(&its_nodes)) {
+ rdists->has_vlpis = false;
pr_warn("ITS: No ITS available, not enabling LPIs\n");
return -ENXIO;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 095/982] ALSA: usb-audio: Add quirk for Novation Mininova
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 094/982] irqchip/gic-v4: Dont advertise VLPIs if no ITS is probed Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 096/982] net: hsr: require valid EOT supervision TLV Greg Kroah-Hartman
` (893 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Uwe Küchler, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uwe Küchler <uwe@kuechler.org>
[ Upstream commit b2e9d2cbbb71b00faf3e27fb741a27b9ad455edd ]
Add a device-specific quirk for the Novation Mininova synthesizer
(USB ID 1235:001e) to enable proper recognition and functionality
as a MIDI device.
Signed-off-by: Uwe Küchler <uwe@kuechler.org>
Link: https://patch.msgid.link/20260526162033.7513-1-uwe@kuechler.org
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/quirks-table.h | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/sound/usb/quirks-table.h b/sound/usb/quirks-table.h
index d1bd8e0d60252..c20a4df886906 100644
--- a/sound/usb/quirks-table.h
+++ b/sound/usb/quirks-table.h
@@ -2131,6 +2131,14 @@ YAMAHA_DEVICE(0x7010, "UB99"),
}
}
},
+{
+ USB_DEVICE(0x1235, 0x001e),
+ QUIRK_DRIVER_INFO {
+ /* .vendor_name = "Novation", */
+ /* .product_name = "Mininova", */
+ QUIRK_DATA_RAW_BYTES(0)
+ }
+},
{
USB_DEVICE_VENDOR_SPEC(0x1235, 0x4661),
QUIRK_DRIVER_INFO {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 096/982] net: hsr: require valid EOT supervision TLV
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 095/982] ALSA: usb-audio: Add quirk for Novation Mininova Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 097/982] ipv6: addrconf: fix temp address generation after prefix deprecation Greg Kroah-Hartman
` (892 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luka Gejak,
Fernando Fernandez Mancera, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luka Gejak <luka.gejak@linux.dev>
[ Upstream commit 46d111a3ef3b5972804dcdce0833767143a12192 ]
Supervision frames are only valid if terminated with a zero-length EOT
TLV. The current check fails to reject non-EOT entries as the terminal
TLV, potentially allowing malformed supervision traffic.
Fix this by strictly requiring the terminal TLV to be HSR_TLV_EOT with
a length of zero.
Signed-off-by: Luka Gejak <luka.gejak@linux.dev>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Link: https://patch.msgid.link/20260523130420.62144-1-luka.gejak@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/hsr/hsr_forward.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/hsr/hsr_forward.c b/net/hsr/hsr_forward.c
index 2a6df958292c8..c66728d7d285e 100644
--- a/net/hsr/hsr_forward.c
+++ b/net/hsr/hsr_forward.c
@@ -110,7 +110,7 @@ static bool is_supervision_frame(struct hsr_priv *hsr, struct sk_buff *skb)
}
/* end of tlvs must follow at the end */
- if (hsr_sup_tlv->HSR_TLV_type == HSR_TLV_EOT &&
+ if (hsr_sup_tlv->HSR_TLV_type != HSR_TLV_EOT ||
hsr_sup_tlv->HSR_TLV_length != 0)
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 097/982] ipv6: addrconf: fix temp address generation after prefix deprecation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 096/982] net: hsr: require valid EOT supervision TLV Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 098/982] net: thunderx: fix PTP device ref leak in nicvf_probe() Greg Kroah-Hartman
` (891 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Łukasz Stelmach, Ido Schimmel,
Fernando Fernandez Mancera, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fernando Fernandez Mancera <fmancera@suse.de>
[ Upstream commit e20d8922aa8fe441d291364c96c2179a005b79ea ]
When a router temporarily deprecates an IPv6 prefix (either by sending a
Router Advertisement with Preferred Lifetime = 0 or by letting the
lifetime expire) and later restores it, the kernel permanently loses its
ability to generate temporary privacy addresses (RFC 8981) for that
prefix.
This happens because the address worker attempts to generate a
replacement temporary address when the current one nears expiration. As
the base prefix is deprecated already, the generation fails after
marking the temporary address as already having spawned a replacement
(ifp->regen_count++).
When the router eventually restores the prefix, the temporary address
becomes active again. However, once it naturally expires, the address
worker sees this temporary address already tried to generate one and
skips the regeneration.
Fix the issue by resetting the regen_count check of the latest temp
address generated for the prefix updated by the incoming RA.
Reported-by: Łukasz Stelmach <steelman@post.pl>
Closes: https://lore.kernel.org/netdev/87340td30q.fsf%25steelman@post.pl/
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260523103811.3790-1-fmancera@suse.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/addrconf.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index 9fe1f67ceacd4..849ed409f74fc 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -1169,6 +1169,7 @@ ipv6_add_addr(struct inet6_dev *idev, struct ifa6_config *cfg,
ipv6_link_dev_addr(idev, ifa);
if (ifa->flags&IFA_F_TEMPORARY) {
+ /* manage_tempaddrs() relies on addresses being added to the head */
list_add(&ifa->tmp_list, &idev->tempaddr_list);
in6_ifa_hold(ifa);
}
@@ -2556,8 +2557,10 @@ static void manage_tempaddrs(struct inet6_dev *idev,
__u32 valid_lft, __u32 prefered_lft,
bool create, unsigned long now)
{
- u32 flags;
+ u32 orig_prefered_lft = prefered_lft;
struct inet6_ifaddr *ift;
+ bool reset_done = false;
+ u32 flags;
read_lock_bh(&idev->lock);
/* update all temporary addresses in the list */
@@ -2592,6 +2595,11 @@ static void manage_tempaddrs(struct inet6_dev *idev,
prefered_lft = max_prefered;
spin_lock(&ift->lock);
+ /* the first match is the most recent temp address */
+ if (!reset_done && orig_prefered_lft > 0) {
+ ift->regen_count = 0;
+ reset_done = true;
+ }
flags = ift->flags;
ift->valid_lft = valid_lft;
ift->prefered_lft = prefered_lft;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 098/982] net: thunderx: fix PTP device ref leak in nicvf_probe()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 097/982] ipv6: addrconf: fix temp address generation after prefix deprecation Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 099/982] drm/amd/pm/si: Fix updating clock limits from power states Greg Kroah-Hartman
` (890 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haoxiang Li <lihaoxiang@isrc.iscas.ac.cn>
[ Upstream commit 2bcf59eefb9f00a2b1d426b639ee49c305a80695 ]
cavium_ptp_get() acquires a reference to the PTP PCI device
through pci_get_device(). If any initialization step fails
after cavium_ptp_get(), the PTP PCI device reference is leaked.
Add a common error path to release the PTP reference before
returning from probe failures.
Signed-off-by: Haoxiang Li <lihaoxiang@isrc.iscas.ac.cn>
Link: https://patch.msgid.link/20260525082611.61817-1-lihaoxiang@isrc.iscas.ac.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cavium/thunder/nicvf_main.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/cavium/thunder/nicvf_main.c b/drivers/net/ethernet/cavium/thunder/nicvf_main.c
index f2f95493ec89a..1c04ebaa705c0 100644
--- a/drivers/net/ethernet/cavium/thunder/nicvf_main.c
+++ b/drivers/net/ethernet/cavium/thunder/nicvf_main.c
@@ -2110,8 +2110,10 @@ static int nicvf_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
}
err = pci_enable_device(pdev);
- if (err)
- return dev_err_probe(dev, err, "Failed to enable PCI device\n");
+ if (err) {
+ err = dev_err_probe(dev, err, "Failed to enable PCI device\n");
+ goto err_put_ptp;
+ }
err = pci_request_regions(pdev, DRV_NAME);
if (err) {
@@ -2261,6 +2263,8 @@ static int nicvf_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
pci_release_regions(pdev);
err_disable_device:
pci_disable_device(pdev);
+err_put_ptp:
+ cavium_ptp_put(ptp_clock);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 099/982] drm/amd/pm/si: Fix updating clock limits from power states
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 098/982] net: thunderx: fix PTP device ref leak in nicvf_probe() Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 100/982] ACPICA: Fix condition check in acpi_ps_parse_loop() Greg Kroah-Hartman
` (889 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Deucher, Timur Kristóf,
Jeremy Klarenbeek, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeremy Klarenbeek <jeremy.klarenbeek99@gmail.com>
[ Upstream commit e6c5d36756e7d4d260e2365fc4d01226f1973152 ]
VBIOS can contain conflicting values between:
- the maximum allowed clocks and voltages on AC or DC
- the clocks and voltages in power states on AC or DC
Update maximum clock (and voltage) limits for both AC/DC
and take the highest value from the VBIOS limits and
the performance/battery power states. Previously this
was only done for AC, but is also needed for DC.
This commit fixes the behaviour on some laptop GPUs,
where the VBIOS limit was set to the lowest possible
clock frequency, so the GPU was stuck on the lowest
possible power level on battery.
Some affected GPUs are:
FirePro W4170M (Dell Precision M2800)
Radeon HD 8790M (Dell Latitude E6540)
and possibly other laptop GPUs.
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Co-developed-by: Timur Kristóf <timur.kristof@gmail.com>
Signed-off-by: Timur Kristóf <timur.kristof@gmail.com>
Signed-off-by: Jeremy Klarenbeek <jeremy.klarenbeek99@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c | 29 ++++++++++++++++++----
1 file changed, 24 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c b/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c
index a28bcff24254b..f71585ae68498 100644
--- a/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c
+++ b/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c
@@ -7218,6 +7218,7 @@ static void si_parse_pplib_clock_info(struct amdgpu_device *adev,
struct evergreen_power_info *eg_pi = evergreen_get_pi(adev);
struct si_power_info *si_pi = si_get_pi(adev);
struct si_ps *ps = si_get_ps(rps);
+ struct amdgpu_clock_and_voltage_limits *limits;
u16 leakage_voltage;
struct rv7xx_pl *pl = &ps->performance_levels[index];
int ret;
@@ -7277,12 +7278,30 @@ static void si_parse_pplib_clock_info(struct amdgpu_device *adev,
si_pi->mvdd_bootup_value = mvdd;
}
+ /*
+ * Update maximum allowed clock limits.
+ * VBIOS can contain conflicting values between:
+ * - the maximum allowed clocks and voltages on AC or DC
+ * - the clocks and voltages in power states on AC or DC
+ */
if ((rps->class & ATOM_PPLIB_CLASSIFICATION_UI_MASK) ==
- ATOM_PPLIB_CLASSIFICATION_UI_PERFORMANCE) {
- adev->pm.dpm.dyn_state.max_clock_voltage_on_ac.sclk = pl->sclk;
- adev->pm.dpm.dyn_state.max_clock_voltage_on_ac.mclk = pl->mclk;
- adev->pm.dpm.dyn_state.max_clock_voltage_on_ac.vddc = pl->vddc;
- adev->pm.dpm.dyn_state.max_clock_voltage_on_ac.vddci = pl->vddci;
+ ATOM_PPLIB_CLASSIFICATION_UI_PERFORMANCE)
+ limits = &adev->pm.dpm.dyn_state.max_clock_voltage_on_ac;
+ else if ((rps->class & ATOM_PPLIB_CLASSIFICATION_UI_MASK) ==
+ ATOM_PPLIB_CLASSIFICATION_UI_BATTERY)
+ limits = &adev->pm.dpm.dyn_state.max_clock_voltage_on_dc;
+ else
+ limits = NULL;
+
+ if (limits) {
+ if (pl->sclk > limits->sclk)
+ limits->sclk = pl->sclk;
+ if (pl->mclk > limits->mclk)
+ limits->mclk = pl->mclk;
+ if (pl->vddc > limits->vddc)
+ limits->vddc = pl->vddc;
+ if (pl->vddci > limits->vddci)
+ limits->vddci = pl->vddci;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 100/982] ACPICA: Fix condition check in acpi_ps_parse_loop()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 099/982] drm/amd/pm/si: Fix updating clock limits from power states Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 101/982] ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() Greg Kroah-Hartman
` (888 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 8de27e2d83c0d07ae9443c6304575b0609394bfd ]
Fix condition check for AML_ELSE_OP in acpi_ps_parse_loop() to prevent
out-of-bounds access.
Link: https://github.com/acpica/acpica/commit/3b537b92336e
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/1959692.tdWV9SEqCh@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/psloop.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/acpica/psloop.c b/drivers/acpi/acpica/psloop.c
index 840512fa9fc61..e851c7fe31906 100644
--- a/drivers/acpi/acpica/psloop.c
+++ b/drivers/acpi/acpica/psloop.c
@@ -425,7 +425,10 @@ acpi_status acpi_ps_parse_loop(struct acpi_walk_state *walk_state)
ACPI_ERROR((AE_INFO,
"Skipping While/If block"));
- if (*walk_state->aml == AML_ELSE_OP) {
+ if ((walk_state->aml <
+ parser_state->aml_end)
+ && (*walk_state->aml ==
+ AML_ELSE_OP)) {
ACPI_ERROR((AE_INFO,
"Skipping Else block"));
walk_state->parser_state.aml =
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 101/982] ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 100/982] ACPICA: Fix condition check in acpi_ps_parse_loop() Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 102/982] ACPICA: add boundary checks in acpi_ps_get_next_field() Greg Kroah-Hartman
` (887 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 945e87267cfd90937b3c637f87324cbb56998b72 ]
Fix use-after-free issue in acpi_ds_terminate_control_method() by
clearing references to method locals and arguments.
Link: https://github.com/acpica/acpica/commit/36f22a94cb1b
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/8730924.NyiUUSuA9g@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/dsmethod.c | 43 ++++++++++++++++++++++++++++++++++
1 file changed, 43 insertions(+)
diff --git a/drivers/acpi/acpica/dsmethod.c b/drivers/acpi/acpica/dsmethod.c
index 12efc4ac9ba64..01fe931163e6c 100644
--- a/drivers/acpi/acpica/dsmethod.c
+++ b/drivers/acpi/acpica/dsmethod.c
@@ -698,6 +698,8 @@ void
acpi_ds_terminate_control_method(union acpi_operand_object *method_desc,
struct acpi_walk_state *walk_state)
{
+ u32 i;
+ struct acpi_namespace_node *ref_node;
ACPI_FUNCTION_TRACE_PTR(ds_terminate_control_method, walk_state);
@@ -708,6 +710,47 @@ acpi_ds_terminate_control_method(union acpi_operand_object *method_desc,
}
if (walk_state) {
+ /*
+ * Check if the return value is a ref_of reference to a method local
+ * or argument. If so, clear the reference to avoid use-after-free
+ * when the walk state is deleted.
+ */
+ if (walk_state->return_desc &&
+ (walk_state->return_desc->common.type ==
+ ACPI_TYPE_LOCAL_REFERENCE)
+ && (walk_state->return_desc->reference.class ==
+ ACPI_REFCLASS_REFOF)) {
+ ref_node = walk_state->return_desc->reference.object;
+ if (ref_node) {
+
+ /* Check against method locals */
+ for (i = 0; i < ACPI_METHOD_NUM_LOCALS; i++) {
+ if (ref_node ==
+ &walk_state->local_variables[i]) {
+ acpi_ut_remove_reference
+ (walk_state->return_desc);
+ walk_state->return_desc = NULL;
+ break;
+ }
+ }
+
+ /* Check against method arguments if not already cleared */
+ if (walk_state->return_desc) {
+ for (i = 0; i < ACPI_METHOD_NUM_ARGS;
+ i++) {
+ if (ref_node ==
+ &walk_state->arguments[i]) {
+ acpi_ut_remove_reference
+ (walk_state->
+ return_desc);
+ walk_state->
+ return_desc = NULL;
+ break;
+ }
+ }
+ }
+ }
+ }
/* Delete all arguments and locals */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 102/982] ACPICA: add boundary checks in acpi_ps_get_next_field()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 101/982] ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:13 ` [PATCH 6.1 103/982] ACPICA: validate byte_count in acpi_ps_get_next_package_length() Greg Kroah-Hartman
` (886 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit e15aa60de0256d63df2331bf5a4bc4dd287504cd ]
Add boundary checks in acpi_ps_get_next_field() to prevent out-of-bounds
access.
Link: https://github.com/acpica/acpica/commit/c39183ea84bc
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/24388159.6Emhk5qWAg@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/psargs.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/acpi/acpica/psargs.c b/drivers/acpi/acpica/psargs.c
index 418d56203e27a..55af9b3fe8d40 100644
--- a/drivers/acpi/acpica/psargs.c
+++ b/drivers/acpi/acpica/psargs.c
@@ -474,6 +474,10 @@ static union acpi_parse_object *acpi_ps_get_next_field(struct acpi_parse_state
ASL_CV_CAPTURE_COMMENTS_ONLY(parser_state);
aml = parser_state->aml;
+ if (aml >= parser_state->aml_end) {
+ return_PTR(NULL);
+ }
+
/* Determine field type */
switch (ACPI_GET8(parser_state->aml)) {
@@ -522,6 +526,11 @@ static union acpi_parse_object *acpi_ps_get_next_field(struct acpi_parse_state
/* Get the 4-character name */
+ if ((parser_state->aml + ACPI_NAMESEG_SIZE) >
+ parser_state->aml_end) {
+ acpi_ps_free_op(field);
+ return_PTR(NULL);
+ }
ACPI_MOVE_32_TO_32(&name, parser_state->aml);
acpi_ps_set_name(field, name);
parser_state->aml += ACPI_NAMESEG_SIZE;
@@ -567,6 +576,10 @@ static union acpi_parse_object *acpi_ps_get_next_field(struct acpi_parse_state
/* Get the two bytes (Type/Attribute) */
+ if ((parser_state->aml + 2) > parser_state->aml_end) {
+ acpi_ps_free_op(field);
+ return_PTR(NULL);
+ }
access_type = ACPI_GET8(parser_state->aml);
parser_state->aml++;
access_attribute = ACPI_GET8(parser_state->aml);
@@ -578,6 +591,10 @@ static union acpi_parse_object *acpi_ps_get_next_field(struct acpi_parse_state
/* This opcode has a third byte, access_length */
if (opcode == AML_INT_EXTACCESSFIELD_OP) {
+ if (parser_state->aml >= parser_state->aml_end) {
+ acpi_ps_free_op(field);
+ return_PTR(NULL);
+ }
access_length = ACPI_GET8(parser_state->aml);
parser_state->aml++;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 103/982] ACPICA: validate byte_count in acpi_ps_get_next_package_length()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 102/982] ACPICA: add boundary checks in acpi_ps_get_next_field() Greg Kroah-Hartman
@ 2026-09-30 15:13 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 104/982] ACPICA: Prevent adding invalid references Greg Kroah-Hartman
` (885 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:13 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit d49c6ee08365a8596f639da46eb7e71752b0cd42 ]
Validate package length reading in acpi_ps_get_next_package_length().
Link: https://github.com/acpica/acpica/commit/40e03f9941e2
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/3616255.QJadu78ljV@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/psargs.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/acpi/acpica/psargs.c b/drivers/acpi/acpica/psargs.c
index 55af9b3fe8d40..cc27f7888bdca 100644
--- a/drivers/acpi/acpica/psargs.c
+++ b/drivers/acpi/acpica/psargs.c
@@ -48,6 +48,7 @@ acpi_ps_get_next_package_length(struct acpi_parse_state *parser_state)
u32 package_length = 0;
u32 byte_count;
u8 byte_zero_mask = 0x3F; /* Default [0:5] */
+ u32 remaining;
ACPI_FUNCTION_TRACE(ps_get_next_package_length);
@@ -55,7 +56,23 @@ acpi_ps_get_next_package_length(struct acpi_parse_state *parser_state)
* Byte 0 bits [6:7] contain the number of additional bytes
* used to encode the package length, either 0,1,2, or 3
*/
+
+ /* Check if we have at least one byte to read */
+ remaining = (u32)ACPI_PTR_DIFF(parser_state->aml_end, aml);
+ if (remaining == 0) {
+ return_UINT32(0);
+ }
+
byte_count = (aml[0] >> 6);
+
+ /* Validate byte_count and ensure we have enough bytes to read */
+ if (byte_count >= remaining) {
+
+ /* Clamp to available bytes and advance to end */
+ parser_state->aml = parser_state->aml_end;
+ return_UINT32(0);
+ }
+
parser_state->aml += ((acpi_size)byte_count + 1);
/* Get bytes 3, 2, 1 as needed */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 104/982] ACPICA: Prevent adding invalid references
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-09-30 15:13 ` [PATCH 6.1 103/982] ACPICA: validate byte_count in acpi_ps_get_next_package_length() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 105/982] ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) Greg Kroah-Hartman
` (884 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 6e8c55e13a5e3a9f38921d62924f18ceba3330eb ]
Prevent adding references for local, argument, and debug objects
in acpi_ut_copy_simple_object().
Link: https://github.com/acpica/acpica/commit/f576898d7814
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/4511989.ejJDZkT8p0@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/utcopy.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/acpica/utcopy.c b/drivers/acpi/acpica/utcopy.c
index 63c17f420fb86..9672a776513c2 100644
--- a/drivers/acpi/acpica/utcopy.c
+++ b/drivers/acpi/acpica/utcopy.c
@@ -731,7 +731,15 @@ acpi_ut_copy_simple_object(union acpi_operand_object *source_desc,
break;
}
- acpi_ut_add_reference(source_desc->reference.object);
+ /*
+ * Local/Arg/Debug references do not have a valid Object pointer
+ * that can be referenced
+ */
+ if ((source_desc->reference.class != ACPI_REFCLASS_LOCAL) &&
+ (source_desc->reference.class != ACPI_REFCLASS_ARG) &&
+ (source_desc->reference.class != ACPI_REFCLASS_DEBUG)) {
+ acpi_ut_add_reference(source_desc->reference.object);
+ }
break;
case ACPI_TYPE_REGION:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 105/982] ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 104/982] ACPICA: Prevent adding invalid references Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 106/982] ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg() Greg Kroah-Hartman
` (883 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 0e2021f49e64b3c8a9aa880d0c62a218bfe147ce ]
Add overflow check for Index + Length to prevent integer overflow
when calculating the truncation length. This prevents negative
size parameter being passed to memcpy().
Link: https://github.com/acpica/acpica/commit/d281ec1ac84e
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/3760974.R56niFO833@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/exoparg3.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/acpi/acpica/exoparg3.c b/drivers/acpi/acpica/exoparg3.c
index 198da79c0cd48..ecb5bc536feeb 100644
--- a/drivers/acpi/acpica/exoparg3.c
+++ b/drivers/acpi/acpica/exoparg3.c
@@ -152,7 +152,7 @@ acpi_status acpi_ex_opcode_3A_1T_1R(struct acpi_walk_state *walk_state)
/* Truncate request if larger than the actual String/Buffer */
- else if ((index + length) > operand[0]->string.length) {
+ else if ((index + length) > operand[0]->string.length || (index + length) < index) { /* Check for overflow */
length =
(acpi_size)operand[0]->string.length -
(acpi_size)index;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 106/982] ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 105/982] ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 107/982] ACPICA: validate handler object type in two places Greg Kroah-Hartman
` (882 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 27d27e75ecb752a0b4da848c440bb3a88396ecba ]
Improve argument parsing in acpi_ps_get_next_simple_arg() to handle
remaining AML data safely.
Link: https://github.com/acpica/acpica/commit/ecbb8bcfe301
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/2008043.taCxCBeP46@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/psargs.c | 78 +++++++++++++++++++++++++++++++-----
1 file changed, 68 insertions(+), 10 deletions(-)
diff --git a/drivers/acpi/acpica/psargs.c b/drivers/acpi/acpica/psargs.c
index cc27f7888bdca..1a52bc08db4ce 100644
--- a/drivers/acpi/acpica/psargs.c
+++ b/drivers/acpi/acpica/psargs.c
@@ -384,6 +384,8 @@ acpi_ps_get_next_simple_arg(struct acpi_parse_state *parser_state,
u32 length;
u16 opcode;
u8 *aml = parser_state->aml;
+ u32 remaining = (u32)ACPI_PTR_DIFF(parser_state->aml_end, aml);
+ u64 partial_value;
ACPI_FUNCTION_TRACE_U32(ps_get_next_simple_arg, arg_type);
@@ -393,8 +395,13 @@ acpi_ps_get_next_simple_arg(struct acpi_parse_state *parser_state,
/* Get 1 byte from the AML stream */
opcode = AML_BYTE_OP;
- arg->common.value.integer = (u64) *aml;
- length = 1;
+ if (remaining >= 1) {
+ arg->common.value.integer = (u64)*aml;
+ length = 1;
+ } else {
+ arg->common.value.integer = 0;
+ length = 0;
+ }
break;
case ARGP_WORDDATA:
@@ -402,8 +409,19 @@ acpi_ps_get_next_simple_arg(struct acpi_parse_state *parser_state,
/* Get 2 bytes from the AML stream */
opcode = AML_WORD_OP;
- ACPI_MOVE_16_TO_64(&arg->common.value.integer, aml);
- length = 2;
+ if (remaining >= 2) {
+ ACPI_MOVE_16_TO_64(&arg->common.value.integer, aml);
+ length = 2;
+ } else {
+ arg->common.value.integer = 0;
+ length = 0;
+ if (remaining > 0) {
+ partial_value = 0;
+ memcpy(&partial_value, aml, remaining);
+ arg->common.value.integer = partial_value;
+ length = remaining;
+ }
+ }
break;
case ARGP_DWORDDATA:
@@ -411,8 +429,19 @@ acpi_ps_get_next_simple_arg(struct acpi_parse_state *parser_state,
/* Get 4 bytes from the AML stream */
opcode = AML_DWORD_OP;
- ACPI_MOVE_32_TO_64(&arg->common.value.integer, aml);
- length = 4;
+ if (remaining >= 4) {
+ ACPI_MOVE_32_TO_64(&arg->common.value.integer, aml);
+ length = 4;
+ } else {
+ arg->common.value.integer = 0;
+ length = 0;
+ if (remaining > 0) {
+ partial_value = 0;
+ memcpy(&partial_value, aml, remaining);
+ arg->common.value.integer = partial_value;
+ length = remaining;
+ }
+ }
break;
case ARGP_QWORDDATA:
@@ -420,8 +449,19 @@ acpi_ps_get_next_simple_arg(struct acpi_parse_state *parser_state,
/* Get 8 bytes from the AML stream */
opcode = AML_QWORD_OP;
- ACPI_MOVE_64_TO_64(&arg->common.value.integer, aml);
- length = 8;
+ if (remaining >= 8) {
+ ACPI_MOVE_64_TO_64(&arg->common.value.integer, aml);
+ length = 8;
+ } else {
+ arg->common.value.integer = 0;
+ length = 0;
+ if (remaining > 0) {
+ partial_value = 0;
+ memcpy(&partial_value, aml, remaining);
+ arg->common.value.integer = partial_value;
+ length = remaining;
+ }
+ }
break;
case ARGP_CHARLIST:
@@ -434,10 +474,28 @@ acpi_ps_get_next_simple_arg(struct acpi_parse_state *parser_state,
/* Find the null terminator */
length = 0;
- while (aml[length]) {
+ while ((length < remaining) && aml[length]) {
+ length++;
+ }
+ if (length < remaining) {
+
+ /* Account for the terminating null */
length++;
+ } else {
+ /*
+ * No terminator found - add null at buffer boundary
+ * and report a warning
+ */
+ ACPI_WARNING((AE_INFO,
+ "Invalid AML string: no null terminator, truncating at offset %u",
+ (u32)(aml - parser_state->aml)));
+
+ /* Add null terminator at the boundary */
+ if (remaining > 0) {
+ aml[remaining - 1] = 0;
+ length = remaining;
+ }
}
- length++;
break;
case ARGP_NAME:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 107/982] ACPICA: validate handler object type in two places
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 106/982] ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 108/982] ACPICA: Add package limit checks in parser functions Greg Kroah-Hartman
` (881 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit c5296da2d516707862f8a2dbb4b515f777e5294f ]
ACPICA: validate handler object type in acpi_ev_has_default_handler()
and acpi_ev_find_region_handler().
Link: https://github.com/acpica/acpica/commit/f6fc648a1389
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/48111441.fMDQidcC6G@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/evhandler.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/acpi/acpica/evhandler.c b/drivers/acpi/acpica/evhandler.c
index be9a05498adc3..6f16e863a60f3 100644
--- a/drivers/acpi/acpica/evhandler.c
+++ b/drivers/acpi/acpica/evhandler.c
@@ -130,6 +130,14 @@ acpi_ev_has_default_handler(struct acpi_namespace_node *node,
/* Walk the linked list of handlers for this object */
while (handler_obj) {
+
+ /* Validate handler object type before accessing fields */
+
+ if (handler_obj->common.type !=
+ ACPI_TYPE_LOCAL_ADDRESS_HANDLER) {
+ break;
+ }
+
if (handler_obj->address_space.space_id == space_id) {
if (handler_obj->address_space.handler_flags &
ACPI_ADDR_HANDLER_DEFAULT_INSTALLED) {
@@ -292,6 +300,9 @@ union acpi_operand_object *acpi_ev_find_region_handler(acpi_adr_space_type
/* Walk the handler list for this device */
while (handler_obj) {
+ if (handler_obj->common.type != ACPI_TYPE_LOCAL_ADDRESS_HANDLER) {
+ break;
+ }
/* Same space_id indicates a handler is installed */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 108/982] ACPICA: Add package limit checks in parser functions
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 107/982] ACPICA: validate handler object type in two places Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 109/982] ACPICA: Add validation for node in acpi_ns_build_normalized_path() Greg Kroah-Hartman
` (880 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit d27d48a528e437aed690f977e69a6fe73fe82ab5 ]
Add package limit checks in parser functions to prevent out-of-bounds
access.
Link: https://github.com/acpica/acpica/commit/b31b45af2122
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/3212937.CbtlEUcBR6@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/nsxfname.c | 4 ++++
drivers/acpi/acpica/psargs.c | 4 ++++
drivers/acpi/acpica/psloop.c | 25 +++++++++++++++++++++++++
drivers/acpi/acpica/psparse.c | 8 ++++++++
4 files changed, 41 insertions(+)
diff --git a/drivers/acpi/acpica/nsxfname.c b/drivers/acpi/acpica/nsxfname.c
index b2cfdfef31947..8079364e2440e 100644
--- a/drivers/acpi/acpica/nsxfname.c
+++ b/drivers/acpi/acpica/nsxfname.c
@@ -512,6 +512,10 @@ acpi_status acpi_install_method(u8 *buffer)
parser_state.aml += acpi_ps_get_opcode_size(opcode);
parser_state.pkg_end = acpi_ps_get_next_package_end(&parser_state);
+ if ((parser_state.pkg_end > parser_state.aml_end) ||
+ (parser_state.pkg_end < parser_state.aml)) {
+ return (AE_AML_PACKAGE_LIMIT);
+ }
path = acpi_ps_get_next_namestring(&parser_state);
method_flags = *parser_state.aml++;
diff --git a/drivers/acpi/acpica/psargs.c b/drivers/acpi/acpica/psargs.c
index 1a52bc08db4ce..35166be684880 100644
--- a/drivers/acpi/acpica/psargs.c
+++ b/drivers/acpi/acpica/psargs.c
@@ -867,6 +867,10 @@ acpi_ps_get_next_arg(struct acpi_walk_state *walk_state,
parser_state->pkg_end =
acpi_ps_get_next_package_end(parser_state);
+ if ((parser_state->pkg_end > parser_state->aml_end)
+ || (parser_state->pkg_end < parser_state->aml)) {
+ return_ACPI_STATUS(AE_AML_PACKAGE_LIMIT);
+ }
break;
case ARGP_FIELDLIST:
diff --git a/drivers/acpi/acpica/psloop.c b/drivers/acpi/acpica/psloop.c
index e851c7fe31906..60c55743d399e 100644
--- a/drivers/acpi/acpica/psloop.c
+++ b/drivers/acpi/acpica/psloop.c
@@ -361,6 +361,13 @@ acpi_status acpi_ps_parse_loop(struct acpi_walk_state *walk_state)
walk_state->parser_state.aml =
acpi_ps_get_next_package_end
(&walk_state->parser_state);
+ if ((walk_state->parser_state.aml >
+ walk_state->parser_state.aml_end)
+ || (walk_state->parser_state.aml <
+ walk_state->aml)) {
+ return_ACPI_STATUS
+ (AE_AML_PACKAGE_LIMIT);
+ }
walk_state->aml =
walk_state->parser_state.aml;
}
@@ -421,6 +428,14 @@ acpi_status acpi_ps_parse_loop(struct acpi_walk_state *walk_state)
parser_state->aml =
acpi_ps_get_next_package_end
(parser_state);
+ if ((parser_state->aml >
+ parser_state->aml_end)
+ || (parser_state->aml <
+ walk_state->control_state->
+ control.aml_predicate_start)) {
+ return_ACPI_STATUS
+ (AE_AML_PACKAGE_LIMIT);
+ }
walk_state->aml = parser_state->aml;
ACPI_ERROR((AE_INFO,
@@ -436,6 +451,16 @@ acpi_status acpi_ps_parse_loop(struct acpi_walk_state *walk_state)
walk_state->parser_state.aml =
acpi_ps_get_next_package_end
(parser_state);
+ if ((walk_state->parser_state.
+ aml >
+ walk_state->parser_state.
+ aml_end)
+ || (walk_state->
+ parser_state.aml <
+ walk_state->aml)) {
+ return_ACPI_STATUS
+ (AE_AML_PACKAGE_LIMIT);
+ }
walk_state->aml =
parser_state->aml;
}
diff --git a/drivers/acpi/acpica/psparse.c b/drivers/acpi/acpica/psparse.c
index ba93f359760a9..a4eb254c62ea5 100644
--- a/drivers/acpi/acpica/psparse.c
+++ b/drivers/acpi/acpica/psparse.c
@@ -300,6 +300,7 @@ acpi_ps_next_parse_state(struct acpi_walk_state *walk_state,
{
struct acpi_parse_state *parser_state = &walk_state->parser_state;
acpi_status status = AE_CTRL_PENDING;
+ u8 *aml;
ACPI_FUNCTION_TRACE_PTR(ps_next_parse_state, op);
@@ -344,7 +345,14 @@ acpi_ps_next_parse_state(struct acpi_walk_state *walk_state,
* Predicate of an IF was true, and we are at the matching ELSE.
* Just close out this package
*/
+ aml = parser_state->aml;
+
parser_state->aml = acpi_ps_get_next_package_end(parser_state);
+ if ((parser_state->aml > parser_state->aml_end) ||
+ (parser_state->aml < aml)) {
+ status = AE_AML_PACKAGE_LIMIT;
+ break;
+ }
status = AE_CTRL_PENDING;
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 109/982] ACPICA: Add validation for node in acpi_ns_build_normalized_path()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 108/982] ACPICA: Add package limit checks in parser functions Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 110/982] ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() Greg Kroah-Hartman
` (879 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 96b2b616870e46e2bc04efec03879683a0036e66 ]
Add validation for node in acpi_ns_build_normalized_path()
to prevent use-after-free vulnerabilities.
Link: https://github.com/acpica/acpica/commit/b35adf49e89a
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/118666237.nniJfEyVGO@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/nsnames.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/acpi/acpica/nsnames.c b/drivers/acpi/acpica/nsnames.c
index d91153f657005..ab6d217d31db4 100644
--- a/drivers/acpi/acpica/nsnames.c
+++ b/drivers/acpi/acpica/nsnames.c
@@ -222,6 +222,12 @@ acpi_ns_build_normalized_path(struct acpi_namespace_node *node,
goto build_trailing_null;
}
+ /* Validate the Node to avoid use-after-free vulnerabilities */
+
+ if (ACPI_GET_DESCRIPTOR_TYPE(node) != ACPI_DESC_TYPE_NAMED) {
+ goto build_trailing_null;
+ }
+
next_node = node;
while (next_node && next_node != acpi_gbl_root_node) {
if (next_node != node) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 110/982] ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 109/982] ACPICA: Add validation for node in acpi_ns_build_normalized_path() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 111/982] ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() Greg Kroah-Hartman
` (878 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit 485829e6999b7909f50761a1c708660304edc945 ]
Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() to
prevent buffer overflows.
Link: https://github.com/acpica/acpica/commit/f85a43098d65
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/2230782.OBFZWjSADL@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/exconfig.c | 26 ++++++++++++++++++++++++--
1 file changed, 24 insertions(+), 2 deletions(-)
diff --git a/drivers/acpi/acpica/exconfig.c b/drivers/acpi/acpica/exconfig.c
index d7d74ef87b186..06f897bec4f14 100644
--- a/drivers/acpi/acpica/exconfig.c
+++ b/drivers/acpi/acpica/exconfig.c
@@ -90,6 +90,8 @@ acpi_ex_load_table_op(struct acpi_walk_state *walk_state,
union acpi_operand_object *return_obj;
union acpi_operand_object *ddb_handle;
u32 table_index;
+ char oem_id[ACPI_OEM_ID_SIZE + 1];
+ char oem_table_id[ACPI_OEM_TABLE_ID_SIZE + 1];
ACPI_FUNCTION_TRACE(ex_load_table_op);
@@ -102,12 +104,32 @@ acpi_ex_load_table_op(struct acpi_walk_state *walk_state,
*return_desc = return_obj;
+ /*
+ * Validate OEM ID and OEM Table ID string lengths.
+ * acpi_tb_find_table expects strings that can safely read
+ * ACPI_OEM_ID_SIZE and ACPI_OEM_TABLE_ID_SIZE bytes.
+ */
+ if ((operand[1]->string.length > ACPI_OEM_ID_SIZE) ||
+ (operand[2]->string.length > ACPI_OEM_TABLE_ID_SIZE)) {
+ return_ACPI_STATUS(AE_AML_STRING_LIMIT);
+ }
+
+ /*
+ * Copy OEM strings to local buffers with guaranteed null-termination.
+ * This prevents heap-buffer-overflow when acpi_tb_find_table reads
+ * ACPI_OEM_ID_SIZE/ACPI_OEM_TABLE_ID_SIZE bytes.
+ */
+ memcpy(oem_id, operand[1]->string.pointer, operand[1]->string.length);
+ oem_id[operand[1]->string.length] = 0;
+ memcpy(oem_table_id, operand[2]->string.pointer,
+ operand[2]->string.length);
+ oem_table_id[operand[2]->string.length] = 0;
+
/* Find the ACPI table in the RSDT/XSDT */
acpi_ex_exit_interpreter();
status = acpi_tb_find_table(operand[0]->string.pointer,
- operand[1]->string.pointer,
- operand[2]->string.pointer, &table_index);
+ oem_id, oem_table_id, &table_index);
acpi_ex_enter_interpreter();
if (ACPI_FAILURE(status)) {
if (status != AE_NOT_FOUND) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 111/982] ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 110/982] ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 112/982] ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() Greg Kroah-Hartman
` (877 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Rafael J. Wysocki, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit f8d14b7bb0063bbbd86c0e4d73edb8cea7b362bc ]
acpi_ns_custom_package() unconditionally dereferences the first element
of the package to read the _BIX version number, without checking for
NULL:
if ((*Elements)->Common.Type != ACPI_TYPE_INTEGER)
When firmware returns a _BIX package whose first element is an
unresolvable reference, ACPICA evaluates that entry to NULL.
acpi_ns_remove_null_elements() does not strip NULL entries for
ACPI_PTYPE_CUSTOM packages (fixed-position format would break if
elements were shifted), so acpi_ns_custom_package() sees the NULL
and causes a crash.
Add a NULL check for the first element (version field) before
dereferencing it. The caller then receives AE_AML_OPERAND_TYPE
instead of crashing.
Link: https://github.com/acpica/acpica/commit/f3f111b9013b
Reported-by: Xiang Mei <xmei5@asu.edu>
Reported-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/5674388.Sb9uPGUboI@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/nsprepkg.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/acpi/acpica/nsprepkg.c b/drivers/acpi/acpica/nsprepkg.c
index 82932c9a774b4..887eb54942ffc 100644
--- a/drivers/acpi/acpica/nsprepkg.c
+++ b/drivers/acpi/acpica/nsprepkg.c
@@ -631,6 +631,13 @@ acpi_ns_custom_package(struct acpi_evaluate_info *info,
/* Get version number, must be Integer */
+ if (!(*elements)) {
+ ACPI_WARN_PREDEFINED((AE_INFO, info->full_pathname,
+ info->node_flags,
+ "Return Package has a NULL version element"));
+ return_ACPI_STATUS(AE_AML_OPERAND_TYPE);
+ }
+
if ((*elements)->common.type != ACPI_TYPE_INTEGER) {
ACPI_WARN_PREDEFINED((AE_INFO, info->full_pathname,
info->node_flags,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 112/982] ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 111/982] ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 113/982] ACPICA: add boundary checks in two places Greg Kroah-Hartman
` (876 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit b2e21fe8c3361c3d0d57ee56d359bea9b51fda3d ]
Enhance buffer validation in acpi_ut_walk_aml_resources() to prevent
buffer overflows.
Link: https://github.com/acpica/acpica/commit/975cb20c7992
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/2481429.NG923GbCHz@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/utresrc.c | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/drivers/acpi/acpica/utresrc.c b/drivers/acpi/acpica/utresrc.c
index 16f9a7035b39c..82326d9547873 100644
--- a/drivers/acpi/acpica/utresrc.c
+++ b/drivers/acpi/acpica/utresrc.c
@@ -162,6 +162,28 @@ acpi_ut_walk_aml_resources(struct acpi_walk_state *walk_state,
/* Walk the byte list, abort on any invalid descriptor type or length */
while (aml < end_aml) {
+ /*
+ * Validate that the remaining buffer space can hold enough
+ * bytes to safely access fields during validation.
+ * For large resource descriptors (bit 7 set), we need enough
+ * bytes to access the Type field in serial_bus resources.
+ * Small resource descriptors only need sizeof(struct aml_resource_end_tag).
+ */
+ if ((acpi_size)(end_aml - aml) <
+ sizeof(struct aml_resource_end_tag)) {
+ return_ACPI_STATUS(AE_AML_BUFFER_LENGTH);
+ }
+
+ /*
+ * For large resource descriptors, ensure enough space for
+ * the header plus serial_bus Type field access.
+ */
+ if ((ACPI_GET8(aml) & ACPI_RESOURCE_NAME_LARGE) &&
+ ((acpi_size)(end_aml - aml) <
+ ACPI_OFFSET(struct aml_resource_common_serialbus,
+ type) + 1)) {
+ return_ACPI_STATUS(AE_AML_BUFFER_LENGTH);
+ }
/* Validate the Resource Type and Resource Length */
@@ -179,6 +201,14 @@ acpi_ut_walk_aml_resources(struct acpi_walk_state *walk_state,
length = acpi_ut_get_descriptor_length(aml);
+ /*
+ * Validate that the descriptor length doesn't exceed the
+ * remaining buffer size to prevent reading beyond the end.
+ */
+ if (length > (acpi_size)(end_aml - aml)) {
+ return_ACPI_STATUS(AE_AML_BUFFER_LENGTH);
+ }
+
/* Invoke the user function */
if (user_function) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 113/982] ACPICA: add boundary checks in two places
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 112/982] ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 114/982] hfs: rework hfsplus_readdir() logic Greg Kroah-Hartman
` (875 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, ikaros, Rafael J. Wysocki,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ikaros <void0red@gmail.com>
[ Upstream commit bdc35754012906dbf094be104b103ca3adfef6f7 ]
Add boundary checks in acpi_ps_get_next_namestring() and
acpi_ps_peek_opcode() to prevent out-of-bounds access.
Link: https://github.com/acpica/acpica/commit/cfdc96896d8d
Signed-off-by: ikaros <void0red@gmail.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/5180044.0VBMTVartN@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/acpica/psargs.c | 18 +++++++++++++++++-
drivers/acpi/acpica/psparse.c | 6 ++++++
2 files changed, 23 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/acpica/psargs.c b/drivers/acpi/acpica/psargs.c
index 35166be684880..1d206670a9786 100644
--- a/drivers/acpi/acpica/psargs.c
+++ b/drivers/acpi/acpica/psargs.c
@@ -148,10 +148,16 @@ char *acpi_ps_get_next_namestring(struct acpi_parse_state *parser_state)
/* Point past any namestring prefix characters (backslash or carat) */
- while (ACPI_IS_ROOT_PREFIX(*end) || ACPI_IS_PARENT_PREFIX(*end)) {
+ while (end < parser_state->aml_end &&
+ (ACPI_IS_ROOT_PREFIX(*end) || ACPI_IS_PARENT_PREFIX(*end))) {
end++;
}
+ if (end >= parser_state->aml_end) {
+ parser_state->aml = parser_state->aml_end;
+ return_PTR(NULL);
+ }
+
/* Decode the path prefix character */
switch (*end) {
@@ -176,6 +182,11 @@ char *acpi_ps_get_next_namestring(struct acpi_parse_state *parser_state)
/* Multiple name segments, 4 chars each, count in next byte */
+ if ((end + 1) >= parser_state->aml_end) {
+ parser_state->aml = parser_state->aml_end;
+ return_PTR(NULL);
+ }
+
end += 2 + (*(end + 1) * ACPI_NAMESEG_SIZE);
break;
@@ -187,6 +198,11 @@ char *acpi_ps_get_next_namestring(struct acpi_parse_state *parser_state)
break;
}
+ if (end > parser_state->aml_end) {
+ parser_state->aml = parser_state->aml_end;
+ return_PTR(NULL);
+ }
+
parser_state->aml = end;
return_PTR((char *)start);
}
diff --git a/drivers/acpi/acpica/psparse.c b/drivers/acpi/acpica/psparse.c
index a4eb254c62ea5..fc5a18cf0c610 100644
--- a/drivers/acpi/acpica/psparse.c
+++ b/drivers/acpi/acpica/psparse.c
@@ -70,6 +70,9 @@ u16 acpi_ps_peek_opcode(struct acpi_parse_state * parser_state)
u16 opcode;
aml = parser_state->aml;
+ if (aml >= parser_state->aml_end) {
+ return (0xFFFF);
+ }
opcode = (u16) ACPI_GET8(aml);
if (opcode == AML_EXTENDED_PREFIX) {
@@ -77,6 +80,9 @@ u16 acpi_ps_peek_opcode(struct acpi_parse_state * parser_state)
/* Extended opcode, get the second opcode byte */
aml++;
+ if (aml >= parser_state->aml_end) {
+ return (0xFFFF);
+ }
opcode = (u16) ((opcode << 8) | ACPI_GET8(aml));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 114/982] hfs: rework hfsplus_readdir() logic
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 113/982] ACPICA: add boundary checks in two places Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 115/982] pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP Greg Kroah-Hartman
` (874 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Yangtao Li, linux-fsdevel, Viacheslav Dubeyko, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viacheslav Dubeyko <slava@dubeyko.com>
[ Upstream commit 7fde7e806657fbe0d33f489521b488eed94f9b39 ]
The xfstests' test-case generic/637 fails with error:
FSTYP -- hfs
PLATFORM -- Linux/x86_64 kvm-xfstests 6.15.0-rc4-xfstests-g00b827f0cffa #1 SMP PREEMPT_DYNAMIC Fri May 25
MKFS_OPTIONS -- /dev/vdc
MOUNT_OPTIONS -- /dev/vdc /vdc
QA output created by 637
entries 7 and 8 have duplicate d_off 8
Found unlinked files in open dir (see xfstests-dev/results//generic/637.full for details)
Likewise HFS+, currently, HFS has very complicated and
fragile logic of rd->file->f_pos correction in hfs_delete_cat().
This patch removes this logic and it stores the current
pos into hfs_readdir_data. Finally, if rd->pos == ctx->pos
then hfs_readdir() tries to find the position in
b-tree's node by means of hfs_cat_key. This position is
used to re-start the folder's content traversal.
sudo ./check generic/637
FSTYP -- hfs
PLATFORM -- Linux/x86_64 hfsplus-testing-0001 7.1.0-rc1+ #55 SMP PREEMPT_DYNAMIC Tue May 19 15:18:02 PDT 2026
MKFS_OPTIONS -- /dev/loop51
MOUNT_OPTIONS -- /dev/loop51 /mnt/scratch
generic/637 32s ... 31s
Ran: generic/637
Passed all 1 tests
Closes: https://github.com/hfs-linux-kernel/hfs-linux-kernel/issues/65
cc: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
cc: Yangtao Li <frank.li@vivo.com>
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/20260519222811.1311071-2-slava@dubeyko.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/hfs/catalog.c | 9 ---------
fs/hfs/dir.c | 28 +++++++++++-----------------
fs/hfs/hfs.h | 3 +--
fs/hfs/hfs_fs.h | 2 --
fs/hfs/inode.c | 4 ----
5 files changed, 12 insertions(+), 34 deletions(-)
diff --git a/fs/hfs/catalog.c b/fs/hfs/catalog.c
index d365bf0b8c77d..41e09f209f745 100644
--- a/fs/hfs/catalog.c
+++ b/fs/hfs/catalog.c
@@ -222,7 +222,6 @@ int hfs_cat_delete(u32 cnid, struct inode *dir, const struct qstr *str)
{
struct super_block *sb;
struct hfs_find_data fd;
- struct hfs_readdir_data *rd;
int res, type;
hfs_dbg(CAT_MOD, "delete_cat: %s,%u\n", str ? str->name : NULL, cnid);
@@ -248,14 +247,6 @@ int hfs_cat_delete(u32 cnid, struct inode *dir, const struct qstr *str)
}
}
- /* we only need to take spinlock for exclusion with ->release() */
- spin_lock(&HFS_I(dir)->open_dir_lock);
- list_for_each_entry(rd, &HFS_I(dir)->open_dir_list, list) {
- if (fd.tree->keycmp(fd.search_key, (void *)&rd->key) < 0)
- rd->file->f_pos--;
- }
- spin_unlock(&HFS_I(dir)->open_dir_lock);
-
res = hfs_brec_remove(&fd);
if (res)
goto out;
diff --git a/fs/hfs/dir.c b/fs/hfs/dir.c
index 527f6e46cbe81..f392aee79f422 100644
--- a/fs/hfs/dir.c
+++ b/fs/hfs/dir.c
@@ -97,7 +97,15 @@ static int hfs_readdir(struct file *file, struct dir_context *ctx)
}
if (ctx->pos >= inode->i_size)
goto out;
- err = hfs_brec_goto(&fd, ctx->pos - 1);
+ rd = file->private_data;
+ if (rd && rd->pos == ctx->pos) {
+ memcpy(fd.search_key, &rd->key, sizeof(struct hfs_cat_key));
+ err = hfs_brec_find(&fd);
+ if (err == -ENOENT)
+ err = hfs_brec_goto(&fd, 1);
+ } else {
+ err = hfs_brec_goto(&fd, ctx->pos - 1);
+ }
if (err)
goto out;
@@ -146,7 +154,6 @@ static int hfs_readdir(struct file *file, struct dir_context *ctx)
if (err)
goto out;
}
- rd = file->private_data;
if (!rd) {
rd = kmalloc(sizeof(struct hfs_readdir_data), GFP_KERNEL);
if (!rd) {
@@ -154,15 +161,8 @@ static int hfs_readdir(struct file *file, struct dir_context *ctx)
goto out;
}
file->private_data = rd;
- rd->file = file;
- spin_lock(&HFS_I(inode)->open_dir_lock);
- list_add(&rd->list, &HFS_I(inode)->open_dir_list);
- spin_unlock(&HFS_I(inode)->open_dir_lock);
}
- /*
- * Can be done after the list insertion; exclusion with
- * hfs_delete_cat() is provided by directory lock.
- */
+ rd->pos = ctx->pos;
memcpy(&rd->key, &fd.key->cat, sizeof(struct hfs_cat_key));
out:
hfs_find_exit(&fd);
@@ -171,13 +171,7 @@ static int hfs_readdir(struct file *file, struct dir_context *ctx)
static int hfs_dir_release(struct inode *inode, struct file *file)
{
- struct hfs_readdir_data *rd = file->private_data;
- if (rd) {
- spin_lock(&HFS_I(inode)->open_dir_lock);
- list_del(&rd->list);
- spin_unlock(&HFS_I(inode)->open_dir_lock);
- kfree(rd);
- }
+ kfree(file->private_data);
return 0;
}
diff --git a/fs/hfs/hfs.h b/fs/hfs/hfs.h
index 6f194d0768b6f..f46d12ce04a3f 100644
--- a/fs/hfs/hfs.h
+++ b/fs/hfs/hfs.h
@@ -281,8 +281,7 @@ struct hfs_mdb {
/*======== Data structures kept in memory ========*/
struct hfs_readdir_data {
- struct list_head list;
- struct file *file;
+ loff_t pos;
struct hfs_cat_key key;
};
diff --git a/fs/hfs/hfs_fs.h b/fs/hfs/hfs_fs.h
index 1bce2ec271d4d..203757a273ac3 100644
--- a/fs/hfs/hfs_fs.h
+++ b/fs/hfs/hfs_fs.h
@@ -68,8 +68,6 @@ struct hfs_inode_info {
struct hfs_cat_key cat_key;
- struct list_head open_dir_list;
- spinlock_t open_dir_lock;
struct inode *rsrc_inode;
struct mutex extents_lock;
diff --git a/fs/hfs/inode.c b/fs/hfs/inode.c
index e45cc396dc004..e4530fdd93de0 100644
--- a/fs/hfs/inode.c
+++ b/fs/hfs/inode.c
@@ -193,8 +193,6 @@ struct inode *hfs_new_inode(struct inode *dir, const struct qstr *name, umode_t
return NULL;
mutex_init(&HFS_I(inode)->extents_lock);
- INIT_LIST_HEAD(&HFS_I(inode)->open_dir_list);
- spin_lock_init(&HFS_I(inode)->open_dir_lock);
hfs_cat_build_key(sb, (btree_key *)&HFS_I(inode)->cat_key, dir->i_ino, name);
inode->i_ino = HFS_SB(sb)->next_id++;
inode->i_mode = mode;
@@ -328,8 +326,6 @@ static int hfs_read_inode(struct inode *inode, void *data)
HFS_I(inode)->flags = 0;
HFS_I(inode)->rsrc_inode = NULL;
mutex_init(&HFS_I(inode)->extents_lock);
- INIT_LIST_HEAD(&HFS_I(inode)->open_dir_list);
- spin_lock_init(&HFS_I(inode)->open_dir_lock);
/* Initialize the inode */
inode->i_uid = hsb->s_uid;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 115/982] pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 114/982] hfs: rework hfsplus_readdir() logic Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 116/982] host1x: bus: Fix missing ops null check in error teardown Greg Kroah-Hartman
` (873 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geert Uytterhoeven, Claudiu Beznea,
Geert Uytterhoeven, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
[ Upstream commit 01f94d53947df35ba77cdb3992a4e3ef9d9dc1ad ]
The pinctrl and GPIO core code make exceptions for the -ENOTSUPP error
code. One such example is gpio_set_config_with_argument_optional(), which
returns success when gpio_set_config_with_argument() returns -ENOTSUPP, but
reports failure for all other error codes.
Returning -EOPNOTSUPP from the pinctrl driver on the unsupported pinctrl
operation may lead to boot failures when pinctrl drivers implements
struct gpio_chip::set_config, the system uses GPIO hogs, and the
struct gpio_chip::set_config implementation returns -EOPNOTSUPP for the
unsupported operations.
Currently, the driver does not implement struct gpio_chip::set_config().
To avoid future failures, return -ENOTSUPP from
rzv2m_pinctrl_pinconf_set().
rzv2m_pinctrl_pinconf_group_get() is used when dumping pinctrl
configuration. pinconf_generic_dump_one(), which calls it, makes
exceptions for the -EINVAL and -ENOTSUPP error codes. The documentation
for struct pinconf_ops::pin_config_group_get states that it "should
return -ENOTSUPP and -EINVAL using the same rules as pin_config_get()".
The documentation for struct pinconf_ops::pin_config_get states:
"get the config of a certain pin, if the requested config is not available
on this controller this should return -ENOTSUPP and if it is available but
disabled it should return -EINVAL".
Return -ENOTSUPP for the unsupported pinctrl operation.
Suggested-by: Geert Uytterhoeven <geert@linux-m68k.org>
Signed-off-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260522105717.1727837-1-claudiu.beznea@kernel.org
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/renesas/pinctrl-rzv2m.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/pinctrl/renesas/pinctrl-rzv2m.c b/drivers/pinctrl/renesas/pinctrl-rzv2m.c
index dc4299c03b990..2ac91512f0c61 100644
--- a/drivers/pinctrl/renesas/pinctrl-rzv2m.c
+++ b/drivers/pinctrl/renesas/pinctrl-rzv2m.c
@@ -664,7 +664,7 @@ static int rzv2m_pinctrl_pinconf_set(struct pinctrl_dev *pctldev,
}
default:
- return -EOPNOTSUPP;
+ return -ENOTSUPP;
}
}
@@ -713,7 +713,7 @@ static int rzv2m_pinctrl_pinconf_group_get(struct pinctrl_dev *pctldev,
/* Check config matches previous pins */
if (i && prev_config != *config)
- return -EOPNOTSUPP;
+ return -ENOTSUPP;
prev_config = *config;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 116/982] host1x: bus: Fix missing ops null check in error teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 115/982] pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 117/982] scripts: modpost: detect and report truncated buf_printf() output Greg Kroah-Hartman
` (872 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, shayderrr, Thierry Reding,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: shayderrr <darknessshayder@gmail.com>
[ Upstream commit 71d25f668bc5c0f36ea843462e12307dea45aaa3 ]
In host1x_device_init(), the error teardown paths do not check
client->ops before dereferencing it, unlike the forward init paths
which correctly guard with 'client->ops &&'. This can result in a
NULL pointer dereference if client->ops is NULL.
Fix by adding the missing client->ops check in both the teardown
and teardown_late labels.
Signed-off-by: shayderrr <darknessshayder@gmail.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260517170456.84927-1-darknessshayder@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/host1x/bus.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/host1x/bus.c b/drivers/gpu/host1x/bus.c
index 8c819af1bce69..751ef2f3342cd 100644
--- a/drivers/gpu/host1x/bus.c
+++ b/drivers/gpu/host1x/bus.c
@@ -226,7 +226,7 @@ int host1x_device_init(struct host1x_device *device)
teardown:
list_for_each_entry_continue_reverse(client, &device->clients, list)
- if (client->ops->exit)
+ if (client->ops && client->ops->exit)
client->ops->exit(client);
/* reset client to end of list for late teardown */
@@ -234,7 +234,7 @@ int host1x_device_init(struct host1x_device *device)
teardown_late:
list_for_each_entry_continue_reverse(client, &device->clients, list)
- if (client->ops->late_exit)
+ if (client->ops && client->ops->late_exit)
client->ops->late_exit(client);
mutex_unlock(&device->clients_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 117/982] scripts: modpost: detect and report truncated buf_printf() output
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 116/982] host1x: bus: Fix missing ops null check in error teardown Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 118/982] ASoC: Intel: catpt: Complete coredump handling Greg Kroah-Hartman
` (871 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexandre Courbot, Nathan Chancellor,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexandre Courbot <acourbot@nvidia.com>
[ Upstream commit d7231d8cb262b1e350c00271bf53d54414b4f3b1 ]
buf_printf() uses a fixed-size stack buffer. vsnprintf() returns the
number of bytes that *would* have been written to that buffer, which can
be larger than the size of said buffer if the formatted string is too
long.
The problem is that whenever this happens buf_printf() currently passes
this length, unchecked, to buf_write(), which silently reads past the
stack buffer and copies invalid data into the output buffer.
Fix this by detecting vsnprintf() failures and truncations before
appending to the output buffer, and report a fatal error instead of
producing corrupt symbol names.
Signed-off-by: Alexandre Courbot <acourbot@nvidia.com>
Link: https://patch.msgid.link/20260527-nova-exports-v2-1-06de4c556d55@nvidia.com
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
scripts/mod/modpost.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/scripts/mod/modpost.c b/scripts/mod/modpost.c
index b2388814fe976..990e514cd747d 100644
--- a/scripts/mod/modpost.c
+++ b/scripts/mod/modpost.c
@@ -1861,8 +1861,17 @@ void __attribute__((format(printf, 2, 3))) buf_printf(struct buffer *buf,
va_start(ap, fmt);
len = vsnprintf(tmp, SZ, fmt, ap);
- buf_write(buf, tmp, len);
va_end(ap);
+
+ if (len < 0) {
+ perror("vsnprintf failed");
+ exit(1);
+ }
+ if (len >= SZ)
+ fatal("buf_printf output truncated for string %s: %d bytes needed, %d available\n",
+ tmp, len + 1, SZ);
+
+ buf_write(buf, tmp, len);
}
void buf_write(struct buffer *buf, const char *s, int len)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 118/982] ASoC: Intel: catpt: Complete coredump handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 117/982] scripts: modpost: detect and report truncated buf_printf() output Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 119/982] libbpf: Add __NR_bpf definition for LoongArch Greg Kroah-Hartman
` (870 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cezary Rojewski, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cezary Rojewski <cezary.rojewski@intel.com>
[ Upstream commit 7e5d59f407bc39d43b350cc45f7880647429eb5d ]
An exception may occur during the firmware booting procedure. In such
case the firmware sends COREDUMP_REQUESTS and expects the driver to dump
relevant information and finish with the COREDUMP_RELEASE write.
To distinguish such situation from generic timeout, always signal
fw_ready completion when a coredump request is received and translate
it to -EREMOTEIO in catpt_boot_firmware().
The "FW READY" print makes the success clearly visible even when
the event-traces are not enabled.
Signed-off-by: Cezary Rojewski <cezary.rojewski@intel.com>
Link: https://patch.msgid.link/20260528083444.1439233-2-cezary.rojewski@intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/intel/catpt/ipc.c | 8 ++++++++
sound/soc/intel/catpt/loader.c | 3 +++
sound/soc/intel/catpt/registers.h | 12 ++++++++++++
3 files changed, 23 insertions(+)
diff --git a/sound/soc/intel/catpt/ipc.c b/sound/soc/intel/catpt/ipc.c
index 5b718a846fda5..3341a3a190e62 100644
--- a/sound/soc/intel/catpt/ipc.c
+++ b/sound/soc/intel/catpt/ipc.c
@@ -205,6 +205,7 @@ static void catpt_dsp_process_response(struct catpt_dev *cdev, u32 header)
memcpy_fromio(&config, cdev->lpe_ba + off, sizeof(config));
trace_catpt_ipc_payload((u8 *)&config, sizeof(config));
+ dev_dbg(cdev->dev, "FW READY 0x%08x\n", header);
catpt_ipc_arm(ipc, &config);
complete(&cdev->fw_ready);
return;
@@ -215,6 +216,13 @@ static void catpt_dsp_process_response(struct catpt_dev *cdev, u32 header)
dev_err(cdev->dev, "ADSP device coredump received\n");
ipc->ready = false;
catpt_coredump(cdev);
+
+ if (catpt_readl_dram(cdev, COREDUMP) == CATPT_COREDUMP_REQUEST) {
+ dev_dbg(cdev->dev, "releasing firmware from the coredump state\n");
+ catpt_writel_dram(cdev, COREDUMP, CATPT_COREDUMP_RELEASE);
+ }
+
+ complete(&cdev->fw_ready);
/* TODO: attempt recovery */
break;
diff --git a/sound/soc/intel/catpt/loader.c b/sound/soc/intel/catpt/loader.c
index ff7b8f0d34ac7..6602587787cb4 100644
--- a/sound/soc/intel/catpt/loader.c
+++ b/sound/soc/intel/catpt/loader.c
@@ -626,6 +626,9 @@ int catpt_boot_firmware(struct catpt_dev *cdev, bool restore)
if (!ret) {
dev_err(cdev->dev, "firmware ready timeout\n");
return -ETIMEDOUT;
+ /* Wake up does not mean FW is ready, an exception could occur. */
+ } else if (!cdev->ipc.ready) {
+ return -EREMOTEIO;
}
/* update sram pg & clock once done booting */
diff --git a/sound/soc/intel/catpt/registers.h b/sound/soc/intel/catpt/registers.h
index 47280d82842eb..a6da59dff76ef 100644
--- a/sound/soc/intel/catpt/registers.h
+++ b/sound/soc/intel/catpt/registers.h
@@ -124,6 +124,11 @@
#define CATPT_SSCR2_DEFAULT 0x0
#define CATPT_SSPSP2_DEFAULT 0x0
+/* Coredump register and its states */
+#define CATPT_DRAM_COREDUMP 0x1F4
+#define CATPT_COREDUMP_REQUEST UINT_MAX
+#define CATPT_COREDUMP_RELEASE 0
+
/* Physically the same block, access address differs between host and dsp */
#define CATPT_DSP_DRAM_OFFSET 0x400000
#define catpt_to_host_offset(offset) ((offset) & ~(CATPT_DSP_DRAM_OFFSET))
@@ -137,6 +142,8 @@
/* registry I/O helpers */
+#define catpt_dram_addr(cdev) \
+ ((cdev)->lpe_ba + (cdev)->spec->host_dram_offset)
#define catpt_shim_addr(cdev) \
((cdev)->lpe_ba + (cdev)->spec->host_shim_offset)
#define catpt_dma_addr(cdev, dma) \
@@ -151,6 +158,11 @@
#define catpt_writel_ssp(cdev, ssp, reg, val) \
writel(val, catpt_ssp_addr(cdev, ssp) + (reg))
+#define catpt_readl_dram(cdev, reg) \
+ readl(catpt_dram_addr(cdev) + CATPT_DRAM_##reg)
+#define catpt_writel_dram(cdev, reg, val) \
+ writel(val, catpt_dram_addr(cdev) + CATPT_DRAM_##reg)
+
#define catpt_readl_shim(cdev, reg) \
readl(catpt_shim_addr(cdev) + CATPT_SHIM_##reg)
#define catpt_writel_shim(cdev, reg, val) \
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 119/982] libbpf: Add __NR_bpf definition for LoongArch
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 118/982] ASoC: Intel: catpt: Complete coredump handling Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 120/982] soundwire: dmi-quirks: Disable ghost Realtek devices Greg Kroah-Hartman
` (869 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tiezhu Yang, Andrii Nakryiko,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tiezhu Yang <yangtiezhu@loongson.cn>
[ Upstream commit a4a5d4ee061240a1d39053db0a87f841d43277c0 ]
LoongArch uses the generic syscall table, where __NR_bpf is defined
as 280 in include/uapi/asm-generic/unistd.h.
To align with other architectures, add the __NR_bpf definition for
LoongArch to avoid a potential compilation failure: "error __NR_bpf
not defined. libbpf does not support your arch."
This is a follow up patch of:
commit b0c47807d31d ("bpf: Add sparc support to tools and samples.")
commit bad1926dd2f6 ("bpf, s390: fix build for libbpf and selftest suite")
commit ca31ca8247e2 ("tools/bpf: fix perf build error with uClibc (seen on ARC)")
commit e32cb12ff52a ("bpf, mips: Fix build errors about __NR_bpf undeclared")
Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260526063936.16769-1-yangtiezhu@loongson.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/build/feature/test-bpf.c | 2 ++
tools/lib/bpf/bpf.c | 2 ++
2 files changed, 4 insertions(+)
diff --git a/tools/build/feature/test-bpf.c b/tools/build/feature/test-bpf.c
index 727d22e34a6e5..febc3a93c29fc 100644
--- a/tools/build/feature/test-bpf.c
+++ b/tools/build/feature/test-bpf.c
@@ -20,6 +20,8 @@
# define __NR_bpf 6319
# elif defined(__mips__) && defined(_ABI64)
# define __NR_bpf 5315
+# elif defined(__loongarch__)
+# define __NR_bpf 280
# else
# error __NR_bpf not defined. libbpf does not support your arch.
# endif
diff --git a/tools/lib/bpf/bpf.c b/tools/lib/bpf/bpf.c
index 1d49a03528365..484d30691a600 100644
--- a/tools/lib/bpf/bpf.c
+++ b/tools/lib/bpf/bpf.c
@@ -59,6 +59,8 @@
# define __NR_bpf 6319
# elif defined(__mips__) && defined(_ABI64)
# define __NR_bpf 5315
+# elif defined(__loongarch__)
+# define __NR_bpf 280
# else
# error __NR_bpf not defined. libbpf does not support your arch.
# endif
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 120/982] soundwire: dmi-quirks: Disable ghost Realtek devices
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 119/982] libbpf: Add __NR_bpf definition for LoongArch Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 121/982] soundwire: only handle alert events when the peripheral is attached Greg Kroah-Hartman
` (868 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Charles Keepax, Pierre-Louis Bossart,
Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 4dab2b904414fac53535c4e4cdad808132f4cdc2 ]
Many systems ship with a Realtek audio codec in the ACPI that doesn't
physically exist in the system. This confuses the newer function
topology system that creates the soundcard, as it builds the card based
on the ACPI information.
Whilst we are working with the laptop vendors to try and stop this
happening there are quite a few systems where this has shipped. Add a
quirk to disable this "ghost" device.
Currently this patch should cover:
- Asus UX5406AA
- Lenovo Yoga Pro 9i (83SF)
- Lenovo Yoga Slim 7 Ultra (83QK)
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260520163631.3300102-4-ckeepax@opensource.cirrus.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/dmi-quirks.c | 35 ++++++++++++++++++++++++++++++++++
1 file changed, 35 insertions(+)
diff --git a/drivers/soundwire/dmi-quirks.c b/drivers/soundwire/dmi-quirks.c
index 5854218e1a274..32a46a2d90f7c 100644
--- a/drivers/soundwire/dmi-quirks.c
+++ b/drivers/soundwire/dmi-quirks.c
@@ -90,6 +90,19 @@ static const struct adr_remap intel_rooks_county[] = {
{}
};
+/*
+ * Many platforms have ghost realtek devices in the ACPI that don't physically
+ * exist, remove those devices.
+ */
+static const struct adr_remap ghost_realtek[] = {
+ /* rt722 on link3 */
+ {
+ 0x000330025d072201ull,
+ 0x0000000000000000ull
+ },
+ {}
+};
+
static const struct dmi_system_id adr_remap_quirk_table[] = {
/* TGL devices */
{
@@ -164,6 +177,28 @@ static const struct dmi_system_id adr_remap_quirk_table[] = {
},
.driver_data = (void *)hp_omen_16,
},
+ /* PTL devices */
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "ASUS"),
+ DMI_MATCH(DMI_BOARD_NAME, "UX5406AA"),
+ },
+ .driver_data = (void *)ghost_realtek,
+ },
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "LENOVO"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "83QK"),
+ },
+ .driver_data = (void *)ghost_realtek,
+ },
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "LENOVO"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "83SF"),
+ },
+ .driver_data = (void *)ghost_realtek,
+ },
{}
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 121/982] soundwire: only handle alert events when the peripheral is attached
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 120/982] soundwire: dmi-quirks: Disable ghost Realtek devices Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 122/982] mmc: davinci: fix mmc_add_host order in probe Greg Kroah-Hartman
` (867 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, Péter Ujfalusi,
Ranjani Sridharan, Pierre-Louis Bossart, Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bard Liao <yung-chuan.liao@linux.intel.com>
[ Upstream commit 38cd651ebce7065a81c7e950d9e2ea1572304605 ]
It doesn't make sense to handle an alert event when the peripheral is
not attached. The slave->status could be SDW_SLAVE_ATTACHED or
SDW_SLAVE_ALERT when it is attached on the bus.
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Péter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Ranjani Sridharan <ranjani.sridharan@linux.intel.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260520025720.1999367-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/bus.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/soundwire/bus.c b/drivers/soundwire/bus.c
index 1b6ba23edf0fa..46bb9026a6c61 100644
--- a/drivers/soundwire/bus.c
+++ b/drivers/soundwire/bus.c
@@ -1874,6 +1874,10 @@ int sdw_handle_slave_status(struct sdw_bus *bus,
break;
case SDW_SLAVE_ALERT:
+ if (slave->status != SDW_SLAVE_ATTACHED &&
+ slave->status != SDW_SLAVE_ALERT)
+ continue;
+
ret = sdw_handle_slave_alerts(slave);
if (ret < 0)
dev_err(&slave->dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 122/982] mmc: davinci: fix mmc_add_host order in probe
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 121/982] soundwire: only handle alert events when the peripheral is attached Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 123/982] mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC Greg Kroah-Hartman
` (866 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Osama Abdelkader, Ulf Hansson,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Osama Abdelkader <osama.abdelkader@gmail.com>
[ Upstream commit d04e0151d316edbdb4f0397a9b92a1936e4a1421 ]
mmc_add_host() makes the host visible to the MMC core. Register the
interrupt handlers and advertise MMC_CAP_SDIO_IRQ before that, so the
core cannot start using the host before IRQ handling is set up.
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mmc/host/davinci_mmc.c | 12 +++++-------
1 file changed, 5 insertions(+), 7 deletions(-)
diff --git a/drivers/mmc/host/davinci_mmc.c b/drivers/mmc/host/davinci_mmc.c
index b744651f3b625..62e75df6b6b00 100644
--- a/drivers/mmc/host/davinci_mmc.c
+++ b/drivers/mmc/host/davinci_mmc.c
@@ -1303,14 +1303,10 @@ static int davinci_mmcsd_probe(struct platform_device *pdev)
goto cpu_freq_fail;
}
- ret = mmc_add_host(mmc);
- if (ret < 0)
- goto mmc_add_host_fail;
-
ret = devm_request_irq(&pdev->dev, irq, mmc_davinci_irq, 0,
mmc_hostname(mmc), host);
if (ret)
- goto request_irq_fail;
+ goto mmc_add_host_fail;
if (host->sdio_irq >= 0) {
ret = devm_request_irq(&pdev->dev, host->sdio_irq,
@@ -1320,6 +1316,10 @@ static int davinci_mmcsd_probe(struct platform_device *pdev)
mmc->caps |= MMC_CAP_SDIO_IRQ;
}
+ ret = mmc_add_host(mmc);
+ if (ret < 0)
+ goto mmc_add_host_fail;
+
rename_region(mem, mmc_hostname(mmc));
dev_info(mmc_dev(host->mmc), "Using %s, %d-bit mode\n",
@@ -1328,8 +1328,6 @@ static int davinci_mmcsd_probe(struct platform_device *pdev)
return 0;
-request_irq_fail:
- mmc_remove_host(mmc);
mmc_add_host_fail:
mmc_davinci_cpufreq_deregister(host);
cpu_freq_fail:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 123/982] mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 122/982] mmc: davinci: fix mmc_add_host order in probe Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 124/982] tracing: Disable KCOV instrumentation for trace_irqsoff.o Greg Kroah-Hartman
` (865 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Wolfram Sang,
Geert Uytterhoeven, Ulf Hansson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
[ Upstream commit 5ce500d31a1625d8fe7ede950201b8df076bdd48 ]
The RZ/G2N (R8A774B1) SoC was previously handled via the generic
"renesas,rcar-gen3-sdhi" fallback compatible string. However, because
the SDHI IP on RZ/G2N is identical with the R-Car M3-N (R8A77965), it
requires the specific quirks and configuration defined in
`of_r8a77965_compatible` rather than the generic Gen3 data.
Add the explicit "renesas,sdhi-r8a774b1" match entry to map it correctly.
Note that the DT binding file renesas,sdhi.yaml does not need an update
as the entry for this SoC is already present.
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mmc/host/renesas_sdhi_internal_dmac.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mmc/host/renesas_sdhi_internal_dmac.c b/drivers/mmc/host/renesas_sdhi_internal_dmac.c
index 58dbc28ead58f..20118b3c428c9 100644
--- a/drivers/mmc/host/renesas_sdhi_internal_dmac.c
+++ b/drivers/mmc/host/renesas_sdhi_internal_dmac.c
@@ -269,6 +269,7 @@ static const struct renesas_sdhi_of_data_with_quirks of_rza2_compatible = {
static const struct of_device_id renesas_sdhi_internal_dmac_of_match[] = {
{ .compatible = "renesas,sdhi-r7s9210", .data = &of_rza2_compatible, },
{ .compatible = "renesas,sdhi-mmc-r8a77470", .data = &of_rcar_gen3_compatible, },
+ { .compatible = "renesas,sdhi-r8a774b1", .data = &of_r8a77965_compatible, },
{ .compatible = "renesas,sdhi-r8a774e1", .data = &of_r8a7795_compatible, },
{ .compatible = "renesas,sdhi-r8a7795", .data = &of_r8a7795_compatible, },
{ .compatible = "renesas,sdhi-r8a77961", .data = &of_r8a77961_compatible, },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 124/982] tracing: Disable KCOV instrumentation for trace_irqsoff.o
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 123/982] mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 125/982] mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC Greg Kroah-Hartman
` (864 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Steven Rostedt,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 01046072880b654dbadf71be2f645aad4a7b5d87 ]
When KCOV runs its boot selftest with whole-kernel instrumentation
enabled, it sets current->kcov_mode to KCOV_MODE_TRACE_PC without
installing a coverage area. Any instrumented code accepted as task-context
coverage in that window dereferences current->kcov_area and crashes.
On ARMv5 Versatile PB with CONFIG_KCOV_SELFTEST=y,
CONFIG_KCOV_INSTRUMENT_ALL=y and CONFIG_IRQSOFF_TRACER=y, boot hits a
NULL pointer fault during the selftest:
kcov: running self test
Internal error: Oops: 5 [#1] ARM
PC is at __sanitizer_cov_trace_pc+0x4c/0x90
Kernel panic - not syncing: Fatal exception
A diagnostic run showed the unwanted coverage comes from the IRQs-off
tracer callbacks reached from ARM IRQ entry before hardirq context is
visible to KCOV:
__sanitizer_cov_trace_pc from tracer_hardirqs_off+0x18/0x1cc
tracer_hardirqs_off from trace_hardirqs_off+0x34/0x54
trace_hardirqs_off from __irq_svc+0x58/0xb0
__irq_svc from kcov_init+0x7c/0xdc
and similarly through tracer_hardirqs_on().
trace_preemptirq.o is already excluded because this tracing path can run
from early interrupt code and produce coverage unrelated to syscall
inputs. Exclude trace_irqsoff.o as well, instead of requiring users to
turn off CONFIG_KCOV_INSTRUMENT_ALL=y, which is the default whole-kernel
KCOV mode.
With the exclusion in place, the same ARMv5 Versatile PB QEMU test boots
through the KCOV selftest and reaches userspace.
Tested on ARMv5 Versatile PB QEMU with CONFIG_KCOV_SELFTEST=y,
CONFIG_KCOV_INSTRUMENT_ALL=y and CONFIG_IRQSOFF_TRACER=y.
Link: https://patch.msgid.link/20260525170428.67211-1-kmehltretter@gmail.com
Assisted-by: Codex:gpt-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/Makefile | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/kernel/trace/Makefile b/kernel/trace/Makefile
index c6651e16b5572..7752b2b04396e 100644
--- a/kernel/trace/Makefile
+++ b/kernel/trace/Makefile
@@ -31,9 +31,10 @@ ifdef CONFIG_GCOV_PROFILE_FTRACE
GCOV_PROFILE := y
endif
-# Functions in this file could be invoked from early interrupt
-# code and produce random code coverage.
+# Functions in these files can run from IRQ entry before hardirq context
+# is visible to KCOV, and produce coverage unrelated to syscall inputs.
KCOV_INSTRUMENT_trace_preemptirq.o := n
+KCOV_INSTRUMENT_trace_irqsoff.o := n
CFLAGS_bpf_trace.o := -I$(src)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 125/982] mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 124/982] tracing: Disable KCOV instrumentation for trace_irqsoff.o Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 126/982] iio: light: stk3310: Deal with the ps interrupt issue in PM Greg Kroah-Hartman
` (863 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Geert Uytterhoeven,
Wolfram Sang, Ulf Hansson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
[ Upstream commit ebf7f2198ac4817bd2929cf83c697cefa8bf36a9 ]
The RZ/G2E (R8A774C0) SoC was previously handled via the generic
"renesas,rcar-gen3-sdhi" fallback compatible string. However, because
the SDHI IP on RZ/G2E is identical with the R-Car E3 (R8A77990), it
requires the specific quirks and configuration defined in
`of_r8a77990_compatible` rather than the generic Gen3 data.
Add the explicit "renesas,sdhi-r8a774c0" match entry to map it correctly.
Note that the DT binding file renesas,sdhi.yaml does not need an update
as the entry for this SoC is already present.
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mmc/host/renesas_sdhi_internal_dmac.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mmc/host/renesas_sdhi_internal_dmac.c b/drivers/mmc/host/renesas_sdhi_internal_dmac.c
index 20118b3c428c9..e05ac6475899d 100644
--- a/drivers/mmc/host/renesas_sdhi_internal_dmac.c
+++ b/drivers/mmc/host/renesas_sdhi_internal_dmac.c
@@ -270,6 +270,7 @@ static const struct of_device_id renesas_sdhi_internal_dmac_of_match[] = {
{ .compatible = "renesas,sdhi-r7s9210", .data = &of_rza2_compatible, },
{ .compatible = "renesas,sdhi-mmc-r8a77470", .data = &of_rcar_gen3_compatible, },
{ .compatible = "renesas,sdhi-r8a774b1", .data = &of_r8a77965_compatible, },
+ { .compatible = "renesas,sdhi-r8a774c0", .data = &of_r8a77990_compatible, },
{ .compatible = "renesas,sdhi-r8a774e1", .data = &of_r8a7795_compatible, },
{ .compatible = "renesas,sdhi-r8a7795", .data = &of_r8a7795_compatible, },
{ .compatible = "renesas,sdhi-r8a77961", .data = &of_r8a77961_compatible, },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 126/982] iio: light: stk3310: Deal with the ps interrupt issue in PM
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 125/982] mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 127/982] perf/ftrace: Fix WARNING in __unregister_ftrace_function Greg Kroah-Hartman
` (862 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Miao Li, Jonathan Cameron,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miao Li <limiao@kylinos.cn>
[ Upstream commit 9c1d639e90cf42f5c1401f91f38ffd89af6dd970 ]
On the Inspur HS326 laptop(which integrated with HiSilicon M900
processor), if the STK3311-X chip's PS interrupt is configured
in "Recommended interrupt mode", the interrupt cannot be triggered
normally after waking from suspend or hibernation.
In this case, neither disabling and re-enabling the interrupt nor
resetting the PS threshold register can restore the interrupt to
normal operation.
If the interrupt is disabled in suspend() then reset the PS threshold
register and enable the interrupt in resume(). This resolves the issue.
Signed-off-by: Miao Li <limiao@kylinos.cn>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/light/stk3310.c | 76 +++++++++++++++++++++++++++++++++----
1 file changed, 69 insertions(+), 7 deletions(-)
diff --git a/drivers/iio/light/stk3310.c b/drivers/iio/light/stk3310.c
index 7b8e0da6aabc1..b1b0e77922ac1 100644
--- a/drivers/iio/light/stk3310.c
+++ b/drivers/iio/light/stk3310.c
@@ -106,6 +106,9 @@ struct stk3310_data {
struct mutex lock;
bool als_enabled;
bool ps_enabled;
+ bool ps_int_enabled;
+ uint32_t ps_thdl;
+ uint32_t ps_thdh;
uint32_t ps_near_level;
u64 timestamp;
struct regmap *regmap;
@@ -275,10 +278,17 @@ static int stk3310_write_event(struct iio_dev *indio_dev,
buf = cpu_to_be16(val);
ret = regmap_bulk_write(data->regmap, reg, &buf, 2);
- if (ret < 0)
+ if (ret < 0) {
dev_err(&client->dev, "failed to set PS threshold!\n");
+ return ret;
+ }
- return ret;
+ if (reg == STK3310_REG_THDH_PS)
+ data->ps_thdh = val;
+ else
+ data->ps_thdl = val;
+
+ return 0;
}
static int stk3310_read_event_config(struct iio_dev *indio_dev,
@@ -313,11 +323,17 @@ static int stk3310_write_event_config(struct iio_dev *indio_dev,
/* Set INT_PS value */
mutex_lock(&data->lock);
ret = regmap_field_write(data->reg_int_ps, state);
- if (ret < 0)
+ if (ret < 0) {
dev_err(&client->dev, "failed to set interrupt mode\n");
+ mutex_unlock(&data->lock);
+ return ret;
+ }
+
+ data->ps_int_enabled = state;
+
mutex_unlock(&data->lock);
- return ret;
+ return 0;
}
static int stk3310_read_raw(struct iio_dev *indio_dev,
@@ -490,10 +506,15 @@ static int stk3310_init(struct iio_dev *indio_dev)
/* Enable PS interrupts */
ret = regmap_field_write(data->reg_int_ps, STK3310_PSINT_EN);
- if (ret < 0)
+ if (ret < 0) {
dev_err(&client->dev, "failed to enable interrupts!\n");
+ return ret;
+ }
- return ret;
+ data->ps_int_enabled = true;
+ data->ps_thdh = STK3310_PS_MAX_VAL;
+
+ return 0;
}
static bool stk3310_is_volatile_reg(struct device *dev, unsigned int reg)
@@ -660,9 +681,18 @@ static void stk3310_remove(struct i2c_client *client)
static int stk3310_suspend(struct device *dev)
{
struct stk3310_data *data;
+ int ret;
data = iio_priv(i2c_get_clientdata(to_i2c_client(dev)));
+ if (data->ps_int_enabled) {
+ ret = regmap_field_write(data->reg_int_ps, 0x0);
+ if (ret < 0) {
+ dev_err(dev, "failed to disable ps int at suspend.\n");
+ return ret;
+ }
+ }
+
return stk3310_set_state(data, STK3310_STATE_STANDBY);
}
@@ -670,6 +700,8 @@ static int stk3310_resume(struct device *dev)
{
u8 state = 0;
struct stk3310_data *data;
+ __be16 buf;
+ int ret;
data = iio_priv(i2c_get_clientdata(to_i2c_client(dev)));
if (data->ps_enabled)
@@ -677,7 +709,37 @@ static int stk3310_resume(struct device *dev)
if (data->als_enabled)
state |= STK3310_STATE_EN_ALS;
- return stk3310_set_state(data, state);
+ ret = stk3310_set_state(data, state);
+ if (ret < 0)
+ return ret;
+
+ if (data->ps_thdl != 0x0) {
+ buf = cpu_to_be16(data->ps_thdl);
+ ret = regmap_bulk_write(data->regmap, STK3310_REG_THDL_PS, &buf, 2);
+ if (ret < 0) {
+ dev_err(dev, "failed to set reg THDL_PS at resume.\n");
+ return ret;
+ }
+ }
+
+ if (data->ps_thdh != STK3310_PS_MAX_VAL) {
+ buf = cpu_to_be16(data->ps_thdh);
+ ret = regmap_bulk_write(data->regmap, STK3310_REG_THDH_PS, &buf, 2);
+ if (ret < 0) {
+ dev_err(dev, "failed to set reg THDH_PS at resume.\n");
+ return ret;
+ }
+ }
+
+ if (data->ps_int_enabled) {
+ ret = regmap_field_write(data->reg_int_ps, STK3310_PSINT_EN);
+ if (ret < 0) {
+ dev_err(dev, "failed to enable ps int at resume.\n");
+ return ret;
+ }
+ }
+
+ return 0;
}
static DEFINE_SIMPLE_DEV_PM_OPS(stk3310_pm_ops, stk3310_suspend,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 127/982] perf/ftrace: Fix WARNING in __unregister_ftrace_function
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 126/982] iio: light: stk3310: Deal with the ps interrupt issue in PM Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 128/982] iio: accel: mma8452: switch to non-devm request_threaded_irq() Greg Kroah-Hartman
` (861 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rik van Riel, Steven Rostedt,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rik van Riel <riel@surriel.com>
[ Upstream commit 9581123304b23049437324038698af9fb56ee663 ]
perf_ftrace_function_unregister() unconditionally calls
unregister_ftrace_function() without checking whether the ftrace_ops
was ever successfully registered. This triggers a WARN_ON in
__unregister_ftrace_function() when the ops doesn't have
FTRACE_OPS_FL_ENABLED set.
This can happen during perf_event_alloc() error cleanup when
perf_trace_destroy() is called via __free_event() on an event whose
ftrace_ops registration failed or was already torn down by
perf_try_init_event()'s err_destroy path.
The call path is:
perf_event_alloc() error cleanup
-> __free_event()
-> event->destroy() [tp_perf_event_destroy]
-> perf_trace_destroy()
-> perf_trace_event_close()
-> TRACE_REG_PERF_CLOSE
-> perf_ftrace_function_unregister()
-> unregister_ftrace_function()
-> __unregister_ftrace_function()
-> WARN_ON(!(ops->flags & FTRACE_OPS_FL_ENABLED))
Fix this by checking FTRACE_OPS_FL_ENABLED before attempting to
unregister. If the ops is not enabled, just free the filter and
return success.
Link: https://patch.msgid.link/20260527111301.2d0d8256@fangorn
Signed-off-by: Rik van Riel <riel@surriel.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/trace_event_perf.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/kernel/trace/trace_event_perf.c b/kernel/trace/trace_event_perf.c
index f2000cf2b3bba..a7e41eee9a796 100644
--- a/kernel/trace/trace_event_perf.c
+++ b/kernel/trace/trace_event_perf.c
@@ -501,7 +501,17 @@ static int perf_ftrace_function_register(struct perf_event *event)
static int perf_ftrace_function_unregister(struct perf_event *event)
{
struct ftrace_ops *ops = &event->ftrace_ops;
- int ret = unregister_ftrace_function(ops);
+ int ret = 0;
+
+ /*
+ * Perf will call this unconditionally even if the ops is not
+ * enabled. The unregister_ftrace_function() will warn if called
+ * when not enabled. Just bypass the unregistering if ops isn't
+ * enabled here.
+ */
+ if (ops->flags & FTRACE_OPS_FL_ENABLED)
+ ret = unregister_ftrace_function(ops);
+
ftrace_free_filter(ops);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 128/982] iio: accel: mma8452: switch to non-devm request_threaded_irq()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 127/982] perf/ftrace: Fix WARNING in __unregister_ftrace_function Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 129/982] libbpf: Also reset {insn,data}_cur on realloc failure Greg Kroah-Hartman
` (860 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sanjay Chitroda, Jonathan Cameron,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanjay Chitroda <sanjayembeddedse@gmail.com>
[ Upstream commit 0a6726ec20cd4c0101f2de0ca485a11676224dea ]
Avoid using devm_request_threaded_irq() as the driver requires explicit
error-handling path(s). Using devm_* API together with goto-based
unwinding breaks the expected LIFO resource release model.
Add explicit IRQ cleanup in the driver teardown paths to follow kernel
resource management conventions.
Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/accel/mma8452.c | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/drivers/iio/accel/mma8452.c b/drivers/iio/accel/mma8452.c
index 28002c714ea98..7be63b5965993 100644
--- a/drivers/iio/accel/mma8452.c
+++ b/drivers/iio/accel/mma8452.c
@@ -1695,18 +1695,16 @@ static int mma8452_probe(struct i2c_client *client,
goto trigger_cleanup;
if (client->irq) {
- ret = devm_request_threaded_irq(&client->dev,
- client->irq,
- NULL, mma8452_interrupt,
- IRQF_TRIGGER_LOW | IRQF_ONESHOT,
- client->name, indio_dev);
+ ret = request_threaded_irq(client->irq, NULL, mma8452_interrupt,
+ IRQF_TRIGGER_LOW | IRQF_ONESHOT,
+ client->name, indio_dev);
if (ret)
goto buffer_cleanup;
}
ret = pm_runtime_set_active(&client->dev);
if (ret < 0)
- goto buffer_cleanup;
+ goto free_irq;
pm_runtime_enable(&client->dev);
pm_runtime_set_autosuspend_delay(&client->dev,
@@ -1715,7 +1713,7 @@ static int mma8452_probe(struct i2c_client *client,
ret = iio_device_register(indio_dev);
if (ret < 0)
- goto buffer_cleanup;
+ goto free_irq;
ret = mma8452_set_freefall_mode(data, false);
if (ret < 0)
@@ -1726,6 +1724,10 @@ static int mma8452_probe(struct i2c_client *client,
unregister_device:
iio_device_unregister(indio_dev);
+free_irq:
+ if (client->irq)
+ free_irq(client->irq, indio_dev);
+
buffer_cleanup:
iio_triggered_buffer_cleanup(indio_dev);
@@ -1751,6 +1753,9 @@ static void mma8452_remove(struct i2c_client *client)
pm_runtime_disable(&client->dev);
pm_runtime_set_suspended(&client->dev);
+ if (client->irq)
+ free_irq(client->irq, indio_dev);
+
iio_triggered_buffer_cleanup(indio_dev);
mma8452_trigger_cleanup(indio_dev);
mma8452_standby(iio_priv(indio_dev));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 129/982] libbpf: Also reset {insn,data}_cur on realloc failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 128/982] iio: accel: mma8452: switch to non-devm request_threaded_irq() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 130/982] net: ibm: emac: Reserve VLAN header in MJS limit Greg Kroah-Hartman
` (859 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann, Alexei Starovoitov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit d2f7bd066ed492aeaf82864fbf1f06770f9d9f9d ]
realloc_insn_buf() as well as realloc_data_buf() free and NULL
gen->insn_start / gen->data_start on -ENOMEM but leave gen->insn_cur /
gen->data_cur pointing into the old, freed buffer. Just reset the
cursors to NULL alongside the base pointers so the freed state is
coherent.
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260529094119.307264-3-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/lib/bpf/gen_loader.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
index b74c82bb831e6..13fac40d5fd92 100644
--- a/tools/lib/bpf/gen_loader.c
+++ b/tools/lib/bpf/gen_loader.c
@@ -63,6 +63,7 @@ static int realloc_insn_buf(struct bpf_gen *gen, __u32 size)
gen->error = -ENOMEM;
free(gen->insn_start);
gen->insn_start = NULL;
+ gen->insn_cur = NULL;
return -ENOMEM;
}
gen->insn_start = insn_start;
@@ -86,6 +87,7 @@ static int realloc_data_buf(struct bpf_gen *gen, __u32 size)
gen->error = -ENOMEM;
free(gen->data_start);
gen->data_start = NULL;
+ gen->data_cur = NULL;
return -ENOMEM;
}
gen->data_start = data_start;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 130/982] net: ibm: emac: Reserve VLAN header in MJS limit
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 129/982] libbpf: Also reset {insn,data}_cur on realloc failure Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 131/982] wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi Greg Kroah-Hartman
` (858 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Rosen Penev, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit 0906c117f81c2ae6e6dbfa82719f79c75e1c9325 ]
The IBM EMAC programs its Maximum Jumbo Size (MJS) drop
threshold from ndev->mtu directly. The hardware sizes the threshold
against the L2 frame minus the ethernet header, but does not
discount the 802.1Q tag, so a frame carrying a VLAN tag and a full
1500-byte payload exceeds MJS by exactly 4 bytes and is dropped.
This is normally hidden because JPSM (and therefore the MJS check)
only engages when the MTU is raised above ETH_DATA_LEN. With the
qca8k DSA tagger the conduit MTU is bumped by QCA_HDR_LEN to 1502
during dsa_conduit_setup(), which is enough to enable JPSM and
expose the off-by-VLAN-tag in the limit.
Pad MJS by VLAN_HLEN so a VLAN-tagged full-MTU frame passes.
Reported on Meraki MX60 (qca8k switch): tagged VLAN
traffic drops at 1500-byte payload, while 1496 bytes works
and untagged 1500 bytes works.
Assisted-by: Claude:Opus-4.7
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Link: https://patch.msgid.link/20260526202247.13823-1-rosenp@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ibm/emac/core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ibm/emac/core.c b/drivers/net/ethernet/ibm/emac/core.c
index 9b08e41ccc294..d78a5a9e79b55 100644
--- a/drivers/net/ethernet/ibm/emac/core.c
+++ b/drivers/net/ethernet/ibm/emac/core.c
@@ -30,6 +30,7 @@
#include <linux/skbuff.h>
#include <linux/crc32.h>
#include <linux/ethtool.h>
+#include <linux/if_vlan.h>
#include <linux/mii.h>
#include <linux/bitops.h>
#include <linux/workqueue.h>
@@ -465,7 +466,7 @@ static inline u32 emac_iff2rmr(struct net_device *ndev)
if (emac_has_feature(dev, EMAC_APM821XX_REQ_JUMBO_FRAME_SIZE)) {
r &= ~EMAC4_RMR_MJS_MASK;
- r |= EMAC4_RMR_MJS(ndev->mtu);
+ r |= EMAC4_RMR_MJS(ndev->mtu + VLAN_HLEN);
}
return r;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 131/982] wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 130/982] net: ibm: emac: Reserve VLAN header in MJS limit Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 132/982] ASoC: qcom: q6apm: return error code to consumers on failures Greg Kroah-Hartman
` (857 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Miaoqing Pan, Rameshkumar Sundaram,
Baochen Qiang, Jeff Johnson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>
[ Upstream commit 6b471e9aefee9ed73278eb1141e0d8530a56fae9 ]
In certain cases, hardware might provide packets with a
length greater than the maximum native Wi-Fi header length.
This can lead to accessing and modifying fields in the header
within the ath11k_dp_rx_h_undecap_nwifi() function for the
DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and
potentially result in invalid data access and memory corruption.
Kernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k]
Call trace:
ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k]
ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k]
ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k]
ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k]
ath11k_dp_service_srng+0x2e0/0x348 [ath11k]
Add a sanity check before processing the SKB to prevent invalid
data access in the undecap native Wi-Fi function for the
DP_RX_DECAP_TYPE_NATIVE_WIFI decap type.
This adapted from the discussion/patch of the ath12k driver [1].
Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
Link: https://lore.kernel.org/linux-wireless/20250211090302.4105141-1-tamizh.raja@oss.qualcomm.com/ # [1]
Signed-off-by: Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260512022351.2033155-2-miaoqing.pan@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/dp_rx.c | 50 +++++++++++++++++++++++--
1 file changed, 47 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/dp_rx.c b/drivers/net/wireless/ath/ath11k/dp_rx.c
index e6ae900006074..7e59260a30b89 100644
--- a/drivers/net/wireless/ath/ath11k/dp_rx.c
+++ b/drivers/net/wireless/ath/ath11k/dp_rx.c
@@ -2513,6 +2513,29 @@ static void ath11k_dp_rx_deliver_msdu(struct ath11k *ar, struct napi_struct *nap
ieee80211_rx_napi(ar->hw, pubsta, msdu, napi);
}
+static bool ath11k_dp_rx_check_nwifi_hdr_len_valid(struct ath11k_base *ab,
+ struct hal_rx_desc *rx_desc,
+ struct sk_buff *msdu)
+{
+ struct ieee80211_hdr *hdr;
+ u8 decap_type;
+ u32 hdr_len;
+
+ decap_type = ath11k_dp_rx_h_msdu_start_decap_type(ab, rx_desc);
+ if (decap_type != DP_RX_DECAP_TYPE_NATIVE_WIFI)
+ return true;
+
+ hdr = (struct ieee80211_hdr *)msdu->data;
+ hdr_len = ieee80211_hdrlen(hdr->frame_control);
+
+ if (likely(hdr_len <= DP_MAX_NWIFI_HDR_LEN))
+ return true;
+
+ ab->soc_stats.invalid_rbm++;
+ WARN_ON_ONCE(1);
+ return false;
+}
+
static int ath11k_dp_rx_process_msdu(struct ath11k *ar,
struct sk_buff *msdu,
struct sk_buff_head *msdu_list,
@@ -2583,6 +2606,11 @@ static int ath11k_dp_rx_process_msdu(struct ath11k *ar,
}
}
+ if (unlikely(!ath11k_dp_rx_check_nwifi_hdr_len_valid(ab, rx_desc, msdu))) {
+ ret = -EINVAL;
+ goto free_out;
+ }
+
ath11k_dp_rx_h_ppdu(ar, rx_desc, rx_status);
ath11k_dp_rx_h_mpdu(ar, msdu, rx_desc, rx_status);
@@ -3244,6 +3272,12 @@ static int ath11k_dp_rx_h_verify_tkip_mic(struct ath11k *ar, struct ath11k_peer
RX_FLAG_IV_STRIPPED | RX_FLAG_DECRYPTED;
skb_pull(msdu, hal_rx_desc_sz);
+ if (unlikely(!ath11k_dp_rx_check_nwifi_hdr_len_valid(ar->ab, rx_desc,
+ msdu))) {
+ dev_kfree_skb_any(msdu);
+ return -EINVAL;
+ }
+
ath11k_dp_rx_h_ppdu(ar, rx_desc, rxs);
ath11k_dp_rx_h_undecap(ar, msdu, rx_desc,
HAL_ENCRYPT_TYPE_TKIP_MIC, rxs, true);
@@ -3936,6 +3970,10 @@ static int ath11k_dp_rx_h_null_q_desc(struct ath11k *ar, struct sk_buff *msdu,
skb_put(msdu, hal_rx_desc_sz + l3pad_bytes + msdu_len);
skb_pull(msdu, hal_rx_desc_sz + l3pad_bytes);
}
+
+ if (unlikely(!ath11k_dp_rx_check_nwifi_hdr_len_valid(ar->ab, desc, msdu)))
+ return -EINVAL;
+
ath11k_dp_rx_h_ppdu(ar, desc, status);
ath11k_dp_rx_h_mpdu(ar, msdu, desc, status);
@@ -3980,7 +4018,7 @@ static bool ath11k_dp_rx_h_reo_err(struct ath11k *ar, struct sk_buff *msdu,
return drop;
}
-static void ath11k_dp_rx_h_tkip_mic_err(struct ath11k *ar, struct sk_buff *msdu,
+static bool ath11k_dp_rx_h_tkip_mic_err(struct ath11k *ar, struct sk_buff *msdu,
struct ieee80211_rx_status *status)
{
u16 msdu_len;
@@ -3988,6 +4026,7 @@ static void ath11k_dp_rx_h_tkip_mic_err(struct ath11k *ar, struct sk_buff *msdu,
u8 l3pad_bytes;
struct ath11k_skb_rxcb *rxcb = ATH11K_SKB_RXCB(msdu);
u32 hal_rx_desc_sz = ar->ab->hw_params.hal_desc_sz;
+ struct ath11k_base *ab = ar->ab;
rxcb->is_first_msdu = ath11k_dp_rx_h_msdu_end_first_msdu(ar->ab, desc);
rxcb->is_last_msdu = ath11k_dp_rx_h_msdu_end_last_msdu(ar->ab, desc);
@@ -3997,6 +4036,9 @@ static void ath11k_dp_rx_h_tkip_mic_err(struct ath11k *ar, struct sk_buff *msdu,
skb_put(msdu, hal_rx_desc_sz + l3pad_bytes + msdu_len);
skb_pull(msdu, hal_rx_desc_sz + l3pad_bytes);
+ if (unlikely(!ath11k_dp_rx_check_nwifi_hdr_len_valid(ab, desc, msdu)))
+ return true;
+
ath11k_dp_rx_h_ppdu(ar, desc, status);
status->flag |= (RX_FLAG_MMIC_STRIPPED | RX_FLAG_MMIC_ERROR |
@@ -4004,19 +4046,21 @@ static void ath11k_dp_rx_h_tkip_mic_err(struct ath11k *ar, struct sk_buff *msdu,
ath11k_dp_rx_h_undecap(ar, msdu, desc,
HAL_ENCRYPT_TYPE_TKIP_MIC, status, false);
+
+ return false;
}
static bool ath11k_dp_rx_h_rxdma_err(struct ath11k *ar, struct sk_buff *msdu,
struct ieee80211_rx_status *status)
{
struct ath11k_skb_rxcb *rxcb = ATH11K_SKB_RXCB(msdu);
- bool drop = false;
+ bool drop;
ar->ab->soc_stats.rxdma_error[rxcb->err_code]++;
switch (rxcb->err_code) {
case HAL_REO_ENTR_RING_RXDMA_ECODE_TKIP_MIC_ERR:
- ath11k_dp_rx_h_tkip_mic_err(ar, msdu, status);
+ drop = ath11k_dp_rx_h_tkip_mic_err(ar, msdu, status);
break;
default:
/* TODO: Review other rxdma error code to check if anything is
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 132/982] ASoC: qcom: q6apm: return error code to consumers on failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 131/982] wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 133/982] ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive Greg Kroah-Hartman
` (856 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Srinivas Kandagatla, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
[ Upstream commit 3075ae5abbc370d2a9a01bd6d554a412d406f5bd ]
Return errors from audioreach_set_media_format() to ensure callers are
notified when media format setup fails.
This could hide failures while programming media format parameters for
individual modules and allow graph setup to continue with incomplete
configuration.
Signed-off-by: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
Link: https://patch.msgid.link/20260528185806.6316-3-srinivas.kandagatla@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/qcom/qdsp6/q6apm.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/sound/soc/qcom/qdsp6/q6apm.c b/sound/soc/qcom/qdsp6/q6apm.c
index f9ee8bbe35f25..48488ba2be212 100644
--- a/sound/soc/qcom/qdsp6/q6apm.c
+++ b/sound/soc/qcom/qdsp6/q6apm.c
@@ -272,10 +272,7 @@ int q6apm_graph_media_format_shmem(struct q6apm_graph *graph,
if (!module)
return -ENODEV;
- audioreach_set_media_format(graph, module, cfg);
-
- return 0;
-
+ return audioreach_set_media_format(graph, module, cfg);
}
EXPORT_SYMBOL_GPL(q6apm_graph_media_format_shmem);
@@ -375,6 +372,7 @@ int q6apm_graph_media_format_pcm(struct q6apm_graph *graph, struct audioreach_mo
struct audioreach_sub_graph *sgs;
struct audioreach_container *container;
struct audioreach_module *module;
+ int ret;
list_for_each_entry(sgs, &info->sg_list, node) {
list_for_each_entry(container, &sgs->container_list, node) {
@@ -383,7 +381,9 @@ int q6apm_graph_media_format_pcm(struct q6apm_graph *graph, struct audioreach_mo
(module->module_id == MODULE_ID_RD_SHARED_MEM_EP))
continue;
- audioreach_set_media_format(graph, module, cfg);
+ ret = audioreach_set_media_format(graph, module, cfg);
+ if (ret)
+ return ret;
}
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 133/982] ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 132/982] ASoC: qcom: q6apm: return error code to consumers on failures Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 134/982] ata: ahci: fail probe if BAR too small for claimed ports Greg Kroah-Hartman
` (855 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cezary Rojewski, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cezary Rojewski <cezary.rojewski@intel.com>
[ Upstream commit eb7107264da8545ba7381a76818bae553e1fd1e4 ]
Revert changes done in commit 489db5d94150 ("ASoC: pcm3168a:
Don't disable pcm3168a when CONFIG_PM defined") and add
pm_runtime_status_suspended() check.
The suspended-check addresses regulator's "unbalanced disables"
warning during driver removal even when CONFIG_PM is enabled.
Signed-off-by: Cezary Rojewski <cezary.rojewski@intel.com>
Link: https://patch.msgid.link/20260525201801.1336936-4-cezary.rojewski@intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/pcm3168a.c | 20 +++++++-------------
1 file changed, 7 insertions(+), 13 deletions(-)
diff --git a/sound/soc/codecs/pcm3168a.c b/sound/soc/codecs/pcm3168a.c
index 329549936bd5c..e5ac1146588cc 100644
--- a/sound/soc/codecs/pcm3168a.c
+++ b/sound/soc/codecs/pcm3168a.c
@@ -820,15 +820,6 @@ int pcm3168a_probe(struct device *dev, struct regmap *regmap)
}
EXPORT_SYMBOL_GPL(pcm3168a_probe);
-static void pcm3168a_disable(struct device *dev)
-{
- struct pcm3168a_priv *pcm3168a = dev_get_drvdata(dev);
-
- regulator_bulk_disable(ARRAY_SIZE(pcm3168a->supplies),
- pcm3168a->supplies);
- clk_disable_unprepare(pcm3168a->scki);
-}
-
void pcm3168a_remove(struct device *dev)
{
struct pcm3168a_priv *pcm3168a = dev_get_drvdata(dev);
@@ -840,10 +831,12 @@ void pcm3168a_remove(struct device *dev)
* The asserted level of GPIO_ACTIVE_LOW is LOW.
*/
gpiod_set_value_cansleep(pcm3168a->gpio_rst, 1);
+
pm_runtime_disable(dev);
-#ifndef CONFIG_PM
- pcm3168a_disable(dev);
-#endif
+ if (!pm_runtime_status_suspended(dev)) {
+ regulator_bulk_disable(ARRAY_SIZE(pcm3168a->supplies), pcm3168a->supplies);
+ clk_disable_unprepare(pcm3168a->scki);
+ }
}
EXPORT_SYMBOL_GPL(pcm3168a_remove);
@@ -899,7 +892,8 @@ static int pcm3168a_rt_suspend(struct device *dev)
regcache_cache_only(pcm3168a->regmap, true);
- pcm3168a_disable(dev);
+ regulator_bulk_disable(ARRAY_SIZE(pcm3168a->supplies), pcm3168a->supplies);
+ clk_disable_unprepare(pcm3168a->scki);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 134/982] ata: ahci: fail probe if BAR too small for claimed ports
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 133/982] ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 135/982] ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach Greg Kroah-Hartman
` (854 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, liyouhong, Damien Le Moal,
Niklas Cassel, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: liyouhong <liyouhong@kylinos.cn>
[ Upstream commit c4086c6e1af757e1ff26fa2d2926b3ec0195de79 ]
When an AHCI controller is disabled in BIOS, its HOST_CAP register may
contain a bogus value, e.g. 0xFFFFFFFF.
Since CAP.NP (Number of Ports) is a zeroes based 5-bit register field,
a value of 0x1f means 32 ports. If CAP.NP claims more ports than can
physically fit within the mapped BAR region, accessing port registers
beyond the BAR boundary causes a kernel panic.
Add validation in ahci_init_one() to check that the BAR size is
sufficient for the number of ports claimed in CAP.NP. The check
calculates the required MMIO size as:
required_size = 0x100 (global registers) + max_ports * 0x80
If required_size exceeds the actual BAR size, the probe fails with
-ENODEV, preventing the panic and providing a clear error message.
Reported-by: liyouhong <liyouhong@kylinos.cn>
Closes: https://lore.kernel.org/all/20260422080322.1006592-1-dayou5941@163.com/
Suggested-by: Damien Le Moal <dlemoal@kernel.org>
Suggested-by: Niklas Cassel <cassel@kernel.org>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: liyouhong <liyouhong@kylinos.cn>
[cassel: commit log]
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ata/ahci.c | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/drivers/ata/ahci.c b/drivers/ata/ahci.c
index cdc18f95cb59f..de996b7c51002 100644
--- a/drivers/ata/ahci.c
+++ b/drivers/ata/ahci.c
@@ -1768,6 +1768,24 @@ static ssize_t remapped_nvme_show(struct device *dev,
static DEVICE_ATTR_RO(remapped_nvme);
+static int ahci_validate_bar_size(struct pci_dev *pdev, int bar,
+ struct ahci_host_priv *hpriv)
+{
+ u32 cap = readl(hpriv->mmio + HOST_CAP);
+ unsigned int max_ports = ahci_nr_ports(cap);
+ u32 last_port_end = 0x100 + (max_ports * 0x80);
+ resource_size_t bar_size = pci_resource_len(pdev, bar);
+
+ if (last_port_end > bar_size) {
+ dev_warn(&pdev->dev,
+ "BAR%d too small for %u ports (last port ends at %#x, BAR %pa)\n",
+ bar, max_ports, last_port_end, &bar_size);
+ return -ENODEV;
+ }
+
+ return 0;
+}
+
static int ahci_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
{
unsigned int board_id = ent->driver_data;
@@ -1870,6 +1888,10 @@ static int ahci_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
hpriv->mmio = pcim_iomap_table(pdev)[ahci_pci_bar];
+ rc = ahci_validate_bar_size(pdev, ahci_pci_bar, hpriv);
+ if (rc)
+ return rc;
+
/* detect remapped nvme devices */
ahci_remap_check(pdev, ahci_pci_bar, hpriv);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 135/982] ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 134/982] ata: ahci: fail probe if BAR too small for claimed ports Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 136/982] net: qrtr: fix node refcount leak on ctrl packet alloc failure Greg Kroah-Hartman
` (853 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen Pei, Dan Williams (nvidia),
Alison Schofield, Rafael J. Wysocki, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Pei <cp0613@linux.alibaba.com>
[ Upstream commit 3a59c3b772e5dc0cedecce8e7fbf7c2d6245b643 ]
PCI root bridges enumerated by acpi_pci_root_add() can be the _DEP
supplier for other ACPI consumers, most notably ACPI0017 CXL root
devices whose probe path depends on acpi_pci_find_root() succeeding.
Once the root bus has been added, those consumers can safely be
enumerated, so notify them by clearing the dependency.
Call acpi_dev_clear_dependencies() at the end of acpi_pci_root_add(),
after pci_bus_add_devices(), following the same pattern used by other
ACPI suppliers such as the EC (drivers/acpi/ec.c) and the ACPI PCI
Link device (drivers/acpi/pci_link.c). The clear is intentionally
done only on the success path; on the error paths the supplier did
not attach and consumers must keep dep_unmet set.
This is a prerequisite for honoring _DEP on ACPI0016 host bridges,
which matters on architectures where the probe order of acpi_pci_root
relative to cxl_acpi is not guaranteed (e.g. RISC-V).
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
Suggested-by: Dan Williams (nvidia) <djbw@kernel.org>
Tested-by: Alison Schofield <alison.schofield@intel.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260526025118.38935-2-cp0613@linux.alibaba.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/pci_root.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/acpi/pci_root.c b/drivers/acpi/pci_root.c
index 92e7aefcce81b..4201677fa748b 100644
--- a/drivers/acpi/pci_root.c
+++ b/drivers/acpi/pci_root.c
@@ -763,6 +763,10 @@ static int acpi_pci_root_add(struct acpi_device *device,
pci_lock_rescan_remove();
pci_bus_add_devices(root->bus);
pci_unlock_rescan_remove();
+
+ /* Clear _DEP dependencies to allow consumers to enumerate */
+ acpi_dev_clear_dependencies(device);
+
return 1;
remove_dmar:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 136/982] net: qrtr: fix node refcount leak on ctrl packet alloc failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 135/982] ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 137/982] net: wwan: t7xx: Add delay between MD and SAP suspend Greg Kroah-Hartman
` (852 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alexander Lobakin,
Manivannan Sadhasivam, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
[ Upstream commit 3b09ff54114566864eea59020f6b69c5bb325b9d ]
qrtr_send_resume_tx() calls qrtr_node_lookup() which takes a
reference on the returned node. If the subsequent call to
qrtr_alloc_ctrl_packet() fails due to memory allocation failure, the
function returns -ENOMEM without calling qrtr_node_release() to
release the node reference.
Add qrtr_node_release(node) before returning on the allocation failure
path to properly release the reference.
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Alexander Lobakin <aleksander.lobakin@intel.com>
Reviewed-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260528080019.1176700-1-vulab@iscas.ac.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/qrtr/af_qrtr.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/net/qrtr/af_qrtr.c b/net/qrtr/af_qrtr.c
index d13ca058fef6d..7e5527ca6ab92 100644
--- a/net/qrtr/af_qrtr.c
+++ b/net/qrtr/af_qrtr.c
@@ -1004,8 +1004,10 @@ static int qrtr_send_resume_tx(struct qrtr_cb *cb)
return -EINVAL;
skb = qrtr_alloc_ctrl_packet(&pkt, GFP_KERNEL);
- if (!skb)
+ if (!skb) {
+ qrtr_node_release(node);
return -ENOMEM;
+ }
pkt->cmd = cpu_to_le32(QRTR_TYPE_RESUME_TX);
pkt->client.node = cpu_to_le32(cb->dst_node);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 137/982] net: wwan: t7xx: Add delay between MD and SAP suspend
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 136/982] net: qrtr: fix node refcount leak on ctrl packet alloc failure Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 138/982] iommu/rockchip: disable fetch dte time limit Greg Kroah-Hartman
` (851 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jose Ignacio Tornos Martinez,
Loic Poulain, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
[ Upstream commit ae733795e593272f67d607c09d2a00637ac13ed0 ]
SAP (Service Access Point) suspend occasionally times out with error
-110 (ETIMEDOUT), followed by modem port errors and complete modem
failure requiring a system reboot to recover.
Error symptoms:
mtk_t7xx 0000:72:00.0: [PM] SAP suspend error: -110
mtk_t7xx 0000:72:00.0: can't suspend (...returned -110)
mtk_t7xx 0000:07:00.0: Failed to send skb: -22
mtk_t7xx 0000:07:00.0: Write error on MBIM port, -22
The modem firmware needs time after receiving the MD (modem) suspend
request to complete internal operations before it is ready to accept
the SAP suspend request. Without this delay, if runtime PM attempts
to suspend while the firmware is busy, the SAP suspend command times
out, leaving the modem in an unrecoverable state.
Root cause and userspace interaction:
ModemManager 1.24+ includes changes that reduce the likelihood of this
issue by ensuring the modem is in a low-power state before the kernel
attempts runtime suspend. However, the kernel driver should not depend
on specific userspace behavior or ModemManager versions. Older versions
(1.20-1.22) are still widely deployed, and the kernel should be robust
regardless of userspace implementation details.
There appears to be no hardware status register or other mechanism
available to query whether the firmware is ready for SAP suspend.
A delay between the two suspend requests is the most reliable solution
found through testing.
Add a 50ms delay between MD suspend and SAP suspend. This gives the
firmware adequate time to complete internal operations without adding
significant latency to the suspend path. This makes the driver robust
across all ModemManager versions and system conditions.
Testing: 96+ hours of continuous operation with ModemManager 1.20.2
and Fibocom FM350-GL modem. Zero SAP suspend timeouts observed across
2000+ successful suspend/resume cycles. Previously failed within
24 hours with 100% reproducibility.
Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260527061451.12710-1-jtornosm@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wwan/t7xx/t7xx_pci.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wwan/t7xx/t7xx_pci.c b/drivers/net/wwan/t7xx/t7xx_pci.c
index 91256e005b846..b19bb261e76bf 100644
--- a/drivers/net/wwan/t7xx/t7xx_pci.c
+++ b/drivers/net/wwan/t7xx/t7xx_pci.c
@@ -313,6 +313,9 @@ static int __t7xx_pci_pm_suspend(struct pci_dev *pdev)
goto abort_suspend;
}
+ /* Delay to prevent SAP suspend timeout */
+ msleep(50);
+
ret = t7xx_send_pm_request(t7xx_dev, H2D_CH_SUSPEND_REQ_AP);
if (ret) {
t7xx_send_pm_request(t7xx_dev, H2D_CH_RESUME_REQ);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 138/982] iommu/rockchip: disable fetch dte time limit
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 137/982] net: wwan: t7xx: Add delay between MD and SAP suspend Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 139/982] fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib Greg Kroah-Hartman
` (850 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Simon Xue, Sven Püschel,
Heiko Stuebner, Joerg Roedel, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Simon Xue <xxm@rock-chips.com>
[ Upstream commit 8d4346ecd4950ae08cc76a6de327c264e846758c ]
Disable the Bit 31 of the AUTO_GATING iommu register, as it causes
hangups with the RGA3 (Raster Graphics Acceleration 3) peripheral.
The RGA3 register description of the TRM already states that the bit
must be set to 1. The vendor kernel sets the bit unconditionally to
1 to fix VOP (Video Output Processor) screen black issues. This patch
squashes the 2 vendor kernel commits with the following commit messages:
Master fetch data and cpu update page table may work in parallel, may
have the following procedure:
master cpu
fetch dte update page tabl
| |
(make dte invalid) <- zap iotlb entry
| |
fetch dte again
(make dte invalid) <- zap iotlb entry
| |
fetch dte again
(make dte invalid) <- zap iotlb entry
| |
fetch dte again
(make iommu block) <- zap iotlb entry
New iommu version has the above bug, if fetch dte consecutively four
times, then it will be blocked. Fortunately, we can set bit 31 of
register MMU_AUTO_GATING to 1 to make it work as old version which does
not have this issue.
This issue only appears on RV1126 so far, so make a workaround dedicated
to "rockchip,rv1126" machine type.
iommu/rockchip: fix vop blocked and screen black on RK356X and RK3588
RK3568 and RK3588 has the same issue as RV1126/RV1109 that caused by
dte fetch time limit, So we can set BIT(31) of register 0x24 default
to 1 as a workaround.
Signed-off-by: Simon Xue <xxm@rock-chips.com>
Signed-off-by: Sven Püschel <s.pueschel@pengutronix.de>
Acked-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/rockchip-iommu.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/iommu/rockchip-iommu.c b/drivers/iommu/rockchip-iommu.c
index 43bb577a26e59..5ce951bbd69af 100644
--- a/drivers/iommu/rockchip-iommu.c
+++ b/drivers/iommu/rockchip-iommu.c
@@ -73,6 +73,8 @@
#define SPAGE_ORDER 12
#define SPAGE_SIZE (1 << SPAGE_ORDER)
+#define DISABLE_FETCH_DTE_TIME_LIMIT BIT(31)
+
/*
* Support mapping any size that fits in one page table:
* 4 KiB to 4 MiB
@@ -922,6 +924,7 @@ static int rk_iommu_enable(struct rk_iommu *iommu)
struct iommu_domain *domain = iommu->domain;
struct rk_iommu_domain *rk_domain = to_rk_domain(domain);
int ret, i;
+ u32 auto_gate;
ret = clk_bulk_enable(iommu->num_clocks, iommu->clocks);
if (ret)
@@ -940,6 +943,11 @@ static int rk_iommu_enable(struct rk_iommu *iommu)
rk_ops->mk_dtentries(rk_domain->dt_dma));
rk_iommu_base_command(iommu->bases[i], RK_MMU_CMD_ZAP_CACHE);
rk_iommu_write(iommu->bases[i], RK_MMU_INT_MASK, RK_MMU_IRQ_MASK);
+
+ /* Workaround for iommu blocked, BIT(31) default to 1 */
+ auto_gate = rk_iommu_read(iommu->bases[i], RK_MMU_AUTO_GATING);
+ auto_gate |= DISABLE_FETCH_DTE_TIME_LIMIT;
+ rk_iommu_write(iommu->bases[i], RK_MMU_AUTO_GATING, auto_gate);
}
ret = rk_iommu_enable_paging(iommu);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 139/982] fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 138/982] iommu/rockchip: disable fetch dte time limit Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 140/982] fs/ntfs3: validate index entry key bounds Greg Kroah-Hartman
` (849 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, ZhengYuan Huang, Konstantin Komarov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ZhengYuan Huang <gality369@gmail.com>
[ Upstream commit b1c1101067d9536bcb0fe023b96ee2dde5535959 ]
[BUG]
A corrupted ntfs3 image can hit a NULL function pointer call in
generic_perform_write() after toggling system.ntfs_attrib and then
overwriting system.dos_attrib on the same file.
BUG: kernel NULL pointer dereference, address: 0000000000000000
\#PF: supervisor instruction fetch in kernel mode
\#PF: error_code(0x0010) - not-present page
PGD bed5067 P4D bed5067 PUD 0
Oops: Oops: 0010 [#1] SMP KASAN NOPTI
RIP: 0010:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
RSP: 0018:ffff88801025f988 EFLAGS: 00010246
Call Trace:
generic_perform_write+0x409/0x8c0 mm/filemap.c:4255
__generic_file_write_iter+0x1bb/0x200 mm/filemap.c:4372
ntfs_file_write_iter+0xcd9/0x1c20 fs/ntfs3/file.c:1253
new_sync_write fs/read_write.c:593 [inline]
vfs_write+0x63b/0xf70 fs/read_write.c:686
ksys_write+0x133/0x250 fs/read_write.c:738
__do_sys_write fs/read_write.c:749 [inline]
__se_sys_write fs/read_write.c:746 [inline]
__x64_sys_write+0x77/0xc0 fs/read_write.c:746
...
[CAUSE]
system.ntfs_attrib updates ATTR_DATA flags via ni_new_attr_flags()
and switches i_mapping->a_ops to ntfs_aops_cmpr when
FILE_ATTRIBUTE_COMPRESSED is set. system.dos_attrib then overwrites
ni->std_fa from a one-byte DOS attribute value, clearing the compression
bit without updating ATTR_DATA or the mapping operations.
Old buffered writes use is_compressed(ni) to choose
__generic_file_write_iter(). That leaves generic_perform_write() calling
a NULL write_begin callback from ntfs_aops_cmpr.
[FIX]
Treat system.dos_attrib as a low-byte DOS attribute update and preserve the
existing non-DOS attribute bits in ni->std_fa. This keeps compressed and
sparse state consistent with ATTR_DATA and the mapping operations while
keeping the existing DOS attribute semantics intact.
Signed-off-by: ZhengYuan Huang <gality369@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs3/xattr.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/ntfs3/xattr.c b/fs/ntfs3/xattr.c
index 409f9545e9cd5..a235050e92098 100644
--- a/fs/ntfs3/xattr.c
+++ b/fs/ntfs3/xattr.c
@@ -874,7 +874,9 @@ static noinline int ntfs_setxattr(const struct xattr_handler *handler,
!memcmp(name, SYSTEM_DOS_ATTRIB, sizeof(SYSTEM_DOS_ATTRIB))) {
if (sizeof(u8) != size)
goto out;
- new_fa = cpu_to_le32(*(u8 *)value);
+ /* system.dos_attrib only covers the low DOS attribute byte. */
+ new_fa = (ni->std_fa & ~cpu_to_le32(0xff)) |
+ cpu_to_le32(*(u8 *)value);
goto set_new_fa;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 140/982] fs/ntfs3: validate index entry key bounds
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 139/982] fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 141/982] ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() Greg Kroah-Hartman
` (848 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, ZhengYuan Huang, Konstantin Komarov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ZhengYuan Huang <gality369@gmail.com>
[ Upstream commit 98d6e5d9dc1d34dcffc61549617581a5fe1ef807 ]
[BUG]
A malformed NTFS directory index entry can advertise a key_size larger
than the bytes actually present in its NTFS_DE payload. Directory lookup
then passes that malformed key to cmp_fnames(), which can read past the
end of the kmalloc'ed index buffer.
BUG: KASAN: slab-out-of-bounds in fname_full_size fs/ntfs3/ntfs.h:590 [inline]
BUG: KASAN: slab-out-of-bounds in cmp_fnames+0x1ea/0x230 fs/ntfs3/index.c:46
Read of size 1 at addr ffff88801c313018 by task syz.6.3365/9279
Call Trace:
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0xbe/0x130 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xd1/0x650 mm/kasan/report.c:482
kasan_report+0xfb/0x140 mm/kasan/report.c:595
__asan_report_load1_noabort+0x14/0x30 mm/kasan/report_generic.c:378
fname_full_size fs/ntfs3/ntfs.h:590 [inline]
cmp_fnames+0x1ea/0x230 fs/ntfs3/index.c:46
hdr_find_e.isra.0+0x3ed/0x670 fs/ntfs3/index.c:762
indx_find+0x4b5/0x900 fs/ntfs3/index.c:1186
dir_search_u+0x2c0/0x460 fs/ntfs3/dir.c:254
ntfs_lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85
__lookup_slow+0x241/0x450 fs/namei.c:1816
lookup_slow fs/namei.c:1833 [inline]
walk_component+0x31c/0x570 fs/namei.c:2151
link_path_walk+0x592/0xd60 fs/namei.c:2519
path_lookupat+0x138/0x660 fs/namei.c:2675
filename_lookup+0x1f3/0x560 fs/namei.c:2705
filename_setxattr+0xad/0x1c0 fs/xattr.c:660
path_setxattrat+0x1d8/0x280 fs/xattr.c:713
__do_sys_lsetxattr fs/xattr.c:754 [inline]
__se_sys_lsetxattr fs/xattr.c:750 [inline]
__x64_sys_lsetxattr+0xd0/0x150 fs/xattr.c:750
...
Allocated by task 9279:
kasan_save_stack+0x39/0x70 mm/kasan/common.c:56
kasan_save_track+0x14/0x40 mm/kasan/common.c:77
kasan_save_alloc_info+0x37/0x60 mm/kasan/generic.c:573
poison_kmalloc_redzone mm/kasan/common.c:400 [inline]
__kasan_kmalloc+0xc3/0xd0 mm/kasan/common.c:417
kasan_kmalloc include/linux/kasan.h:262 [inline]
__do_kmalloc_node mm/slub.c:5650 [inline]
__kmalloc_noprof+0x2bd/0x900 mm/slub.c:5662
kmalloc_noprof include/linux/slab.h:961 [inline]
indx_read+0x41d/0xad0 fs/ntfs3/index.c:1059
indx_find+0x447/0x900 fs/ntfs3/index.c:1179
dir_search_u+0x2c0/0x460 fs/ntfs3/dir.c:254
ntfs_lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85
__lookup_slow+0x241/0x450 fs/namei.c:1816
lookup_slow fs/namei.c:1833 [inline]
walk_component+0x31c/0x570 fs/namei.c:2151
link_path_walk+0x592/0xd60 fs/namei.c:2519
path_lookupat+0x138/0x660 fs/namei.c:2675
filename_lookup+0x1f3/0x560 fs/namei.c:2705
filename_setxattr+0xad/0x1c0 fs/xattr.c:660
path_setxattrat+0x1d8/0x280 fs/xattr.c:713
__do_sys_lsetxattr fs/xattr.c:754 [inline]
__se_sys_lsetxattr fs/xattr.c:750 [inline]
__x64_sys_lsetxattr+0xd0/0x150 fs/xattr.c:750
...
[CAUSE]
The index-header validators only validated INDEX_HDR-level geometry.
They did not walk each NTFS_DE to verify entry alignment, subnode
layout, or that key_size fit inside the entry payload. They also
allowed a last sentinel entry to carry a non-zero key_size.
[FIX]
Walk every NTFS_DE in ntfs3's index-header validators and reject
entries with invalid layout, mismatched subnode state, oversized
key_size, or non-zero sentinel keys before lookup or log replay can
consume them.
Signed-off-by: ZhengYuan Huang <gality369@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs3/fslog.c | 26 ++++++++++++++++++++------
fs/ntfs3/index.c | 37 ++++++++++++++++++++++++++++++++++++-
2 files changed, 56 insertions(+), 7 deletions(-)
diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index c0f4822699a9b..c7762a24f8fed 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -2645,11 +2645,12 @@ static int read_next_log_rec(struct ntfs_log *log, struct lcb *lcb, u64 *lsn)
bool check_index_header(const struct INDEX_HDR *hdr, size_t bytes)
{
+ const bool has_subnode = hdr_has_subnode(hdr);
__le16 mask;
u32 min_de, de_off, used, total;
const struct NTFS_DE *e;
- if (hdr_has_subnode(hdr)) {
+ if (has_subnode) {
min_de = sizeof(struct NTFS_DE) + sizeof(u64);
mask = NTFS_IE_HAS_SUBNODES;
} else {
@@ -2666,20 +2667,33 @@ bool check_index_header(const struct INDEX_HDR *hdr, size_t bytes)
return false;
}
- e = Add2Ptr(hdr, de_off);
+ e = (const struct NTFS_DE *)((const u8 *)hdr + de_off);
for (;;) {
u16 esize = le16_to_cpu(e->size);
- struct NTFS_DE *next = Add2Ptr(e, esize);
+ u16 key_size = le16_to_cpu(e->key_size);
+ u16 data_size;
- if (esize < min_de || PtrOffset(hdr, next) > used ||
+ if (!IS_ALIGNED(esize, 8) || esize < min_de ||
(e->flags & NTFS_IE_HAS_SUBNODES) != mask) {
return false;
}
- if (de_is_last(e))
+ if (size_add(de_off, esize) > used)
+ return false;
+
+ if (de_is_last(e)) {
+ if (key_size)
+ return false;
+
break;
+ }
+
+ data_size = esize - min_de;
+ if (key_size > data_size)
+ return false;
- e = next;
+ de_off += esize;
+ e = (const struct NTFS_DE *)((const u8 *)hdr + de_off);
}
return true;
diff --git a/fs/ntfs3/index.c b/fs/ntfs3/index.c
index 90720adb4d839..ce1e9cff8d1b7 100644
--- a/fs/ntfs3/index.c
+++ b/fs/ntfs3/index.c
@@ -612,16 +612,51 @@ static const struct NTFS_DE *hdr_insert_head(struct INDEX_HDR *hdr,
*/
static bool index_hdr_check(const struct INDEX_HDR *hdr, u32 bytes)
{
+ const bool has_subnode = hdr_has_subnode(hdr);
+ const u16 min_size = sizeof(struct NTFS_DE) +
+ (has_subnode ? sizeof(u64) : 0);
u32 end = le32_to_cpu(hdr->used);
u32 tot = le32_to_cpu(hdr->total);
u32 off = le32_to_cpu(hdr->de_off);
+ const struct NTFS_DE *e;
if (!IS_ALIGNED(off, 8) || tot > bytes || end > tot ||
- size_add(off, sizeof(struct NTFS_DE)) > end) {
+ size_add(off, min_size) > end) {
/* incorrect index buffer. */
return false;
}
+ /* Ensure every key stays inside its entry before lookup walks it. */
+ e = (const struct NTFS_DE *)((const u8 *)hdr + off);
+ for (;;) {
+ u16 e_size = le16_to_cpu(e->size);
+ u16 key_size = le16_to_cpu(e->key_size);
+ u16 data_size;
+
+ if (!IS_ALIGNED(e_size, 8) || e_size < min_size ||
+ de_has_vcn(e) != has_subnode) {
+ /* incorrect index entry. */
+ return false;
+ }
+
+ if (size_add(off, e_size) > end)
+ return false;
+
+ if (de_is_last(e)) {
+ if (key_size)
+ return false;
+
+ break;
+ }
+
+ data_size = e_size - min_size;
+ if (key_size > data_size)
+ return false;
+
+ off += e_size;
+ e = (const struct NTFS_DE *)((const u8 *)hdr + off);
+ }
+
return true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 141/982] ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 140/982] fs/ntfs3: validate index entry key bounds Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 142/982] ASoC: codecs: rk3328: Use managed GPIO and clock helpers Greg Kroah-Hartman
` (847 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alessandro Schino,
Konstantin Komarov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alessandro Schino <7991aleschino@gmail.com>
[ Upstream commit aa1bdbb39f49c5bc9779316891c40005517842a5 ]
The bounds check in ntfs_dir_emit() compares fname->name_len (a
character count) against e->size (a byte count) without accounting
for the 2-byte-per-character UTF-16LE encoding or the ATTR_FILE_NAME
header size:
if (fname->name_len + sizeof(struct NTFS_DE) > le16_to_cpu(e->size))
This computes: name_len + 16 > e_size
The correct check must account for the ATTR_FILE_NAME header (66 bytes
before the name) and the UTF-16LE character size (2 bytes each):
sizeof(NTFS_DE) + offsetof(ATTR_FILE_NAME, name) +
name_len * sizeof(short) > e_size
Which computes: 16 + 66 + name_len * 2 > e_size
The correct calculation already exists as fname_full_size() in ntfs.h
and is used in cmp_fnames(), namei.c, and fslog.c, but was not used
in the readdir path.
A crafted NTFS image with an index entry containing a small e->size
but large fname->name_len bypasses the current check, causing
ntfs_utf16_to_nls() to read past the entry boundary.
Additionally, add a key_size validation in hdr_find_e() to ensure the
declared key_size does not exceed the available entry data, preventing
comparison functions from reading past entry boundaries on the lookup
path.
Signed-off-by: Alessandro Schino <7991aleschino@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs3/dir.c | 4 +++-
fs/ntfs3/index.c | 4 ++++
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/fs/ntfs3/dir.c b/fs/ntfs3/dir.c
index c49e64ebbd0a9..ca13b5a1fdabf 100644
--- a/fs/ntfs3/dir.c
+++ b/fs/ntfs3/dir.c
@@ -304,7 +304,9 @@ static inline bool ntfs_dir_emit(struct ntfs_sb_info *sbi,
if (sbi->options->nohidden && (fname->dup.fa & FILE_ATTRIBUTE_HIDDEN))
return true;
- if (fname->name_len + sizeof(struct NTFS_DE) > le16_to_cpu(e->size))
+ if (sizeof(struct NTFS_DE) +
+ offsetof(struct ATTR_FILE_NAME, name) +
+ fname->name_len * sizeof(short) > le16_to_cpu(e->size))
return true;
name_len = ntfs_utf16_to_nls(sbi, fname->name, fname->name_len, name,
diff --git a/fs/ntfs3/index.c b/fs/ntfs3/index.c
index ce1e9cff8d1b7..82feda419c0aa 100644
--- a/fs/ntfs3/index.c
+++ b/fs/ntfs3/index.c
@@ -794,6 +794,10 @@ static struct NTFS_DE *hdr_find_e(const struct ntfs_index *indx,
binary_search:
e_key_len = le16_to_cpu(e->key_size);
+ /* Validate key_size fits within the entry data area. */
+ if (e_key_len > le16_to_cpu(e->size) - sizeof(struct NTFS_DE))
+ return NULL;
+
diff2 = (*cmp)(key, key_len, e + 1, e_key_len, ctx);
if (diff2 > 0) {
if (found) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 142/982] ASoC: codecs: rk3328: Use managed GPIO and clock helpers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 141/982] ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 143/982] ALSA: seq: oss: Reject reads that cannot fit the next event Greg Kroah-Hartman
` (846 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cássio Gabriel <cassiogabrielcontato@gmail.com>
[ Upstream commit 0cf3489bba9ad13aae052232e223e19a620fe7a7 ]
rk3328_platform_probe() acquires the mute GPIO with gpiod_get_optional()
but never releases it. It also enables mclk and pclk manually while
relying on probe error labels for unwind, and the driver has no platform
remove callback to disable those clocks after a successful unbind.
This path has already needed fixes for missing clock unwinds on probe
errors. Use devm_gpiod_get_optional() and devm_clk_get_enabled() so the
GPIO and enabled clock lifetimes are tied to the device. This removes the
manual error labels and makes both probe failure and driver unbind follow
the normal devres cleanup path.
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260525-asoc-rk3328-devm-resources-v1-1-2abde0006f89@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/rk3328_codec.c | 54 ++++++++-------------------------
1 file changed, 13 insertions(+), 41 deletions(-)
diff --git a/sound/soc/codecs/rk3328_codec.c b/sound/soc/codecs/rk3328_codec.c
index 1d523bfd9d84f..11d797288027a 100644
--- a/sound/soc/codecs/rk3328_codec.c
+++ b/sound/soc/codecs/rk3328_codec.c
@@ -426,7 +426,6 @@ static int rk3328_platform_probe(struct platform_device *pdev)
struct rk3328_codec_priv *rk3328;
struct regmap *grf;
void __iomem *base;
- int ret = 0;
rk3328 = devm_kzalloc(&pdev->dev, sizeof(*rk3328), GFP_KERNEL);
if (!rk3328)
@@ -442,14 +441,13 @@ static int rk3328_platform_probe(struct platform_device *pdev)
regmap_write(grf, RK3328_GRF_SOC_CON2,
(BIT(14) << 16 | BIT(14)));
- ret = of_property_read_u32(rk3328_np, "spk-depop-time-ms",
- &rk3328->spk_depop_time);
- if (ret < 0) {
+ if (of_property_read_u32(rk3328_np, "spk-depop-time-ms",
+ &rk3328->spk_depop_time)) {
dev_info(&pdev->dev, "spk_depop_time use default value.\n");
rk3328->spk_depop_time = 200;
}
- rk3328->mute = gpiod_get_optional(&pdev->dev, "mute", GPIOD_OUT_HIGH);
+ rk3328->mute = devm_gpiod_get_optional(&pdev->dev, "mute", GPIOD_OUT_HIGH);
if (IS_ERR(rk3328->mute))
return PTR_ERR(rk3328->mute);
/*
@@ -462,57 +460,31 @@ static int rk3328_platform_probe(struct platform_device *pdev)
regmap_write(grf, RK3328_GRF_SOC_CON10, BIT(17) | BIT(1));
}
- rk3328->mclk = devm_clk_get(&pdev->dev, "mclk");
+ rk3328->mclk = devm_clk_get_enabled(&pdev->dev, "mclk");
if (IS_ERR(rk3328->mclk))
return PTR_ERR(rk3328->mclk);
- ret = clk_prepare_enable(rk3328->mclk);
- if (ret)
- return ret;
clk_set_rate(rk3328->mclk, INITIAL_FREQ);
- rk3328->pclk = devm_clk_get(&pdev->dev, "pclk");
- if (IS_ERR(rk3328->pclk)) {
- dev_err(&pdev->dev, "can't get acodec pclk\n");
- ret = PTR_ERR(rk3328->pclk);
- goto err_unprepare_mclk;
- }
-
- ret = clk_prepare_enable(rk3328->pclk);
- if (ret < 0) {
- dev_err(&pdev->dev, "failed to enable acodec pclk\n");
- goto err_unprepare_mclk;
- }
+ rk3328->pclk = devm_clk_get_enabled(&pdev->dev, "pclk");
+ if (IS_ERR(rk3328->pclk))
+ return dev_err_probe(&pdev->dev, PTR_ERR(rk3328->pclk),
+ "failed to get or enable acodec pclk\n");
base = devm_platform_ioremap_resource(pdev, 0);
- if (IS_ERR(base)) {
- ret = PTR_ERR(base);
- goto err_unprepare_pclk;
- }
+ if (IS_ERR(base))
+ return PTR_ERR(base);
rk3328->regmap = devm_regmap_init_mmio(&pdev->dev, base,
&rk3328_codec_regmap_config);
- if (IS_ERR(rk3328->regmap)) {
- ret = PTR_ERR(rk3328->regmap);
- goto err_unprepare_pclk;
- }
+ if (IS_ERR(rk3328->regmap))
+ return PTR_ERR(rk3328->regmap);
platform_set_drvdata(pdev, rk3328);
- ret = devm_snd_soc_register_component(&pdev->dev, &soc_codec_rk3328,
+ return devm_snd_soc_register_component(&pdev->dev, &soc_codec_rk3328,
rk3328_dai,
ARRAY_SIZE(rk3328_dai));
- if (ret)
- goto err_unprepare_pclk;
-
- return 0;
-
-err_unprepare_pclk:
- clk_disable_unprepare(rk3328->pclk);
-
-err_unprepare_mclk:
- clk_disable_unprepare(rk3328->mclk);
- return ret;
}
static const struct of_device_id rk3328_codec_of_match[] __maybe_unused = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 143/982] ALSA: seq: oss: Reject reads that cannot fit the next event
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 142/982] ASoC: codecs: rk3328: Use managed GPIO and clock helpers Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 144/982] dpaa2-switch: rework FDB management on the bridge leave path Greg Kroah-Hartman
` (845 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cássio Gabriel <cassiogabrielcontato@gmail.com>
[ Upstream commit 611f538253d970f4d152003841544e875828d015 ]
snd_seq_oss_read() checks whether the next queued OSS sequencer event
fits in the remaining userspace buffer before removing it from the read
queue.
The check is inverted. It currently stops when the event is smaller than
the remaining buffer, so a normal 4-byte event is not copied for an
8-byte read buffer. Conversely, an 8-byte event can be copied for a
smaller read count.
Break only when the remaining userspace buffer is smaller than the next
event, and report -EINVAL if no complete event has been copied. This
prevents an undersized read from looking like end-of-file while leaving
the event queued for a later read with a large enough buffer.
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260602-alsa-seq-oss-read-size-check-v1-1-10e59b1742e0@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/core/seq/oss/seq_oss_rw.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/sound/core/seq/oss/seq_oss_rw.c b/sound/core/seq/oss/seq_oss_rw.c
index 307ef98c44c7b..45bb458597708 100644
--- a/sound/core/seq/oss/seq_oss_rw.c
+++ b/sound/core/seq/oss/seq_oss_rw.c
@@ -57,7 +57,8 @@ snd_seq_oss_read(struct seq_oss_devinfo *dp, char __user *buf, int count)
break;
}
ev_len = ev_length(&rec);
- if (ev_len < count) {
+ if (count < ev_len) {
+ err = -EINVAL;
snd_seq_oss_readq_unlock(readq, flags);
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 144/982] dpaa2-switch: rework FDB management on the bridge leave path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 143/982] ALSA: seq: oss: Reject reads that cannot fit the next event Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 145/982] dpaa2-switch: fix the error path in dpaa2_switch_rx() Greg Kroah-Hartman
` (844 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ioana Ciornei, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ioana Ciornei <ioana.ciornei@nxp.com>
[ Upstream commit efc1d92eacf03afa6f4d53bf7120e059b6f961f2 ]
On bridge leave, the dpaa2_switch_port_set_fdb() function always
allocates a new FDB for the port which is becoming standalone. In case
no FDB is found, then the port leaving a bridge will continue to use the
current one.
The above logic does not cover the case in which there are multiple
bridges which have ports from the same DPSW instance. In this case, when
the last port leaves bridge #1, it finds an unused FDB to switch to, but
the old FDB is not marked as unused. Since the number of FDBs is equal
to the number of DPSW interfaces, this will eventually lead to multiple
ports sharing the same FDB.
Fix this by changing how we are managing the FDBs on the leave path.
Instead of directly allocating a new FDB, first verify if the current
port is the last one to leave a bridge. If this is the case, then
continue to use the current FDB and only allocate another FDB if there
are other ports remaining in the bridge.
Signed-off-by: Ioana Ciornei <ioana.ciornei@nxp.com>
Link: https://patch.msgid.link/20260528173452.1953102-2-ioana.ciornei@nxp.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../ethernet/freescale/dpaa2/dpaa2-switch.c | 31 ++++++++++++++-----
1 file changed, 24 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
index 8f7c3466f52c4..763fc85c8d46c 100644
--- a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
+++ b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
@@ -55,27 +55,44 @@ dpaa2_switch_filter_block_get_unused(struct ethsw_core *ethsw)
static u16 dpaa2_switch_port_set_fdb(struct ethsw_port_priv *port_priv,
struct net_device *bridge_dev)
{
+ struct ethsw_core *ethsw = port_priv->ethsw_data;
struct ethsw_port_priv *other_port_priv = NULL;
struct dpaa2_switch_fdb *fdb;
struct net_device *other_dev;
+ bool last_fdb_user = true;
struct list_head *iter;
+ int i;
/* If we leave a bridge (bridge_dev is NULL), find an unused
* FDB and use that.
*/
if (!bridge_dev) {
- fdb = dpaa2_switch_fdb_get_unused(port_priv->ethsw_data);
-
- /* If there is no unused FDB, we must be the last port that
- * leaves the last bridge, all the others are standalone. We
- * can just keep the FDB that we already have.
- */
+ /* First verify if this is the last port to leave this bridge */
+ for (i = 0; i < ethsw->sw_attr.num_ifs; i++) {
+ if (!ethsw->ports[i] || ethsw->ports[i] == port_priv)
+ continue;
+ if (ethsw->ports[i]->fdb == port_priv->fdb) {
+ last_fdb_user = false;
+ break;
+ }
+ }
- if (!fdb) {
+ /* If this is the last user of the FDB, just keep using it. */
+ if (last_fdb_user) {
port_priv->fdb->bridge_dev = NULL;
return 0;
}
+ /* Since we are not the last port which leaves a bridge,
+ * acquire a new FDB and use it. The number of FDBs is sized to
+ * accommodate all switch ports as standalone, each with its
+ * private FDB, which means that dpaa2_switch_fdb_get_unused()
+ * must succeed here. WARN if not.
+ */
+ fdb = dpaa2_switch_fdb_get_unused(port_priv->ethsw_data);
+ if (WARN_ON(!fdb))
+ return 0;
+
port_priv->fdb = fdb;
port_priv->fdb->in_use = true;
port_priv->fdb->bridge_dev = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 145/982] dpaa2-switch: fix the error path in dpaa2_switch_rx()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 144/982] dpaa2-switch: rework FDB management on the bridge leave path Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 146/982] net: dsa: sja1105: flower: reject cross-chip redirect Greg Kroah-Hartman
` (843 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ioana Ciornei, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ioana Ciornei <ioana.ciornei@nxp.com>
[ Upstream commit 74c1c9f5c0c30bbd0c2cf87b6e3507e7ea46c13d ]
In case of an error in dpaa2_switch_rx(), the dpaa2_switch_free_fd()
function is called in order to free the FD. This is incorrect since the
dpaa2_switch_free_fd() is intended to be used on Tx frame descriptors,
meaning that it expects in the software annotation area of the FD data
to find a valid skb pointer on which to call dev_kfree_skb().
Fix this by extracting the dma_unmap_page() from
dpaa2_switch_build_linear_skb() directly into the dpaa2_switch_rx()
function. This allows us to directly use free_pages() in case of an
error before an SKB was created and kfree_skb() afterwards.
Signed-off-by: Ioana Ciornei <ioana.ciornei@nxp.com>
Link: https://patch.msgid.link/20260528173452.1953102-3-ioana.ciornei@nxp.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../ethernet/freescale/dpaa2/dpaa2-switch.c | 23 ++++++++++---------
1 file changed, 12 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
index 763fc85c8d46c..a89b954ec91af 100644
--- a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
+++ b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
@@ -2400,18 +2400,13 @@ static int dpaa2_switch_port_blocking_event(struct notifier_block *nb,
/* Build a linear skb based on a single-buffer frame descriptor */
static struct sk_buff *dpaa2_switch_build_linear_skb(struct ethsw_core *ethsw,
- const struct dpaa2_fd *fd)
+ const struct dpaa2_fd *fd,
+ void *fd_vaddr)
{
u16 fd_offset = dpaa2_fd_get_offset(fd);
- dma_addr_t addr = dpaa2_fd_get_addr(fd);
u32 fd_length = dpaa2_fd_get_len(fd);
struct device *dev = ethsw->dev;
struct sk_buff *skb = NULL;
- void *fd_vaddr;
-
- fd_vaddr = dpaa2_iova_to_virt(ethsw->iommu_domain, addr);
- dma_unmap_page(dev, addr, DPAA2_SWITCH_RX_BUF_SIZE,
- DMA_FROM_DEVICE);
skb = build_skb(fd_vaddr, DPAA2_SWITCH_RX_BUF_SIZE +
SKB_DATA_ALIGN(sizeof(struct skb_shared_info)));
@@ -2437,6 +2432,7 @@ static void dpaa2_switch_tx_conf(struct dpaa2_switch_fq *fq,
static void dpaa2_switch_rx(struct dpaa2_switch_fq *fq,
const struct dpaa2_fd *fd)
{
+ dma_addr_t addr = dpaa2_fd_get_addr(fd);
struct ethsw_core *ethsw = fq->ethsw;
struct ethsw_port_priv *port_priv;
struct net_device *netdev;
@@ -2444,10 +2440,14 @@ static void dpaa2_switch_rx(struct dpaa2_switch_fq *fq,
struct sk_buff *skb;
u16 vlan_tci, vid;
int if_id, err;
+ void *vaddr;
+
+ vaddr = dpaa2_iova_to_virt(ethsw->iommu_domain, addr);
+ dma_unmap_page(ethsw->dev, addr, DPAA2_SWITCH_RX_BUF_SIZE,
+ DMA_FROM_DEVICE);
/* get switch ingress interface ID */
if_id = upper_32_bits(dpaa2_fd_get_flc(fd)) & 0x0000FFFF;
-
if (if_id >= ethsw->sw_attr.num_ifs) {
dev_err(ethsw->dev, "Frame received from unknown interface!\n");
goto err_free_fd;
@@ -2463,7 +2463,7 @@ static void dpaa2_switch_rx(struct dpaa2_switch_fq *fq,
}
}
- skb = dpaa2_switch_build_linear_skb(ethsw, fd);
+ skb = dpaa2_switch_build_linear_skb(ethsw, fd, vaddr);
if (unlikely(!skb))
goto err_free_fd;
@@ -2481,7 +2481,8 @@ static void dpaa2_switch_rx(struct dpaa2_switch_fq *fq,
err = __skb_vlan_pop(skb, &vlan_tci);
if (err) {
dev_info(ethsw->dev, "__skb_vlan_pop() returned %d", err);
- goto err_free_fd;
+ kfree_skb(skb);
+ return;
}
}
@@ -2496,7 +2497,7 @@ static void dpaa2_switch_rx(struct dpaa2_switch_fq *fq,
return;
err_free_fd:
- dpaa2_switch_free_fd(ethsw, fd);
+ free_pages((unsigned long)vaddr, 0);
}
static void dpaa2_switch_detect_features(struct ethsw_core *ethsw)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 146/982] net: dsa: sja1105: flower: reject cross-chip redirect
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 145/982] dpaa2-switch: fix the error path in dpaa2_switch_rx() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 147/982] dpaa2-switch: fix handling of NAPI on the remove path Greg Kroah-Hartman
` (842 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Yang, Vladimir Oltean,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Yang <mmyangfl@gmail.com>
[ Upstream commit cfa5274a5dc2a23b957da5dc806d2ac0c7a66af0 ]
dsa_port_from_netdev() may return a valid port from a different switch
chip. Programming another chip's port index into the local hardware
causes redirection to the wrong port, or an out-of-bounds access if the
index exceeds the local chip's port count.
Apply a minimal fix that adds a check to catch this case and adjusts the
extack message. When cls->common.skip_sw is not set, the operation could
instead redirect to the upstream port and let the software or upstream
switch(es) handle the forward, but that is not addressed here.
Signed-off-by: David Yang <mmyangfl@gmail.com>
Reviewed-by: Vladimir Oltean <olteanv@gmail.com>
Link: https://patch.msgid.link/20260530003940.2000994-1-mmyangfl@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/sja1105/sja1105_flower.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/dsa/sja1105/sja1105_flower.c b/drivers/net/dsa/sja1105/sja1105_flower.c
index fad5afe3819cc..23cc263085a8b 100644
--- a/drivers/net/dsa/sja1105/sja1105_flower.c
+++ b/drivers/net/dsa/sja1105/sja1105_flower.c
@@ -388,9 +388,9 @@ int sja1105_cls_flower_add(struct dsa_switch *ds, int port,
struct dsa_port *to_dp;
to_dp = dsa_port_from_netdev(act->dev);
- if (IS_ERR(to_dp)) {
+ if (IS_ERR(to_dp) || to_dp->ds != ds) {
NL_SET_ERR_MSG_MOD(extack,
- "Destination not a switch port");
+ "Destination not a local switch port");
return -EOPNOTSUPP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 147/982] dpaa2-switch: fix handling of NAPI on the remove path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 146/982] net: dsa: sja1105: flower: reject cross-chip redirect Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 148/982] xhci: Prevent queuing new commands if xhci is inaccessible Greg Kroah-Hartman
` (841 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ioana Ciornei, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ioana Ciornei <ioana.ciornei@nxp.com>
[ Upstream commit e23d7c8c1d4ba435c457d7ffb2669175ec819b07 ]
All the NAPI instances for a DPSW device are attached to the first
switch port's net_device but shared by all ports. The NAPI instances get
disabled only once the last port goes down.
This causes an issue on the .remove() path where each port is
unregistered and freed one at a time, causing the NAPI instances to be
deleted even though they are not disabled.
In order to avoid this, split up the unregister_netdev() calls from the
free_netdev() so that we make sure all ports go down before we attempt
a deletion of NAPI instances. Also, make the netif_napi_del() explicit
as it is on the .probe() path.
Signed-off-by: Ioana Ciornei <ioana.ciornei@nxp.com>
Link: https://patch.msgid.link/20260528173452.1953102-6-ioana.ciornei@nxp.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/freescale/dpaa2/dpaa2-switch.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
index a89b954ec91af..939591171aa55 100644
--- a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
+++ b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
@@ -3271,7 +3271,6 @@ static void dpaa2_switch_teardown(struct fsl_mc_device *sw_dev)
static int dpaa2_switch_remove(struct fsl_mc_device *sw_dev)
{
- struct ethsw_port_priv *port_priv;
struct ethsw_core *ethsw;
struct device *dev;
int i;
@@ -3283,11 +3282,17 @@ static int dpaa2_switch_remove(struct fsl_mc_device *sw_dev)
dpsw_disable(ethsw->mc_io, 0, ethsw->dpsw_handle);
- for (i = 0; i < ethsw->sw_attr.num_ifs; i++) {
- port_priv = ethsw->ports[i];
- unregister_netdev(port_priv->netdev);
+ /* Unregister all the netdevs so that they are brought down and the
+ * shared NAPI instances gets disabled.
+ */
+ for (i = 0; i < ethsw->sw_attr.num_ifs; i++)
+ unregister_netdev(ethsw->ports[i]->netdev);
+
+ for (i = 0; i < DPAA2_SWITCH_RX_NUM_FQS; i++)
+ netif_napi_del(ðsw->fq[i].napi);
+
+ for (i = 0; i < ethsw->sw_attr.num_ifs; i++)
dpaa2_switch_remove_port(ethsw, i);
- }
kfree(ethsw->fdbs);
kfree(ethsw->filter_blocks);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 148/982] xhci: Prevent queuing new commands if xhci is inaccessible
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 147/982] dpaa2-switch: fix handling of NAPI on the remove path Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 149/982] drm/amd/pm: bound pp_dpm_set_pp_table() memcpy Greg Kroah-Hartman
` (840 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mathias Nyman, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mathias Nyman <mathias.nyman@linux.intel.com>
[ Upstream commit 82b70c799281cc24506085be978b829149ba0ca4 ]
Refuse to queue a new command on the command ring if xHC is marked
inaccessible with the HCD_FLAG_HW_ACCESSIBLE.
HCD_FLAG_HW_ACCESSIBLE is set and cleared in suspend and resume.
Also print a warning if xhci is being suspended with commands
still pending on the command ring.
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Link: https://patch.msgid.link/20260603091132.1110849-13-mathias.nyman@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/host/xhci-ring.c | 6 ++++++
drivers/usb/host/xhci.c | 4 ++++
2 files changed, 10 insertions(+)
diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c
index b0da53e9037ed..3f34aa004bc98 100644
--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -4429,6 +4429,7 @@ static int queue_command(struct xhci_hcd *xhci, struct xhci_command *cmd,
u32 field3, u32 field4, bool command_must_succeed)
{
int reserved_trbs = xhci->cmd_ring_reserved_trbs;
+ struct usb_hcd *hcd = xhci_to_hcd(xhci);
int ret;
if ((xhci->xhc_state & XHCI_STATE_DYING) ||
@@ -4438,6 +4439,11 @@ static int queue_command(struct xhci_hcd *xhci, struct xhci_command *cmd,
return -ESHUTDOWN;
}
+ if (!HCD_HW_ACCESSIBLE(hcd)) {
+ xhci_warn(xhci, "Can't queue command, xHC not accessible\n");
+ return -ESHUTDOWN;
+ }
+
if (!command_must_succeed)
reserved_trbs++;
diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
index 37fb2491d88f2..104ee26b27aa4 100644
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -1062,6 +1062,10 @@ int xhci_suspend(struct xhci_hcd *xhci, bool do_wakeup)
/* step 1: stop endpoint */
/* skipped assuming that port suspend has done */
+ /* Check if command ring is empty */
+ if (!list_empty(&xhci->cmd_list))
+ xhci_warn(xhci, "Suspending and stopping xHC with pending command!\n");
+
/* step 2: clear Run/Stop bit */
command = readl(&xhci->op_regs->command);
command &= ~CMD_RUN;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 149/982] drm/amd/pm: bound pp_dpm_set_pp_table() memcpy
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 148/982] xhci: Prevent queuing new commands if xhci is inaccessible Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 150/982] RDMA/irdma: Fix typo in SQ completions generation Greg Kroah-Hartman
` (839 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Asad Kamal, Yang Wang, Alex Deucher,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Asad Kamal <asad.kamal@amd.com>
[ Upstream commit f193e71fa9fab2e68ef85201b106e8f580d3a25b ]
The powerplay path allocates hardcode_pp_table once with kmemdup(...,
soft_pp_table_size). memcpy(..., size) used the sysfs store count (up to
PAGE_SIZE) with no upper bound, causing heap overflow. Reject
writes where size exceeds soft_pp_table_size.
Signed-off-by: Asad Kamal <asad.kamal@amd.com>
Reviewed-by: Yang Wang <kevinyang.wang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/pm/powerplay/amd_powerplay.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/gpu/drm/amd/pm/powerplay/amd_powerplay.c b/drivers/gpu/drm/amd/pm/powerplay/amd_powerplay.c
index 1f8b744d6b178..e4494d963e356 100644
--- a/drivers/gpu/drm/amd/pm/powerplay/amd_powerplay.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/amd_powerplay.c
@@ -681,6 +681,9 @@ static int pp_dpm_set_pp_table(void *handle, const char *buf, size_t size)
if (!hwmgr || !hwmgr->pm_en)
return -EINVAL;
+ if (size > hwmgr->soft_pp_table_size)
+ return -EINVAL;
+
if (!hwmgr->hardcode_pp_table) {
hwmgr->hardcode_pp_table = kmemdup(hwmgr->soft_pp_table,
hwmgr->soft_pp_table_size,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 150/982] RDMA/irdma: Fix typo in SQ completions generation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 149/982] drm/amd/pm: bound pp_dpm_set_pp_table() memcpy Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 151/982] clk: keystone: dont cache clock rate Greg Kroah-Hartman
` (838 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cyrill Gorcunov, Jacob Moroni,
Jason Gunthorpe, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cyrill Gorcunov <gorcunov@gmail.com>
[ Upstream commit b548a6c4eee5c428663f3944e173e6c92e2e8d6f ]
When we generate completion for SQ the opcode while being properly read
from ring buffer is ignored when written back to completion. Seems
to be a simple typo.
Link: https://patch.msgid.link/r/ahjB87k54bYdFbft@grain
Signed-off-by: Cyrill Gorcunov <gorcunov@gmail.com>
Reviewed-by: Jacob Moroni <jmoroni@google.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/utils.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/irdma/utils.c b/drivers/infiniband/hw/irdma/utils.c
index 98a3849c39bf0..b66910b2942c2 100644
--- a/drivers/infiniband/hw/irdma/utils.c
+++ b/drivers/infiniband/hw/irdma/utils.c
@@ -2589,7 +2589,7 @@ void irdma_generate_flush_completions(struct irdma_qp *iwqp)
cmpl->cpi.wr_id = qp->sq_wrtrk_array[wqe_idx].wrid;
sw_wqe = qp->sq_base[wqe_idx].elem;
get_64bit_val(sw_wqe, 24, &wqe_qword);
- cmpl->cpi.op_type = (u8)FIELD_GET(IRDMAQPSQ_OPCODE, IRDMAQPSQ_OPCODE);
+ cmpl->cpi.op_type = (u8)FIELD_GET(IRDMAQPSQ_OPCODE, wqe_qword);
cmpl->cpi.q_type = IRDMA_CQE_QTYPE_SQ;
/* remove the SQ WR by moving SQ tail*/
IRDMA_RING_SET_TAIL(*sq_ring,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 151/982] clk: keystone: dont cache clock rate
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 150/982] RDMA/irdma: Fix typo in SQ completions generation Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 152/982] ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP Greg Kroah-Hartman
` (837 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Walle, Kevin Hilman,
Randolph Sapp, Nishanth Menon, Antonios Christidis, Brian Masney,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Walle <mwalle@kernel.org>
[ Upstream commit a80b32a140c8612bbaed27009c383d43304db6d5 ]
The TISCI firmware will return 0 if the clock or consumer is not
enabled although there is a stored value in the firmware. IOW a call to
set rate will work but at get rate will always return 0 if the clock is
disabled.
The clk framework will try to cache the clock rate when it's requested
by a consumer. If the clock or consumer is not enabled at that point,
the cached value is 0, which is wrong. Thus, disable the cache
altogether.
Signed-off-by: Michael Walle <mwalle@kernel.org>
Reviewed-by: Kevin Hilman <khilman@baylibre.com>
Reviewed-by: Randolph Sapp <rs@ti.com>
Reviewed-by: Nishanth Menon <nm@ti.com>
Signed-off-by: Antonios Christidis <a-christidis@ti.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Link: https://patch.msgid.link/20260507-clk-sci-v2-1-38f59b48777a@ti.com
Signed-off-by: Nishanth Menon <nm@ti.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/keystone/sci-clk.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/clk/keystone/sci-clk.c b/drivers/clk/keystone/sci-clk.c
index 254f2cf24be21..e1d5c08564c2c 100644
--- a/drivers/clk/keystone/sci-clk.c
+++ b/drivers/clk/keystone/sci-clk.c
@@ -334,6 +334,14 @@ static int _sci_clk_build(struct sci_clk_provider *provider,
init.ops = &sci_clk_ops;
init.num_parents = sci_clk->num_parents;
+
+ /*
+ * A clock rate query to the SCI firmware will return 0 if either the
+ * clock itself is disabled or the attached device/consumer is disabled.
+ * This makes it inherently unsuitable for the caching of the clk
+ * framework.
+ */
+ init.flags = CLK_GET_RATE_NOCACHE;
sci_clk->hw.init = &init;
ret = devm_clk_hw_register(provider->dev, &sci_clk->hw);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 152/982] ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 151/982] clk: keystone: dont cache clock rate Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 153/982] ipmi: si: Use platform_get_irq_optional() to retrieve interrupt Greg Kroah-Hartman
` (836 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrei Faleichyk, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrei Faleichyk <andrei.faleichyk@noogadev.com>
[ Upstream commit 3580bc53520ce4efc94ece5886ad3670b93667ba ]
The internal microphone on ASUS VivoBook X509DAP (subsystem ID
0x1043:0x197e) is not detected without a quirk entry. Add
ALC256_FIXUP_ASUS_MIC_NO_PRESENCE to fix the issue.
Signed-off-by: Andrei Faleichyk <andrei.faleichyk@noogadev.com>
Link: https://patch.msgid.link/20260603213313.6298-1-andrei.faleichyk@noogadev.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 7b4fd95c66f9b..94bcf1fc639b9 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -10146,6 +10146,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x1043, 0x18f1, "Asus FX505DT", ALC256_FIXUP_ASUS_HEADSET_MIC),
SND_PCI_QUIRK(0x1043, 0x194e, "ASUS UX563FD", ALC294_FIXUP_ASUS_HPE),
SND_PCI_QUIRK(0x1043, 0x1970, "ASUS UX550VE", ALC289_FIXUP_ASUS_GA401),
+ SND_PCI_QUIRK(0x1043, 0x197e, "ASUS VivoBook X509DAP", ALC256_FIXUP_ASUS_MIC_NO_PRESENCE),
SND_PCI_QUIRK(0x1043, 0x1982, "ASUS B1400CEPE", ALC256_FIXUP_ASUS_HPE),
SND_PCI_QUIRK(0x1043, 0x19ce, "ASUS B9450FA", ALC294_FIXUP_ASUS_HPE),
SND_PCI_QUIRK(0x1043, 0x19e1, "ASUS UX581LV", ALC295_FIXUP_ASUS_MIC_NO_PRESENCE),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 153/982] ipmi: si: Use platform_get_irq_optional() to retrieve interrupt
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 152/982] ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 154/982] wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer notifications Greg Kroah-Hartman
` (835 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Rosen Penev, Corey Minyard,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit 39851b7e580a65bee732e5364f0efb974b242370 ]
Use platform_get_irq_optional() to retrieve the interrupt resource
instead of directly parsing and mapping the OF node via
irq_of_parse_and_map(). This is the standard pattern for platform
devices. irq_of_parse_and_map() requires ire_dispose_mapping(), which
is missing.
Assisted-by: Antigravity:Gemini-3.5-Flash
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Message-ID: <20260603192511.6869-1-rosenp@gmail.com>
[Handle a negative return from platform_get_irq_optional() to mean
no interrupt is assigned.]
Signed-off-by: Corey Minyard <corey@minyard.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/ipmi/ipmi_si_platform.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/char/ipmi/ipmi_si_platform.c b/drivers/char/ipmi/ipmi_si_platform.c
index 505cc978c97a0..f7f602067a574 100644
--- a/drivers/char/ipmi/ipmi_si_platform.c
+++ b/drivers/char/ipmi/ipmi_si_platform.c
@@ -279,7 +279,10 @@ static int of_ipmi_probe(struct platform_device *pdev)
io.regspacing = regspacing ? be32_to_cpup(regspacing) : DEFAULT_REGSPACING;
io.regshift = regshift ? be32_to_cpup(regshift) : 0;
- io.irq = irq_of_parse_and_map(pdev->dev.of_node, 0);
+ io.irq = platform_get_irq_optional(pdev, 0);
+ if (io.irq < 0)
+ io.irq = 0;
+
io.dev = &pdev->dev;
dev_dbg(&pdev->dev, "addr 0x%lx regsize %d spacing %d irq %d\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 154/982] wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer notifications
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 153/982] ipmi: si: Use platform_get_irq_optional() to retrieve interrupt Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 155/982] RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() Greg Kroah-Hartman
` (834 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thiyagarajan Pandiyan, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thiyagarajan Pandiyan <thiyagarajan@aerlync.com>
[ Upstream commit dfb67ae569bf0726187725b1ef8d89377778861e ]
Currently, ie_len in cfg80211_notify_new_peer_candidate is defined as
1-byte field, capping the maximum IE list size at 255 bytes. When a
large beacon is received, the IE list is truncated, passing incomplete
data to wpa_supplicant. This causes supplicant to fail parsing the IEs.
Increasing the size of ie_len to allow the full length of the IE list to
be forwarded properly.
Signed-off-by: Thiyagarajan Pandiyan <thiyagarajan@aerlync.com>
Link: https://patch.msgid.link/20260605054307.427874-1-thiyagarajan@aerlync.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 2 +-
net/wireless/nl80211.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index f39a60475c24c..90aad35cccc10 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -7273,7 +7273,7 @@ void cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
* cfg80211 then sends a notification to userspace.
*/
void cfg80211_notify_new_peer_candidate(struct net_device *dev,
- const u8 *macaddr, const u8 *ie, u8 ie_len,
+ const u8 *macaddr, const u8 *ie, size_t ie_len,
int sig_dbm, gfp_t gfp);
/**
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 069b04c29b64e..aa85e2e063bbc 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -18280,7 +18280,7 @@ void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
}
void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
- const u8 *ie, u8 ie_len,
+ const u8 *ie, size_t ie_len,
int sig_dbm, gfp_t gfp)
{
struct wireless_dev *wdev = dev->ieee80211_ptr;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 155/982] RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 154/982] wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer notifications Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 156/982] RDMA/mlx5: Fix state and counter desync on loopback enable failure Greg Kroah-Hartman
` (833 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Gunthorpe <jgg@nvidia.com>
[ Upstream commit 09ea6837a0434fb4db99528a5055b6d822135dcf ]
Several corner cases, especially important on 32 bits:
- umem->iova is u64, the function argument should pass in u64 or
iova will be truncated
- Check that the length is not too large for the iova
- Check that lengths > 4G don't overflow the GENMASK
Link: https://patch.msgid.link/r/2-v1-88303e9e509f+f7-ib_umem_types_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/umem.c | 18 ++++++++++++------
include/rdma/ib_umem.h | 4 ++--
2 files changed, 14 insertions(+), 8 deletions(-)
diff --git a/drivers/infiniband/core/umem.c b/drivers/infiniband/core/umem.c
index 1d154055a335b..9b1994ba7b487 100644
--- a/drivers/infiniband/core/umem.c
+++ b/drivers/infiniband/core/umem.c
@@ -78,14 +78,17 @@ static void __ib_umem_release(struct ib_device *dev, struct ib_umem *umem, int d
*/
unsigned long ib_umem_find_best_pgsz(struct ib_umem *umem,
unsigned long pgsz_bitmap,
- unsigned long virt)
+ u64 virt)
{
unsigned long curr_len = 0;
dma_addr_t curr_base = ~0;
- unsigned long va, pgoff;
+ unsigned long pgoff;
struct scatterlist *sg;
- dma_addr_t mask;
+ unsigned long mask = 0;
+ unsigned int bits;
dma_addr_t end;
+ u64 last_va;
+ u64 va;
int i;
umem->iova = va = virt;
@@ -103,9 +106,12 @@ unsigned long ib_umem_find_best_pgsz(struct ib_umem *umem,
* number of required pages. Compute the largest page size that could
* work based on VA address bits that don't change.
*/
- mask = pgsz_bitmap &
- GENMASK(BITS_PER_LONG - 1,
- bits_per((umem->length - 1 + virt) ^ virt));
+ if (check_add_overflow(umem->length - 1, virt, &last_va))
+ return 0;
+ bits = bits_per(virt ^ last_va);
+ if (bits < BITS_PER_LONG)
+ mask = pgsz_bitmap & GENMASK(BITS_PER_LONG - 1, bits);
+
/* offset into first SGL */
pgoff = umem->address & ~PAGE_MASK;
diff --git a/include/rdma/ib_umem.h b/include/rdma/ib_umem.h
index d049e7a60ad65..ace2ffff2312d 100644
--- a/include/rdma/ib_umem.h
+++ b/include/rdma/ib_umem.h
@@ -80,7 +80,7 @@ int ib_umem_copy_from(void *dst, struct ib_umem *umem, size_t offset,
size_t length);
unsigned long ib_umem_find_best_pgsz(struct ib_umem *umem,
unsigned long pgsz_bitmap,
- unsigned long virt);
+ u64 virt);
/**
* ib_umem_find_best_pgoff - Find best HW page size
@@ -144,7 +144,7 @@ static inline int ib_umem_copy_from(void *dst, struct ib_umem *umem, size_t offs
}
static inline unsigned long ib_umem_find_best_pgsz(struct ib_umem *umem,
unsigned long pgsz_bitmap,
- unsigned long virt)
+ u64 virt)
{
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 156/982] RDMA/mlx5: Fix state and counter desync on loopback enable failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 155/982] RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 157/982] bpf: NUL-terminate replaced sysctl value Greg Kroah-Hartman
` (832 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Jason Gunthorpe,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 0d32eabccbe4b2f8d45be3192c5f3c76c8af703d ]
In mlx5_ib_enable_lb(), dev->lb.enabled was unconditionally set
to true even if mlx5_nic_vport_update_local_lb() failed.
Fix this by only setting dev->lb.enabled on success. On failure,
roll back the reference counters and return the error.
Link: https://patch.msgid.link/r/20260601095818.2227-1-lirongqing@baidu.com
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/main.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index 987e9087c9d92..9da42edecb05c 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -1689,6 +1689,9 @@ int mlx5_ib_enable_lb(struct mlx5_ib_dev *dev, bool td, bool qp)
dev->lb.qps == 1) {
if (!dev->lb.enabled) {
err = mlx5_nic_vport_update_local_lb(dev->mdev, true);
+ if (err)
+ goto err_rollback;
+
dev->lb.enabled = true;
}
}
@@ -1696,6 +1699,14 @@ int mlx5_ib_enable_lb(struct mlx5_ib_dev *dev, bool td, bool qp)
mutex_unlock(&dev->lb.mutex);
return err;
+
+err_rollback:
+ if (td)
+ dev->lb.user_td--;
+ if (qp)
+ dev->lb.qps--;
+ mutex_unlock(&dev->lb.mutex);
+ return err;
}
void mlx5_ib_disable_lb(struct mlx5_ib_dev *dev, bool td, bool qp)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 157/982] bpf: NUL-terminate replaced sysctl value
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 156/982] RDMA/mlx5: Fix state and counter desync on loopback enable failure Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 158/982] net: cpsw_new: unregister devlink on port registration failure Greg Kroah-Hartman
` (831 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zilin Guan, Dawei Feng,
Yonghong Song, Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawei Feng <dawei.feng@seu.edu.cn>
[ Upstream commit a66e3b5bacf38d6ab29fa05a9754f7a114485605 ]
When writing to sysctls, proc_sys_call_handler() guarantees that the
buffer passed to proc handlers is NUL-terminated. If
bpf_sysctl_set_new_value() replaces the pending sysctl value, it can
hand a replacement buffer directly to proc handlers. However, the
helper currently copies only buf_len bytes into that buffer without
appending a NUL terminator, leaving downstream parsers vulnerable to
out-of-bounds access.
Fix this by appending a '\0' after the replaced value to restore the
expected sysctl semantics. Since the helper already rejects buf_len
greater than PAGE_SIZE - 1, there is always room for the extra byte.
Reproduced in a QEMU x86_64 guest booted with KASAN while exercising
the sysctl replacement path with a cgroup/sysctl BPF program. The
reproducer targets `/proc/sys/net/core/flow_limit_cpu_bitmap`, fills
the original user write buffer with non-zero bytes, and overrides the
sysctl value so the replacement buffer lacks a terminating NUL. Under
that setup, the pre-fix kernel reported:
BUG: KASAN: slab-out-of-bounds in strnchrnul+0x72/0x90
Read of size 1 at addr ffff88800de57000 by task repro_patch3/66
CPU: 0 UID: 0 PID: 66 Comm: repro_patch3 Not tainted 7.1.0-rc3-00269-g8370ca1f87cc #6 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0x68/0xa0
print_report+0xcb/0x5e0
? __virt_addr_valid+0x21d/0x3f0
? strnchrnul+0x72/0x90
? strnchrnul+0x72/0x90
kasan_report+0xca/0x100
? strnchrnul+0x72/0x90
strnchrnul+0x72/0x90
bitmap_parse+0x37/0x2e0
flow_limit_cpu_sysctl+0xc6/0x840
? __pfx_flow_limit_cpu_sysctl+0x10/0x10
? __kvmalloc_node_noprof+0x5ba/0x870
proc_sys_call_handler+0x31d/0x480
? __pfx_proc_sys_call_handler+0x10/0x10
? selinux_file_permission+0x39f/0x500
? lock_is_held_type+0x9e/0x120
vfs_write+0x98e/0x1000
...
</TASK>
The buggy address is located 0 bytes to the right of
allocated 4096-byte region [ffff88800de56000, ffff88800de57000)
With this fix applied, rerunning the same sysctl-targeted path yields
no corresponding KASAN reports.
Signed-off-by: Zilin Guan <zilin@seu.edu.cn>
Signed-off-by: Dawei Feng <dawei.feng@seu.edu.cn>
Acked-by: Yonghong Song <yonghong.song@linux.dev>
Link: https://lore.kernel.org/r/20260603105317.944304-2-dawei.feng@seu.edu.cn
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/cgroup.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/bpf/cgroup.c b/kernel/bpf/cgroup.c
index 3929c7548e6ff..6158b021f617f 100644
--- a/kernel/bpf/cgroup.c
+++ b/kernel/bpf/cgroup.c
@@ -2148,6 +2148,7 @@ BPF_CALL_3(bpf_sysctl_set_new_value, struct bpf_sysctl_kern *, ctx,
return -E2BIG;
memcpy(ctx->new_val, buf, buf_len);
+ ((char *)ctx->new_val)[buf_len] = '\0';
ctx->new_len = buf_len;
ctx->new_updated = 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 158/982] net: cpsw_new: unregister devlink on port registration failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 157/982] bpf: NUL-terminate replaced sysctl value Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 159/982] hsr: broadcast netlink notifications in the devices net namespace Greg Kroah-Hartman
` (830 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aleksandr Loktionov,
Alexander Sverdlin, Guangshuo Li, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit b64f763b607426ac97e44b114f0b8844ac3b86dd ]
cpsw_probe() registers devlink before registering the CPSW ports.
If cpsw_register_ports() fails, the error path only unregisters the
notifiers and then releases the lower level resources. It does not undo
the successful cpsw_register_devlink() call, leaving the devlink instance
and its parameters registered after probe has failed.
Add a devlink cleanup label for the path where devlink registration has
already succeeded, and use it when port registration fails.
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Reviewed-by: Alexander Sverdlin <alexander.sverdlin@siemens.com>
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260604043115.1409134-1-lgs201920130244@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ti/cpsw_new.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/cpsw_new.c b/drivers/net/ethernet/ti/cpsw_new.c
index 17c267f6d79aa..931fc8fdead05 100644
--- a/drivers/net/ethernet/ti/cpsw_new.c
+++ b/drivers/net/ethernet/ti/cpsw_new.c
@@ -2010,7 +2010,7 @@ static int cpsw_probe(struct platform_device *pdev)
ret = cpsw_register_ports(cpsw);
if (ret)
- goto clean_unregister_notifiers;
+ goto clean_unregister_devlink;
dev_notice(dev, "initialized (regs %pa, pool size %d) hw_ver:%08X %d.%d (%d)\n",
&ss_res->start, descs_pool_size,
@@ -2022,6 +2022,8 @@ static int cpsw_probe(struct platform_device *pdev)
return 0;
+clean_unregister_devlink:
+ cpsw_unregister_devlink(cpsw);
clean_unregister_notifiers:
cpsw_unregister_notifiers(cpsw);
clean_cpts:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 159/982] hsr: broadcast netlink notifications in the devices net namespace
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 158/982] net: cpsw_new: unregister devlink on port registration failure Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 160/982] ALSA: es18xx: check control allocation before private data setup Greg Kroah-Hartman
` (829 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fernando Fernandez Mancera,
Maoyi Xie, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
[ Upstream commit a762fabd7ef9a6cc07258684138f9c3f078d0326 ]
The HSR generic netlink family sets .netnsok = true. HSR devices can
live in network namespaces other than init_net.
Two async notifiers broadcast events with genlmsg_multicast(). They
are hsr_nl_ringerror() and hsr_nl_nodedown(). That helper delivers
only on the default genl socket in init_net. So the events always land
in init_net. The network namespace of the device does not matter.
This has two effects. A listener in the device's own namespace never
sees its own ring error and node down events. A privileged listener in
init_net receives events from HSR devices in other namespaces. The
payload carries the peer node MAC (HSR_A_NODE_ADDR) and the slave port
ifindex (HSR_A_IFINDEX).
Switch both callers to genlmsg_multicast_netns(). Other families with
.netnsok = true already do this. Examples are gtp, ovpn, team,
batman-adv, netdev-genl, ethtool and handshake.
hsr_nl_ringerror() already has the slave port. It uses
dev_net(port->dev). hsr_nl_nodedown() takes the namespace from the
master port via hsr_port_get_hsr().
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://patch.msgid.link/20260604054949.2999304-1-maoyixie.tju@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/hsr/hsr_netlink.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/net/hsr/hsr_netlink.c b/net/hsr/hsr_netlink.c
index 898f18c6da53e..72aad6f845319 100644
--- a/net/hsr/hsr_netlink.c
+++ b/net/hsr/hsr_netlink.c
@@ -233,7 +233,8 @@ void hsr_nl_ringerror(struct hsr_priv *hsr, unsigned char addr[ETH_ALEN],
goto nla_put_failure;
genlmsg_end(skb, msg_head);
- genlmsg_multicast(&hsr_genl_family, skb, 0, 0, GFP_ATOMIC);
+ genlmsg_multicast_netns(&hsr_genl_family, dev_net(port->dev),
+ skb, 0, 0, GFP_ATOMIC);
return;
@@ -269,8 +270,12 @@ void hsr_nl_nodedown(struct hsr_priv *hsr, unsigned char addr[ETH_ALEN])
if (res < 0)
goto nla_put_failure;
+ rcu_read_lock();
+ master = hsr_port_get_hsr(hsr, HSR_PT_MASTER);
genlmsg_end(skb, msg_head);
- genlmsg_multicast(&hsr_genl_family, skb, 0, 0, GFP_ATOMIC);
+ genlmsg_multicast_netns(&hsr_genl_family, dev_net(master->dev),
+ skb, 0, 0, GFP_ATOMIC);
+ rcu_read_unlock();
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 160/982] ALSA: es18xx: check control allocation before private data setup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 159/982] hsr: broadcast netlink notifications in the devices net namespace Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 161/982] netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() Greg Kroah-Hartman
` (828 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 422e42b7c2b882ba1d16d4afc8891bcea7c4de93 ]
snd_es18xx_mixer() creates controls with snd_ctl_new1() and then stores
bookkeeping pointers or sets private_free before calling snd_ctl_add().
snd_ctl_new1() can return NULL on allocation failure, so those writes
can dereference a NULL control pointer.
Check the returned control pointers before using them and return -ENOMEM
on allocation failure.
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Link: https://patch.msgid.link/20260607074219.3-1-ruoyuw560@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/isa/es18xx.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/sound/isa/es18xx.c b/sound/isa/es18xx.c
index 0a32845b1017a..1d21c24c9e20d 100644
--- a/sound/isa/es18xx.c
+++ b/sound/isa/es18xx.c
@@ -1776,6 +1776,8 @@ static int snd_es18xx_mixer(struct snd_card *card)
for (idx = 0; idx < ARRAY_SIZE(snd_es18xx_base_controls); idx++) {
struct snd_kcontrol *kctl;
kctl = snd_ctl_new1(&snd_es18xx_base_controls[idx], chip);
+ if (!kctl)
+ return -ENOMEM;
if (chip->caps & ES18XX_HWV) {
switch (idx) {
case 0:
@@ -1837,6 +1839,8 @@ static int snd_es18xx_mixer(struct snd_card *card)
for (idx = 0; idx < ARRAY_SIZE(snd_es18xx_hw_volume_controls); idx++) {
struct snd_kcontrol *kctl;
kctl = snd_ctl_new1(&snd_es18xx_hw_volume_controls[idx], chip);
+ if (!kctl)
+ return -ENOMEM;
if (idx == 0)
chip->hw_volume = kctl;
else
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 161/982] netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 160/982] ALSA: es18xx: check control allocation before private data setup Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 162/982] btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() Greg Kroah-Hartman
` (827 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev,
Fernando Fernandez Mancera, Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit d3bf9eae486490832bd08fd62ab0ac601f346bd4 ]
The timestamp-only fast path dereferences the option stream as
*(__be32 *)ptr, which assumes 4-byte alignment that the TCP option
stream does not guarantee. Use get_unaligned_be32() instead, which
reads the value safely and already returns host byte order, so the
htonl() on the comparison constant can be dropped.
This matches the existing get_unaligned_be32() use later in the same
function.
Assisted-by: Claude:Opus-4.7
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_conntrack_proto_tcp.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/net/netfilter/nf_conntrack_proto_tcp.c b/net/netfilter/nf_conntrack_proto_tcp.c
index ef1068f9c2fad..c75f42168b6d5 100644
--- a/net/netfilter/nf_conntrack_proto_tcp.c
+++ b/net/netfilter/nf_conntrack_proto_tcp.c
@@ -405,11 +405,11 @@ static void tcp_sack(const struct sk_buff *skb, unsigned int dataoff,
return;
/* Fast path for timestamp-only option */
- if (length == TCPOLEN_TSTAMP_ALIGNED
- && *(__be32 *)ptr == htonl((TCPOPT_NOP << 24)
- | (TCPOPT_NOP << 16)
- | (TCPOPT_TIMESTAMP << 8)
- | TCPOLEN_TIMESTAMP))
+ if (length == TCPOLEN_TSTAMP_ALIGNED &&
+ get_unaligned_be32(ptr) == ((TCPOPT_NOP << 24) |
+ (TCPOPT_NOP << 16) |
+ (TCPOPT_TIMESTAMP << 8) |
+ TCPOLEN_TIMESTAMP))
return;
while (length > 0) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 162/982] btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 161/982] netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:14 ` [PATCH 6.1 163/982] btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF Greg Kroah-Hartman
` (826 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, ZhengYuan Huang, David Sterba,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ZhengYuan Huang <gality369@gmail.com>
[ Upstream commit 18d32b0013efba19f7ad3e5b08d7aee813d604a6 ]
[BUG]
Running btrfs balance can trigger a null-ptr-deref before relocating a
data chunk when metadata corruption leaves a chunk in the chunk tree
without a corresponding block group in the in-memory cache:
KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f]
RIP: 0010:btrfs_may_alloc_data_chunk+0x40/0x1c0 fs/btrfs/volumes.c:3601
Call Trace:
__btrfs_balance fs/btrfs/volumes.c:4217 [inline]
btrfs_balance+0x2516/0x42b0 fs/btrfs/volumes.c:4604
btrfs_ioctl_balance fs/btrfs/ioctl.c:3577 [inline]
btrfs_ioctl+0x25cf/0x5b90 fs/btrfs/ioctl.c:5313
...
[CAUSE]
__btrfs_balance() iterates the on-disk chunk tree and passes the chunk
logical bytenr to btrfs_may_alloc_data_chunk() before relocating a data
chunk. That helper then queries the in-memory block group cache:
cache = btrfs_lookup_block_group(fs_info, chunk_offset);
chunk_type = cache->flags; /* cache may be NULL */
A corrupt image can contain a chunk item whose matching block group
item is missing, so no block group is ever inserted into the cache. In
that case btrfs_lookup_block_group() returns NULL.
The code only guards this with ASSERT(cache), which becomes a no-op when
CONFIG_BTRFS_ASSERT is disabled. The subsequent dereference of
cache->flags therefore crashes the kernel.
[FIX]
Add a NULL check after btrfs_lookup_block_group() in
btrfs_may_alloc_data_chunk() and print and error message for clarity.
Signed-off-by: ZhengYuan Huang <gality369@gmail.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/volumes.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c
index 9f5d5f5c53131..e0a310bd0421f 100644
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -3495,7 +3495,11 @@ static int btrfs_may_alloc_data_chunk(struct btrfs_fs_info *fs_info,
u64 chunk_type;
cache = btrfs_lookup_block_group(fs_info, chunk_offset);
- ASSERT(cache);
+ if (unlikely(!cache)) {
+ btrfs_err(fs_info, "balance: chunk at bytenr %llu has no corresponding block group",
+ chunk_offset);
+ return -EUCLEAN;
+ }
chunk_type = cache->flags;
btrfs_put_block_group(cache);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 163/982] btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 162/982] btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() Greg Kroah-Hartman
@ 2026-09-30 15:14 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 164/982] NFS: fix eof updates after NFSv4.2 fallocate/zero-range Greg Kroah-Hartman
` (825 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:14 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Zhang Cen, David Sterba,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhang Cen <rollkingzzc@gmail.com>
[ Upstream commit 0af37c217edf15fa21dac1c40822086df356c6bb ]
ROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed
by the subvolume name. Several readers assume that this layout is already
valid and then use the on-disk name length directly. A corrupted item can
therefore make those readers address bytes outside the item, and
BTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI
name buffer.
Validate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader
uses them. Reject records that do not contain a non-empty name, whose
name_len does not exactly describe the remaining item payload, or whose
name exceeds BTRFS_NAME_LEN.
For BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len
instead of deriving the copy length from the item size. The ioctl result is
zeroed when allocated. That leaves the existing trailing zero byte
untouched.
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/ioctl.c | 11 +++++------
fs/btrfs/tree-checker.c | 35 +++++++++++++++++++++++++++++++++++
2 files changed, 40 insertions(+), 6 deletions(-)
diff --git a/fs/btrfs/ioctl.c b/fs/btrfs/ioctl.c
index b84b1cce17723..e278da90888e1 100644
--- a/fs/btrfs/ioctl.c
+++ b/fs/btrfs/ioctl.c
@@ -3058,7 +3058,6 @@ static int btrfs_ioctl_get_subvol_info(struct inode *inode, void __user *argp)
struct btrfs_root_ref *rref;
struct extent_buffer *leaf;
unsigned long item_off;
- unsigned long item_len;
int slot;
int ret = 0;
@@ -3133,17 +3132,17 @@ static int btrfs_ioctl_get_subvol_info(struct inode *inode, void __user *argp)
btrfs_item_key_to_cpu(leaf, &key, slot);
if (key.objectid == subvol_info->treeid &&
key.type == BTRFS_ROOT_BACKREF_KEY) {
+ u16 name_len;
+
subvol_info->parent_id = key.offset;
rref = btrfs_item_ptr(leaf, slot, struct btrfs_root_ref);
+ name_len = btrfs_root_ref_name_len(leaf, rref);
subvol_info->dirid = btrfs_root_ref_dirid(leaf, rref);
- item_off = btrfs_item_ptr_offset(leaf, slot)
- + sizeof(struct btrfs_root_ref);
- item_len = btrfs_item_size(leaf, slot)
- - sizeof(struct btrfs_root_ref);
+ item_off = btrfs_item_ptr_offset(leaf, slot) + sizeof(*rref);
read_extent_buffer(leaf, subvol_info->name,
- item_off, item_len);
+ item_off, name_len);
} else {
ret = -ENOENT;
goto out;
diff --git a/fs/btrfs/tree-checker.c b/fs/btrfs/tree-checker.c
index 0b1ab9b6b84b4..3e3ffa23cea65 100644
--- a/fs/btrfs/tree-checker.c
+++ b/fs/btrfs/tree-checker.c
@@ -1232,6 +1232,37 @@ static int check_root_item(struct extent_buffer *leaf, struct btrfs_key *key,
return 0;
}
+static int check_root_ref(struct extent_buffer *leaf, struct btrfs_key *key, int slot)
+{
+ struct btrfs_root_ref *rref;
+ u32 item_size = btrfs_item_size(leaf, slot);
+ u32 name_len;
+
+ if (unlikely(item_size <= sizeof(*rref))) {
+ generic_err(leaf, slot,
+ "invalid root ref item size for key type %u, have %u expect > %zu",
+ key->type, item_size, sizeof(*rref));
+ return -EUCLEAN;
+ }
+
+ rref = btrfs_item_ptr(leaf, slot, struct btrfs_root_ref);
+ name_len = btrfs_root_ref_name_len(leaf, rref);
+ if (unlikely(name_len > BTRFS_NAME_LEN)) {
+ generic_err(leaf, slot,
+ "root ref name too long for key type %u, have %u max %u",
+ key->type, name_len, BTRFS_NAME_LEN);
+ return -EUCLEAN;
+ }
+ if (unlikely(item_size != sizeof(*rref) + name_len)) {
+ generic_err(leaf, slot,
+ "invalid root ref item size for key type %u, have %u expect %zu",
+ key->type, item_size, sizeof(*rref) + name_len);
+ return -EUCLEAN;
+ }
+
+ return 0;
+}
+
__printf(3,4)
__cold
static void extent_err(const struct extent_buffer *eb, int slot,
@@ -1765,6 +1796,10 @@ static int check_leaf_item(struct extent_buffer *leaf,
case BTRFS_ROOT_ITEM_KEY:
ret = check_root_item(leaf, key, slot);
break;
+ case BTRFS_ROOT_REF_KEY:
+ case BTRFS_ROOT_BACKREF_KEY:
+ ret = check_root_ref(leaf, key, slot);
+ break;
case BTRFS_EXTENT_ITEM_KEY:
case BTRFS_METADATA_ITEM_KEY:
ret = check_extent_item(leaf, key, slot, prev_key);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 164/982] NFS: fix eof updates after NFSv4.2 fallocate/zero-range
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-09-30 15:14 ` [PATCH 6.1 163/982] btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 165/982] RDMA/rtrs-srv: Fix integer underflow in process_read and process_write Greg Kroah-Hartman
` (824 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dai Ngo, Anna Schumaker, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dai Ngo <dai.ngo@oracle.com>
[ Upstream commit 35168eb947f230aaa35fd8416a30563ef89f5421 ]
Generic/075 reliably exposes a regression when the client holds an
NFSv4 write delegation: ZERO_RANGE/ALLOCATE extends the file on the
server, but the local inode keeps the old i_size. The test then fails
with 'Size error' because the post-op attribute refresh refuses to
touch i_size while a delegation is outstanding, and the cached EOF
was never marked stale.
Update _nfs42_proc_fallocate() so that on success it:
- bumps i_size when the operation extends the file, and
- marks NFS_INO_INVALID_BLOCKS since the block count can also change
Tested with xfstests generic/075 over NFSv4.2.
Signed-off-by: Dai Ngo <dai.ngo@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/nfs/nfs42proc.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/fs/nfs/nfs42proc.c b/fs/nfs/nfs42proc.c
index 923ccd3b540f5..ad0ab93c1bb04 100644
--- a/fs/nfs/nfs42proc.c
+++ b/fs/nfs/nfs42proc.c
@@ -79,12 +79,17 @@ static int _nfs42_proc_fallocate(struct rpc_message *msg, struct file *filep,
status = nfs4_call_sync(server->client, server, msg,
&args.seq_args, &res.seq_res, 0);
if (status == 0) {
- if (nfs_should_remove_suid(inode)) {
- spin_lock(&inode->i_lock);
+ loff_t newsize = offset + len;
+
+ spin_lock(&inode->i_lock);
+ if (newsize > i_size_read(inode))
+ i_size_write(inode, newsize);
+ nfs_set_cache_invalid(inode, NFS_INO_INVALID_BLOCKS);
+ if (nfs_should_remove_suid(inode))
nfs_set_cache_invalid(inode,
- NFS_INO_REVAL_FORCED | NFS_INO_INVALID_MODE);
- spin_unlock(&inode->i_lock);
- }
+ NFS_INO_REVAL_FORCED |
+ NFS_INO_INVALID_MODE);
+ spin_unlock(&inode->i_lock);
status = nfs_post_op_update_inode_force_wcc(inode,
res.falloc_fattr);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 165/982] RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 164/982] NFS: fix eof updates after NFSv4.2 fallocate/zero-range Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 166/982] xprtrdma: Add request-pool slack for delayed recycling Greg Kroah-Hartman
` (823 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aurelien DESBRIERES, Md Haris Iqbal,
Jason Gunthorpe, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aurelien DESBRIERES <aurelien@hackers.camp>
[ Upstream commit 54bf38b27afc08a0eb6b732f9c14eb8a4bcb66b5 ]
usr_len is read from a network-supplied message field (le16_to_cpu)
and used to compute data_len = off - usr_len without validating that
usr_len <= off. A malicious RDMA client can send usr_len > off causing
an integer underflow, resulting in data_len wrapping to a huge size_t
value which is then passed to the rdma_ev callback as a memory length,
leading to out-of-bounds memory access.
Fix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids()
in both process_read() and process_write(), ensuring the early return
path acquires no reference and has no resource leak.
Link: https://patch.msgid.link/r/20260608134802.5019-1-aurelien@hackers.camp
Reported-by: Aurelien DESBRIERES <aurelien@hackers.camp>
Reviewed-by: Md Haris Iqbal <haris.iqbal@ionos.com>
Signed-off-by: Aurelien DESBRIERES <aurelien@hackers.camp>
Assisted-by: Claude <claude-sonnet-4-6>
Acked-by: Md Haris Iqbal <haris.iqbal@ionos.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/rtrs/rtrs-srv.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-srv.c b/drivers/infiniband/ulp/rtrs/rtrs-srv.c
index 086dba6b97c64..a7c0b7e513fea 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-srv.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-srv.c
@@ -1040,6 +1040,11 @@ static void process_read(struct rtrs_srv_con *con,
"Processing read request failed, invalid message\n");
return;
}
+ usr_len = le16_to_cpu(msg->usr_len);
+ if (usr_len > off) {
+ pr_debug("rtrs-srv: Invalid usr_len %zu > off %u\n", usr_len, off);
+ return;
+ }
rtrs_srv_get_ops_ids(srv_path);
rtrs_srv_update_rdma_stats(srv_path->stats, off, READ);
id = srv_path->ops_ids[buf_id];
@@ -1047,7 +1052,6 @@ static void process_read(struct rtrs_srv_con *con,
id->dir = READ;
id->msg_id = buf_id;
id->rd_msg = msg;
- usr_len = le16_to_cpu(msg->usr_len);
data_len = off - usr_len;
data = page_address(srv->chunks[buf_id]);
ret = ctx->ops.rdma_ev(srv->priv, id, data, data_len,
@@ -1093,6 +1097,11 @@ static void process_write(struct rtrs_srv_con *con,
rtrs_srv_state_str(srv_path->state));
return;
}
+ usr_len = le16_to_cpu(req->usr_len);
+ if (usr_len > off) {
+ pr_debug("rtrs-srv: Invalid usr_len %zu > off %u\n", usr_len, off);
+ return;
+ }
rtrs_srv_get_ops_ids(srv_path);
rtrs_srv_update_rdma_stats(srv_path->stats, off, WRITE);
id = srv_path->ops_ids[buf_id];
@@ -1100,7 +1109,6 @@ static void process_write(struct rtrs_srv_con *con,
id->dir = WRITE;
id->msg_id = buf_id;
- usr_len = le16_to_cpu(req->usr_len);
data_len = off - usr_len;
data = page_address(srv->chunks[buf_id]);
ret = ctx->ops.rdma_ev(srv->priv, id, data, data_len,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 166/982] xprtrdma: Add request-pool slack for delayed recycling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 165/982] RDMA/rtrs-srv: Fix integer underflow in process_read and process_write Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 167/982] configfs_depend_prep(): pass configfs_dirent instead of dentry Greg Kroah-Hartman
` (822 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chuck Lever <chuck.lever@oracle.com>
[ Upstream commit 64bf6892057b746c55bcc045b9492741b72d8d27 ]
After the previous patch gates req recycling on Send completion,
a completed RPC's rpcrdma_req can remain pinned by the sendctx
ring until the next signaled Send completion releases it. The
transmitted-RPC ceiling is unchanged: xprt_request_get_cong()
gates Sends against xprt->cwnd, the RPC/RDMA credit window fed
by server-granted credits and capped at re_max_requests. The
req pool, however, must exceed max_reqs by enough that this
recycle delay does not stall a slot allocation that the credit
window would admit.
The headroom is bounded. frwr_open() sets re_send_batch to
re_max_requests >> 3 -- one in every eight Sends is signaled --
so at most re_send_batch unsignaled Sends can be outstanding
before the next signaled completion releases them. That equals
max_reqs / 8 reqs in the worst case, with a one-slot floor for
small max_reqs values where the right-shift rounds to zero.
The sendctx ring and the hardware Send Queue are not enlarged
to match. Both are sized in rpcrdma_sendctxs_create() and
frwr_query_device() for re_max_requests in-flight Sends, which
is the ceiling the credit window enforces. The pool slack does
not raise that ceiling -- it only lets allocation keep pace
with the credit window during the brief interval in which
earlier reqs are pinned waiting for the next signaled
completion. At any moment, at most re_send_batch sendctxes are
held by unswept unsignaled Sends, leaving the rest of the ring
available for newly admitted Sends.
Allocate max_reqs + DIV_ROUND_UP(max_reqs, 8) request objects
and name the slack calculation at the allocation site so the
1/8 bound stays tied to the Send-signaling batch size.
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sunrpc/xprtrdma/verbs.c | 21 ++++++++++++++++++++-
1 file changed, 20 insertions(+), 1 deletion(-)
diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index a97f0b18ac429..34a3c08a82fba 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -1110,6 +1110,22 @@ static void rpcrdma_reps_destroy(struct rpcrdma_buffer *buf)
spin_unlock(&buf->rb_lock);
}
+static unsigned int rpcrdma_req_pool_slack(unsigned int max_reqs)
+{
+ /* The sendctx ring can hold up to one Send-signaling batch
+ * (re_send_batch, set by frwr_open() to re_max_requests >> 3)
+ * of unfinished Sends. Each pins its req until a signaled Send
+ * completion releases the sendctx. Size the pool above max_reqs
+ * by that batch so the recycle delay does not stall a slot
+ * allocation that the RPC/RDMA credit window would admit.
+ *
+ * Round up: re_max_requests >> 3 is zero when max_reqs < 8, but
+ * a single unsignaled Send is still enough to pin one req. One
+ * slack slot covers that case.
+ */
+ return DIV_ROUND_UP(max_reqs, 8);
+}
+
/**
* rpcrdma_buffer_create - Create initial set of req/rep objects
* @r_xprt: transport instance to (re)initialize
@@ -1119,6 +1135,7 @@ static void rpcrdma_reps_destroy(struct rpcrdma_buffer *buf)
int rpcrdma_buffer_create(struct rpcrdma_xprt *r_xprt)
{
struct rpcrdma_buffer *buf = &r_xprt->rx_buf;
+ unsigned int max_reqs;
int i, rc;
buf->rb_bc_srv_max_requests = 0;
@@ -1132,7 +1149,9 @@ int rpcrdma_buffer_create(struct rpcrdma_xprt *r_xprt)
INIT_LIST_HEAD(&buf->rb_all_reps);
rc = -ENOMEM;
- for (i = 0; i < r_xprt->rx_xprt.max_reqs; i++) {
+ max_reqs = r_xprt->rx_xprt.max_reqs;
+ max_reqs += rpcrdma_req_pool_slack(max_reqs);
+ for (i = 0; i < max_reqs; i++) {
struct rpcrdma_req *req;
req = rpcrdma_req_create(r_xprt,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 167/982] configfs_depend_prep(): pass configfs_dirent instead of dentry
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 166/982] xprtrdma: Add request-pool slack for delayed recycling Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 168/982] net: ibm: emac: mal: fix potential system hang in mal_remove() Greg Kroah-Hartman
` (821 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jan Kara, Breno Leitao, Al Viro,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Al Viro <viro@zeniv.linux.org.uk>
[ Upstream commit 764682e0118432260191d194edbdaff208260483 ]
Again, the only thing it uses dentry for is dentry->d_fsdata; for the
recursive call the situation is the same as with configfs_detach_prep()
and the same observation about ->s_dentry->d_fsdata applies.
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/configfs/dir.c | 12 ++++--------
1 file changed, 4 insertions(+), 8 deletions(-)
diff --git a/fs/configfs/dir.c b/fs/configfs/dir.c
index 01c9d54833b30..69762a33dff6b 100644
--- a/fs/configfs/dir.c
+++ b/fs/configfs/dir.c
@@ -1060,15 +1060,12 @@ static int configfs_dump(struct configfs_dirent *sd, int level)
* much on the stack, though, so folks that need this function - be careful
* about your stack! Patches will be accepted to make it iterative.
*/
-static int configfs_depend_prep(struct dentry *origin,
+static int configfs_depend_prep(struct configfs_dirent *sd,
struct config_item *target)
{
- struct configfs_dirent *child_sd, *sd;
+ struct configfs_dirent *child_sd;
int ret = 0;
- BUG_ON(!origin || !origin->d_fsdata);
- sd = origin->d_fsdata;
-
if (sd->s_element == target) /* Boo-yah */
goto out;
@@ -1076,8 +1073,7 @@ static int configfs_depend_prep(struct dentry *origin,
if ((child_sd->s_type & CONFIGFS_DIR) &&
!(child_sd->s_type & CONFIGFS_USET_DROPPING) &&
!(child_sd->s_type & CONFIGFS_USET_CREATING)) {
- ret = configfs_depend_prep(child_sd->s_dentry,
- target);
+ ret = configfs_depend_prep(child_sd, target);
if (!ret)
goto out; /* Child path boo-yah */
}
@@ -1098,7 +1094,7 @@ static int configfs_do_depend_item(struct dentry *subsys_dentry,
spin_lock(&configfs_dirent_lock);
/* Scan the tree, return 0 if found */
- ret = configfs_depend_prep(subsys_dentry, target);
+ ret = configfs_depend_prep(subsys_dentry->d_fsdata, target);
if (ret)
goto out_unlock_dirent_lock;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 168/982] net: ibm: emac: mal: fix potential system hang in mal_remove()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 167/982] configfs_depend_prep(): pass configfs_dirent instead of dentry Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 169/982] platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table Greg Kroah-Hartman
` (820 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit 7c5d41f87f079990bf241359e3c1332d8d10fe87 ]
napi_disable() is not idempotent and calling it on an already-disabled
or unenabled NAPI context will cause the kernel to spin indefinitely
waiting for the NAPI_STATE_SCHED bit to clear.
In mal_remove(), napi_disable() is called unconditionally. If no MACs were
registered, NAPI was never enabled. Also, if they were registered but
subsequently unregistered, NAPI was already disabled in
mal_unregister_commac(). In either case, calling napi_disable() causes
the kernel to hang upon module removal.
Fix this by only calling napi_disable() in mal_remove() if the commac list
is not empty (which implies NAPI is enabled).
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Link: https://patch.msgid.link/20260603230821.5619-1-rosenp@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ibm/emac/mal.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/ibm/emac/mal.c b/drivers/net/ethernet/ibm/emac/mal.c
index f30a2b8a7c173..4e8afa8ad5e4a 100644
--- a/drivers/net/ethernet/ibm/emac/mal.c
+++ b/drivers/net/ethernet/ibm/emac/mal.c
@@ -716,13 +716,13 @@ static int mal_remove(struct platform_device *ofdev)
MAL_DBG(mal, "remove" NL);
/* Synchronize with scheduled polling */
- napi_disable(&mal->napi);
-
- if (!list_empty(&mal->list))
+ if (!list_empty(&mal->list)) {
+ napi_disable(&mal->napi);
/* This is *very* bad */
WARN(1, KERN_EMERG
"mal%d: commac list is not empty on remove!\n",
mal->index);
+ }
free_irq(mal->serr_irq, mal);
free_irq(mal->txde_irq, mal);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 169/982] platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 168/982] net: ibm: emac: mal: fix potential system hang in mal_remove() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 170/982] wifi: mt76: transform aspm_conf for pci_disable_link_state Greg Kroah-Hartman
` (819 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gleb Sonichev, Pali Rohár,
Ilpo Järvinen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gleb Sonichev <sonichev555@gmail.com>
[ Upstream commit bfe91a80b13f8068f6fa07aa8c468d284150d4ad ]
The Inspiron N5110 needs the touchpad LED quirk (Vostro V130 quirk)
to properly control the touchpad LED. Add its DMI identifier
to the existing quirk table, next to the similar Inspiron M5110 entry.
Tested on Dell Inspiron N5110.
The touchpad LED works correctly with this quirk enabled.
Signed-off-by: Gleb Sonichev <sonichev555@gmail.com>
Acked-by: Pali Rohár <pali@kernel.org>
Link: https://patch.msgid.link/20260525100047.20046-1-sonichev555@gmail.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/dell/dell-laptop.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/platform/x86/dell/dell-laptop.c b/drivers/platform/x86/dell/dell-laptop.c
index e92c3ad06d696..215861c11dc45 100644
--- a/drivers/platform/x86/dell/dell-laptop.c
+++ b/drivers/platform/x86/dell/dell-laptop.c
@@ -205,6 +205,15 @@ static const struct dmi_system_id dell_quirks[] __initconst = {
},
.driver_data = &quirk_dell_vostro_v130,
},
+ {
+ .callback = dmi_matched,
+ .ident = "Dell Inspiron N5110",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "Dell Inc."),
+ DMI_MATCH(DMI_PRODUCT_NAME, "Inspiron N5110"),
+ },
+ .driver_data = &quirk_dell_vostro_v130,
+ },
{
.callback = dmi_matched,
.ident = "Dell Vostro 3360",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 170/982] wifi: mt76: transform aspm_conf for pci_disable_link_state
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 169/982] platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 171/982] btrfs: protect sb_write_pointer() with invalidate lock Greg Kroah-Hartman
` (818 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiajia Liu, Felix Fietkau,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiajia Liu <liujiajia@kylinos.cn>
[ Upstream commit 2dd78856223484895306351df1f903a4b75d213f ]
commit b478e162f227 ("PCI/ASPM: Consolidate link state defines") changed
PCIE_LINK_STATE_L0S (1) to (BIT(0) | BIT(1)). PCI_EXP_LNKCTL_ASPM_L0S (1)
and PCI_EXP_LNKCTL_ASPM_L1 (2) are no longer matched with
PCIE_LINK_STATE_L0S (3) and PCIE_LINK_STATE_L1 (4).
On the platform enabling ASPM L0s and L1, mt76_pci_disable_aspm is not able
to disable L1. Fix this by transforming aspm_conf to pcie link state.
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
Link: https://patch.msgid.link/20260602054349.42429-1-liujia6264@gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/pci.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/pci.c b/drivers/net/wireless/mediatek/mt76/pci.c
index 4c1c159fbb62f..36dba6e03e8b4 100644
--- a/drivers/net/wireless/mediatek/mt76/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/pci.c
@@ -30,8 +30,14 @@ void mt76_pci_disable_aspm(struct pci_dev *pdev)
if (IS_ENABLED(CONFIG_PCIEASPM)) {
int err;
+ int state = 0;
- err = pci_disable_link_state(pdev, aspm_conf);
+ if (aspm_conf & PCI_EXP_LNKCTL_ASPM_L0S)
+ state |= PCIE_LINK_STATE_L0S;
+ if (aspm_conf & PCI_EXP_LNKCTL_ASPM_L1)
+ state |= PCIE_LINK_STATE_L1;
+
+ err = pci_disable_link_state(pdev, state);
if (!err)
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 171/982] btrfs: protect sb_write_pointer() with invalidate lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 170/982] wifi: mt76: transform aspm_conf for pci_disable_link_state Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 172/982] hwmon: (adt7462) Add of_match_table to support devicetree Greg Kroah-Hartman
` (817 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, KangNing Liao, Qu Wenruo,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: KangNing Liao <lkangn.kernel@gmail.com>
[ Upstream commit 123b9a545f4d0348e81f558a032bf2a93ee5722f ]
sb_write_pointer() reads the super block from the block device page cache
using read_cache_page_gfp(). This has the same race with BLKBSZSET as the
one fixed by commit 3f29d661e568 ("btrfs: sync read disk super and set
block size").
Take the mapping invalidate lock around read_cache_page_gfp() to
serialize the read against block size changes.
Signed-off-by: KangNing Liao <lkangn.kernel@gmail.com>
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/zoned.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
index 4e2ed51297ea1..1c4f959923dd4 100644
--- a/fs/btrfs/zoned.c
+++ b/fs/btrfs/zoned.c
@@ -123,8 +123,10 @@ static int sb_write_pointer(struct block_device *bdev, struct blk_zone *zones,
u64 bytenr = ALIGN_DOWN(zone_end, BTRFS_SUPER_INFO_SIZE) -
BTRFS_SUPER_INFO_SIZE;
+ filemap_invalidate_lock(mapping);
page[i] = read_cache_page_gfp(mapping,
bytenr >> PAGE_SHIFT, GFP_NOFS);
+ filemap_invalidate_unlock(mapping);
if (IS_ERR(page[i])) {
if (i == 1)
btrfs_release_disk_super(super[0]);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 172/982] hwmon: (adt7462) Add of_match_table to support devicetree
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 171/982] btrfs: protect sb_write_pointer() with invalidate lock Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 173/982] vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add() Greg Kroah-Hartman
` (816 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kory Maincent, Romain Gantois,
Guenter Roeck, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kory Maincent <kory.maincent@bootlin.com>
[ Upstream commit cd1b42617aafe01810ab7d3b9948d2f5fa9fb8af ]
Add of_match_table to add support of devicetree probing.
Signed-off-by: Kory Maincent <kory.maincent@bootlin.com>
[rgantois: Removed of_match_ptr().]
Signed-off-by: Romain Gantois <romain.gantois@bootlin.com>
Link: https://lore.kernel.org/r/20260608-adt7462-bindings-v2-1-272982c40325@bootlin.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/adt7462.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/hwmon/adt7462.c b/drivers/hwmon/adt7462.c
index 9c0235849d4b6..f6ec0c1e51b19 100644
--- a/drivers/hwmon/adt7462.c
+++ b/drivers/hwmon/adt7462.c
@@ -12,6 +12,7 @@
#include <linux/hwmon.h>
#include <linux/hwmon-sysfs.h>
#include <linux/err.h>
+#include <linux/mod_devicetable.h>
#include <linux/mutex.h>
#include <linux/log2.h>
#include <linux/slab.h>
@@ -1814,10 +1815,17 @@ static const struct i2c_device_id adt7462_id[] = {
};
MODULE_DEVICE_TABLE(i2c, adt7462_id);
+static const struct of_device_id adt7462_of_match[] = {
+ { .compatible = "onnn,adt7462" },
+ { },
+};
+MODULE_DEVICE_TABLE(of, adt7462_of_match);
+
static struct i2c_driver adt7462_driver = {
.class = I2C_CLASS_HWMON,
.driver = {
.name = "adt7462",
+ .of_match_table = adt7462_of_match,
},
.probe_new = adt7462_probe,
.id_table = adt7462_id,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 173/982] vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 172/982] hwmon: (adt7462) Add of_match_table to support devicetree Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 174/982] ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC Greg Kroah-Hartman
` (815 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Evgenii Burenchev, Jason Wang,
Zhu Lingshan, Michael S. Tsirkin, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Evgenii Burenchev <evg28bur@yandex.ru>
[ Upstream commit 4c653e85857b41a7148917f2628fae1d04a9c251 ]
dev_set_name() may fail and return an error, but its return value
is currently ignored and overwritten by _vdpa_register_device().
Abort device creation if dev_set_name() fails and release the
device reference to avoid continuing with an improperly initialized
struct device.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Signed-off-by: Evgenii Burenchev <evg28bur@yandex.ru>
Acked-by: Jason Wang <jasowang@redhat.com>
Acked-by: Zhu Lingshan <lingshan.zhu@kernel.org>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260226152924.38790-1-evg28bur@yandex.ru>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/vdpa/ifcvf/ifcvf_main.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/vdpa/ifcvf/ifcvf_main.c b/drivers/vdpa/ifcvf/ifcvf_main.c
index d5036f49f161a..b1711b2e30ceb 100644
--- a/drivers/vdpa/ifcvf/ifcvf_main.c
+++ b/drivers/vdpa/ifcvf/ifcvf_main.c
@@ -766,15 +766,22 @@ static int ifcvf_vdpa_dev_add(struct vdpa_mgmt_dev *mdev, const char *name,
ret = dev_set_name(&vdpa_dev->dev, "%s", name);
else
ret = dev_set_name(&vdpa_dev->dev, "vdpa%u", vdpa_dev->index);
+ if (ret) {
+ IFCVF_ERR(pdev, "Failed to set device name");
+ goto err;
+ }
ret = _vdpa_register_device(&adapter->vdpa, vf->nr_vring);
if (ret) {
- put_device(&adapter->vdpa.dev);
IFCVF_ERR(pdev, "Failed to register to vDPA bus");
- return ret;
+ goto err;
}
return 0;
+
+err:
+ put_device(&adapter->vdpa.dev);
+ return ret;
}
static void ifcvf_vdpa_dev_del(struct vdpa_mgmt_dev *mdev, struct vdpa_device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 174/982] ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 173/982] vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 175/982] ata: libata-pmp: add JMicron JMS562 quirk Greg Kroah-Hartman
` (814 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Furst Blumier, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Furst Blumier <seal@furst.blue>
[ Upstream commit 98e157916f83c26a41448267180944048d2f1460 ]
The HP 255 15.6 inch G9 Notebook PC (PCI SSID 103c:8a1b) uses the
ALC236 codec but lacks an entry in the quirk table, causing the kernel
to fall back to a null SSID match (103c:0000) and skip the necessary
fixup. Add a quirk entry using ALC236_FIXUP_HP_MUTE_LED_COEFBIT2,
matching the HP 255 G8 which uses the same codec and fixup. This fixes
the mute-button LED and fixes an issue with unplugging and replugging a
headset jack not being recognized as an audio sink.
Signed-off-by: Furst Blumier <seal@furst.blue>
Link: https://patch.msgid.link/20260609201706.502075-1-seal@furst.blue
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 94bcf1fc639b9..a7e802e6d0d58 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -10021,6 +10021,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x103c, 0x89ca, "HP", ALC236_FIXUP_HP_MUTE_LED_MICMUTE_VREF),
SND_PCI_QUIRK(0x103c, 0x89d3, "HP EliteBook 645 G9 (MB 89D2)", ALC236_FIXUP_HP_MUTE_LED_MICMUTE_VREF),
SND_PCI_QUIRK(0x103c, 0x8a0f, "HP Pavilion 14-ec1xxx", ALC287_FIXUP_HP_GPIO_LED),
+ SND_PCI_QUIRK(0x103c, 0x8a1b, "HP 255 15.6 inch G9 Notebook PC", ALC236_FIXUP_HP_MUTE_LED_COEFBIT2),
SND_PCI_QUIRK(0x103c, 0x8a1f, "HP Laptop 14s-dr5xxx", ALC236_FIXUP_HP_MUTE_LED_COEFBIT2),
SND_PCI_QUIRK(0x103c, 0x8a20, "HP Laptop 15s-fq5xxx", ALC236_FIXUP_HP_MUTE_LED_COEFBIT2),
SND_PCI_QUIRK(0x103c, 0x8a25, "HP Victus 16-d1xxx (MB 8A25)", ALC245_FIXUP_HP_MUTE_LED_COEFBIT),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 175/982] ata: libata-pmp: add JMicron JMS562 quirk
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 174/982] ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 176/982] platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table Greg Kroah-Hartman
` (813 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xu Rao, Damien Le Moal,
Niklas Cassel, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Rao <raoxu@uniontech.com>
[ Upstream commit c62aff1174cf88e10716c7513702443c47551fc6 ]
JMicron JMS562, as used in QNAP QDA-A2AR RAID1 adapters, may
keep the exported ATA device not ready while the array is rebuilding.
In this state, libata may repeatedly try to softreset and classify
the fan-out link. On the affected adapter, this can time out, make
PMP/SCR access fail, and eventually disable the fan-out link before
the RAID volume is exported.
A failing boot shows the fan-out link failing SRST, PMP access
timing out, SCR read failing, and the link being disabled:
ata4.00: softreset failed (device not ready)
ata4.15: qc timeout after 3000 msecs (cmd 0xe4)
ata4.00: failed to read SCR 0 (Emask=0x4)
ata4.00: failed to recover link after 3 tries, disabling
After that, the root filesystem on the exported RAID volume cannot
be found.
Add JMS562 to the existing JMicron PMP quirk that disables LPM,
avoids softreset on fan-out links, and assumes an ATA device. This
prevents libata from dropping the exported RAID volume during rebuild
recovery.
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ata/libata-pmp.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/ata/libata-pmp.c b/drivers/ata/libata-pmp.c
index e2e9cbd405fa0..97f9fe5f5fb02 100644
--- a/drivers/ata/libata-pmp.c
+++ b/drivers/ata/libata-pmp.c
@@ -446,8 +446,13 @@ static void sata_pmp_quirks(struct ata_port *ap)
* otherwise. Don't try hard to recover it.
*/
ap->pmp_link[ap->nr_pmp_links - 1].flags |= ATA_LFLAG_NO_RETRY;
- } else if (vendor == 0x197b && (devid == 0x2352 || devid == 0x0325)) {
+ } else if (vendor == 0x197b &&
+ (devid == 0x0562 || devid == 0x2352 || devid == 0x0325)) {
/*
+ * 0x0562: JMicron JMS562, as used in QNAP QDA-A2AR RAID1
+ * adapters. The exported device may stay not ready
+ * while the array is rebuilding, and SRST/classify can
+ * time out before the RAID volume is exported.
* 0x2352: found in Thermaltake BlackX Duet, jmicron JMB350?
* 0x0325: jmicron JMB394.
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 176/982] platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 175/982] ata: libata-pmp: add JMicron JMS562 quirk Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 177/982] sctp: Unwind address notifier registration on failure Greg Kroah-Hartman
` (812 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Metchev, Hans de Goede,
Ilpo Järvinen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikolay Metchev <nikolaymetchev@gmail.com>
[ Upstream commit c39023ca9a447f09c072080efc84d6874c2275c9 ]
The volume rocker buttons on the HP ProBook x360 440 G1 convertible emit
events 0xc4-0xc7 via the intel-hid ACPI device (INT33D5). These codes are
only present in intel_array_keymap, which is used when the "5 button
array" input device exists. On this machine button_array_present()
returns false because the firmware does not advertise the array through
the HEBC method, so notify_handler() routes the events to a NULL
priv->array and they are dropped as "unknown event 0xc4". As a result
the side volume keys do nothing.
Add the machine to button_array_table so the array device is created and
the volume rocker emits KEY_VOLUMEUP / KEY_VOLUMEDOWN. This is equivalent
to booting with the enable_5_button_array=1 module parameter, which was
used to confirm the fix on the affected hardware.
Signed-off-by: Nikolay Metchev <nikolaymetchev@gmail.com>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Link: https://patch.msgid.link/20260609213309.445019-1-nikolaymetchev@gmail.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/intel/hid.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/platform/x86/intel/hid.c b/drivers/platform/x86/intel/hid.c
index ddf46fceb1c37..a6d4c8e3a78db 100644
--- a/drivers/platform/x86/intel/hid.c
+++ b/drivers/platform/x86/intel/hid.c
@@ -123,6 +123,13 @@ static const struct dmi_system_id button_array_table[] = {
DMI_MATCH(DMI_PRODUCT_NAME, "Surface Go 4"),
},
},
+ {
+ .ident = "HP ProBook x360 440 G1",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "HP"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "HP ProBook x360 440 G1"),
+ },
+ },
{ }
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 177/982] sctp: Unwind address notifier registration on failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 176/982] platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 178/982] PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems Greg Kroah-Hartman
` (811 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit c8459ee2fef502d6ef6c063751c33d9ac7943eab ]
sctp_v4_add_protocol() and sctp_v6_add_protocol() register their
address notifiers before registering the SCTP protocol handlers. If
protocol registration fails, the functions return without unregistering
the notifiers.
Unregister the notifiers on the protocol registration failure paths.
Also propagate notifier registration failures instead of ignoring them.
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260608162230.46644-1-dbgh9129@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/ipv6.c | 10 ++++++++--
net/sctp/protocol.c | 10 ++++++++--
2 files changed, 16 insertions(+), 4 deletions(-)
diff --git a/net/sctp/ipv6.c b/net/sctp/ipv6.c
index be190f5696d88..3b07b9f5d7525 100644
--- a/net/sctp/ipv6.c
+++ b/net/sctp/ipv6.c
@@ -1202,11 +1202,17 @@ void sctp_v6_protosw_exit(void)
/* Register with inet6 layer. */
int sctp_v6_add_protocol(void)
{
+ int ret;
+
/* Register notifier for inet6 address additions/deletions. */
- register_inet6addr_notifier(&sctp_inet6addr_notifier);
+ ret = register_inet6addr_notifier(&sctp_inet6addr_notifier);
+ if (ret)
+ return ret;
- if (inet6_add_protocol(&sctpv6_protocol, IPPROTO_SCTP) < 0)
+ if (inet6_add_protocol(&sctpv6_protocol, IPPROTO_SCTP) < 0) {
+ unregister_inet6addr_notifier(&sctp_inet6addr_notifier);
return -EAGAIN;
+ }
return 0;
}
diff --git a/net/sctp/protocol.c b/net/sctp/protocol.c
index 9384ff5418d59..c6a5af7560748 100644
--- a/net/sctp/protocol.c
+++ b/net/sctp/protocol.c
@@ -1269,12 +1269,18 @@ static void sctp_v4_protosw_exit(void)
static int sctp_v4_add_protocol(void)
{
+ int ret;
+
/* Register notifier for inet address additions/deletions. */
- register_inetaddr_notifier(&sctp_inetaddr_notifier);
+ ret = register_inetaddr_notifier(&sctp_inetaddr_notifier);
+ if (ret)
+ return ret;
/* Register SCTP with inet layer. */
- if (inet_add_protocol(&sctp_protocol, IPPROTO_SCTP) < 0)
+ if (inet_add_protocol(&sctp_protocol, IPPROTO_SCTP) < 0) {
+ unregister_inetaddr_notifier(&sctp_inetaddr_notifier);
return -EAGAIN;
+ }
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 178/982] PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 177/982] sctp: Unwind address notifier registration on failure Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 179/982] dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc Greg Kroah-Hartman
` (810 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jose Ignacio Tornos Martinez,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
[ Upstream commit 6a4f64c3a3ada43e71ef1e06da89beb36bdaeefa ]
Some Qualcomm PCIe devices (WCN6855/WCN7850 WiFi cards, SDX62/SDX65 modems)
do not properly support Secondary Bus Reset (SBR).
Testing confirms this is device-specific, not deployment-specific:
MediaTek MT7925e successfully uses bus reset through the same passive
M.2-to-PCIe adapters where Qualcomm devices fail, proving PERST# is
properly wired through the adapters.
Prevent use of Secondary Bus Reset for these devices.
Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://lore.kernel.org/all/20260609163649.319755-4-jtornosm@redhat.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/quirks.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c
index 41779aea9b2bc..a9c5dfdd11a85 100644
--- a/drivers/pci/quirks.c
+++ b/drivers/pci/quirks.c
@@ -3673,6 +3673,9 @@ DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x003c, quirk_no_bus_reset);
DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x0033, quirk_no_bus_reset);
DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x0034, quirk_no_bus_reset);
DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x003e, quirk_no_bus_reset);
+DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_QCOM, 0x1103, quirk_no_bus_reset); /* WCN6855 */
+DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_QCOM, 0x1107, quirk_no_bus_reset); /* WCN7850 */
+DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_QCOM, 0x0308, quirk_no_bus_reset); /* SDX62/SDX65 */
/*
* Root port on some Cavium CN8xxx chips do not successfully complete a bus
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 179/982] dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 178/982] PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 180/982] hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i Greg Kroah-Hartman
` (809 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tze Yee Ng, Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tze Yee Ng <tze.yee.ng@altera.com>
[ Upstream commit df0c2dc68770cf43f15df40b184df030b850ea05 ]
The driver only had runtime PM callbacks. If a channel stayed allocated
across system suspend/resume, the runtime usage count could remain
non-zero while hardware state (DMAC_CFG, clocks) was lost, and
axi_dma_runtime_resume() would not run to restore it.
Add system-sleep PM ops that use pm_runtime_force_suspend() and
pm_runtime_force_resume() so suspend/resume reuses the existing
axi_dma_suspend() and axi_dma_resume() paths.
Replace pm_runtime_get() with pm_runtime_resume_and_get() in
dma_chan_alloc_chan_resources() so clocks are enabled before a client
can immediately submit a transfer and touch MMIO.
Signed-off-by: Tze Yee Ng <tze.yee.ng@altera.com>
Link: https://patch.msgid.link/18bf778a3a1cc2f377ef8eb0d1508d8ac6371896.1779688569.git.tze.yee.ng@altera.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c b/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
index 46b080941b621..d313db5379f8c 100644
--- a/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
+++ b/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
@@ -464,11 +464,17 @@ static void dw_axi_dma_synchronize(struct dma_chan *dchan)
static int dma_chan_alloc_chan_resources(struct dma_chan *dchan)
{
struct axi_dma_chan *chan = dchan_to_axi_dma_chan(dchan);
+ int ret;
+
+ ret = pm_runtime_resume_and_get(chan->chip->dev);
+ if (ret < 0)
+ return ret;
/* ASSERT: channel is idle */
if (axi_chan_is_hw_enable(chan)) {
dev_err(chan2dev(chan), "%s is non-idle!\n",
axi_chan_name(chan));
+ pm_runtime_put(chan->chip->dev);
return -EBUSY;
}
@@ -479,12 +485,11 @@ static int dma_chan_alloc_chan_resources(struct dma_chan *dchan)
64, 0);
if (!chan->desc_pool) {
dev_err(chan2dev(chan), "No memory for descriptors\n");
+ pm_runtime_put(chan->chip->dev);
return -ENOMEM;
}
dev_vdbg(dchan2dev(dchan), "%s: allocating\n", axi_chan_name(chan));
- pm_runtime_get(chan->chip->dev);
-
return 0;
}
@@ -1548,6 +1553,8 @@ static int dw_remove(struct platform_device *pdev)
}
static const struct dev_pm_ops dw_axi_dma_pm_ops = {
+ SET_SYSTEM_SLEEP_PM_OPS(pm_runtime_force_suspend,
+ pm_runtime_force_resume)
SET_RUNTIME_PM_OPS(axi_dma_runtime_suspend, axi_dma_runtime_resume, NULL)
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 180/982] hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 179/982] dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 181/982] spi: xilinx: let transfers timeout in case of no IRQ Greg Kroah-Hartman
` (808 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Potin Lai, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Potin Lai <potin.lai.pt@gmail.com>
[ Upstream commit 83dda7ed185501ba1f8165aeca83ff4a8ef7c263 ]
Swap the high setting and low setting coefficients in the lm25066_coeff
table for LM5064, LM5066, and LM5066i. The coefficients were previously
mapped incorrectly, resulting in inverted current and power scaling.
Additionally, dynamically assign the exponent (R) registers inside the
probe's LM25066_DEV_SETUP_CL check. This ensures that the proper
exponent is applied (e.g., for LM25056, high setting power exponent
is -4, but low setting power exponent is -3).
Signed-off-by: Potin Lai <potin.lai.pt@gmail.com>
Link: https://lore.kernel.org/r/20260611-lm25066-driver-fix-v3-1-9d7d4b4e253d@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/pmbus/lm25066.c | 54 ++++++++++++++++++-----------------
1 file changed, 28 insertions(+), 26 deletions(-)
diff --git a/drivers/hwmon/pmbus/lm25066.c b/drivers/hwmon/pmbus/lm25066.c
index 8fef24a25d728..25b8d9fbb5a1a 100644
--- a/drivers/hwmon/pmbus/lm25066.c
+++ b/drivers/hwmon/pmbus/lm25066.c
@@ -133,23 +133,23 @@ static const struct __coeff lm25066_coeff[][PSC_NUM_CLASSES + 2] = {
.R = -2,
},
[PSC_CURRENT_IN] = {
- .m = 10742,
- .b = 1552,
+ .m = 5456,
+ .b = 2118,
.R = -2,
},
[PSC_CURRENT_IN_L] = {
- .m = 5456,
- .b = 2118,
+ .m = 10742,
+ .b = 1552,
.R = -2,
},
[PSC_POWER] = {
- .m = 1204,
- .b = 8524,
+ .m = 612,
+ .b = 11202,
.R = -3,
},
[PSC_POWER_L] = {
- .m = 612,
- .b = 11202,
+ .m = 1204,
+ .b = 8524,
.R = -3,
},
[PSC_TEMPERATURE] = {
@@ -168,23 +168,23 @@ static const struct __coeff lm25066_coeff[][PSC_NUM_CLASSES + 2] = {
.R = -2,
},
[PSC_CURRENT_IN] = {
- .m = 10753,
- .b = -1200,
+ .m = 5405,
+ .b = -600,
.R = -2,
},
[PSC_CURRENT_IN_L] = {
- .m = 5405,
- .b = -600,
+ .m = 10753,
+ .b = -1200,
.R = -2,
},
[PSC_POWER] = {
- .m = 1204,
- .b = -6000,
+ .m = 605,
+ .b = -8000,
.R = -3,
},
[PSC_POWER_L] = {
- .m = 605,
- .b = -8000,
+ .m = 1204,
+ .b = -6000,
.R = -3,
},
[PSC_TEMPERATURE] = {
@@ -203,23 +203,23 @@ static const struct __coeff lm25066_coeff[][PSC_NUM_CLASSES + 2] = {
.R = -2,
},
[PSC_CURRENT_IN] = {
- .m = 15076,
- .b = -504,
+ .m = 7645,
+ .b = 100,
.R = -2,
},
[PSC_CURRENT_IN_L] = {
- .m = 7645,
- .b = 100,
+ .m = 15076,
+ .b = -504,
.R = -2,
},
[PSC_POWER] = {
- .m = 1701,
- .b = -4000,
+ .m = 861,
+ .b = -965,
.R = -3,
},
[PSC_POWER_L] = {
- .m = 861,
- .b = -965,
+ .m = 1701,
+ .b = -4000,
.R = -3,
},
[PSC_TEMPERATURE] = {
@@ -520,18 +520,20 @@ static int lm25066_probe(struct i2c_client *client)
info->m[PSC_VOLTAGE_OUT] = coeff[PSC_VOLTAGE_OUT].m;
info->b[PSC_VOLTAGE_OUT] = coeff[PSC_VOLTAGE_OUT].b;
info->R[PSC_VOLTAGE_OUT] = coeff[PSC_VOLTAGE_OUT].R;
- info->R[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN].R;
- info->R[PSC_POWER] = coeff[PSC_POWER].R;
if (config & LM25066_DEV_SETUP_CL) {
info->m[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN_L].m;
info->b[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN_L].b;
+ info->R[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN_L].R;
info->m[PSC_POWER] = coeff[PSC_POWER_L].m;
info->b[PSC_POWER] = coeff[PSC_POWER_L].b;
+ info->R[PSC_POWER] = coeff[PSC_POWER_L].R;
} else {
info->m[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN].m;
info->b[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN].b;
+ info->R[PSC_CURRENT_IN] = coeff[PSC_CURRENT_IN].R;
info->m[PSC_POWER] = coeff[PSC_POWER].m;
info->b[PSC_POWER] = coeff[PSC_POWER].b;
+ info->R[PSC_POWER] = coeff[PSC_POWER].R;
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 181/982] spi: xilinx: let transfers timeout in case of no IRQ
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 180/982] hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 182/982] Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV Greg Kroah-Hartman
` (807 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vadim Fedorenko, Michal Simek,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
[ Upstream commit 0f95264f49ace739d411fd9149e2b3545d741d06 ]
In case of failed HW the driver may not see an interrupt and will stuck
in waiting forever. We can avoid such situation by timing out of
transfers if the interrupt is not seen in a reasonable time.
This problem can be found on unload of ptp_ocp driver for TimeCard which
uses Xilinx SPI AXI and SPI-NOR flash memory. During tear-down process
spi-nor drivers send soft reset command which is not triggering an
interrupt stalling the unload process completely.
Signed-off-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Acked-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260610222843.782337-1-vadim.fedorenko@linux.dev
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-xilinx.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/spi/spi-xilinx.c b/drivers/spi/spi-xilinx.c
index 6551628998926..0c8360d7f39bc 100644
--- a/drivers/spi/spi-xilinx.c
+++ b/drivers/spi/spi-xilinx.c
@@ -283,7 +283,11 @@ static int xilinx_spi_txrx_bufs(struct spi_device *spi, struct spi_transfer *t)
if (use_irq) {
xspi->write_fn(cr, xspi->regs + XSPI_CR_OFFSET);
- wait_for_completion(&xspi->done);
+ if (!wait_for_completion_timeout(&xspi->done, secs_to_jiffies(1))) {
+ dev_err(&spi->dev, "SPI transfer timed out\n");
+ xspi_init_hw(xspi);
+ return -ETIMEDOUT;
+ }
/* A transmit has just completed. Process received data
* and check for more data to transmit. Always inhibit
* the transmitter while the Isr refills the transmit
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 182/982] Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 181/982] spi: xilinx: let transfers timeout in case of no IRQ Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 183/982] Bluetooth: btusb: Add support for TP-Link TL-UB250 Greg Kroah-Hartman
` (806 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hrvoje Nuic, Luiz Augusto von Dentz,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hrvoje Nuic <hrvoje.nuic@gmail.com>
[ Upstream commit ce21a5cf3d1fd92b84ea9ad2b7c7240aff2162d2 ]
Add the USB ID for the Mercusys MA530 Bluetooth adapter. The device uses
a Realtek RTL8761BUV controller and works with the existing Realtek setup
path.
The device reports vendor ID 0x2c4e and product ID 0x0115, and loads the
rtl_bt/rtl8761bu_fw.bin firmware successfully with this quirk.
Signed-off-by: Hrvoje Nuic <hrvoje.nuic@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index acf58aaa551ef..0e38bf99d572b 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -659,6 +659,8 @@ static const struct usb_device_id blacklist_table[] = {
{ USB_DEVICE(0x2ff8, 0xb011), .driver_info = BTUSB_REALTEK },
/* Additional Realtek 8761BUV Bluetooth devices */
+ { USB_DEVICE(0x2c4e, 0x0115), .driver_info = BTUSB_REALTEK |
+ BTUSB_WIDEBAND_SPEECH },
{ USB_DEVICE(0x2357, 0x0604), .driver_info = BTUSB_REALTEK |
BTUSB_WIDEBAND_SPEECH },
{ USB_DEVICE(0x0b05, 0x190e), .driver_info = BTUSB_REALTEK |
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 183/982] Bluetooth: btusb: Add support for TP-Link TL-UB250
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 182/982] Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 184/982] Bluetooth: L2CAP: validate connectionless PSM length Greg Kroah-Hartman
` (805 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul Menzel, Cris,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cris <cxs1494089474@gmail.com>
[ Upstream commit ea77debfe443f505a4edbb7f21340a583a8a143f ]
Add USB ID 2357:0607 for TP-Link TL-UB250.
This is a Realtek RTL8761BUV based Bluetooth adapter.
Without this entry the device is picked up by the generic Bluetooth USB
class match and exposes hci0, but the Realtek setup path is not used and
rtl8761bu firmware/config are not loaded.
The controller reports Realtek Semiconductor Corporation as the
manufacturer and LMP subversion 0x8761. With this entry added, btusb
loads rtl_bt/rtl8761bu_fw.bin and rtl_bt/rtl8761bu_config.bin
successfully.
Relevant part of /sys/kernel/debug/usb/devices:
T: Bus=01 Lev=02 Prnt=06 Port=00 Cnt=01 Dev#= 9 Spd=12 MxCh= 0
D: Ver= 1.10 Cls=e0(wlcon) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=2357 ProdID=0607 Rev= 2.00
S: Product=TP-Link TL-UB250 Adapter
C:* #Ifs= 2 Cfg#= 1 Atr=e0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
I:* If#= 1 Alt= 0 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
Use the same flags as the existing TP-Link 2357:0604 entry.
Reviewed-by: Paul Menzel <pmenzel@molgen.mpg.de>
Signed-off-by: Cris <cxs1494089474@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 0e38bf99d572b..795a6b3de900d 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -663,6 +663,8 @@ static const struct usb_device_id blacklist_table[] = {
BTUSB_WIDEBAND_SPEECH },
{ USB_DEVICE(0x2357, 0x0604), .driver_info = BTUSB_REALTEK |
BTUSB_WIDEBAND_SPEECH },
+ { USB_DEVICE(0x2357, 0x0607), .driver_info = BTUSB_REALTEK |
+ BTUSB_WIDEBAND_SPEECH },
{ USB_DEVICE(0x0b05, 0x190e), .driver_info = BTUSB_REALTEK |
BTUSB_WIDEBAND_SPEECH },
{ USB_DEVICE(0x2550, 0x8761), .driver_info = BTUSB_REALTEK |
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 184/982] Bluetooth: L2CAP: validate connectionless PSM length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 183/982] Bluetooth: btusb: Add support for TP-Link TL-UB250 Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 185/982] ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt Greg Kroah-Hartman
` (804 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Samuel Moelius,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Samuel Moelius <sam.moelius@trailofbits.com>
[ Upstream commit a40a5f922546b3bd7c094d882b29177db4f2abe0 ]
Connectionless L2CAP frames carry a two-byte PSM at the start of the
payload. l2cap_recv_frame() currently reads that PSM unconditionally
after validating only the outer L2CAP length.
A malformed connectionless frame with a zero- or one-byte payload can
therefore make the parser read beyond the advertised skb payload and use
tailroom bytes as part of the PSM. A VHCI-backed QEMU reproducer
injected a one-byte connectionless payload and reached the unchecked
read.
Reject connectionless frames that cannot contain the PSM before reading
or pulling it. This preserves all valid connectionless frames while
dropping only structurally incomplete packets.
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/l2cap_core.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
index 836db84816d67..3097ffd654c1e 100644
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -7137,6 +7137,11 @@ static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
break;
case L2CAP_CID_CONN_LESS:
+ if (skb->len < L2CAP_PSMLEN_SIZE) {
+ kfree_skb(skb);
+ break;
+ }
+
psm = get_unaligned((__le16 *) skb->data);
skb_pull(skb, L2CAP_PSMLEN_SIZE);
l2cap_conless_channel(conn, psm, skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 185/982] ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (183 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 184/982] Bluetooth: L2CAP: validate connectionless PSM length Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 186/982] ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence Greg Kroah-Hartman
` (803 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI Review, bui duc phuc,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: bui duc phuc <phucduc.bui@gmail.com>
[ Upstream commit ee7b5f7b39332febf917f9ebf212842cc9379815 ]
rockchip_pdm_set_fmt() calls pm_runtime_get_sync() before accessing
hardware registers, but ignores its return value.
If the runtime resume fails, the function continues to perform register
accesses while the device state is undefined.
Replace pm_runtime_get_sync() with pm_runtime_resume_and_get() and
return early on failure to avoid unpowered register accesses.
Reported-by: Sashiko AI Review <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260522110302.349421F000E9@smtp.kernel.org/
Signed-off-by: bui duc phuc <phucduc.bui@gmail.com>
Link: https://patch.msgid.link/20260602101608.45137-6-phucduc.bui@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/rockchip/rockchip_pdm.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/sound/soc/rockchip/rockchip_pdm.c b/sound/soc/rockchip/rockchip_pdm.c
index 5b1e47bdc376b..336d0eb0e8b47 100644
--- a/sound/soc/rockchip/rockchip_pdm.c
+++ b/sound/soc/rockchip/rockchip_pdm.c
@@ -322,6 +322,7 @@ static int rockchip_pdm_set_fmt(struct snd_soc_dai *cpu_dai,
{
struct rk_pdm_dev *pdm = to_info(cpu_dai);
unsigned int mask = 0, val = 0;
+ int ret;
mask = PDM_CKP_MSK;
switch (fmt & SND_SOC_DAIFMT_INV_MASK) {
@@ -335,7 +336,10 @@ static int rockchip_pdm_set_fmt(struct snd_soc_dai *cpu_dai,
return -EINVAL;
}
- pm_runtime_get_sync(cpu_dai->dev);
+ ret = pm_runtime_resume_and_get(cpu_dai->dev);
+ if (ret)
+ return ret;
+
regmap_update_bits(pdm->regmap, PDM_CLK_CTRL, mask, val);
pm_runtime_put(cpu_dai->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 186/982] ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (184 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 185/982] ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 187/982] ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure Greg Kroah-Hartman
` (802 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, bui duc phuc, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: bui duc phuc <phucduc.bui@gmail.com>
[ Upstream commit 3168721d6ec3b610edf6a3c22ad190722a27d276 ]
Enable the 'hclk' bus clock before the 'clk' controller clock during
runtime resume.
The bus clock provides the register access interface, so enable it before
the controller clock. This also makes the resume sequence the reverse of
the suspend sequence, which keeps the clock ordering consistent.
Signed-off-by: bui duc phuc <phucduc.bui@gmail.com>
Link: https://patch.msgid.link/20260602101608.45137-4-phucduc.bui@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/rockchip/rockchip_pdm.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/sound/soc/rockchip/rockchip_pdm.c b/sound/soc/rockchip/rockchip_pdm.c
index 336d0eb0e8b47..6a412b834b76e 100644
--- a/sound/soc/rockchip/rockchip_pdm.c
+++ b/sound/soc/rockchip/rockchip_pdm.c
@@ -427,16 +427,16 @@ static int rockchip_pdm_runtime_resume(struct device *dev)
struct rk_pdm_dev *pdm = dev_get_drvdata(dev);
int ret;
- ret = clk_prepare_enable(pdm->clk);
+ ret = clk_prepare_enable(pdm->hclk);
if (ret) {
- dev_err(pdm->dev, "clock enable failed %d\n", ret);
+ dev_err(pdm->dev, "hclock enable failed %d\n", ret);
return ret;
}
- ret = clk_prepare_enable(pdm->hclk);
+ ret = clk_prepare_enable(pdm->clk);
if (ret) {
- clk_disable_unprepare(pdm->clk);
- dev_err(pdm->dev, "hclock enable failed %d\n", ret);
+ clk_disable_unprepare(pdm->hclk);
+ dev_err(pdm->dev, "clock enable failed %d\n", ret);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 187/982] ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (185 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 186/982] ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 188/982] sparc64: uprobes: add missing break Greg Kroah-Hartman
` (801 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI Review, bui duc phuc,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: bui duc phuc <phucduc.bui@gmail.com>
[ Upstream commit 3546e9aa691ac981e4734fedd1646d0180784893 ]
If regcache_sync() fails during runtime resume, the driver disables the
clocks and returns an error. However, the regmap cache-only mode is left
disabled.
Restore cache-only mode in the error path so subsequent register accesses
continue to use the cache while the device is inactive.
Reported-by: Sashiko AI Review <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260522103713.6C09D1F000E9@smtp.kernel.org/
Signed-off-by: bui duc phuc <phucduc.bui@gmail.com>
Link: https://patch.msgid.link/20260602101608.45137-5-phucduc.bui@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/rockchip/rockchip_spdif.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/soc/rockchip/rockchip_spdif.c b/sound/soc/rockchip/rockchip_spdif.c
index 5b4f004575879..d10fbae8d473c 100644
--- a/sound/soc/rockchip/rockchip_spdif.c
+++ b/sound/soc/rockchip/rockchip_spdif.c
@@ -98,6 +98,7 @@ static int __maybe_unused rk_spdif_runtime_resume(struct device *dev)
ret = regcache_sync(spdif->regmap);
if (ret) {
+ regcache_cache_only(spdif->regmap, true);
clk_disable_unprepare(spdif->mclk);
clk_disable_unprepare(spdif->hclk);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 188/982] sparc64: uprobes: add missing break
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (186 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 187/982] ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 189/982] net: stmmac: xgmac2: disable RBUE in default RX interrupt mask Greg Kroah-Hartman
` (800 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev,
Masami Hiramatsu (Google), Andreas Larsson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit 5b0eee4cd812bd6547eea393cb9b5c0322f26c88 ]
Missing fallthrough causes failure with newer compilers:
arch/sparc/kernel/uprobes.c:284:2: error: unannotated fall-through between switch labels [-Werror,-Wimplicit-fallthrough]
284 | default:
| ^
arch/sparc/kernel/uprobes.c:284:2: note: insert 'break;' to avoid fall-through
284 | default:
| ^
| break;
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Andreas Larsson <andreas@gaisler.com>
Signed-off-by: Andreas Larsson <andreas@gaisler.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/sparc/kernel/uprobes.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/sparc/kernel/uprobes.c b/arch/sparc/kernel/uprobes.c
index 1a0600206bf5c..dbc51dc2bb4f4 100644
--- a/arch/sparc/kernel/uprobes.c
+++ b/arch/sparc/kernel/uprobes.c
@@ -278,6 +278,7 @@ int arch_uprobe_exception_notify(struct notifier_block *self,
case DIE_SSTEP:
if (uprobe_post_sstep_notifier(args->regs))
ret = NOTIFY_STOP;
+ break;
default:
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 189/982] net: stmmac: xgmac2: disable RBUE in default RX interrupt mask
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (187 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 188/982] sparc64: uprobes: add missing break Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 190/982] ptp: ocp: add shutdown callback Greg Kroah-Hartman
` (799 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Nazim Amirul,
Simon Horman, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nazim Amirul <muhammad.nazim.amirul.nazle.asmade@altera.com>
[ Upstream commit d3265c19b35d036bba327b36b5366bee76b0157c ]
Enabling the RX Buffer Unavailable (RBUE) interrupt is counterproductive
and can trigger a MAC interrupt storm under heavy RX pressure. When the
DMA runs out of RX descriptors it fires RBUE continuously until software
refills the ring.
However, RBUE is redundant: the normal RX completion interrupt (RIE)
already triggers NAPI, which processes completed descriptors and refills
the ring, causing the DMA to resume. The RBUE handler itself only sets
handle_rx - the same outcome as RIE.
On Agilex5 under heavy RX pressure, the MAC interrupt (which includes
RBUE) was observed firing 1,821,811,555 times against only 2,618,627
actual RX completions - a ~695x ratio - confirming the severity of the
storm.
RBUE does not provide OOM recovery. If page_pool is exhausted,
stmmac_rx_refill() cannot advance the DMA tail pointer, the DMA stays
suspended, and RBUE fires again on the next NAPI completion - a storm
with no forward progress. This patch trades that storm for a clean
stall with the same RX outcome. Proper OOM recovery is a pre-existing
gap outside the scope of this fix.
Note: as a consequence of disabling RBUE, the rx_buf_unav_irq ethtool
counter will always read 0 on XGMAC2 devices. This behaviour is already
inconsistent across DWMAC core versions.
Remove RBUE from XGMAC_DMA_INT_DEFAULT_EN and XGMAC_DMA_INT_DEFAULT_RX
to prevent the interrupt storm while keeping normal RX handling intact.
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Signed-off-by: Nazim Amirul <muhammad.nazim.amirul.nazle.asmade@altera.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260609121703.9736-1-muhammad.nazim.amirul.nazle.asmade@altera.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/dwxgmac2.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/dwxgmac2.h b/drivers/net/ethernet/stmicro/stmmac/dwxgmac2.h
index 8748c37e9dac9..f9110e6164843 100644
--- a/drivers/net/ethernet/stmicro/stmmac/dwxgmac2.h
+++ b/drivers/net/ethernet/stmicro/stmmac/dwxgmac2.h
@@ -398,9 +398,9 @@
#define XGMAC_RIE BIT(6)
#define XGMAC_TBUE BIT(2)
#define XGMAC_TIE BIT(0)
-#define XGMAC_DMA_INT_DEFAULT_EN (XGMAC_NIE | XGMAC_AIE | XGMAC_RBUE | \
+#define XGMAC_DMA_INT_DEFAULT_EN (XGMAC_NIE | XGMAC_AIE | \
XGMAC_RIE | XGMAC_TIE)
-#define XGMAC_DMA_INT_DEFAULT_RX (XGMAC_RBUE | XGMAC_RIE)
+#define XGMAC_DMA_INT_DEFAULT_RX (XGMAC_RIE)
#define XGMAC_DMA_INT_DEFAULT_TX (XGMAC_TIE)
#define XGMAC_DMA_CH_Rx_WATCHDOG(x) (0x0000313c + (0x80 * (x)))
#define XGMAC_RWT GENMASK(7, 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 190/982] ptp: ocp: add shutdown callback
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (188 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 189/982] net: stmmac: xgmac2: disable RBUE in default RX interrupt mask Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 191/982] vsock: use sk_acceptq_is_full() helper in all transports Greg Kroah-Hartman
` (798 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vadim Fedorenko, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
[ Upstream commit f6f955cbf9d4e02deebe54ca91c118b53be9ffe6 ]
The shutdown callback was never implemented for this driver, but it's
needed because .remove() callback is never called during kexec/reboot
process. That leaves HW with some interrupts enabled and may cause
spurious interrupt while booting into a new kernel during with kexec.
If it happens that I2C interrupt fires during kexec, the whole I2C bus
is disabled leaving TimeCard with no devlink communication. The same
happens if timestampers were enabled, leaving the card without
timestamper interrupts until full reboot cycle.
Implement .shutdown() callback with the same function as remove
callback.
Signed-off-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260611190333.787132-1-vadim.fedorenko@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ptp/ptp_ocp.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/ptp/ptp_ocp.c b/drivers/ptp/ptp_ocp.c
index c4793bb13e3cb..f2332b954bcf0 100644
--- a/drivers/ptp/ptp_ocp.c
+++ b/drivers/ptp/ptp_ocp.c
@@ -3794,6 +3794,7 @@ static struct pci_driver ptp_ocp_driver = {
.id_table = ptp_ocp_pcidev_id,
.probe = ptp_ocp_probe,
.remove = ptp_ocp_remove,
+ .shutdown = ptp_ocp_remove,
};
static int
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 191/982] vsock: use sk_acceptq_is_full() helper in all transports
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (189 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 190/982] ptp: ocp: add shutdown callback Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 192/982] e1000e: limit endianness conversion to boundary words Greg Kroah-Hartman
` (797 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefano Garzarella, Raf Dickson,
Luigi Leonardi, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raf Dickson <rafdog35@gmail.com>
[ Upstream commit 4ff2e84ff1b33d79fa0e3ae355ce4a334908ef9a ]
Replace the open-coded backlog check with sk_acceptq_is_full().
The helper uses > instead of >=, which is the correct comparison
per commit 64a146513f8f ("[NET]: Revert incorrect accept queue
backlog changes."), and adds READ_ONCE() for proper memory ordering.
Suggested-by: Stefano Garzarella <sgarzare@redhat.com>
Signed-off-by: Raf Dickson <rafdog35@gmail.com>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Reviewed-by: Luigi Leonardi <leonardi@redhat.com>
Link: https://patch.msgid.link/20260612045842.122207-1-rafdog35@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/vmw_vsock/hyperv_transport.c | 2 +-
net/vmw_vsock/vmci_transport.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/vmw_vsock/hyperv_transport.c b/net/vmw_vsock/hyperv_transport.c
index cf8a2194a37f7..66dd3ded053fe 100644
--- a/net/vmw_vsock/hyperv_transport.c
+++ b/net/vmw_vsock/hyperv_transport.c
@@ -323,7 +323,7 @@ static void hvs_open_connection(struct vmbus_channel *chan)
goto out;
if (conn_from_host) {
- if (sk->sk_ack_backlog >= sk->sk_max_ack_backlog)
+ if (sk_acceptq_is_full(sk))
goto out;
new = vsock_create_connected(sk);
diff --git a/net/vmw_vsock/vmci_transport.c b/net/vmw_vsock/vmci_transport.c
index 6217c3122a074..ff3602d45de92 100644
--- a/net/vmw_vsock/vmci_transport.c
+++ b/net/vmw_vsock/vmci_transport.c
@@ -1002,7 +1002,7 @@ static int vmci_transport_recv_listen(struct sock *sk,
* reset. Otherwise we create and initialize a child socket and reply
* with a connection negotiation.
*/
- if (sk->sk_ack_backlog >= sk->sk_max_ack_backlog) {
+ if (sk_acceptq_is_full(sk)) {
vmci_transport_reply_reset(pkt);
return -ECONNREFUSED;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 192/982] e1000e: limit endianness conversion to boundary words
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (190 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 191/982] vsock: use sk_acceptq_is_full() helper in all transports Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 193/982] net/sched: act_csum: dont mangle UDP tunnel GSO packets Greg Kroah-Hartman
` (796 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iskhakov Daniil, Agalakov Daniil,
Avigail Dahan, Tony Nguyen, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Agalakov Daniil <ade@amicon.ru>
[ Upstream commit a5ecafcfb27baf2dba766c4fd99dbb947f4e85d8 ]
[Why]
In e1000_set_eeprom(), the eeprom_buff is allocated to hold a range of
words. However, only the boundary words (the first and the last) are
populated from the EEPROM if the write request is not word-aligned.
The words in the middle of the buffer remain uninitialized because they
are intended to be completely overwritten by the new data via memcpy().
The previous implementation had a loop that performed le16_to_cpus()
on the entire buffer. This resulted in endianness conversion being
performed on uninitialized memory for all interior words.
Fix this by converting the endianness only for the boundary words
immediately after they are successfully read from the EEPROM.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Co-developed-by: Iskhakov Daniil <dish@amicon.ru>
Signed-off-by: Iskhakov Daniil <dish@amicon.ru>
Signed-off-by: Agalakov Daniil <ade@amicon.ru>
Tested-by: Avigail Dahan <avigailx.dahan@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Link: https://patch.msgid.link/20260609213559.178657-14-anthony.l.nguyen@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/e1000e/ethtool.c | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/intel/e1000e/ethtool.c b/drivers/net/ethernet/intel/e1000e/ethtool.c
index 40de9f6893310..359f018d03c2b 100644
--- a/drivers/net/ethernet/intel/e1000e/ethtool.c
+++ b/drivers/net/ethernet/intel/e1000e/ethtool.c
@@ -597,20 +597,25 @@ static int e1000_set_eeprom(struct net_device *netdev,
/* need read/modify/write of first changed EEPROM word */
/* only the second byte of the word is being modified */
ret_val = e1000_read_nvm(hw, first_word, 1, &eeprom_buff[0]);
+ if (ret_val)
+ goto out;
+
+ /* Device's eeprom is always little-endian, word addressable */
+ le16_to_cpus(&eeprom_buff[0]);
+
ptr++;
}
- if (((eeprom->offset + eeprom->len) & 1) && (!ret_val))
+ if ((eeprom->offset + eeprom->len) & 1) {
/* need read/modify/write of last changed EEPROM word */
/* only the first byte of the word is being modified */
ret_val = e1000_read_nvm(hw, last_word, 1,
&eeprom_buff[last_word - first_word]);
+ if (ret_val)
+ goto out;
- if (ret_val)
- goto out;
-
- /* Device's eeprom is always little-endian, word addressable */
- for (i = 0; i < last_word - first_word + 1; i++)
- le16_to_cpus(&eeprom_buff[i]);
+ /* Device's eeprom is always little-endian, word addressable */
+ le16_to_cpus(&eeprom_buff[last_word - first_word]);
+ }
memcpy(ptr, bytes, eeprom->len);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 193/982] net/sched: act_csum: dont mangle UDP tunnel GSO packets
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (191 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 192/982] e1000e: limit endianness conversion to boundary words Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 194/982] i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA Greg Kroah-Hartman
` (795 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alice Mikityanska, Davide Caratti,
Willem de Bruijn, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alice Mikityanska <alice@isovalent.com>
[ Upstream commit 9bcb30b389ec5888590cb6ec58c7a3b80fe49a11 ]
Similar to commit add641e7dee3 ("sched: act_csum: don't mangle TCP and
UDP GSO packets"), UDP tunnel GSO packets going through act_csum
shouldn't have their checksum calculated at this point, because it will
be done after segmentation. Setting the checksum in act_csum modifies
skb->ip_summed and prevents inner IP csum offload from kicking in,
resulting in a packet with a bad checksum.
Add UDP tunnel GSO packets to the exceptions, and also add UDP GSO
(SKB_GSO_UDP_L4), as the same logic as in the commit mentioned above
applies to UDP GSO too.
Signed-off-by: Alice Mikityanska <alice@isovalent.com>
Reviewed-by: Davide Caratti <dcaratti@redhat.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260611192955.604661-2-alice.kernel@fastmail.im
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_csum.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/net/sched/act_csum.c b/net/sched/act_csum.c
index bcef42a3ad645..4e4cf29f0c069 100644
--- a/net/sched/act_csum.c
+++ b/net/sched/act_csum.c
@@ -257,7 +257,9 @@ static int tcf_csum_ipv4_udp(struct sk_buff *skb, unsigned int ihl,
const struct iphdr *iph;
u16 ul;
- if (skb_is_gso(skb) && skb_shinfo(skb)->gso_type & SKB_GSO_UDP)
+ if (skb_is_gso(skb) && skb_shinfo(skb)->gso_type &
+ (SKB_GSO_UDP | SKB_GSO_UDP_L4 |
+ SKB_GSO_UDP_TUNNEL | SKB_GSO_UDP_TUNNEL_CSUM))
return 1;
/*
@@ -313,7 +315,9 @@ static int tcf_csum_ipv6_udp(struct sk_buff *skb, unsigned int ihl,
const struct ipv6hdr *ip6h;
u16 ul;
- if (skb_is_gso(skb) && skb_shinfo(skb)->gso_type & SKB_GSO_UDP)
+ if (skb_is_gso(skb) && skb_shinfo(skb)->gso_type &
+ (SKB_GSO_UDP | SKB_GSO_UDP_L4 |
+ SKB_GSO_UDP_TUNNEL | SKB_GSO_UDP_TUNNEL_CSUM))
return 1;
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 194/982] i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (192 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 193/982] net/sched: act_csum: dont mangle UDP tunnel GSO packets Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 195/982] sparc: Disable compat support with LLD Greg Kroah-Hartman
` (794 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter, Frank Li,
Alexandre Belloni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit c236563c8a84239d31a1e6ec4444887a7b5ed98f ]
i3c_master_add_i3c_dev_locked() no longer leaves the address marked as
free on failure, so aborting the DAA sequence on its error is unnecessary.
Failure to register a discovered device does not invalidate the entire
Dynamic Address Assignment (DAA) procedure. Align with the behavior of
other I3C master drivers by ignoring errors from
i3c_master_add_i3c_dev_locked() and continuing enumeration.
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260612080107.11606-5-adrian.hunter@intel.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/i3c/master/mipi-i3c-hci/cmd_v1.c | 4 +---
drivers/i3c/master/mipi-i3c-hci/cmd_v2.c | 4 +---
2 files changed, 2 insertions(+), 6 deletions(-)
diff --git a/drivers/i3c/master/mipi-i3c-hci/cmd_v1.c b/drivers/i3c/master/mipi-i3c-hci/cmd_v1.c
index 61e34ed8ca533..3be836e859234 100644
--- a/drivers/i3c/master/mipi-i3c-hci/cmd_v1.c
+++ b/drivers/i3c/master/mipi-i3c-hci/cmd_v1.c
@@ -359,9 +359,7 @@ static int hci_cmd_v1_daa(struct i3c_hci *hci)
* TODO: Extend the subsystem layer to allow for registering
* new device and provide BCR/DCR/PID at the same time.
*/
- ret = i3c_master_add_i3c_dev_locked(&hci->master, next_addr);
- if (ret)
- break;
+ i3c_master_add_i3c_dev_locked(&hci->master, next_addr);
}
if (dat_idx >= 0)
diff --git a/drivers/i3c/master/mipi-i3c-hci/cmd_v2.c b/drivers/i3c/master/mipi-i3c-hci/cmd_v2.c
index 3d33bfe937a6a..3ab51aaf63dc1 100644
--- a/drivers/i3c/master/mipi-i3c-hci/cmd_v2.c
+++ b/drivers/i3c/master/mipi-i3c-hci/cmd_v2.c
@@ -299,9 +299,7 @@ static int hci_cmd_v2_daa(struct i3c_hci *hci)
* TODO: Extend the subsystem layer to allow for registering
* new device and provide BCR/DCR/PID at the same time.
*/
- ret = i3c_master_add_i3c_dev_locked(&hci->master, next_addr);
- if (ret)
- break;
+ i3c_master_add_i3c_dev_locked(&hci->master, next_addr);
}
hci_free_xfer(xfer, 2);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 195/982] sparc: Disable compat support with LLD
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (193 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 194/982] i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 196/982] ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT Greg Kroah-Hartman
` (793 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev, Nathan Chancellor,
Andreas Larsson, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit 852fed2e8bfe195351fb0078ba7245d41154e7a5 ]
An LLVM=1 sparc64 allmodconfig enables COMPAT and then tries to
build the 32-bit vDSO. That path cannot be linked with ld.lld:
ld.lld: error: unknown emulation: elf32_sparc
ld.lld does not support the 32-bit SPARC ELF emulation used for
the compat vDSO, so keep COMPAT disabled when LLD is the linker.
This avoids selecting an unsupported build path while leaving the
existing GNU ld configuration unchanged.
Assisted-by: Codex:GPT-5.5
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Acked-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Andreas Larsson <andreas@gaisler.com>
Link: https://lore.kernel.org/r/20260508000834.834824-1-rosenp@gmail.com
Signed-off-by: Andreas Larsson <andreas@gaisler.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/sparc/Kconfig | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/sparc/Kconfig b/arch/sparc/Kconfig
index b67d96e3392e5..deb664e7d0142 100644
--- a/arch/sparc/Kconfig
+++ b/arch/sparc/Kconfig
@@ -487,6 +487,7 @@ endmenu
config COMPAT
bool
depends on SPARC64
+ depends on !LD_IS_LLD
default y
select HAVE_UID16
select ARCH_WANT_OLD_COMPAT_IPC
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 196/982] ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (194 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 195/982] sparc: Disable compat support with LLD Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 197/982] HID: hidpp: fix potential UAF in hidpp_connect_event() Greg Kroah-Hartman
` (792 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Viktor Menshin, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viktor Menshin <ripeeerr@gmail.com>
[ Upstream commit 3a3e810e91080a5121170ee11554a55ed89a1c8b ]
The Lenovo Xiaoxin 14 GT (Chinese market model, AMD Ryzen AI 9 365)
produces constant electrical hissing and crackling noise from both
internal speakers and 3.5mm headphone jack during audio playback.
Audio works correctly on Windows.
The PCI SSID 17aa:3912 is not present in the quirk list. The device
shares the same AMD platform and ALC287 codec as neighboring Lenovo
14" AMD models (17aa:3911, 17aa:390d), so apply the same fixup.
Note: the fixup selection is based on similarity with neighboring
models and has not been verified by testing a compiled kernel.
Guidance from maintainers on the correct fixup is welcome.
Signed-off-by: Viktor Menshin <ripeeerr@gmail.com>
Link: https://patch.msgid.link/20260615092515.1082-1-ripeeerr@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index a7e802e6d0d58..5ff2e113054fe 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -10399,6 +10399,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x17aa, 0x3902, "Lenovo E50-80", ALC269_FIXUP_DMIC_THINKPAD_ACPI),
SND_PCI_QUIRK(0x17aa, 0x390d, "Lenovo Yoga Pro 7 14ASP10", ALC287_FIXUP_YOGA9_14IAP7_BASS_SPK_PIN),
SND_PCI_QUIRK(0x17aa, 0x3911, "Lenovo Yoga Pro 7 14IAH10", ALC287_FIXUP_YOGA9_14IAP7_BASS_SPK_PIN),
+ SND_PCI_QUIRK(0x17aa, 0x3912, "Lenovo Xiaoxin 14 GT", ALC287_FIXUP_YOGA9_14IAP7_BASS_SPK_PIN),
SND_PCI_QUIRK(0x17aa, 0x3913, "Lenovo 145", ALC236_FIXUP_LENOVO_INV_DMIC),
SND_PCI_QUIRK(0x17aa, 0x3977, "IdeaPad S210", ALC283_FIXUP_INT_MIC),
SND_PCI_QUIRK(0x17aa, 0x3978, "Lenovo B50-70", ALC269_FIXUP_DMIC_THINKPAD_ACPI),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 197/982] HID: hidpp: fix potential UAF in hidpp_connect_event()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (195 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 196/982] ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 198/982] fuse: set ff->flock only on success Greg Kroah-Hartman
` (791 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, zdi-disclosures, Jiri Kosina,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Kosina <jkosina@suse.com>
[ Upstream commit 6df6b1f2c49678211f65647c300bc51dda02893b ]
If input_register_device() fails, we call input_free_device(), but keep
stale pointer to the old device in hidpp->input, which could potentially
lead to UAF. Fix that by resetting it to NULL before returning from
hidpp_connect_event().
Reported-by: zdi-disclosures@trendmicro.com
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-logitech-hidpp.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/hid/hid-logitech-hidpp.c b/drivers/hid/hid-logitech-hidpp.c
index eae0b0b46439d..1d4df88f690c0 100644
--- a/drivers/hid/hid-logitech-hidpp.c
+++ b/drivers/hid/hid-logitech-hidpp.c
@@ -4056,6 +4056,7 @@ static void hidpp_connect_event(struct hidpp_device *hidpp)
ret = input_register_device(input);
if (ret) {
+ hidpp->input = NULL;
input_free_device(input);
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 198/982] fuse: set ff->flock only on success
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (196 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 197/982] HID: hidpp: fix potential UAF in hidpp_connect_event() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 199/982] scsi: bfa: Reduce kernel stack usage in bfa_fcs_lport_fdmi_build_portattr_block() Greg Kroah-Hartman
` (790 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Yichao, Zhang Tianci,
Miklos Szeredi, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhang Tianci <zhangtianci.1997@bytedance.com>
[ Upstream commit 71947173cef279be5eed209ec28f8c11f9d73159 ]
If FUSE_SETLK fails (e.g., due to EWOULDBLOCK), we shall not set
FUSE_RELEASE_FLOCK_UNLOCK in fuse_file_release().
Reported-by: Li Yichao <liyichao.1@bytedance.com>
Signed-off-by: Zhang Tianci <zhangtianci.1997@bytedance.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/fuse/file.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/fuse/file.c b/fs/fuse/file.c
index 30da0d0397f23..56774b31d5ff6 100644
--- a/fs/fuse/file.c
+++ b/fs/fuse/file.c
@@ -2668,8 +2668,9 @@ static int fuse_file_flock(struct file *file, int cmd, struct file_lock *fl)
struct fuse_file *ff = file->private_data;
/* emulate flock with POSIX locks */
- ff->flock = true;
err = fuse_setlk(file, fl, 1);
+ if (!err)
+ ff->flock = true;
}
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 199/982] scsi: bfa: Reduce kernel stack usage in bfa_fcs_lport_fdmi_build_portattr_block()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (197 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 198/982] fuse: set ff->flock only on success Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 200/982] gpio: pisosr: Read "ngpios" as u32 Greg Kroah-Hartman
` (789 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Martin K. Petersen,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
[ Upstream commit 57a6ed0b41677ccc5e28cc0976e495c1dfa33747 ]
bfa_fcs_fdmi_get_portattr() gets inlined into multiple places and has
two fairly large variables on the stack, to the point of causing a
warning in some randconfig builds:
drivers/scsi/bfa/bfa_fcs_lport.c:2198:1: error: stack frame size (1560) exceeds limit (1280) in 'bfa_fcs_lport_fdmi_build_portattr_block' [-Werror,-Wframe-larger-than]
2198 | bfa_fcs_lport_fdmi_build_portattr_block(struct bfa_fcs_lport_fdmi_s *fdmi,
| ^
drivers/scsi/bfa/bfa_fcs_lport.c:1856:1: error: stack frame size (1600) exceeds limit (1280) in 'bfa_fcs_lport_fdmi_build_rhba_pyld' [-Werror,-Wframe-larger-than]
1856 | bfa_fcs_lport_fdmi_build_rhba_pyld(struct bfa_fcs_lport_fdmi_s *fdmi, u8 *pyld)
| ^
Mark the inner function as noinline_for_stack to keep it separate from
the other variables and prevent multiple copies of the same variable to
get inlined here.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260611125601.3385418-1-arnd@kernel.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/bfa/bfa_fcs_lport.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/bfa/bfa_fcs_lport.c b/drivers/scsi/bfa/bfa_fcs_lport.c
index b12afcc4b1894..58360ea4f0109 100644
--- a/drivers/scsi/bfa/bfa_fcs_lport.c
+++ b/drivers/scsi/bfa/bfa_fcs_lport.c
@@ -2673,7 +2673,7 @@ bfa_fcs_fdmi_get_hbaattr(struct bfa_fcs_lport_fdmi_s *fdmi,
}
-static void
+static noinline_for_stack void
bfa_fcs_fdmi_get_portattr(struct bfa_fcs_lport_fdmi_s *fdmi,
struct bfa_fcs_fdmi_port_attr_s *port_attr)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 200/982] gpio: pisosr: Read "ngpios" as u32
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (198 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 199/982] scsi: bfa: Reduce kernel stack usage in bfa_fcs_lport_fdmi_build_portattr_block() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 201/982] spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() Greg Kroah-Hartman
` (788 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rob Herring (Arm),
Bartosz Golaszewski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rob Herring (Arm) <robh@kernel.org>
[ Upstream commit 4910aa198d25e5d1067236560ba34ab12bccc677 ]
The generic "ngpios" property is encoded as a normal uint32 cell. The
pisosr driver stores it in the gpio_chip field, but reading it with a
u16 helper does not match the DT property encoding.
Read "ngpios" as u32 and keep the existing assignment to the chip
field.
Assisted-by: Codex:gpt-5-5
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Link: https://patch.msgid.link/20260612215216.1887485-1-robh@kernel.org
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-pisosr.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpio/gpio-pisosr.c b/drivers/gpio/gpio-pisosr.c
index 67071bea08c26..2c8bb0ab488ed 100644
--- a/drivers/gpio/gpio-pisosr.c
+++ b/drivers/gpio/gpio-pisosr.c
@@ -120,6 +120,7 @@ static int pisosr_gpio_probe(struct spi_device *spi)
{
struct device *dev = &spi->dev;
struct pisosr_gpio *gpio;
+ u32 ngpios;
int ret;
gpio = devm_kzalloc(dev, sizeof(*gpio), GFP_KERNEL);
@@ -130,7 +131,8 @@ static int pisosr_gpio_probe(struct spi_device *spi)
gpio->chip = template_chip;
gpio->chip.parent = dev;
- of_property_read_u16(dev->of_node, "ngpios", &gpio->chip.ngpio);
+ if (!of_property_read_u32(dev->of_node, "ngpios", &ngpios))
+ gpio->chip.ngpio = ngpios;
gpio->spi = spi;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 201/982] spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (199 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 200/982] gpio: pisosr: Read "ngpios" as u32 Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 202/982] ALSA: usb-audio: Add quirk flags for SC13A Greg Kroah-Hartman
` (787 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, guoqi0226, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: guoqi0226 <guoqi0226@163.com>
[ Upstream commit f1b061b4d4c6cbf861319ba954caa80145cf018f ]
Prevent NULL pointer dereference when spi_get_device_id() returns NULL,
which can happen when using driver_override without matching SPI ID entry.
Signed-off-by: guoqi0226 <guoqi0226@163.com>
Link: https://patch.msgid.link/20260616103018.105612-3-guoqi0226@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c
index 4fbf5925bdb89..e1eabb959c515 100644
--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -365,12 +365,16 @@ EXPORT_SYMBOL_GPL(spi_get_device_id);
const void *spi_get_device_match_data(const struct spi_device *sdev)
{
const void *match;
+ const struct spi_device_id *id;
match = device_get_match_data(&sdev->dev);
if (match)
return match;
- return (const void *)spi_get_device_id(sdev)->driver_data;
+ id = spi_get_device_id(sdev);
+ if (!id)
+ return NULL;
+ return (const void *)id->driver_data;
}
EXPORT_SYMBOL_GPL(spi_get_device_match_data);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 202/982] ALSA: usb-audio: Add quirk flags for SC13A
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (200 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 201/982] spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 203/982] tls: reject the combination of TLS and sockmap Greg Kroah-Hartman
` (786 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ai Chao, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ai Chao <aichao@kylinos.cn>
[ Upstream commit 8956950dab22fbaefe92ca1980728165c5da793d ]
The SC13A ( VID 0x1ff7, PID 0x0f81) not support reading the current
sample rate and results in an error message printed to kmsg. Set
QUIRK_FLAG_GET_SAMPLE_RATE to skip the sample rate check.
Quirky device sample:
usb 3-5.2.4.1: new high-speed USB device number 11 using xhci_hcd
usb 3-5.2.4.1: New USB device found, idVendor=1ff7, idProduct=0f81
usb 3-5.2.4.1: New USB device strings: Mfr=1, Product=2, SerialNumber=3
usb 3-5.2.4.1: Product: SC13A
usb 3-5.2.4.1: Manufacturer: Linux Foundation
usb 3-5.2.4.1: SerialNumber: 000002
usb 3-5.2.4.1: Found UVC 1.50 device SC13A (1ff7:0f81)
usb 3-5.2.4.1: 3:1: cannot get freq at ep 0x86
usb 3-5.2.4.1: Warning! Unlikely big volume range (=4096),
cval->res is probably wrong.
usb 3-5.2.4.1: [5] FU [Mic Capture Volume] ch = 1, val = 0/4096/1
usbcore: registered new interface driver snd-usb-audio
usb 3-5.2.4.1: 3:1: cannot get freq at ep 0x86
usb 3-5.2.4.1: 3:1: cannot get freq at ep 0x86
Signed-off-by: Ai Chao <aichao@kylinos.cn>
Link: https://patch.msgid.link/20260617025234.3344935-1-aichao@kylinos.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/quirks.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/usb/quirks.c b/sound/usb/quirks.c
index ece6ae4a21ed9..b575b50337cbd 100644
--- a/sound/usb/quirks.c
+++ b/sound/usb/quirks.c
@@ -2217,6 +2217,8 @@ static const struct usb_audio_quirk_flags_table quirk_flags_table[] = {
QUIRK_FLAG_GET_SAMPLE_RATE | QUIRK_FLAG_MIC_RES_16),
DEVICE_FLG(0x1bcf, 0x2283, /* NexiGo N930AF FHD Webcam */
QUIRK_FLAG_GET_SAMPLE_RATE | QUIRK_FLAG_MIC_RES_16),
+ DEVICE_FLG(0x1ff7, 0x0f81, /* SC13A Webcam */
+ QUIRK_FLAG_GET_SAMPLE_RATE),
DEVICE_FLG(0x2040, 0x7200, /* Hauppauge HVR-950Q */
QUIRK_FLAG_SHARE_MEDIA_DEVICE | QUIRK_FLAG_ALIGN_TRANSFER),
DEVICE_FLG(0x2040, 0x7201, /* Hauppauge HVR-950Q-MXL */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 203/982] tls: reject the combination of TLS and sockmap
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (201 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 202/982] ALSA: usb-audio: Add quirk flags for SC13A Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 204/982] ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10 Greg Kroah-Hartman
` (785 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Sitnicki, Sabrina Dubroca,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 460e6486617c17dd19abe8f3fc67d9a6fa25f8ca ]
TLS and sockmap (BPF psock) integration hides a lot of latent bugs.
Bugs which may be more or less relevant for real users but they
are definitely exploitable.
We could not find anyone actively using this integration so let's
reject this config. Adding a TLS socket to a sockmap was already
rejected by sk_psock_init() through the inet_csk_has_ulp() check.
We need to reject the attempts to configure the TLS keys (rather
than adding the ULP itself) because checking prior to the ULP
installation is tricky without risking a race with sockmap getting
added in parallel (sockmap does not hold the socket lock).
This patch is a minimal rejection of the feature. Subsequent patch
in the series will do a light dead code removal. Full cleanup would
require a major rewrite of the Tx path, we don't need skmsg any more.
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/20260614014102.461064-2-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/tls/tls_main.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/net/tls/tls_main.c b/net/tls/tls_main.c
index 4797f68b9ec80..42c61cd1359c6 100644
--- a/net/tls/tls_main.c
+++ b/net/tls/tls_main.c
@@ -665,6 +665,17 @@ static int do_tls_setsockopt_conf(struct sock *sk, sockptr_t optval,
int rc = 0;
int conf;
+ /* TLS and sockmap are mutually exclusive. A socket already in a
+ * sockmap (i.e. with a psock attached) cannot be upgraded to TLS.
+ * sockmap rejects TLS sockets already (see sk_psock_init()).
+ */
+ rcu_read_lock();
+ if (sk_psock(sk)) {
+ rcu_read_unlock();
+ return -EINVAL;
+ }
+ rcu_read_unlock();
+
if (sockptr_is_null(optval) || (optlen < sizeof(*crypto_info)))
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 204/982] ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (202 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 203/982] tls: reject the combination of TLS and sockmap Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 205/982] leds: uleds: Return -EFAULT on copy_to_user() failure Greg Kroah-Hartman
` (784 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Galen Hassen, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Galen Hassen <rwekyes@gmail.com>
[ Upstream commit f7c4968ae3af3e819428da5416c2dfd361473f5c ]
The Lenovo IdeaPad Slim 5 16AKP10 (PCI SSID 17aa:38b6) uses the
Conexant SN6140 codec. The internal microphone is on pin 0x1a but
the BIOS configures it with pin default 0x95a60120, which includes
a jack detection bit that causes the kernel to treat it as an
unplugged external mic rather than a fixed internal mic.
Add a pin config quirk that overrides pin 0x1a to 0x95a60130,
setting the connectivity bits to indicate a fixed/always-connected
device. This allows the internal microphone to be correctly
identified and used.
Signed-off-by: Galen Hassen <rwekyes@gmail.com>
Link: https://patch.msgid.link/20260616173257.37373-1-rwekyes@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_conexant.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c
index 0aed86820402c..0a2ebb8789bb3 100644
--- a/sound/pci/hda/patch_conexant.c
+++ b/sound/pci/hda/patch_conexant.c
@@ -307,6 +307,7 @@ enum {
CXT_FIXUP_HEADSET_MIC,
CXT_FIXUP_HP_MIC_NO_PRESENCE,
CXT_PINCFG_SWS_JS201D,
+ CXT_PINCFG_LENOVO_IDEAPAD_SLIM5_16AKP10,
CXT_PINCFG_TOP_SPEAKER,
CXT_FIXUP_HP_A_U,
CXT_FIXUP_ACER_SWIFT_HP,
@@ -841,6 +842,12 @@ static const struct hda_pintbl cxt_pincfg_lemote[] = {
{}
};
+/* Lenovo IdeaPad Slim 5 16AKP10 with SN6140 */
+static const struct hda_pintbl cxt_pincfg_lenovo_ideapad_slim5_16akp10[] = {
+ { 0x1a, 0x95a60130 }, /* Internal mic, fixed/always-connected */
+ {}
+};
+
/* SuoWoSi/South-holding JS201D with sn6140 */
static const struct hda_pintbl cxt_pincfg_sws_js201d[] = {
{ 0x16, 0x03211040 }, /* hp out */
@@ -1032,6 +1039,10 @@ static const struct hda_fixup cxt_fixups[] = {
.type = HDA_FIXUP_PINS,
.v.pins = cxt_pincfg_sws_js201d,
},
+ [CXT_PINCFG_LENOVO_IDEAPAD_SLIM5_16AKP10] = {
+ .type = HDA_FIXUP_PINS,
+ .v.pins = cxt_pincfg_lenovo_ideapad_slim5_16akp10,
+ },
[CXT_PINCFG_TOP_SPEAKER] = {
.type = HDA_FIXUP_FUNC,
.v.func = cxt_fixup_sirius_top_speaker,
@@ -1137,6 +1148,7 @@ static const struct snd_pci_quirk cxt5066_fixups[] = {
SND_PCI_QUIRK(0x17aa, 0x21da, "Lenovo X220", CXT_PINCFG_LENOVO_TP410),
SND_PCI_QUIRK(0x17aa, 0x21db, "Lenovo X220-tablet", CXT_PINCFG_LENOVO_TP410),
SND_PCI_QUIRK(0x17aa, 0x38af, "Lenovo IdeaPad Z560", CXT_FIXUP_MUTE_LED_EAPD),
+ SND_PCI_QUIRK(0x17aa, 0x38b6, "Lenovo IdeaPad Slim 5 16AKP10", CXT_PINCFG_LENOVO_IDEAPAD_SLIM5_16AKP10),
SND_PCI_QUIRK(0x17aa, 0x3905, "Lenovo G50-30", CXT_FIXUP_STEREO_DMIC),
SND_PCI_QUIRK(0x17aa, 0x390b, "Lenovo G50-80", CXT_FIXUP_STEREO_DMIC),
SND_PCI_QUIRK(0x17aa, 0x3975, "Lenovo U300s", CXT_FIXUP_STEREO_DMIC),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 205/982] leds: uleds: Return -EFAULT on copy_to_user() failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (203 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 204/982] ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10 Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 206/982] leds: pca9532: Dont stop blinking for non-zero brightness Greg Kroah-Hartman
` (783 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yousef Alhouseen, Lee Jones,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yousef Alhouseen <alhouseenyousef@gmail.com>
[ Upstream commit 61ed78f55a46e12afd4b464c4ba736f55ff33c5e ]
uleds_read() copies the current brightness value to userspace but
ignores copy_to_user() failures. It then clears the pending update and
reports a successful full read even when no data was copied.
Return -EFAULT when the copy fails and leave the update pending so a
later read can retry.
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Link: https://patch.msgid.link/20260521181205.15130-1-alhouseenyousef@gmail.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/uleds.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/leds/uleds.c b/drivers/leds/uleds.c
index 90e54370fe7ea..3e47cb74f49ab 100644
--- a/drivers/leds/uleds.c
+++ b/drivers/leds/uleds.c
@@ -148,10 +148,13 @@ static ssize_t uleds_read(struct file *file, char __user *buffer, size_t count,
} else if (!udev->new_data && (file->f_flags & O_NONBLOCK)) {
retval = -EAGAIN;
} else if (udev->new_data) {
- retval = copy_to_user(buffer, &udev->brightness,
- sizeof(udev->brightness));
- udev->new_data = false;
- retval = sizeof(udev->brightness);
+ if (copy_to_user(buffer, &udev->brightness,
+ sizeof(udev->brightness))) {
+ retval = -EFAULT;
+ } else {
+ udev->new_data = false;
+ retval = sizeof(udev->brightness);
+ }
}
mutex_unlock(&udev->mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 206/982] leds: pca9532: Dont stop blinking for non-zero brightness
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (204 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 205/982] leds: uleds: Return -EFAULT on copy_to_user() failure Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 207/982] mfd: rsmu: Add 8a34002 support Greg Kroah-Hartman
` (782 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tobias Deiminger, Lee Jones,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tobias Deiminger <tobias.deiminger@linutronix.de>
[ Upstream commit 0261683a4d31783d680e74b3ae5f22f6a62128cc ]
pca9532 unexpectedly stopped blinking when changing brightness to a
non-zero value. To reproduce:
echo timer > /sys/class/leds/led-1/trigger # blinks
echo 255 > /sys/class/leds/led-1/brightness # blinking stops, light on
cat /sys/class/leds/led-1/trigger # still claims [timer]
According to Documentation/leds/leds-class.rst, only brightness = 0
shall be a stop condition:
> You can change the brightness value of a LED independently of the
> timer trigger. However, if you set the brightness value to LED_OFF it
> will also disable the timer trigger.
Therefore add a guard to continue blinking when brightness != LED_OFF,
similar to how pca955x does it since 575f10dc64a2 ("leds: pca955x: Add
HW blink support").
Signed-off-by: Tobias Deiminger <tobias.deiminger@linutronix.de>
Link: https://patch.msgid.link/20260331202848.658676-1-tobias.deiminger@linutronix.de
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-pca9532.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/leds/leds-pca9532.c b/drivers/leds/leds-pca9532.c
index 40abb7eb033b9..b518b40099677 100644
--- a/drivers/leds/leds-pca9532.c
+++ b/drivers/leds/leds-pca9532.c
@@ -177,11 +177,13 @@ static int pca9532_set_brightness(struct led_classdev *led_cdev,
int err = 0;
struct pca9532_led *led = ldev_to_led(led_cdev);
- if (value == LED_OFF)
+ if (value == LED_OFF) {
led->state = PCA9532_OFF;
- else if (value == LED_FULL)
+ } else if (led->state == PCA9532_PWM1) {
+ return 0; /* Non-zero brightness shall not stop HW blinking */
+ } else if (value == LED_FULL) {
led->state = PCA9532_ON;
- else {
+ } else {
led->state = PCA9532_PWM0; /* Thecus: hardcode one pwm */
err = pca9532_calcpwm(led->client, 0, 0, value);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 207/982] mfd: rsmu: Add 8a34002 support
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (205 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 206/982] leds: pca9532: Dont stop blinking for non-zero brightness Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 208/982] ALSA: usb-audio: Add quirk for YAMAHA CDS3000 Greg Kroah-Hartman
` (781 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Matthew Bystrin, Lee Jones,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Bystrin <dev.mbstr@gmail.com>
[ Upstream commit d18fd55c780c2bae3d353024cab7f8746d3d9e91 ]
Add compatible string, i2c_devcie_id and spi_devcie_id to support
8a34002.
Signed-off-by: Matthew Bystrin <dev.mbstr@gmail.com>
Link: https://patch.msgid.link/20260429072047.1111427-3-dev.mbstr@gmail.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mfd/rsmu_i2c.c | 2 ++
drivers/mfd/rsmu_spi.c | 2 ++
2 files changed, 4 insertions(+)
diff --git a/drivers/mfd/rsmu_i2c.c b/drivers/mfd/rsmu_i2c.c
index f716ab8039a06..332ca76518ace 100644
--- a/drivers/mfd/rsmu_i2c.c
+++ b/drivers/mfd/rsmu_i2c.c
@@ -156,6 +156,7 @@ static void rsmu_i2c_remove(struct i2c_client *client)
static const struct i2c_device_id rsmu_i2c_id[] = {
{ "8a34000", RSMU_CM },
{ "8a34001", RSMU_CM },
+ { "8a34002", RSMU_CM },
{ "82p33810", RSMU_SABRE },
{ "82p33811", RSMU_SABRE },
{ "8v19n850", RSMU_SL },
@@ -167,6 +168,7 @@ MODULE_DEVICE_TABLE(i2c, rsmu_i2c_id);
static const struct of_device_id rsmu_i2c_of_match[] = {
{ .compatible = "idt,8a34000", .data = (void *)RSMU_CM },
{ .compatible = "idt,8a34001", .data = (void *)RSMU_CM },
+ { .compatible = "idt,8a34002", .data = (void *)RSMU_CM },
{ .compatible = "idt,82p33810", .data = (void *)RSMU_SABRE },
{ .compatible = "idt,82p33811", .data = (void *)RSMU_SABRE },
{ .compatible = "idt,8v19n850", .data = (void *)RSMU_SL },
diff --git a/drivers/mfd/rsmu_spi.c b/drivers/mfd/rsmu_spi.c
index d2f3d8f1e05af..56195ca4fc614 100644
--- a/drivers/mfd/rsmu_spi.c
+++ b/drivers/mfd/rsmu_spi.c
@@ -230,6 +230,7 @@ static void rsmu_spi_remove(struct spi_device *client)
static const struct spi_device_id rsmu_spi_id[] = {
{ "8a34000", RSMU_CM },
{ "8a34001", RSMU_CM },
+ { "8a34002", RSMU_CM },
{ "82p33810", RSMU_SABRE },
{ "82p33811", RSMU_SABRE },
{}
@@ -239,6 +240,7 @@ MODULE_DEVICE_TABLE(spi, rsmu_spi_id);
static const struct of_device_id rsmu_spi_of_match[] = {
{ .compatible = "idt,8a34000", .data = (void *)RSMU_CM },
{ .compatible = "idt,8a34001", .data = (void *)RSMU_CM },
+ { .compatible = "idt,8a34002", .data = (void *)RSMU_CM },
{ .compatible = "idt,82p33810", .data = (void *)RSMU_SABRE },
{ .compatible = "idt,82p33811", .data = (void *)RSMU_SABRE },
{}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 208/982] ALSA: usb-audio: Add quirk for YAMAHA CDS3000
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (206 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 207/982] mfd: rsmu: Add 8a34002 support Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 209/982] PCI: iproc: Protect root bus removal with rescan lock Greg Kroah-Hartman
` (780 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jean-Louis Colaco, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jean-Louis Colaco <jean-louis.colaco@orange.fr>
[ Upstream commit 348f69320e4db6ebec6940c81154bec4b9eb275a ]
This quirk is identical to the one for the Yamaha Steinberg UR22, here
applied to a CD player that also uses the Steinberg USB interface.
This quirk is necessary to avoid sporadic "clic" noise when using the DAC
of the player.
Signed-off-by: Jean-Louis Colaco <jean-louis.colaco@orange.fr>
Link: https://patch.msgid.link/20260618113202.8363-1-jean-louis.colaco@orange.fr
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/quirks-table.h | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/sound/usb/quirks-table.h b/sound/usb/quirks-table.h
index c20a4df886906..f4995560050ab 100644
--- a/sound/usb/quirks-table.h
+++ b/sound/usb/quirks-table.h
@@ -390,6 +390,20 @@ YAMAHA_DEVICE(0x105d, NULL),
}
}
},
+{
+ USB_DEVICE(0x0499, 0x150d),
+ QUIRK_DRIVER_INFO {
+ /* .vendor_name = "Yamaha", */
+ /* .product_name = "CDS3000", */
+ QUIRK_DATA_COMPOSITE {
+ { QUIRK_DATA_STANDARD_AUDIO(1) },
+ { QUIRK_DATA_STANDARD_AUDIO(2) },
+ { QUIRK_DATA_MIDI_YAMAHA(3) },
+ { QUIRK_DATA_IGNORE(4) },
+ QUIRK_COMPOSITE_END
+ }
+ }
+},
{
USB_DEVICE(0x0499, 0x1718),
QUIRK_DRIVER_INFO {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 209/982] PCI: iproc: Protect root bus removal with rescan lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (207 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 208/982] ALSA: usb-audio: Add quirk for YAMAHA CDS3000 Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 210/982] PCI: altera: " Greg Kroah-Hartman
` (779 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hans Zhang, Manivannan Sadhasivam,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans Zhang <18255117159@163.com>
[ Upstream commit a6a64e150f12ad5391e0a0d60f6a3d119b06ce50 ]
Hold the pci_rescan_remove_lock lock while stopping and removing a root bus
to avoid racing with concurrent rescan or hotplug operations triggered via
sysfs. Such races may lead to use-after-free issues or system crashes.
Signed-off-by: Hans Zhang <18255117159@163.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
[bhelgaas: commit log]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260521161822.132996-6-18255117159@163.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/pcie-iproc.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pci/controller/pcie-iproc.c b/drivers/pci/controller/pcie-iproc.c
index 6525c7ded5c40..2eae2d1859d34 100644
--- a/drivers/pci/controller/pcie-iproc.c
+++ b/drivers/pci/controller/pcie-iproc.c
@@ -1541,8 +1541,10 @@ int iproc_pcie_remove(struct iproc_pcie *pcie)
{
struct pci_host_bridge *host = pci_host_bridge_from_priv(pcie);
+ pci_lock_rescan_remove();
pci_stop_root_bus(host->bus);
pci_remove_root_bus(host->bus);
+ pci_unlock_rescan_remove();
iproc_pcie_msi_disable(pcie);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 210/982] PCI: altera: Protect root bus removal with rescan lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (208 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 209/982] PCI: iproc: Protect root bus removal with rescan lock Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 211/982] PCI: rockchip: " Greg Kroah-Hartman
` (778 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hans Zhang, Manivannan Sadhasivam,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans Zhang <18255117159@163.com>
[ Upstream commit a8759c8ac48c0419f5899e95a6ffc611b07c965b ]
Hold the pci_rescan_remove_lock lock while stopping and removing a root bus
to avoid racing with concurrent rescan or hotplug operations triggered via
sysfs. Such races may lead to use-after-free issues or system crashes.
Signed-off-by: Hans Zhang <18255117159@163.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
[bhelgaas: commit log]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260521161822.132996-4-18255117159@163.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/pcie-altera.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pci/controller/pcie-altera.c b/drivers/pci/controller/pcie-altera.c
index afd03c47d6f5a..acdd8ed8c34fa 100644
--- a/drivers/pci/controller/pcie-altera.c
+++ b/drivers/pci/controller/pcie-altera.c
@@ -833,8 +833,10 @@ static int altera_pcie_remove(struct platform_device *pdev)
struct altera_pcie *pcie = platform_get_drvdata(pdev);
struct pci_host_bridge *bridge = pci_host_bridge_from_priv(pcie);
+ pci_lock_rescan_remove();
pci_stop_root_bus(bridge->bus);
pci_remove_root_bus(bridge->bus);
+ pci_unlock_rescan_remove();
altera_pcie_irq_teardown(pcie);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 211/982] PCI: rockchip: Protect root bus removal with rescan lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (209 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 210/982] PCI: altera: " Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 212/982] PCI: mediatek: " Greg Kroah-Hartman
` (777 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hans Zhang, Manivannan Sadhasivam,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans Zhang <18255117159@163.com>
[ Upstream commit 0bd9611587bb494c33566d825fe34b2705e4b167 ]
Hold the pci_rescan_remove_lock lock while stopping and removing a root bus
to avoid racing with concurrent rescan or hotplug operations triggered via
sysfs. Such races may lead to use-after-free issues or system crashes.
Signed-off-by: Hans Zhang <18255117159@163.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
[bhelgaas: commit log]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260521161822.132996-8-18255117159@163.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/pcie-rockchip-host.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pci/controller/pcie-rockchip-host.c b/drivers/pci/controller/pcie-rockchip-host.c
index 32b82e916b57d..de521ad927c40 100644
--- a/drivers/pci/controller/pcie-rockchip-host.c
+++ b/drivers/pci/controller/pcie-rockchip-host.c
@@ -1021,8 +1021,10 @@ static int rockchip_pcie_remove(struct platform_device *pdev)
struct rockchip_pcie *rockchip = dev_get_drvdata(dev);
struct pci_host_bridge *bridge = pci_host_bridge_from_priv(rockchip);
+ pci_lock_rescan_remove();
pci_stop_root_bus(bridge->bus);
pci_remove_root_bus(bridge->bus);
+ pci_unlock_rescan_remove();
irq_domain_remove(rockchip->irq_domain);
rockchip_pcie_deinit_phys(rockchip);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 212/982] PCI: mediatek: Protect root bus removal with rescan lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (210 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 211/982] PCI: rockchip: " Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 213/982] md/raid5: account discard IO Greg Kroah-Hartman
` (776 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hans Zhang, Manivannan Sadhasivam,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans Zhang <18255117159@163.com>
[ Upstream commit a29812a55da8d0dbeb071b26ac428c338e3fc389 ]
Hold the pci_rescan_remove_lock lock while stopping and removing a root bus
to avoid racing with concurrent rescan or hotplug operations triggered via
sysfs. Such races may lead to use-after-free issues or system crashes.
Signed-off-by: Hans Zhang <18255117159@163.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
[bhelgaas: commit log]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260521161822.132996-7-18255117159@163.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/pcie-mediatek.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pci/controller/pcie-mediatek.c b/drivers/pci/controller/pcie-mediatek.c
index 2697288af4708..c58f14de19f32 100644
--- a/drivers/pci/controller/pcie-mediatek.c
+++ b/drivers/pci/controller/pcie-mediatek.c
@@ -1174,8 +1174,10 @@ static int mtk_pcie_remove(struct platform_device *pdev)
struct mtk_pcie *pcie = platform_get_drvdata(pdev);
struct pci_host_bridge *host = pci_host_bridge_from_priv(pcie);
+ pci_lock_rescan_remove();
pci_stop_root_bus(host->bus);
pci_remove_root_bus(host->bus);
+ pci_unlock_rescan_remove();
mtk_pcie_free_resources(pcie);
mtk_pcie_irq_teardown(pcie);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 213/982] md/raid5: account discard IO
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (211 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 212/982] PCI: mediatek: " Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 214/982] md/raid5: let stripe batch bm_seq comparison wrap-safe Greg Kroah-Hartman
` (775 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yu Kuai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 74ddbf98e2db646ec58f7e7731c936b7a4a470fe ]
Raid5 handles discard bios internally through make_discard_request() and
never passes them through md_account_bio(). As a result, discard IO is
missing the md-device iostat accounting that normal raid5 IO and discard
IO in other raid levels get from md_account_bio().
Before accounting the bio, trim the request to the full data stripes that
raid5 will actually discard. The first full stripe is the ceiling of the
bio start divided by data-stripe sectors, and the last full stripe is the
floor of the bio end divided by data-stripe sectors. Account that exact
MD logical full-stripe range, then restore the original iterator so bio
completion and iostat still cover the original request.
Link: https://patch.msgid.link/20260605072639.2434847-2-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid5.c | 33 +++++++++++++++++++++++----------
1 file changed, 23 insertions(+), 10 deletions(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index 6675ca50259e0..664aa8c0781e9 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -5796,7 +5796,10 @@ static void make_discard_request(struct mddev *mddev, struct bio *bi)
{
struct r5conf *conf = mddev->private;
sector_t logical_sector, last_sector;
+ sector_t first_stripe, last_stripe;
struct stripe_head *sh;
+ struct bvec_iter bi_iter;
+ struct bio *orig_bi = bi;
int stripe_sectors;
/* We need to handle this when io_uring supports discard/trim */
@@ -5807,19 +5810,29 @@ static void make_discard_request(struct mddev *mddev, struct bio *bi)
/* Skip discard while reshape is happening */
return;
- logical_sector = bi->bi_iter.bi_sector & ~((sector_t)RAID5_STRIPE_SECTORS(conf)-1);
- last_sector = bio_end_sector(bi);
-
- bi->bi_next = NULL;
-
stripe_sectors = conf->chunk_sectors *
(conf->raid_disks - conf->max_degraded);
- logical_sector = DIV_ROUND_UP_SECTOR_T(logical_sector,
- stripe_sectors);
- sector_div(last_sector, stripe_sectors);
+ first_stripe = DIV_ROUND_UP_SECTOR_T(bi->bi_iter.bi_sector,
+ stripe_sectors);
+ last_stripe = bio_end_sector(bi);
+ sector_div(last_stripe, stripe_sectors);
+
+ if (first_stripe >= last_stripe) {
+ bio_endio(bi);
+ return;
+ }
+
+ bi_iter = bi->bi_iter;
+ bi->bi_iter.bi_sector = first_stripe * stripe_sectors;
+ bi->bi_iter.bi_size = ((last_stripe - first_stripe) *
+ stripe_sectors) << 9;
+ md_account_bio(mddev, &bi);
+ orig_bi->bi_iter = bi_iter;
+ bi->bi_iter = bi_iter;
+ bi->bi_next = NULL;
- logical_sector *= conf->chunk_sectors;
- last_sector *= conf->chunk_sectors;
+ logical_sector = first_stripe * conf->chunk_sectors;
+ last_sector = last_stripe * conf->chunk_sectors;
for (; logical_sector < last_sector;
logical_sector += RAID5_STRIPE_SECTORS(conf)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 214/982] md/raid5: let stripe batch bm_seq comparison wrap-safe
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (212 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 213/982] md/raid5: account discard IO Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 215/982] f2fs: validate inline dentry name lengths before conversion Greg Kroah-Hartman
` (774 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Cheng, Yu Kuai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Cheng <chencheng@fnnas.com>
[ Upstream commit 00e93faf4cea9e8802ac5dfee0952d84fc95c40f ]
Once the 32-bit seq wraps, a newer bm_seq can look smaller
than old, so .. covert to wrap-safe calculate way.
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Link: https://patch.msgid.link/20260618025735.915113-1-chencheng@fnnas.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid5.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index 664aa8c0781e9..dd0864df1d8cf 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -992,7 +992,7 @@ static void stripe_add_to_batch_list(struct r5conf *conf,
if (test_and_clear_bit(STRIPE_BIT_DELAY, &sh->state)) {
int seq = sh->bm_seq;
if (test_bit(STRIPE_BIT_DELAY, &sh->batch_head->state) &&
- sh->batch_head->bm_seq > seq)
+ sh->batch_head->bm_seq - seq > 0)
seq = sh->batch_head->bm_seq;
set_bit(STRIPE_BIT_DELAY, &sh->batch_head->state);
sh->batch_head->bm_seq = seq;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 215/982] f2fs: validate inline dentry name lengths before conversion
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (213 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 214/982] md/raid5: let stripe batch bm_seq comparison wrap-safe Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 216/982] rtc: aspeed: add AST2700 compatible Greg Kroah-Hartman
` (773 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Samuel Moelius, Chao Yu, Jaegeuk Kim,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Samuel Moelius <sam.moelius@trailofbits.com>
[ Upstream commit cfcd0e49a178b3dac2c0ece656079081dbf5da74 ]
Inline dentry conversion copies names out of the inline dentry area
before checking that each recorded name length fits in the available
filename slots.
A corrupted image can therefore make the conversion path read past
the inline filename storage while building the regular dentry block.
Validate each inline dentry name length against the inline filename
area before copying it.
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <samuel.moelius@trailofbits.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/f2fs/inline.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/fs/f2fs/inline.c b/fs/f2fs/inline.c
index 8e09832a0e692..e2dddced55afb 100644
--- a/fs/f2fs/inline.c
+++ b/fs/f2fs/inline.c
@@ -490,6 +490,12 @@ static int f2fs_add_inline_entries(struct inode *dir, void *inline_dentry)
bit_pos++;
continue;
}
+ if (unlikely(le16_to_cpu(de->name_len) > F2FS_NAME_LEN ||
+ bit_pos + GET_DENTRY_SLOTS(le16_to_cpu(de->name_len)) >
+ d.max)) {
+ err = -EFSCORRUPTED;
+ goto punch_dentry_pages;
+ }
/*
* We only need the disk_name and hash to move the dentry.
@@ -510,6 +516,7 @@ static int f2fs_add_inline_entries(struct inode *dir, void *inline_dentry)
bit_pos += GET_DENTRY_SLOTS(le16_to_cpu(de->name_len));
}
return 0;
+
punch_dentry_pages:
truncate_inode_pages(&dir->i_data, 0);
f2fs_truncate_blocks(dir, 0, false);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 216/982] rtc: aspeed: add AST2700 compatible
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (214 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 215/982] f2fs: validate inline dentry name lengths before conversion Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 217/982] ksmbd: align SMB2 oplock break ack handling Greg Kroah-Hartman
` (772 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tommy Huang, Alexandre Belloni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tommy Huang <tommy_huang@aspeedtech.com>
[ Upstream commit 3319cfeeb8c4047026f84df045c438f7bbd338a6 ]
Add support for matching the RTC controller on ASPEED AST2700 SoCs.
The AST2700 RTC controller is compatible with the existing ASPEED
RTC driver implementation.
Signed-off-by: Tommy Huang <tommy_huang@aspeedtech.com>
Link: https://patch.msgid.link/20260601-ast2700-rtc-v1-2-15d4ca46500a@aspeedtech.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/rtc/rtc-aspeed.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/rtc/rtc-aspeed.c b/drivers/rtc/rtc-aspeed.c
index a93352ed3aec9..4f5935b7f4a60 100644
--- a/drivers/rtc/rtc-aspeed.c
+++ b/drivers/rtc/rtc-aspeed.c
@@ -111,6 +111,7 @@ static const struct of_device_id aspeed_rtc_match[] = {
{ .compatible = "aspeed,ast2400-rtc", },
{ .compatible = "aspeed,ast2500-rtc", },
{ .compatible = "aspeed,ast2600-rtc", },
+ { .compatible = "aspeed,ast2700-rtc", },
{}
};
MODULE_DEVICE_TABLE(of, aspeed_rtc_match);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 217/982] ksmbd: align SMB2 oplock break ack handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (215 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 216/982] rtc: aspeed: add AST2700 compatible Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 218/982] ksmbd: use connection ClientGUID for lease lookup Greg Kroah-Hartman
` (771 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 80a56d4a826c6c84430286fcf7d8655f7c5b0868 ]
Handle SMB2 oplock break acknowledgments according to the server-side
validation rules in MS-SMB2.
Return STATUS_INVALID_DEVICE_STATE when an ACK arrives while the open is
not breaking, reject SMB2_OPLOCK_LEVEL_LEASE with
STATUS_INVALID_PARAMETER, allow BATCH acknowledgments to EXCLUSIVE, and
make invalid ACK levels fail with STATUS_INVALID_OPLOCK_PROTOCOL after
lowering the oplock to NONE.
Update the successful response from the final granted oplock level instead
of relying on the oplock transition helpers, which could turn invalid ACKs
into successful responses.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 104 ++++++++++++++++++----------------------
1 file changed, 46 insertions(+), 58 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 7d47f7749cdc9..4765edcff9dbd 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -8177,11 +8177,10 @@ static void smb20_oplock_break_ack(struct ksmbd_work *work)
struct smb2_oplock_break *rsp;
struct ksmbd_file *fp;
struct oplock_info *opinfo = NULL;
- __le32 err = 0;
- int ret = 0;
+ __le32 status = STATUS_SUCCESS;
+ int ret;
u64 volatile_id, persistent_id;
char req_oplevel = 0, rsp_oplevel = 0;
- unsigned int oplock_change_type;
WORK_BUFFERS(work, req, rsp);
@@ -8207,71 +8206,55 @@ static void smb20_oplock_break_ack(struct ksmbd_work *work)
return;
}
- if (opinfo->level == SMB2_OPLOCK_LEVEL_NONE) {
- rsp->hdr.Status = STATUS_INVALID_OPLOCK_PROTOCOL;
+ if (opinfo->op_state != OPLOCK_ACK_WAIT) {
+ ksmbd_debug(SMB, "unexpected oplock state 0x%x\n",
+ opinfo->op_state);
+ status = STATUS_INVALID_DEVICE_STATE;
goto err_out;
}
- if (opinfo->op_state == OPLOCK_STATE_NONE) {
- ksmbd_debug(SMB, "unexpected oplock state 0x%x\n", opinfo->op_state);
- rsp->hdr.Status = STATUS_UNSUCCESSFUL;
+ if (req_oplevel == SMB2_OPLOCK_LEVEL_LEASE) {
+ opinfo->level = SMB2_OPLOCK_LEVEL_NONE;
+ status = STATUS_INVALID_PARAMETER;
goto err_out;
}
- if ((opinfo->level == SMB2_OPLOCK_LEVEL_EXCLUSIVE ||
- opinfo->level == SMB2_OPLOCK_LEVEL_BATCH) &&
- (req_oplevel != SMB2_OPLOCK_LEVEL_II &&
- req_oplevel != SMB2_OPLOCK_LEVEL_NONE)) {
- err = STATUS_INVALID_OPLOCK_PROTOCOL;
- oplock_change_type = OPLOCK_WRITE_TO_NONE;
- } else if (opinfo->level == SMB2_OPLOCK_LEVEL_II &&
- req_oplevel != SMB2_OPLOCK_LEVEL_NONE) {
- err = STATUS_INVALID_OPLOCK_PROTOCOL;
- oplock_change_type = OPLOCK_READ_TO_NONE;
- } else if (req_oplevel == SMB2_OPLOCK_LEVEL_II ||
- req_oplevel == SMB2_OPLOCK_LEVEL_NONE) {
- err = STATUS_INVALID_DEVICE_STATE;
- if ((opinfo->level == SMB2_OPLOCK_LEVEL_EXCLUSIVE ||
- opinfo->level == SMB2_OPLOCK_LEVEL_BATCH) &&
- req_oplevel == SMB2_OPLOCK_LEVEL_II) {
- oplock_change_type = OPLOCK_WRITE_TO_READ;
- } else if ((opinfo->level == SMB2_OPLOCK_LEVEL_EXCLUSIVE ||
- opinfo->level == SMB2_OPLOCK_LEVEL_BATCH) &&
- req_oplevel == SMB2_OPLOCK_LEVEL_NONE) {
- oplock_change_type = OPLOCK_WRITE_TO_NONE;
- } else if (opinfo->level == SMB2_OPLOCK_LEVEL_II &&
- req_oplevel == SMB2_OPLOCK_LEVEL_NONE) {
- oplock_change_type = OPLOCK_READ_TO_NONE;
- } else {
- oplock_change_type = 0;
- }
- } else {
- oplock_change_type = 0;
+ if (opinfo->level == SMB2_OPLOCK_LEVEL_NONE) {
+ status = STATUS_INVALID_OPLOCK_PROTOCOL;
+ goto err_out;
}
- switch (oplock_change_type) {
- case OPLOCK_WRITE_TO_READ:
- ret = opinfo_write_to_read(opinfo);
- rsp_oplevel = SMB2_OPLOCK_LEVEL_II;
- break;
- case OPLOCK_WRITE_TO_NONE:
- ret = opinfo_write_to_none(opinfo);
- rsp_oplevel = SMB2_OPLOCK_LEVEL_NONE;
- break;
- case OPLOCK_READ_TO_NONE:
- ret = opinfo_read_to_none(opinfo);
- rsp_oplevel = SMB2_OPLOCK_LEVEL_NONE;
- break;
- default:
- pr_err("unknown oplock change 0x%x -> 0x%x\n",
- opinfo->level, rsp_oplevel);
+ if (opinfo->level == SMB2_OPLOCK_LEVEL_EXCLUSIVE &&
+ req_oplevel != SMB2_OPLOCK_LEVEL_II &&
+ req_oplevel != SMB2_OPLOCK_LEVEL_NONE) {
+ opinfo->level = SMB2_OPLOCK_LEVEL_NONE;
+ status = STATUS_INVALID_OPLOCK_PROTOCOL;
+ goto err_out;
}
- if (ret < 0) {
- rsp->hdr.Status = err;
+ if (opinfo->level == SMB2_OPLOCK_LEVEL_BATCH &&
+ req_oplevel != SMB2_OPLOCK_LEVEL_II &&
+ req_oplevel != SMB2_OPLOCK_LEVEL_NONE &&
+ req_oplevel != SMB2_OPLOCK_LEVEL_EXCLUSIVE) {
+ opinfo->level = SMB2_OPLOCK_LEVEL_NONE;
+ status = STATUS_INVALID_OPLOCK_PROTOCOL;
+ goto err_out;
+ }
+
+ if (opinfo->level == SMB2_OPLOCK_LEVEL_II &&
+ req_oplevel != SMB2_OPLOCK_LEVEL_NONE) {
+ opinfo->level = SMB2_OPLOCK_LEVEL_NONE;
+ status = STATUS_INVALID_OPLOCK_PROTOCOL;
goto err_out;
}
+ if (req_oplevel == SMB2_OPLOCK_LEVEL_EXCLUSIVE)
+ rsp_oplevel = SMB2_OPLOCK_LEVEL_NONE;
+ else
+ rsp_oplevel = req_oplevel;
+
+ opinfo->level = rsp_oplevel;
+
rsp->StructureSize = cpu_to_le16(24);
rsp->OplockLevel = rsp_oplevel;
rsp->Reserved = 0;
@@ -8279,11 +8262,16 @@ static void smb20_oplock_break_ack(struct ksmbd_work *work)
rsp->VolatileFid = volatile_id;
rsp->PersistentFid = persistent_id;
ret = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_oplock_break));
- if (ret) {
+ if (ret)
+ ksmbd_debug(SMB, "failed to pin oplock break response: %d\n",
+ ret);
+ goto out;
+
err_out:
- smb2_set_err_rsp(work);
- }
+ rsp->hdr.Status = status;
+ smb2_set_err_rsp(work);
+out:
opinfo->op_state = OPLOCK_STATE_NONE;
wake_up_interruptible_all(&opinfo->oplock_q);
opinfo_put(opinfo);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 218/982] ksmbd: use connection ClientGUID for lease lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (216 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 217/982] ksmbd: align SMB2 oplock break ack handling Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 219/982] ksmbd: treat unnamed DATA stream as base file Greg Kroah-Hartman
` (770 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit fa111daae1a02dbff5693dfc12f368bccd9eb5f4 ]
MS-SMB2 defines the lease table lookup key as Connection.ClientGuid.
Use the connection ClientGUID consistently when checking for same-client
leases and duplicate lease keys.
Also preserve directory and parent lease metadata when copying an existing
lease state to a new open.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/oplock.c | 16 +++++++++-------
fs/smb/server/oplock.h | 2 +-
fs/smb/server/smb2pdu.c | 2 +-
3 files changed, 11 insertions(+), 9 deletions(-)
diff --git a/fs/smb/server/oplock.c b/fs/smb/server/oplock.c
index 2414e103b79e3..0b71399af50cc 100644
--- a/fs/smb/server/oplock.c
+++ b/fs/smb/server/oplock.c
@@ -510,7 +510,7 @@ static inline int compare_guid_key(struct oplock_info *opinfo,
* Return: oplock(lease) object on success, otherwise NULL
*/
static struct oplock_info *same_client_has_lease(struct ksmbd_inode *ci,
- char *client_guid,
+ const char *client_guid,
struct lease_ctx_info *lctx)
{
int ret;
@@ -995,7 +995,7 @@ void destroy_lease_table(struct ksmbd_conn *conn)
write_unlock(&lease_list_lock);
}
-int find_same_lease_key(struct ksmbd_session *sess, struct ksmbd_inode *ci,
+int find_same_lease_key(struct ksmbd_conn *conn, struct ksmbd_inode *ci,
struct lease_ctx_info *lctx)
{
struct oplock_info *opinfo;
@@ -1012,7 +1012,7 @@ int find_same_lease_key(struct ksmbd_session *sess, struct ksmbd_inode *ci,
}
list_for_each_entry(lb, &lease_table_list, l_entry) {
- if (!memcmp(lb->client_guid, sess->ClientGUID,
+ if (!memcmp(lb->client_guid, conn->ClientGUID,
SMB2_CLIENT_GUID_SIZE))
goto found;
}
@@ -1028,7 +1028,7 @@ int find_same_lease_key(struct ksmbd_session *sess, struct ksmbd_inode *ci,
rcu_read_unlock();
if (opinfo->o_fp->f_ci == ci)
goto op_next;
- err = compare_guid_key(opinfo, sess->ClientGUID,
+ err = compare_guid_key(opinfo, conn->ClientGUID,
lctx->lease_key);
if (err) {
err = -EINVAL;
@@ -1061,6 +1061,9 @@ static void copy_lease(struct oplock_info *op1, struct oplock_info *op2)
lease2->flags = lease1->flags;
lease2->epoch = lease1->epoch;
lease2->version = lease1->version;
+ lease2->is_dir = lease1->is_dir;
+ memcpy(lease2->parent_lease_key, lease1->parent_lease_key,
+ SMB2_LEASE_KEY_SIZE);
}
static int add_lease_global_list(struct oplock_info *opinfo)
@@ -1209,7 +1212,6 @@ int smb_grant_oplock(struct ksmbd_work *work, int req_op_level, u64 pid,
struct ksmbd_file *fp, __u16 tid,
struct lease_ctx_info *lctx, int share_ret)
{
- struct ksmbd_session *sess = work->sess;
int err = 0;
struct oplock_info *opinfo = NULL, *prev_opinfo = NULL;
struct ksmbd_inode *ci = fp->f_ci;
@@ -1251,12 +1253,12 @@ int smb_grant_oplock(struct ksmbd_work *work, int req_op_level, u64 pid,
struct oplock_info *m_opinfo;
/* is lease already granted ? */
- m_opinfo = same_client_has_lease(ci, sess->ClientGUID,
+ m_opinfo = same_client_has_lease(ci, work->conn->ClientGUID,
lctx);
if (m_opinfo) {
copy_lease(m_opinfo, opinfo);
if (atomic_read(&m_opinfo->breaking_cnt))
- opinfo->o_lease->flags =
+ opinfo->o_lease->flags |=
SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE;
opinfo_put(m_opinfo);
goto out;
diff --git a/fs/smb/server/oplock.h b/fs/smb/server/oplock.h
index 5b93ea9196c01..0e2b1d63ca26b 100644
--- a/fs/smb/server/oplock.h
+++ b/fs/smb/server/oplock.h
@@ -124,7 +124,7 @@ void create_posix_rsp_buf(char *cc, struct ksmbd_file *fp);
struct create_context *smb2_find_context_vals(void *open_req, const char *tag, int tag_len);
struct oplock_info *lookup_lease_in_table(struct ksmbd_conn *conn,
char *lease_key);
-int find_same_lease_key(struct ksmbd_session *sess, struct ksmbd_inode *ci,
+int find_same_lease_key(struct ksmbd_conn *conn, struct ksmbd_inode *ci,
struct lease_ctx_info *lctx);
void destroy_lease_table(struct ksmbd_conn *conn);
void smb_send_parent_lease_break_noti(struct ksmbd_file *fp,
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 4765edcff9dbd..e7cbc8944ca80 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -3267,7 +3267,7 @@ int smb2_open(struct ksmbd_work *work)
ksmbd_debug(SMB,
"lease req for(%s) req oplock state 0x%x, lease state 0x%x\n",
name, req_op_level, lc->req_state);
- rc = find_same_lease_key(sess, fp->f_ci, lc);
+ rc = find_same_lease_key(conn, fp->f_ci, lc);
if (rc)
goto err_out1;
} else if (open_flags == O_RDONLY &&
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 219/982] ksmbd: treat unnamed DATA stream as base file
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (217 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 218/982] ksmbd: use connection ClientGUID for lease lookup Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 220/982] ksmbd: apply create security descriptor first Greg Kroah-Hartman
` (769 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 171b5d72dd80f99271c073c6e38d5263687c3b6d ]
The SMB path suffix :: names the unnamed data stream of the base
file, not an alternate data stream backed by a DosStream xattr.
Canonicalize an empty stream name with an explicit type to a NULL
stream name after parsing. This keeps the base filename produced by
strsep() and lets open continue through the normal base-file path instead
of looking for a non-existent empty stream xattr.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/misc.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/fs/smb/server/misc.c b/fs/smb/server/misc.c
index 9e8afaa686e3a..11314f7c622a6 100644
--- a/fs/smb/server/misc.c
+++ b/fs/smb/server/misc.c
@@ -121,7 +121,9 @@ int parse_stream_name(char *filename, char **stream_name, int *s_type)
char *stream_type;
char *s_name;
int rc = 0;
+ bool has_stream_type = false;
+ *stream_name = NULL;
s_name = filename;
filename = strsep(&s_name, ":");
ksmbd_debug(SMB, "filename : %s, streams : %s\n", filename, s_name);
@@ -137,14 +139,20 @@ int parse_stream_name(char *filename, char **stream_name, int *s_type)
ksmbd_debug(SMB, "stream name : %s, stream type : %s\n", s_name,
stream_type);
- if (!strncasecmp("$data", stream_type, 5))
+ if (!strncasecmp("$data", stream_type, 5)) {
*s_type = DATA_STREAM;
- else if (!strncasecmp("$index_allocation", stream_type, 17))
+ has_stream_type = true;
+ } else if (!strncasecmp("$index_allocation", stream_type, 17)) {
*s_type = DIR_STREAM;
- else
+ has_stream_type = true;
+ } else {
rc = -ENOENT;
+ }
}
+ if (has_stream_type && !s_name[0] && *s_type == DATA_STREAM)
+ goto out;
+
*stream_name = s_name;
out:
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 220/982] ksmbd: apply create security descriptor first
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (218 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 219/982] ksmbd: treat unnamed DATA stream as base file Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 221/982] ksmbd: start file id allocation at 1 Greg Kroah-Hartman
` (768 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit ba3cf6ee4f0eacc1f8c607b80188e3b32ef5e0e3 ]
smb2.create.aclfile creates files with an SMB2_CREATE_SD_BUFFER create
context and expects the resulting security descriptor to match
the descriptor supplied by the client.
ksmbd currently tries to inherit the parent DACL first and only parses
the SMB2_CREATE_SD_BUFFER context when DACL inheritance fails.
If inheritance succeeds, the explicit security descriptor supplied on
create is ignored. This breaks create requests that include owner/group
information in the security descriptor.
Apply the create security descriptor first when the context is present.
Fall back to the existing inherited/default ACL path only when no create
security descriptor was supplied.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index e7cbc8944ca80..5e20db1d0ddd6 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -3141,14 +3141,16 @@ int smb2_open(struct ksmbd_work *work)
if (posix_acl_rc)
ksmbd_debug(SMB, "inherit posix acl failed : %d\n", posix_acl_rc);
- if (test_share_config_flag(work->tcon->share_conf,
- KSMBD_SHARE_FLAG_ACL_XATTR)) {
- rc = smb_inherit_dacl(conn, &path, sess->user->uid,
- sess->user->gid);
- }
+ rc = smb2_create_sd_buffer(work, req, &path);
+ if (rc && rc != -ENOENT)
+ goto err_out;
- if (rc) {
- rc = smb2_create_sd_buffer(work, req, &path);
+ if (rc == -ENOENT) {
+ if (test_share_config_flag(work->tcon->share_conf,
+ KSMBD_SHARE_FLAG_ACL_XATTR)) {
+ rc = smb_inherit_dacl(conn, &path, sess->user->uid,
+ sess->user->gid);
+ }
if (rc) {
if (posix_acl_rc)
ksmbd_vfs_set_init_posix_acl(user_ns,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 221/982] ksmbd: start file id allocation at 1
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (219 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 220/982] ksmbd: apply create security descriptor first Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 222/982] ksmbd: break RH leases before delete-on-close Greg Kroah-Hartman
` (767 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 6b375be0b4e1be89e9a817880515311503a19114 ]
ksmbd allocates both the volatile id (per-session file table) and the
persistent id (global file table) with idr_alloc_cyclic() starting at 0.
The first open after the module loads therefore gets volatile id 0 and
persistent id 0, and ksmbd returns an SMB2 FileId of {0, 0} in the create
response.
Clients treat an all-zero FileId as a null handle. smbtorture's
smb2_util_handle_empty() considers {0, 0} empty, so tests that guard the
close with it (e.g. smb2.oplock.statopen1, smb2.lease.statopen*) never
close that first handle. The leaked open keeps the inode's oplock count
non-zero, so a later batch oplock request on the same file is downgraded
to level II and the test fails.
Start the id allocation at 1 (KSMBD_START_FID) so no handle is ever
assigned a {0, 0} FileId, matching the behaviour of other SMB servers.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/vfs_cache.c | 3 ++-
fs/smb/server/vfs_cache.h | 7 ++++++-
2 files changed, 8 insertions(+), 2 deletions(-)
diff --git a/fs/smb/server/vfs_cache.c b/fs/smb/server/vfs_cache.c
index 5b3a55bd700dc..9eb9f892ac2b5 100644
--- a/fs/smb/server/vfs_cache.c
+++ b/fs/smb/server/vfs_cache.c
@@ -556,7 +556,8 @@ static int __open_id(struct ksmbd_file_table *ft, struct ksmbd_file *fp,
idr_preload(GFP_KERNEL);
write_lock(&ft->lock);
- ret = idr_alloc_cyclic(ft->idr, fp, 0, INT_MAX - 1, GFP_NOWAIT);
+ ret = idr_alloc_cyclic(ft->idr, fp, KSMBD_START_FID, INT_MAX - 1,
+ GFP_NOWAIT);
if (ret >= 0) {
id = ret;
ret = 0;
diff --git a/fs/smb/server/vfs_cache.h b/fs/smb/server/vfs_cache.h
index 8d1bf34eb4a18..ffa2737e279af 100644
--- a/fs/smb/server/vfs_cache.h
+++ b/fs/smb/server/vfs_cache.h
@@ -22,7 +22,12 @@
#define FILE_GENERIC_WRITE 0x120116
#define FILE_GENERIC_EXECUTE 0X1200a0
-#define KSMBD_START_FID 0
+/*
+ * Start volatile/persistent file id allocation at 1. A file id of 0 yields an
+ * SMB2 FileId of {0, 0}, which clients (e.g. Windows, Samba) treat as a null
+ * handle and never close, leaking the open on the server.
+ */
+#define KSMBD_START_FID 1
#define KSMBD_NO_FID (INT_MAX)
#define SMB2_NO_FID (0xFFFFFFFFFFFFFFFFULL)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 222/982] ksmbd: break RH leases before delete-on-close
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (220 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 221/982] ksmbd: start file id allocation at 1 Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.1 223/982] PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device() Greg Kroah-Hartman
` (766 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 1f1083c36fa11c5d9011451c7b9ab380545c72ea ]
The delete paths only marked the opened file delete pending or
delete-on-close. When another client still held a read/handle lease, no
lease break was sent before the delete state changed.
smb2.lease.unlink uses a create request with FILE_DELETE_ON_CLOSE and
expects the second client's unlink to break the first client's RH lease to
R with ACK_REQUIRED set. SetInfo(FileDispositionInformation) has the same
lease-breaking requirement.
Break level-II/read-handle leases before setting delete pending or
delete-on-close so clients are notified before the file is removed.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 5e20db1d0ddd6..ebd13393f8d46 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -3285,8 +3285,10 @@ int smb2_open(struct ksmbd_work *work)
goto err_out1;
}
- if (req->CreateOptions & FILE_DELETE_ON_CLOSE_LE)
+ if (req->CreateOptions & FILE_DELETE_ON_CLOSE_LE) {
+ smb_break_all_levII_oplock(work, fp, 0);
ksmbd_fd_set_delete_on_close(fp, file_info);
+ }
if (need_truncate) {
rc = smb2_create_truncate(&fp->filp->f_path);
@@ -5952,7 +5954,8 @@ static int set_rename_info(struct ksmbd_work *work, struct ksmbd_file *fp,
return smb2_rename(work, fp, rename_info, work->conn->local_nls);
}
-static int set_file_disposition_info(struct ksmbd_file *fp,
+static int set_file_disposition_info(struct ksmbd_work *work,
+ struct ksmbd_file *fp,
struct smb2_file_disposition_info *file_info)
{
struct inode *inode;
@@ -5967,6 +5970,7 @@ static int set_file_disposition_info(struct ksmbd_file *fp,
if (S_ISDIR(inode->i_mode) &&
ksmbd_vfs_empty_dir(fp) == -ENOTEMPTY)
return -EBUSY;
+ smb_break_all_levII_oplock(work, fp, 0);
ksmbd_set_inode_pending_delete(fp);
} else {
ksmbd_clear_inode_pending_delete(fp);
@@ -6090,7 +6094,7 @@ static int smb2_set_info_file(struct ksmbd_work *work, struct ksmbd_file *fp,
if (buf_len < sizeof(struct smb2_file_disposition_info))
return -EINVAL;
- return set_file_disposition_info(fp,
+ return set_file_disposition_info(work, fp,
(struct smb2_file_disposition_info *)buffer);
}
case FILE_FULL_EA_INFORMATION:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 223/982] PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (221 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 222/982] ksmbd: break RH leases before delete-on-close Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 224/982] PCI/sysfs: Use kstrtobool() to parse the ROM attribute input Greg Kroah-Hartman
` (765 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuan He, Krzysztof Wilczyński,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krzysztof Wilczyński <kwilczynski@kernel.org>
[ Upstream commit 8857f6578b001bcf5f53c8c6a3936647f05291a8 ]
pci_proc_attach_device() creates procfs entries for PCI devices and is
called from pci_bus_add_device(). It lazily creates the per-bus procfs
directory (bus->procdir) via proc_mkdir() on first use, and returns early
if proc_initialized is not yet set.
On x86 with ACPI, PCI enumeration occurs at subsys_initcall, before
pci_proc_init() sets proc_initialized at device_initcall. The
for_each_pci_dev() loop in pci_proc_init() then creates procfs entries for
these already-enumerated devices, but runs without holding
pci_rescan_remove_lock.
On ARM64 with devicetree, PCI host bridges probe at device_initcall. With
async probing enabled, pci_bus_add_device() can run concurrently with
pci_proc_init(), and both may call pci_proc_attach_device() for the same
device or for different devices on the same bus. As pci_host_probe() holds
pci_rescan_remove_lock while pci_proc_init() does not, there is no
serialisation between the two paths.
When two threads concurrently call pci_proc_attach_device() for devices on
the same bus, both observe bus->procdir as NULL and both call proc_mkdir().
The proc filesystem serialises directory creation internally, so only one
caller succeeds. The other results in a warning like:
proc_dir_entry '000c:00/00.0' already registered
The caller receives NULL (duplicate entry) and unconditionally stores it to
bus->procdir, corrupting the valid pointer set by the first caller.
Serialise access to proc_initialized, proc_bus_pci_dir, bus->procdir and
dev->procent with a new mutex local to drivers/pci/proc.c, and store the
created entries to bus->procdir and dev->procent only on success, so a
failed creation can never overwrite a valid pointer.
Additionally, wrap the for_each_pci_dev() loop in pci_proc_init() with
pci_lock_rescan_remove() to serialise against concurrent PCI bus
operations, add an early return in pci_proc_attach_device() when
dev->procent is already set to make the function idempotent, and clear
bus->procdir in pci_proc_detach_bus() to prevent use of a dangling pointer
after proc_remove().
Reported-by: Shuan He <heshuan@bytedance.com>
Closes: https://lore.kernel.org/linux-pci/20250702155112.40124-2-heshuan@bytedance.com/
Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://lore.kernel.org/r/20260611150543.511422-1-kwilczynski@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/proc.c | 79 ++++++++++++++++++++++++++++++++--------------
1 file changed, 56 insertions(+), 23 deletions(-)
diff --git a/drivers/pci/proc.c b/drivers/pci/proc.c
index ac3c105fcf8fc..2967e4d2918dc 100644
--- a/drivers/pci/proc.c
+++ b/drivers/pci/proc.c
@@ -20,6 +20,7 @@
#include "pci.h"
static int proc_initialized; /* = 0 */
+static DEFINE_MUTEX(pci_proc_lock);
static loff_t proc_bus_pci_lseek(struct file *file, loff_t off, int whence)
{
@@ -426,40 +427,64 @@ static const struct seq_operations proc_bus_pci_devices_op = {
static struct proc_dir_entry *proc_bus_pci_dir;
-int pci_proc_attach_device(struct pci_dev *dev)
+static int __pci_proc_attach_bus(struct pci_bus *bus)
{
- struct pci_bus *bus = dev->bus;
- struct proc_dir_entry *e;
+ struct proc_dir_entry *dir;
char name[16];
+ lockdep_assert_held(&pci_proc_lock);
+
if (!proc_initialized)
return -EACCES;
- if (!bus->procdir) {
- if (pci_proc_domain(bus)) {
- sprintf(name, "%04x:%02x", pci_domain_nr(bus),
- bus->number);
- } else {
- sprintf(name, "%02x", bus->number);
- }
- bus->procdir = proc_mkdir(name, proc_bus_pci_dir);
- if (!bus->procdir)
- return -ENOMEM;
- }
+ if (bus->procdir)
+ return 0;
+
+ if (pci_proc_domain(bus))
+ sprintf(name, "%04x:%02x", pci_domain_nr(bus), bus->number);
+ else
+ sprintf(name, "%02x", bus->number);
+
+ dir = proc_mkdir(name, proc_bus_pci_dir);
+ if (!dir)
+ return -ENOMEM;
+
+ bus->procdir = dir;
+
+ return 0;
+}
+
+int pci_proc_attach_device(struct pci_dev *dev)
+{
+ struct pci_bus *bus = dev->bus;
+ struct proc_dir_entry *entry;
+ char name[16];
+ int ret;
+
+ guard(mutex)(&pci_proc_lock);
+
+ if (dev->procent)
+ return 0;
+
+ ret = __pci_proc_attach_bus(bus);
+ if (ret)
+ return ret;
sprintf(name, "%02x.%x", PCI_SLOT(dev->devfn), PCI_FUNC(dev->devfn));
- e = proc_create_data(name, S_IFREG | S_IRUGO | S_IWUSR, bus->procdir,
- &proc_bus_pci_ops, dev);
- if (!e)
+ entry = proc_create_data(name, S_IFREG | S_IRUGO | S_IWUSR,
+ bus->procdir, &proc_bus_pci_ops, dev);
+ if (!entry)
return -ENOMEM;
- proc_set_size(e, dev->cfg_size);
- dev->procent = e;
+
+ proc_set_size(entry, dev->cfg_size);
+ dev->procent = entry;
return 0;
}
int pci_proc_detach_device(struct pci_dev *dev)
{
+ guard(mutex)(&pci_proc_lock);
proc_remove(dev->procent);
dev->procent = NULL;
return 0;
@@ -467,19 +492,27 @@ int pci_proc_detach_device(struct pci_dev *dev)
int pci_proc_detach_bus(struct pci_bus *bus)
{
+ guard(mutex)(&pci_proc_lock);
proc_remove(bus->procdir);
+ bus->procdir = NULL;
return 0;
}
static int __init pci_proc_init(void)
{
struct pci_dev *dev = NULL;
- proc_bus_pci_dir = proc_mkdir("bus/pci", NULL);
- proc_create_seq("devices", 0, proc_bus_pci_dir,
- &proc_bus_pci_devices_op);
- proc_initialized = 1;
+
+ scoped_guard(mutex, &pci_proc_lock) {
+ proc_bus_pci_dir = proc_mkdir("bus/pci", NULL);
+ proc_create_seq("devices", 0, proc_bus_pci_dir,
+ &proc_bus_pci_devices_op);
+ proc_initialized = 1;
+ }
+
+ pci_lock_rescan_remove();
for_each_pci_dev(dev)
pci_proc_attach_device(dev);
+ pci_unlock_rescan_remove();
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 224/982] PCI/sysfs: Use kstrtobool() to parse the ROM attribute input
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (222 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.1 223/982] PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 225/982] regulator: da9121: Use subvariant ids in the I2C table Greg Kroah-Hartman
` (764 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Krzysztof Wilczyński,
Bjorn Helgaas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krzysztof Wilczyński <kwilczynski@kernel.org>
[ Upstream commit 92742802ecbf215a2b60dcfd326d2213595010f1 ]
pci_write_rom() controls access to the ROM content through the
corresponding sysfs attribute, and treats the input as a request to
disable only when it matches the string "0\n" exactly:
if ((off == 0) && (*buf == '0') && (count == 2))
The count == 2 condition encodes the trailing newline that echo(1) appends.
This was found when userspace wrote "0" without a trailing newline aiming
to disable access, which failed to match the condition above and enabled
access instead. For example:
$ echo 0 > rom # "0\n", count 2, access disabled
$ echo -n 0 > rom # "0", count 1, access enabled
$ echo > rom # "", count 1, access enabled (likely not desirable)
Parse the input with kstrtobool(), which handles common boolean inputs such
as "0", "1", "n", "y" or "off", "on", with or without a trailing newline,
so both of the above disable access, and update the now stale comment.
As a side effect, input that does not parse as a boolean is rejected with
-EINVAL rather than enabling access. The documented "0" and "1" continue
to work as before, and rejecting malformed input brings the attribute in
line with how sysfs attributes typically handle it.
Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260612182448.552406-1-kwilczynski@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/pci-sysfs.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/drivers/pci/pci-sysfs.c b/drivers/pci/pci-sysfs.c
index 2b7d20dcc37f7..d0ec908908303 100644
--- a/drivers/pci/pci-sysfs.c
+++ b/drivers/pci/pci-sysfs.c
@@ -1305,18 +1305,19 @@ void __weak pci_remove_resource_files(struct pci_dev *dev) { return; }
* @off: file offset
* @count: number of byte in input
*
- * writing anything except 0 enables it
+ * Writing a boolean value enables or disables the ROM display.
*/
static ssize_t pci_write_rom(struct file *filp, struct kobject *kobj,
struct bin_attribute *bin_attr, char *buf,
loff_t off, size_t count)
{
struct pci_dev *pdev = to_pci_dev(kobj_to_dev(kobj));
+ bool enable;
- if ((off == 0) && (*buf == '0') && (count == 2))
- pdev->rom_attr_enabled = 0;
- else
- pdev->rom_attr_enabled = 1;
+ if (kstrtobool(buf, &enable))
+ return -EINVAL;
+
+ pdev->rom_attr_enabled = enable;
return count;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 225/982] regulator: da9121: Use subvariant ids in the I2C table
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (223 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 224/982] PCI/sysfs: Use kstrtobool() to parse the ROM attribute input Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 226/982] net: au1000: move free_irq out of the close-time spinlocked section Greg Kroah-Hartman
` (763 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 7ddbf1cde4a03e36e17d06fbc711870eb0b256d7 ]
da9121_i2c_probe() stores i2c_get_match_data() in chip->subvariant_id
and da9121_assign_chip_model() switches on DA9121_SUBTYPE_* values. The
OF table provides those subvariant values, but the I2C id table
currently provides DA9121_TYPE_* values.
Make the I2C id table use the same subvariant namespace as the OF table
so non-DT I2C matches feed the expected data type into the model
assignment code.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260624060024.61300-1-pengpeng@iscas.ac.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/regulator/da9121-regulator.c | 18 +++++++++---------
1 file changed, 9 insertions(+), 9 deletions(-)
diff --git a/drivers/regulator/da9121-regulator.c b/drivers/regulator/da9121-regulator.c
index e4c753b830888..3b34e1e027ef0 100644
--- a/drivers/regulator/da9121-regulator.c
+++ b/drivers/regulator/da9121-regulator.c
@@ -1179,15 +1179,15 @@ static void da9121_i2c_remove(struct i2c_client *i2c)
}
static const struct i2c_device_id da9121_i2c_id[] = {
- {"da9121", DA9121_TYPE_DA9121_DA9130},
- {"da9130", DA9121_TYPE_DA9121_DA9130},
- {"da9217", DA9121_TYPE_DA9217},
- {"da9122", DA9121_TYPE_DA9122_DA9131},
- {"da9131", DA9121_TYPE_DA9122_DA9131},
- {"da9220", DA9121_TYPE_DA9220_DA9132},
- {"da9132", DA9121_TYPE_DA9220_DA9132},
- {"da9141", DA9121_TYPE_DA9141},
- {"da9142", DA9121_TYPE_DA9142},
+ {"da9121", DA9121_SUBTYPE_DA9121},
+ {"da9130", DA9121_SUBTYPE_DA9130},
+ {"da9217", DA9121_SUBTYPE_DA9217},
+ {"da9122", DA9121_SUBTYPE_DA9122},
+ {"da9131", DA9121_SUBTYPE_DA9131},
+ {"da9220", DA9121_SUBTYPE_DA9220},
+ {"da9132", DA9121_SUBTYPE_DA9132},
+ {"da9141", DA9121_SUBTYPE_DA9141},
+ {"da9142", DA9121_SUBTYPE_DA9142},
{},
};
MODULE_DEVICE_TABLE(i2c, da9121_i2c_id);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 226/982] net: au1000: move free_irq out of the close-time spinlocked section
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (224 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 225/982] regulator: da9121: Use subvariant ids in the I2C table Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 227/982] blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat() Greg Kroah-Hartman
` (762 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Simon Horman,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
[ Upstream commit f48763beab4eea41fc480c9702ec6eebe8d75e4f ]
au1000_close() calls free_irq() while aup->lock is still held with
spin_lock_irqsave(). free_irq() can sleep because it takes the IRQ
descriptor request mutex, so it does not belong inside the close-time
spinlocked section.
This was found by our static analysis tool and then confirmed by manual
review of the in-tree au1000_close() .ndo_stop path. The reviewed path
keeps aup->lock held across the MAC reset, queue stop and
free_irq(dev->irq, dev).
A directed runtime validation kept that ndo_stop carrier and the same
free_irq(dev->irq, dev) operation under the driver lock. Lockdep reported
"BUG: sleeping function called from invalid context" and "Invalid wait
context" while free_irq() was taking desc->request_mutex, with
au1000_close() and free_irq() on the stack.
Drop aup->lock before freeing the IRQ. The protected close-time work still
stops the device and queue before IRQ teardown, but the sleepable IRQ core
path now runs outside the spinlocked section.
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260619151816.1144289-1-runyu.xiao@seu.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/amd/au1000_eth.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/amd/au1000_eth.c b/drivers/net/ethernet/amd/au1000_eth.c
index c5cec4e794895..7f084583af2ed 100644
--- a/drivers/net/ethernet/amd/au1000_eth.c
+++ b/drivers/net/ethernet/amd/au1000_eth.c
@@ -943,9 +943,10 @@ static int au1000_close(struct net_device *dev)
/* stop the device */
netif_stop_queue(dev);
+ spin_unlock_irqrestore(&aup->lock, flags);
+
/* disable the interrupt */
free_irq(dev->irq, dev);
- spin_unlock_irqrestore(&aup->lock, flags);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 227/982] blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (225 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 226/982] net: au1000: move free_irq out of the close-time spinlocked section Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 228/982] rtc: bq32000: add delay between RTC reads Greg Kroah-Hartman
` (761 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yu Kuai, Jens Axboe, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 25656304dabd26198ec69460c594a19d086ef099 ]
blkcg_print_one_stat() will be called for each blkg:
- access blkg->iostat, which is freed from rcu callback
blkg_free_workfn();
- access policy data from pd_stat_fn(), which is freed from
pd_free_fn(), while pd_free_fn() can be called by removing blkcg or
deactivating policy;
Take blkcg->lock while iterating so the blkgs stay online and both
blkg->iostat and policy data for activated policies stay valid. Use
irq-safe locking because blkcg->lock can be nested under q->queue_lock,
which is used from IRQ completion paths.
Prepare to convert protecting blkgs from request_queue with mutex.
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/05799877e720dcd300e2ddd4625e8e162959d7cc.1780621988.git.yukuai@fygo.io
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-cgroup.c | 9 +++------
1 file changed, 3 insertions(+), 6 deletions(-)
diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
index e88e493457519..c02292b0bd694 100644
--- a/block/blk-cgroup.c
+++ b/block/blk-cgroup.c
@@ -1003,13 +1003,10 @@ static int blkcg_print_stat(struct seq_file *sf, void *v)
else
cgroup_rstat_flush(blkcg->css.cgroup);
- rcu_read_lock();
- hlist_for_each_entry_rcu(blkg, &blkcg->blkg_list, blkcg_node) {
- spin_lock_irq(&blkg->q->queue_lock);
+ guard(spinlock_irq)(&blkcg->lock);
+ hlist_for_each_entry(blkg, &blkcg->blkg_list, blkcg_node)
blkcg_print_one_stat(blkg, sf);
- spin_unlock_irq(&blkg->q->queue_lock);
- }
- rcu_read_unlock();
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 228/982] rtc: bq32000: add delay between RTC reads
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (226 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 227/982] blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 229/982] eth: mlx5: fix macsec dependency Greg Kroah-Hartman
` (760 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adriana Stancu, Alexandre Belloni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adriana Stancu <adriana@arista.com>
[ Upstream commit d4992b7050a10079bc760bdc5b8688e05a09dfc2 ]
When the RTC is used on systems without a interrupt line, userspace
tools like `hwclock` fall back to a frequent polling loop to synchronize
with the edge of the next second.
On the BQ32000, this aggressive polling can temporarly lock the register
refresh cycle, because the continuous transfers prevent the hardware from
updating the buffer. This results in stale data reads or select() timeouts
in userspace.
This patch introduces a delay before reading the RTC registers in order to
provide a sufficient idle time for the hardware to sync with the register
buffer.
Signed-off-by: Adriana Stancu <adriana@arista.com>
Link: https://patch.msgid.link/20260416142151.3385827-1-adriana@arista.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/rtc/rtc-bq32k.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/rtc/rtc-bq32k.c b/drivers/rtc/rtc-bq32k.c
index 6d6a55efb9cc7..4522bec54d3ff 100644
--- a/drivers/rtc/rtc-bq32k.c
+++ b/drivers/rtc/rtc-bq32k.c
@@ -15,6 +15,7 @@
#include <linux/init.h>
#include <linux/errno.h>
#include <linux/bcd.h>
+#include <linux/delay.h>
#define BQ32K_SECONDS 0x00 /* Seconds register address */
#define BQ32K_SECONDS_MASK 0x7F /* Mask over seconds value */
@@ -88,9 +89,17 @@ static int bq32k_write(struct device *dev, void *data, uint8_t off, uint8_t len)
static int bq32k_rtc_read_time(struct device *dev, struct rtc_time *tm)
{
+ struct i2c_client *client = to_i2c_client(dev);
struct bq32k_regs regs;
int error;
+ /*
+ * When the device doesn't have the interrupt connected, prevent
+ * userpace from polling the RTC registers too frequently.
+ */
+ if (client->irq <= 0)
+ usleep_range(2000, 2500);
+
error = bq32k_read(dev, ®s, 0, sizeof(regs));
if (error)
return error;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 229/982] eth: mlx5: fix macsec dependency
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (227 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 228/982] rtc: bq32000: add delay between RTC reads Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 230/982] fbdev: pm2fb: unwind WC setup on probe failure Greg Kroah-Hartman
` (759 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Sabrina Dubroca,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
[ Upstream commit 87ab8276ed24d688febfef4d0c1794896e778192 ]
Configurations with mlx5 built-in but macsec=m fail to link:
x86_64-linux-ld: drivers/infiniband/hw/mlx5/macsec.o: in function `mlx5r_add_gid_macsec_operations':
macsec.c:(.text+0x77d): undefined reference to `macsec_netdev_is_offloaded'
x86_64-linux-ld: drivers/infiniband/hw/mlx5/macsec.o: in function `mlx5r_del_gid_macsec_operations':
macsec.c:(.text+0xe81): undefined reference to `macsec_netdev_is_offloaded'
Fix the dependency so this configuration cannot happen.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/20260622124229.2444502-1-arnd@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/Kconfig b/drivers/net/ethernet/mellanox/mlx5/core/Kconfig
index 26685fd0fdaa4..0cfe56b90556a 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/Kconfig
+++ b/drivers/net/ethernet/mellanox/mlx5/core/Kconfig
@@ -142,7 +142,7 @@ config MLX5_CORE_IPOIB
config MLX5_EN_MACSEC
bool "Connect-X support for MACSec offload"
depends on MLX5_CORE_EN
- depends on MACSEC
+ depends on MACSEC=y || MACSEC=MLX5_CORE
default n
help
Build support for MACsec cryptography-offload acceleration in the NIC.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 230/982] fbdev: pm2fb: unwind WC setup on probe failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (228 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 229/982] eth: mlx5: fix macsec dependency Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 231/982] spi: core: Abort active target transfer on controller suspend Greg Kroah-Hartman
` (758 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Helge Deller,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haoxiang Li <haoxiang_li2024@163.com>
[ Upstream commit 16eb19f0c90af03bda6ba66586d7bb0e9cf85b43 ]
Add arch_phys_wc_del() on error path to keep the
write-combining setup balanced when later probe
steps fail.
Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/video/fbdev/pm2fb.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/video/fbdev/pm2fb.c b/drivers/video/fbdev/pm2fb.c
index 7a8609c40ae93..cd628e057f5bd 100644
--- a/drivers/video/fbdev/pm2fb.c
+++ b/drivers/video/fbdev/pm2fb.c
@@ -1710,6 +1710,7 @@ static int pm2fb_probe(struct pci_dev *pdev, const struct pci_device_id *id)
err_exit_both:
kfree(info->pixmap.addr);
err_exit_pixmap:
+ arch_phys_wc_del(default_par->wc_cookie);
iounmap(info->screen_base);
release_mem_region(pm2fb_fix.smem_start, pm2fb_fix.smem_len);
err_exit_mmio:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 231/982] spi: core: Abort active target transfer on controller suspend
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (229 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 230/982] fbdev: pm2fb: unwind WC setup on probe failure Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 232/982] btrfs: tree-checker: validate INODE_REFs namelen Greg Kroah-Hartman
` (757 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Praveen Talari, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Praveen Talari <praveen.talari@oss.qualcomm.com>
[ Upstream commit c1bab046d4786c5b17aab7c5225bf0d4a2a2d19b ]
When an SPI controller operating in target mode has a transfer in
progress at the time of system suspend, the suspend path proceeds
without aborting the ongoing transfer. This can leave the hardware in
an inconsistent state, potentially causing the system to hang or fail
to resume cleanly.
Fix this by invoking the controller's target_abort callback from
spi_controller_suspend() when the controller is in target mode and the
callback is registered. This ensures any active target transfer is
cleanly terminated before the controller is suspended.
Signed-off-by: Praveen Talari <praveen.talari@oss.qualcomm.com>
Link: https://patch.msgid.link/20260625-abort_active_transfer_duirng_s2r-v2-1-1d6f724406b6@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c
index e1eabb959c515..2dbdf10e9803a 100644
--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -3374,6 +3374,9 @@ int spi_controller_suspend(struct spi_controller *ctlr)
{
int ret = 0;
+ if (ctlr->cur_msg && spi_controller_is_target(ctlr) && ctlr->target_abort)
+ ctlr->target_abort(ctlr);
+
/* Basically no-ops for non-queued controllers */
if (ctlr->queued) {
ret = spi_stop_queue(ctlr);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 232/982] btrfs: tree-checker: validate INODE_REFs namelen
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (230 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 231/982] spi: core: Abort active target transfer on controller suspend Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 233/982] drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend Greg Kroah-Hartman
` (756 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi, Qu Wenruo,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 3dc22abc21f5892406c09202fa2627196cc96967 ]
[BUG]
A crafted btrfs image can trigger the following crash:
BUG: unable to handle page fault for address: ffffd1dc42884000
#PF: supervisor write access in kernel mode
#PF: error_code(0x0002) - not-present page
CPU: 9 UID: 0 PID: 1034 Comm: poc Not tainted 7.1.0-rc4-custom+ #383 PREEMPT(full) 46af0a92938a63be7132e0dfd71e62327c51d5c2
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022
RIP: 0010:memcpy+0xc/0x10
Call Trace:
<TASK>
read_extent_buffer+0xe4/0x100 [btrfs 3cf0785dd58fec8c5ff84633b772f17ce1f92a8f]
btrfs_get_name+0x15e/0x1e0 [btrfs 3cf0785dd58fec8c5ff84633b772f17ce1f92a8f]
reconnect_path+0x165/0x390
exportfs_decode_fh_raw+0x337/0x400
? drop_caches_sysctl_handler+0xb0/0xb0
</TASK>
---[ end trace 0000000000000000 ]---
RIP: 0010:memcpy+0xc/0x10
Kernel panic - not syncing: Fatal exception
[CAUSE]
TThe crafted image has the following corrupted INODE_REF item:
item 9 key (258 INODE_REF 257) itemoff 11544 itemsize 4106
index 2 namelen 4096 name: d\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000
The itemsize matches the namelen, but the namelen is 4096, way larger
than normal name length limit (BTRFS_NAME_LEN, 255).
Meanwhile the memory of the @name is only 255 byte sized, this will cause
out-of-boundary access, and cause the above crash.
[FIX]
Add extra namelen verification for INODE_REF, just like what we have
done in ROOT_REF checks.
Now the crafted image can be rejected gracefully:
BTRFS critical (device dm-2): corrupt leaf: root=5 block=30572544 slot=14 ino=259, invalid inode ref name length, has 4096 expect [1, 255]
BTRFS error (device dm-2): read time tree block corruption detected on logical 30572544 mirror 2
Reported-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/linux-btrfs/aik0hEV6ehKx6Ldv@Air.local/
Acked-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
[ Rebase, add a Link: tag, add an simple cause analyze ]
Signed-off-by: Qu Wenruo <wqu@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/tree-checker.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/btrfs/tree-checker.c b/fs/btrfs/tree-checker.c
index 3e3ffa23cea65..8e9139dc4bbe2 100644
--- a/fs/btrfs/tree-checker.c
+++ b/fs/btrfs/tree-checker.c
@@ -1669,6 +1669,12 @@ static int check_inode_ref(struct extent_buffer *leaf,
iref = (struct btrfs_inode_ref *)ptr;
namelen = btrfs_inode_ref_name_len(leaf, iref);
+ if (unlikely(namelen == 0 || namelen > BTRFS_NAME_LEN)) {
+ inode_ref_err(leaf, slot,
+ "invalid inode ref name length, has %u expect [1, %u]",
+ namelen, BTRFS_NAME_LEN);
+ return -EUCLEAN;
+ }
if (unlikely(ptr + sizeof(*iref) + namelen > end)) {
inode_ref_err(leaf, slot,
"inode ref overflow, ptr %lu end %lu namelen %u",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 233/982] drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (231 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 232/982] btrfs: tree-checker: validate INODE_REFs namelen Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 234/982] netfilter: nf_conntrack_expect: zero at allocation time Greg Kroah-Hartman
` (755 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gustavo Kenji Mendonça Kaneko,
Liviu Dudau, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gustavo Kenji Mendonça Kaneko <kaneko.dev@pm.me>
[ Upstream commit 46f715a16989f4e7bbbc2eb41447051874b027f3 ]
malidp_runtime_pm_resume() calls clk_prepare_enable() three times
without checking the return value. If any clock fails to enable, the
driver silently proceeds with unclocked hardware, leading to undefined
behavior.
Convert both the resume and suspend paths to use the clk_bulk API:
clk_bulk_prepare_enable() in resume checks the return value and rolls
back any successfully enabled clocks on failure;
clk_bulk_disable_unprepare() in suspend keeps the two paths symmetric.
This issue was found by code review without access to Mali DP hardware.
Signed-off-by: Gustavo Kenji Mendonça Kaneko <kaneko.dev@pm.me>
Reviewed-by: Liviu Dudau <liviu.dudau@arm.com>
Link: https://patch.msgid.link/20260609130812.1065699-1-kaneko.dev@pm.me
Signed-off-by: Liviu Dudau <liviu.dudau@arm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/arm/malidp_drv.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/arm/malidp_drv.c b/drivers/gpu/drm/arm/malidp_drv.c
index 1d0b0c54ccc74..7c82a228b6e40 100644
--- a/drivers/gpu/drm/arm/malidp_drv.c
+++ b/drivers/gpu/drm/arm/malidp_drv.c
@@ -672,6 +672,11 @@ static int malidp_runtime_pm_suspend(struct device *dev)
struct drm_device *drm = dev_get_drvdata(dev);
struct malidp_drm *malidp = drm->dev_private;
struct malidp_hw_device *hwdev = malidp->dev;
+ struct clk_bulk_data clks[] = {
+ { .clk = hwdev->pclk },
+ { .clk = hwdev->aclk },
+ { .clk = hwdev->mclk },
+ };
/* we can only suspend if the hardware is in config mode */
WARN_ON(!hwdev->hw->in_config_mode(hwdev));
@@ -679,9 +684,7 @@ static int malidp_runtime_pm_suspend(struct device *dev)
malidp_se_irq_fini(hwdev);
malidp_de_irq_fini(hwdev);
hwdev->pm_suspended = true;
- clk_disable_unprepare(hwdev->mclk);
- clk_disable_unprepare(hwdev->aclk);
- clk_disable_unprepare(hwdev->pclk);
+ clk_bulk_disable_unprepare(ARRAY_SIZE(clks), clks);
return 0;
}
@@ -691,10 +694,17 @@ static int malidp_runtime_pm_resume(struct device *dev)
struct drm_device *drm = dev_get_drvdata(dev);
struct malidp_drm *malidp = drm->dev_private;
struct malidp_hw_device *hwdev = malidp->dev;
+ struct clk_bulk_data clks[] = {
+ { .clk = hwdev->pclk },
+ { .clk = hwdev->aclk },
+ { .clk = hwdev->mclk },
+ };
+ int err;
+
+ err = clk_bulk_prepare_enable(ARRAY_SIZE(clks), clks);
+ if (err)
+ return err;
- clk_prepare_enable(hwdev->pclk);
- clk_prepare_enable(hwdev->aclk);
- clk_prepare_enable(hwdev->mclk);
hwdev->pm_suspended = false;
malidp_de_irq_hw_init(hwdev);
malidp_se_irq_hw_init(hwdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 234/982] netfilter: nf_conntrack_expect: zero at allocation time
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (232 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 233/982] drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 235/982] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr Greg Kroah-Hartman
` (754 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Florian Westphal, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 241ccd2fed9051db443aadce248fc0ab30f55e97 ]
There are occasional LLM hints wrt. leaking uninitialized data to
userspace via ctnetlink. Just zero at allocation time,
expectations are not frequently used these days.
Intentionally keeps _init as-is because we could theoretically
support re-init, so add the missing exp->dir there.
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_conntrack_expect.c | 3 ++-
net/netfilter/nf_conntrack_netlink.c | 11 +----------
2 files changed, 3 insertions(+), 11 deletions(-)
diff --git a/net/netfilter/nf_conntrack_expect.c b/net/netfilter/nf_conntrack_expect.c
index 34324dece89df..70d06ae0a3795 100644
--- a/net/netfilter/nf_conntrack_expect.c
+++ b/net/netfilter/nf_conntrack_expect.c
@@ -304,7 +304,7 @@ struct nf_conntrack_expect *nf_ct_expect_alloc(struct nf_conn *me)
{
struct nf_conntrack_expect *new;
- new = kmem_cache_alloc(nf_ct_expect_cachep, GFP_ATOMIC);
+ new = kmem_cache_zalloc(nf_ct_expect_cachep, GFP_ATOMIC);
if (!new)
return NULL;
@@ -386,6 +386,7 @@ void nf_ct_expect_init(struct nf_conntrack_expect *exp, unsigned int class,
#if IS_ENABLED(CONFIG_NF_NAT)
memset(&exp->saved_addr, 0, sizeof(exp->saved_addr));
memset(&exp->saved_proto, 0, sizeof(exp->saved_proto));
+ exp->dir = 0;
#endif
}
EXPORT_SYMBOL_GPL(nf_ct_expect_init);
diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
index 55bc5626b9679..bdeeff71b4c0b 100644
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -3552,8 +3552,6 @@ ctnetlink_alloc_expect(const struct nlattr * const cda[], struct nf_conn *ct,
if (cda[CTA_EXPECT_FLAGS]) {
exp->flags = ntohl(nla_get_be32(cda[CTA_EXPECT_FLAGS]));
exp->flags &= ~NF_CT_EXPECT_USERSPACE;
- } else {
- exp->flags = 0;
}
if (cda[CTA_EXPECT_FN]) {
const char *name = nla_data(cda[CTA_EXPECT_FN]);
@@ -3565,8 +3563,7 @@ ctnetlink_alloc_expect(const struct nlattr * const cda[], struct nf_conn *ct,
goto err_out;
}
exp->expectfn = expfn->expectfn;
- } else
- exp->expectfn = NULL;
+ }
exp->class = class;
exp->master = ct;
@@ -3585,12 +3582,6 @@ ctnetlink_alloc_expect(const struct nlattr * const cda[], struct nf_conn *ct,
exp, nf_ct_l3num(ct));
if (err < 0)
goto err_out;
-#if IS_ENABLED(CONFIG_NF_NAT)
- } else {
- memset(&exp->saved_addr, 0, sizeof(exp->saved_addr));
- memset(&exp->saved_proto, 0, sizeof(exp->saved_proto));
- exp->dir = 0;
-#endif
}
return exp;
err_out:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 235/982] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (233 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 234/982] netfilter: nf_conntrack_expect: zero at allocation time Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 236/982] drm/arm/komeda: fix error handling for clk_prepare_enable() and callers Greg Kroah-Hartman
` (753 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qiang Liu, ChenXiaoSong, Namjae Jeon,
Steve French, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qiang Liu <liuqiang@kylinos.cn>
[ Upstream commit d4d56b00c7df88cd5751e7415bdfabc9fdbc82a7 ]
ndr_encode_v4_ntacl() allocates sd_ndr.data via kzalloc() at entry.
If any subsequent ndr_write_*() call returns error during encoding,
the allocated sd_ndr.data won't be freed and causes memory leak.
Move kfree(sd_ndr.data) into out label to ensure the buffer gets
released on all success and error return paths.
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/vfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 2915f7e98fe93..413071ce9633f 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1520,8 +1520,8 @@ int ksmbd_vfs_set_sd_xattr(struct ksmbd_conn *conn,
if (rc < 0)
pr_err("Failed to store XATTR ntacl :%d\n", rc);
- kfree(sd_ndr.data);
out:
+ kfree(sd_ndr.data);
kfree(acl_ndr.data);
kfree(smb_acl);
kfree(def_smb_acl);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 236/982] drm/arm/komeda: fix error handling for clk_prepare_enable() and callers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (234 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 235/982] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 237/982] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr Greg Kroah-Hartman
` (752 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gustavo Kenji Mendonça Kaneko,
Liviu Dudau, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gustavo Kenji Mendonça Kaneko <kaneko.dev@pm.me>
[ Upstream commit 6502eb8cfcd6f7bc5f1f8b73ee524112bd93319d ]
komeda_dev_resume() calls clk_prepare_enable() without checking the
return value. If the clock fails to enable, the function returns 0
(success) while IRQs are enabled and IOMMU is connected on potentially
unclocked hardware, causing undefined behavior on resume.
Propagate the error from clk_prepare_enable() and fix all call sites
in komeda_drv.c that previously ignored the return value of
komeda_dev_resume():
- komeda_platform_probe(): if resume fails, jump to err_destroy_mdev
(skipping the suspend call, since the clock was never enabled)
- komeda_pm_resume(): propagate the error and skip
drm_mode_config_helper_resume() on failure
This issue was found by code review without access to Komeda hardware.
Signed-off-by: Gustavo Kenji Mendonça Kaneko <kaneko.dev@pm.me>
Reviewed-by: Liviu Dudau <liviu.dudau@arm.com>
Link: https://patch.msgid.link/20260609130828.1066038-1-kaneko.dev@pm.me
Signed-off-by: Liviu Dudau <liviu.dudau@arm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/arm/display/komeda/komeda_dev.c | 6 +++++-
drivers/gpu/drm/arm/display/komeda/komeda_drv.c | 14 +++++++++-----
2 files changed, 14 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/arm/display/komeda/komeda_dev.c b/drivers/gpu/drm/arm/display/komeda/komeda_dev.c
index cc7664c95a547..5df7756efd525 100644
--- a/drivers/gpu/drm/arm/display/komeda/komeda_dev.c
+++ b/drivers/gpu/drm/arm/display/komeda/komeda_dev.c
@@ -321,7 +321,11 @@ void komeda_dev_destroy(struct komeda_dev *mdev)
int komeda_dev_resume(struct komeda_dev *mdev)
{
- clk_prepare_enable(mdev->aclk);
+ int err;
+
+ err = clk_prepare_enable(mdev->aclk);
+ if (err)
+ return err;
mdev->funcs->enable_irq(mdev);
diff --git a/drivers/gpu/drm/arm/display/komeda/komeda_drv.c b/drivers/gpu/drm/arm/display/komeda/komeda_drv.c
index 9fce4239d4ad4..4762fdb9c19e9 100644
--- a/drivers/gpu/drm/arm/display/komeda/komeda_drv.c
+++ b/drivers/gpu/drm/arm/display/komeda/komeda_drv.c
@@ -63,8 +63,11 @@ static int komeda_bind(struct device *dev)
}
pm_runtime_enable(dev);
- if (!pm_runtime_enabled(dev))
- komeda_dev_resume(mdrv->mdev);
+ if (!pm_runtime_enabled(dev)) {
+ err = komeda_dev_resume(mdrv->mdev);
+ if (err)
+ goto err_destroy_mdev;
+ }
mdrv->kms = komeda_kms_attach(mdrv->mdev);
if (IS_ERR(mdrv->kms)) {
@@ -82,7 +85,7 @@ static int komeda_bind(struct device *dev)
pm_runtime_disable(dev);
else
komeda_dev_suspend(mdrv->mdev);
-
+err_destroy_mdev:
komeda_dev_destroy(mdrv->mdev);
free_mdrv:
@@ -174,11 +177,12 @@ static int __maybe_unused komeda_pm_suspend(struct device *dev)
static int __maybe_unused komeda_pm_resume(struct device *dev)
{
struct komeda_drv *mdrv = dev_get_drvdata(dev);
+ int err = 0;
if (!pm_runtime_status_suspended(dev))
- komeda_dev_resume(mdrv->mdev);
+ err = komeda_dev_resume(mdrv->mdev);
- return drm_mode_config_helper_resume(&mdrv->kms->base);
+ return err ? err : drm_mode_config_helper_resume(&mdrv->kms->base);
}
static const struct dev_pm_ops komeda_pm_ops = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 237/982] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (235 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 236/982] drm/arm/komeda: fix error handling for clk_prepare_enable() and callers Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 238/982] ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling Greg Kroah-Hartman
` (751 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qiang Liu, ChenXiaoSong, Namjae Jeon,
Steve French, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qiang Liu <liuqiang@kylinos.cn>
[ Upstream commit 7ac657bb9c5c1b0f7bdf1fa6d3ad532f969be5cf ]
Free ndr buffer data when ndr_encode_dos_attr() returns error
to avoid memory leak.
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/vfs.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 413071ce9633f..27a15c9d3cc22 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1613,14 +1613,15 @@ int ksmbd_vfs_set_dos_attrib_xattr(struct user_namespace *user_ns,
err = ndr_encode_dos_attr(&n, da);
if (err)
- return err;
+ goto out;
err = ksmbd_vfs_setxattr(user_ns, path, XATTR_NAME_DOS_ATTRIBUTE,
(void *)n.data, n.offset, 0, get_write);
if (err)
ksmbd_debug(SMB, "failed to store dos attribute in xattr\n");
- kfree(n.data);
+out:
+ kfree(n.data);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 238/982] ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (236 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 237/982] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 239/982] xen/front-pgdir-shbuf: free grant reference head on errors Greg Kroah-Hartman
` (750 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qiang Liu, ChenXiaoSong, Namjae Jeon,
Steve French, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qiang Liu <liuqiang@kylinos.cn>
[ Upstream commit d708a36634bb7b6f94d0e76d587d2ec50b2b93b5 ]
1. When ndr_decode_v4_ntacl() fails, the code jumped to free_n_data
which only freed n.data, skipping kfree(acl.sd_buf) and leaking
the buffer. Zero-initialize struct xattr_ntacl acl, reorder error
labels to out_free to release acl.sd_buf on all error paths.
2. if (acl.sd_size < sizeof(struct smb_ntsd)) is true, original code
returned success without freeing sd_buf and left stale *pntsd.
Set rc = -EINVAL before jumping to out_free to return error code and
free buffer.
Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/vfs.c | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 27a15c9d3cc22..1da397999941a 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1537,7 +1537,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
struct ndr n;
struct inode *inode = d_inode(dentry);
struct ndr acl_ndr = {0};
- struct xattr_ntacl acl;
+ struct xattr_ntacl acl = {0};
struct xattr_smb_acl *smb_acl = NULL, *def_smb_acl = NULL;
__u8 cmp_hash[XATTR_SD_HASH_SIZE] = {0};
@@ -1548,7 +1548,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
n.length = rc;
rc = ndr_decode_v4_ntacl(&n, &acl);
if (rc)
- goto free_n_data;
+ goto out_free;
smb_acl = ksmbd_vfs_make_xattr_posix_acl(user_ns, inode,
ACL_TYPE_ACCESS);
@@ -1578,6 +1578,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
*pntsd = acl.sd_buf;
if (acl.sd_size < sizeof(struct smb_ntsd)) {
pr_err("sd size is invalid\n");
+ rc = -EINVAL;
goto out_free;
}
@@ -1597,8 +1598,6 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
kfree(acl.sd_buf);
*pntsd = NULL;
}
-
-free_n_data:
kfree(n.data);
return rc;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 239/982] xen/front-pgdir-shbuf: free grant reference head on errors
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (237 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 238/982] ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 240/982] freevxfs: dont BUG() on unknown typed-extent type Greg Kroah-Hartman
` (749 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yousef Alhouseen, Stefano Stabellini,
Juergen Gross, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yousef Alhouseen <alhouseenyousef@gmail.com>
[ Upstream commit 678d59219ce0ae883f04c96936222c6168ef1164 ]
grant_references() allocates a private grant-reference head before
claiming references for the page directory and, for guest-owned buffers,
the data pages. The success path frees the remaining head, but claim
failures and grant_refs_for_buffer() errors return immediately.
Unwind through a common exit path so the private grant-reference head is
released even when granting fails part-way through setup. The caller
still tears down any references already stored in buf->grefs.
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Reviewed-by: Stefano Stabellini <sstabellini@kernel.org>
Signed-off-by: Juergen Gross <jgross@suse.com>
Message-ID: <20260629160517.29340-1-alhouseenyousef@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/xen/xen-front-pgdir-shbuf.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/xen/xen-front-pgdir-shbuf.c b/drivers/xen/xen-front-pgdir-shbuf.c
index 5c0b5cb5b4195..e21c1e00f94f8 100644
--- a/drivers/xen/xen-front-pgdir-shbuf.c
+++ b/drivers/xen/xen-front-pgdir-shbuf.c
@@ -447,8 +447,10 @@ static int grant_references(struct xen_front_pgdir_shbuf *buf)
unsigned long frame;
cur_ref = gnttab_claim_grant_reference(&priv_gref_head);
- if (cur_ref < 0)
- return cur_ref;
+ if (cur_ref < 0) {
+ ret = cur_ref;
+ goto out_free_refs;
+ }
frame = xen_page_to_gfn(virt_to_page(buf->directory +
PAGE_SIZE * i));
@@ -459,11 +461,13 @@ static int grant_references(struct xen_front_pgdir_shbuf *buf)
if (buf->ops->grant_refs_for_buffer) {
ret = buf->ops->grant_refs_for_buffer(buf, &priv_gref_head, j);
if (ret)
- return ret;
+ goto out_free_refs;
}
+ ret = 0;
+out_free_refs:
gnttab_free_grant_references(priv_gref_head);
- return 0;
+ return ret;
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 240/982] freevxfs: dont BUG() on unknown typed-extent type
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (238 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 239/982] xen/front-pgdir-shbuf: free grant reference head on errors Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 241/982] xen/gntalloc: validate grant count before allocation Greg Kroah-Hartman
` (748 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Farhad Alemi, Christoph Hellwig,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhad Alemi <farhad.alemi@berkeley.edu>
[ Upstream commit 704d48d81dc41470e108811c32c577ada66192d4 ]
vxfs_bmap_typed() handles four typed-extent types and calls BUG() in
its default case, so an on-disk typed extent with any other type value
crashes the kernel. It is reachable from ioctl(FIBMAP) on a regular
file:
kernel BUG at fs/freevxfs/vxfs_bmap.c:230!
RIP: vxfs_bmap_typed fs/freevxfs/vxfs_bmap.c:230 [inline]
vxfs_bmap1+0x128a/0x12d0 fs/freevxfs/vxfs_bmap.c:257
Replace the BUG() with WARN_ON_ONCE() and return 0 -- the value
vxfs_bmap_typed() already returns on failure (and from the DEV4 case
above); vxfs_getblk() maps 0 to -EIO, so the ioctl fails cleanly.
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Link: https://patch.msgid.link/CA+0ovChveuAwv=t15dr2m09E32bM48hHJxvfeEYZOhdNiEc9Tw@mail.gmail.com
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/freevxfs/vxfs_bmap.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/freevxfs/vxfs_bmap.c b/fs/freevxfs/vxfs_bmap.c
index de2a5bccb9307..d10a99b25be8c 100644
--- a/fs/freevxfs/vxfs_bmap.c
+++ b/fs/freevxfs/vxfs_bmap.c
@@ -227,7 +227,8 @@ vxfs_bmap_typed(struct inode *ip, long iblock)
return 0;
}
default:
- BUG();
+ WARN_ON_ONCE(1);
+ return 0;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 241/982] xen/gntalloc: validate grant count before allocation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (239 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 240/982] freevxfs: dont BUG() on unknown typed-extent type Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 242/982] ksmbd: fix outstanding credit leak on abort and error paths Greg Kroah-Hartman
` (747 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yousef Alhouseen, Juergen Gross,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yousef Alhouseen <alhouseenyousef@gmail.com>
[ Upstream commit 2299822f3f466b5dcad2377bf63986199f881a6b ]
gntalloc_ioctl_alloc() allocates the grant-id array before checking
whether the requested count fits within the global grant limit. Counts
above that limit cannot succeed, so reject them before the
user-controlled allocation reaches kcalloc().
Use a subtraction-based check while holding gref_mutex so adding the
requested count cannot wrap. Also cast the count before advancing the
per-file index so the page-size multiplication is performed in 64-bit
arithmetic.
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Reviewed-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
Message-ID: <20260626223805.43781-3-alhouseenyousef@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/xen/gntalloc.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/drivers/xen/gntalloc.c b/drivers/xen/gntalloc.c
index a15729beb9d1b..22747fa4bbb89 100644
--- a/drivers/xen/gntalloc.c
+++ b/drivers/xen/gntalloc.c
@@ -272,6 +272,7 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv,
int rc = 0;
struct ioctl_gntalloc_alloc_gref op;
uint32_t *gref_ids;
+ unsigned int limit_snapshot;
pr_debug("%s: priv %p\n", __func__, priv);
@@ -280,6 +281,12 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv,
goto out;
}
+ limit_snapshot = READ_ONCE(limit);
+ if (op.count > limit_snapshot) {
+ rc = -ENOSPC;
+ goto out;
+ }
+
gref_ids = kcalloc(op.count, sizeof(gref_ids[0]), GFP_KERNEL);
if (!gref_ids) {
rc = -ENOMEM;
@@ -292,14 +299,16 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv,
* are about to enforce, removing them here is a good idea.
*/
do_cleanup();
- if (gref_size + op.count > limit) {
+ limit_snapshot = READ_ONCE(limit);
+ if (gref_size > limit_snapshot ||
+ op.count > limit_snapshot - gref_size) {
mutex_unlock(&gref_mutex);
rc = -ENOSPC;
goto out_free;
}
gref_size += op.count;
op.index = priv->index;
- priv->index += op.count * PAGE_SIZE;
+ priv->index += (uint64_t)op.count * PAGE_SIZE;
mutex_unlock(&gref_mutex);
rc = add_grefs(&op, gref_ids, priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 242/982] ksmbd: fix outstanding credit leak on abort and error paths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (240 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 241/982] xen/gntalloc: validate grant count before allocation Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 243/982] cachefiles: Fix double fput Greg Kroah-Hartman
` (746 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 4a0b7826615a01c47924334a2e8a9dbd84a598b2 ]
smb2_validate_credit_charge() adds the request's CreditCharge to
conn->outstanding_credits when an SMB2 PDU is received, and
smb2_set_rsp_credits() subtracts it again when the response is built.
However smb2_set_rsp_credits() only runs on the normal response path:
- __process_request() returning SERVER_HANDLER_ABORT (unimplemented
command, command index out of range, signature check failure, or a
handler that sets send_no_response such as a cancelled blocking
lock) breaks out of the processing loop before set_rsp_credits() is
called;
- smb2_set_rsp_credits() itself returns early with -EINVAL (total
credit overflow or insufficient credits) before the subtraction.
On all of these paths the charge added at receive time is never
returned, so conn->outstanding_credits only grows. Because a client can
repeatedly trigger them (e.g. by sending unimplemented commands or by
issuing and cancelling blocking locks), outstanding_credits eventually
reaches total_credits and smb2_validate_credit_charge() then rejects
every subsequent request, wedging the connection.
Record the charge that was added in work->credit_charge and release any
charge still pending at the single send. exit point of
__handle_ksmbd_work(), which all abort and error paths fall through to.
smb2_set_rsp_credits() clears work->credit_charge once it has returned
the charge so the response path is unchanged and the credit is never
released twice. Paths that never charged a credit (no multi-credit
support, validation failure) leave work->credit_charge at zero and are
unaffected.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/ksmbd_work.h | 7 +++++++
fs/smb/server/server.c | 14 ++++++++++++++
fs/smb/server/smb2misc.c | 9 ++++++---
fs/smb/server/smb2pdu.c | 1 +
4 files changed, 28 insertions(+), 3 deletions(-)
diff --git a/fs/smb/server/ksmbd_work.h b/fs/smb/server/ksmbd_work.h
index 8ca2c813246e6..9c3f834901e13 100644
--- a/fs/smb/server/ksmbd_work.h
+++ b/fs/smb/server/ksmbd_work.h
@@ -63,6 +63,13 @@ struct ksmbd_work {
/* Number of granted credits */
unsigned int credits_granted;
+ /*
+ * Credit charge added to conn->outstanding_credits at receive time
+ * for the SMB2 PDU currently being processed, pending release. Zero
+ * once the charge has been returned (on the response or error path).
+ */
+ unsigned short credit_charge;
+
/* response smb header size */
unsigned int response_sz;
diff --git a/fs/smb/server/server.c b/fs/smb/server/server.c
index fe797e8fe9419..ac7477edc62f2 100644
--- a/fs/smb/server/server.c
+++ b/fs/smb/server/server.c
@@ -238,6 +238,20 @@ static void __handle_ksmbd_work(struct ksmbd_work *work,
} while (is_chained == true);
send:
+ /*
+ * Release any credit charge still outstanding for this request. On
+ * the normal path smb2_set_rsp_credits() already returned it, but the
+ * abort, error and send-no-response paths skip that call, so the
+ * charge would otherwise leak and eventually exhaust the connection's
+ * outstanding credit window.
+ */
+ if (work->credit_charge) {
+ spin_lock(&conn->credits_lock);
+ conn->outstanding_credits -= work->credit_charge;
+ work->credit_charge = 0;
+ spin_unlock(&conn->credits_lock);
+ }
+
if (work->tcon)
ksmbd_tree_connect_put(work->tcon);
smb3_preauth_hash_rsp(work);
diff --git a/fs/smb/server/smb2misc.c b/fs/smb/server/smb2misc.c
index 6a4f1b8a0b13c..8b56770f36ed8 100644
--- a/fs/smb/server/smb2misc.c
+++ b/fs/smb/server/smb2misc.c
@@ -298,9 +298,10 @@ static inline int smb2_ioctl_resp_len(struct smb2_ioctl_req *h)
le32_to_cpu(h->MaxOutputResponse);
}
-static int smb2_validate_credit_charge(struct ksmbd_conn *conn,
+static int smb2_validate_credit_charge(struct ksmbd_work *work,
struct smb2_hdr *hdr)
{
+ struct ksmbd_conn *conn = work->conn;
unsigned int req_len = 0, expect_resp_len = 0, calc_credit_num, max_len;
unsigned short credit_charge = le16_to_cpu(hdr->CreditCharge);
void *__hdr = hdr;
@@ -357,8 +358,10 @@ static int smb2_validate_credit_charge(struct ksmbd_conn *conn,
ksmbd_debug(SMB, "Limits exceeding the maximum allowable outstanding requests, given : %u, pending : %u\n",
credit_charge, conn->outstanding_credits);
ret = 1;
- } else
+ } else {
conn->outstanding_credits += credit_charge;
+ work->credit_charge = credit_charge;
+ }
spin_unlock(&conn->credits_lock);
@@ -466,7 +469,7 @@ int ksmbd_smb2_check_message(struct ksmbd_work *work)
validate_credit:
if ((work->conn->vals->req_capabilities & SMB2_GLOBAL_CAP_LARGE_MTU) &&
- smb2_validate_credit_charge(work->conn, hdr))
+ smb2_validate_credit_charge(work, hdr))
return 1;
return 0;
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index ebd13393f8d46..1f903350039cf 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -342,6 +342,7 @@ int smb2_set_rsp_credits(struct ksmbd_work *work)
conn->total_credits -= credit_charge;
conn->outstanding_credits -= credit_charge;
+ work->credit_charge = 0;
credits_requested = max_t(unsigned short,
le16_to_cpu(req_hdr->CreditRequest), 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 243/982] cachefiles: Fix double fput
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (241 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 242/982] ksmbd: fix outstanding credit leak on abort and error paths Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 244/982] ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table Greg Kroah-Hartman
` (745 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Howells, Paulo Alcantara,
netfs, linux-fsdevel, Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
[ Upstream commit af6830cc12dfe86c832dccc9c9878a93aaa22f83 ]
Fix a double fput() in error handling in cachefiles_create_tmpfile().
Link: https://sashiko.dev/#/patchset/20260608145432.681865-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260625140640.3116900-4-dhowells@redhat.com
cc: Paulo Alcantara <pc@manguebit.org>
cc: netfs@lists.linux.dev
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/cachefiles/namei.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/fs/cachefiles/namei.c b/fs/cachefiles/namei.c
index cbd0ff47acea0..7893c607b2479 100644
--- a/fs/cachefiles/namei.c
+++ b/fs/cachefiles/namei.c
@@ -494,7 +494,6 @@ struct file *cachefiles_create_tmpfile(struct cachefiles_object *object)
ret = -EINVAL;
if (unlikely(!file->f_op->read_iter) ||
unlikely(!file->f_op->write_iter)) {
- fput(file);
pr_notice("Cache does not support read_iter and write_iter\n");
goto err_unuse;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 244/982] ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (242 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 243/982] cachefiles: Fix double fput Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 245/982] ksmbd: fix credit charge calculation for SMB2 QUERY_INFO Greg Kroah-Hartman
` (744 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jetha Chan, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jetha Chan <jethachan@gmail.com>
[ Upstream commit e782d687d2f5bf8b8113dc48ba22cca4b472c252 ]
The Alienware m15 R7 AMD exposes an ACP6x DMIC path, but its DMI
product name is not present in the Yellow Carp ACP quirk table. As a
result, the ACP machine driver does not enable the DMIC card on this
system.
Add the DMI product name for this machine. With this quirk applied, the
kernel reports:
acp_yc_mach acp_yc_mach.0: Enabling ACP DMIC support via DMI
and ALSA exposes the ACP DMIC capture device:
card 3: acp6x
device 0: DMIC capture dmic-hifi-0
Tested on an Alienware m15 R7 AMD with product SKU 0B59.
Link: https://jethachan.net/dev/2026/03/21/fixing-internal-microphone-alienware-linux.html
Assisted-by: OpenAI-Codex:gpt-5.5
Signed-off-by: Jetha Chan <jethachan@gmail.com>
Link: https://patch.msgid.link/20260630003328.15675-1-jethachan@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/yc/acp6x-mach.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/sound/soc/amd/yc/acp6x-mach.c b/sound/soc/amd/yc/acp6x-mach.c
index d2ad98dbebf14..afbf1edbeeb5b 100644
--- a/sound/soc/amd/yc/acp6x-mach.c
+++ b/sound/soc/amd/yc/acp6x-mach.c
@@ -395,6 +395,13 @@ static const struct dmi_system_id yc_acp_quirk_table[] = {
DMI_MATCH(DMI_PRODUCT_NAME, "83J3"),
}
},
+ {
+ .driver_data = &acp6x_card,
+ .matches = {
+ DMI_MATCH(DMI_BOARD_VENDOR, "Alienware"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "Alienware m15 R7 AMD"),
+ }
+ },
{
.driver_data = &acp6x_card,
.matches = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 245/982] ksmbd: fix credit charge calculation for SMB2 QUERY_INFO
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (243 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 244/982] ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 246/982] ALSA: usb-audio: caiaq: validate EP1 reply lengths Greg Kroah-Hartman
` (743 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 284dc80ff529a0b454f11b6c2fea0d5daf6f315f ]
smb2_validate_credit_charge() computes the credit charge a request is
allowed to consume from the payload size:
CreditCharge = (max(SendPayloadSize, ResponsePayloadSize) - 1)/65536 + 1
For SMB2 QUERY_INFO, the server must validate CreditCharge based on the
*maximum* of InputBufferLength and OutputBufferLength. ksmbd instead
summed the two lengths, which overestimates the required charge.
As a result a single-credit QUERY_INFO whose InputBufferLength and
OutputBufferLength each fit in 64KB but whose sum exceeds 64KB is
rejected with STATUS_INVALID_PARAMETER, even though it is a valid
request. IOCTL already uses max() of the request and response sizes;
make QUERY_INFO consistent by feeding InputBufferLength as the request
length and OutputBufferLength as the expected response length so that
smb2_validate_credit_charge() takes their maximum.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2misc.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/fs/smb/server/smb2misc.c b/fs/smb/server/smb2misc.c
index 8b56770f36ed8..5b6fb0ba83a54 100644
--- a/fs/smb/server/smb2misc.c
+++ b/fs/smb/server/smb2misc.c
@@ -262,8 +262,12 @@ static int smb2_calc_size(void *buf, unsigned int *len)
static inline int smb2_query_info_req_len(struct smb2_query_info_req *h)
{
- return le32_to_cpu(h->InputBufferLength) +
- le32_to_cpu(h->OutputBufferLength);
+ return le32_to_cpu(h->InputBufferLength);
+}
+
+static inline int smb2_query_info_resp_len(struct smb2_query_info_req *h)
+{
+ return le32_to_cpu(h->OutputBufferLength);
}
static inline int smb2_set_info_req_len(struct smb2_set_info_req *h)
@@ -310,6 +314,7 @@ static int smb2_validate_credit_charge(struct ksmbd_work *work,
switch (hdr->Command) {
case SMB2_QUERY_INFO:
req_len = smb2_query_info_req_len(__hdr);
+ expect_resp_len = smb2_query_info_resp_len(__hdr);
break;
case SMB2_SET_INFO:
req_len = smb2_set_info_req_len(__hdr);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 246/982] ALSA: usb-audio: caiaq: validate EP1 reply lengths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (244 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 245/982] ksmbd: fix credit charge calculation for SMB2 QUERY_INFO Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 247/982] wifi: ralink: RT2X00: init EEPROM properly Greg Kroah-Hartman
` (742 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit aba30af07d4fe499b50209801eba9da8a815522f ]
usb_ep1_command_reply_dispatch() uses buf[0] as a command byte and then
reads command-specific fixed items from the same URB buffer. Several
paths use buf + 1, buf[1], buf[2], or buf + 3 without first proving that
urb->actual_length contains those bytes.
Add per-command length checks, use a payload length derived from the
bytes after the command byte for the control-state copy, and reject short
analog input payloads before the input helper reads fixed offsets from
the EP1 reply.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260705084601.56400-1-pengpeng@iscas.ac.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/caiaq/device.c | 17 ++++++++++++++---
sound/usb/caiaq/input.c | 6 ++++++
2 files changed, 20 insertions(+), 3 deletions(-)
diff --git a/sound/usb/caiaq/device.c b/sound/usb/caiaq/device.c
index 12f79e977c5a6..7ad64d23269fe 100644
--- a/sound/usb/caiaq/device.c
+++ b/sound/usb/caiaq/device.c
@@ -134,14 +134,22 @@ static void usb_ep1_command_reply_dispatch (struct urb* urb)
struct device *dev = &urb->dev->dev;
struct snd_usb_caiaqdev *cdev = urb->context;
unsigned char *buf = urb->transfer_buffer;
+ unsigned int payload_len;
+ unsigned int copy_len;
if (urb->status || !cdev) {
dev_warn(dev, "received EP1 urb->status = %i\n", urb->status);
return;
}
+ if (urb->actual_length < 1)
+ return;
+
+ payload_len = urb->actual_length - 1;
switch(buf[0]) {
case EP1_CMD_GET_DEVICE_INFO:
+ if (payload_len < sizeof(struct caiaq_device_spec))
+ break;
memcpy(&cdev->spec, buf+1, sizeof(struct caiaq_device_spec));
cdev->spec.fw_version = le16_to_cpu(cdev->spec.fw_version);
dev_dbg(dev, "device spec (firmware %d): audio: %d in, %d out, "
@@ -157,18 +165,21 @@ static void usb_ep1_command_reply_dispatch (struct urb* urb)
wake_up(&cdev->ep1_wait_queue);
break;
case EP1_CMD_AUDIO_PARAMS:
+ if (payload_len < 1)
+ break;
cdev->audio_parm_answer = buf[1];
wake_up(&cdev->ep1_wait_queue);
break;
case EP1_CMD_MIDI_READ:
+ if (urb->actual_length < 3 || urb->actual_length - 3 < buf[2])
+ break;
snd_usb_caiaq_midi_handle_input(cdev, buf[1], buf + 3, buf[2]);
break;
case EP1_CMD_READ_IO:
if (cdev->chip.usb_id ==
USB_ID(USB_VID_NATIVEINSTRUMENTS, USB_PID_AUDIO8DJ)) {
- if (urb->actual_length > sizeof(cdev->control_state))
- urb->actual_length = sizeof(cdev->control_state);
- memcpy(cdev->control_state, buf + 1, urb->actual_length);
+ copy_len = min_t(unsigned int, payload_len, sizeof(cdev->control_state));
+ memcpy(cdev->control_state, buf + 1, copy_len);
wake_up(&cdev->ep1_wait_queue);
break;
}
diff --git a/sound/usb/caiaq/input.c b/sound/usb/caiaq/input.c
index 2db4d1332df1c..c12eeb9710002 100644
--- a/sound/usb/caiaq/input.c
+++ b/sound/usb/caiaq/input.c
@@ -203,6 +203,8 @@ static void snd_caiaq_input_read_analog(struct snd_usb_caiaqdev *cdev,
switch (cdev->chip.usb_id) {
case USB_ID(USB_VID_NATIVEINSTRUMENTS, USB_PID_RIGKONTROL2):
+ if (len < 6)
+ return;
snd_caiaq_input_report_abs(cdev, ABS_X, buf, 2);
snd_caiaq_input_report_abs(cdev, ABS_Y, buf, 0);
snd_caiaq_input_report_abs(cdev, ABS_Z, buf, 1);
@@ -210,11 +212,15 @@ static void snd_caiaq_input_read_analog(struct snd_usb_caiaqdev *cdev,
case USB_ID(USB_VID_NATIVEINSTRUMENTS, USB_PID_RIGKONTROL3):
case USB_ID(USB_VID_NATIVEINSTRUMENTS, USB_PID_KORECONTROLLER):
case USB_ID(USB_VID_NATIVEINSTRUMENTS, USB_PID_KORECONTROLLER2):
+ if (len < 6)
+ return;
snd_caiaq_input_report_abs(cdev, ABS_X, buf, 0);
snd_caiaq_input_report_abs(cdev, ABS_Y, buf, 1);
snd_caiaq_input_report_abs(cdev, ABS_Z, buf, 2);
break;
case USB_ID(USB_VID_NATIVEINSTRUMENTS, USB_PID_TRAKTORKONTROLX1):
+ if (len < 16)
+ return;
snd_caiaq_input_report_abs(cdev, ABS_HAT0X, buf, 4);
snd_caiaq_input_report_abs(cdev, ABS_HAT0Y, buf, 2);
snd_caiaq_input_report_abs(cdev, ABS_HAT1X, buf, 6);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 247/982] wifi: ralink: RT2X00: init EEPROM properly
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (245 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 246/982] ALSA: usb-audio: caiaq: validate EP1 reply lengths Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 248/982] wifi: mac80211: validate deauth frame length before reason access Greg Kroah-Hartman
` (741 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Corentin Labbe, Stanislaw Gruszka,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Corentin Labbe <clabbe@baylibre.com>
[ Upstream commit 0a2581cbae9e442835f68d22044157db61cdf54d ]
I have an hostapd setup with a
01:00.0 Network controller: Ralink corp. RT2790 Wireless 802.11n 1T/2R PCIe
The setup work fine on 6.18.26-gentoo
It breaks on 6.18.33-gentoo (and still broken on 6.18.37)
I found an hint in dmesg:
On 6.18.26-gentoo I see:
May 31 15:48:45 trash01 kernel: ieee80211 phy0: rt2x00_set_rf: Info - RF chipset 0003 detected
On 6.18.33-gentoo I see:
May 31 15:22:57 trash01 kernel: ieee80211 phy0: rt2x00_set_rf: Info - RF chipset 0006 detected
The RF chipset seems badly detected.
The problem was the EEPROM which was badly initialized.
Probably the origin was in some PCI change but unfortunately I couldn't play
to bisect/reboot often the board with this card to do it.
Signed-off-by: Corentin Labbe <clabbe@baylibre.com>
Acked-by: Stanislaw Gruszka <stf_xl@wp.pl>
Link: https://patch.msgid.link/20260703134932.3786771-1-clabbe@baylibre.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ralink/rt2x00/rt2400pci.c | 2 +-
drivers/net/wireless/ralink/rt2x00/rt2500pci.c | 2 +-
drivers/net/wireless/ralink/rt2x00/rt2800pci.c | 2 +-
drivers/net/wireless/ralink/rt2x00/rt61pci.c | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/ralink/rt2x00/rt2400pci.c b/drivers/net/wireless/ralink/rt2x00/rt2400pci.c
index ddfc16de1b26f..4eb12dbbdd8b0 100644
--- a/drivers/net/wireless/ralink/rt2x00/rt2400pci.c
+++ b/drivers/net/wireless/ralink/rt2x00/rt2400pci.c
@@ -1429,7 +1429,7 @@ static irqreturn_t rt2400pci_interrupt(int irq, void *dev_instance)
*/
static int rt2400pci_validate_eeprom(struct rt2x00_dev *rt2x00dev)
{
- struct eeprom_93cx6 eeprom;
+ struct eeprom_93cx6 eeprom = {};
u32 reg;
u16 word;
u8 *mac;
diff --git a/drivers/net/wireless/ralink/rt2x00/rt2500pci.c b/drivers/net/wireless/ralink/rt2x00/rt2500pci.c
index cd6371e25062b..7efb96f1cc797 100644
--- a/drivers/net/wireless/ralink/rt2x00/rt2500pci.c
+++ b/drivers/net/wireless/ralink/rt2x00/rt2500pci.c
@@ -1555,7 +1555,7 @@ static irqreturn_t rt2500pci_interrupt(int irq, void *dev_instance)
*/
static int rt2500pci_validate_eeprom(struct rt2x00_dev *rt2x00dev)
{
- struct eeprom_93cx6 eeprom;
+ struct eeprom_93cx6 eeprom = {};
u32 reg;
u16 word;
u8 *mac;
diff --git a/drivers/net/wireless/ralink/rt2x00/rt2800pci.c b/drivers/net/wireless/ralink/rt2x00/rt2800pci.c
index 1fde0e767ce39..631e27d73729f 100644
--- a/drivers/net/wireless/ralink/rt2x00/rt2800pci.c
+++ b/drivers/net/wireless/ralink/rt2x00/rt2800pci.c
@@ -108,7 +108,7 @@ static void rt2800pci_eepromregister_write(struct eeprom_93cx6 *eeprom)
static int rt2800pci_read_eeprom_pci(struct rt2x00_dev *rt2x00dev)
{
- struct eeprom_93cx6 eeprom;
+ struct eeprom_93cx6 eeprom = {};
u32 reg;
reg = rt2x00mmio_register_read(rt2x00dev, E2PROM_CSR);
diff --git a/drivers/net/wireless/ralink/rt2x00/rt61pci.c b/drivers/net/wireless/ralink/rt2x00/rt61pci.c
index 81db7f57c7e42..9c713117b3f32 100644
--- a/drivers/net/wireless/ralink/rt2x00/rt61pci.c
+++ b/drivers/net/wireless/ralink/rt2x00/rt61pci.c
@@ -2298,7 +2298,7 @@ static irqreturn_t rt61pci_interrupt(int irq, void *dev_instance)
*/
static int rt61pci_validate_eeprom(struct rt2x00_dev *rt2x00dev)
{
- struct eeprom_93cx6 eeprom;
+ struct eeprom_93cx6 eeprom = {};
u32 reg;
u16 word;
u8 *mac;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 248/982] wifi: mac80211: validate deauth frame length before reason access
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (246 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 247/982] wifi: ralink: RT2X00: init EEPROM properly Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 249/982] wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers Greg Kroah-Hartman
` (740 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit 4a360c6e18dfa9d70006c7247a6a8cc8dfe0d60f ]
ieee80211_rx_mgmt_deauth() reads the deauth reason code before checking
that the fixed field is actually present in the received frame.
Validate the deauth frame length first and only then read the reason
code.
Assisted-by: Codex:gpt-5.5
Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260612185042.66260-6-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mlme.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/net/mac80211/mlme.c b/net/mac80211/mlme.c
index aa9aaa9cb42b6..32f24dca40ab5 100644
--- a/net/mac80211/mlme.c
+++ b/net/mac80211/mlme.c
@@ -3833,13 +3833,15 @@ static void ieee80211_rx_mgmt_deauth(struct ieee80211_sub_if_data *sdata,
struct ieee80211_mgmt *mgmt, size_t len)
{
struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
- u16 reason_code = le16_to_cpu(mgmt->u.deauth.reason_code);
+ u16 reason_code;
sdata_assert_lock(sdata);
- if (len < 24 + 2)
+ if (len < offsetofend(struct ieee80211_mgmt, u.deauth.reason_code))
return;
+ reason_code = le16_to_cpu(mgmt->u.deauth.reason_code);
+
if (!ether_addr_equal(mgmt->bssid, mgmt->sa)) {
ieee80211_tdls_handle_disconnect(sdata, mgmt->sa, reason_code);
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 249/982] wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (247 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 248/982] wifi: mac80211: validate deauth frame length before reason access Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 250/982] wifi: libertas: reject short monitor TX frames Greg Kroah-Hartman
` (739 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 843fe9bc583b7686ca68312ac9319c9240a73c03 ]
rsi_hal_load_key() copies tx_mic_key and rx_mic_key from data[16] and
data[24] whenever key data is present. Those offsets are only part of
the 32-byte TKIP key layout. Shorter keys used by other ciphers, such as
CCMP, do not provide those bytes, so the unconditional copies can read
past the supplied key buffer.
Only copy the MIC keys for TKIP, and reject malformed TKIP keys that are
shorter than the expected 32-byte layout.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260701053414.34015-1-pengpeng@iscas.ac.cn
[drop useless length check]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/rsi/rsi_91x_mgmt.c b/drivers/net/wireless/rsi/rsi_91x_mgmt.c
index 1b309e47a1f11..195d7394ab775 100644
--- a/drivers/net/wireless/rsi/rsi_91x_mgmt.c
+++ b/drivers/net/wireless/rsi/rsi_91x_mgmt.c
@@ -848,8 +848,10 @@ int rsi_hal_load_key(struct rsi_common *common,
} else {
memcpy(&set_key->key[0][0], data, key_len);
}
- memcpy(set_key->tx_mic_key, &data[16], 8);
- memcpy(set_key->rx_mic_key, &data[24], 8);
+ if (cipher == WLAN_CIPHER_SUITE_TKIP) {
+ memcpy(set_key->tx_mic_key, &data[16], 8);
+ memcpy(set_key->rx_mic_key, &data[24], 8);
+ }
} else {
memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 250/982] wifi: libertas: reject short monitor TX frames
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (248 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 249/982] wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 251/982] wifi: cfg80211: validate assoc response length before status and IE access Greg Kroah-Hartman
` (738 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 13ff543e0b2c713aedeaadadde686686e949dc78 ]
In monitor mode, lbs_hard_start_xmit() casts skb->data to a
radiotap TX header, skips that header, and then copies the 802.11
destination address from offset 4 in the remaining frame. The
generic length check only rejects zero-length and oversized skbs, so
a short monitor frame can be read past the end of the skb data.
Require enough bytes for the radiotap TX header and the destination
address field before using the monitor-mode header layout.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260704011140.37639-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/libertas/tx.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/net/wireless/marvell/libertas/tx.c b/drivers/net/wireless/marvell/libertas/tx.c
index 27304a98787d6..13d08022e4141 100644
--- a/drivers/net/wireless/marvell/libertas/tx.c
+++ b/drivers/net/wireless/marvell/libertas/tx.c
@@ -117,6 +117,13 @@ netdev_tx_t lbs_hard_start_xmit(struct sk_buff *skb, struct net_device *dev)
if (priv->wdev->iftype == NL80211_IFTYPE_MONITOR) {
struct tx_radiotap_hdr *rtap_hdr = (void *)skb->data;
+ if (skb->len < sizeof(*rtap_hdr) + 4 + ETH_ALEN) {
+ lbs_deb_tx("tx err: short monitor frame %u\n", skb->len);
+ dev->stats.tx_dropped++;
+ dev->stats.tx_errors++;
+ goto free;
+ }
+
/* set txpd fields from the radiotap header */
txpd->tx_control = cpu_to_le32(convert_radiotap_rate_to_mv(rtap_hdr->rate));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 251/982] wifi: cfg80211: validate assoc response length before status and IE access
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (249 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 250/982] wifi: libertas: reject short monitor TX frames Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 252/982] ksmbd: find bound sessions during reauthentication Greg Kroah-Hartman
` (737 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit b760113aeca2e9362d56bf9e9263373ffe6c8eb3 ]
cfg80211_rx_assoc_resp() initialises the status and response-IE fields
of cfg80211_connect_resp_params from the management frame before
proving that the frame is long enough for those offsets. S1G and
regular association responses also have different IE offsets, but the
S1G path only patched resp_ie after the unsafe initialiser had already
run.
Defer resp_ie, resp_ie_len, and status to after the link-iteration
loop. Use a bool to remember whether the frame is S1G, then validate
the appropriate minimum length and set all three fields in a single
if/else block. Funnel short-frame and SME-reject cleanup through a
shared free_bss label for the abandon paths.
Assisted-by: Codex:gpt-5.5
Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260707025336.22557-2-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/mlme.c | 56 ++++++++++++++++++++++++++++-----------------
1 file changed, 35 insertions(+), 21 deletions(-)
diff --git a/net/wireless/mlme.c b/net/wireless/mlme.c
index e0246ed9f66f2..4ba97fdbf724d 100644
--- a/net/wireless/mlme.c
+++ b/net/wireless/mlme.c
@@ -32,14 +32,10 @@ void cfg80211_rx_assoc_resp(struct net_device *dev,
.timeout_reason = NL80211_TIMEOUT_UNSPECIFIED,
.req_ie = data->req_ies,
.req_ie_len = data->req_ies_len,
- .resp_ie = mgmt->u.assoc_resp.variable,
- .resp_ie_len = data->len -
- offsetof(struct ieee80211_mgmt,
- u.assoc_resp.variable),
- .status = le16_to_cpu(mgmt->u.assoc_resp.status_code),
.ap_mld_addr = data->ap_mld_addr,
};
unsigned int link_id;
+ bool is_s1g = false;
for (link_id = 0; link_id < ARRAY_SIZE(data->links); link_id++) {
cr.links[link_id].bss = data->links[link_id].bss;
@@ -54,16 +50,32 @@ void cfg80211_rx_assoc_resp(struct net_device *dev,
if (cr.links[link_id].bss->channel->band == NL80211_BAND_S1GHZ) {
WARN_ON(link_id);
- cr.resp_ie = (u8 *)&mgmt->u.s1g_assoc_resp.variable;
- cr.resp_ie_len = data->len -
- offsetof(struct ieee80211_mgmt,
- u.s1g_assoc_resp.variable);
+ is_s1g = true;
}
if (cr.ap_mld_addr)
cr.valid_links |= BIT(link_id);
}
+ if (is_s1g) {
+ if (data->len < offsetof(struct ieee80211_mgmt,
+ u.s1g_assoc_resp.variable))
+ goto free_bss;
+ cr.resp_ie = (u8 *)&mgmt->u.s1g_assoc_resp.variable;
+ cr.resp_ie_len = data->len -
+ offsetof(struct ieee80211_mgmt,
+ u.s1g_assoc_resp.variable);
+ } else {
+ if (data->len < offsetof(struct ieee80211_mgmt,
+ u.assoc_resp.variable))
+ goto free_bss;
+ cr.resp_ie = mgmt->u.assoc_resp.variable;
+ cr.resp_ie_len = data->len -
+ offsetof(struct ieee80211_mgmt,
+ u.assoc_resp.variable);
+ }
+ cr.status = le16_to_cpu(mgmt->u.assoc_resp.status_code);
+
trace_cfg80211_send_rx_assoc(dev, data);
/*
@@ -72,22 +84,24 @@ void cfg80211_rx_assoc_resp(struct net_device *dev,
* and got a reject -- we only try again with an assoc
* frame instead of reassoc.
*/
- if (cfg80211_sme_rx_assoc_resp(wdev, cr.status)) {
- for (link_id = 0; link_id < ARRAY_SIZE(data->links); link_id++) {
- struct cfg80211_bss *bss = data->links[link_id].bss;
-
- if (!bss)
- continue;
-
- cfg80211_unhold_bss(bss_from_pub(bss));
- cfg80211_put_bss(wiphy, bss);
- }
- return;
- }
+ if (cfg80211_sme_rx_assoc_resp(wdev, cr.status))
+ goto free_bss;
nl80211_send_rx_assoc(rdev, dev, data);
/* update current_bss etc., consumes the bss reference */
__cfg80211_connect_result(dev, &cr, cr.status == WLAN_STATUS_SUCCESS);
+ return;
+
+free_bss:
+ for (link_id = 0; link_id < ARRAY_SIZE(data->links); link_id++) {
+ struct cfg80211_bss *bss = data->links[link_id].bss;
+
+ if (!bss)
+ continue;
+
+ cfg80211_unhold_bss(bss_from_pub(bss));
+ cfg80211_put_bss(wiphy, bss);
+ }
}
EXPORT_SYMBOL(cfg80211_rx_assoc_resp);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 252/982] ksmbd: find bound sessions during reauthentication
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (250 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 251/982] wifi: cfg80211: validate assoc response length before status and IE access Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 253/982] ksmbd: mark invalid session responses as signed Greg Kroah-Hartman
` (736 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit faf8578c77f3d846aca9cd882c293e03eafcc6df ]
A session bound to an additional connection is stored in the session
channel list, but it is not added to that connection's local session table.
After the binding exchange completes, conn->binding is cleared.
A later SESSION_SETUP reauthentication on the bound channel only searches
the local session table. It fails to find the session and returns
STATUS_USER_SESSION_DELETED instead of processing authentication and
returning STATUS_LOGON_FAILURE for invalid credentials.
If the local lookup fails, look up the session globally and accept it only
when the current connection is registered in its channel list. This keeps
unbound connections from using the session while allowing reauthentication
on an established channel.
This fixes smb2.session.bind_invalid_auth.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 1f903350039cf..b5861e830aba3 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -1788,6 +1788,13 @@ int smb2_sess_setup(struct ksmbd_work *work)
} else {
sess = ksmbd_session_lookup(conn,
le64_to_cpu(req->hdr.SessionId));
+ if (!sess) {
+ sess = ksmbd_session_lookup_slowpath(le64_to_cpu(req->hdr.SessionId));
+ if (sess && !lookup_chann_list(sess, conn)) {
+ ksmbd_user_session_put(sess);
+ sess = NULL;
+ }
+ }
if (!sess) {
rc = -ENOENT;
goto out_err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 253/982] ksmbd: mark invalid session responses as signed
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (251 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 252/982] ksmbd: find bound sessions during reauthentication Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 254/982] ksmbd: validate SID namespace before mapping IDs Greg Kroah-Hartman
` (735 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 9e8ad620ddfde5a5f4ef58372e3805e9388cb0f4 ]
When a signed request uses a session that is not registered on the
connection, ksmbd returns STATUS_USER_SESSION_DELETED before reaching the
normal response signing path. The response therefore lacks
SMB2_FLAGS_SIGNED.
Clients that require signing check this flag before handling
STATUS_USER_SESSION_DELETED and replace the server status with
STATUS_ACCESS_DENIED when it is absent. The protocol permits this error
response to skip signature verification because the connection has no
matching session key.
Preserve SMB2_FLAGS_SIGNED on the early error response when the request was
signed. This lets the client propagate STATUS_USER_SESSION_DELETED.
It fixes smb2.session.bind2.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/server.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/smb/server/server.c b/fs/smb/server/server.c
index ac7477edc62f2..a5e9bb40e2191 100644
--- a/fs/smb/server/server.c
+++ b/fs/smb/server/server.c
@@ -195,6 +195,12 @@ static void __handle_ksmbd_work(struct ksmbd_work *work,
else
conn->ops->set_rsp_status(work,
STATUS_USER_SESSION_DELETED);
+ if (conn->ops->is_sign_req(work, conn->ops->get_cmd_val(work))) {
+ struct smb2_hdr *rsp_hdr;
+
+ rsp_hdr = ksmbd_resp_buf_curr(work);
+ rsp_hdr->Flags |= SMB2_FLAGS_SIGNED;
+ }
goto send;
} else if (rc > 0) {
rc = conn->ops->get_ksmbd_tcon(work);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 254/982] ksmbd: validate SID namespace before mapping IDs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (252 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 253/982] ksmbd: mark invalid session responses as signed Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 255/982] wifi: cfg80211: validate rx/tx MLME callback frame lengths before access Greg Kroah-Hartman
` (734 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit fbe0bb2b75eb3c61e8464486506253d1b471240b ]
sid_to_id() currently treats the last subauthority of any owner or group
SID as a Unix uid or gid. For example, this maps Everyone (S-1-1-0) to
uid 0 and BUILTIN\Users (S-1-5-32-545) to gid 545.
When an SMB2 CREATE security descriptor contains those SIDs, ksmbd
attempts to change the newly created file to the bogus Unix ownership.
notify_change() then returns -EPERM, which makes smb2.create.aclfile fail
with NT_STATUS_SHARING_VIOLATION.
Validate the SID prefix before extracting its RID. Only server-domain
owner SIDs and S-1-22-2 Unix group SIDs have local ID representations.
Treat other valid Windows SIDs as unmapped so their original values can
still be preserved in the NT ACL xattr.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smbacl.c | 21 +++++++++++++++++----
1 file changed, 17 insertions(+), 4 deletions(-)
diff --git a/fs/smb/server/smbacl.c b/fs/smb/server/smbacl.c
index 17987e83bdd87..051df6536f7a3 100644
--- a/fs/smb/server/smbacl.c
+++ b/fs/smb/server/smbacl.c
@@ -258,6 +258,7 @@ static int sid_to_id(struct user_namespace *user_ns,
struct smb_sid *psid, uint sidtype,
struct smb_fattr *fattr)
{
+ const struct smb_sid *sid_prefix;
int rc = -EINVAL;
/*
@@ -279,6 +280,12 @@ static int sid_to_id(struct user_namespace *user_ns,
kuid_t uid;
uid_t id;
+ /* Only the server domain RID has a local uid representation. */
+ sid_prefix = &server_conf.domain_sid;
+ if (psid->num_subauth != sid_prefix->num_subauth + 1 ||
+ compare_sids(psid, sid_prefix))
+ return -EINVAL;
+
id = le32_to_cpu(psid->sub_auth[psid->num_subauth - 1]);
uid = KUIDT_INIT(id);
uid = from_vfsuid(user_ns, &init_user_ns, VFSUIDT_INIT(uid));
@@ -290,6 +297,12 @@ static int sid_to_id(struct user_namespace *user_ns,
kgid_t gid;
gid_t id;
+ /* Local gids are represented by S-1-22-2-<gid>. */
+ sid_prefix = &sid_unix_groups;
+ if (psid->num_subauth != sid_prefix->num_subauth + 1 ||
+ compare_sids(psid, sid_prefix))
+ return -EINVAL;
+
id = le32_to_cpu(psid->sub_auth[psid->num_subauth - 1]);
gid = KGIDT_INIT(id);
gid = from_vfsgid(user_ns, &init_user_ns, VFSGIDT_INIT(gid));
@@ -900,9 +913,9 @@ int parse_sec_desc(struct user_namespace *user_ns, struct smb_ntsd *pntsd,
rc = sid_to_id(user_ns, owner_sid_ptr, SIDOWNER, fattr);
if (rc) {
- pr_err("%s: Error %d mapping Owner SID to uid\n",
- __func__, rc);
+ ksmbd_debug(SMB, "Owner SID has no Unix uid mapping\n");
owner_sid_ptr = NULL;
+ rc = 0;
}
}
@@ -918,9 +931,9 @@ int parse_sec_desc(struct user_namespace *user_ns, struct smb_ntsd *pntsd,
}
rc = sid_to_id(user_ns, group_sid_ptr, SIDUNIX_GROUP, fattr);
if (rc) {
- pr_err("%s: Error %d mapping Group SID to gid\n",
- __func__, rc);
+ ksmbd_debug(SMB, "Group SID has no Unix gid mapping\n");
group_sid_ptr = NULL;
+ rc = 0;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 255/982] wifi: cfg80211: validate rx/tx MLME callback frame lengths before access
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (253 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 254/982] ksmbd: validate SID namespace before mapping IDs Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 256/982] gpio: dwapb: Mask interrupts at hardware initialization Greg Kroah-Hartman
` (733 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit d5e4586546974179feca305a94e07fac3e9727fe ]
cfg80211_rx_mlme_mgmt() and cfg80211_tx_mlme_mgmt() call tracepoints
before rejecting frames shorter than the frame-control field. After
that, they only require len >= 2 before dispatching into subtype
handlers that assume their fixed fields are present.
The frames that trip this are not shorter than 2 bytes; they are short
relative to their subtype. mwifiex is a concrete in-tree example on the
length side: mwifiex_process_mgmt_packet() only requires a 4-address
ieee80211_hdr plus the 2-byte firmware length prefix before handing the
frame to cfg80211_rx_mlme_mgmt(). After stripping the length prefix and
removing addr4, pkt_len can be exactly 24: a bare 3-address management
header with no reason-code body. The existing WARN_ON(len < 2) does not
fire on such a frame, and cfg80211_process_deauth() then reads
u.deauth.reason_code as a two-byte access starting at offset 24,
immediately past the 24-byte buffer.
Add a frame-control length gate, then validate each subtype's minimum
frame size in an if/else-if chain that mirrors the dispatch logic. Trace
only after the frame is known to be well-formed.
Side effects of this change:
- The WARN_ON(len < 2) is dropped. It only guarded the frame_control
read, never the subtype fixed fields, and it does not fire on the
frames that actually trigger the out-of-bounds read (which are >= 2).
The len >= 2 check is kept as the guard before dereferencing
frame_control, but without the warning: these are exported callbacks
and a malformed frame from a driver should be dropped silently rather
than backtraced.
- cfg80211_tx_mlme_mgmt() previously routed every non-deauth subtype
through disassociation handling; it now silently ignores unrecognised
subtypes.
Assisted-by: Codex:gpt-5.5
Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260707025336.22557-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/mlme.c | 45 +++++++++++++++++++++++++++++++++++++--------
1 file changed, 37 insertions(+), 8 deletions(-)
diff --git a/net/wireless/mlme.c b/net/wireless/mlme.c
index 4ba97fdbf724d..3cc0026f378be 100644
--- a/net/wireless/mlme.c
+++ b/net/wireless/mlme.c
@@ -158,19 +158,35 @@ void cfg80211_rx_mlme_mgmt(struct net_device *dev, const u8 *buf, size_t len)
{
struct wireless_dev *wdev = dev->ieee80211_ptr;
struct ieee80211_mgmt *mgmt = (void *)buf;
+ __le16 fc;
ASSERT_WDEV_LOCK(wdev);
- trace_cfg80211_rx_mlme_mgmt(dev, buf, len);
+ if (len < sizeof(fc))
+ return;
+
+ fc = mgmt->frame_control;
- if (WARN_ON(len < 2))
+ if (ieee80211_is_auth(fc)) {
+ if (len < offsetofend(struct ieee80211_mgmt, u.auth.status_code))
+ return;
+ } else if (ieee80211_is_deauth(fc)) {
+ if (len < offsetofend(struct ieee80211_mgmt, u.deauth.reason_code))
+ return;
+ } else if (ieee80211_is_disassoc(fc)) {
+ if (len < offsetofend(struct ieee80211_mgmt, u.disassoc.reason_code))
+ return;
+ } else {
return;
+ }
+
+ trace_cfg80211_rx_mlme_mgmt(dev, buf, len);
- if (ieee80211_is_auth(mgmt->frame_control))
+ if (ieee80211_is_auth(fc))
cfg80211_process_auth(wdev, buf, len);
- else if (ieee80211_is_deauth(mgmt->frame_control))
+ else if (ieee80211_is_deauth(fc))
cfg80211_process_deauth(wdev, buf, len, false);
- else if (ieee80211_is_disassoc(mgmt->frame_control))
+ else
cfg80211_process_disassoc(wdev, buf, len, false);
}
EXPORT_SYMBOL(cfg80211_rx_mlme_mgmt);
@@ -223,15 +239,28 @@ void cfg80211_tx_mlme_mgmt(struct net_device *dev, const u8 *buf, size_t len,
{
struct wireless_dev *wdev = dev->ieee80211_ptr;
struct ieee80211_mgmt *mgmt = (void *)buf;
+ __le16 fc;
ASSERT_WDEV_LOCK(wdev);
- trace_cfg80211_tx_mlme_mgmt(dev, buf, len, reconnect);
+ if (len < sizeof(fc))
+ return;
- if (WARN_ON(len < 2))
+ fc = mgmt->frame_control;
+
+ if (ieee80211_is_deauth(fc)) {
+ if (len < offsetofend(struct ieee80211_mgmt, u.deauth.reason_code))
+ return;
+ } else if (ieee80211_is_disassoc(fc)) {
+ if (len < offsetofend(struct ieee80211_mgmt, u.disassoc.reason_code))
+ return;
+ } else {
return;
+ }
+
+ trace_cfg80211_tx_mlme_mgmt(dev, buf, len, reconnect);
- if (ieee80211_is_deauth(mgmt->frame_control))
+ if (ieee80211_is_deauth(fc))
cfg80211_process_deauth(wdev, buf, len, reconnect);
else
cfg80211_process_disassoc(wdev, buf, len, reconnect);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 256/982] gpio: dwapb: Mask interrupts at hardware initialization
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (254 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 255/982] wifi: cfg80211: validate rx/tx MLME callback frame lengths before access Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 257/982] wifi: libipw: fix key index receive bound checks Greg Kroah-Hartman
` (732 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Liang Hao, Bartosz Golaszewski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liang Hao <haohlliang@gmail.com>
[ Upstream commit aaf7766ba3b99a3834319e7cf939838afc705574 ]
GPIO interrupts may retain stale state across warm reboots when
peripherals remain powered. If a GPIO line is not explicitly
configured for interrupts, this can result in interrupt storms
due to missing handlers.
Fix this by ensuring all interrupts are masked and disabled at
hardware initialization time via the init_hw() callback. Pending
interrupts are also cleared to start from a known-safe state.
Interrupts will be unmasked only when explicitly configured by
userspace or kernel drivers.
Signed-off-by: Liang Hao <haohlliang@gmail.com>
Link: https://patch.msgid.link/20260705074759.47863-1-haohlliang@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-dwapb.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/gpio/gpio-dwapb.c b/drivers/gpio/gpio-dwapb.c
index 6b7d47a52b10a..8c07776725dda 100644
--- a/drivers/gpio/gpio-dwapb.c
+++ b/drivers/gpio/gpio-dwapb.c
@@ -200,6 +200,22 @@ static void dwapb_toggle_trigger(struct dwapb_gpio *gpio, unsigned int offs)
dwapb_write(gpio, GPIO_INT_POLARITY, pol);
}
+static int dwapb_irq_init_hw(struct gpio_chip *gc)
+{
+ struct dwapb_gpio *gpio = to_dwapb_gpio(gc);
+
+ /*
+ * GPIO interrupts may retain stale state across warm reboots when
+ * peripherals stay powered. Force a known-safe state before the GPIO
+ * irqchip and irq domain are set up.
+ */
+ dwapb_write(gpio, GPIO_INTEN, 0);
+ dwapb_write(gpio, GPIO_INTMASK, 0xffffffff);
+ dwapb_write(gpio, GPIO_PORTA_EOI, 0xffffffff);
+
+ return 0;
+}
+
static u32 dwapb_do_irq(struct dwapb_gpio *gpio)
{
struct gpio_chip *gc = &gpio->ports[0].gc;
@@ -461,6 +477,7 @@ static void dwapb_configure_irqs(struct dwapb_gpio *gpio,
girq = &gc->irq;
girq->handler = handle_bad_irq;
girq->default_type = IRQ_TYPE_NONE;
+ girq->init_hw = dwapb_irq_init_hw;
port->pirq = pirq;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 257/982] wifi: libipw: fix key index receive bound checks
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (255 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 256/982] gpio: dwapb: Mask interrupts at hardware initialization Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 258/982] netfilter: ipset: mark the rcu locked areas properly Greg Kroah-Hartman
` (731 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 74ed3669f26803b1761c1f55403062bea44c3466 ]
libipw_rx() reads skb->data[hdrlen + 3] to extract the WEP key index in
both the software-decrypt key selection path and the hardware-decrypted
IV/ICV strip path. In both places the existing guard only checks
skb->len >= hdrlen + 3, which proves bytes up to hdrlen + 2 but not the
byte at hdrlen + 3.
Require hdrlen + 4 bytes before reading that item in both paths. This is
a local source-boundary check only; it does not change the key index
semantics.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260705083519.23567-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 9a97ab9b89ae8..2220a9814c8a6 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -417,7 +417,7 @@ int libipw_rx(struct libipw_device *ieee, struct sk_buff *skb,
ieee->host_mc_decrypt : ieee->host_decrypt;
if (can_be_decrypted) {
- if (skb->len >= hdrlen + 3) {
+ if (skb->len >= hdrlen + 4) {
/* Top two-bits of byte 3 are the key index */
keyidx = skb->data[hdrlen + 3] >> 6;
}
@@ -663,7 +663,7 @@ int libipw_rx(struct libipw_device *ieee, struct sk_buff *skb,
int trimlen = 0;
/* Top two-bits of byte 3 are the key index */
- if (skb->len >= hdrlen + 3)
+ if (skb->len >= hdrlen + 4)
keyidx = skb->data[hdrlen + 3] >> 6;
/* To strip off any security data which appears before the
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 258/982] netfilter: ipset: mark the rcu locked areas properly
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (256 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 257/982] wifi: libipw: fix key index receive bound checks Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 259/982] wifi: rsi: validate beacon length before fixed buffer copy Greg Kroah-Hartman
` (730 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jozsef Kadlecsik, Florian Westphal,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jozsef Kadlecsik <kadlec@netfilter.org>
[ Upstream commit 5d0c22e73656d050daffad10a2ba8765ce8441c8 ]
When we bump the uref counter, there's no need to keep
the rcu lock because the referred hash table can't
disappear. Also, from the same reason in mtype_gc we
need the rcu lock and not a spinlock.
Signed-off-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/ipset/ip_set_hash_gen.h | 13 +++++--------
1 file changed, 5 insertions(+), 8 deletions(-)
diff --git a/net/netfilter/ipset/ip_set_hash_gen.h b/net/netfilter/ipset/ip_set_hash_gen.h
index 6588571648ead..a4ec28b223c4d 100644
--- a/net/netfilter/ipset/ip_set_hash_gen.h
+++ b/net/netfilter/ipset/ip_set_hash_gen.h
@@ -556,9 +556,10 @@ mtype_gc(struct work_struct *work)
set = gc->set;
h = set->data;
- spin_lock_bh(&set->lock);
- t = ipset_dereference_set(h->table, set);
+ rcu_read_lock_bh();
+ t = rcu_dereference_bh(h->table);
atomic_inc(&t->uref);
+ rcu_read_unlock_bh();
numof_locks = ahash_numof_locks(t->htable_bits);
r = gc->region++;
if (r >= numof_locks) {
@@ -567,7 +568,6 @@ mtype_gc(struct work_struct *work)
next_run = (IPSET_GC_PERIOD(set->timeout) * HZ) / numof_locks;
if (next_run < HZ/10)
next_run = HZ/10;
- spin_unlock_bh(&set->lock);
mtype_gc_do(set, h, t, r);
@@ -847,15 +847,13 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
key = HKEY(value, h->initval, t->htable_bits);
r = ahash_region(key);
atomic_inc(&t->uref);
+ rcu_read_unlock_bh();
elements = t->hregion[r].elements;
maxelem = t->maxelem;
if (elements >= maxelem) {
u32 e;
- if (SET_WITH_TIMEOUT(set)) {
- rcu_read_unlock_bh();
+ if (SET_WITH_TIMEOUT(set))
mtype_gc_do(set, h, t, r);
- rcu_read_lock_bh();
- }
maxelem = h->maxelem;
elements = 0;
for (e = 0; e < ahash_numof_locks(t->htable_bits); e++)
@@ -863,7 +861,6 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
if (elements >= maxelem && SET_WITH_FORCEADD(set))
forceadd = true;
}
- rcu_read_unlock_bh();
spin_lock_bh(&t->hregion[r].lock);
n = rcu_dereference_bh(hbucket(t, key));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 259/982] wifi: rsi: validate beacon length before fixed buffer copy
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (257 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 258/982] netfilter: ipset: mark the rcu locked areas properly Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 260/982] ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series Greg Kroah-Hartman
` (729 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 8ecdeb8b8a33b22c597299043c0dcfce50beb9ea ]
rsi_prepare_beacon() copies the mac80211 beacon frame after
FRAME_DESC_SZ into a management skb whose usable tailroom may be smaller
than MAX_MGMT_PKT_SIZE after alignment.
Validate the beacon length against the actual tailroom before the copy
and skb_put(). Leave ownership of the management skb with the caller on
error, matching the existing rsi_send_beacon() cleanup path.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260705084824.68105-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/rsi/rsi_91x_hal.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/wireless/rsi/rsi_91x_hal.c b/drivers/net/wireless/rsi/rsi_91x_hal.c
index c7460fbba0142..389de0bc25608 100644
--- a/drivers/net/wireless/rsi/rsi_91x_hal.c
+++ b/drivers/net/wireless/rsi/rsi_91x_hal.c
@@ -431,6 +431,7 @@ int rsi_prepare_beacon(struct rsi_common *common, struct sk_buff *skb)
struct ieee80211_vif *vif;
struct sk_buff *mac_bcn;
u8 vap_id = 0, i;
+ unsigned int tailroom;
u16 tim_offset = 0;
for (i = 0; i < RSI_MAX_VIFS; i++) {
@@ -480,6 +481,13 @@ int rsi_prepare_beacon(struct rsi_common *common, struct sk_buff *skb)
if (mac_bcn->data[tim_offset + 2] == 0)
bcn_frm->frame_info |= cpu_to_le16(RSI_DATA_DESC_DTIM_BEACON);
+ tailroom = skb_tailroom(skb);
+ if (tailroom < FRAME_DESC_SZ ||
+ mac_bcn->len > tailroom - FRAME_DESC_SZ) {
+ dev_kfree_skb(mac_bcn);
+ return -EMSGSIZE;
+ }
+
memcpy(&skb->data[FRAME_DESC_SZ], mac_bcn->data, mac_bcn->len);
skb_put(skb, mac_bcn->len + FRAME_DESC_SZ);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 260/982] ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (258 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 259/982] wifi: rsi: validate beacon length before fixed buffer copy Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 261/982] btrfs: only account delalloc bytes for regular file inodes in btrfs_getattr() Greg Kroah-Hartman
` (728 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Bowen, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Bowen <hicbowen@gmail.com>
[ Upstream commit 9064637fb2a80b43105900a47d414997630e5b6b ]
The internal speakers on the MECHREVO WUJIE Series are silent,
while the headphone output works correctly.
The BIOS reports NID 0x1b on the Realtek ALC233 codec as
unconnected with pin configuration 0x411111f0. However, the pin
is connected to an internal speaker.
Overriding NID 0x1b with 0x90170150 makes the HDA generic parser
detect both 0x14 and 0x1b as speaker outputs and restores internal
speaker playback.
Add a pin configuration fixup for the affected PCI SSID c011:1d05.
Tested on a MECHREVO WUJIE Series laptop with board
WUJIE Series-Lark4-LNL and firmware EM_LNL326_V1.0.23.
Signed-off-by: Chen Bowen <hicbowen@gmail.com>
Link: https://patch.msgid.link/20260710133409.16641-1-hicbowen@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_realtek.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 5ff2e113054fe..e79eb082810d7 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -7378,6 +7378,7 @@ enum {
ALC275_FIXUP_DELL_XPS,
ALC293_FIXUP_LENOVO_SPK_NOISE,
ALC233_FIXUP_LENOVO_LINE2_MIC_HOTKEY,
+ ALC233_FIXUP_WUJIE_SPEAKERS,
ALC233_FIXUP_LENOVO_L2MH_LOW_ENLED,
ALC255_FIXUP_DELL_SPK_NOISE,
ALC225_FIXUP_DISABLE_MIC_VREF,
@@ -7561,6 +7562,13 @@ static void alc298_fixup_lenovo_c940_duet7(struct hda_codec *codec,
}
static const struct hda_fixup alc269_fixups[] = {
+ [ALC233_FIXUP_WUJIE_SPEAKERS] = {
+ .type = HDA_FIXUP_PINS,
+ .v.pins = (const struct hda_pintbl[]) {
+ { 0x1b, 0x90170150 }, /* internal speaker */
+ { }
+ },
+ },
[ALC269_FIXUP_GPIO2] = {
.type = HDA_FIXUP_FUNC,
.v.func = alc_fixup_gpio2,
@@ -10473,6 +10481,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x8086, 0x2080, "Intel NUC 8 Rugged", ALC256_FIXUP_INTEL_NUC8_RUGGED),
SND_PCI_QUIRK(0x8086, 0x2081, "Intel NUC 10", ALC256_FIXUP_INTEL_NUC10),
SND_PCI_QUIRK(0x8086, 0x3038, "Intel NUC 13", ALC295_FIXUP_CHROME_BOOK),
+ SND_PCI_QUIRK(0xc011, 0x1d05, "MECHREVO WUJIE Series", ALC233_FIXUP_WUJIE_SPEAKERS),
SND_PCI_QUIRK(0xf111, 0x0001, "Framework Laptop", ALC295_FIXUP_FRAMEWORK_LAPTOP_MIC_NO_PRESENCE),
SND_PCI_QUIRK(0xf111, 0x0006, "Framework Laptop", ALC295_FIXUP_FRAMEWORK_LAPTOP_MIC_NO_PRESENCE),
SND_PCI_QUIRK(0xf111, 0x0009, "Framework Laptop", ALC295_FIXUP_FRAMEWORK_LAPTOP_MIC_NO_PRESENCE),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 261/982] btrfs: only account delalloc bytes for regular file inodes in btrfs_getattr()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (259 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 260/982] ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 262/982] btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() Greg Kroah-Hartman
` (727 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Filipe Manana, Dave Chen,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Chen <davechen@synology.com>
[ Upstream commit 9411aafdf352b8d72668732af5a37dcb27383e25 ]
btrfs_getattr() unconditionally reads BTRFS_I(inode)->new_delalloc_bytes
and adds it (sector-aligned) to stat->blocks for every inode type.
However, new_delalloc_bytes lives in a union with last_dir_index_offset:
union {
u64 new_delalloc_bytes; /* files only */
u64 last_dir_index_offset; /* directories only */
};
For a directory inode this memory holds last_dir_index_offset, which is
set during directory logging (e.g. flush_dir_items_batch()) to the
offset of the last logged BTRFS_DIR_INDEX_KEY. That offset grows with
the number of entries ever created in the directory (dir indexes are
monotonic and never reused), so it can be arbitrarily large.
As a result, after a directory has been logged (e.g. via an fsync that
triggers directory logging), btrfs_getattr() reports inflated st_blocks
for that directory. The inflation is purely in-core and disappears
after the inode is evicted and reloaded (btrfs_alloc_inode() zeroes the
union), e.g. after a remount.
Reproducer (on a btrfs filesystem):
D=/mnt/btrfs/d
mkdir -p $D
for i in $(seq 1 20000); do touch $D/f$i; done
sync # commit, push dir index high
touch $D/trigger # dirty the dir in a new transaction
xfs_io -c fsync $D # log the directory -> sets last_dir_index_offset
stat -c '%b' $D # st_blocks is now inflated (e.g. 40)
# umount + mount -> st_blocks drops back to the correct value
The evict path already knows this union is type-dependent and guards the
corresponding WARN_ON with !S_ISDIR() in btrfs_destroy_inode(); only
btrfs_getattr() was missing the equivalent check.
Only read new_delalloc_bytes for regular files, which are the only
inodes that ever set it.
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Dave Chen <davechen@synology.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
index b2a1d96a806a9..e53b42a047e8b 100644
--- a/fs/btrfs/inode.c
+++ b/fs/btrfs/inode.c
@@ -9275,7 +9275,8 @@ static int btrfs_getattr(struct user_namespace *mnt_userns,
stat->dev = BTRFS_I(inode)->root->anon_dev;
spin_lock(&BTRFS_I(inode)->lock);
- delalloc_bytes = BTRFS_I(inode)->new_delalloc_bytes;
+ delalloc_bytes = S_ISREG(inode->i_mode) ?
+ BTRFS_I(inode)->new_delalloc_bytes : 0;
inode_bytes = inode_get_bytes(inode);
spin_unlock(&BTRFS_I(inode)->lock);
stat->blocks = (ALIGN(inode_bytes, blocksize) +
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 262/982] btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (260 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 261/982] btrfs: only account delalloc bytes for regular file inodes in btrfs_getattr() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 263/982] spi: dw-dma: Wait for controller idle before completing Tx Greg Kroah-Hartman
` (726 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b3d472d13f9d7bf20669,
Qu Wenruo, Filipe Manana, David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit 83201804efa4a5168be754e1dfc9b2faee760cac ]
If during relocation we fail in insert_dirty_subvol() because
btrfs_update_reloc_root() returned an error, we will leave a root's
reloc_root field pointing to a reloc root that was freed instead of NULL,
resulting later in a use-after-free, or double free attempt during
unmount.
The sequence of steps is this:
1) During relocation the call to btrfs_update_reloc_root() in
insert_dirty_subvol() fails, so insert_dirty_subvol() returns the
error to merge_reloc_root() without adding the root to the list
rc->dirty_subvol_roots;
2) Then merge_reloc_root() aborts the current transaction because
insert_dirty_subvol() returned an error;
3) Up the call chain, merge_reloc_roots() gets the error, adds the
reloc root for root X to the local reloc_roots list and jumps to the
'out' label, where it calls free_reloc_roots() to free all the reloc
roots in the local reloc_roots list. This frees the reloc root for
root X;
4) We go up the call chain to relocate_block_group() which calls
clean_dirty_subvols() to go over dirty roots and set their
->reloc_root field to NULL, but root X is not in the dirty_subvol_roots
list, so its ->reloc_root still points to a reloc root;
5) Relocation finishes, with an error and a transaction abort, but the
->reloc_root field for root X still points to the reloc root that was
freed in step 3;
6) When unmounting the fs we end up calling:
btrfs_free_fs_roots()
btrfs_drop_and_free_fs_root()
--> calls btrfs_put_root() against root X's ->reloc_root
which is not NULL and points to the already freed
reloc root in step 4 above
Resulting in a use-after-free to a double free attempt.
Syzbot reported this with the following dmesg/syslog:
[ 106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)
[ 106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure
[ 106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5
[ 106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.
[ 106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0
[ 106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure
[ 106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly
[ 106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure
[ 106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1
[ 106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30
[ 106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30
[ 106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409
[ 106.682946][ T5338] ==================================================================
[ 106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250
[ 106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338
[ 106.693173][ T5338]
[ 106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
[ 106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 106.694300][ T5338] Call Trace:
[ 106.694308][ T5338] <TASK>
[ 106.694314][ T5338] dump_stack_lvl+0xe8/0x150
[ 106.694331][ T5338] print_address_description+0x55/0x1e0
[ 106.694343][ T5338] ? btrfs_put_root+0x2f/0x250
[ 106.694358][ T5338] print_report+0x58/0x70
[ 106.694368][ T5338] kasan_report+0x117/0x150
[ 106.694384][ T5338] ? btrfs_put_root+0x2f/0x250
[ 106.694399][ T5338] kasan_check_range+0x264/0x2c0
[ 106.694416][ T5338] btrfs_put_root+0x2f/0x250
[ 106.694430][ T5338] btrfs_drop_and_free_fs_root+0x160/0x210
[ 106.694447][ T5338] btrfs_free_fs_roots+0x2f9/0x3c0
[ 106.694464][ T5338] ? __pfx_btrfs_free_fs_roots+0x10/0x10
[ 106.694479][ T5338] ? free_root_pointers+0x5bf/0x5f0
[ 106.694494][ T5338] close_ctree+0x798/0x12d0
[ 106.694511][ T5338] ? __pfx_close_ctree+0x10/0x10
[ 106.694526][ T5338] ? _raw_spin_unlock_irqrestore+0x74/0x80
[ 106.694599][ T5338] ? rcu_preempt_deferred_qs_irqrestore+0x906/0xbc0
[ 106.694620][ T5338] ? __rcu_read_unlock+0x83/0xe0
[ 106.694636][ T5338] ? btrfs_put_super+0x48/0x1c0
[ 106.694652][ T5338] ? __pfx_btrfs_put_super+0x10/0x10
[ 106.694667][ T5338] generic_shutdown_super+0x13d/0x2d0
[ 106.694682][ T5338] kill_anon_super+0x3b/0x70
[ 106.694695][ T5338] btrfs_kill_super+0x41/0x50
[ 106.694710][ T5338] deactivate_locked_super+0xbc/0x130
[ 106.694722][ T5338] cleanup_mnt+0x437/0x4d0
[ 106.694736][ T5338] ? _raw_spin_unlock_irq+0x23/0x50
[ 106.694752][ T5338] task_work_run+0x1d9/0x270
[ 106.694769][ T5338] ? __pfx_task_work_run+0x10/0x10
[ 106.694784][ T5338] ? do_raw_spin_unlock+0x4d/0x210
[ 106.694802][ T5338] do_exit+0x70f/0x22c0
[ 106.694817][ T5338] ? trace_irq_disable+0x3b/0x140
[ 106.694835][ T5338] ? __pfx_do_exit+0x10/0x10
[ 106.694848][ T5338] ? preempt_schedule_thunk+0x16/0x30
[ 106.694863][ T5338] ? preempt_schedule_common+0x82/0xd0
[ 106.694878][ T5338] ? preempt_schedule_thunk+0x16/0x30
[ 106.694892][ T5338] do_group_exit+0x21b/0x2d0
[ 106.694906][ T5338] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 106.694918][ T5338] __x64_sys_exit_group+0x3f/0x40
[ 106.694932][ T5338] x64_sys_call+0x221a/0x2240
[ 106.694944][ T5338] do_syscall_64+0x174/0x580
[ 106.694954][ T5338] ? clear_bhb_loop+0x40/0x90
[ 106.694967][ T5338] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 106.694978][ T5338] RIP: 0033:0x7f958ef9ce59
[ 106.694988][ T5338] Code: Unable to access opcode bytes at 0x7f958ef9ce2f.
[ 106.694994][ T5338] RSP: 002b:00007fffd4058318 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
[ 106.695008][ T5338] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f958ef9ce59
[ 106.695015][ T5338] RDX: 00007f958c3f8000 RSI: 0000000000000000 RDI: 0000000000000000
[ 106.695022][ T5338] RBP: 0000000000000003 R08: 0000000000000000 R09: 00007f958f1e73e0
[ 106.695028][ T5338] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
[ 106.695034][ T5338] R13: 00007f958f1e73e0 R14: 0000000000000003 R15: 00007fffd40583d0
[ 106.695046][ T5338] </TASK>
[ 106.695050][ T5338]
[ 106.821635][ T5338] Allocated by task 1061:
[ 106.823446][ T5338] kasan_save_track+0x3e/0x80
[ 106.825498][ T5338] __kasan_kmalloc+0x93/0xb0
[ 106.827381][ T5338] __kmalloc_cache_noprof+0x31c/0x660
[ 106.829525][ T5338] btrfs_alloc_root+0x75/0x930
[ 106.831458][ T5338] read_tree_root_path+0x127/0xb00
[ 106.833556][ T5338] btrfs_read_tree_root+0x34/0x60
[ 106.835553][ T5338] create_reloc_root+0x6b3/0xcb0
[ 106.837556][ T5338] btrfs_init_reloc_root+0x2ec/0x4b0
[ 106.839557][ T5338] record_root_in_trans+0x2ab/0x350
[ 106.841685][ T5338] btrfs_record_root_in_trans+0x15c/0x180
[ 106.844237][ T5338] start_transaction+0x39c/0x1820
[ 106.846638][ T5338] btrfs_finish_one_ordered+0x88e/0x2680
[ 106.849436][ T5338] btrfs_work_helper+0x37b/0xc20
[ 106.851549][ T5338] process_scheduled_works+0xb5d/0x1860
[ 106.853807][ T5338] worker_thread+0xa53/0xfc0
[ 106.855773][ T5338] kthread+0x389/0x470
[ 106.857548][ T5338] ret_from_fork+0x514/0xb70
[ 106.859493][ T5338] ret_from_fork_asm+0x1a/0x30
[ 106.861504][ T5338]
[ 106.862527][ T5338] Freed by task 5339:
[ 106.864224][ T5338] kasan_save_track+0x3e/0x80
[ 106.866180][ T5338] kasan_save_free_info+0x46/0x50
[ 106.868371][ T5338] __kasan_slab_free+0x5c/0x80
[ 106.870462][ T5338] kfree+0x1c5/0x640
[ 106.872180][ T5338] __del_reloc_root+0x341/0x3b0
[ 106.874290][ T5338] free_reloc_roots+0x5f/0x90
[ 106.876282][ T5338] merge_reloc_roots+0x73f/0x8a0
[ 106.878489][ T5338] relocate_block_group+0xbcc/0xe70
[ 106.880742][ T5338] do_nonremap_reloc+0xa8/0x5b0
[ 106.882885][ T5338] btrfs_relocate_block_group+0x7e6/0xc40
[ 106.885336][ T5338] btrfs_relocate_chunk+0x115/0x820
[ 106.887502][ T5338] __btrfs_balance+0x1db0/0x2ae0
[ 106.889543][ T5338] btrfs_balance+0xaf3/0x11b0
[ 106.891456][ T5338] btrfs_ioctl_balance+0x3d3/0x610
[ 106.893672][ T5338] __se_sys_ioctl+0xfc/0x170
[ 106.895530][ T5338] do_syscall_64+0x174/0x580
[ 106.897518][ T5338] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 106.900101][ T5338]
[ 106.901123][ T5338] The buggy address belongs to the object at ffff88803f978000
[ 106.901123][ T5338] which belongs to the cache kmalloc-4k of size 4096
[ 106.906907][ T5338] The buggy address is located 1584 bytes inside of
[ 106.906907][ T5338] freed 4096-byte region [ffff88803f978000, ffff88803f979000)
[ 106.912980][ T5338]
[ 106.914022][ T5338] The buggy address belongs to the physical page:
[ 106.916716][ T5338] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x3f978
[ 106.920390][ T5338] head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 106.923834][ T5338] flags: 0x4fff00000000040(head|node=1|zone=1|lastcpupid=0x7ff)
[ 106.927104][ T5338] page_type: f5(slab)
[ 106.928898][ T5338] raw: 04fff00000000040 ffff88801ac42140 dead000000000122 0000000000000000
[ 106.932507][ T5338] raw: 0000000000000000 0000000800040004 00000000f5000000 0000000000000000
[ 106.936193][ T5338] head: 04fff00000000040 ffff88801ac42140 dead000000000122 0000000000000000
[ 106.939856][ T5338] head: 0000000000000000 0000000800040004 00000000f5000000 0000000000000000
[ 106.943601][ T5338] head: 04fff00000000003 fffffffffffffe01 00000000ffffffff 00000000ffffffff
[ 106.947268][ T5338] head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000008
[ 106.950988][ T5338] page dumped because: kasan: bad access detected
[ 106.953710][ T5338] page_owner tracks the page as allocated
[ 106.956198][ T5338] page last allocated via order 3, migratetype Unmovable, gfp_mask 0xd2820(GFP_ATOMIC|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 24, tgid 24 (kworker/u4:2), ts 105728970387, free_ts 29540875453
[ 106.964984][ T5338] post_alloc_hook+0x22d/0x280
[ 106.966956][ T5338] get_page_from_freelist+0x2593/0x2610
[ 106.969307][ T5338] __alloc_frozen_pages_noprof+0x18d/0x380
[ 106.971839][ T5338] allocate_slab+0x77/0x660
[ 106.973709][ T5338] refill_objects+0x339/0x3d0
[ 106.975696][ T5338] __pcs_replace_empty_main+0x321/0x720
[ 106.978136][ T5338] __kmalloc_node_track_caller_noprof+0x572/0x7b0
[ 106.981009][ T5338] __alloc_skb+0x2c1/0x7d0
[ 106.982983][ T5338] nsim_dev_trap_report_work+0x29a/0xb90
[ 106.985356][ T5338] process_scheduled_works+0xb5d/0x1860
[ 106.987710][ T5338] worker_thread+0xa53/0xfc0
[ 106.989847][ T5338] kthread+0x389/0x470
[ 106.991727][ T5338] ret_from_fork+0x514/0xb70
[ 106.993722][ T5338] ret_from_fork_asm+0x1a/0x30
[ 106.995900][ T5338] page last free pid 77 tgid 77 stack trace:
[ 106.998479][ T5338] __free_frozen_pages+0xc1c/0xd30
[ 107.000819][ T5338] vfree+0x1d1/0x2f0
[ 107.002631][ T5338] delayed_vfree_work+0x55/0x80
[ 107.004848][ T5338] process_scheduled_works+0xb5d/0x1860
[ 107.007366][ T5338] worker_thread+0xa53/0xfc0
[ 107.009388][ T5338] kthread+0x389/0x470
[ 107.011177][ T5338] ret_from_fork+0x514/0xb70
[ 107.013313][ T5338] ret_from_fork_asm+0x1a/0x30
[ 107.015454][ T5338]
[ 107.016460][ T5338] Memory state around the buggy address:
[ 107.019052][ T5338] ffff88803f978500: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 107.022691][ T5338] ffff88803f978580: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 107.026264][ T5338] >ffff88803f978600: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 107.029721][ T5338] ^
[ 107.032062][ T5338] ffff88803f978680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 107.035547][ T5338] ffff88803f978700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 107.038865][ T5338] ==================================================================
Fix this by resetting a root's ->reloc_root if we get an error while
trying to merge a reloc root.
Reported-by: syzbot+b3d472d13f9d7bf20669@syzkaller.appspotmail.com
Link: https://lore.kernel.org/linux-btrfs/6a1ebde9.c1435f33.112120.0176.GAE@google.com/
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/relocation.c | 42 +++++++++++++++++++++++++++++++++---------
1 file changed, 33 insertions(+), 9 deletions(-)
diff --git a/fs/btrfs/relocation.c b/fs/btrfs/relocation.c
index d37904a806d6a..ffd1319a9155d 100644
--- a/fs/btrfs/relocation.c
+++ b/fs/btrfs/relocation.c
@@ -1644,6 +1644,17 @@ static int insert_dirty_subvol(struct btrfs_trans_handle *trans,
return 0;
}
+static void clear_reloc_root(struct btrfs_root *root)
+{
+ root->reloc_root = NULL;
+ /*
+ * Need barrier to ensure clear_bit() only happens after
+ * root->reloc_root = NULL. Pairs with have_reloc_root().
+ */
+ smp_wmb();
+ clear_bit(BTRFS_ROOT_DEAD_RELOC_TREE, &root->state);
+}
+
static int clean_dirty_subvols(struct reloc_control *rc)
{
struct btrfs_root *root;
@@ -1658,13 +1669,7 @@ static int clean_dirty_subvols(struct reloc_control *rc)
struct btrfs_root *reloc_root = root->reloc_root;
list_del_init(&root->reloc_dirty_list);
- root->reloc_root = NULL;
- /*
- * Need barrier to ensure clear_bit() only happens after
- * root->reloc_root = NULL. Pairs with have_reloc_root.
- */
- smp_wmb();
- clear_bit(BTRFS_ROOT_DEAD_RELOC_TREE, &root->state);
+ clear_reloc_root(root);
if (reloc_root) {
/*
* btrfs_drop_snapshot drops our ref we hold for
@@ -2050,13 +2055,32 @@ void merge_reloc_roots(struct reloc_control *rc)
goto out;
}
ret = merge_reloc_root(rc, root);
- btrfs_put_root(root);
if (ret) {
- if (list_empty(&reloc_root->root_list))
+ /*
+ * Clear the reloc root since below we will call
+ * free_reloc_roots(), otherwise we leave
+ * root->reloc_root pointing to a freed reloc
+ * root and trigger a use-after-free during
+ * unmount or elsewhere.
+ */
+ clear_reloc_root(root);
+ btrfs_put_root(root);
+ /*
+ * We are adding the reloc_root to the local
+ * reloc_roots list, so we add a ref for this
+ * list which will be dropped below by the call
+ * to free_reloc_roots().
+ */
+ if (list_empty(&reloc_root->root_list)) {
list_add_tail(&reloc_root->root_list,
&reloc_roots);
+ btrfs_grab_root(reloc_root);
+ }
+ /* Now drop the ref for root->reloc_root. */
+ btrfs_put_root(reloc_root);
goto out;
}
+ btrfs_put_root(root);
} else {
if (!IS_ERR(root)) {
if (root->reloc_root == reloc_root) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 263/982] spi: dw-dma: Wait for controller idle before completing Tx
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (261 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 262/982] btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 264/982] btrfs: fix reloc root cleanup in merge_reloc_roots() Greg Kroah-Hartman
` (725 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wang YuWei, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wang YuWei <1973615295@qq.com>
[ Upstream commit 0bcd59706aeda8a5d48ba656bab74cb26f2b423e ]
dw_spi_dma_wait_tx_done() polls dw_spi_dma_tx_busy(), which only checks
DW_SPI_SR_TF_EMPT. An empty TX FIFO merely means the last data word has
been moved into the shift register; the transfer is not complete on the
bus until DW_SPI_SR_BUSY is also cleared. As a result the wait can
return while the controller is still shifting out the final word.
Any caller that tears down or reconfigures the controller right after
the transfer can then lose the tail of the transfer.
The memory-operation path in spi-dw-core.c already waits for both
DW_SPI_SR_BUSY == 0 and DW_SPI_SR_TF_EMPT == 1. Use the same completion
condition in the DMA path so the transfer is guaranteed to be finished
on the bus before the wait returns.
Signed-off-by: Wang YuWei <1973615295@qq.com>
Link: https://patch.msgid.link/tencent_4EA7B5C94669ED4C38A5F6C1C9126E5D9106@qq.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-dw-dma.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/spi/spi-dw-dma.c b/drivers/spi/spi-dw-dma.c
index ababb910b3914..a795df52c5fe7 100644
--- a/drivers/spi/spi-dw-dma.c
+++ b/drivers/spi/spi-dw-dma.c
@@ -241,7 +241,8 @@ static int dw_spi_dma_wait(struct dw_spi *dws, unsigned int len, u32 speed)
static inline bool dw_spi_dma_tx_busy(struct dw_spi *dws)
{
- return !(dw_readl(dws, DW_SPI_SR) & DW_SPI_SR_TF_EMPT);
+ return (dw_readl(dws, DW_SPI_SR) &
+ (DW_SPI_SR_BUSY | DW_SPI_SR_TF_EMPT)) != DW_SPI_SR_TF_EMPT;
}
static int dw_spi_dma_wait_tx_done(struct dw_spi *dws,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 264/982] btrfs: fix reloc root cleanup in merge_reloc_roots()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (262 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 263/982] spi: dw-dma: Wait for controller idle before completing Tx Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 265/982] wifi: iwlwifi: mvm: fix an off-by-1 boundary check Greg Kroah-Hartman
` (724 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Boris Burkov, Filipe Manana,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit b78fe9563e2d5ae47805f1e5dc722c91fd30e1f8 ]
If the root we got has zero root refs in its root item, we are resetting
the root's ->reloc_root without using barriers like we do everywhere else.
Sashiko complained about this while reviewing another patch, and it's
correct (see the Link tag below).
Also, we should not clear BTRFS_ROOT_DEAD_RELOC_TREE from the root unless
the root points to the reloc root we have.
Fix this by using clear_reloc_root(), which issues the memory barrier
after setting the root's ->reloc_root to NULL and before clearing the bit
BTRFS_ROOT_DEAD_RELOC_TREE from the root.
Link: https://sashiko.dev/#/patchset/cf84f1a217c719e25b6b69e4298dd7afd36c9427.1781194426.git.fdmanana%40suse.com
Reviewed-by: Boris Burkov <boris@bur.io>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/relocation.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/fs/btrfs/relocation.c b/fs/btrfs/relocation.c
index ffd1319a9155d..84b153eb9d6b8 100644
--- a/fs/btrfs/relocation.c
+++ b/fs/btrfs/relocation.c
@@ -2084,11 +2084,10 @@ void merge_reloc_roots(struct reloc_control *rc)
} else {
if (!IS_ERR(root)) {
if (root->reloc_root == reloc_root) {
- root->reloc_root = NULL;
+ clear_reloc_root(root);
+ /* Drop the ref for root->reloc_root. */
btrfs_put_root(reloc_root);
}
- clear_bit(BTRFS_ROOT_DEAD_RELOC_TREE,
- &root->state);
btrfs_put_root(root);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 265/982] wifi: iwlwifi: mvm: fix an off-by-1 boundary check
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (263 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 264/982] btrfs: fix reloc root cleanup in merge_reloc_roots() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 266/982] wifi: iwlwifi: mvm: fix sched scan IE sizing Greg Kroah-Hartman
` (723 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Ilan Peer,
Miri Korenblit, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit d77aff138c9ec6c8562f4c2c9f262d3d9c4b4cb8 ]
Before looking at the 11th byte, check the length is big enough.
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Reviewed-by: Ilan Peer <ilan.peer@intel.com>
Link: https://patch.msgid.link/20260714141909.d22bf52a18d0.If0ef6612a67cca671428b06dbdeec68549e50ae6@changeid
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
index bd4301857ba87..184de7b3ebbec 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
@@ -2962,7 +2962,7 @@ static void iwl_mvm_check_he_obss_narrow_bw_ru_iter(struct wiphy *wiphy,
elem = cfg80211_find_elem(WLAN_EID_EXT_CAPABILITY, ies->data,
ies->len);
- if (!elem || elem->datalen < 10 ||
+ if (!elem || elem->datalen < 11 ||
!(elem->data[10] &
WLAN_EXT_CAPA10_OBSS_NARROW_BW_RU_TOLERANCE_SUPPORT)) {
data->tolerated = false;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 266/982] wifi: iwlwifi: mvm: fix sched scan IE sizing
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (264 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 265/982] wifi: iwlwifi: mvm: fix an off-by-1 boundary check Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 267/982] ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute LEDs Greg Kroah-Hartman
` (722 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Ilan Peer,
Miri Korenblit, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit 4f155d262b31b9b17e0f9856bdabe0968eb4930f ]
Scheduled scan built the probe request before iwl_mvm_scan_fits(),
so oversized IEs could be copied into the fixed preq buffer before
length validation. Move iwl_mvm_build_scan_probe() after the fits
check.
Also advertise max_sched_scan_ie_len using iwl_mvm_max_scan_ie_len()
so userspace limits account for driver-inserted DS/TPC bytes.
Assisted-by: GitHubCopilot:gpt-5.3-codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Reviewed-by: Ilan Peer <ilan.peer@intel.com>
Link: https://patch.msgid.link/20260714141909.53d2722c79e7.Iebb922efa6173c92f14cd8aa8b4e7f372c0a0fb7@changeid
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c | 4 +---
drivers/net/wireless/intel/iwlwifi/mvm/scan.c | 4 ++--
2 files changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
index 184de7b3ebbec..20a9dd6182173 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
@@ -495,9 +495,7 @@ int iwl_mvm_mac_setup_register(struct iwl_mvm *mvm)
hw->wiphy->max_sched_scan_reqs = 1;
hw->wiphy->max_sched_scan_ssids = PROBE_OPTION_MAX;
hw->wiphy->max_match_sets = iwl_umac_scan_get_max_profiles(mvm->fw);
- /* we create the 802.11 header and zero length SSID IE. */
- hw->wiphy->max_sched_scan_ie_len =
- SCAN_OFFLOAD_PROBE_REQ_SIZE - 24 - 2;
+ hw->wiphy->max_sched_scan_ie_len = iwl_mvm_max_scan_ie_len(mvm);
hw->wiphy->max_sched_scan_plans = IWL_MAX_SCHED_SCAN_PLANS;
hw->wiphy->max_sched_scan_plan_interval = U16_MAX;
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/scan.c b/drivers/net/wireless/intel/iwlwifi/mvm/scan.c
index 1d9798775f8a9..1785e021c66b9 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/scan.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/scan.c
@@ -2906,8 +2906,6 @@ int iwl_mvm_sched_scan_start(struct iwl_mvm *mvm,
if (ret)
return ret;
- iwl_mvm_build_scan_probe(mvm, vif, ies, ¶ms);
-
/* for 6 GHZ band only PSC channels need to be added */
for (i = 0; i < params.n_channels; i++) {
struct ieee80211_channel *channel = params.channels[i];
@@ -2941,6 +2939,8 @@ int iwl_mvm_sched_scan_start(struct iwl_mvm *mvm,
goto out;
}
+ iwl_mvm_build_scan_probe(mvm, vif, ies, ¶ms);
+
uid = iwl_mvm_build_scan_cmd(mvm, vif, &hcmd, ¶ms, type);
if (uid < 0) {
ret = uid;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 267/982] ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute LEDs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (265 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 266/982] wifi: iwlwifi: mvm: fix sched scan IE sizing Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 268/982] blk-cgroup: fix leaks and online flag on radix_tree_insert failure Greg Kroah-Hartman
` (721 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marcel Kłos, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marcel Kłos <marcel@marmak.net.pl>
[ Upstream commit 728d34ebf91c0e80b63a66b237dd0dfc5a8e5b4d ]
The sound and microphone mute LEDs do not function on this newer
revision of the board (8AB8) while they do on the older 880D models.
I have verified this on another laptop which was manufactured before
the one with the issue.
Added the ALC245_FIXUP_CS35L41_SPI_2_HP_GPIO_LED from a G9 model, which
uses the same codec, to make it work. Tested on kernel version 7.1.3 on
the aforementioned newer revision notebook.
Signed-off-by: Marcel Kłos <marcel@marmak.net.pl>
Link: https://patch.msgid.link/4dab5622-9100-4730-8c99-b58da939549b@marmak.net.pl
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index e79eb082810d7..c2b941bf338db 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -10038,6 +10038,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x103c, 0x8aa3, "HP ProBook 450 G9 (MB 8AA1)", ALC236_FIXUP_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8aa8, "HP EliteBook 640 G9 (MB 8AA6)", ALC236_FIXUP_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8aab, "HP EliteBook 650 G9 (MB 8AA9)", ALC236_FIXUP_HP_GPIO_LED),
+ SND_PCI_QUIRK(0x103c, 0x8ab8, "HP EliteBook 830 G8 Notebook PC (MB 8AB8)", ALC245_FIXUP_CS35L41_SPI_2_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8ab9, "HP EliteBook 840 G8 (MB 8AB8)", ALC285_FIXUP_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8abb, "HP ZBook Firefly 14 G9", ALC245_FIXUP_CS35L41_SPI_2_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x8ad1, "HP EliteBook 840 14 inch G9 Notebook PC", ALC245_FIXUP_CS35L41_SPI_2_HP_GPIO_LED),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 268/982] blk-cgroup: fix leaks and online flag on radix_tree_insert failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (266 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 267/982] ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute LEDs Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 269/982] arm64: fixmap: Allow 256K early_ioremap() at any offset Greg Kroah-Hartman
` (720 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tejun Heo, Tao Cui, Jens Axboe,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tao Cui <cuitao@kylinos.cn>
[ Upstream commit dbbca20764382b4d411ec2918f4e278ffe547acc ]
When radix_tree_insert() fails in blkg_create(), the error path has two
issues:
1. blkg->online is set to true unconditionally, even when the blkg was
never fully inserted. Move the assignment inside the success block.
2. The error path calls blkg_put() without first calling
percpu_ref_kill(). Because the refcount is still in percpu mode,
percpu_ref_put() only does this_cpu_sub() without checking for zero,
so blkg_release() is never triggered. This permanently leaks the
blkg memory, its percpu iostat, policy data, the parent blkg
reference, and the cgroup css reference — the latter preventing the
cgroup from ever being destroyed.
Fix by replacing blkg_put() with percpu_ref_kill(), matching the pattern
used in blkg_destroy().
Acked-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Link: https://patch.msgid.link/20260715132407.1469777-1-cui.tao@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-cgroup.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
index c02292b0bd694..7d7c99d93bdb8 100644
--- a/block/blk-cgroup.c
+++ b/block/blk-cgroup.c
@@ -334,15 +334,15 @@ static struct blkcg_gq *blkg_create(struct blkcg *blkcg, struct gendisk *disk,
blkg->pd[i]->online = true;
}
}
+ blkg->online = true;
}
- blkg->online = true;
spin_unlock(&blkcg->lock);
if (!ret)
return blkg;
/* @blkg failed fully initialized, use the usual release path */
- blkg_put(blkg);
+ percpu_ref_kill(&blkg->refcnt);
return ERR_PTR(ret);
err_put_css:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 269/982] arm64: fixmap: Allow 256K early_ioremap() at any offset
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (267 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 268/982] blk-cgroup: fix leaks and online flag on radix_tree_insert failure Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 270/982] arm64: kprobes: Allow reentering kprobes while single-stepping Greg Kroah-Hartman
` (719 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yu Peng, Will Deacon, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Peng <pengyu@kylinos.cn>
[ Upstream commit 21fc7ec93f8b633b60d5bddef2f1529ff6b36185 ]
NR_FIX_BTMAPS is the per-slot page limit for early_ioremap(). Since
__early_ioremap() maps the page-aligned physical range, a 256K request
can require one extra page when the physical address is not page-aligned.
Reserve one extra page per slot so the 256K mapping budget is usable
regardless of the initial page offset.
Link: https://lore.kernel.org/r/08fd96fa-ee3a-4904-bd11-bb08bd90436f@kylinos.cn
Signed-off-by: Yu Peng <pengyu@kylinos.cn>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/include/asm/fixmap.h | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/include/asm/fixmap.h b/arch/arm64/include/asm/fixmap.h
index 71ed5fdf718bd..491b5b43c5a1d 100644
--- a/arch/arm64/include/asm/fixmap.h
+++ b/arch/arm64/include/asm/fixmap.h
@@ -75,8 +75,12 @@ enum fixed_addresses {
/*
* Temporary boot-time mappings, used by early_ioremap(),
* before ioremap() is functional.
+ *
+ * Reserve one extra page so a 256K mapping may start at any
+ * offset within a page. early_ioremap() maps the page-aligned
+ * physical range, so the initial offset can consume an extra page.
*/
-#define NR_FIX_BTMAPS (SZ_256K / PAGE_SIZE)
+#define NR_FIX_BTMAPS ((SZ_256K / PAGE_SIZE) + 1)
#define FIX_BTMAPS_SLOTS 7
#define TOTAL_FIX_BTMAPS (NR_FIX_BTMAPS * FIX_BTMAPS_SLOTS)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 270/982] arm64: kprobes: Allow reentering kprobes while single-stepping
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (268 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 269/982] arm64: fixmap: Allow 256K early_ioremap() at any offset Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 271/982] drm/amd/pm/si: Dont schedule thermal work when queue isnt initialized Greg Kroah-Hartman
` (718 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pu Hu, Hongyan Xia,
Masami Hiramatsu (Google), Will Deacon, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Hu <hupu@transsion.com>
[ Upstream commit 23f851ac0078a908bf3422d6467ebc1db5828c46 ]
A kprobe can be hit while another kprobe is in KPROBE_HIT_SS state. This
can happen when tracing or perf code runs from the debug exception path
while the first kprobe is preparing or executing its out-of-line
single-step instruction.
Currently arm64 treats a kprobe hit in KPROBE_HIT_SS as unrecoverable,
the same as a hit in KPROBE_REENTER. This is too strict. A hit in
KPROBE_HIT_SS is still a one-level reentry and can be handled by saving
the current kprobe state and setting up single-step for the new probe,
just like reentry from KPROBE_HIT_ACTIVE or KPROBE_HIT_SSDONE.
The truly unrecoverable case is hitting another kprobe while already in
KPROBE_REENTER, because the reentry save area has already been consumed.
Move KPROBE_HIT_SS to the recoverable reentry cases and leave
KPROBE_REENTER as the unrecoverable nested reentry case.
This change also requires saving saved_irqflag in struct prev_kprobe.
When a nested kprobe calls kprobes_save_local_irqflag(), it overwrites
kcb->saved_irqflag with the currently masked DAIF value, losing the
outer kprobe's original DAIF state. Without this fix, when the outer
kprobe's single-step finishes, kprobes_restore_local_irqflag() applies
the wrong DAIF mask and leaves interrupts permanently disabled.
Extend struct prev_kprobe with a saved_irqflag field and save/restore it
alongside kp and status. This ensures the outer kprobe's original
interrupt state is preserved across reentry.
This mirrors the x86 fix in commit 6a5022a56ac3
("kprobes/x86: Allow to handle reentered kprobe on single-stepping").
Signed-off-by: Pu Hu <hupu@transsion.com>
Signed-off-by: Hongyan Xia <hongyan.xia@transsion.com>
Reviewed-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/include/asm/kprobes.h | 6 ++++++
arch/arm64/kernel/probes/kprobes.c | 23 ++++++++++++++++++++++-
2 files changed, 28 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/include/asm/kprobes.h b/arch/arm64/include/asm/kprobes.h
index 05cd82eeca136..221c7ab3ee6f4 100644
--- a/arch/arm64/include/asm/kprobes.h
+++ b/arch/arm64/include/asm/kprobes.h
@@ -26,6 +26,12 @@
struct prev_kprobe {
struct kprobe *kp;
unsigned int status;
+
+ /*
+ * The original DAIF state of the outer kprobe, saved here before
+ * a nested kprobe overwrites kcb->saved_irqflag during reentry.
+ */
+ unsigned long saved_irqflag;
};
/* per-cpu kprobe control block */
diff --git a/arch/arm64/kernel/probes/kprobes.c b/arch/arm64/kernel/probes/kprobes.c
index c9e4d07202856..46acee523d782 100644
--- a/arch/arm64/kernel/probes/kprobes.c
+++ b/arch/arm64/kernel/probes/kprobes.c
@@ -165,12 +165,27 @@ static void __kprobes save_previous_kprobe(struct kprobe_ctlblk *kcb)
{
kcb->prev_kprobe.kp = kprobe_running();
kcb->prev_kprobe.status = kcb->kprobe_status;
+
+ /*
+ * Save the outer kprobe's original DAIF flags before the nested
+ * kprobe calls kprobes_save_local_irqflag() and overwrites
+ * kcb->saved_irqflag. Without this, the outer kprobe will restore
+ * the wrong DAIF state and leave interrupts permanently masked.
+ */
+ kcb->prev_kprobe.saved_irqflag = kcb->saved_irqflag;
}
static void __kprobes restore_previous_kprobe(struct kprobe_ctlblk *kcb)
{
__this_cpu_write(current_kprobe, kcb->prev_kprobe.kp);
kcb->kprobe_status = kcb->prev_kprobe.status;
+
+ /*
+ * Restore the outer kprobe's saved_irqflag so that when its
+ * single-step completes, kprobes_restore_local_irqflag() uses
+ * the correct original DAIF value.
+ */
+ kcb->saved_irqflag = kcb->prev_kprobe.saved_irqflag;
}
static void __kprobes set_current_kprobe(struct kprobe *p)
@@ -231,10 +246,16 @@ static int __kprobes reenter_kprobe(struct kprobe *p,
switch (kcb->kprobe_status) {
case KPROBE_HIT_SSDONE:
case KPROBE_HIT_ACTIVE:
+ case KPROBE_HIT_SS:
+ /*
+ * A probe can be hit while another kprobe is preparing or
+ * executing its XOL single-step instruction. This is still a
+ * recoverable one-level reentry, so handle it in the same way as
+ * reentry from KPROBE_HIT_ACTIVE or KPROBE_HIT_SSDONE.
+ */
kprobes_inc_nmissed_count(p);
setup_singlestep(p, regs, kcb, 1);
break;
- case KPROBE_HIT_SS:
case KPROBE_REENTER:
pr_warn("Failed to recover from reentered kprobes.\n");
dump_kprobe(p);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 271/982] drm/amd/pm/si: Dont schedule thermal work when queue isnt initialized
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (269 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 270/982] arm64: kprobes: Allow reentering kprobes while single-stepping Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 272/982] wifi: iwlwifi: bound aligned TLV advance in FW parser Greg Kroah-Hartman
` (717 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Timur Kristóf, Alex Deucher,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Timur Kristóf <timur.kristof@gmail.com>
[ Upstream commit f8922d5a946699fc2bdc7660e6778bd6726bf8b8 ]
When DPM is turned off with the amdgpu.dpm=0 module parameter,
the thermal work queue isn't initialized so we shouldn't
schedule any work on it.
Signed-off-by: Timur Kristóf <timur.kristof@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit bd018d36171a695952c6d391471c279c9e05c8b2)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c b/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c
index f71585ae68498..be70e2b6376a8 100644
--- a/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c
+++ b/drivers/gpu/drm/amd/pm/legacy-dpm/si_dpm.c
@@ -7670,7 +7670,7 @@ static int si_dpm_process_interrupt(struct amdgpu_device *adev,
break;
}
- if (queue_thermal)
+ if (queue_thermal && amdgpu_dpm)
schedule_work(&adev->pm.dpm.thermal.work);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 272/982] wifi: iwlwifi: bound aligned TLV advance in FW parser
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (270 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 271/982] drm/amd/pm/si: Dont schedule thermal work when queue isnt initialized Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 273/982] ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless Greg Kroah-Hartman
` (716 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Miri Korenblit,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit acad742714bdc70e7fd7f234323807c596828213 ]
Validate ALIGN(tlv_len, 4) against remaining parser length before
consuming bytes from the firmware image.
This avoids length underflow on malformed TLVs.
Assisted-by: GitHubCopilot:GPT-5.3-Codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Link: https://patch.msgid.link/20260717173215.393c286488f9.Ia39144dc3ca334325ee4eacb7420901e2446fc23@changeid
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/iwl-drv.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/iwl-drv.c b/drivers/net/wireless/intel/iwlwifi/iwl-drv.c
index 789393aa68cd8..7524b85baa712 100644
--- a/drivers/net/wireless/intel/iwlwifi/iwl-drv.c
+++ b/drivers/net/wireless/intel/iwlwifi/iwl-drv.c
@@ -644,6 +644,7 @@ static int iwl_parse_tlv_firmware(struct iwl_drv *drv,
u32 build, paging_mem_size;
int num_of_cpus;
bool usniffer_req = false;
+ size_t aligned_tlv_len;
if (len < sizeof(*ucode)) {
IWL_ERR(drv, "uCode has invalid length: %zd\n", len);
@@ -692,8 +693,16 @@ static int iwl_parse_tlv_firmware(struct iwl_drv *drv,
len, tlv_len);
return -EINVAL;
}
- len -= ALIGN(tlv_len, 4);
- data += sizeof(*tlv) + ALIGN(tlv_len, 4);
+
+ aligned_tlv_len = ALIGN(tlv_len, 4);
+ if (len < aligned_tlv_len) {
+ IWL_ERR(drv, "invalid aligned TLV len: %zd/%zu\n",
+ len, aligned_tlv_len);
+ return -EINVAL;
+ }
+
+ len -= aligned_tlv_len;
+ data += sizeof(*tlv) + aligned_tlv_len;
switch (tlv_type) {
case IWL_UCODE_TLV_INST:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 273/982] ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (271 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 272/982] wifi: iwlwifi: bound aligned TLV advance in FW parser Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 274/982] wifi: iwlwifi: acpi: validate WGDS table revision index Greg Kroah-Hartman
` (715 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel C. Ribeiro, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel C. Ribeiro <dcoutinho.96@gmail.com>
[ Upstream commit f6d6a4147ace0c417035f65b021027c209c75190 ]
JBL Quantum650 Wireless (0ecb:2125) requires the same workaround that
was used for JBL Quantum610 and Quantum810 for limiting the sample rate.
Without it, the capture (microphone) stream fails to work. Setting the
QUIRK_FLAG_FIXED_RATE flag, as done for the sibling models, makes both
playback and capture work correctly.
Signed-off-by: Daniel C. Ribeiro <dcoutinho.96@gmail.com>
Link: https://patch.msgid.link/20260719090037.40149-1-dcoutinho.96@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/quirks.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/usb/quirks.c b/sound/usb/quirks.c
index b575b50337cbd..22e69a6528dff 100644
--- a/sound/usb/quirks.c
+++ b/sound/usb/quirks.c
@@ -2157,6 +2157,8 @@ static const struct usb_audio_quirk_flags_table quirk_flags_table[] = {
QUIRK_FLAG_CTL_MSG_DELAY_1M | QUIRK_FLAG_MIXER_MIN_MUTE),
DEVICE_FLG(0x0ecb, 0x205c, /* JBL Quantum610 Wireless */
QUIRK_FLAG_FIXED_RATE),
+ DEVICE_FLG(0x0ecb, 0x2125, /* JBL Quantum650 Wireless */
+ QUIRK_FLAG_FIXED_RATE),
DEVICE_FLG(0x0ecb, 0x2069, /* JBL Quantum810 Wireless */
QUIRK_FLAG_FIXED_RATE),
DEVICE_FLG(0x0fd9, 0x0008, /* Hauppauge HVR-950Q */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 274/982] wifi: iwlwifi: acpi: validate WGDS table revision index
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (272 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 273/982] ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 275/982] wifi: mwifiex: replace one-element arrays with flexible array members Greg Kroah-Hartman
` (714 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Miri Korenblit,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit 954e821f42aaca56073ca830c5fd4bcf1a89048c ]
Check tbl_rev bounds before BIT(tbl_rev) to avoid undefined shifts when
firmware reports an invalid revision value.
Assisted-by: GitHubCopilot:GPT-5.3-Codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Link: https://patch.msgid.link/20260717173215.52a01f841f2a.Ic0131eaac31d9ff71b169138d9b0865cb39b44a9@changeid
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/fw/acpi.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/net/wireless/intel/iwlwifi/fw/acpi.c b/drivers/net/wireless/intel/iwlwifi/fw/acpi.c
index 84980f6a0d603..99f6e5138c01e 100644
--- a/drivers/net/wireless/intel/iwlwifi/fw/acpi.c
+++ b/drivers/net/wireless/intel/iwlwifi/fw/acpi.c
@@ -815,6 +815,11 @@ int iwl_sar_get_wgds_table(struct iwl_fw_runtime *fwrt)
min_size, max_size,
&tbl_rev);
if (!IS_ERR(wifi_pkg)) {
+ if (tbl_rev < 0 ||
+ tbl_rev >= BITS_PER_BYTE *
+ sizeof(rev_data[idx].revisions))
+ continue;
+
if (!(BIT(tbl_rev) & rev_data[idx].revisions))
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 275/982] wifi: mwifiex: replace one-element arrays with flexible array members
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (273 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 274/982] wifi: iwlwifi: acpi: validate WGDS table revision index Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 276/982] smb: client: bound dirent name against end of SMB response in cifs_filldir Greg Kroah-Hartman
` (713 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Georgi Valkov, Francesco Dolcini,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Georgi Valkov <gvalkov@gmail.com>
[ Upstream commit 1cb5845a58d8e1f85d5766c6fbcbfddf96c212a1 ]
Replace deprecated one-element arrays with flexible array members.
CONFIG_FORTIFY_SOURCE reports the following warning when
one-element arrays are used as variable-length buffers:
sta_cmd.c:1033 mwifiex_sta_prepare_cmd
memcpy: detected field-spanning write (size 84) of single field
"domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3)
Convert affected structs to use flexible array members.
- Preserve existing wire layouts.
- Use DECLARE_FLEX_ARRAY() for structs inside affected unions.
Tested-on: WRT3200ACM, OpenWrt
Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
Reviewed-by: Francesco Dolcini <francesco.dolcini@toradex.com>
Link: https://patch.msgid.link/20260716001728.57799-1-gvalkov@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/mwifiex/fw.h | 18 +++++++++---------
drivers/net/wireless/marvell/mwifiex/join.c | 8 ++++----
drivers/net/wireless/marvell/mwifiex/sta_cmd.c | 2 +-
3 files changed, 14 insertions(+), 14 deletions(-)
diff --git a/drivers/net/wireless/marvell/mwifiex/fw.h b/drivers/net/wireless/marvell/mwifiex/fw.h
index 9c9fe5757b295..d22b5c1796617 100644
--- a/drivers/net/wireless/marvell/mwifiex/fw.h
+++ b/drivers/net/wireless/marvell/mwifiex/fw.h
@@ -790,7 +790,7 @@ struct chan_band_param_set {
struct mwifiex_ie_types_chan_band_list_param_set {
struct mwifiex_ie_types_header header;
- struct chan_band_param_set chan_band_param[1];
+ struct chan_band_param_set chan_band_param[];
} __packed;
struct mwifiex_ie_types_rates_param_set {
@@ -848,7 +848,7 @@ struct mwifiex_ie_types_wildcard_ssid_params {
#define TSF_DATA_SIZE 8
struct mwifiex_ie_types_tsf_timestamp {
struct mwifiex_ie_types_header header;
- u8 tsf_data[1];
+ u8 tsf_data[];
} __packed;
struct mwifiex_cf_param_set {
@@ -865,8 +865,8 @@ struct mwifiex_ibss_param_set {
struct mwifiex_ie_types_ss_param_set {
struct mwifiex_ie_types_header header;
union {
- struct mwifiex_cf_param_set cf_param_set[1];
- struct mwifiex_ibss_param_set ibss_param_set[1];
+ DECLARE_FLEX_ARRAY(struct mwifiex_cf_param_set, cf_param_set);
+ DECLARE_FLEX_ARRAY(struct mwifiex_ibss_param_set, ibss_param_set);
} cf_ibss;
} __packed;
@@ -884,8 +884,8 @@ struct mwifiex_ds_param_set {
struct mwifiex_ie_types_phy_param_set {
struct mwifiex_ie_types_header header;
union {
- struct mwifiex_fh_param_set fh_param_set[1];
- struct mwifiex_ds_param_set ds_param_set[1];
+ DECLARE_FLEX_ARRAY(struct mwifiex_fh_param_set, fh_param_set);
+ DECLARE_FLEX_ARRAY(struct mwifiex_ds_param_set, ds_param_set);
} fh_ds;
} __packed;
@@ -1337,7 +1337,7 @@ struct host_cmd_ds_802_11_snmp_mib {
__le16 query_type;
__le16 oid;
__le16 buf_size;
- u8 value[1];
+ u8 value[];
} __packed;
struct mwifiex_rate_scope {
@@ -1505,7 +1505,7 @@ struct mwifiex_scan_cmd_config {
* TLV_TYPE_CHANLIST, mwifiex_ie_types_chan_list_param_set
* WLAN_EID_SSID, mwifiex_ie_types_ssid_param_set
*/
- u8 tlv_buf[1]; /* SSID TLV(s) and ChanList TLVs are stored
+ u8 tlv_buf[]; /* SSID TLV(s) and ChanList TLVs are stored
here */
} __packed;
@@ -1637,7 +1637,7 @@ struct host_cmd_ds_802_11_bg_scan_query_rsp {
struct mwifiex_ietypes_domain_param_set {
struct mwifiex_ie_types_header header;
u8 country_code[IEEE80211_COUNTRY_STRING_LEN];
- struct ieee80211_country_ie_triplet triplet[1];
+ struct ieee80211_country_ie_triplet triplet[];
} __packed;
struct host_cmd_ds_802_11d_domain_info {
diff --git a/drivers/net/wireless/marvell/mwifiex/join.c b/drivers/net/wireless/marvell/mwifiex/join.c
index c2fa654e7f61e..1eec794be8684 100644
--- a/drivers/net/wireless/marvell/mwifiex/join.c
+++ b/drivers/net/wireless/marvell/mwifiex/join.c
@@ -419,15 +419,15 @@ int mwifiex_cmd_802_11_associate(struct mwifiex_private *priv,
phy_tlv = (struct mwifiex_ie_types_phy_param_set *) pos;
phy_tlv->header.type = cpu_to_le16(WLAN_EID_DS_PARAMS);
- phy_tlv->header.len = cpu_to_le16(sizeof(phy_tlv->fh_ds.ds_param_set));
- memcpy(&phy_tlv->fh_ds.ds_param_set,
+ phy_tlv->header.len = cpu_to_le16(sizeof(*phy_tlv->fh_ds.ds_param_set));
+ memcpy(phy_tlv->fh_ds.ds_param_set,
&bss_desc->phy_param_set.ds_param_set.current_chan,
- sizeof(phy_tlv->fh_ds.ds_param_set));
+ sizeof(*phy_tlv->fh_ds.ds_param_set));
pos += sizeof(phy_tlv->header) + le16_to_cpu(phy_tlv->header.len);
ss_tlv = (struct mwifiex_ie_types_ss_param_set *) pos;
ss_tlv->header.type = cpu_to_le16(WLAN_EID_CF_PARAMS);
- ss_tlv->header.len = cpu_to_le16(sizeof(ss_tlv->cf_ibss.cf_param_set));
+ ss_tlv->header.len = cpu_to_le16(sizeof(*ss_tlv->cf_ibss.cf_param_set));
pos += sizeof(ss_tlv->header) + le16_to_cpu(ss_tlv->header.len);
/* Get the common rates supported between the driver and the BSS Desc */
diff --git a/drivers/net/wireless/marvell/mwifiex/sta_cmd.c b/drivers/net/wireless/marvell/mwifiex/sta_cmd.c
index e2800a831c8ed..db16ec72d91cc 100644
--- a/drivers/net/wireless/marvell/mwifiex/sta_cmd.c
+++ b/drivers/net/wireless/marvell/mwifiex/sta_cmd.c
@@ -108,7 +108,7 @@ static int mwifiex_cmd_802_11_snmp_mib(struct mwifiex_private *priv,
"cmd: SNMP_CMD: cmd_oid = 0x%x\n", cmd_oid);
cmd->command = cpu_to_le16(HostCmd_CMD_802_11_SNMP_MIB);
cmd->size = cpu_to_le16(sizeof(struct host_cmd_ds_802_11_snmp_mib)
- - 1 + S_DS_GEN);
+ + S_DS_GEN);
snmp_mib->oid = cpu_to_le16((u16)cmd_oid);
if (cmd_action == HostCmd_ACT_GEN_GET) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 276/982] smb: client: bound dirent name against end of SMB response in cifs_filldir
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (274 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 275/982] wifi: mwifiex: replace one-element arrays with flexible array members Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 277/982] regulator: core: clamp voltage constraints before applying apply_uV Greg Kroah-Hartman
` (712 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jay Vadayath, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jay Vadayath <jay@artiphishell.com>
[ Upstream commit f8cf09a53a0dc1da298e9dd0ba5f21710cf119d6 ]
cifs_filldir() copies the entry name out of an SMB1 TRANS2_FIND_FIRST /
FIND_NEXT response using a length (de.namelen) supplied by the server.
The kmalloc'd SMB response buffer is bounded, but nothing checks that
de.name + de.namelen still lies inside that buffer before the eventual
filldir64() -> verify_dirent_name() -> memchr() reads namelen bytes.
A hostile SMB1 server that returns an oversized FileNameLength in a
directory entry therefore causes memchr() to read past the end of the
response slab buffer. Reachable from any user who can list a directory
on a CIFS mount served by an attacker-controlled server (getdents64()
on the mounted directory):
BUG: KASAN: slab-out-of-bounds in memchr+0x71/0x80
Read of size 1 at addr ffff88800e0640cc by task poc/115
Call Trace:
dump_stack_lvl+0x64/0x80
print_report+0xce/0x620
kasan_report+0xec/0x120
memchr+0x71/0x80
filldir64+0x4c/0x6a0
cifs_filldir.constprop.0+0x9bb/0x1e00
cifs_readdir+0x2101/0x3380
iterate_dir+0x19c/0x520
__x64_sys_getdents64+0x126/0x210
do_syscall_64+0x107/0x5a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Pass the end-of-response pointer down to cifs_filldir() and reject
entries whose name would extend past that boundary.
This bug was discovered by Artiphishell's vTriage pipeline, which
generated a userspace reproducer (an emulated hostile SMB1 server plus
a getdents64() client) that reliably triggers the KASAN report on an
unpatched kernel. The fix below was drafted with the Claude coding
assistant; a userspace reproducer is available on request.
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Jay Vadayath <jay@artiphishell.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/client/readdir.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/fs/smb/client/readdir.c b/fs/smb/client/readdir.c
index 20955d595e6a5..7564927e2c427 100644
--- a/fs/smb/client/readdir.c
+++ b/fs/smb/client/readdir.c
@@ -966,7 +966,7 @@ static bool cifs_dir_emit(struct dir_context *ctx,
static int cifs_filldir(char *find_entry, struct file *file,
struct dir_context *ctx,
char *scratch_buf, unsigned int max_len,
- struct cached_fid *cfid)
+ char *end_of_smb, struct cached_fid *cfid)
{
struct cifsFileInfo *file_info = file->private_data;
struct super_block *sb = file_inode(file)->i_sb;
@@ -987,6 +987,11 @@ static int cifs_filldir(char *find_entry, struct file *file,
return -EINVAL;
}
+ if (de.name + de.namelen > end_of_smb) {
+ cifs_dbg(VFS, "search entry name extends past end of SMB\n");
+ return -EINVAL;
+ }
+
/* skip . and .. since we added them first */
if (cifs_entry_is_dot(&de, file_info->srch_inf.unicode))
return 0;
@@ -1207,7 +1212,7 @@ int cifs_readdir(struct file *file, struct dir_context *ctx)
*/
*tmp_buf = 0;
rc = cifs_filldir(current_entry, file, ctx,
- tmp_buf, max_len, cfid);
+ tmp_buf, max_len, end_of_smb, cfid);
if (rc) {
if (rc > 0)
rc = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 277/982] regulator: core: clamp voltage constraints before applying apply_uV
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (275 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 276/982] smb: client: bound dirent name against end of SMB response in cifs_filldir Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 278/982] wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO Greg Kroah-Hartman
` (711 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kamal Wadhwa, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
[ Upstream commit a45cc646a3aa83eb4ab4c7ed2685785ea51dc5e6 ]
machine_constraints_voltage() currently applies apply_uV against the
machine-supplied [min_uV, max_uV] range, and only afterwards clamps
that range down to what the regulator can actually supply (via
ops->list_voltage()).
If the machine-supplied range is wider than the regulator's actual
range, apply_uV's rounding can pick a selector outside the (correct)
clamped range, so the regulator ends up programmed outside its clamped
min/max. At bring-up this shows up as a voltage read-back outside the
clamped range.
Fix this by moving the clamping block ahead of the apply_uV block, so
apply_uV always targets an already-clamped range. Whether apply_uV
should run is decided from the unclamped constraints beforehand and
stored in a local bool, since clamping must not itself change whether
apply_uV fires.
No functional change to the clamping logic itself, only its position
relative to apply_uV. Its early return 0 exits become fallthroughs
since the apply_uV logic now follows it.
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
Link: https://patch.msgid.link/20260720-b4-regulator-core-clamp-voltage-v1-1-8e5eec076a8e@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/regulator/core.c | 163 +++++++++++++++++++++------------------
1 file changed, 90 insertions(+), 73 deletions(-)
diff --git a/drivers/regulator/core.c b/drivers/regulator/core.c
index a7a567d5eec38..52fb31ed59e48 100644
--- a/drivers/regulator/core.c
+++ b/drivers/regulator/core.c
@@ -1242,10 +1242,98 @@ static int machine_constraints_voltage(struct regulator_dev *rdev,
{
const struct regulator_ops *ops = rdev->desc->ops;
int ret;
+ bool apply_uV;
+
+ /*
+ * Decide up front, from the constraints as handed to us, whether
+ * apply_uV needs to run below. The clamping pass right after this
+ * may rewrite constraints->min_uV/max_uV (e.g. the fixed-voltage
+ * autoconfigure case), and we don't want that to change whether
+ * apply_uV fires.
+ */
+ apply_uV = rdev->constraints->apply_uV &&
+ rdev->constraints->min_uV && rdev->constraints->max_uV;
+
+ /*
+ * Constrain machine-level voltage specs to fit the actual range
+ * supported by this regulator before apply_uV (below) tries to
+ * force hardware to a value from that range: otherwise apply_uV
+ * can target a constraint value that doesn't correspond to any
+ * real voltage selector and fail registration outright, even
+ * though the clamping pass would have narrowed it to a value
+ * the regulator can actually hit.
+ */
+ if (ops->list_voltage && rdev->desc->n_voltages) {
+ int count = rdev->desc->n_voltages;
+ int i;
+ int min_uV = INT_MAX;
+ int max_uV = INT_MIN;
+ int cmin = constraints->min_uV;
+ int cmax = constraints->max_uV;
+
+ /* it's safe to autoconfigure fixed-voltage supplies
+ * and the constraints are used by list_voltage.
+ */
+ if (count == 1 && !cmin) {
+ cmin = 1;
+ cmax = INT_MAX;
+ constraints->min_uV = cmin;
+ constraints->max_uV = cmax;
+ }
+
+ /* voltage constraints are optional */
+ if ((cmin == 0) && (cmax == 0)) {
+ /* nothing more to do */
+
+ /* else require explicit machine-level constraints */
+ } else if (cmin <= 0 || cmax <= 0 || cmax < cmin) {
+ rdev_err(rdev, "invalid voltage constraints\n");
+ return -EINVAL;
+
+ /* no need to loop voltages if range is continuous */
+ } else if (rdev->desc->continuous_voltage_range) {
+ /* nothing more to do */
+
+ } else {
+ /* initial: [cmin..cmax] valid, [min_uV..max_uV] not */
+ for (i = 0; i < count; i++) {
+ int value;
+
+ value = ops->list_voltage(rdev, i);
+ if (value <= 0)
+ continue;
+
+ /* maybe adjust [min_uV..max_uV] */
+ if (value >= cmin && value < min_uV)
+ min_uV = value;
+ if (value <= cmax && value > max_uV)
+ max_uV = value;
+ }
+
+ /* final: [min_uV..max_uV] valid iff constraints valid */
+ if (max_uV < min_uV) {
+ rdev_err(rdev,
+ "unsupportable voltage constraints %u-%uuV\n",
+ min_uV, max_uV);
+ return -EINVAL;
+ }
+
+ /* use regulator's subset of machine constraints */
+ if (constraints->min_uV < min_uV) {
+ rdev_dbg(rdev, "override min_uV, %d -> %d\n",
+ constraints->min_uV, min_uV);
+ constraints->min_uV = min_uV;
+ }
+ if (constraints->max_uV > max_uV) {
+ rdev_dbg(rdev, "override max_uV, %d -> %d\n",
+ constraints->max_uV, max_uV);
+ constraints->max_uV = max_uV;
+ }
+ }
+ }
/* do we need to apply the constraint voltage */
- if (rdev->constraints->apply_uV &&
- rdev->constraints->min_uV && rdev->constraints->max_uV) {
+ if (apply_uV) {
int target_min, target_max;
int current_uV = regulator_get_voltage_rdev(rdev);
@@ -1300,77 +1388,6 @@ static int machine_constraints_voltage(struct regulator_dev *rdev,
}
}
- /* constrain machine-level voltage specs to fit
- * the actual range supported by this regulator.
- */
- if (ops->list_voltage && rdev->desc->n_voltages) {
- int count = rdev->desc->n_voltages;
- int i;
- int min_uV = INT_MAX;
- int max_uV = INT_MIN;
- int cmin = constraints->min_uV;
- int cmax = constraints->max_uV;
-
- /* it's safe to autoconfigure fixed-voltage supplies
- * and the constraints are used by list_voltage.
- */
- if (count == 1 && !cmin) {
- cmin = 1;
- cmax = INT_MAX;
- constraints->min_uV = cmin;
- constraints->max_uV = cmax;
- }
-
- /* voltage constraints are optional */
- if ((cmin == 0) && (cmax == 0))
- return 0;
-
- /* else require explicit machine-level constraints */
- if (cmin <= 0 || cmax <= 0 || cmax < cmin) {
- rdev_err(rdev, "invalid voltage constraints\n");
- return -EINVAL;
- }
-
- /* no need to loop voltages if range is continuous */
- if (rdev->desc->continuous_voltage_range)
- return 0;
-
- /* initial: [cmin..cmax] valid, [min_uV..max_uV] not */
- for (i = 0; i < count; i++) {
- int value;
-
- value = ops->list_voltage(rdev, i);
- if (value <= 0)
- continue;
-
- /* maybe adjust [min_uV..max_uV] */
- if (value >= cmin && value < min_uV)
- min_uV = value;
- if (value <= cmax && value > max_uV)
- max_uV = value;
- }
-
- /* final: [min_uV..max_uV] valid iff constraints valid */
- if (max_uV < min_uV) {
- rdev_err(rdev,
- "unsupportable voltage constraints %u-%uuV\n",
- min_uV, max_uV);
- return -EINVAL;
- }
-
- /* use regulator's subset of machine constraints */
- if (constraints->min_uV < min_uV) {
- rdev_dbg(rdev, "override min_uV, %d -> %d\n",
- constraints->min_uV, min_uV);
- constraints->min_uV = min_uV;
- }
- if (constraints->max_uV > max_uV) {
- rdev_dbg(rdev, "override max_uV, %d -> %d\n",
- constraints->max_uV, max_uV);
- constraints->max_uV = max_uV;
- }
- }
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 278/982] wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (276 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 277/982] regulator: core: clamp voltage constraints before applying apply_uV Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 279/982] drm/gma500: return errors from Oaktrail HDMI I2C reads Greg Kroah-Hartman
` (710 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ibrahim Hashimov, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ibrahim Hashimov <security@auditcode.ai>
[ Upstream commit 3dc723ac78a6e4fa0fd49e27e487ed319da40a9f ]
hwsim_tx_info_frame_received_nl() casts the HWSIM_ATTR_TX_INFO payload
to a struct hwsim_tx_rate * and unconditionally reads
IEEE80211_TX_MAX_RATES entries (8 bytes) from it. The policy only bounds
the attribute from above (NLA_BINARY .len is a maximum) and the op sets
GENL_DONT_VALIDATE_STRICT, so a short or zero-length attribute is
accepted and the loop reads past the payload.
Require the exact length in the policy, so a malformed attribute is
rejected before the handler runs.
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Assisted-by: AuditCode-AI:2026.07
Link: https://patch.msgid.link/20260721115346.17236-1-security@auditcode.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mac80211_hwsim.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/mac80211_hwsim.c b/drivers/net/wireless/mac80211_hwsim.c
index 60e48df794f5a..e71e40376ba58 100644
--- a/drivers/net/wireless/mac80211_hwsim.c
+++ b/drivers/net/wireless/mac80211_hwsim.c
@@ -768,9 +768,9 @@ static const struct nla_policy hwsim_genl_policy[HWSIM_ATTR_MAX + 1] = {
[HWSIM_ATTR_FLAGS] = { .type = NLA_U32 },
[HWSIM_ATTR_RX_RATE] = { .type = NLA_U32 },
[HWSIM_ATTR_SIGNAL] = { .type = NLA_U32 },
- [HWSIM_ATTR_TX_INFO] = { .type = NLA_BINARY,
- .len = IEEE80211_TX_MAX_RATES *
- sizeof(struct hwsim_tx_rate)},
+ [HWSIM_ATTR_TX_INFO] =
+ NLA_POLICY_EXACT_LEN(IEEE80211_TX_MAX_RATES *
+ sizeof(struct hwsim_tx_rate)),
[HWSIM_ATTR_COOKIE] = { .type = NLA_U64 },
[HWSIM_ATTR_CHANNELS] = { .type = NLA_U32 },
[HWSIM_ATTR_RADIO_ID] = { .type = NLA_U32 },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 279/982] drm/gma500: return errors from Oaktrail HDMI I2C reads
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (277 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 278/982] wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 280/982] phonet: check register_netdevice_notifier() error in phonet_device_init() Greg Kroah-Hartman
` (709 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Patrik Jakobsson,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 9b5ce5c496efd20c1c662cedba88465d39ec1f93 ]
xfer_read() waits for the HDMI I2C transaction to reach
I2C_TRANSACTION_DONE, but it ignores both timeout and signal returns from
wait_for_completion_interruptible_timeout(). If the interrupt never
advances the transaction state, the loop can wait forever.
Return -ETIMEDOUT when the completion wait expires, propagate interrupted
waits, and make the I2C master_xfer callback return the first transfer
error instead of reporting a successful message count.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Patrik Jakobsson <patrik.r.jakobsson@gmail.com>
Link: https://patch.msgid.link/20260625003240.6923-1-pengpeng@iscas.ac.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/gma500/oaktrail_hdmi_i2c.c | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/gma500/oaktrail_hdmi_i2c.c b/drivers/gpu/drm/gma500/oaktrail_hdmi_i2c.c
index fc9a34ed58bd1..48a2adba94879 100644
--- a/drivers/gpu/drm/gma500/oaktrail_hdmi_i2c.c
+++ b/drivers/gpu/drm/gma500/oaktrail_hdmi_i2c.c
@@ -95,6 +95,7 @@ static int xfer_read(struct i2c_adapter *adap, struct i2c_msg *pmsg)
struct oaktrail_hdmi_dev *hdmi_dev = i2c_get_adapdata(adap);
struct hdmi_i2c_dev *i2c_dev = hdmi_dev->i2c_dev;
u32 temp;
+ int ret;
i2c_dev->status = I2C_STAT_INIT;
i2c_dev->msg = pmsg;
@@ -106,9 +107,14 @@ static int xfer_read(struct i2c_adapter *adap, struct i2c_msg *pmsg)
HDMI_WRITE(HDMI_HI2CHCR, temp);
HDMI_READ(HDMI_HI2CHCR);
- while (i2c_dev->status != I2C_TRANSACTION_DONE)
- wait_for_completion_interruptible_timeout(&i2c_dev->complete,
+ while (i2c_dev->status != I2C_TRANSACTION_DONE) {
+ ret = wait_for_completion_interruptible_timeout(&i2c_dev->complete,
10 * HZ);
+ if (ret < 0)
+ return ret;
+ if (!ret)
+ return -ETIMEDOUT;
+ }
return 0;
}
@@ -127,7 +133,7 @@ static int oaktrail_hdmi_i2c_access(struct i2c_adapter *adap,
{
struct oaktrail_hdmi_dev *hdmi_dev = i2c_get_adapdata(adap);
struct hdmi_i2c_dev *i2c_dev = hdmi_dev->i2c_dev;
- int i;
+ int i, ret = 0;
mutex_lock(&i2c_dev->i2c_lock);
@@ -139,9 +145,11 @@ static int oaktrail_hdmi_i2c_access(struct i2c_adapter *adap,
for (i = 0; i < num; i++) {
if (pmsg->len && pmsg->buf) {
if (pmsg->flags & I2C_M_RD)
- xfer_read(adap, pmsg);
+ ret = xfer_read(adap, pmsg);
else
- xfer_write(adap, pmsg);
+ ret = xfer_write(adap, pmsg);
+ if (ret)
+ break;
}
pmsg++; /* next message */
}
@@ -151,6 +159,9 @@ static int oaktrail_hdmi_i2c_access(struct i2c_adapter *adap,
mutex_unlock(&i2c_dev->i2c_lock);
+ if (ret)
+ return ret;
+
return i;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 280/982] phonet: check register_netdevice_notifier() error in phonet_device_init()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (278 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 279/982] drm/gma500: return errors from Oaktrail HDMI I2C reads Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 281/982] ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4 Greg Kroah-Hartman
` (708 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Minhong He, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Minhong He <heminhong@kylinos.cn>
[ Upstream commit d1ff66b66151c14b084e88040512a064b1c1e493 ]
phonet_device_init() registers a netdevice notifier before calling
phonet_netlink_register(), but does not check whether notifier
registration succeeded. On failure, netlink setup still proceeds and
init may return success without the notifier in place.
Also, the existing phonet_netlink_register() failure path called
phonet_device_exit(), which runs rtnl_unregister_all() even though
rtnl_register_many() already unwound any partial registration. Calling
the full exit helper on a partial init is not correct.
Check each registration error, including proc_create_net(), and unwind
only the steps that have succeeded so far, in reverse order.
Signed-off-by: Minhong He <heminhong@kylinos.cn>
Link: https://patch.msgid.link/20260721093956.162617-1-heminhong@kylinos.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/phonet/pn_dev.c | 30 ++++++++++++++++++++++++------
1 file changed, 24 insertions(+), 6 deletions(-)
diff --git a/net/phonet/pn_dev.c b/net/phonet/pn_dev.c
index 3f020c362d6cd..260131669ed73 100644
--- a/net/phonet/pn_dev.c
+++ b/net/phonet/pn_dev.c
@@ -336,16 +336,34 @@ static struct pernet_operations phonet_net_ops = {
/* Initialize Phonet devices list */
int __init phonet_device_init(void)
{
- int err = register_pernet_subsys(&phonet_net_ops);
+ int err;
+
+ err = register_pernet_subsys(&phonet_net_ops);
if (err)
return err;
- proc_create_net("pnresource", 0, init_net.proc_net, &pn_res_seq_ops,
- sizeof(struct seq_net_private));
- register_netdevice_notifier(&phonet_device_notifier);
+ if (!proc_create_net("pnresource", 0, init_net.proc_net,
+ &pn_res_seq_ops, sizeof(struct seq_net_private))) {
+ err = -ENOMEM;
+ goto err_pernet;
+ }
+
+ err = register_netdevice_notifier(&phonet_device_notifier);
+ if (err)
+ goto err_proc;
+
err = phonet_netlink_register();
if (err)
- phonet_device_exit();
+ goto err_notifier;
+
+ return 0;
+
+err_notifier:
+ unregister_netdevice_notifier(&phonet_device_notifier);
+err_proc:
+ remove_proc_entry("pnresource", init_net.proc_net);
+err_pernet:
+ unregister_pernet_subsys(&phonet_net_ops);
return err;
}
@@ -353,8 +371,8 @@ void phonet_device_exit(void)
{
rtnl_unregister_all(PF_PHONET);
unregister_netdevice_notifier(&phonet_device_notifier);
- unregister_pernet_subsys(&phonet_net_ops);
remove_proc_entry("pnresource", init_net.proc_net);
+ unregister_pernet_subsys(&phonet_net_ops);
}
int phonet_route_add(struct net_device *dev, u8 daddr)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 281/982] ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (279 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 280/982] phonet: check register_netdevice_notifier() error in phonet_device_init() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 282/982] ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx Greg Kroah-Hartman
` (707 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Markus Lindner, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Markus Lindner <lindner.markus@outlook.at>
[ Upstream commit acd8aa3c4b91a38c8521000790890bc9d1083f1d ]
The Razer Barracuda X 2.4 GHz USB headset dongle (0x1532:0x0552)
reports a minimum volume register value of cval->min = -16800.
In UAC 1/256 dB units, -16800 corresponds to -65.625 dB. However,
stock ALSA misinterprets this raw integer as 1/100 dB units
(-168.00 dB), causing user-space audio servers (PipeWire /
PulseAudio) to map their volume curves against an incorrectly wide
range.
Add an explicit usbmix_dB_map entry overriding Unit 2 to -6562
(-65.62 dB) to accurately report the physical hardware
attenuation bounds.
Signed-off-by: Markus Lindner <lindner.markus@outlook.at>
Link: https://patch.msgid.link/AS8P195MB2142F4EFF83980BD02BA6566E1C12@AS8P195MB2142.EURP195.PROD.OUTLOOK.COM
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/mixer_maps.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/sound/usb/mixer_maps.c b/sound/usb/mixer_maps.c
index faac7df1fbcf0..4d8dca04f87d0 100644
--- a/sound/usb/mixer_maps.c
+++ b/sound/usb/mixer_maps.c
@@ -344,6 +344,16 @@ static const struct usbmix_name_map bose_soundlink_map[] = {
{ 0 } /* terminator */
};
+/*
+ * Razer Barracuda X 2.4: Firmware reports cval->min = -16800 in 1/256 dB units
+ * (-65.62 dB), which stock ALSA misinterprets as a -168 dB floor
+ */
+static const struct usbmix_dB_map razer_barracuda_x_2_4_dB = {-6562, 0};
+static const struct usbmix_name_map razer_barracuda_x_2_4_map[] = {
+ { 2, NULL, .dB = &razer_barracuda_x_2_4_dB },
+ { 0 } /* terminator */
+};
+
/* Sennheiser Communications Headset [PC 8], the dB value is reported as -6 negative maximum */
static const struct usbmix_dB_map sennheiser_pc8_dB = {-9500, 0};
static const struct usbmix_name_map sennheiser_pc8_map[] = {
@@ -689,6 +699,11 @@ static const struct usbmix_ctl_map usbmix_ctl_maps[] = {
.id = USB_ID(0x17aa, 0x1046),
.map = lenovo_p620_rear_map,
},
+ {
+ /* Razer Barracuda X 2.4 */
+ .id = USB_ID(0x1532, 0x0552),
+ .map = razer_barracuda_x_2_4_map,
+ },
{
/* Sennheiser Communications Headset [PC 8] */
.id = USB_ID(0x1395, 0x0025),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 282/982] ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (280 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 281/982] ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4 Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.1 283/982] ice: pass the return value of skb_checksum_help() Greg Kroah-Hartman
` (706 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Madhavender Singh, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Madhavender Singh <madhav@disroot.org>
[ Upstream commit bf4fc9f33ec21595143132a3e7fb8b5d2c2261cd ]
This laptop with an ALC236 codec requires the
ALC236_FIXUP_HP_MUTE_LED_COEFBIT2
fixup for its mute LED to function correctly.
Add the subsystem ID 0x103c:0x86c8 to the quirk table to apply this
fixup.
Signed-off-by: Madhavender Singh <madhav@disroot.org>
Link: https://patch.msgid.link/20260723104736.23386-1-madhav@disroot.org
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index c2b941bf338db..5382e6036cbb5 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -9933,6 +9933,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x103c, 0x869d, "HP", ALC236_FIXUP_HP_MUTE_LED),
SND_PCI_QUIRK(0x103c, 0x86c1, "HP Laptop 15-da3001TU", ALC236_FIXUP_HP_MUTE_LED_COEFBIT2),
SND_PCI_QUIRK(0x103c, 0x86c7, "HP Envy AiO 32", ALC274_FIXUP_HP_ENVY_GPIO),
+ SND_PCI_QUIRK(0x103c, 0x86c8, "HP Laptop 14s-dr1xxx", ALC236_FIXUP_HP_MUTE_LED_COEFBIT2),
SND_PCI_QUIRK(0x103c, 0x86e7, "HP Spectre x360 15-eb0xxx", ALC285_FIXUP_HP_SPECTRE_X360_EB1),
SND_PCI_QUIRK(0x103c, 0x863e, "HP Spectre x360 15-df1xxx", ALC285_FIXUP_HP_SPECTRE_X360_DF1),
SND_PCI_QUIRK(0x103c, 0x86e8, "HP Spectre x360 15-eb0xxx", ALC285_FIXUP_HP_SPECTRE_X360_EB1),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 283/982] ice: pass the return value of skb_checksum_help()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (281 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 282/982] ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 284/982] powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash Greg Kroah-Hartman
` (705 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aleksandr Loktionov,
Michal Swiatkowski, Tony Nguyen, Jakub Kicinski, Sasha Levin,
Rinitha S
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michal Swiatkowski <michal.swiatkowski@linux.intel.com>
[ Upstream commit 2d19302f628853742c4828381abbd668c1315598 ]
skb_checksum_help() can fail. Pass its return value back to the caller.
Commonize this software path in goto.
Instead of just returning error try calculating software checksum first.
There is a check for TSO in checksum_sw_fb.
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Signed-off-by: Michal Swiatkowski <michal.swiatkowski@linux.intel.com>
Tested-by: Rinitha S <sx.rinitha@intel.com> (A Contingent worker at Intel)
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Link: https://patch.msgid.link/20260717185340.3595286-4-anthony.l.nguyen@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/ice/ice_txrx.c | 20 +++++++++-----------
1 file changed, 9 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_txrx.c b/drivers/net/ethernet/intel/ice/ice_txrx.c
index 6172e0daa718d..1d64966da1e8a 100644
--- a/drivers/net/ethernet/intel/ice/ice_txrx.c
+++ b/drivers/net/ethernet/intel/ice/ice_txrx.c
@@ -1784,7 +1784,7 @@ int ice_tx_csum(struct ice_tx_buf *first, struct ice_tx_offload_params *off)
ret = ipv6_skip_exthdr(skb, exthdr - skb->data,
&l4_proto, &frag_off);
if (ret < 0)
- return -1;
+ goto checksum_sw_fb;
}
/* define outer transport */
@@ -1803,11 +1803,7 @@ int ice_tx_csum(struct ice_tx_buf *first, struct ice_tx_offload_params *off)
l4.hdr = skb_inner_network_header(skb);
break;
default:
- if (first->tx_flags & ICE_TX_FLAGS_TSO)
- return -1;
-
- skb_checksum_help(skb);
- return 0;
+ goto checksum_sw_fb;
}
/* compute outer L3 header size */
@@ -1866,7 +1862,7 @@ int ice_tx_csum(struct ice_tx_buf *first, struct ice_tx_offload_params *off)
ipv6_skip_exthdr(skb, exthdr - skb->data, &l4_proto,
&frag_off);
} else {
- return -1;
+ goto checksum_sw_fb;
}
/* compute inner L3 header size */
@@ -1895,15 +1891,17 @@ int ice_tx_csum(struct ice_tx_buf *first, struct ice_tx_offload_params *off)
break;
default:
- if (first->tx_flags & ICE_TX_FLAGS_TSO)
- return -1;
- skb_checksum_help(skb);
- return 0;
+ goto checksum_sw_fb;
}
off->td_cmd |= cmd;
off->td_offset |= offset;
return 1;
+
+checksum_sw_fb:
+ if (first->tx_flags & ICE_TX_FLAGS_TSO)
+ return -1;
+ return skb_checksum_help(skb);
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 284/982] powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (282 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.1 283/982] ice: pass the return value of skb_checksum_help() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 285/982] cifs: validate idmap key payload length Greg Kroah-Hartman
` (704 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vaibhav Jain, Anushree Mathur,
Madhavan Srinivasan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vaibhav Jain <vaibhav@linux.ibm.com>
[ Upstream commit 810d07fb4cf7577847f85a6fd6273b69cad8d580 ]
Currently pseries_kexec_cpu_down() skips unregistering vpa, slb_shadow and
dtl areas during a crash and kexec shutdown path. It was done to avoid
doing an HCALL while crashing. However recently Anushree reported that
during kernel crash while the kdump kernel was coming up, Hypervisor
reported invalid values for 'vpa.yield_count' while it dispatching L2-KVM
Guest vcpus. The error manifested as debug build Hypervisor assert
triggering to indicate possible VPA corruption.
Looking at the kexec cpu offline path it was discovered that during crash
kernel doesn't unregister the VPA/SLB-Shadow/DTL area with
Hypervisor. Instead it re-allocates and re-registers these areas
for cpus during boot. During kexec boot the previously allocated areas
can get overwritten with new content without hypervisor knowledge. This
creates a small window where while kexec kernel boots and the L2-VCPUs are
being dispatched, Hypervisor may try to read/write to a wrong memory area
which previously belonged to older VPA.
Fix this possible race and memory corruption by updating
pseries_kexec_cpu_down() to also unregister vpa,slb_shadow & dtl areas
during a kernel crash.
Signed-off-by: Vaibhav Jain <vaibhav@linux.ibm.com>
Tested-by: Anushree Mathur <anushree.mathur@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260708015802.274271-1-vaibhav@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/platforms/pseries/kexec.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/arch/powerpc/platforms/pseries/kexec.c b/arch/powerpc/platforms/pseries/kexec.c
index 431be156ca9bb..29f7c97ff1932 100644
--- a/arch/powerpc/platforms/pseries/kexec.c
+++ b/arch/powerpc/platforms/pseries/kexec.c
@@ -20,12 +20,15 @@
void pseries_kexec_cpu_down(int crash_shutdown, int secondary)
{
/*
- * Don't risk a hypervisor call if we're crashing
- * XXX: Why? The hypervisor is not crashing. It might be better
- * to at least attempt unregister to avoid the hypervisor stepping
- * on our memory.
+ * Ensure vpa/slb_shadow/dtl cleanup even while we are crashing.
+ * Why? The hypervisor is not crashing so at least attempt unregister to
+ * avoid the hypervisor stepping on our memory. If hypervisor or kexec
+ * kernel steps on the old memory allocated to these areas before the
+ * new kexec-kernel happens to allocate and register new areas,
+ * the hypervisor will see invalid content which may cause
+ * unexpected behavior.
*/
- if (firmware_has_feature(FW_FEATURE_SPLPAR) && !crash_shutdown) {
+ if (firmware_has_feature(FW_FEATURE_SPLPAR)) {
int ret;
int cpu = smp_processor_id();
int hwcpu = hard_smp_processor_id();
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 285/982] cifs: validate idmap key payload length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (283 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 284/982] powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 286/982] wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() Greg Kroah-Hartman
` (703 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Li Qiang, Steve French, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Qiang <liqiang01@kylinos.cn>
[ Upstream commit 455488cd5054bcc59db40fa1cc2c004031a5b2a5 ]
The cifs.idmap key type stores its payload length in key->datalen, which
is limited to U16_MAX. Accepting a larger key payload truncates the
recorded length and can make later users interpret the payload using
inconsistent bounds.
Reject oversized preparsed payloads before allocating or copying them.
This keeps key->datalen consistent with the stored data for both inline
and separately allocated idmap payloads.
Signed-off-by: Li Qiang <liqiang01@kylinos.cn>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/client/cifsacl.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c
index 3dbc71556cb00..1bcaf2644a6f1 100644
--- a/fs/smb/client/cifsacl.c
+++ b/fs/smb/client/cifsacl.c
@@ -64,6 +64,9 @@ cifs_idmap_key_instantiate(struct key *key, struct key_preparsed_payload *prep)
{
char *payload;
+ if (prep->datalen > U16_MAX)
+ return -EINVAL;
+
/*
* If the payload is less than or equal to the size of a pointer, then
* an allocation here is wasteful. Just copy the data directly to the
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 286/982] wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (284 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 285/982] cifs: validate idmap key payload length Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 287/982] Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame Greg Kroah-Hartman
` (702 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+cc867e537e4bd36f69bb,
Deepanshu Kartikey, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Deepanshu Kartikey <kartikey406@gmail.com>
[ Upstream commit a2f5286ca4f304d3fd469f01b96b518608912a5c ]
The KASAN allocation trace shows that a malformed IE buffer is
stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any
validation. The crash trace shows that a subsequent SIOCSIWESSID
triggers a connection attempt which calls cfg80211_sme_get_conn_ies()
to process the stored IE buffer, causing:
- An out-of-bounds read in skip_ie() which reads ies[pos+1]
(the length byte) past the end of the 1-byte buffer.
- An integer underflow in the memcpy size argument when offs
returned by ieee80211_ie_split() exceeds ies_len, causing
unsigned subtraction to wrap to SIZE_MAX and triggering a
fortify panic.
Fix this by validating the IE buffer in cfg80211_wext_siwgenie()
before storing it.
Reported-by: syzbot+cc867e537e4bd36f69bb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=cc867e537e4bd36f69bb
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Link: https://patch.msgid.link/20260725142028.32560-1-kartikey406@gmail.com
[drop unnecessary ie_len check, update commit message]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/wext-sme.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/net/wireless/wext-sme.c b/net/wireless/wext-sme.c
index 68f45afc352de..be121fa36c514 100644
--- a/net/wireless/wext-sme.c
+++ b/net/wireless/wext-sme.c
@@ -346,6 +346,15 @@ int cfg80211_wext_siwgenie(struct net_device *dev,
goto out;
if (ie_len) {
+ const struct element *elem;
+
+ for_each_element(elem, extra, ie_len) {
+ /* nothing */
+ }
+
+ if (!for_each_element_completed(elem, extra, ie_len))
+ return -EINVAL;
+
ie = kmemdup(extra, ie_len, GFP_KERNEL);
if (!ie) {
err = -ENOMEM;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 287/982] Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (285 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 286/982] wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 288/982] ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision) Greg Kroah-Hartman
` (701 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiale Yao, Luiz Augusto von Dentz,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiale Yao <yaojiale02@163.com>
[ Upstream commit b230e5bf501c5edaf2eb0991cb862ac142031d4b ]
rfcomm_recv_frame() casts skb->data to struct rfcomm_hdr and dereferences
hdr->addr and hdr->ctrl without validating skb->len first. A truncated
frame with skb->len less than the minimum header size causes an
out-of-bounds read of uninitialized memory. Additionally, a zero-length
frame causes skb->len-- to underflow to UINT_MAX, making
skb_tail_pointer() read far past the buffer.
Commit 23882b828c3c ("Bluetooth: RFCOMM: validate skb length in MCC
handlers") fixed the same class of missing-length-check bugs in the MCC
sub-handlers, but the top-level rfcomm_recv_frame() was left unfixed.
KMSAN reports:
BUG: KMSAN: uninit-value in rfcomm_run
...
Uninit was created at:
__alloc_skb+0x474/0xb60
vhci_write+0xe9/0x870
Fix this by rejecting frames smaller than sizeof(struct rfcomm_hdr) + 1
(the minimum frame must have a 3-byte header and a 1-byte FCS).
Signed-off-by: Jiale Yao <yaojiale02@163.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/core.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/bluetooth/rfcomm/core.c b/net/bluetooth/rfcomm/core.c
index 2914ac1c50024..104d75908dbc9 100644
--- a/net/bluetooth/rfcomm/core.c
+++ b/net/bluetooth/rfcomm/core.c
@@ -1813,6 +1813,11 @@ static struct rfcomm_session *rfcomm_recv_frame(struct rfcomm_session *s,
return s;
}
+ if (skb->len < sizeof(*hdr) + 1) {
+ kfree_skb(skb);
+ return s;
+ }
+
dlci = __get_dlci(hdr->addr);
type = __get_type(hdr->ctrl);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 288/982] ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision)
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (286 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 287/982] Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 289/982] vhost-scsi: flush backend after device ioctls Greg Kroah-Hartman
` (700 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Robert Abrahamse, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Robert Abrahamse <denobyte2@gmail.com>
[ Upstream commit cee046679655b4822f76efc9658f19efee9ac979 ]
Add USB mixer mapping quirk for later revisions of the Corsair Virtuoso
headset with USB IDs 0x1b1c:0x0a43 (wired) and 0x1b1c:0x0a44
(wireless). These devices exhibit the same mixer label collision as
earlier Virtuoso variants: all controls are labelled "Headset", causing
applications like PulseAudio to move the sidetone control instead of
the main playback volume.
Signed-off-by: Robert Abrahamse <denobyte2@gmail.com>
Link: https://patch.msgid.link/20260728140314.11601-1-denobyte2@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/mixer_maps.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/sound/usb/mixer_maps.c b/sound/usb/mixer_maps.c
index 4d8dca04f87d0..ce27fc871f513 100644
--- a/sound/usb/mixer_maps.c
+++ b/sound/usb/mixer_maps.c
@@ -638,6 +638,16 @@ static const struct usbmix_ctl_map usbmix_ctl_maps[] = {
.id = USB_ID(0x1b1c, 0x0a42),
.map = corsair_virtuoso_map,
},
+ {
+ /* Corsair Virtuoso (wired mode, later revision) */
+ .id = USB_ID(0x1b1c, 0x0a43),
+ .map = corsair_virtuoso_map,
+ },
+ {
+ /* Corsair Virtuoso (wireless mode, later revision) */
+ .id = USB_ID(0x1b1c, 0x0a44),
+ .map = corsair_virtuoso_map,
+ },
{
/* Corsair HS80 RGB Wireless (wired mode) */
.id = USB_ID(0x1b1c, 0x0a6a),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 289/982] vhost-scsi: flush backend after device ioctls
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (287 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 288/982] ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision) Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 290/982] spi: dw: fix wrong RX_SAMPLE_DLY setting after resume Greg Kroah-Hartman
` (699 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jia Jia, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jia Jia <physicalmtea@gmail.com>
[ Upstream commit 22598f55a4c2b510b3df5e69e563387a963222ae ]
vhost-scsi translates guest response descriptors into userspace iovecs
when commands are submitted. Target-core completes those commands
asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while
an in-flight command still retains response iovecs translated through the
old table.
If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command
completion can write the response to an unrelated userspace object.
Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device
ioctl. This waits for in-flight commands that can still use the old
response iovecs before the ioctl returns.
Signed-off-by: Jia Jia <physicalmtea@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260724060919.1569170-1-physicalmtea@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/vhost/scsi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/vhost/scsi.c b/drivers/vhost/scsi.c
index f9ef17c3e5664..ade822a8c1a3d 100644
--- a/drivers/vhost/scsi.c
+++ b/drivers/vhost/scsi.c
@@ -1948,9 +1948,10 @@ vhost_scsi_ioctl(struct file *f,
default:
mutex_lock(&vs->dev.mutex);
r = vhost_dev_ioctl(&vs->dev, ioctl, argp);
- /* TODO: flush backend after dev ioctl. */
if (r == -ENOIOCTLCMD)
r = vhost_vring_ioctl(&vs->dev, ioctl, argp);
+ else
+ vhost_scsi_flush(vs);
mutex_unlock(&vs->dev.mutex);
return r;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 290/982] spi: dw: fix wrong RX_SAMPLE_DLY setting after resume
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (288 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 289/982] vhost-scsi: flush backend after device ioctls Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 291/982] ASoC: rt5645: Perform the initial jack detect at probe Greg Kroah-Hartman
` (698 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jisheng Zhang, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jisheng Zhang <jszhang@kernel.org>
[ Upstream commit 133c71b2c0bc976a4751f9e05ef7cdea67f964e5 ]
On platforms which need a non-zero rx sample delay, the RX_SAMPLE_DLY
reg setting is lost after resume. The reason is that the reg may be
reset to 0 after resuming, but dws->cur_rx_sample_dly doesn't know
this fact. Fix this issue by clearing dws->cur_rx_sample_dly in
dw_spi_shutdown_chip().
Signed-off-by: Jisheng Zhang <jszhang@kernel.org>
Suggested-by: Mark Brown <broonie@kernel.org>
Link: https://patch.msgid.link/20260803135925.12622-1-jszhang@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-dw.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/spi/spi-dw.h b/drivers/spi/spi-dw.h
index 62f82024a706e..0366f069d1955 100644
--- a/drivers/spi/spi-dw.h
+++ b/drivers/spi/spi-dw.h
@@ -282,6 +282,7 @@ static inline void dw_spi_shutdown_chip(struct dw_spi *dws)
dw_spi_enable_chip(dws, 0);
dw_spi_set_clk(dws, 0);
dws->current_freq = 0;
+ dws->cur_rx_sample_dly = 0;
}
extern void dw_spi_set_cs(struct spi_device *spi, bool enable);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 291/982] ASoC: rt5645: Perform the initial jack detect at probe
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (289 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 290/982] spi: dw: fix wrong RX_SAMPLE_DLY setting after resume Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 292/982] scsi: core: Do not block on tag allocation in scsi_eh_lock_door() Greg Kroah-Hartman
` (697 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Rudi Heitbaum, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rudi Heitbaum <rudi@heitbaum.com>
[ Upstream commit 54b279699279411c77c8afbc73b83c70740a7303 ]
The only initial jack detect is the rt5645_irq(0, rt5645) at the end of
rt5645_set_jack_detect(). A card described with simple-audio-card has no
machine driver to call that, so jack state is only ever sampled from an
edge on hp-detect-gpios.
A headphone already in the socket at boot is therefore never noticed, and
the card is silent with every mixer control set correctly.
rt5645_jack_detect() is what force enables the "LDO2" and "Mic Det Power"
supplies that the "HP amp" widget depends on, and what programs
RT5645_CHARGE_PUMP away from its reset value, so without it "HP amp"
cannot power up. Unplugging and replugging the jack is the only way to
recover.
Do the detect at the end of the component probe when the driver owns a
hp-detect GPIO and the codec's own jack detect is unused, which is the
case that has no other trigger. A machine driver calling
rt5645_set_jack_detect() later just repeats it.
Signed-off-by: Rudi Heitbaum <rudi@heitbaum.com>
Link: https://patch.msgid.link/anNU3tOUR7rOReSB@5e001e58230e
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/rt5645.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/sound/soc/codecs/rt5645.c b/sound/soc/codecs/rt5645.c
index 0bb70066111b7..7d4ebef1edfd7 100644
--- a/sound/soc/codecs/rt5645.c
+++ b/sound/soc/codecs/rt5645.c
@@ -3453,6 +3453,10 @@ static int rt5645_probe(struct snd_soc_component *component)
if (!rt5645->eq_param)
return -ENOMEM;
+ /* no machine driver to call rt5645_set_jack_detect(), so detect here */
+ if (!rt5645->pdata.jd_mode && rt5645->gpiod_hp_det)
+ rt5645_irq(0, rt5645);
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 292/982] scsi: core: Do not block on tag allocation in scsi_eh_lock_door()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (290 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 291/982] ASoC: rt5645: Perform the initial jack detect at probe Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 293/982] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state Greg Kroah-Hartman
` (696 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zizhi Wo, Bart Van Assche,
Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zizhi Wo <wozizhi@huawei.com>
[ Upstream commit 732cb6bb37fd26863d5786522fb1997e7f5865b4 ]
scsi_eh_lock_door() is called from scsi_restart_operations() while the
host is still in the SHOST_RECOVERY state, i.e. before the host is
switched back to SHOST_RUNNING and scsi_run_host_queues() restarts the
queues. It allocates a request via scsi_alloc_request() with no flags,
so blk_mq_get_tag() may block waiting for a free sched tag when all tags
are already in use.
Those tags can be held by commands that were just requeued by
scsi_eh_flush_done_q() during error handling. Such commands cannot be
dispatched until the host leaves SHOST_RECOVERY and
scsi_run_host_queues() is called - which only happens *after*
scsi_eh_lock_door() returns.
This forms a circular dependency:
- scsi_eh_lock_door(), running in the SCSI error handler thread, waits
for a sched tag held by a requeued command;
- the requeued command cannot complete and release its sched tag until
the error handler thread leaves scsi_restart_operations() and restart
the queues.
For devices with a single driver tag (e.g. USB storage) it is a
guaranteed deadlock and I/O that can never be submitted. This problem
has also been reproduced in our environment.
Locking the door is a best-effort operation, and scsi_eh_lock_door()
already returns silently when the request allocation fails. Pass
BLK_MQ_REQ_NOWAIT to scsi_alloc_request() so the allocation fails
instead of blocking when no tag is available. This breaks the circular
dependency and allows the error handler to finish restarting the queues,
after which the pending commands are dispatched normally.
Signed-off-by: Zizhi Wo <wozizhi@huawei.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260723041238.1584632-1-wozizhi@huaweicloud.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/scsi_error.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/scsi_error.c b/drivers/scsi/scsi_error.c
index 79dc157661ce9..f6d3f35647636 100644
--- a/drivers/scsi/scsi_error.c
+++ b/drivers/scsi/scsi_error.c
@@ -2060,7 +2060,7 @@ static void scsi_eh_lock_door(struct scsi_device *sdev)
struct scsi_cmnd *scmd;
struct request *req;
- req = scsi_alloc_request(sdev->request_queue, REQ_OP_DRV_IN, 0);
+ req = scsi_alloc_request(sdev->request_queue, REQ_OP_DRV_IN, BLK_MQ_REQ_NOWAIT);
if (IS_ERR(req))
return;
scmd = blk_mq_rq_to_pdu(req);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 293/982] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (291 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 292/982] scsi: core: Do not block on tag allocation in scsi_eh_lock_door() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 294/982] firmware: stratix10-svc: fix FCS SMC call kernel-doc Greg Kroah-Hartman
` (695 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Westphal, Pablo Neira Ayuso,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 33d1469b0124cc0baaea7a2032123b77a81e0940 ]
sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which
clears the logger pointer without an RCU grace period. Immediately after,
ops_free_list() frees the per-net state while concurrent packets might
still be executing nf_log_packet() under rcu_read_lock()."
Clear the pointer via .pre_exit to make sure rcu readers have completed
before pernet storage is free'd. The change in nf_log_syslog.c is only
done for consistency: it doesn't use pernet data.
Link: https://sashiko.dev/#/patchset/20260731151806.849724-1-pablo%40netfilter.org
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_log_syslog.c | 4 ++--
net/netfilter/nfnetlink_log.c | 13 +++++++++----
2 files changed, 11 insertions(+), 6 deletions(-)
diff --git a/net/netfilter/nf_log_syslog.c b/net/netfilter/nf_log_syslog.c
index 11325bad19b36..70bac3f45a015 100644
--- a/net/netfilter/nf_log_syslog.c
+++ b/net/netfilter/nf_log_syslog.c
@@ -1004,7 +1004,7 @@ static int __net_init nf_log_syslog_net_init(struct net *net)
return ret;
}
-static void __net_exit nf_log_syslog_net_exit(struct net *net)
+static void __net_exit nf_log_syslog_net_pre_exit(struct net *net)
{
nf_log_unset(net, &nf_ip_logger);
nf_log_unset(net, &nf_arp_logger);
@@ -1015,7 +1015,7 @@ static void __net_exit nf_log_syslog_net_exit(struct net *net)
static struct pernet_operations nf_log_syslog_net_ops = {
.init = nf_log_syslog_net_init,
- .exit = nf_log_syslog_net_exit,
+ .pre_exit = nf_log_syslog_net_pre_exit,
};
static int __init nf_log_syslog_init(void)
diff --git a/net/netfilter/nfnetlink_log.c b/net/netfilter/nfnetlink_log.c
index b7528fa74f3af..d3c43897250a5 100644
--- a/net/netfilter/nfnetlink_log.c
+++ b/net/netfilter/nfnetlink_log.c
@@ -1129,21 +1129,26 @@ static int __net_init nfnl_log_net_init(struct net *net)
return 0;
}
-static void __net_exit nfnl_log_net_exit(struct net *net)
+static void __net_exit nfnl_log_net_pre_exit(struct net *net)
{
- struct nfnl_log_net *log = nfnl_log_pernet(net);
- unsigned int i;
-
#ifdef CONFIG_PROC_FS
remove_proc_entry("nfnetlink_log", net->nf.proc_netfilter);
#endif
nf_log_unset(net, &nfulnl_logger);
+}
+
+static void __net_exit nfnl_log_net_exit(struct net *net)
+{
+ struct nfnl_log_net *log = nfnl_log_pernet(net);
+ unsigned int i;
+
for (i = 0; i < INSTANCE_BUCKETS; i++)
WARN_ON_ONCE(!hlist_empty(&log->instance_table[i]));
}
static struct pernet_operations nfnl_log_net_ops = {
.init = nfnl_log_net_init,
+ .pre_exit = nfnl_log_net_pre_exit,
.exit = nfnl_log_net_exit,
.id = &nfnl_log_net_id,
.size = sizeof(struct nfnl_log_net),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 294/982] firmware: stratix10-svc: fix FCS SMC call kernel-doc
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (292 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 293/982] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 295/982] ksmbd: remove stale channels from all sessions on teardown Greg Kroah-Hartman
` (694 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Genevieve Chan, Dinh Nguyen,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Genevieve Chan <genevieve.chan@altera.com>
[ Upstream commit 9b9a6e31bdd1ff20c3ffdab87431672d8bfc2a07 ]
Correct kernel-doc errors for two FCS SMC calls:
INTEL_SIP_SMC_FCS_SEND_CERTIFICATE:
- Describe as async to match STD_CALL_VAL usage
- Replace INTEL_SIP_SMC_FCS_REJECTED with INTEL_SIP_SMC_REJECTED
INTEL_SIP_SMC_FCS_GET_PROVISION_DATA:
- Replace FCS-specific status macros with standard status macros
(INTEL_SIP_SMC_STATUS_ERROR and INTEL_SIP_SMC_STATUS_REJECTED)
- Restore return register documentation for a1 (mailbox error),
a2 (physical address), and a3 (structure size)
Fixes: 4a4709d470e6 ("firmware: stratix10-svc: add new FCS commands")
Fixes: 4b0a32016347 ("firmware: stratix10-svc: change get provision data to async SMC call")
Cc: stable@vger.kernel.org # 6.0+
Signed-off-by: Genevieve Chan <genevieve.chan@altera.com>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/firmware/intel/stratix10-smc.h | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/include/linux/firmware/intel/stratix10-smc.h b/include/linux/firmware/intel/stratix10-smc.h
index 4ae295c4e9cc1..118be73846ccc 100644
--- a/include/linux/firmware/intel/stratix10-smc.h
+++ b/include/linux/firmware/intel/stratix10-smc.h
@@ -557,7 +557,7 @@ INTEL_SIP_SMC_FAST_CALL_VAL(INTEL_SIP_SMC_FUNCID_FPGA_CONFIG_COMPLETED_WRITE)
/**
* Request INTEL_SIP_SMC_FUNCID_FCS_SEND_CERTIFICATE
- * Sync call to send a signed certificate
+ * Async call to send a signed certificate
*
* Call register usage:
* a0 INTEL_SIP_SMC_FCS_SEND_CERTIFICATE
@@ -566,7 +566,7 @@ INTEL_SIP_SMC_FAST_CALL_VAL(INTEL_SIP_SMC_FUNCID_FPGA_CONFIG_COMPLETED_WRITE)
* a3-a7 not used
*
* Return status:
- * a0 INTEL_SIP_SMC_STATUS_OK or INTEL_SIP_SMC_FCS_REJECTED
+ * a0 INTEL_SIP_SMC_STATUS_OK or INTEL_SIP_SMC_REJECTED
* a1-a3 not used
*/
#define INTEL_SIP_SMC_FUNCID_FCS_SEND_CERTIFICATE 93
@@ -582,9 +582,11 @@ INTEL_SIP_SMC_FAST_CALL_VAL(INTEL_SIP_SMC_FUNCID_FPGA_CONFIG_COMPLETED_WRITE)
* a1-a7 not used
*
* Return status:
- * a0 INTEL_SIP_SMC_STATUS_OK, INTEL_SIP_SMC_FCS_ERROR or
- * INTEL_SIP_SMC_FCS_REJECTED
- * a1-a3 not used
+ * a0 INTEL_SIP_SMC_STATUS_OK, INTEL_SIP_SMC_STATUS_ERROR or
+ * INTEL_SIP_SMC_STATUS_REJECTED
+ * a1 mailbox error if a0 is INTEL_SIP_SMC_STATUS_ERROR
+ * a2 physical address for the structure of fuse and key hashes
+ * a3 the size of structure
*
*/
#define INTEL_SIP_SMC_FUNCID_FCS_GET_PROVISION_DATA 94
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 295/982] ksmbd: remove stale channels from all sessions on teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (293 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 294/982] firmware: stratix10-svc: fix FCS SMC call kernel-doc Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 296/982] tracing/histograms: Simplify last_cmd_set() Greg Kroah-Hartman
` (693 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gil Portnoy, Namjae Jeon,
Steve French, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gil Portnoy <dddhkts1@gmail.com>
[ Upstream commit b10665730fbf6b5e45fe422badcbbc3f0df96ef5 ]
ksmbd_sessions_deregister() removes a connection's channels from other
sessions' channel lists only while conn->binding is still set:
if (conn->binding) {
hash_for_each_safe(sessions_table, ...)
ksmbd_chann_del(conn, sess);
}
conn->binding is a transient flag: it is cleared once a binding
SESSION_SETUP completes, and also by a subsequent non-binding
SESSION_SETUP on the same connection (a reauthentication on a bound
channel, or a new SessionId==0 setup). A connection that has bound a
channel into another session's ksmbd_chann_list and then clears
conn->binding leaves that channel behind when it disconnects: the
channel, whose chann->conn points at the now freed struct ksmbd_conn,
stays on the owner session's list.
When the owning connection later tears down, the second loop
dereferences the stale channel:
xa_for_each(&sess->ksmbd_chann_list, chann_id, chann)
if (chann->conn != conn)
ksmbd_conn_set_exiting(chann->conn); /* freed */
which is a use-after-free write into the freed ksmbd_conn (the same
stale channel is also walked by show_proc_session() through /proc). The
session is leaked as well, because its channel list never empties.
Remove the conn->binding gate so a connection always removes its
channels from every session on teardown.
Fixes: faf8578c77f3 ("ksmbd: find bound sessions during reauthentication")
Signed-off-by: Gil Portnoy <dddhkts1@gmail.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/mgmt/user_session.c | 25 +++++++++++--------------
1 file changed, 11 insertions(+), 14 deletions(-)
diff --git a/fs/smb/server/mgmt/user_session.c b/fs/smb/server/mgmt/user_session.c
index 08eeca8ab0042..605e17c7b2a17 100644
--- a/fs/smb/server/mgmt/user_session.c
+++ b/fs/smb/server/mgmt/user_session.c
@@ -232,22 +232,19 @@ void ksmbd_sessions_deregister(struct ksmbd_conn *conn)
{
struct ksmbd_session *sess;
unsigned long id;
+ struct hlist_node *tmp;
+ int bkt;
down_write(&sessions_table_lock);
- if (conn->binding) {
- int bkt;
- struct hlist_node *tmp;
-
- hash_for_each_safe(sessions_table, bkt, tmp, sess, hlist) {
- if (!ksmbd_chann_del(conn, sess) &&
- xa_empty(&sess->ksmbd_chann_list)) {
- hash_del(&sess->hlist);
- down_write(&conn->session_lock);
- xa_erase(&conn->sessions, sess->id);
- up_write(&conn->session_lock);
- if (atomic_dec_and_test(&sess->refcnt))
- ksmbd_session_destroy(sess);
- }
+ hash_for_each_safe(sessions_table, bkt, tmp, sess, hlist) {
+ if (!ksmbd_chann_del(conn, sess) &&
+ xa_empty(&sess->ksmbd_chann_list)) {
+ hash_del(&sess->hlist);
+ down_write(&conn->session_lock);
+ xa_erase(&conn->sessions, sess->id);
+ up_write(&conn->session_lock);
+ if (atomic_dec_and_test(&sess->refcnt))
+ ksmbd_session_destroy(sess);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 296/982] tracing/histograms: Simplify last_cmd_set()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (294 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 295/982] ksmbd: remove stale channels from all sessions on teardown Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 297/982] clk: at91: pmc: #undef field_{get,prep}() before definition Greg Kroah-Hartman
` (692 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu, Christophe JAILLET,
Mukesh ojha, Steven Rostedt (Google), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
[ Upstream commit 545db7e21e64766e6b7cb987fbfd3e79419726ce ]
Turn a kzalloc()+strcpy()+strncat() into an equivalent and less verbose
kasprintf().
Link: https://lore.kernel.org/linux-trace-kernel/30b6fb04dadc10a03cc1ad08f5d8a93ef623a167.1697899346.git.christophe.jaillet@wanadoo.fr
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Reviewed-by: Mukesh ojha <quic_mojha@quicinc.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/trace_events_hist.c | 11 ++---------
1 file changed, 2 insertions(+), 9 deletions(-)
diff --git a/kernel/trace/trace_events_hist.c b/kernel/trace/trace_events_hist.c
index 4e131895d6a9c..25c2334bab2d7 100644
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -771,23 +771,16 @@ static void last_cmd_set(struct trace_event_file *file, char *str)
{
const char *system = NULL, *name = NULL;
struct trace_event_call *call;
- int len;
if (!str)
return;
- /* sizeof() contains the nul byte */
- len = sizeof(HIST_PREFIX) + strlen(str);
kfree(last_cmd);
- last_cmd = kzalloc(len, GFP_KERNEL);
+
+ last_cmd = kasprintf(GFP_KERNEL, HIST_PREFIX "%s", str);
if (!last_cmd)
return;
- strcpy(last_cmd, HIST_PREFIX);
- /* Again, sizeof() contains the nul byte */
- len -= sizeof(HIST_PREFIX);
- strncat(last_cmd, str, len);
-
if (file) {
call = file->event_call;
system = call->class->system;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 297/982] clk: at91: pmc: #undef field_{get,prep}() before definition
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (295 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 296/982] tracing/histograms: Simplify last_cmd_set() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 298/982] wifi: mt76: mt7921: validate CLC firmware records Greg Kroah-Hartman
` (691 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yury Norov, Geert Uytterhoeven,
Alexandre Belloni, Stephen Boyd, Claudiu Beznea, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geert Uytterhoeven <geert+renesas@glider.be>
[ Upstream commit dbfe51513aae6bace00cc390e11cb486a64a63d2 ]
Prepare for the advent of globally available common field_get() and
field_prep() macros by undefining the symbols before defining local
variants. This prevents redefinition warnings from the C preprocessor
when introducing the common macros later.
Suggested-by: Yury Norov <yury.norov@gmail.com>
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Acked-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Acked-by: Stephen Boyd <sboyd@kernel.org>
Acked-by: Claudiu Beznea <claudiu.beznea@tuxon.dev>
Signed-off-by: Yury Norov (NVIDIA) <yury.norov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/at91/pmc.h | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/clk/at91/pmc.h b/drivers/clk/at91/pmc.h
index efe4975bddc3b..7509fd83b7bac 100644
--- a/drivers/clk/at91/pmc.h
+++ b/drivers/clk/at91/pmc.h
@@ -114,7 +114,9 @@ struct at91_clk_pms {
unsigned int parent;
};
+#undef field_get
#define field_get(_mask, _reg) (((_reg) & (_mask)) >> (ffs(_mask) - 1))
+#undef field_prep
#define field_prep(_mask, _val) (((_val) << (ffs(_mask) - 1)) & (_mask))
#define ndck(a, s) (a[s - 1].id + 1)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 298/982] wifi: mt76: mt7921: validate CLC firmware records
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (296 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 297/982] clk: at91: pmc: #undef field_{get,prep}() before definition Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 299/982] wifi: mt76: mt7921: skip unknown " Greg Kroah-Hartman
` (690 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Laxman Acharya Padhya, Felix Fietkau,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
[ Upstream commit 9417c5818a0146980c2608fda94c908e604eb033 ]
The CLC region is supplied by firmware, but the loader trusts the
region count and each record length. A malformed image can make the
region table pointer precede the firmware buffer, make the record loop
fail to advance, or index phy->clc past its end. Validate the table and
record bounds before dereferencing or copying.
Fixes: 23bdc5d8cadf ("wifi: mt76: mt7921: introduce Country Location Control support")
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Link: https://patch.msgid.link/CAMyXUJmh=WfwC4_KHupNxYR5e2Gy5QhBDL5TSG6XEW-XLa+X4Q@mail.gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7921/mcu.c | 28 ++++++++++++++++---
1 file changed, 24 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
index 9d719dc62f3bd..d34a2a3f9326c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
@@ -369,7 +369,8 @@ static int mt7921_load_clc(struct mt7921_dev *dev, const char *fw_name)
struct mt76_dev *mdev = &dev->mt76;
struct mt7921_phy *phy = &dev->phy;
const struct firmware *fw;
- int ret, i, len, offset = 0;
+ size_t clc_len, fw_data_len, len, offset = 0;
+ int ret, i;
u8 *clc_base = NULL, hw_encap = 0;
if (mt7921_disable_clc ||
@@ -394,13 +395,21 @@ static int mt7921_load_clc(struct mt7921_dev *dev, const char *fw_name)
}
hdr = (const void *)(fw->data + fw->size - sizeof(*hdr));
+ if (hdr->n_region > (fw->size - sizeof(*hdr)) / sizeof(*region)) {
+ dev_err(mdev->dev, "Invalid firmware region table\n");
+ ret = -EINVAL;
+ goto out;
+ }
+ fw_data_len = fw->size - sizeof(*hdr) -
+ hdr->n_region * sizeof(*region);
+
for (i = 0; i < hdr->n_region; i++) {
region = (const void *)((const u8 *)hdr -
(hdr->n_region - i) * sizeof(*region));
len = le32_to_cpu(region->len);
/* check if we have valid buffer size */
- if (offset + len > fw->size) {
+ if (len > fw_data_len - offset) {
dev_err(mdev->dev, "Invalid firmware region\n");
ret = -EINVAL;
goto out;
@@ -417,8 +426,19 @@ static int mt7921_load_clc(struct mt7921_dev *dev, const char *fw_name)
if (!clc_base)
goto out;
- for (offset = 0; offset < len; offset += le32_to_cpu(clc->len)) {
+ for (offset = 0; offset < len; offset += clc_len) {
+ if (len - offset < sizeof(*clc)) {
+ ret = -EINVAL;
+ goto out;
+ }
+
clc = (const struct mt7921_clc *)(clc_base + offset);
+ clc_len = le32_to_cpu(clc->len);
+ if (clc_len < sizeof(*clc) || clc_len > len - offset ||
+ clc->idx >= ARRAY_SIZE(phy->clc)) {
+ ret = -EINVAL;
+ goto out;
+ }
/* do not init buf again if chip reset triggered */
if (phy->clc[clc->idx])
@@ -430,7 +450,7 @@ static int mt7921_load_clc(struct mt7921_dev *dev, const char *fw_name)
continue;
phy->clc[clc->idx] = devm_kmemdup(mdev->dev, clc,
- le32_to_cpu(clc->len),
+ clc_len,
GFP_KERNEL);
if (!phy->clc[clc->idx]) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 299/982] wifi: mt76: mt7921: skip unknown CLC firmware records
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (297 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 298/982] wifi: mt76: mt7921: validate CLC firmware records Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 300/982] ppp_async: drop the errored frame instead of resetting its headroom Greg Kroah-Hartman
` (689 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikhail Gavrilov,
Laxman Acharya Padhya, Junjie Cao, Linus Torvalds, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
[ Upstream commit 1a296bfd3e775e515233f746218824fc7dd5ff16 ]
Treat an out-of-range CLC index as newer firmware rather than a
malformed image. linux-firmware 20260810 ships MT7922 records with
idx 3, and rejecting them made mt7921e fail to probe.
Keep the record-length checks, and report those as errors so a
truncated table is visible instead of a silent retry loop.
Fixes: 9417c5818a01 ("wifi: mt76: mt7921: validate CLC firmware records")
Reported-by: Mikhail Gavrilov <mikhail.v.gavrilov@gmail.com>
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Reviewed-by: Junjie Cao <junjie.cao@intel.com>
Tested-by: Mikhail Gavrilov <mikhail.v.gavrilov@gmail.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7921/mcu.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
index d34a2a3f9326c..991298475844f 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
@@ -428,18 +428,23 @@ static int mt7921_load_clc(struct mt7921_dev *dev, const char *fw_name)
for (offset = 0; offset < len; offset += clc_len) {
if (len - offset < sizeof(*clc)) {
+ dev_err(mdev->dev, "Invalid CLC record\n");
ret = -EINVAL;
goto out;
}
clc = (const struct mt7921_clc *)(clc_base + offset);
clc_len = le32_to_cpu(clc->len);
- if (clc_len < sizeof(*clc) || clc_len > len - offset ||
- clc->idx >= ARRAY_SIZE(phy->clc)) {
+ if (clc_len < sizeof(*clc) || clc_len > len - offset) {
+ dev_err(mdev->dev, "Invalid CLC record\n");
ret = -EINVAL;
goto out;
}
+ /* Newer firmware may add records this driver does not use yet */
+ if (clc->idx >= ARRAY_SIZE(phy->clc))
+ continue;
+
/* do not init buf again if chip reset triggered */
if (phy->clc[clc->idx])
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 300/982] ppp_async: drop the errored frame instead of resetting its headroom
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (298 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 299/982] wifi: mt76: mt7921: skip unknown " Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 301/982] ksmbd: validate ACE size against SID sub-authorities Greg Kroah-Hartman
` (688 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Vlatko Kosturjak,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlatko Kosturjak <kost@linux.hr>
[ Upstream commit 8dc5d98a16fa23c00999aecf10018c9f69fa5bf4 ]
ppp_receive_nonmp_frame() prepends a two-byte direction tag before running
the pass/active BPF filters:
*(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG);
Nothing on the receive path guarantees those two bytes of headroom. The
frame-error path in ppp_async's process_input_packet() resets a reused skb's
headroom to zero while claiming to restore it to a freshly allocated state -
but a fresh skb from dev_alloc_skb() carries NET_SKB_PAD:
err:
if (skb) {
/* make skb appear as freshly allocated */
skb_trim(skb, 0);
skb_reserve(skb, - skb_headroom(skb));
}
ap->rpkt still points at that skb, so the next frame is reassembled into it
with no headroom at all. A peer that sends a bad-FCS frame followed by one
beginning ff 03 then leaves a single byte of headroom by the time the filter
tag is pushed, which lands one byte below skb->head:
skbuff: skb_under_panic: len:49 put:2 head:ffff888003c10000
data:ffff888003c0ffff tail:0x30 end:0x640 dev:<NULL>
kernel BUG at net/core/skbuff.c:214!
RIP: 0010:skb_panic+0x13e/0x230
Call Trace:
skb_push+0xbd/0x100
ppp_receive_nonmp_frame+0x48a/0x1d10
ppp_input+0x4e9/0x2f80
ppp_async_process+0x2a/0xe0
tasklet_action_common+0x20f/0x8a0
handle_softirqs+0x18e/0x590
Kernel panic - not syncing: Fatal exception in interrupt
Zeroing the headroom violates the NET_SKB_PAD guarantee that dev_alloc_skb()
gives the rest of the receive path. Besides the filter panic above, when CCP
compression is enabled ppp_decompress_frame() hands skb->data - 2 to
->decompress()/->incomp(), which then reads out of bounds before skb->head
for the same reason.
Rather than restore the headroom, drop the errored frame - as ppp_synctty
already does on its error path - and clear ap->rpkt so the next frame is
reassembled into a fresh skb with proper headroom. This is simpler and fixes
both the filter under-panic and the CCP out-of-bounds read.
The original V1 of this patch made room in ppp_receive_nonmp_frame() with
skb_cow_head(); Eric pointed out that fixing the root cause in the transport
is the right approach.
Found by fuzzing the PPP receive path with a mutating peer on a pty; it is an
interesting (remote) DoS: root configures PPP, the peer supplies two crashing
frames. The reproducer (repro-ppp-skb.c, unchanged from v1) panics in about a
second, and returns cleanly with this applied.
Fixes: 6722e78c9005 ("[PPP]: handle misaligned accesses")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Vlatko Kosturjak <kost@linux.hr>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/apkR6ZU+tqP2C3Fl@griffin.linux.hr
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ppp/ppp_async.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ppp/ppp_async.c b/drivers/net/ppp/ppp_async.c
index 669a3a9aa5cb8..aba0744c0ab58 100644
--- a/drivers/net/ppp/ppp_async.c
+++ b/drivers/net/ppp/ppp_async.c
@@ -820,11 +820,8 @@ process_input_packet(struct asyncppp *ap)
err:
/* frame had an error, remember that, reset SC_TOSS & SC_ESCAPE */
ap->state = SC_PREV_ERROR;
- if (skb) {
- /* make skb appear as freshly allocated */
- skb_trim(skb, 0);
- skb_reserve(skb, - skb_headroom(skb));
- }
+ kfree_skb(skb);
+ ap->rpkt = NULL;
}
/* Called when the tty driver has data for us. Runs parallel with the
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 301/982] ksmbd: validate ACE size against SID sub-authorities
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (299 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 300/982] ppp_async: drop the errored frame instead of resetting its headroom Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 302/982] sctp: close UDP tunnel sockets during netns teardown Greg Kroah-Hartman
` (687 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, LocalHost, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 5152c6d49e3fd4e9f2e857c57527aead752f1f87 ]
set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but
does not verify that the declared ACE size contains all sub-authorities
described by that field. An undersized ACE can therefore be copied
and later make the POSIX ACL deduplication walk inspect data beyond
the copied ACE boundary.
The existing initial bound check is also too small. It only ensures
that the ACE size field is accessible before set_ntacl_dacl() reads
sid.num_subauth farther into the input buffer.
Require enough input for the fixed SID header before accessing
num_subauth, reject ACEs smaller than that header, and skip ACEs
whose declared size cannot contain the complete SID. This makes the
validation consistent with the other ACE walk paths.
Reported-by: LocalHost <localhost.detect@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smbacl.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/fs/smb/server/smbacl.c b/fs/smb/server/smbacl.c
index 051df6536f7a3..7a0396db6f1d2 100644
--- a/fs/smb/server/smbacl.c
+++ b/fs/smb/server/smbacl.c
@@ -749,15 +749,22 @@ static void set_ntacl_dacl(struct user_namespace *user_ns,
for (i = 0; i < nt_num_aces; i++) {
unsigned short nt_ace_size;
- if (offsetof(struct smb_ace, access_req) > aces_size)
+ if (aces_size < offsetof(struct smb_ace, sid) +
+ CIFS_SID_BASE_SIZE)
break;
nt_ace_size = le16_to_cpu(ntace->size);
- if (nt_ace_size > aces_size)
+ if (nt_ace_size > aces_size ||
+ nt_ace_size < offsetof(struct smb_ace, sid) +
+ CIFS_SID_BASE_SIZE)
break;
if (ntace->sid.num_subauth == 0 ||
- ntace->sid.num_subauth > SID_MAX_SUB_AUTHORITIES)
+ ntace->sid.num_subauth > SID_MAX_SUB_AUTHORITIES ||
+ nt_ace_size < offsetof(struct smb_ace, sid) +
+ CIFS_SID_BASE_SIZE +
+ sizeof(__le32) *
+ ntace->sid.num_subauth)
goto next_ace;
memcpy((char *)pndace + size, ntace, nt_ace_size);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 302/982] sctp: close UDP tunnel sockets during netns teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (300 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 301/982] ksmbd: validate ACE size against SID sub-authorities Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 303/982] drop_monitor: perform u64_stats updates under IRQ-disabled section Greg Kroah-Hartman
` (686 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Zhiling Zou, Ren Wei,
Xin Long, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <roxy520tt@gmail.com>
[ Upstream commit ffb2bd7ade36ec4da32c46a6eddbf4515316d08c ]
proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when
net.sctp.udp_port is set, and stops/restarts them when the sysctl value
changes. The netns exit path does not stop these sockets, so a namespace
can be torn down while its SCTP UDP tunnel sockets are still installed.
Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering
the per-net sysctl table. This prevents new sysctl writes from racing in
while the sockets are being released, and closes the sockets before the
control socket is destroyed.
Fixes: 046c052b475e ("sctp: enable udp tunneling socks")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/b9f1f02b0780ad6a719e2413f5f0bb8eb7702d94.1782585631.git.roxy520tt%40gmail.com
Signed-off-by: Zhiling Zou <roxy520tt@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/6dab75f22855cb219e2e30a5497cab03b970ab91.1784033357.git.roxy520tt@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/protocol.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/sctp/protocol.c b/net/sctp/protocol.c
index c6a5af7560748..94878fc63f07b 100644
--- a/net/sctp/protocol.c
+++ b/net/sctp/protocol.c
@@ -1466,6 +1466,7 @@ static int __net_init sctp_ctrlsock_init(struct net *net)
static void __net_exit sctp_ctrlsock_exit(struct net *net)
{
sctp_sysctl_net_unregister(net);
+ sctp_udp_sock_stop(net);
/* Free the control endpoint. */
inet_ctl_sock_destroy(net->sctp.ctl_sock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 303/982] drop_monitor: perform u64_stats updates under IRQ-disabled section
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (301 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 302/982] sctp: close UDP tunnel sockets during netns teardown Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 304/982] drop_monitor: fix size calculations for 64-bit attributes Greg Kroah-Hartman
` (685 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit fd098a23bf8fda7eae48db9b06e7c34fc4d228fa ]
In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(),
u64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were
called after spin_unlock_irqrestore(&...drop_queue.lock, flags), when local
IRQs had already been re-enabled.
Tracepoint probes can execute in IRQ or softirq context. On 32-bit
architectures, u64_stats_update_begin() disables preemption but not interrupts,
relying on seqcount writes. If a nested interrupt occurs on the same CPU during
the 64-bit stats update, the reentrant seqcount update can corrupt the
seqcount state or stats value.
Fix this by performing the 64-bit per-CPU stats update before releasing
drop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain
disabled during the u64_stats update.
Fixes: e9feb58020f9 ("drop_monitor: Expose tail drop counter")
Fixes: 5e58109b1ea4 ("drop_monitor: Add support for packet alert mode for hardware drops")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260722141743.3266924-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 768a79428dc92..a917faac7c5a8 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -528,10 +528,10 @@ static void net_dm_packet_trace_kfree_skb_hit(void *ignore,
return;
unlock_free:
- spin_unlock_irqrestore(&data->drop_queue.lock, flags);
u64_stats_update_begin(&data->stats.syncp);
u64_stats_inc(&data->stats.dropped);
u64_stats_update_end(&data->stats.syncp);
+ spin_unlock_irqrestore(&data->drop_queue.lock, flags);
consume_skb(nskb);
}
@@ -984,10 +984,10 @@ net_dm_hw_trap_packet_probe(void *ignore, const struct devlink *devlink,
return;
unlock_free:
- spin_unlock_irqrestore(&hw_data->drop_queue.lock, flags);
u64_stats_update_begin(&hw_data->stats.syncp);
u64_stats_inc(&hw_data->stats.dropped);
u64_stats_update_end(&hw_data->stats.syncp);
+ spin_unlock_irqrestore(&hw_data->drop_queue.lock, flags);
net_dm_hw_metadata_free(n_hw_metadata);
free:
consume_skb(nskb);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 304/982] drop_monitor: fix size calculations for 64-bit attributes
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (302 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 303/982] drop_monitor: perform u64_stats updates under IRQ-disabled section Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 305/982] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD Greg Kroah-Hartman
` (684 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 7089f7ab99c89f443c92d8fcc585e63f2727f0b3 ]
net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use
nla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC and
NET_DM_ATTR_TIMESTAMP).
On 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS,
nla_put_u64_64bit() may append a 4-byte NET_DM_ATTR_PAD attribute for
64-bit alignment.
However, net_dm_packet_report_size() and net_dm_hw_packet_report_size()
used nla_total_size(sizeof(u64)) instead of nla_total_size_64bit(sizeof(u64)),
budgeting 12 bytes instead of up to 16 bytes.
This under-estimation of SKB size can lead to an skb_over_panic() when
__nla_reserve() or skb_put() is subsequently called.
Fix this by using nla_total_size_64bit(sizeof(u64)) in both size calculations.
Fixes: ca30707dee2b ("drop_monitor: Add packet alert mode")
Fixes: 5e58109b1ea4 ("drop_monitor: Add support for packet alert mode for hardware drops")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260722141743.3266924-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index a917faac7c5a8..eb5956d15cde0 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -564,13 +564,13 @@ static size_t net_dm_packet_report_size(size_t payload_len,
/* NET_DM_ATTR_ORIGIN */
nla_total_size(sizeof(u16)) +
/* NET_DM_ATTR_PC */
- nla_total_size(sizeof(u64)) +
+ nla_total_size_64bit(sizeof(u64)) +
/* NET_DM_ATTR_SYMBOL */
nla_total_size(NET_DM_MAX_SYMBOL_LEN + 1) +
/* NET_DM_ATTR_IN_PORT */
net_dm_in_port_size() +
/* NET_DM_ATTR_TIMESTAMP */
- nla_total_size(sizeof(u64)) +
+ nla_total_size_64bit(sizeof(u64)) +
/* NET_DM_ATTR_ORIG_LEN */
nla_total_size(sizeof(u32)) +
/* NET_DM_ATTR_PROTO */
@@ -751,7 +751,7 @@ net_dm_hw_packet_report_size(size_t payload_len,
/* NET_DM_ATTR_FLOW_ACTION_COOKIE */
net_dm_flow_action_cookie_size(hw_metadata) +
/* NET_DM_ATTR_TIMESTAMP */
- nla_total_size(sizeof(u64)) +
+ nla_total_size_64bit(sizeof(u64)) +
/* NET_DM_ATTR_ORIG_LEN */
nla_total_size(sizeof(u32)) +
/* NET_DM_ATTR_PROTO */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 305/982] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (303 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 304/982] drop_monitor: fix size calculations for 64-bit attributes Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 306/982] tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() Greg Kroah-Hartman
` (683 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Yehyeong Lee,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 5e9c8baee0329fbefe7c67aea945e2a07f15e98b ]
net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload
before overwriting it with skb_copy_bits().
skb_put() reserves nla_total_size(payload_len), i.e. the header plus the
NLA_ALIGN() padding, but only payload_len bytes are copied in. When
payload_len is not a multiple of 4 the 1-3 padding bytes are never
initialized and are leaked to user space inside the netlink message.
KMSAN confirms the leak for the software path when the packet payload
length is not 4-byte aligned:
BUG: KMSAN: kernel-infoleak in _copy_to_iter
_copy_to_iter
__skb_datagram_iter
skb_copy_datagram_iter
netlink_recvmsg
sock_recvmsg
__sys_recvfrom
Uninit was created at:
kmem_cache_alloc_node_noprof
__alloc_skb
net_dm_packet_work
Bytes 173-175 of 176 are uninitialized
Use __nla_reserve(), which sets up the attribute header and zeroes the
padding, instead of open coding the attribute construction.
Fixes: ca30707dee2b ("drop_monitor: Add packet alert mode")
Fixes: 5e58109b1ea4 ("drop_monitor: Add support for packet alert mode for hardware drops")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260722122817.5548-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index eb5956d15cde0..78c248b9b6860 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -652,9 +652,7 @@ static int net_dm_packet_report_fill(struct sk_buff *msg, struct sk_buff *skb,
if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
goto nla_put_failure;
- attr = skb_put(msg, nla_total_size(payload_len));
- attr->nla_type = NET_DM_ATTR_PAYLOAD;
- attr->nla_len = nla_attr_size(payload_len);
+ attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
goto nla_put_failure;
@@ -814,9 +812,7 @@ static int net_dm_hw_packet_report_fill(struct sk_buff *msg,
if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
goto nla_put_failure;
- attr = skb_put(msg, nla_total_size(payload_len));
- attr->nla_type = NET_DM_ATTR_PAYLOAD;
- attr->nla_len = nla_attr_size(payload_len);
+ attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
goto nla_put_failure;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 306/982] tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (304 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 305/982] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 307/982] Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Greg Kroah-Hartman
` (682 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AutonomousCodeSecurity,
Cen Zhang (Microsoft), Tung Nguyen, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang (Microsoft) <blbllhy@gmail.com>
[ Upstream commit 47f42ff521b4eeb46e82f9a46a4783a99f7570d7 ]
In tipc_recvmsg(), the copy length is computed as:
copy = min_t(int, dlen - offset, buflen);
buflen is size_t but min_t(int, ...) casts it to int. When buflen
exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it
wraps negative, wins the comparison, and the negative copy length
propagates to simple_copy_to_iter() where int-to-size_t promotion
makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the
same pattern.
Kernel panic - not syncing: kernel: panic_on_warn set ...
RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)
Call Trace:
__skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)
skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)
tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)
io_recvmsg+0x47e/0xda0
Fix by changing min_t(int, ...) to min_t(size_t, ...) in both
functions. The result is always <= (dlen - offset), which is bounded
by TIPC maximum message size (0x1ffff bytes), so the implicit
narrowing on assignment to int copy is always safe.
Fixes: e9f8b10101c6 ("tipc: refactor function tipc_sk_recvmsg()")
Fixes: ec8a09fbbeff ("tipc: refactor function tipc_sk_recv_stream()")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260720214103.47732-1-blbllhy@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/tipc/socket.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/tipc/socket.c b/net/tipc/socket.c
index 3b93cceb0d3ca..7b8cac8b3b994 100644
--- a/net/tipc/socket.c
+++ b/net/tipc/socket.c
@@ -1939,7 +1939,7 @@ static int tipc_recvmsg(struct socket *sock, struct msghdr *m,
if (likely(!err)) {
int offset = skb_cb->bytes_read;
- copy = min_t(int, dlen - offset, buflen);
+ copy = min_t(size_t, dlen - offset, buflen);
rc = skb_copy_datagram_msg(skb, hlen + offset, m, copy);
if (unlikely(rc))
goto exit;
@@ -2071,7 +2071,7 @@ static int tipc_recvstream(struct socket *sock, struct msghdr *m,
/* Copy data if msg ok, otherwise return error/partial data */
if (likely(!err)) {
offset = skb_cb->bytes_read;
- copy = min_t(int, dlen - offset, buflen - copied);
+ copy = min_t(size_t, dlen - offset, buflen - copied);
rc = skb_copy_datagram_msg(skb, hlen + offset, m, copy);
if (unlikely(rc))
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 307/982] Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (305 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 306/982] tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 308/982] Bluetooth: ISO: fix malformed ISO_END/CONT handling Greg Kroah-Hartman
` (681 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit da55f570191d5d72f10c607a7043b947eb05ea46 ]
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also
needs to hold refcount to avoid UAF.
Take appropriate locks for hci_conn lookups, and take refcount for
hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays
valid.
When accessing conn->state, ensure hdev->lock is held to avoid data
race.
Fixes: 7b445e220db9 ("Bluetooth: MGMT: Fix holding hci_conn reference while command is queued")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/mgmt.c | 26 ++++++++++++++++++++++----
1 file changed, 22 insertions(+), 4 deletions(-)
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index c53b128adb7bd..6a3f4afc9760a 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -7363,6 +7363,9 @@ static void get_conn_info_complete(struct hci_dev *hdev, void *data, int err)
rp.max_tx_power = HCI_TX_POWER_INVALID;
}
+ if (conn)
+ hci_conn_put(conn);
+
mgmt_cmd_complete(cmd->sk, cmd->hdev->id, MGMT_OP_GET_CONN_INFO, status,
&rp, sizeof(rp));
@@ -7377,6 +7380,8 @@ static int get_conn_info_sync(struct hci_dev *hdev, void *data)
int err;
__le16 handle;
+ hci_dev_lock(hdev);
+
/* Make sure we are still connected */
if (cp->addr.type == BDADDR_BREDR)
conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK,
@@ -7384,12 +7389,16 @@ static int get_conn_info_sync(struct hci_dev *hdev, void *data)
else
conn = hci_conn_hash_lookup_ba(hdev, LE_LINK, &cp->addr.bdaddr);
- if (!conn || conn->state != BT_CONNECTED)
+ if (!conn || conn->state != BT_CONNECTED) {
+ hci_dev_unlock(hdev);
return MGMT_STATUS_NOT_CONNECTED;
+ }
- cmd->user_data = conn;
+ cmd->user_data = hci_conn_get(conn);
handle = cpu_to_le16(conn->handle);
+ hci_dev_unlock(hdev);
+
/* Refresh RSSI each time */
err = hci_read_rssi_sync(hdev, handle);
@@ -7524,6 +7533,9 @@ static void get_clock_info_complete(struct hci_dev *hdev, void *data, int err)
}
complete:
+ if (conn)
+ hci_conn_put(conn);
+
mgmt_cmd_complete(cmd->sk, cmd->hdev->id, cmd->opcode, status, &rp,
sizeof(rp));
@@ -7540,15 +7552,21 @@ static int get_clock_info_sync(struct hci_dev *hdev, void *data)
memset(&hci_cp, 0, sizeof(hci_cp));
hci_read_clock_sync(hdev, &hci_cp);
+ hci_dev_lock(hdev);
+
/* Make sure connection still exists */
conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->addr.bdaddr);
- if (!conn || conn->state != BT_CONNECTED)
+ if (!conn || conn->state != BT_CONNECTED) {
+ hci_dev_unlock(hdev);
return MGMT_STATUS_NOT_CONNECTED;
+ }
- cmd->user_data = conn;
+ cmd->user_data = hci_conn_get(conn);
hci_cp.handle = cpu_to_le16(conn->handle);
hci_cp.which = 0x01; /* Piconet clock */
+ hci_dev_unlock(hdev);
+
return hci_read_clock_sync(hdev, &hci_cp);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 308/982] Bluetooth: ISO: fix malformed ISO_END/CONT handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (306 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 307/982] Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 309/982] bpf: Mask pseudo pointer values in verifier logs Greg Kroah-Hartman
` (680 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit e054c1a6ae7310d2815778fddb87da616e11c255 ]
Core specification (Part C vol 4 sec 5.4.5) does not exclude empty
ISO_CONT, ISO_END packets. We currently reject them if they are last.
If controller sends malformed sequence
ISO_START -> rx_len = 4, ISO_CONT skb->len 4, ISO_START
that ends payload in ISO_CONT, we leak conn->rx_skb. If controller sends
too long ISO_END, we panic on skb_put. If controller sends too short
ISO_END we accept it.
Fix by marking unfinished ISO_START via conn->rx_skb != NULL. Check
skb->len properly before skb_put. Combine the ISO_CONT/END code paths
as they require the same initial checks. Reject too short ISO_END
packets.
Fixes: 84c24fb151fc ("Bluetooth: ISO: drop ISO_END frames received without prior ISO_START")
Fixes: ccf74f2390d6 ("Bluetooth: Add BTPROTO_ISO socket type")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 31 ++++++++++++++++---------------
1 file changed, 16 insertions(+), 15 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index acaf99dbf7fec..7ffb47a12dd3d 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -1702,7 +1702,7 @@ void iso_recv(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
switch (pb) {
case ISO_START:
case ISO_SINGLE:
- if (conn->rx_len) {
+ if (conn->rx_skb || conn->rx_len) {
BT_ERR("Unexpected start frame (len %d)", skb->len);
kfree_skb(conn->rx_skb);
conn->rx_skb = NULL;
@@ -1767,12 +1767,14 @@ void iso_recv(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
break;
case ISO_CONT:
- BT_DBG("Cont: frag len %d (expecting %d)", skb->len,
+ case ISO_END:
+ BT_DBG("%s: frag len %d (expecting %d)",
+ (pb == ISO_END) ? "End" : "Cont", skb->len,
conn->rx_len);
- if (!conn->rx_len) {
- BT_ERR("Unexpected continuation frame (len %d)",
- skb->len);
+ if (!conn->rx_skb) {
+ BT_ERR("Unexpected ISO %s frame (len %d)",
+ (pb == ISO_END) ? "End" : "Cont", skb->len);
goto drop;
}
@@ -1788,17 +1790,9 @@ void iso_recv(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
skb->len);
conn->rx_len -= skb->len;
- break;
- case ISO_END:
- if (!conn->rx_len) {
- BT_ERR("Unexpected end frame (len %d)", skb->len);
- goto drop;
- }
-
- skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
- skb->len);
- conn->rx_len -= skb->len;
+ if (pb == ISO_CONT)
+ break;
if (!conn->rx_len) {
struct sk_buff *rx_skb = conn->rx_skb;
@@ -1809,6 +1803,13 @@ void iso_recv(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
*/
conn->rx_skb = NULL;
iso_recv_frame(conn, rx_skb);
+ } else {
+ BT_ERR("ISO fragment incomplete (len %d, expected %d)",
+ skb->len, conn->rx_len);
+ kfree_skb(conn->rx_skb);
+ conn->rx_skb = NULL;
+ conn->rx_len = 0;
+ goto drop;
}
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 309/982] bpf: Mask pseudo pointer values in verifier logs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (307 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 308/982] Bluetooth: ISO: fix malformed ISO_END/CONT handling Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 310/982] sctp: fix err_chunk memory leaks in INIT handling Greg Kroah-Hartman
` (679 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nuoqi Gui, Alexei Starovoitov,
Eduard Zingerman, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
[ Upstream commit 72a85e9464a5332fb2cd7efd26d9295275ceda2d ]
print_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo
sources when pointer leaks are not allowed, but the mask only covers
BPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.
BPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can
also be resolved to kernel pointer values before the verifier log prints
the instruction. Include them in the existing pointer classification so
the log prints 0x0 instead of the rewritten address.
Fixes: 4976b718c355 ("bpf: Introduce pseudo_btf_id")
Fixes: 387544bfa291 ("bpf: Introduce fd_idx")
Signed-off-by: Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
Link: https://lore.kernel.org/r/20260623-f01-13-pseudo-btf-id-cap-bpf-v2-1-a190ebb8f3e2@mails.tsinghua.edu.cn
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/disasm.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/disasm.c b/kernel/bpf/disasm.c
index 7b4afb7d96db1..9661cce10689a 100644
--- a/kernel/bpf/disasm.c
+++ b/kernel/bpf/disasm.c
@@ -244,7 +244,10 @@ void print_bpf_insn(const struct bpf_insn_cbs *cbs,
*/
u64 imm = ((u64)(insn + 1)->imm << 32) | (u32)insn->imm;
bool is_ptr = insn->src_reg == BPF_PSEUDO_MAP_FD ||
- insn->src_reg == BPF_PSEUDO_MAP_VALUE;
+ insn->src_reg == BPF_PSEUDO_MAP_VALUE ||
+ insn->src_reg == BPF_PSEUDO_MAP_IDX ||
+ insn->src_reg == BPF_PSEUDO_MAP_IDX_VALUE ||
+ insn->src_reg == BPF_PSEUDO_BTF_ID;
char tmp[64];
if (is_ptr && !allow_ptr_leaks)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 310/982] sctp: fix err_chunk memory leaks in INIT handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (308 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 309/982] bpf: Mask pseudo pointer values in verifier logs Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 311/982] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify() Greg Kroah-Hartman
` (678 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Xin Long, Simon Horman,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xin Long <lucien.xin@gmail.com>
[ Upstream commit 9f58a0a4d6c2ed5d341bba64f058f15d1b0c36f2 ]
When sctp_verify_init() encounters unrecognized parameters, it allocates an
err_chunk to report them. However, this chunk is leaked in several code
paths:
1. In sctp_sf_do_5_1B_init(), if security_sctp_assoc_request() fails after
sctp_verify_init() has populated err_chunk, the function returns
immediately without freeing it.
2. In sctp_sf_do_unexpected_init(), the same leak occurs on the
security_sctp_assoc_request() failure path.
3. In sctp_sf_do_unexpected_init(), on the success path after copying
unrecognized parameters to the INIT-ACK, the function returns without
freeing err_chunk, unlike sctp_sf_do_5_1B_init() which properly frees
it.
Fix all three leaks by adding sctp_chunk_free(err_chunk) calls before
returning in the error paths and on the success path in
sctp_sf_do_unexpected_init().
Fixes: c081d53f97a1 ("security: pass asoc to sctp_assoc_request and sctp_sk_clone")
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/0656704f1b0158287c98aec09ba36c83e4a537ab.1781970534.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/sm_statefuns.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
index 4a029098a7f17..f06a563dc3988 100644
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -415,6 +415,8 @@ enum sctp_disposition sctp_sf_do_5_1B_init(struct net *net,
/* Update socket peer label if first association. */
if (security_sctp_assoc_request(new_asoc, chunk->skb)) {
sctp_association_free(new_asoc);
+ if (err_chunk)
+ sctp_chunk_free(err_chunk);
return sctp_sf_pdiscard(net, ep, asoc, type, arg, commands);
}
@@ -1607,6 +1609,8 @@ static enum sctp_disposition sctp_sf_do_unexpected_init(
/* Update socket peer label if first association. */
if (security_sctp_assoc_request(new_asoc, chunk->skb)) {
sctp_association_free(new_asoc);
+ if (err_chunk)
+ sctp_chunk_free(err_chunk);
return sctp_sf_pdiscard(net, ep, asoc, type, arg, commands);
}
@@ -1672,6 +1676,7 @@ static enum sctp_disposition sctp_sf_do_unexpected_init(
* parameter type.
*/
sctp_addto_chunk(repl, len, unk_param);
+ sctp_chunk_free(err_chunk);
}
sctp_add_cmd_sf(commands, SCTP_CMD_NEW_ASOC, SCTP_ASOC(new_asoc));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 311/982] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (309 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 310/982] sctp: fix err_chunk memory leaks in INIT handling Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 312/982] ASoC: meson: aiu: Validate written enum values Greg Kroah-Hartman
` (677 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+cb2aa2390ac024e25f5c,
Kuniyuki Iwashima, Ido Schimmel, David Ahern, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 06b693d2eb6651a63ad85bad8673de3b7d4edd6d ]
syzbot reported use-after-free in nsim_fib4_prepare_event(). [0]
The problem is that the following functions call fib_info_hold() /
refcount_inc() while dumping fib_info under RCU, which is unsafe.
* mlxsw_sp_router_fib4_event()
* rocker_router_fib_event()
* nsim_fib4_prepare_event()
refcount_inc_not_zero() must be used, but it would be too late
there.
Let's guarantee the lifetime of fib_info in fib_leaf_notify().
Note that IPv6 does not need the corresponding change since
fib6_table_dump() holds fib6_table.tb6_lock.
[0]:
refcount_t: addition on 0; use-after-free.
WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420
Modules linked in:
CPU: 0 UID: 0 PID: 3420 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
Workqueue: netns cleanup_net
RIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25
Code: eb 66 85 db 74 3e 83 fb 01 75 4c e8 1b f1 22 fd 48 8d 3d 84 cb f1 0a 67 48 0f b9 3a eb 4a e8 08 f1 22 fd 48 8d 3d 81 cb f1 0a <67> 48 0f b9 3a eb 37 e8 f5 f0 22 fd 48 8d 3d 7e cb f1 0a 67 48 0f
RSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293
RAX: ffffffff84a18858 RBX: 0000000000000002 RCX: ffff888032ff9ec0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8f9353e0
RBP: 0000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005
R10: 0000000000000100 R11: 0000000000000004 R12: ffff8880570cc000
R13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000
FS: 0000000000000000(0000) GS:ffff888126173000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0
Call Trace:
<TASK>
__refcount_add include/linux/refcount.h:-1 [inline]
__refcount_inc include/linux/refcount.h:366 [inline]
refcount_inc include/linux/refcount.h:383 [inline]
fib_info_hold include/net/ip_fib.h:629 [inline]
nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [inline]
nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [inline]
nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043
call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25
call_fib_entry_notifier net/ipv4/fib_trie.c:90 [inline]
fib_leaf_notify net/ipv4/fib_trie.c:2176 [inline]
fib_table_notify net/ipv4/fib_trie.c:2194 [inline]
fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217
fib_net_dump net/core/fib_notifier.c:70 [inline]
register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108
nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596
nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [inline]
nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058
devlink_reload+0x501/0x8d0 net/devlink/dev.c:475
devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558
ops_pre_exit_list net/core/net_namespace.c:161 [inline]
ops_undo_list+0x187/0x940 net/core/net_namespace.c:234
cleanup_net+0x56e/0x800 net/core/net_namespace.c:702
process_one_work kernel/workqueue.c:3314 [inline]
process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397
worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Fixes: 0ae3eb7b4611 ("netdevsim: fib: Perform the route programming in a non-atomic context")
Fixes: c3852ef7f2f8 ("ipv4: fib: Replay events when registering FIB notifier")
Reported-by: syzbot+cb2aa2390ac024e25f5c@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a290011.39669fcc.33b062.00b1.GAE@google.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260610061744.2030996-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip_fib.h | 5 +++++
net/ipv4/fib_trie.c | 4 ++++
2 files changed, 9 insertions(+)
diff --git a/include/net/ip_fib.h b/include/net/ip_fib.h
index b6fc9924ef7a0..a41e7c299af8d 100644
--- a/include/net/ip_fib.h
+++ b/include/net/ip_fib.h
@@ -576,6 +576,11 @@ static inline void fib_info_hold(struct fib_info *fi)
refcount_inc(&fi->fib_clntref);
}
+static inline bool fib_info_hold_safe(struct fib_info *fi)
+{
+ return refcount_inc_not_zero(&fi->fib_clntref);
+}
+
static inline void fib_info_put(struct fib_info *fi)
{
if (refcount_dec_and_test(&fi->fib_clntref))
diff --git a/net/ipv4/fib_trie.c b/net/ipv4/fib_trie.c
index 53e7664eeb0a2..f40a774686ebf 100644
--- a/net/ipv4/fib_trie.c
+++ b/net/ipv4/fib_trie.c
@@ -2178,10 +2178,14 @@ static int fib_leaf_notify(struct key_vector *l, struct fib_table *tb,
if (fa->fa_slen == last_slen)
continue;
+ if (!fib_info_hold_safe(fa->fa_info))
+ continue;
+
last_slen = fa->fa_slen;
err = call_fib_entry_notifier(nb, FIB_EVENT_ENTRY_REPLACE,
l->key, KEYLENGTH - fa->fa_slen,
fa, extack);
+ fib_info_put(fa->fa_info);
if (err)
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 312/982] ASoC: meson: aiu: Validate written enum values
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (310 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 311/982] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 313/982] ksmbd: use memcmp() to compare ClientGUIDs Greg Kroah-Hartman
` (676 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit d65adf85477247be04ac86886f8edfaa047b5d4a ]
The AIU HDMI and internal codec mux put callbacks use the written enum
value with snd_soc_enum_item_to_val() before checking whether the value is
valid for the enumeration.
Reject out-of-range values before converting the enum item, matching the
validation already done by the G12A HDMI and internal codec mux controls.
Fixes: b82b734c0e9a ("ASoC: meson: aiu: add hdmi codec control support")
Fixes: 65816025d461 ("ASoC: meson: aiu: add internal dac codec control support")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260609124317.38046-3-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/meson/aiu-acodec-ctrl.c | 3 +++
sound/soc/meson/aiu-codec-ctrl.c | 3 +++
2 files changed, 6 insertions(+)
diff --git a/sound/soc/meson/aiu-acodec-ctrl.c b/sound/soc/meson/aiu-acodec-ctrl.c
index d0f0ada5f4bce..3fd2532271511 100644
--- a/sound/soc/meson/aiu-acodec-ctrl.c
+++ b/sound/soc/meson/aiu-acodec-ctrl.c
@@ -38,6 +38,9 @@ static int aiu_acodec_ctrl_mux_put_enum(struct snd_kcontrol *kcontrol,
struct soc_enum *e = (struct soc_enum *)kcontrol->private_value;
unsigned int mux, changed;
+ if (ucontrol->value.enumerated.item[0] >= e->items)
+ return -EINVAL;
+
mux = snd_soc_enum_item_to_val(e, ucontrol->value.enumerated.item[0]);
changed = snd_soc_component_test_bits(component, e->reg,
CTRL_DIN_LRCLK_SRC,
diff --git a/sound/soc/meson/aiu-codec-ctrl.c b/sound/soc/meson/aiu-codec-ctrl.c
index 84c10956c2414..35274d6367233 100644
--- a/sound/soc/meson/aiu-codec-ctrl.c
+++ b/sound/soc/meson/aiu-codec-ctrl.c
@@ -30,6 +30,9 @@ static int aiu_codec_ctrl_mux_put_enum(struct snd_kcontrol *kcontrol,
struct soc_enum *e = (struct soc_enum *)kcontrol->private_value;
unsigned int mux, changed;
+ if (ucontrol->value.enumerated.item[0] >= e->items)
+ return -EINVAL;
+
mux = snd_soc_enum_item_to_val(e, ucontrol->value.enumerated.item[0]);
changed = snd_soc_component_test_bits(component, e->reg,
CTRL_DATA_SEL,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 313/982] ksmbd: use memcmp() to compare ClientGUIDs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (311 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 312/982] ASoC: meson: aiu: Validate written enum values Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 314/982] af_unix: Unlink scc_entry in unix_del_edge() Greg Kroah-Hartman
` (675 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Samu, Namjae Jeon, Steve French,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit e8bb506e6ef749ac0336f3e579d8d02396b7d832 ]
ClientGUID is a fixed-size binary value and can contain embedded NUL
bytes. strncmp() stops comparing at the first NUL byte, so different
ClientGUID values can incorrectly be treated as equal.
Use memcmp() in SMB3 multichannel session binding and
FSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE
bytes.
Fixes: f5a544e3bab7 ("ksmbd: add support for SMB3 multichannel")
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Reported-by: Samu <nomomentomori@gmail.com>
Suggested-by: Samu <nomomentomori@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index b5861e830aba3..f30866efe2f4f 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -1745,7 +1745,7 @@ int smb2_sess_setup(struct ksmbd_work *work)
goto out_err;
}
- if (strncmp(conn->ClientGUID, sess->ClientGUID,
+ if (memcmp(conn->ClientGUID, sess->ClientGUID,
SMB2_CLIENT_GUID_SIZE)) {
rc = -ENOENT;
goto out_err;
@@ -7632,7 +7632,7 @@ static int fsctl_validate_negotiate_info(struct ksmbd_conn *conn,
goto err_out;
}
- if (strncmp(neg_req->Guid, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE)) {
+ if (memcmp(neg_req->Guid, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE)) {
ret = -EINVAL;
goto err_out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 314/982] af_unix: Unlink scc_entry in unix_del_edge().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (312 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 313/982] ksmbd: use memcmp() to compare ClientGUIDs Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 315/982] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Greg Kroah-Hartman
` (674 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, Kuniyuki Iwashima,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 594d905195024b228c962627ae5ae7c17bd582a4 ]
Kyle Zeng reported that GC could free a dead SCC partially.
The scenario is as follows:
1) Create two SCCs:
X -. A <-> B
^--'
2) Run the following concurrently:
2-1) send() sk-B to sk-B from sk-X
2-2) close() both A and B
At 2-1), there is a small window where unix_add_edges()
publishes a new edge (B <-> B) to GC but its skb is not queued
by skb_queue_tail().
If 2-2) completes before skb_queue_tail() and GC is triggered,
it judges A <-> B as dead, but B is not freed because GC cannot
collect the not-yet-queued skb holding the B <-> B edge.
X -. A <-> B -. This edge is visible
^--' ^..' but skb is not
This itself is not a problem since the next GC run will judge
B as dead as well and free it finally.
X -. A <.> B -.
^--' ^--'
However, X's SCC forces the next GC to call unix_walk_scc_fast(),
and it iterates over A through B's scc_entry.
Let's unlink scc_entry before freeing the vertex in unix_del_edge().
Fixes: 4090fa373f0e ("af_unix: Replace garbage collection algorithm.")
Reported-by: Kyle Zeng <kylebot@openai.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Kyle Zeng <kylebot@openai.com>
Fixes: 4090fa373f0e ("af_unix: Replace garbage collection algorithm.").
Link: https://patch.msgid.link/20260804002155.2233594-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/unix/garbage.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/unix/garbage.c b/net/unix/garbage.c
index fa6983dc3181d..338769200065e 100644
--- a/net/unix/garbage.c
+++ b/net/unix/garbage.c
@@ -173,6 +173,7 @@ static void unix_del_edge(struct scm_fp_list *fpl, struct unix_edge *edge)
if (!vertex->out_degree) {
edge->predecessor->vertex = NULL;
list_move_tail(&vertex->entry, &fpl->vertices);
+ list_del(&vertex->scc_entry);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 315/982] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (313 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 314/982] af_unix: Unlink scc_entry in unix_del_edge() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 316/982] Revert "Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU" Greg Kroah-Hartman
` (673 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: SJ Park <sj@kernel.org>
commit 123e4619ab6c8ab1c4cb1d7a58311a2af13929cd upstream.
Patch series "mm/damon: unurgent fixes for infinite loop, NULL de-ref and
races", v1.1.
Sashiko found a few issues in DAMON that could cause infinite loop, NULL
dereference and monitoring results degradation. The first two sounds
scary but the infinite loop happens only under unreasonable user setup.
The NULL dereference is only in a unit test. Monitoring results
degradation is trivial since it is only best-effort, and those happens
from only unlikely races. Still those are bugs that better to fix if
possible. Fix those.
This patch (of 6):
Due to online parameter update like events, the number of DAMON regions
could be higher than the user-set upper limit. kdamond_merge_regions()
repeats merge regions until the number meets the limit, while doubling the
merge threshold up to the theoretical maximum threshold. It is tried only
up to the theoretical maximum threshold because even the aggressive
merging can fail from reducing the number of regions under the
user-defined upper limit. For example, there could be many user-defined
non-contiguous regions that cannot be merged.
The threshold based loop break condition is evaluated by comparing the
threshold for the next merging try against the theoretical maximum
threshold. If max_thres is larger than UINT_MAX / 2, doubling the
threshold could make it overflow, and bypass the loop break condition. In
the case, if the number of regions cannot be reduced under the upper limit
like explained above, the loop will run infinitely.
Prevent the case by doing the break condition check before doubling the
threshold. Also, prevent the threshold exceeding the maximum threshold,
as it could overflow and apply the wrong merge threshold.
This issue is unlikely to occur in real world, since having the max_thres
higher than UINT_MAX / 2 require unrealistically large aggregation
intervals compared to the sampling interval. Also, it requires an
unrealistically large number of uncontiguous regions setup. Nonetheless,
the consequence is bad and the fix is simple.
The issue was discovered [1] by Sashiko.
Link: https://lore.kernel.org/20260715031002.108504-1-sj@kernel.org
Link: https://lore.kernel.org/20260715031002.108504-2-sj@kernel.org
Link: https://lore.kernel.org/20260709145425.96247-1-sj@kernel.org [1]
Fixes: 310d6c15e910 ("mm/damon/core: merge regions aggressively when max_nr_regions is unmet")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.10.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/damon/core.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/mm/damon/core.c b/mm/damon/core.c
index 859a6a636ab0e..7afbc20833ea4 100644
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -988,7 +988,7 @@ static void kdamond_merge_regions(struct damon_ctx *c, unsigned int threshold,
max_thres = c->attrs.aggr_interval /
(c->attrs.sample_interval ? c->attrs.sample_interval : 1);
- do {
+ while (true) {
nr_regions = 0;
damon_for_each_target(t, c) {
damon_merge_regions_of(t, threshold, sz_limit,
@@ -996,9 +996,14 @@ static void kdamond_merge_regions(struct damon_ctx *c, unsigned int threshold,
nr_regions += damon_nr_regions(t);
}
count_age = false;
- threshold = max(1, threshold * 2);
- } while (nr_regions > c->attrs.max_nr_regions &&
- threshold / 2 < max_thres);
+ if (nr_regions <= c->attrs.max_nr_regions ||
+ max_thres <= threshold)
+ break;
+ if (threshold < max_thres / 2)
+ threshold = max(1, threshold * 2);
+ else
+ threshold = max_thres;
+ }
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 316/982] Revert "Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (314 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 315/982] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 317/982] Revert "Bluetooth: btusb: Add ASUS USB-BT540 " Greg Kroah-Hartman
` (672 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 566d0ed699a17e4a52e5ba18a73a548c343fa748.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 795a6b3de900d..153b9fbc73f19 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -677,8 +677,6 @@ static const struct usb_device_id blacklist_table[] = {
/* Additional Realtek 8761CU Bluetooth devices */
{ USB_DEVICE(0x0b05, 0x1bef), .driver_info = BTUSB_REALTEK |
BTUSB_WIDEBAND_SPEECH },
- { USB_DEVICE(0x0b05, 0x1d70), .driver_info = BTUSB_REALTEK |
- BTUSB_WIDEBAND_SPEECH },
/* Additional Realtek 8821AE Bluetooth devices */
{ USB_DEVICE(0x0b05, 0x17dc), .driver_info = BTUSB_REALTEK },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 317/982] Revert "Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (315 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 316/982] Revert "Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU" Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 318/982] ARM: 9484/1: enable interrupts when unhandled user faults are triggered Greg Kroah-Hartman
` (671 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 128aa24b355690e76babcaa463c29618b20a4ac9.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 153b9fbc73f19..e545cf1abd0ea 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -674,10 +674,6 @@ static const struct usb_device_id blacklist_table[] = {
{ USB_DEVICE(0x7392, 0xc611), .driver_info = BTUSB_REALTEK |
BTUSB_WIDEBAND_SPEECH },
- /* Additional Realtek 8761CU Bluetooth devices */
- { USB_DEVICE(0x0b05, 0x1bef), .driver_info = BTUSB_REALTEK |
- BTUSB_WIDEBAND_SPEECH },
-
/* Additional Realtek 8821AE Bluetooth devices */
{ USB_DEVICE(0x0b05, 0x17dc), .driver_info = BTUSB_REALTEK },
{ USB_DEVICE(0x13d3, 0x3414), .driver_info = BTUSB_REALTEK },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 318/982] ARM: 9484/1: enable interrupts when unhandled user faults are triggered
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (316 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 317/982] Revert "Bluetooth: btusb: Add ASUS USB-BT540 " Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 319/982] ARM: ensure interrupts are enabled in __do_user_fault() Greg Kroah-Hartman
` (670 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Russell King,
Sebastian Andrzej Siewior, Linus Walleij, Xie Yuanbin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xie Yuanbin <xieyuanbin1@huawei.com>
[ Upstream commit e79ca91165d4fd18549c536abdb86101e889052f ]
PREEMPT_RT requires interrupts to be enabled when sending signals.
When do_DataAbort()/do_PrefetchAbort() triggers unhandled user faults,
that is `inf->fn()` return a non-zero value, and the interrupts are not
enabled within the hook function, force_sig_fault() will be called
with interrupts disabled.
This can be triggered by user programs executing the bkpt instruction,
with kernel config CONFIG_PERF_EVENTS=n.
Enable interrupts in do_DataAbort()/do_PrefetchAbort() when unhandled
user faults are triggered to fix the issue.
Fixes: c6e61c06d606 ("ARM: 9463/1: Allow to enable RT")
Link: https://lore.kernel.org/20260629123349.134224-1-xieyuanbin1@huawei.com
Suggested-by: Russell King <rmk+kernel@armlinux.org.uk>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Xie Yuanbin <xieyuanbin1@huawei.com>
Signed-off-by: Russell King <rmk+kernel@armlinux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mm/fault.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/arch/arm/mm/fault.c b/arch/arm/mm/fault.c
index 29a995c6d7c6b..1010e808e2308 100644
--- a/arch/arm/mm/fault.c
+++ b/arch/arm/mm/fault.c
@@ -583,6 +583,9 @@ do_DataAbort(unsigned long addr, unsigned int fsr, struct pt_regs *regs)
if (!inf->fn(addr, fsr & ~FSR_LNX_PF, regs))
return;
+ if (likely(user_mode(regs)))
+ local_irq_enable();
+
pr_alert("8<--- cut here ---\n");
pr_alert("Unhandled fault: %s (0x%03x) at 0x%08lx\n",
inf->name, fsr, addr);
@@ -621,6 +624,9 @@ do_PrefetchAbort(unsigned long addr, unsigned int ifsr, struct pt_regs *regs)
if (!inf->fn(addr, ifsr | FSR_LNX_PF, regs))
return;
+ if (likely(user_mode(regs)))
+ local_irq_enable();
+
pr_alert("8<--- cut here ---\n");
pr_alert("Unhandled prefetch abort: %s (0x%03x) at 0x%08lx\n",
inf->name, ifsr, addr);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 319/982] ARM: ensure interrupts are enabled in __do_user_fault()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (317 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 318/982] ARM: 9484/1: enable interrupts when unhandled user faults are triggered Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 320/982] EDAC/igen6: Fix interleave boundary condition Greg Kroah-Hartman
` (669 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yadi.hu, Sebastian Andrzej Siewior,
Russell King (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
[ Upstream commit 59e4f3b45b96a24fc9b7a89e5f8a2168b30f95af ]
__do_user_fault() may be called from fault handling paths where the
interrupts are enabled or disabled. E.g. do_page_fault() calls this
with interrupts enabled, whereas do_sect_fault()->do_bad_area()
will call this with interrupts disabled. Since this is a userspace
fault, we know that interrupts were enabled in the parent context,
so call local_irq_enable() here to give a consistent interrupt state.
This is necessary for force_sig_info() when PREEMPT_RT is enabled.
Reported-by: Yadi.hu <yadi.hu@windriver.com>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mm/fault.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/arch/arm/mm/fault.c b/arch/arm/mm/fault.c
index 1010e808e2308..3d15acacc6866 100644
--- a/arch/arm/mm/fault.c
+++ b/arch/arm/mm/fault.c
@@ -187,7 +187,8 @@ __do_kernel_fault(struct mm_struct *mm, unsigned long addr, unsigned int fsr,
/*
* Something tried to access memory that isn't in our memory map..
- * User mode accesses just cause a SIGSEGV
+ * User mode accesses just cause a SIGSEGV. Ensure interrupts are enabled
+ * for preempt RT.
*/
static void
__do_user_fault(unsigned long addr, unsigned int fsr, unsigned int sig,
@@ -195,6 +196,8 @@ __do_user_fault(unsigned long addr, unsigned int fsr, unsigned int sig,
{
struct task_struct *tsk = current;
+ local_irq_enable();
+
#ifdef CONFIG_DEBUG_USER
if (((user_debug & UDBG_SEGV) && (sig == SIGSEGV)) ||
((user_debug & UDBG_BUS) && (sig == SIGBUS))) {
@@ -251,6 +254,7 @@ do_kernel_address_page_fault(struct mm_struct *mm, unsigned long addr,
* should not be faulting in kernel space, which includes the
* vector/khelper page. Handle the branch predictor hardening
* while interrupts are still disabled, then send a SIGSEGV.
+ * Note that __do_user_fault() will enable interrupts.
*/
harden_branch_predictor();
__do_user_fault(addr, fsr, SIGSEGV, SEGV_MAPERR, regs);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 320/982] EDAC/igen6: Fix interleave boundary condition
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (318 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 319/982] ARM: ensure interrupts are enabled in __do_user_fault() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 321/982] EDAC/igen6: Fix channel selection hash Greg Kroah-Hartman
` (668 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Qiuxu Zhuo, Tony Luck, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
[ Upstream commit f4008169bd320eedb9ddf2b39eeb21370ddac278 ]
The address translation logic splits the memory space into interleaved
and non-interleaved regions using a boundary at 2 * s_size.
The current check uses '>' and incorrectly classifies the boundary
address (2 * s_size) as part of the interleaved region. This leads to
incorrect channel/sub-channel selection at the region boundary.
Fix the classification by using '>=' so that the boundary address is
handled in the non-interleaved region, matching the hardware layout.
Fixes: 10590a9d4f23 ("EDAC/igen6: Add EDAC driver for Intel client SoCs using IBECC")
Signed-off-by: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/20260730024238.4096623-3-qiuxu.zhuo@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/edac/igen6_edac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/edac/igen6_edac.c b/drivers/edac/igen6_edac.c
index 0ab8642c4e55a..8201e92714c68 100644
--- a/drivers/edac/igen6_edac.c
+++ b/drivers/edac/igen6_edac.c
@@ -493,7 +493,7 @@ static void decode_addr(u64 addr, u32 hash, u64 s_size, int l_map,
{
int intlv_bit = CHANNEL_HASH_LSB_MASK_BIT(hash) + 6;
- if (addr > 2 * s_size) {
+ if (addr >= 2 * s_size) {
*sub_addr = addr - s_size;
*idx = l_map;
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 321/982] EDAC/igen6: Fix channel selection hash
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (319 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 320/982] EDAC/igen6: Fix interleave boundary condition Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 322/982] EDAC/igen6: Fix channel address decode for non-hash mode Greg Kroah-Hartman
` (667 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Qiuxu Zhuo, Tony Luck, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
[ Upstream commit 540b79536f3a89a66c5b6c490110298d43025618 ]
In channel selection hash mode, the hardware decoding logic always
includes the channel interleave bit in XOR operations. However, the
hash mask may or may not include this channel interleave bit. When
the mask does include this bit, the current igen6_edac code performs
XOR on the interleave bit twice, effectively ignoring it - which is
incorrect.
Fix this issue by ensuring the hash mask always includes the interleave
bit, so XOR is performed on the interleave bit exactly once.
Fixes: 10590a9d4f23 ("EDAC/igen6: Add EDAC driver for Intel client SoCs using IBECC")
Signed-off-by: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/20260730024238.4096623-4-qiuxu.zhuo@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/edac/igen6_edac.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/drivers/edac/igen6_edac.c b/drivers/edac/igen6_edac.c
index 8201e92714c68..d91b775173621 100644
--- a/drivers/edac/igen6_edac.c
+++ b/drivers/edac/igen6_edac.c
@@ -467,14 +467,22 @@ static enum mem_type get_memory_type(u32 mad_inter)
static int decode_chan_idx(u64 addr, u64 mask, int intlv_bit)
{
- u64 hash_addr = addr & mask, hash = 0;
- u64 intlv = (addr >> intlv_bit) & 1;
+ u64 hash_addr, hash = 0;
int i;
+ /*
+ * In hash mode, the @intlv_bit is the lowest selected bit of @addr
+ * to be XORed. While @mask may or may not include this @intlv_bit,
+ * we enforce that @mask includes @intlv_bit to ensure @intlv_bit is
+ * XORed exactly once.
+ */
+ mask |= 1 << intlv_bit;
+ hash_addr = addr & mask;
+
for (i = 6; i < 20; i++)
hash ^= (hash_addr >> i) & 1;
- return (int)hash ^ intlv;
+ return (int)hash;
}
static u64 decode_channel_addr(u64 addr, int intlv_bit)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 322/982] EDAC/igen6: Fix channel address decode for non-hash mode
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (320 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 321/982] EDAC/igen6: Fix channel selection hash Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 323/982] EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation Greg Kroah-Hartman
` (666 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Qiuxu Zhuo, Tony Luck, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
[ Upstream commit 7b348d0d401d478f1923ba20a34a61681d1f7971 ]
In non-hash mode, decode_channel_addr() and channel index extraction
used a hardcoded interleave bit position 6 instead of the actual
intlv_bit parameter, causing incorrect channel address decoding.
Fix this by using intlv_bit consistently in both hash and non-hash modes.
Fixes: 10590a9d4f23 ("EDAC/igen6: Add EDAC driver for Intel client SoCs using IBECC")
Signed-off-by: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/20260730024238.4096623-5-qiuxu.zhuo@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/edac/igen6_edac.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/drivers/edac/igen6_edac.c b/drivers/edac/igen6_edac.c
index d91b775173621..97468fbf17b74 100644
--- a/drivers/edac/igen6_edac.c
+++ b/drivers/edac/igen6_edac.c
@@ -507,13 +507,12 @@ static void decode_addr(u64 addr, u32 hash, u64 s_size, int l_map,
return;
}
- if (CHANNEL_HASH_MODE(hash)) {
- *sub_addr = decode_channel_addr(addr, intlv_bit);
+ *sub_addr = decode_channel_addr(addr, intlv_bit);
+
+ if (CHANNEL_HASH_MODE(hash))
*idx = decode_chan_idx(addr, CHANNEL_HASH_MASK(hash), intlv_bit);
- } else {
- *sub_addr = decode_channel_addr(addr, 6);
- *idx = GET_BITFIELD(addr, 6, 6);
- }
+ else
+ *idx = GET_BITFIELD(addr, intlv_bit, intlv_bit);
}
static int igen6_decode(struct decoded_addr *res)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 323/982] EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (321 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 322/982] EDAC/igen6: Fix channel address decode for non-hash mode Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 324/982] drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() Greg Kroah-Hartman
` (665 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jad Keskes, Borislav Petkov (AMD),
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jad Keskes <inasj268@gmail.com>
[ Upstream commit 66cc9dec919dd63d8e4b3d386f7aed3ae684e645 ]
The poll_msec sysfs store file uses simple_strtoul() which accepts an unsigned
long, but the target field (poll_msec) is unsigned int. On 64-bit systems,
a value > UINT_MAX is silently truncated when stored.
Fix the mismatch by using kstrtouint() instead. This rejects values larger
than UINT_MAX at parse time, making truncation impossible. Also add a check
for value < 1 to reject the 0-delay case, which would cause the poll work to
spin without delay and consume 100% CPU.
Fixes: e27e3dac6517 ("drivers/edac: add edac_device class")
Signed-off-by: Jad Keskes <inasj268@gmail.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://patch.msgid.link/20260730145549.148229-1-inasj268@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/edac/edac_device_sysfs.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/edac/edac_device_sysfs.c b/drivers/edac/edac_device_sysfs.c
index ac678b4a21fcb..e2ee5c6c56d3b 100644
--- a/drivers/edac/edac_device_sysfs.c
+++ b/drivers/edac/edac_device_sysfs.c
@@ -90,14 +90,21 @@ static ssize_t edac_device_ctl_poll_msec_store(struct edac_device_ctl_info
*ctl_info, const char *data,
size_t count)
{
- unsigned long value;
+ unsigned int value;
+ int ret;
/* get the value and enforce that it is non-zero, must be at least
* one millisecond for the delay period, between scans
* Then cancel last outstanding delay for the work request
* and set a new one.
*/
- value = simple_strtoul(data, NULL, 0);
+ ret = kstrtouint(data, 0, &value);
+ if (ret < 0)
+ return ret;
+
+ if (value < 1)
+ return -EINVAL;
+
edac_device_reset_delay_period(ctl_info, value);
return count;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 324/982] drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (322 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 323/982] EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 325/982] nvme-rdma: fix -EIO cleanup order in queue_rq Greg Kroah-Hartman
` (664 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Dmitry Osipenko,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <error27@gmail.com>
[ Upstream commit 94579f24e2b526a04eb41050af0ba018c6f528e7 ]
Smatch complains that returning a NULL here will lead to a NULL pointer
dereference in drm_mode_addfb2(). Return an error pointer instead.
Fixes: dc5698e80cf7 ("Add virtio gpu driver.")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/an1tWfHIHwtXd9SO@stanley.mountain
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_display.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_display.c b/drivers/gpu/drm/virtio/virtgpu_display.c
index 9ea7611a9e0fc..77d52d7e3a39c 100644
--- a/drivers/gpu/drm/virtio/virtgpu_display.c
+++ b/drivers/gpu/drm/virtio/virtgpu_display.c
@@ -320,7 +320,7 @@ virtio_gpu_user_framebuffer_create(struct drm_device *dev,
if (ret) {
kfree(virtio_gpu_fb);
drm_gem_object_put(obj);
- return NULL;
+ return ERR_PTR(ret);
}
return &virtio_gpu_fb->base;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 325/982] nvme-rdma: fix -EIO cleanup order in queue_rq
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (323 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 324/982] drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 326/982] selftests/cgroup: Fix cg_run_in_subcgroups ignoring arg parameter Greg Kroah-Hartman
` (663 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Xixin Liu,
Keith Busch, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit d61828199c6cb4b76d48403c77023cd4bb9d09fc ]
On -EIO, the RDMA queue_rq path reports a host path error and then
still cleans up the command and unmaps the SQE DMA. The path error
helper completes the request, so that is double cleanup and DMA unmap
after the request is already complete.
Unmap the SQE first, then report the host path error. Skip the outer
command cleanup on that path.
Fixes: 62eca39722fd ("nvme-rdma: handle nvme_rdma_post_send failures better")
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/rdma.c | 18 ++++++++++--------
1 file changed, 10 insertions(+), 8 deletions(-)
diff --git a/drivers/nvme/host/rdma.c b/drivers/nvme/host/rdma.c
index 8f511240addd7..ac76f1ac17090 100644
--- a/drivers/nvme/host/rdma.c
+++ b/drivers/nvme/host/rdma.c
@@ -2022,7 +2022,7 @@ static blk_status_t nvme_rdma_queue_rq(struct blk_mq_hw_ctx *hctx,
struct ib_device *dev;
bool queue_ready = test_bit(NVME_RDMA_Q_LIVE, &queue->flags);
blk_status_t ret;
- int err;
+ int err = 0;
WARN_ON_ONCE(rq->tag < 0);
@@ -2078,16 +2078,18 @@ static blk_status_t nvme_rdma_queue_rq(struct blk_mq_hw_ctx *hctx,
err_unmap:
nvme_rdma_unmap_data(queue, rq);
err:
- if (err == -EIO)
- ret = nvme_host_path_error(rq);
- else if (err == -ENOMEM || err == -EAGAIN)
- ret = BLK_STS_RESOURCE;
- else
- ret = BLK_STS_IOERR;
- nvme_cleanup_cmd(rq);
+ if (err != -EIO) {
+ nvme_cleanup_cmd(rq);
+ if (err == -ENOMEM || err == -EAGAIN)
+ ret = BLK_STS_RESOURCE;
+ else
+ ret = BLK_STS_IOERR;
+ }
unmap_qe:
ib_dma_unmap_single(dev, req->sqe.dma, sizeof(struct nvme_command),
DMA_TO_DEVICE);
+ if (err == -EIO)
+ return nvme_host_path_error(rq);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 326/982] selftests/cgroup: Fix cg_run_in_subcgroups ignoring arg parameter
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (324 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 325/982] nvme-rdma: fix -EIO cleanup order in queue_rq Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 327/982] net: icmp: avoid invalid transport header access in icmp_send tracepoint Greg Kroah-Hartman
` (662 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hongfu Li, Michal Koutný,
Tejun Heo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongfu Li <lihongfu@kylinos.cn>
[ Upstream commit a8c6daab4b0e276508b7ffdd66c60fd3020a9178 ]
cg_run_in_subcgroups() discards its arg and always passes NULL to cg_run(),
turning the (void *)100 from test_kmem_dead_cgroups() into NULL so no
allocation occurs.
This makes test_kmem_dead_cgroups() falsely pass without exercising the
"dying cgroup with charged slab" scenario it intends to test.
Pass the arg through to cg_run() to fix this.
Fixes: 933dc80ec262 ("kselftests: cgroup: add kernel memory accounting tests")
Signed-off-by: Hongfu Li <lihongfu@kylinos.cn>
Reviewed-by: Michal Koutný <mkoutny@suse.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/cgroup/test_kmem.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/cgroup/test_kmem.c b/tools/testing/selftests/cgroup/test_kmem.c
index 258ddc565deba..89823fa0cf6d9 100644
--- a/tools/testing/selftests/cgroup/test_kmem.c
+++ b/tools/testing/selftests/cgroup/test_kmem.c
@@ -140,7 +140,7 @@ static int cg_run_in_subcgroups(const char *parent,
return -1;
}
- if (cg_run(child, fn, NULL)) {
+ if (cg_run(child, fn, arg)) {
cg_destroy(child);
free(child);
return -1;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 327/982] net: icmp: avoid invalid transport header access in icmp_send tracepoint
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (325 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 326/982] selftests/cgroup: Fix cg_run_in_subcgroups ignoring arg parameter Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 328/982] net/sched: act_api: budget all shared attributes in notify skbs Greg Kroah-Hartman
` (661 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+6d2762674103618994b0,
Eric Dumazet, Peilin He, xu xin, Steven Rostedt, Jiayuan Chen,
David Ahern, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 7fcc2fe39fed1cb98a7374a113ff3800e8f9af80 ]
syzbot reported a WARNING triggered by DEBUG_NET_WARN_ON_ONCE():
WARNING: at skb_transport_header include/linux/skbuff.h:3087 [inline]
WARNING: at udp_hdr include/linux/udp.h:23 [inline]
WARNING: at do_trace_event_raw_event_icmp_send include/trace/events/icmp.h:30 [inline]
WARNING: at trace_event_raw_event_icmp_send+0x48c/0x6ec include/trace/events/icmp.h:11
Call trace:
skb_transport_header include/linux/skbuff.h:3087 [inline]
udp_hdr include/linux/udp.h:23 [inline]
do_trace_event_raw_event_icmp_send include/trace/events/icmp.h:30 [inline]
trace_event_raw_event_icmp_send+0x48c/0x6ec include/trace/events/icmp.h:11
__traceiter_icmp_send include/trace/events/icmp.h:11 [inline]
__do_trace_icmp_send include/trace/events/icmp.h:11 [inline]
trace_icmp_send+0x320/0x49c include/trace/events/icmp.h:11
__icmp_send+0xcfc/0x11d8 net/ipv4/icmp.c:1013
ipv4_send_dest_unreach net/ipv4/route.c:1280 [inline]
ipv4_link_failure+0x57c/0x8dc net/ipv4/route.c:1287
dst_link_failure include/net/dst.h:438 [inline]
vti_tunnel_xmit+0xe40/0x17a4 net/ipv4/ip_vti.c:307
TP_fast_assign() unconditionally calls udp_hdr(skb) before checking
whether the packet is UDP. Furthermore, __icmp_send() can be invoked
from paths (e.g., link failures, ARP errors, forwarding, AF_PACKET)
where skb->transport_header was never initialized (~0U).
Under CONFIG_DEBUG_NET=y, calling skb_transport_header(skb) triggers
DEBUG_NET_WARN_ON_ONCE(!skb_transport_header_was_set(skb)).
Fix this by:
1. Only parsing transport info when iph->protocol == IPPROTO_UDP.
2. Using skb_header_pointer() at skb_network_offset(skb) + (iph->ihl << 2)
to safely fetch the UDP header without assuming transport_header is set.
Fixes: db3efdcf70c7 ("net/ipv4: add tracepoint for icmp_send")
Reported-by: syzbot+6d2762674103618994b0@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a8d5538.91706f20.ef82.0009.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Peilin He <he.peilin@zte.com.cn>
Cc: xu xin <xu.xin16@zte.com.cn>
Cc: Steven Rostedt <rostedt@goodmis.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260825084551.1562967-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/trace/events/icmp.h | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/include/trace/events/icmp.h b/include/trace/events/icmp.h
index 31559796949a7..acfcf2b132d60 100644
--- a/include/trace/events/icmp.h
+++ b/include/trace/events/icmp.h
@@ -27,17 +27,20 @@ TRACE_EVENT(icmp_send,
TP_fast_assign(
struct iphdr *iph = ip_hdr(skb);
- struct udphdr *uh = udp_hdr(skb);
- int proto_4 = iph->protocol;
+ struct udphdr _uh, *uh = NULL;
__be32 *p32;
__entry->skbaddr = skb;
__entry->type = type;
__entry->code = code;
- if (proto_4 != IPPROTO_UDP || (u8 *)uh < skb->head ||
- (u8 *)uh + sizeof(struct udphdr)
- > skb_tail_pointer(skb)) {
+ if (iph->protocol == IPPROTO_UDP)
+ uh = skb_header_pointer(skb,
+ skb_network_offset(skb) +
+ (iph->ihl << 2),
+ sizeof(_uh), &_uh);
+
+ if (!uh) {
__entry->sport = 0;
__entry->dport = 0;
__entry->ulen = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 328/982] net/sched: act_api: budget all shared attributes in notify skbs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (326 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 327/982] net: icmp: avoid invalid transport header access in icmp_send tracepoint Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 329/982] net/sched: act_api: size the RTM_GETACTION reply from the actions Greg Kroah-Hartman
` (660 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Jamal Hadi Salim,
Victor Nogueira, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Victor Nogueira <victor@mojatatu.com>
[ Upstream commit 13eb543cebef6d6c3ec42e31afe3856f51b7126b ]
tcf_action_shared_attrs_size() is supposed to return an upper bound on the
netlink attributes every action dump emits outside of TCA_ACT_OPTIONS, so
that tcf_add_notify_msg(), tcf_del_notify_msg() and friends can allocate
an skb large enough for the reply. It has fallen behind the dump path and
is now an underestimate for every single action.
Attributes, such as, TCA_ACT_IN_HW_COUNT and TCA_STATS_BASIC_HW are
emitted unconditionally and never accounted for. TCA_STATS_PKT64,
TCA_ACT_USED_HW_STATS, TCA_STATS_RATE_EST, TCA_STATS_RATE_EST64 require
specific conditions, but are also not accounted for.
Fix the issue by budgeting all of them so that we have a legitimate
upper bound. Even tough for of them require specific conditions, they
are cheap so, to avoid overcomplicating, we opted to account for them
unconditionally as well to account for a real worst case scenario.
Fixes: 4e76e75d6aba ("net sched actions: calculate add/delete event message size")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260810164357.1653956-1-victor%40mojatatu.com
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260824153903.4143642-2-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_api.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index 47f0d4c3dc487..b3fb160765dbe 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -446,12 +446,21 @@ static size_t tcf_action_shared_attrs_size(const struct tc_action *act)
+ nla_total_size(IFNAMSIZ) /* TCA_ACT_KIND */
+ cookie_len /* TCA_ACT_COOKIE */
+ nla_total_size(sizeof(struct nla_bitfield32)) /* TCA_ACT_HW_STATS */
+ /* TCA_ACT_USED_HW_STATS */
+ + nla_total_size(sizeof(struct nla_bitfield32))
+ + nla_total_size(sizeof(u32)) /* TCA_ACT_IN_HW_COUNT */
+ nla_total_size(0) /* TCA_ACT_STATS nested */
+ nla_total_size(sizeof(struct nla_bitfield32)) /* TCA_ACT_FLAGS */
/* TCA_STATS_BASIC */
+ nla_total_size_64bit(sizeof(struct gnet_stats_basic))
- /* TCA_STATS_PKT64 */
- + nla_total_size_64bit(sizeof(u64))
+ /* TCA_STATS_BASIC_HW */
+ + nla_total_size_64bit(sizeof(struct gnet_stats_basic))
+ /* TCA_STATS_PKT64, emitted by both of the basic copies above */
+ + 2 * nla_total_size_64bit(sizeof(u64))
+ /* TCA_STATS_RATE_EST */
+ + nla_total_size_64bit(sizeof(struct gnet_stats_rate_est))
+ /* TCA_STATS_RATE_EST64 */
+ + nla_total_size_64bit(sizeof(struct gnet_stats_rate_est64))
/* TCA_STATS_QUEUE */
+ nla_total_size_64bit(sizeof(struct gnet_stats_queue))
+ nla_total_size(0) /* TCA_OPTIONS nested */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 329/982] net/sched: act_api: size the RTM_GETACTION reply from the actions
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (327 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 328/982] net/sched: act_api: budget all shared attributes in notify skbs Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 330/982] rtnl: add helper to send if skb is not null Greg Kroah-Hartman
` (659 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Jamal Hadi Salim,
Victor Nogueira, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Victor Nogueira <victor@mojatatu.com>
[ Upstream commit e9ca46ebc3262b498626c4095826b8fa034bbf21 ]
tca_action_gd() already walks every requested action and accumulates
attr_size += tcf_action_fill_size(act), then wraps the result in
tcf_action_full_attrs_size(). For RTM_DELACTION that value is handed to
tcf_del_notify_msg(), which allocates max(attr_size, NLMSG_GOODSIZE). For
RTM_GETACTION it is silently discarded and tcf_get_notify() allocates a
fixed NLMSG_GOODSIZE skb instead.
Any action whose dump exceeds that fixed budget therefore cannot be read
back. For example, act_pedit overruns the budget with 32 actions of four
munge keys each, act_police with 32 policers once the optional
rate/peakrate/result/avrate attributes are present
Fix this by passing attr_size through and allocate the reply the way the
add and delete paths do.
Note on exposure: RTM_GETACTION is the only one of the three action
commands that is not capability checked - tc_ctl_action() requires
CAP_NET_ADMIN for RTM_NEWACTION and RTM_DELACTION only - so this turns a
fixed NLMSG_GOODSIZE reply into a user sized allocation on an
unprivileged path. It is bounded by TCA_ACT_MAX_PRIO actions per
request, and tca_action_gd() does not reject duplicate indices, so a
single large action can be requested 32 times; an act_bpf program near
BPF_MAXINSNS is about 32KB of dump, or roughly 1MB for one request.
Creating such an action still requires CAP_NET_ADMIN, and the add and
delete paths have sized their skbs this way since the Fixes commit.
Should this ever need bounding, GFP_KERNEL_ACCOUNT would charge the
reply to the caller's memcg.
Fixes: 4e76e75d6aba ("net sched actions: calculate add/delete event message size")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260810164357.1653956-1-victor%40mojatatu.com
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260824153903.4143642-3-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_api.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index b3fb160765dbe..26dd0158f14ef 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -1665,12 +1665,12 @@ static int tca_get_fill(struct sk_buff *skb, struct tc_action *actions[],
static int
tcf_get_notify(struct net *net, u32 portid, struct nlmsghdr *n,
- struct tc_action *actions[], int event,
+ struct tc_action *actions[], size_t attr_size, int event,
struct netlink_ext_ack *extack)
{
struct sk_buff *skb;
- skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
+ skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
return -ENOBUFS;
if (tca_get_fill(skb, actions, portid, n->nlmsg_seq, 0, event,
@@ -1990,7 +1990,8 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
attr_size = tcf_action_full_attrs_size(attr_size);
if (event == RTM_GETACTION)
- ret = tcf_get_notify(net, portid, n, actions, event, extack);
+ ret = tcf_get_notify(net, portid, n, actions, attr_size, event,
+ extack);
else { /* delete */
ret = tcf_del_notify(net, n, actions, portid, attr_size, extack);
if (ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 330/982] rtnl: add helper to send if skb is not null
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (328 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 329/982] net/sched: act_api: size the RTM_GETACTION reply from the actions Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 331/982] net/sched: act_api: dont open code max() Greg Kroah-Hartman
` (658 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiri Pirko, Simon Horman,
Pedro Tammela, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pedro Tammela <pctammela@mojatatu.com>
[ Upstream commit ddb6b284bdc32b6e218b3d90b5a745ea26620812 ]
This is a convenience helper for routines handling conditional rtnl
events, that is code that might send a notification depending on
rtnl_has_listeners/rtnl_notify_needed.
Instead of:
if (skb)
rtnetlink_send(...)
Use:
rtnetlink_maybe_send(...)
Reviewed-by: Jiri Pirko <jiri@nvidia.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Pedro Tammela <pctammela@mojatatu.com>
Link: https://lore.kernel.org/r/20231208192847.714940-4-pctammela@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 251367a0a331 ("net/sched: act_api: fix skb sizing and action leak on reoffload delete")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/rtnetlink.h | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/include/linux/rtnetlink.h b/include/linux/rtnetlink.h
index 9494b7647e812..a01bd720e7cdd 100644
--- a/include/linux/rtnetlink.h
+++ b/include/linux/rtnetlink.h
@@ -10,6 +10,13 @@
#include <uapi/linux/rtnetlink.h>
extern int rtnetlink_send(struct sk_buff *skb, struct net *net, u32 pid, u32 group, int echo);
+
+static inline int rtnetlink_maybe_send(struct sk_buff *skb, struct net *net,
+ u32 pid, u32 group, int echo)
+{
+ return !skb ? 0 : rtnetlink_send(skb, net, pid, group, echo);
+}
+
extern int rtnl_unicast(struct sk_buff *skb, struct net *net, u32 pid);
extern void rtnl_notify(struct sk_buff *skb, struct net *net, u32 pid,
u32 group, const struct nlmsghdr *nlh, gfp_t flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 331/982] net/sched: act_api: dont open code max()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (329 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 330/982] rtnl: add helper to send if skb is not null Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 332/982] net/sched: act_api: conditional notification of events Greg Kroah-Hartman
` (657 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pedro Tammela, Jiri Pirko,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pedro Tammela <pctammela@mojatatu.com>
[ Upstream commit c73724bfde0932cb0cafff2855e8ce81e12fd594 ]
Use max() in a couple of places that are open coding it with the
ternary operator.
Signed-off-by: Pedro Tammela <pctammela@mojatatu.com>
Reviewed-by: Jiri Pirko <jiri@nvidia.com>
Link: https://lore.kernel.org/r/20231208192847.714940-5-pctammela@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 251367a0a331 ("net/sched: act_api: fix skb sizing and action leak on reoffload delete")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_api.c | 9 +++------
1 file changed, 3 insertions(+), 6 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index 26dd0158f14ef..e68c1cacb5e58 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -1843,8 +1843,7 @@ tcf_reoffload_del_notify(struct net *net, struct tc_action *action)
struct sk_buff *skb;
int ret;
- skb = alloc_skb(attr_size <= NLMSG_GOODSIZE ? NLMSG_GOODSIZE : attr_size,
- GFP_KERNEL);
+ skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
return -ENOBUFS;
@@ -1929,8 +1928,7 @@ tcf_del_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
int ret;
struct sk_buff *skb;
- skb = alloc_skb(attr_size <= NLMSG_GOODSIZE ? NLMSG_GOODSIZE : attr_size,
- GFP_KERNEL);
+ skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
return -ENOBUFS;
@@ -2009,8 +2007,7 @@ tcf_add_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
{
struct sk_buff *skb;
- skb = alloc_skb(attr_size <= NLMSG_GOODSIZE ? NLMSG_GOODSIZE : attr_size,
- GFP_KERNEL);
+ skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
return -ENOBUFS;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 332/982] net/sched: act_api: conditional notification of events
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (330 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 331/982] net/sched: act_api: dont open code max() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 333/982] net/sched: act_api: fix skb sizing and action leak on reoffload delete Greg Kroah-Hartman
` (656 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pedro Tammela, Jiri Pirko,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pedro Tammela <pctammela@mojatatu.com>
[ Upstream commit 8d4390f51920c1edb2d09d44d918c7940ac51e54 ]
As of today tc-action events are unconditionally built and sent to
RTNLGRP_TC. As with the introduction of rtnl_notify_needed we can check
before-hand if they are really needed.
Signed-off-by: Pedro Tammela <pctammela@mojatatu.com>
Reviewed-by: Jiri Pirko <jiri@nvidia.com>
Link: https://lore.kernel.org/r/20231208192847.714940-6-pctammela@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 251367a0a331 ("net/sched: act_api: fix skb sizing and action leak on reoffload delete")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_api.c | 98 ++++++++++++++++++++++++++++++++++-----------
1 file changed, 75 insertions(+), 23 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index e68c1cacb5e58..8b81c25b3e8b2 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -1832,30 +1832,45 @@ static int tcf_action_delete(struct net *net, struct tc_action *actions[])
return 0;
}
-static int
-tcf_reoffload_del_notify(struct net *net, struct tc_action *action)
+static struct sk_buff *tcf_reoffload_del_notify_msg(struct net *net,
+ struct tc_action *action)
{
size_t attr_size = tcf_action_fill_size(action);
struct tc_action *actions[TCA_ACT_MAX_PRIO] = {
[0] = action,
};
- const struct tc_action_ops *ops = action->ops;
struct sk_buff *skb;
- int ret;
skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
- return -ENOBUFS;
+ return ERR_PTR(-ENOBUFS);
if (tca_get_fill(skb, actions, 0, 0, 0, RTM_DELACTION, 0, 1, NULL) <= 0) {
kfree_skb(skb);
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
+ }
+
+ return skb;
+}
+
+static int tcf_reoffload_del_notify(struct net *net, struct tc_action *action)
+{
+ const struct tc_action_ops *ops = action->ops;
+ struct sk_buff *skb;
+ int ret;
+
+ if (!rtnl_notify_needed(net, 0, RTNLGRP_TC)) {
+ skb = NULL;
+ } else {
+ skb = tcf_reoffload_del_notify_msg(net, action);
+ if (IS_ERR(skb))
+ return PTR_ERR(skb);
}
ret = tcf_idr_release_unsafe(action);
if (ret == ACT_P_DELETED) {
module_put(ops->owner);
- ret = rtnetlink_send(skb, net, 0, RTNLGRP_TC, 0);
+ ret = rtnetlink_maybe_send(skb, net, 0, RTNLGRP_TC, 0);
} else {
kfree_skb(skb);
}
@@ -1921,22 +1936,41 @@ int tcf_action_reoffload_cb(flow_indr_block_bind_cb_t *cb,
return 0;
}
-static int
-tcf_del_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
- u32 portid, size_t attr_size, struct netlink_ext_ack *extack)
+static struct sk_buff *tcf_del_notify_msg(struct net *net, struct nlmsghdr *n,
+ struct tc_action *actions[],
+ u32 portid, size_t attr_size,
+ struct netlink_ext_ack *extack)
{
- int ret;
struct sk_buff *skb;
skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
- return -ENOBUFS;
+ return ERR_PTR(-ENOBUFS);
if (tca_get_fill(skb, actions, portid, n->nlmsg_seq, 0, RTM_DELACTION,
0, 2, extack) <= 0) {
NL_SET_ERR_MSG(extack, "Failed to fill netlink TC action attributes");
kfree_skb(skb);
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
+ }
+
+ return skb;
+}
+
+static int tcf_del_notify(struct net *net, struct nlmsghdr *n,
+ struct tc_action *actions[], u32 portid,
+ size_t attr_size, struct netlink_ext_ack *extack)
+{
+ struct sk_buff *skb;
+ int ret;
+
+ if (!rtnl_notify_needed(net, n->nlmsg_flags, RTNLGRP_TC)) {
+ skb = NULL;
+ } else {
+ skb = tcf_del_notify_msg(net, n, actions, portid, attr_size,
+ extack);
+ if (IS_ERR(skb))
+ return PTR_ERR(skb);
}
/* now do the delete */
@@ -1947,9 +1981,8 @@ tcf_del_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
return ret;
}
- ret = rtnetlink_send(skb, net, portid, RTNLGRP_TC,
- n->nlmsg_flags & NLM_F_ECHO);
- return ret;
+ return rtnetlink_maybe_send(skb, net, portid, RTNLGRP_TC,
+ n->nlmsg_flags & NLM_F_ECHO);
}
static int
@@ -2001,25 +2034,44 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
return ret;
}
-static int
-tcf_add_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
- u32 portid, size_t attr_size, struct netlink_ext_ack *extack)
+static struct sk_buff *tcf_add_notify_msg(struct net *net, struct nlmsghdr *n,
+ struct tc_action *actions[],
+ u32 portid, size_t attr_size,
+ struct netlink_ext_ack *extack)
{
struct sk_buff *skb;
skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
- return -ENOBUFS;
+ return ERR_PTR(-ENOBUFS);
if (tca_get_fill(skb, actions, portid, n->nlmsg_seq, n->nlmsg_flags,
RTM_NEWACTION, 0, 0, extack) <= 0) {
NL_SET_ERR_MSG(extack, "Failed to fill netlink attributes while adding TC action");
kfree_skb(skb);
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
+ }
+
+ return skb;
+}
+
+static int tcf_add_notify(struct net *net, struct nlmsghdr *n,
+ struct tc_action *actions[], u32 portid,
+ size_t attr_size, struct netlink_ext_ack *extack)
+{
+ struct sk_buff *skb;
+
+ if (!rtnl_notify_needed(net, n->nlmsg_flags, RTNLGRP_TC)) {
+ skb = NULL;
+ } else {
+ skb = tcf_add_notify_msg(net, n, actions, portid, attr_size,
+ extack);
+ if (IS_ERR(skb))
+ return PTR_ERR(skb);
}
- return rtnetlink_send(skb, net, portid, RTNLGRP_TC,
- n->nlmsg_flags & NLM_F_ECHO);
+ return rtnetlink_maybe_send(skb, net, portid, RTNLGRP_TC,
+ n->nlmsg_flags & NLM_F_ECHO);
}
static int tcf_action_add(struct net *net, struct nlattr *nla,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 333/982] net/sched: act_api: fix skb sizing and action leak on reoffload delete
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (331 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 332/982] net/sched: act_api: conditional notification of events Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 334/982] sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START Greg Kroah-Hartman
` (655 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Jamal Hadi Salim,
Victor Nogueira, Pedro Tammela, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Victor Nogueira <victor@mojatatu.com>
[ Upstream commit 251367a0a3319fa565daf7468b0afd933b1f5ab1 ]
tcf_reoffload_del_notify_msg() sizes the RTM_DELACTION skb with
tcf_action_fill_size(action) alone. Unlike every other notification path
it never wraps that in tcf_action_full_attrs_size(), so the nlmsg_put()
header, struct tcamsg and the TCA_ACT_TAB nest that tca_get_fill() emits -
24 bytes on x86_64 - are not budgeted. As long as the single action stays
well under NLMSG_GOODSIZE the floor in alloc_skb() hides this, but once its
fill size crosses NLMSG_GOODSIZE the allocation is exactly 24 bytes short
and tca_get_fill() runs out of tailroom. That is now easy to reach for an
offloadable act_pedit with a large tcfp_nkeys, which commit 8e2efb3f45a5
("net/sched: add get_fill_size callbacks for actions missing them") started
accounting for properly.
When that happens tcf_reoffload_del_notify() returns early, before
tcf_idr_release_unsafe(), and tcf_action_reoffload_cb() discards the return
value:
if (tc_act_skip_sw(p->tcfa_flags) && !tc_act_in_hw(p))
tcf_reoffload_del_notify(net, p);
The action has just lost its last hardware instance and is skip_sw, so it
is left installed while processing no packets, and with no notification to
tell userspace about it. An -ENOBUFS from alloc_skb() gets the same
treatment.
Fix this by budgeting the message header the way the add and delete paths
do, and release the action even when the notification cannot be built -
dropping the notification is strictly better than leaking a dead action,
and there is no caller left to report the error to.
Fixes: 13926d19a11e ("flow_offload: add reoffload process to update hw_count")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260810164357.1653956-1-victor%40mojatatu.com
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Reviewed-by: Pedro Tammela <pctammela@mojatatu.com>
Link: https://patch.msgid.link/20260824153903.4143642-4-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_api.c | 17 +++++++++++------
1 file changed, 11 insertions(+), 6 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index 8b81c25b3e8b2..cf57294821a1a 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -1835,11 +1835,13 @@ static int tcf_action_delete(struct net *net, struct tc_action *actions[])
static struct sk_buff *tcf_reoffload_del_notify_msg(struct net *net,
struct tc_action *action)
{
- size_t attr_size = tcf_action_fill_size(action);
struct tc_action *actions[TCA_ACT_MAX_PRIO] = {
[0] = action,
};
struct sk_buff *skb;
+ size_t attr_size;
+
+ attr_size = tcf_action_full_attrs_size(tcf_action_fill_size(action));
skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
@@ -1856,15 +1858,18 @@ static struct sk_buff *tcf_reoffload_del_notify_msg(struct net *net,
static int tcf_reoffload_del_notify(struct net *net, struct tc_action *action)
{
const struct tc_action_ops *ops = action->ops;
- struct sk_buff *skb;
+ struct sk_buff *skb = NULL;
int ret;
- if (!rtnl_notify_needed(net, 0, RTNLGRP_TC)) {
- skb = NULL;
- } else {
+ if (rtnl_notify_needed(net, 0, RTNLGRP_TC)) {
skb = tcf_reoffload_del_notify_msg(net, action);
+ /* The action has already lost its hardware instance and is
+ * skip_sw, so it must be released whether or not the
+ * notification can be built. Drop the notification rather
+ * than leave an action behind that processes no packets.
+ */
if (IS_ERR(skb))
- return PTR_ERR(skb);
+ skb = NULL;
}
ret = tcf_idr_release_unsafe(action);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 334/982] sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (332 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 333/982] net/sched: act_api: fix skb sizing and action leak on reoffload delete Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 335/982] scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() Greg Kroah-Hartman
` (654 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zero Day Initiative, Xin Long,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xin Long <lucien.xin@gmail.com>
[ Upstream commit 2188569e7e1b0bc3f3b557dc97ab7a02befc11c8 ]
The SCTP_CMD_TIMER_START handler checks timer_pending() before calling
timer_reduce(). The timer can expire and detach between these operations,
causing timer_reduce() to rearm the timer without taking the association
reference required for the newly armed timer.
The timer callback later unconditionally drops its association reference,
which can leave the association reference count unbalanced and result in
use-after-free during association teardown.
Use the return value of timer_reduce() to determine whether the timer was
actually armed. Take the association reference only when timer_reduce()
successfully starts a new timer, closing the race between checking the
timer state and rearming it.
This issue was reported by Nico Yip (@_cyeaa_) working with TrendAI Zero
Day Initiative.
Fixes: 20a785aa52c8 ("sctp: Don't add the shutdown timer if its already been added")
Reported-by: Zero Day Initiative <zdi-disclosures@trendmicro.com>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/9d8f1b5c50329d5ea7c642128d35681abaa9ed20.1787773744.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/sm_sideeffect.c | 11 +----------
1 file changed, 1 insertion(+), 10 deletions(-)
diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c
index 6989798a83c8c..4391f070dc1e1 100644
--- a/net/sctp/sm_sideeffect.c
+++ b/net/sctp/sm_sideeffect.c
@@ -1540,17 +1540,8 @@ static int sctp_cmd_interpreter(enum sctp_event_type event_type,
timeout = asoc->timeouts[cmd->obj.to];
BUG_ON(!timeout);
- /*
- * SCTP has a hard time with timer starts. Because we process
- * timer starts as side effects, it can be hard to tell if we
- * have already started a timer or not, which leads to BUG
- * halts when we call add_timer. So here, instead of just starting
- * a timer, if the timer is already started, and just mod
- * the timer with the shorter of the two expiration times
- */
- if (!timer_pending(timer))
+ if (!timer_reduce(timer, jiffies + timeout))
sctp_association_hold(asoc);
- timer_reduce(timer, jiffies + timeout);
break;
case SCTP_CMD_TIMER_RESTART:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 335/982] scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (333 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 334/982] sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 336/982] scsi: mpi3mr: Fix target device refcount leak " Greg Kroah-Hartman
` (653 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Milan P. Gandhi, Laurence Oberman,
Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Milan P. Gandhi <mgandhi@redhat.com>
[ Upstream commit dba9e2181ca5e875f98b8b9b4535cdaab87dcb0d ]
sas_port_alloc_num() can return NULL on memory allocation failure. The
return value is passed directly to sas_port_add() without a NULL check,
which causes a NULL pointer dereference.
Additionally, if sas_port_add() fails, the allocated port is not freed
before jumping to out_fail, leaking the sas_port structure. Call
sas_port_free() to properly release it.
Fixes: e22bae30667a ("scsi: mpi3mr: Add expander devices to STL")
Signed-off-by: Milan P. Gandhi <mgandhi@redhat.com>
Reviewed-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260812103344.174247-2-mgandhi@redhat.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/mpi3mr/mpi3mr_transport.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/scsi/mpi3mr/mpi3mr_transport.c b/drivers/scsi/mpi3mr/mpi3mr_transport.c
index f5001fadd5b12..b56fa01894f46 100644
--- a/drivers/scsi/mpi3mr/mpi3mr_transport.c
+++ b/drivers/scsi/mpi3mr/mpi3mr_transport.c
@@ -1404,9 +1404,15 @@ static struct mpi3mr_sas_port *mpi3mr_sas_port_add(struct mpi3mr_ioc *mrioc,
}
port = sas_port_alloc_num(mr_sas_node->parent_dev);
+ if (!port) {
+ ioc_err(mrioc, "failure at %s:%d/%s()!\n",
+ __FILE__, __LINE__, __func__);
+ goto out_fail;
+ }
if ((sas_port_add(port))) {
ioc_err(mrioc, "failure at %s:%d/%s()!\n",
__FILE__, __LINE__, __func__);
+ sas_port_free(port);
goto out_fail;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 336/982] scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (334 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 335/982] scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 337/982] smb/client: mark file sparse before emulating insert range Greg Kroah-Hartman
` (652 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Milan P. Gandhi, Laurence Oberman,
Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Milan P. Gandhi <mgandhi@redhat.com>
[ Upstream commit 419d129f970aaa6567dbac366b0c93784bf9ec97 ]
mpi3mr_get_tgtdev_by_addr() increments the target device kref when it
returns a device. If a subsequent error triggers a goto out_fail after
the tgtdev reference is acquired, the reference is never released
because the out_fail path does not call mpi3mr_tgtdev_put(). This
prevents the target device structure from ever being freed.
Add a tgtdev put in the out_fail path, guarded by a NULL check since
tgtdev is only acquired for SAS_END_DEVICE types and the same cleanup
path is shared by earlier error cases where tgtdev is still NULL.
Fixes: e22bae30667a ("scsi: mpi3mr: Add expander devices to STL")
Signed-off-by: Milan P. Gandhi <mgandhi@redhat.com>
Reviewed-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260812103344.174247-3-mgandhi@redhat.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/mpi3mr/mpi3mr_transport.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/scsi/mpi3mr/mpi3mr_transport.c b/drivers/scsi/mpi3mr/mpi3mr_transport.c
index b56fa01894f46..9a25d819b417a 100644
--- a/drivers/scsi/mpi3mr/mpi3mr_transport.c
+++ b/drivers/scsi/mpi3mr/mpi3mr_transport.c
@@ -1483,6 +1483,8 @@ static struct mpi3mr_sas_port *mpi3mr_sas_port_add(struct mpi3mr_ioc *mrioc,
list_for_each_entry_safe(mr_sas_phy, next, &mr_sas_port->phy_list,
port_siblings)
list_del(&mr_sas_phy->port_siblings);
+ if (tgtdev)
+ mpi3mr_tgtdev_put(tgtdev);
kfree(mr_sas_port);
return NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 337/982] smb/client: mark file sparse before emulating insert range
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (335 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 336/982] scsi: mpi3mr: Fix target device refcount leak " Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 338/982] smb: client: transport: Fix debug printing in __release_mid() Greg Kroah-Hartman
` (651 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Huiwen He, ChenXiaoSong, Namjae Jeon,
Paulo Alcantara, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Huiwen He <hehuiwen@kylinos.cn>
[ Upstream commit cd03ce4950d80147ac8f20bc03c42b75b0352407 ]
The SMB client emulates FALLOC_FL_INSERT_RANGE with SET_EOF, COPYCHUNK
and SET_ZERO_DATA.
SET_ZERO_DATA creates a hole only when the file is sparse. On a
non-sparse file, it clears the inserted range but leaves its blocks
allocated, causing the extent count check in xfstests generic/064 to
fail.
Fix this by marking the file sparse before modifying it.
This patch produces the expected sparse extents in xfstests generic/064
only when the server-reported block size is compatible with the server's
deallocation granularity.
For ksmbd, the reported block size follows the backing filesystem,
and the test passes. For Samba, the test passes with a block size
matching the backend granularity, for example, 4 KiB on Btrfs, but not
with the default 1 KiB value. For Windows Server 2022, 4 KiB inserts do
not generate holes, while aligned inserts of 64 KiB or larger do.
Fixes: 7fe6fe95b936 ("cifs: add FALLOC_FL_INSERT_RANGE support")
Signed-off-by: Huiwen He <hehuiwen@kylinos.cn>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/client/smb2ops.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
index 2b38e8e7efd4e..644c19c05237b 100644
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -3945,6 +3945,11 @@ static long smb3_insert_range(struct file *file, struct cifs_tcon *tcon,
count = old_eof - off;
eof = cpu_to_le64(old_eof + len);
+ /* SET_ZERO_DATA creates a hole only in a sparse file. */
+ rc = smb2_set_sparse(xid, tcon, cfile, inode, true);
+ if (rc)
+ goto out;
+
filemap_invalidate_lock(inode->i_mapping);
rc = filemap_write_and_wait_range(inode->i_mapping, off, old_eof + len - 1);
if (rc < 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 338/982] smb: client: transport: Fix debug printing in __release_mid()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (336 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 337/982] smb/client: mark file sparse before emulating insert range Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 339/982] sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration Greg Kroah-Hartman
` (650 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andy Shevchenko, Paulo Alcantara,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
[ Upstream commit d83a21bb26015bfdd79b0440fe816b271b8bbab3 ]
Long time ago during upgrading printk():s to the respective pr_<level>()
calls one misconversion happened and nobody has noticed that. So,
previously printk(KERN_DEBUG) + printk() worked as one long debug print
since the trailing '\n' is only present in the followup printk() format
string. The culprit change missed that and split the message to two on
the different levels. Restore the original behaviour to make users be
less confused in the most likely never happen cases of partially getting
that message.
Fixes: 0b456f04bcdf ("cifs: convert printk(LEVEL...) to pr_<level>")
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/client/transport.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/fs/smb/client/transport.c b/fs/smb/client/transport.c
index b72d12a24056c..59063b26afe43 100644
--- a/fs/smb/client/transport.c
+++ b/fs/smb/client/transport.c
@@ -143,12 +143,11 @@ void __release_mid(struct kref *refcount)
trace_smb3_slow_rsp(smb_cmd, midEntry->mid, midEntry->pid,
midEntry->when_sent, midEntry->when_received);
if (cifsFYI & CIFS_TIMER) {
- pr_debug("slow rsp: cmd %d mid %llu",
- midEntry->command, midEntry->mid);
- cifs_info("A: 0x%lx S: 0x%lx R: 0x%lx\n",
- now - midEntry->when_alloc,
- now - midEntry->when_sent,
- now - midEntry->when_received);
+ pr_debug("slow rsp: cmd %d mid %llu A: 0x%lx S: 0x%lx R: 0x%lx\n",
+ midEntry->command, midEntry->mid,
+ now - midEntry->when_alloc,
+ now - midEntry->when_sent,
+ now - midEntry->when_received);
}
}
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 339/982] sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (337 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 338/982] smb: client: transport: Fix debug printing in __release_mid() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 340/982] raw: annotate disconnect-side IPv4 match writers Greg Kroah-Hartman
` (649 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Henry Martin, Xin Long,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Henry Martin <bsdhenrymartin@gmail.com>
[ Upstream commit 2cb0b0b1ed69430bf73740377ea0a1c44c50db63 ]
sctp_verify_asconf() walks ASCONF-ACK parameters with
sctp_walk_params(), which advances by SCTP_PAD4(length), while the
consumer sctp_get_asconf_response() iterates the same parameters
advancing by the raw length, without padding. A single odd-length
parameter desynchronises the two walks and makes the consumer
interpret attacker-controlled bytes at a misaligned offset.
When those bytes yield a length of zero, the while loop over
asconf_ack_len makes no progress, spinning forever in softirq
context, and the watchdog reports a soft lockup. All reads stay
within the received skb, so the lockup is a pure remote denial of
service. A remote peer can trigger it with a crafted ASCONF-ACK on
an ADD-IP enabled association with an outstanding ASCONF (RFC 5061
section 4.1.2 requires the chunk to be authenticated, but the
predefined empty key id 0 allows the peer to compute the same
association HMAC from publicly exchanged parameters, so the gate
does not help).
The SCTP_PARAM_ERR_CAUSE case of sctp_verify_asconf() also performs
no length check, letting a parameter without a complete error
header reach the consumer, which reads errhdr.cause past the end of
the parameter, an out-of-bounds read.
Reject SCTP_PARAM_ERR_CAUSE parameters shorter than
sizeof(struct sctp_addip_param) + sizeof(struct sctp_errhdr) at the
verifier, and advance the consumer iterator with the same padding
rule as the verifier to keep the two walks in lockstep. The verifier
change guarantees a complete error header in every ERR_CAUSE
parameter the consumer can see, so the consumer's asconf_ack_len
check is dropped and it returns err_param->cause directly. The
consumer padding fix is still required because odd lengths remain
valid for SCTP_PARAM_ERR_CAUSE per RFC 5061.
The issue was found by ZeroHive, a vulnerability hunting agent at
Tencent Yunding Lab.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260828042431.3873725-1-bsdhenrymartin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/sm_make_chunk.c | 14 ++++++--------
1 file changed, 6 insertions(+), 8 deletions(-)
diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
index 6d738f95aff1d..649384ff0e547 100644
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@ -3238,6 +3238,9 @@ bool sctp_verify_asconf(const struct sctp_association *asoc,
*errp = param.p;
switch (param.p->type) {
case SCTP_PARAM_ERR_CAUSE:
+ if (length < sizeof(struct sctp_addip_param) +
+ sizeof(struct sctp_errhdr))
+ return false;
break;
case SCTP_PARAM_IPV4_ADDRESS:
if (length != sizeof(struct sctp_ipv4addr_param))
@@ -3471,20 +3474,15 @@ static __be16 sctp_get_asconf_response(struct sctp_chunk *asconf_ack,
case SCTP_PARAM_ERR_CAUSE:
length = sizeof(*asconf_ack_param);
err_param = (void *)asconf_ack_param + length;
- asconf_ack_len -= length;
- if (asconf_ack_len > 0)
- return err_param->cause;
- else
- return SCTP_ERROR_INV_PARAM;
- break;
+ return err_param->cause;
default:
return SCTP_ERROR_INV_PARAM;
}
}
length = ntohs(asconf_ack_param->param_hdr.length);
- asconf_ack_param = (void *)asconf_ack_param + length;
- asconf_ack_len -= length;
+ asconf_ack_param = (void *)asconf_ack_param + SCTP_PAD4(length);
+ asconf_ack_len -= SCTP_PAD4(length);
}
return err_code;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 340/982] raw: annotate disconnect-side IPv4 match writers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (338 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 339/982] sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 341/982] net: amd-xgbe: discard rx packets with bad FCS Greg Kroah-Hartman
` (648 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Jackie Liu,
Xuanqiang Luo, Eric Dumazet, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
[ Upstream commit ac08d183dac0441e41f77bbad50798fe609d90f1 ]
raw_v4_match() reads inet_daddr, inet_rcv_saddr and
sk_bound_dev_if locklessly under RCU. Bind and connect writers are
annotated, but __udp_disconnect() still clears the same fields using
plain stores.
Commit 18f116931f52e ("raw: annotate lockless match fields in
raw_v4_match()") added the lockless readers and annotated the raw bind
and datagram connect writers. Its v4 revision intentionally left the
shared disconnect-side IPv4 writers for follow-up cleanup.
Complete that follow-up by using WRITE_ONCE() for the disconnect-side
stores, including the inet_rcv_saddr reset in inet_reset_saddr(), to
pair with the lockless raw socket matcher.
Fixes: 0daf07e52709 ("raw: convert raw sockets to RCU")
Link: https://lore.kernel.org/netdev/20260716142958.3064224-1-runyu.xiao@seu.edu.cn/
Suggested-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Signed-off-by: Jackie Liu <liuyun01@kylinos.cn>
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260828012918.1461-1-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip.h | 3 ++-
net/ipv4/udp.c | 4 ++--
2 files changed, 4 insertions(+), 3 deletions(-)
diff --git a/include/net/ip.h b/include/net/ip.h
index 1b0722e9b55e4..05ce8b38e3dab 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -654,7 +654,8 @@ static inline void ip_ipgre_mc_map(__be32 naddr, const unsigned char *broadcast,
static __inline__ void inet_reset_saddr(struct sock *sk)
{
- inet_sk(sk)->inet_rcv_saddr = inet_sk(sk)->inet_saddr = 0;
+ inet_sk(sk)->inet_saddr = 0;
+ WRITE_ONCE(inet_sk(sk)->inet_rcv_saddr, 0);
#if IS_ENABLED(CONFIG_IPV6)
if (sk->sk_family == PF_INET6) {
struct ipv6_pinfo *np = inet6_sk(sk);
diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index d1714aaedf176..6f745efa0db4b 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -1968,10 +1968,10 @@ int __udp_disconnect(struct sock *sk, int flags)
*/
sk->sk_state = TCP_CLOSE;
- inet->inet_daddr = 0;
+ WRITE_ONCE(inet->inet_daddr, 0);
inet->inet_dport = 0;
sock_rps_reset_rxhash(sk);
- sk->sk_bound_dev_if = 0;
+ WRITE_ONCE(sk->sk_bound_dev_if, 0);
if (!(sk->sk_userlocks & SOCK_BINDADDR_LOCK)) {
inet_reset_saddr(sk);
if (sk->sk_prot->rehash &&
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 341/982] net: amd-xgbe: discard rx packets with bad FCS
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (339 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 340/982] raw: annotate disconnect-side IPv4 match writers Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 342/982] watchdog: msc313e: Fix NULL pointer dereference in PM callbacks Greg Kroah-Hartman
` (647 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Nugraha, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Nugraha <aslan.jnn@gmail.com>
[ Upstream commit ac8d6b28d48c5d951dcd923d33e461588e762a6d ]
amd-xgbe driver currently sets the MAC_RCR.DCRCC bit whenever
RX is enabled. This disables hardware FCS validation, causing packets
with bad FCS to be accepted unconditionally.
This change unsets DCRCC so that packets with bad FCS will be dropped,
in-line with typical behaviours of many other network controllers.
Tests:
- Verified that packets with bad FCS are now dropped.
- Verified that receiving packets with bad FCS will increment the
`rx_crc_errors` counter.
Fixes: c5aa9e3b8156 ("amd-xgbe: Initial AMD 10GbE platform driver")
Signed-off-by: James Nugraha <aslan.jnn@gmail.com>
Link: https://patch.msgid.link/20260827232220.69907-1-aslan.jnn@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/amd/xgbe/xgbe-dev.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/amd/xgbe/xgbe-dev.c b/drivers/net/ethernet/amd/xgbe/xgbe-dev.c
index 3cf7943b590cf..58c510e38add6 100644
--- a/drivers/net/ethernet/amd/xgbe/xgbe-dev.c
+++ b/drivers/net/ethernet/amd/xgbe/xgbe-dev.c
@@ -3388,7 +3388,7 @@ static void xgbe_enable_rx(struct xgbe_prv_data *pdata)
XGMAC_IOWRITE(pdata, MAC_RQC0R, reg_val);
/* Enable MAC Rx */
- XGMAC_IOWRITE_BITS(pdata, MAC_RCR, DCRCC, 1);
+ XGMAC_IOWRITE_BITS(pdata, MAC_RCR, DCRCC, 0);
XGMAC_IOWRITE_BITS(pdata, MAC_RCR, CST, 1);
XGMAC_IOWRITE_BITS(pdata, MAC_RCR, ACS, 1);
XGMAC_IOWRITE_BITS(pdata, MAC_RCR, RE, 1);
@@ -3399,7 +3399,6 @@ static void xgbe_disable_rx(struct xgbe_prv_data *pdata)
unsigned int i;
/* Disable MAC Rx */
- XGMAC_IOWRITE_BITS(pdata, MAC_RCR, DCRCC, 0);
XGMAC_IOWRITE_BITS(pdata, MAC_RCR, CST, 0);
XGMAC_IOWRITE_BITS(pdata, MAC_RCR, ACS, 0);
XGMAC_IOWRITE_BITS(pdata, MAC_RCR, RE, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 342/982] watchdog: msc313e: Fix NULL pointer dereference in PM callbacks
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (340 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 341/982] net: amd-xgbe: discard rx packets with bad FCS Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.1 343/982] OPP: of: Fix potential multiplication overflow when calculating freq Greg Kroah-Hartman
` (646 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit e3eceb76515910746e6268c4e4ac1c07516ebd7b ]
msc313e_wdt_probe() doesn't set the driver data for the platform device.
As a result, dev_get_drvdata() in msc313e_wdt_suspend() and
msc313e_wdt_resume() will return NULL, leading to a NULL pointer
dereference afterward.
Set the platform device driver data in msc313e_wdt_probe().
Fixes: e9800b799464 ("watchdog: Add Mstar MSC313e WDT driver")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260827044700.554333-2-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 90171431fc594..3b62650375628 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -125,6 +125,7 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
set_bit(WDOG_HW_RUNNING, &priv->wdev.status);
watchdog_set_drvdata(&priv->wdev, priv);
+ platform_set_drvdata(pdev, priv);
watchdog_init_timeout(&priv->wdev, timeout, dev);
watchdog_stop_on_reboot(&priv->wdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 343/982] OPP: of: Fix potential multiplication overflow when calculating freq
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (341 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 342/982] watchdog: msc313e: Fix NULL pointer dereference in PM callbacks Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 344/982] ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF Greg Kroah-Hartman
` (645 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Colin Ian King, Viresh Kumar,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Colin Ian King <colin.i.king@gmail.com>
[ Upstream commit e11811a552252740bd396ec38378e9570ee16578 ]
The multiplication be32_to_cpup(val++) * 1000 is performed using 32 bit
unsigned integers and hence uses a 32 bit multiplication; this will
overflow if be32_to_cpup(val++) is greater than 4294967 (which is
very unlikely at present). The result is assigned to an unsigned long
(which is a 64 bit value on 64 bit systems), so fix this potential
overflow by casting the first operand of the multiplication to
an unsigned int.
Fixes: b496dfbc94ab ("PM / OPP: Initialize OPP table from device tree")
Signed-off-by: Colin Ian King <colin.i.king@gmail.com>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/opp/of.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/opp/of.c b/drivers/opp/of.c
index c1b2d8927845c..c09e05c5a5711 100644
--- a/drivers/opp/of.c
+++ b/drivers/opp/of.c
@@ -1108,7 +1108,7 @@ static int _of_add_opp_table_v1(struct device *dev, struct opp_table *opp_table)
val = prop->value;
while (nr) {
- unsigned long freq = be32_to_cpup(val++) * 1000;
+ unsigned long freq = (unsigned long)be32_to_cpup(val++) * 1000;
unsigned long volt = be32_to_cpup(val++);
ret = _opp_add_v1(opp_table, dev, freq, volt, false);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 344/982] ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (342 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.1 343/982] OPP: of: Fix potential multiplication overflow when calculating freq Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 345/982] ksmbd: rate limit unmapped SID errors Greg Kroah-Hartman
` (644 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kimi Security Team, Yilin Zhang,
Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yilin Zhang <yilinzhang@moonshot.ai>
[ Upstream commit 9b110a9dcecc59516c77cb3c0caf1f492f75df2d ]
snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation
with an mmap_count check performed under the PCM stream lock, but the
lock is released long before the buffer is actually freed:
snd_pcm_sync_stop(), constraint refinement and do_free_pages() all
happen in between. snd_pcm_mmap_data(), on the other hand, takes no
lock at all: it validates against the old buffer's state and
dma_bytes, remaps its pages into the VMA, and only then increments
mmap_count.
A concurrent mmap() can therefore slip in between the check and the
free. remap_pfn_range() installs writable PTEs for the old buffer's
pages without taking page references, and the subsequent
do_free_pages() returns those pages to the page allocator while the
VMA still maps them. This leaves a stale, writable mapping of freed
pages: a page-level use-after-free that can be leveraged for local
privilege escalation.
Make snd_pcm_mmap_data() participate in the buffer-access scheme
introduced for hw_params/hw_free: acquire runtime->buffer_accessing
before validating and remapping, and release it afterwards. Buffer
reallocation already fails with -EBUSY while accessors are active,
and the mmap side now fails with -EBUSY while a reallocation is in
progress, so the validate/remap sequence and the check/free sequence
can no longer interleave.
A reproducer that turns this race into a stale writable mapping of
the freed DMA buffer pages is available on request.
Reported-by: Kimi Security Team <bug-report@moonshot.ai>
Fixes: 92ee3c60ec9f ("ALSA: pcm: Fix races among concurrent hw_params and hw_free calls")
Signed-off-by: Yilin Zhang <yilinzhang@moonshot.ai>
Link: https://patch.msgid.link/20260831045506.889070-1-yilinzhang@moonshot.ai
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/core/pcm_native.c | 35 +++++++++++++++++++++++++----------
1 file changed, 25 insertions(+), 10 deletions(-)
diff --git a/sound/core/pcm_native.c b/sound/core/pcm_native.c
index 87695490219e5..497521424ea71 100644
--- a/sound/core/pcm_native.c
+++ b/sound/core/pcm_native.c
@@ -3930,20 +3930,33 @@ int snd_pcm_mmap_data(struct snd_pcm_substream *substream, struct file *file,
return -EINVAL;
}
runtime = substream->runtime;
- if (runtime->state == SNDRV_PCM_STATE_OPEN)
- return -EBADFD;
- if (!(runtime->info & SNDRV_PCM_INFO_MMAP))
- return -ENXIO;
+ /* don't race with buffer reallocation in hw_params/hw_free */
+ if (!atomic_inc_unless_negative(&runtime->buffer_accessing))
+ return -EBUSY;
+ if (runtime->state == SNDRV_PCM_STATE_OPEN) {
+ err = -EBADFD;
+ goto out;
+ }
+ if (!(runtime->info & SNDRV_PCM_INFO_MMAP)) {
+ err = -ENXIO;
+ goto out;
+ }
if (runtime->access == SNDRV_PCM_ACCESS_RW_INTERLEAVED ||
- runtime->access == SNDRV_PCM_ACCESS_RW_NONINTERLEAVED)
- return -EINVAL;
+ runtime->access == SNDRV_PCM_ACCESS_RW_NONINTERLEAVED) {
+ err = -EINVAL;
+ goto out;
+ }
size = area->vm_end - area->vm_start;
offset = area->vm_pgoff << PAGE_SHIFT;
dma_bytes = PAGE_ALIGN(runtime->dma_bytes);
- if ((size_t)size > dma_bytes)
- return -EINVAL;
- if (offset > dma_bytes - size)
- return -EINVAL;
+ if ((size_t)size > dma_bytes) {
+ err = -EINVAL;
+ goto out;
+ }
+ if (offset > dma_bytes - size) {
+ err = -EINVAL;
+ goto out;
+ }
area->vm_ops = &snd_pcm_vm_ops_data;
area->vm_private_data = substream;
@@ -3953,6 +3966,8 @@ int snd_pcm_mmap_data(struct snd_pcm_substream *substream, struct file *file,
err = snd_pcm_lib_default_mmap(substream, area);
if (!err)
atomic_inc(&substream->mmap_count);
+out:
+ atomic_dec(&runtime->buffer_accessing);
return err;
}
EXPORT_SYMBOL(snd_pcm_mmap_data);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 345/982] ksmbd: rate limit unmapped SID errors
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (343 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 344/982] ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 346/982] Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan Greg Kroah-Hartman
` (643 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cheryl Babcock, Namjae Jeon,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit feca5e70fc963b088377b20879e8cd8237c2fd7d ]
A client can include many structurally valid but unmapped SIDs in a DACL.
Logging every mapping failure lets one request generate hundreds of kernel
error messages.
Rate limit the message to prevent an authenticated client from flooding
the kernel log.
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Reported-by: Cheryl Babcock <cheryl@renat.io>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smbacl.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/smb/server/smbacl.c b/fs/smb/server/smbacl.c
index 7a0396db6f1d2..5cb020fc01050 100644
--- a/fs/smb/server/smbacl.c
+++ b/fs/smb/server/smbacl.c
@@ -516,8 +516,8 @@ static void parse_dacl(struct user_namespace *user_ns,
temp_fattr.cf_uid = INVALID_UID;
ret = sid_to_id(user_ns, &ppace[i]->sid, SIDOWNER, &temp_fattr);
if (ret || uid_eq(temp_fattr.cf_uid, INVALID_UID)) {
- pr_err("%s: Error %d mapping Owner SID to uid\n",
- __func__, ret);
+ pr_err_ratelimited("%s: Error %d mapping Owner SID to uid\n",
+ __func__, ret);
continue;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 346/982] Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (344 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 345/982] ksmbd: rate limit unmapped SID errors Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 347/982] Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM Greg Kroah-Hartman
` (642 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 4ef05db5b08b176a551b4a6287372045998806b0 ]
l2cap_new_connection() sets default value of channel mode to match the
parent channel. l2cap_le_connect_req() left this at the default, and
created L2CAP_MODE_EXT_FLOWCTL channels if listening pchan has that
mode. This causes FLAG_DEFER_SETUP channels to reply to
L2CAP_LE_CONN_REQ with L2CAP_ECRED_CONN_RSP, which is incorrect.
It can also result to stack OOB write (of l2cap_alloc_cid determined
values) in l2cap_ecred_rsp_defer(), as l2cap_le_connect_req() does not
limit maximum number of deferred channels or check for duplicate ident.
Fix by setting chan->mode correctly in l2cap_le_connect_req().
Also check channel mode in l2cap_ecred_rsp_defer(), and do WARN_ON_ONCE
instead of OOB write to make it less brittle.
Fixes: 15f02b910562 ("Bluetooth: L2CAP: Add initial code for Enhanced Credit Based Mode")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/l2cap_core.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
index 3097ffd654c1e..1a625c4fb395c 100644
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -3866,6 +3866,9 @@ static void l2cap_ecred_rsp_defer(struct l2cap_chan *chan, void *data)
{
struct l2cap_ecred_rsp_data *rsp = data;
+ if (chan->mode != L2CAP_MODE_EXT_FLOWCTL)
+ return;
+
/* Check if channel for outgoing connection or if it wasn't deferred
* since in those cases it must be skipped.
*/
@@ -3876,6 +3879,10 @@ static void l2cap_ecred_rsp_defer(struct l2cap_chan *chan, void *data)
/* Reset ident so only one response is sent */
chan->ident = 0;
+ /* Unreachable, check in l2cap_ecred_conn_req. If reached, drop rest */
+ if (WARN_ON_ONCE(rsp->count >= ARRAY_SIZE(rsp->pdu.scid)))
+ rsp->pdu.rsp.result = cpu_to_le16(L2CAP_CR_LE_NO_MEM);
+
/* Include all channels pending with the same ident */
if (!rsp->pdu.rsp.result)
rsp->pdu.rsp.dcid[rsp->count++] = cpu_to_le16(chan->scid);
@@ -5079,6 +5086,7 @@ static int l2cap_le_connect_req(struct l2cap_conn *conn,
__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
chan->ident = cmd->ident;
+ chan->mode = L2CAP_MODE_LE_FLOWCTL;
if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
l2cap_state_change(chan, BT_CONNECT2);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 347/982] Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (345 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 346/982] Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 348/982] Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() Greg Kroah-Hartman
` (641 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit 0d77683237270702fa93489ca759c89b4e970554 ]
l2cap_ecred_defer_connect() clears FLAG_DEFER_SETUP also for channels
with different PID/PSM, which will not be added to the same
ECRED_CONN_REQ in any case. Consequently, only one ECRED connection
group can work at a time although it appears intended they would be
separate for each PID/PSM combination.
Fix by clearing FLAG_DEFER_SETUP only for the connections that could be
added in the request. Retain test_bit(FLAG_DEFER_SETUP) before calling
get_peer_pid as it may be NULL otherwise.
Fixes: da49b602f7f7 ("Bluetooth: L2CAP: Use DEFER_SETUP to group ECRED connections")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/l2cap_core.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
index 1a625c4fb395c..1e3022e097118 100644
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -1350,7 +1350,7 @@ static void l2cap_ecred_defer_connect(struct l2cap_chan *chan, void *data)
if (chan == conn->chan)
return;
- if (!test_and_clear_bit(FLAG_DEFER_SETUP, &chan->flags))
+ if (!test_bit(FLAG_DEFER_SETUP, &chan->flags))
return;
pid = chan->ops->get_peer_pid(chan);
@@ -1360,6 +1360,9 @@ static void l2cap_ecred_defer_connect(struct l2cap_chan *chan, void *data)
chan->mode != L2CAP_MODE_EXT_FLOWCTL || chan->state != BT_CONNECT)
return;
+ if (!test_and_clear_bit(FLAG_DEFER_SETUP, &chan->flags))
+ return;
+
if (test_and_set_bit(FLAG_ECRED_CONN_REQ_SENT, &chan->flags))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 348/982] Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (346 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 347/982] Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 349/982] ASoC: ab8500: Reset the audio block before configuring it Greg Kroah-Hartman
` (640 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gongwei Li, Luiz Augusto von Dentz,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gongwei Li <ligongwei@kylinos.cn>
[ Upstream commit 2deb76c21b81e42b3282224f7dd2046fe73fd1e0 ]
wait_on_bit_timeout() returns 0 if the bit was cleared, -EINTR if the
process received a signal and the mode permitted wake up on that signal,
or -EAGAIN if the timeout elapsed. It never returns 1.
Hence the check "err == 1" in mrvl_load_firmware() is dead code: when
the waiting task is interrupted by a signal (-EINTR), the code falls
into the "else if (err)" branch and misreports it as "Firmware request
timeout" with -ETIMEDOUT instead of propagating -EINTR.
Fix this by testing for -EINTR so that an interrupted firmware load is
properly detected and reported.
Fixes: 162f812f23ba ("Bluetooth: hci_uart: Add Marvell support")
Signed-off-by: Gongwei Li <ligongwei@kylinos.cn>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/hci_mrvl.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/bluetooth/hci_mrvl.c b/drivers/bluetooth/hci_mrvl.c
index fbc3f7c3a5c71..b986bdbe09b56 100644
--- a/drivers/bluetooth/hci_mrvl.c
+++ b/drivers/bluetooth/hci_mrvl.c
@@ -297,9 +297,8 @@ static int mrvl_load_firmware(struct hci_dev *hdev, const char *name)
err = wait_on_bit_timeout(&mrvl->flags, STATE_FW_REQ_PENDING,
TASK_INTERRUPTIBLE,
msecs_to_jiffies(2000));
- if (err == 1) {
+ if (err == -EINTR) {
bt_dev_err(hdev, "Firmware load interrupted");
- err = -EINTR;
break;
} else if (err) {
bt_dev_err(hdev, "Firmware request timeout");
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 349/982] ASoC: ab8500: Reset the audio block before configuring it
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (347 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 348/982] Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 350/982] ASoC: ab8500: Repair the DAPM capture graph Greg Kroah-Hartman
` (639 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 8e839bca7793a0b03c005f4b2b0825464290d425 ]
ResetAudn is active low, but the codec probe only deasserts it. It also
clears Clk32kOut2Dis despite claiming to disable that output, and writes
codec registers before releasing reset.
Pulse ResetAudn before the first audio-bank access and leave the unused
32 kHz output disabled.
Fixes: 679d7abdc754 ("ASoC: codecs: Add AB8500 codec-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260831-ab8500-codec-fixes-v1-1-f85024e717e3@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/ab8500-codec.c | 26 +++++++++++++-------------
1 file changed, 13 insertions(+), 13 deletions(-)
diff --git a/sound/soc/codecs/ab8500-codec.c b/sound/soc/codecs/ab8500-codec.c
index 42e448978c4a0..187250400613d 100644
--- a/sound/soc/codecs/ab8500-codec.c
+++ b/sound/soc/codecs/ab8500-codec.c
@@ -1917,18 +1917,18 @@ enum ab8500_filter {
static int ab8500_audio_init_audioblock(struct snd_soc_component *component)
{
int status;
+ u8 mask = AB8500_STW4500CTRL3_CLK32KOUT2DIS |
+ AB8500_STW4500CTRL3_RESETAUDN;
dev_dbg(component->dev, "%s: Enter.\n", __func__);
- /* Reset audio-registers and disable 32kHz-clock output 2 */
- status = ab8500_sysctrl_write(AB8500_STW4500CTRL3,
- AB8500_STW4500CTRL3_CLK32KOUT2DIS |
- AB8500_STW4500CTRL3_RESETAUDN,
- AB8500_STW4500CTRL3_RESETAUDN);
+ /* Reset the audio registers and disable the unused 32 kHz output. */
+ status = ab8500_sysctrl_write(AB8500_STW4500CTRL3, mask,
+ AB8500_STW4500CTRL3_CLK32KOUT2DIS);
if (status < 0)
return status;
- return 0;
+ return ab8500_sysctrl_write(AB8500_STW4500CTRL3, mask, mask);
}
static int ab8500_audio_setup_mics(struct snd_soc_component *component,
@@ -2461,6 +2461,13 @@ static int ab8500_codec_probe(struct snd_soc_component *component)
ab8500_codec_of_probe(dev, np, &codec_pdata);
+ status = ab8500_audio_init_audioblock(component);
+ if (status < 0) {
+ dev_err(dev, "%s: failed to init audio-block (%d)!\n",
+ __func__, status);
+ return status;
+ }
+
status = ab8500_audio_setup_mics(component, &codec_pdata.amics);
if (status < 0) {
pr_err("%s: Failed to setup mics (%d)!\n", __func__, status);
@@ -2473,13 +2480,6 @@ static int ab8500_codec_probe(struct snd_soc_component *component)
return status;
}
- status = ab8500_audio_init_audioblock(component);
- if (status < 0) {
- dev_err(dev, "%s: failed to init audio-block (%d)!\n",
- __func__, status);
- return status;
- }
-
/* Override HW-defaults */
snd_soc_component_write(component, AB8500_ANACONF5,
BIT(AB8500_ANACONF5_HSAUTOEN));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 350/982] ASoC: ab8500: Repair the DAPM capture graph
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (348 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 349/982] ASoC: ab8500: Reset the audio block before configuring it Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 351/982] ASoC: ab8500: Correct digital interface format setup Greg Kroah-Hartman
` (638 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 103fe1a37f040ef6ac9ed1cf33be786149d2bb15 ]
The capture stream routes point away from the stream widget. Digital
microphone mux routes are unconditional and bypass their enable bits,
and several widgets independently own shared AD path enable bits. The
dummy ADC and DAC widgets hide the resulting power graph errors.
Connect each real AIF widget to the stream and main supply, use the mux
item names on digital microphone routes, and model shared AD enables as
supplies. Also make the ANC DAPM switch writable.
Fixes: 679d7abdc754 ("ASoC: codecs: Add AB8500 codec-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260831-ab8500-codec-fixes-v1-2-f85024e717e3@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/ab8500-codec.c | 120 +++++++++++++++-----------------
1 file changed, 56 insertions(+), 64 deletions(-)
diff --git a/sound/soc/codecs/ab8500-codec.c b/sound/soc/codecs/ab8500-codec.c
index 187250400613d..c40e1a47e6eee 100644
--- a/sound/soc/codecs/ab8500-codec.c
+++ b/sound/soc/codecs/ab8500-codec.c
@@ -303,7 +303,7 @@ static const struct snd_kcontrol_new dapm_anc_in_select[] = {
/* ANC - Enable/Disable */
static const struct snd_kcontrol_new dapm_anc_enable[] = {
SOC_DAPM_SINGLE("Switch", AB8500_ANCCONF1,
- AB8500_ANCCONF1_ENANC, 0, 0),
+ AB8500_ANCCONF1_ENANC, 1, 0),
};
/* ANC to Earpiece - Mute */
@@ -385,12 +385,6 @@ static const struct snd_soc_dapm_widget ab8500_dapm_widgets[] = {
/* DA/AD */
- SND_SOC_DAPM_INPUT("ADC Input"),
- SND_SOC_DAPM_ADC("ADC", "ab8500_0c", SND_SOC_NOPM, 0, 0),
-
- SND_SOC_DAPM_DAC("DAC", NULL, SND_SOC_NOPM, 0, 0),
- SND_SOC_DAPM_OUTPUT("DAC Output"),
-
SND_SOC_DAPM_AIF_IN("DA_IN1", NULL, 0, SND_SOC_NOPM, 0, 0),
SND_SOC_DAPM_AIF_IN("DA_IN2", NULL, 0, SND_SOC_NOPM, 0, 0),
SND_SOC_DAPM_AIF_IN("DA_IN3", NULL, 0, SND_SOC_NOPM, 0, 0),
@@ -582,9 +576,8 @@ static const struct snd_soc_dapm_widget ab8500_dapm_widgets[] = {
SND_SOC_DAPM_MIXER("AD3 Channel Volume",
SND_SOC_NOPM, 0, 0,
NULL, 0),
- SND_SOC_DAPM_MIXER("AD3 Enable",
- AB8500_ADPATHENA, AB8500_ADPATHENA_ENAD34, 0,
- NULL, 0),
+ SND_SOC_DAPM_SUPPLY("AD34 Enable", AB8500_ADPATHENA,
+ AB8500_ADPATHENA_ENAD34, 0, NULL, 0),
/* Mic 2 */
@@ -643,9 +636,8 @@ static const struct snd_soc_dapm_widget ab8500_dapm_widgets[] = {
SND_SOC_NOPM, 0, 0,
NULL, 0),
- SND_SOC_DAPM_MIXER("AD12 Enable",
- AB8500_ADPATHENA, AB8500_ADPATHENA_ENAD12, 0,
- NULL, 0),
+ SND_SOC_DAPM_SUPPLY("AD12 Enable", AB8500_ADPATHENA,
+ AB8500_ADPATHENA_ENAD12, 0, NULL, 0),
/* HD Capture path */
@@ -659,12 +651,8 @@ static const struct snd_soc_dapm_widget ab8500_dapm_widgets[] = {
SND_SOC_DAPM_MIXER("AD6 Channel Volume",
SND_SOC_NOPM, 0, 0,
NULL, 0),
- SND_SOC_DAPM_MIXER("AD57 Enable",
- AB8500_ADPATHENA, AB8500_ADPATHENA_ENAD5768, 0,
- NULL, 0),
- SND_SOC_DAPM_MIXER("AD68 Enable",
- AB8500_ADPATHENA, AB8500_ADPATHENA_ENAD5768, 0,
- NULL, 0),
+ SND_SOC_DAPM_SUPPLY("AD5768 Enable", AB8500_ADPATHENA,
+ AB8500_ADPATHENA_ENAD5768, 0, NULL, 0),
/* Digital Microphone path */
@@ -696,10 +684,6 @@ static const struct snd_soc_dapm_widget ab8500_dapm_widgets[] = {
SND_SOC_DAPM_MIXER("AD4 Channel Volume",
SND_SOC_NOPM, 0, 0,
NULL, 0),
- SND_SOC_DAPM_MIXER("AD4 Enable",
- AB8500_ADPATHENA, AB8500_ADPATHENA_ENAD34,
- 0, NULL, 0),
-
/* Acoustical Noise Cancellation path */
SND_SOC_DAPM_INPUT("ANC Configure Input"),
@@ -747,24 +731,17 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
{"Main Supply", NULL, "Audio Power"},
{"Main Supply", NULL, "Audio Analog Power"},
- {"DAC", NULL, "ab8500_0p"},
- {"DAC", NULL, "Main Supply"},
- {"ADC", NULL, "ab8500_0c"},
- {"ADC", NULL, "Main Supply"},
-
/* ANC Configure */
{"ANC Configure Input", NULL, "Main Supply"},
{"ANC Configure Output", NULL, "ANC Configure Input"},
- /* AD/DA */
- {"ADC", NULL, "ADC Input"},
- {"DAC Output", NULL, "DAC"},
-
/* Powerup charge pump if DA1/2 is in use */
{"DA_IN1", NULL, "ab8500_0p"},
+ {"DA_IN1", NULL, "Main Supply"},
{"DA_IN1", NULL, "Charge Pump"},
{"DA_IN2", NULL, "ab8500_0p"},
+ {"DA_IN2", NULL, "Main Supply"},
{"DA_IN2", NULL, "Charge Pump"},
/* Headset path */
@@ -799,8 +776,10 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
/* HF or LineOut path */
{"DA_IN3", NULL, "ab8500_0p"},
+ {"DA_IN3", NULL, "Main Supply"},
{"DA3 Channel Volume", NULL, "DA_IN3"},
{"DA_IN4", NULL, "ab8500_0p"},
+ {"DA_IN4", NULL, "Main Supply"},
{"DA4 Channel Volume", NULL, "DA_IN4"},
{"Speaker Left Source", "Audio Path", "DA3 Channel Volume"},
@@ -858,8 +837,10 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
/* Vibrator path */
{"DA_IN5", NULL, "ab8500_0p"},
+ {"DA_IN5", NULL, "Main Supply"},
{"DA5 Channel Volume", NULL, "DA_IN5"},
{"DA_IN6", NULL, "ab8500_0p"},
+ {"DA_IN6", NULL, "Main Supply"},
{"DA6 Channel Volume", NULL, "DA_IN6"},
{"VIB1 DAC", NULL, "DA5 Channel Volume"},
@@ -901,13 +882,15 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
{"AD1 Channel Volume", NULL, "AD1 Source Select"},
{"AD2 Channel Volume", NULL, "AD2 Source Select"},
- {"AD12 Enable", NULL, "AD1 Channel Volume"},
- {"AD12 Enable", NULL, "AD2 Channel Volume"},
+ {"AD1 Channel Volume", NULL, "AD12 Enable"},
+ {"AD2 Channel Volume", NULL, "AD12 Enable"},
- {"AD_OUT1", NULL, "ab8500_0c"},
- {"AD_OUT1", NULL, "AD12 Enable"},
- {"AD_OUT2", NULL, "ab8500_0c"},
- {"AD_OUT2", NULL, "AD12 Enable"},
+ {"ab8500_0c", NULL, "AD_OUT1"},
+ {"AD_OUT1", NULL, "Main Supply"},
+ {"AD_OUT1", NULL, "AD1 Channel Volume"},
+ {"ab8500_0c", NULL, "AD_OUT2"},
+ {"AD_OUT2", NULL, "Main Supply"},
+ {"AD_OUT2", NULL, "AD2 Channel Volume"},
/* Mic 1 */
@@ -924,11 +907,11 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
{"AD3 Source Select", "Mic 1", "MIC1 ADC"},
{"AD3 Channel Volume", NULL, "AD3 Source Select"},
+ {"AD3 Channel Volume", NULL, "AD34 Enable"},
- {"AD3 Enable", NULL, "AD3 Channel Volume"},
-
- {"AD_OUT3", NULL, "ab8500_0c"},
- {"AD_OUT3", NULL, "AD3 Enable"},
+ {"ab8500_0c", NULL, "AD_OUT3"},
+ {"AD_OUT3", NULL, "Main Supply"},
+ {"AD_OUT3", NULL, "AD3 Channel Volume"},
/* HD Capture path */
@@ -937,14 +920,15 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
{"AD5 Channel Volume", NULL, "AD5 Source Select"},
{"AD6 Channel Volume", NULL, "AD6 Source Select"},
+ {"AD5 Channel Volume", NULL, "AD5768 Enable"},
+ {"AD6 Channel Volume", NULL, "AD5768 Enable"},
- {"AD57 Enable", NULL, "AD5 Channel Volume"},
- {"AD68 Enable", NULL, "AD6 Channel Volume"},
-
- {"AD_OUT57", NULL, "ab8500_0c"},
- {"AD_OUT57", NULL, "AD57 Enable"},
- {"AD_OUT68", NULL, "ab8500_0c"},
- {"AD_OUT68", NULL, "AD68 Enable"},
+ {"ab8500_0c", NULL, "AD_OUT57"},
+ {"AD_OUT57", NULL, "Main Supply"},
+ {"AD_OUT57", NULL, "AD5 Channel Volume"},
+ {"ab8500_0c", NULL, "AD_OUT68"},
+ {"AD_OUT68", NULL, "Main Supply"},
+ {"AD_OUT68", NULL, "AD6 Channel Volume"},
/* Digital Microphone path */
@@ -955,17 +939,25 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
{"DMic 5", NULL, "V-DMIC"},
{"DMic 6", NULL, "V-DMIC"},
- {"AD1 Source Select", NULL, "DMic 1"},
- {"AD2 Source Select", NULL, "DMic 2"},
- {"AD3 Source Select", NULL, "DMic 3"},
- {"AD5 Source Select", NULL, "DMic 5"},
- {"AD6 Source Select", NULL, "DMic 6"},
+ {"DMIC1", NULL, "DMic 1"},
+ {"DMIC2", NULL, "DMic 2"},
+ {"DMIC3", NULL, "DMic 3"},
+ {"DMIC4", NULL, "DMic 4"},
+ {"DMIC5", NULL, "DMic 5"},
+ {"DMIC6", NULL, "DMic 6"},
+
+ {"AD1 Source Select", "DMic 1", "DMIC1"},
+ {"AD2 Source Select", "DMic 2", "DMIC2"},
+ {"AD3 Source Select", "DMic 3", "DMIC3"},
+ {"AD5 Source Select", "DMic 5", "DMIC5"},
+ {"AD6 Source Select", "DMic 6", "DMIC6"},
- {"AD4 Channel Volume", NULL, "DMic 4"},
- {"AD4 Enable", NULL, "AD4 Channel Volume"},
+ {"AD4 Channel Volume", NULL, "DMIC4"},
+ {"AD4 Channel Volume", NULL, "AD34 Enable"},
- {"AD_OUT4", NULL, "ab8500_0c"},
- {"AD_OUT4", NULL, "AD4 Enable"},
+ {"ab8500_0c", NULL, "AD_OUT4"},
+ {"AD_OUT4", NULL, "Main Supply"},
+ {"AD_OUT4", NULL, "AD4 Channel Volume"},
/* LineIn Bypass path */
@@ -990,13 +982,13 @@ static const struct snd_soc_dapm_route ab8500_dapm_routes[] = {
/* Sidetone Filter path */
- {"Sidetone Left Source", "LineIn Left", "AD12 Enable"},
- {"Sidetone Left Source", "LineIn Right", "AD12 Enable"},
- {"Sidetone Left Source", "Mic 1", "AD3 Enable"},
+ {"Sidetone Left Source", "LineIn Left", "AD1 Channel Volume"},
+ {"Sidetone Left Source", "LineIn Right", "AD2 Channel Volume"},
+ {"Sidetone Left Source", "Mic 1", "AD3 Channel Volume"},
{"Sidetone Left Source", "Headset Left", "DA_IN1"},
- {"Sidetone Right Source", "LineIn Right", "AD12 Enable"},
- {"Sidetone Right Source", "Mic 1", "AD3 Enable"},
- {"Sidetone Right Source", "DMic 4", "AD4 Enable"},
+ {"Sidetone Right Source", "LineIn Right", "AD2 Channel Volume"},
+ {"Sidetone Right Source", "Mic 1", "AD3 Channel Volume"},
+ {"Sidetone Right Source", "DMic 4", "AD4 Channel Volume"},
{"Sidetone Right Source", "Headset Right", "DA_IN2"},
{"STFIR1 Control", NULL, "Sidetone Left Source"},
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 351/982] ASoC: ab8500: Correct digital interface format setup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (349 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 350/982] ASoC: ab8500: Repair the DAPM capture graph Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 352/982] ASoC: ab8500: Validate and program TDM slots correctly Greg Kroah-Hartman
` (637 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit f98785adf004db6b1c9f4cea9dadae7b800db72f ]
The codec programs I2S as an undelayed left-aligned format, although the
hardware manual defines delayed left-aligned as I2S compatible. It also
enables the master generator when the codec is a clock consumer, changes
registers before the complete format has been validated, and discards
register I/O errors.
Build all three interface register values before writing them, use the
required one-bit I2S delay, only run the master generator for a provider
configuration, and propagate write failures.
Fixes: 679d7abdc754 ("ASoC: codecs: Add AB8500 codec-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260831-ab8500-codec-fixes-v1-3-f85024e717e3@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/ab8500-codec.c | 175 ++++++++++++--------------------
1 file changed, 64 insertions(+), 111 deletions(-)
diff --git a/sound/soc/codecs/ab8500-codec.c b/sound/soc/codecs/ab8500-codec.c
index c40e1a47e6eee..7d6a90ee337c6 100644
--- a/sound/soc/codecs/ab8500-codec.c
+++ b/sound/soc/codecs/ab8500-codec.c
@@ -2016,149 +2016,91 @@ static int ab8500_audio_set_ear_cmv(struct snd_soc_component *component,
return 0;
}
-static int ab8500_audio_set_bit_delay(struct snd_soc_dai *dai,
- unsigned int delay)
-{
- unsigned int mask, val;
- struct snd_soc_component *component = dai->component;
-
- mask = BIT(AB8500_DIGIFCONF2_IF0DEL);
- val = 0;
-
- switch (delay) {
- case 0:
- break;
- case 1:
- val |= BIT(AB8500_DIGIFCONF2_IF0DEL);
- break;
- default:
- dev_err(dai->component->dev,
- "%s: ERROR: Unsupported bit-delay (0x%x)!\n",
- __func__, delay);
- return -EINVAL;
- }
-
- dev_dbg(dai->component->dev, "%s: IF0 Bit-delay: %d bits.\n",
- __func__, delay);
- snd_soc_component_update_bits(component, AB8500_DIGIFCONF2, mask, val);
-
- return 0;
-}
-
-/* Gates clocking according format mask */
-static int ab8500_codec_set_dai_clock_gate(struct snd_soc_component *component,
- unsigned int fmt)
-{
- unsigned int mask;
- unsigned int val;
-
- mask = BIT(AB8500_DIGIFCONF1_ENMASTGEN) |
- BIT(AB8500_DIGIFCONF1_ENFSBITCLK0);
-
- val = BIT(AB8500_DIGIFCONF1_ENMASTGEN);
-
- switch (fmt & SND_SOC_DAIFMT_CLOCK_MASK) {
- case SND_SOC_DAIFMT_CONT: /* continuous clock */
- dev_dbg(component->dev, "%s: IF0 Clock is continuous.\n",
- __func__);
- val |= BIT(AB8500_DIGIFCONF1_ENFSBITCLK0);
- break;
- case SND_SOC_DAIFMT_GATED: /* clock is gated */
- dev_dbg(component->dev, "%s: IF0 Clock is gated.\n",
- __func__);
- break;
- default:
- dev_err(component->dev,
- "%s: ERROR: Unsupported clock mask (0x%x)!\n",
- __func__, fmt & SND_SOC_DAIFMT_CLOCK_MASK);
- return -EINVAL;
- }
-
- snd_soc_component_update_bits(component, AB8500_DIGIFCONF1, mask, val);
-
- return 0;
-}
-
static int ab8500_codec_set_dai_fmt(struct snd_soc_dai *dai, unsigned int fmt)
{
- unsigned int mask;
- unsigned int val;
struct snd_soc_component *component = dai->component;
- int status;
+ unsigned int conf1_mask, conf1_val = 0;
+ unsigned int conf2_mask, conf2_val = 0;
+ unsigned int conf3_mask, conf3_val = 0;
+ bool provider = false;
+ int ret;
dev_dbg(component->dev, "%s: Enter (fmt = 0x%x)\n", __func__, fmt);
- mask = BIT(AB8500_DIGIFCONF3_IF1DATOIF0AD) |
+ conf3_mask = BIT(AB8500_DIGIFCONF3_IF1DATOIF0AD) |
BIT(AB8500_DIGIFCONF3_IF1CLKTOIF0CLK) |
BIT(AB8500_DIGIFCONF3_IF0BFIFOEN) |
BIT(AB8500_DIGIFCONF3_IF0MASTER);
- val = 0;
switch (fmt & SND_SOC_DAIFMT_CLOCK_PROVIDER_MASK) {
case SND_SOC_DAIFMT_CBP_CFP:
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0 Master-mode: AB8500 provider.\n", __func__);
- val |= BIT(AB8500_DIGIFCONF3_IF0MASTER);
+ conf3_val |= BIT(AB8500_DIGIFCONF3_IF0MASTER);
+ provider = true;
break;
case SND_SOC_DAIFMT_CBC_CFC:
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0 Master-mode: AB8500 consumer.\n", __func__);
break;
case SND_SOC_DAIFMT_CBC_CFP:
case SND_SOC_DAIFMT_CBP_CFC:
- dev_err(dai->component->dev,
+ dev_err(component->dev,
"%s: ERROR: The device is either a provider or a consumer.\n",
__func__);
fallthrough;
default:
- dev_err(dai->component->dev,
- "%s: ERROR: Unsupporter clocking mask 0x%x\n",
+ dev_err(component->dev,
+ "%s: ERROR: Unsupported clocking mask 0x%x\n",
__func__, fmt & SND_SOC_DAIFMT_CLOCK_PROVIDER_MASK);
return -EINVAL;
}
- snd_soc_component_update_bits(component, AB8500_DIGIFCONF3, mask, val);
-
- /* Set clock gating */
- status = ab8500_codec_set_dai_clock_gate(component, fmt);
- if (status) {
- dev_err(dai->component->dev,
- "%s: ERROR: Failed to set clock gate (%d).\n",
- __func__, status);
- return status;
+ conf1_mask = BIT(AB8500_DIGIFCONF1_ENMASTGEN) |
+ BIT(AB8500_DIGIFCONF1_ENFSBITCLK0);
+ switch (fmt & SND_SOC_DAIFMT_CLOCK_MASK) {
+ case SND_SOC_DAIFMT_CONT:
+ if (provider)
+ conf1_val = conf1_mask;
+ break;
+ case SND_SOC_DAIFMT_GATED:
+ if (provider)
+ conf1_val = BIT(AB8500_DIGIFCONF1_ENMASTGEN);
+ break;
+ default:
+ dev_err(component->dev, "%s: Unsupported clock mask 0x%x\n",
+ __func__, fmt & SND_SOC_DAIFMT_CLOCK_MASK);
+ return -EINVAL;
}
- /* Setting data transfer format */
-
- mask = BIT(AB8500_DIGIFCONF2_IF0FORMAT0) |
- BIT(AB8500_DIGIFCONF2_IF0FORMAT1) |
- BIT(AB8500_DIGIFCONF2_FSYNC0P) |
- BIT(AB8500_DIGIFCONF2_BITCLK0P);
- val = 0;
+ conf2_mask = BIT(AB8500_DIGIFCONF2_IF0FORMAT0) |
+ BIT(AB8500_DIGIFCONF2_IF0FORMAT1) |
+ BIT(AB8500_DIGIFCONF2_IF0DEL) |
+ BIT(AB8500_DIGIFCONF2_FSYNC0P) |
+ BIT(AB8500_DIGIFCONF2_BITCLK0P);
switch (fmt & SND_SOC_DAIFMT_FORMAT_MASK) {
case SND_SOC_DAIFMT_I2S: /* I2S mode */
- dev_dbg(dai->component->dev, "%s: IF0 Protocol: I2S\n", __func__);
- val |= BIT(AB8500_DIGIFCONF2_IF0FORMAT1);
- ab8500_audio_set_bit_delay(dai, 0);
+ dev_dbg(component->dev, "%s: IF0 Protocol: I2S\n", __func__);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_IF0FORMAT1) |
+ BIT(AB8500_DIGIFCONF2_IF0DEL);
break;
case SND_SOC_DAIFMT_DSP_A: /* L data MSB after FRM LRC */
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0 Protocol: DSP A (TDM)\n", __func__);
- val |= BIT(AB8500_DIGIFCONF2_IF0FORMAT0);
- ab8500_audio_set_bit_delay(dai, 1);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_IF0FORMAT0) |
+ BIT(AB8500_DIGIFCONF2_IF0DEL);
break;
case SND_SOC_DAIFMT_DSP_B: /* L data MSB during FRM LRC */
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0 Protocol: DSP B (TDM)\n", __func__);
- val |= BIT(AB8500_DIGIFCONF2_IF0FORMAT0);
- ab8500_audio_set_bit_delay(dai, 0);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_IF0FORMAT0);
break;
default:
- dev_err(dai->component->dev,
+ dev_err(component->dev,
"%s: ERROR: Unsupported format (0x%x)!\n",
__func__, fmt & SND_SOC_DAIFMT_FORMAT_MASK);
return -EINVAL;
@@ -2166,39 +2108,50 @@ static int ab8500_codec_set_dai_fmt(struct snd_soc_dai *dai, unsigned int fmt)
switch (fmt & SND_SOC_DAIFMT_INV_MASK) {
case SND_SOC_DAIFMT_NB_NF: /* normal bit clock + frame */
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0: Normal bit clock, normal frame\n",
__func__);
break;
case SND_SOC_DAIFMT_NB_IF: /* normal BCLK + inv FRM */
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0: Normal bit clock, inverted frame\n",
__func__);
- val |= BIT(AB8500_DIGIFCONF2_FSYNC0P);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_FSYNC0P);
break;
case SND_SOC_DAIFMT_IB_NF: /* invert BCLK + nor FRM */
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0: Inverted bit clock, normal frame\n",
__func__);
- val |= BIT(AB8500_DIGIFCONF2_BITCLK0P);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_BITCLK0P);
break;
case SND_SOC_DAIFMT_IB_IF: /* invert BCLK + FRM */
- dev_dbg(dai->component->dev,
+ dev_dbg(component->dev,
"%s: IF0: Inverted bit clock, inverted frame\n",
__func__);
- val |= BIT(AB8500_DIGIFCONF2_FSYNC0P);
- val |= BIT(AB8500_DIGIFCONF2_BITCLK0P);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_FSYNC0P) |
+ BIT(AB8500_DIGIFCONF2_BITCLK0P);
break;
default:
- dev_err(dai->component->dev,
+ dev_err(component->dev,
"%s: ERROR: Unsupported INV mask 0x%x\n",
__func__, fmt & SND_SOC_DAIFMT_INV_MASK);
return -EINVAL;
}
- snd_soc_component_update_bits(component, AB8500_DIGIFCONF2, mask, val);
+ ret = snd_soc_component_update_bits(component, AB8500_DIGIFCONF3,
+ conf3_mask, conf3_val);
+ if (ret < 0)
+ return ret;
- return 0;
+ ret = snd_soc_component_update_bits(component, AB8500_DIGIFCONF1,
+ conf1_mask, conf1_val);
+ if (ret < 0)
+ return ret;
+
+ ret = snd_soc_component_update_bits(component, AB8500_DIGIFCONF2,
+ conf2_mask, conf2_val);
+
+ return ret < 0 ? ret : 0;
}
static int ab8500_codec_set_dai_tdm_slot(struct snd_soc_dai *dai,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 352/982] ASoC: ab8500: Validate and program TDM slots correctly
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (350 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 351/982] ASoC: ab8500: Correct digital interface format setup Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 353/982] net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted Greg Kroah-Hartman
` (636 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 85cef7e2004ef5c1a715feaddb55d3f3d27bac0a ]
The interface clock ratio is selected from the slot count alone, ffs()
and fls() produce one-based hardware slot numbers, eight-channel mode
does not program any mappings, and all register errors are ignored.
Invalid masks can also leave a partially programmed interface.
Validate the complete configuration first, derive the supported BCLK
ratio from slots times slot width, use zero-based slot indices, program
deterministic eight-channel maps, and propagate register failures.
Fixes: 679d7abdc754 ("ASoC: codecs: Add AB8500 codec-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260831-ab8500-codec-fixes-v1-4-f85024e717e3@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/ab8500-codec.c | 216 ++++++++++++++++++--------------
1 file changed, 123 insertions(+), 93 deletions(-)
diff --git a/sound/soc/codecs/ab8500-codec.c b/sound/soc/codecs/ab8500-codec.c
index 7d6a90ee337c6..b6a74d2e6c290 100644
--- a/sound/soc/codecs/ab8500-codec.c
+++ b/sound/soc/codecs/ab8500-codec.c
@@ -2159,23 +2159,27 @@ static int ab8500_codec_set_dai_tdm_slot(struct snd_soc_dai *dai,
int slots, int slot_width)
{
struct snd_soc_component *component = dai->component;
- unsigned int val, mask, slot, slots_active;
+ unsigned int active_mask, clock_ratio, slot, value, ad_out, reg;
+ unsigned int tx_active, rx_active;
+ unsigned int conf1_val, conf2_val;
+ unsigned int mask;
+ int channel, ret;
mask = BIT(AB8500_DIGIFCONF2_IF0WL0) |
BIT(AB8500_DIGIFCONF2_IF0WL1);
- val = 0;
+ conf2_val = 0;
switch (slot_width) {
case 16:
break;
case 20:
- val |= BIT(AB8500_DIGIFCONF2_IF0WL0);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_IF0WL0);
break;
case 24:
- val |= BIT(AB8500_DIGIFCONF2_IF0WL1);
+ conf2_val |= BIT(AB8500_DIGIFCONF2_IF0WL1);
break;
case 32:
- val |= BIT(AB8500_DIGIFCONF2_IF0WL1) |
+ conf2_val |= BIT(AB8500_DIGIFCONF2_IF0WL1) |
BIT(AB8500_DIGIFCONF2_IF0WL0);
break;
default:
@@ -2184,27 +2188,11 @@ static int ab8500_codec_set_dai_tdm_slot(struct snd_soc_dai *dai,
return -EINVAL;
}
- dev_dbg(dai->component->dev, "%s: IF0 slot-width: %d bits.\n",
- __func__, slot_width);
- snd_soc_component_update_bits(component, AB8500_DIGIFCONF2, mask, val);
-
- /* Setup TDM clocking according to slot count */
- dev_dbg(dai->component->dev, "%s: Slots, total: %d\n", __func__, slots);
- mask = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS0) |
- BIT(AB8500_DIGIFCONF1_IF0BITCLKOS1);
switch (slots) {
case 2:
- val = AB8500_MASK_NONE;
- break;
case 4:
- val = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS0);
- break;
case 8:
- val = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS1);
- break;
case 16:
- val = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS0) |
- BIT(AB8500_DIGIFCONF1_IF0BITCLKOS1);
break;
default:
dev_err(dai->component->dev,
@@ -2212,92 +2200,134 @@ static int ab8500_codec_set_dai_tdm_slot(struct snd_soc_dai *dai,
__func__, slots);
return -EINVAL;
}
- snd_soc_component_update_bits(component, AB8500_DIGIFCONF1, mask, val);
-
- /* Setup TDM DA according to active tx slots */
- if (tx_mask & ~0xff)
- return -EINVAL;
-
- mask = AB8500_DASLOTCONFX_SLTODAX_MASK;
- tx_mask = tx_mask << AB8500_DA_DATA0_OFFSET;
- slots_active = hweight32(tx_mask);
-
- dev_dbg(dai->component->dev, "%s: Slots, active, TX: %d\n", __func__,
- slots_active);
-
- switch (slots_active) {
- case 0:
+ clock_ratio = slots * slot_width;
+ switch (clock_ratio) {
+ case 32:
+ conf1_val = 0;
break;
- case 1:
- slot = ffs(tx_mask);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF1, mask, slot);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF3, mask, slot);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF2, mask, slot);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF4, mask, slot);
+ case 64:
+ conf1_val = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS0);
break;
- case 2:
- slot = ffs(tx_mask);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF1, mask, slot);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF3, mask, slot);
- slot = fls(tx_mask);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF2, mask, slot);
- snd_soc_component_update_bits(component, AB8500_DASLOTCONF4, mask, slot);
+ case 128:
+ conf1_val = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS1);
break;
- case 8:
- dev_dbg(dai->component->dev,
- "%s: In 8-channel mode DA-from-slot mapping is set manually.",
- __func__);
+ case 256:
+ conf1_val = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS0) |
+ BIT(AB8500_DIGIFCONF1_IF0BITCLKOS1);
break;
default:
- dev_err(dai->component->dev,
- "%s: Unsupported number of active TX-slots (%d)!\n",
- __func__, slots_active);
+ dev_err(component->dev, "%s: Unsupported BCLK ratio (%u)!\n",
+ __func__, clock_ratio);
return -EINVAL;
}
- /* Setup TDM AD according to active RX-slots */
+ active_mask = GENMASK(min(slots, 8) - 1, 0);
+ if ((tx_mask | rx_mask) & ~active_mask) {
+ dev_err(component->dev, "%s: Slot mask exceeds slot count\n",
+ __func__);
+ return -EINVAL;
+ }
- if (rx_mask & ~0xff)
+ tx_active = hweight32(tx_mask);
+ rx_active = hweight32(rx_mask);
+ if (tx_active != 0 && tx_active != 1 && tx_active != 2 &&
+ tx_active != 8) {
+ dev_err(component->dev, "%s: Unsupported active TX slots (%u)!\n",
+ __func__, tx_active);
+ return -EINVAL;
+ }
+ if (rx_active != 0 && rx_active != 1 && rx_active != 2 &&
+ rx_active != 8) {
+ dev_err(component->dev, "%s: Unsupported active RX slots (%u)!\n",
+ __func__, rx_active);
return -EINVAL;
+ }
+
+ dev_dbg(component->dev,
+ "%s: %d slots of %d bits, TX active: %u, RX active: %u\n",
+ __func__, slots, slot_width, tx_active, rx_active);
- rx_mask = rx_mask << AB8500_AD_DATA0_OFFSET;
- slots_active = hweight32(rx_mask);
+ ret = snd_soc_component_update_bits(component, AB8500_DIGIFCONF2,
+ mask, conf2_val);
+ if (ret < 0)
+ return ret;
- dev_dbg(dai->component->dev, "%s: Slots, active, RX: %d\n", __func__,
- slots_active);
+ mask = BIT(AB8500_DIGIFCONF1_IF0BITCLKOS0) |
+ BIT(AB8500_DIGIFCONF1_IF0BITCLKOS1);
+ ret = snd_soc_component_update_bits(component, AB8500_DIGIFCONF1,
+ mask, conf1_val);
+ if (ret < 0)
+ return ret;
- switch (slots_active) {
- case 0:
- break;
- case 1:
- slot = ffs(rx_mask);
- snd_soc_component_update_bits(component, AB8500_ADSLOTSEL(slot),
- AB8500_MASK_SLOT(slot),
- AB8500_ADSLOTSELX_AD_OUT_TO_SLOT(AB8500_AD_OUT3, slot));
- break;
- case 2:
- slot = ffs(rx_mask);
- snd_soc_component_update_bits(component,
- AB8500_ADSLOTSEL(slot),
- AB8500_MASK_SLOT(slot),
- AB8500_ADSLOTSELX_AD_OUT_TO_SLOT(AB8500_AD_OUT3, slot));
- slot = fls(rx_mask);
- snd_soc_component_update_bits(component,
- AB8500_ADSLOTSEL(slot),
- AB8500_MASK_SLOT(slot),
- AB8500_ADSLOTSELX_AD_OUT_TO_SLOT(AB8500_AD_OUT2, slot));
- break;
- case 8:
- dev_dbg(dai->component->dev,
- "%s: In 8-channel mode AD-to-slot mapping is set manually.",
- __func__);
- break;
- default:
- dev_err(dai->component->dev,
- "%s: Unsupported number of active RX-slots (%d)!\n",
- __func__, slots_active);
- return -EINVAL;
+ mask = AB8500_DASLOTCONFX_SLTODAX_MASK;
+ if (tx_active == 1 || tx_active == 2) {
+ slot = __ffs(tx_mask) + AB8500_DA_DATA0_OFFSET;
+ reg = AB8500_DASLOTCONF1;
+ ret = snd_soc_component_update_bits(component, reg, mask, slot);
+ if (ret < 0)
+ return ret;
+ reg = AB8500_DASLOTCONF3;
+ ret = snd_soc_component_update_bits(component, reg, mask, slot);
+ if (ret < 0)
+ return ret;
+
+ if (tx_active == 2)
+ slot = __fls(tx_mask) + AB8500_DA_DATA0_OFFSET;
+ reg = AB8500_DASLOTCONF2;
+ ret = snd_soc_component_update_bits(component, reg, mask, slot);
+ if (ret < 0)
+ return ret;
+ reg = AB8500_DASLOTCONF4;
+ ret = snd_soc_component_update_bits(component, reg, mask, slot);
+ if (ret < 0)
+ return ret;
+ } else if (tx_active == 8) {
+ channel = 0;
+ for (slot = 0; slot < 8; slot++) {
+ if (!(tx_mask & BIT(slot)))
+ continue;
+ reg = AB8500_DASLOTCONF1 + channel++;
+ value = slot + AB8500_DA_DATA0_OFFSET;
+ ret = snd_soc_component_update_bits(component, reg, mask, value);
+ if (ret < 0)
+ return ret;
+ }
+ }
+
+ if (rx_active == 1 || rx_active == 2) {
+ slot = __ffs(rx_mask) + AB8500_AD_DATA0_OFFSET;
+ value = AB8500_ADSLOTSELX_AD_OUT_TO_SLOT(AB8500_AD_OUT3,
+ slot);
+ reg = AB8500_ADSLOTSEL(slot);
+ mask = AB8500_MASK_SLOT(slot);
+ ret = snd_soc_component_update_bits(component, reg, mask, value);
+ if (ret < 0)
+ return ret;
+
+ if (rx_active == 2) {
+ slot = __fls(rx_mask) + AB8500_AD_DATA0_OFFSET;
+ value = AB8500_ADSLOTSELX_AD_OUT_TO_SLOT(AB8500_AD_OUT2,
+ slot);
+ reg = AB8500_ADSLOTSEL(slot);
+ mask = AB8500_MASK_SLOT(slot);
+ ret = snd_soc_component_update_bits(component, reg, mask, value);
+ if (ret < 0)
+ return ret;
+ }
+ } else if (rx_active == 8) {
+ channel = 0;
+ for (slot = 0; slot < 8; slot++) {
+ if (!(rx_mask & BIT(slot)))
+ continue;
+ ad_out = AB8500_AD_OUT1 + channel++;
+ value = AB8500_ADSLOTSELX_AD_OUT_TO_SLOT(ad_out, slot);
+ reg = AB8500_ADSLOTSEL(slot);
+ mask = AB8500_MASK_SLOT(slot);
+ ret = snd_soc_component_update_bits(component, reg, mask, value);
+ if (ret < 0)
+ return ret;
+ }
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 353/982] net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (351 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 352/982] ASoC: ab8500: Validate and program TDM slots correctly Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 354/982] ppp: ppp_async: simplify tty disc_data access Greg Kroah-Hartman
` (635 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, vega, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit d7e7e98d23f42a92d9ab7e36302bd96bd9b33b5f ]
gen_new_kid() falls back to returning max (htid | 0xFFF) when both
idr_alloc_u32() ranges are full, instead of reporting an error.
u32_change() trusts that value and inserts a new knode with a handle
that is already live in the hash table, breaking handle uniqueness
within the table's node ID space.
The handle was never reserved in ht->handle_idr, so every later error
path that does idr_remove(&ht->handle_idr, handle) removes the
reservation of a different, live knode, which is then reused — one
failed add compounds into further duplicates.
The 4095 limit is per (table, bucket) — ht->handle_idr is per hash
table and the range is derived from htid (bucketid), so a table with
divisor 256 can legitimately hold 256*4095 knodes.
The sibling helper gen_new_htid() has the same silent in-band failure:
it returns 0 when the tp_c handle pool (1..0x7FF) is full, and
u32_init() publishes the root hash table with handle 0 without
checking. Two root tables with handle 0 alias in u32_lookup_ht(),
allowing cross-tcf_proto knode add/lookup/delete. Add the same
exhaustion check that the divisor path already has.
Return an error so u32_change() fails with ENOSPC/ENOMEM when the
node ID space is exhausted, and so u32_init() fails with -ENOMEM
when the hash table ID space is exhausted. The extack message
distinguishes pool exhaustion (-ENOSPC) from a transient allocation
failure (-ENOMEM).
Conditions to recreate the bug:
- CONFIG_NET_SCHED=y, CONFIG_CLS_U32=y (or =m with module loaded)
- Create a clsact qdisc on a device, then add 4095 u32 filters with
auto-generated handles to fill the node ID space for the root hash
table (single bucket). The 4096th auto-handle filter add triggers
the duplicate handle (fh 800::fff reused). Reachable at Level 2
(unshare -Urn, namespace-local CAP_NET_ADMIN).
- For gen_new_htid: create 2047 u32 proto entries on the same block
to fill the tp_c handle pool, then create one more. The root table
gets handle 0 and aliases with other handle-0 root tables.
Fixes: 7801db8aec95 ("net_sched: avoid generating same handle for u32 filters")
Reported-by: vega@nebusec.ai
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/20260825081052.133898-1-jhs@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/cls_u32.c | 32 ++++++++++++++++++++++++++------
1 file changed, 26 insertions(+), 6 deletions(-)
diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
index 1c914e721a3ca..0c6b6f2aeb531 100644
--- a/net/sched/cls_u32.c
+++ b/net/sched/cls_u32.c
@@ -368,6 +368,10 @@ static int u32_init(struct tcf_proto *tp)
refcount_set(&root_ht->refcnt, 1);
root_ht->handle = tp_c ? gen_new_htid(tp_c, root_ht) : id2handle(0);
+ if (root_ht->handle == 0) {
+ kfree(root_ht);
+ return -ENOMEM;
+ }
root_ht->prio = tp->prio;
root_ht->is_root = true;
idr_init(&root_ht->handle_idr);
@@ -693,21 +697,33 @@ static int u32_delete(struct tcf_proto *tp, void *arg, bool *last,
return ret;
}
-static u32 gen_new_kid(struct tc_u_hnode *ht, u32 htid)
+static u32 gen_new_kid(struct tc_u_hnode *ht, u32 htid, int *err)
{
u32 index = htid | 0x800;
u32 max = htid | 0xFFF;
+ *err = 0;
+
if (idr_alloc_u32(&ht->handle_idr, NULL, &index, max, GFP_KERNEL)) {
index = htid + 1;
- if (idr_alloc_u32(&ht->handle_idr, NULL, &index, max,
- GFP_KERNEL))
- index = max;
+ *err = idr_alloc_u32(&ht->handle_idr, NULL, &index, max,
+ GFP_KERNEL);
+ if (*err)
+ return 0;
}
return index;
}
+static int u32_kid_extack(int err, struct netlink_ext_ack *extack)
+{
+ if (err == -ENOSPC)
+ NL_SET_ERR_MSG_MOD(extack, "Hash table node ID pool exhausted");
+ else
+ NL_SET_ERR_MSG_MOD(extack, "Failed to allocate node ID");
+ return err;
+}
+
static const struct nla_policy u32_policy[TCA_U32_MAX + 1] = {
[TCA_U32_CLASSID] = { .type = NLA_U32 },
[TCA_U32_HASH] = { .type = NLA_U32 },
@@ -1072,7 +1088,9 @@ static int u32_change(struct net *net, struct sk_buff *in_skb,
* handle which is used to uniquely identify the match entry.
*/
if (!TC_U32_NODE(handle)) {
- handle = gen_new_kid(ht, htid);
+ handle = gen_new_kid(ht, htid, &err);
+ if (err)
+ return u32_kid_extack(err, extack);
} else {
handle = htid | TC_U32_NODE(handle);
err = idr_alloc_u32(&ht->handle_idr, NULL, &handle,
@@ -1084,7 +1102,9 @@ static int u32_change(struct net *net, struct sk_buff *in_skb,
/* The user did not give us a handle; lets just generate one
* from the table's pool of nodeids.
*/
- handle = gen_new_kid(ht, htid);
+ handle = gen_new_kid(ht, htid, &err);
+ if (err)
+ return u32_kid_extack(err, extack);
}
if (tb[TCA_U32_SEL] == NULL) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 354/982] ppp: ppp_async: simplify tty disc_data access
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (352 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 353/982] net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 355/982] ipv6: tunnels: use DEV_STATS_INC() Greg Kroah-Hartman
` (634 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+8e808eb853386f575d86,
Qingfang Deng, Eric Dumazet, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qingfang Deng <qingfang.deng@linux.dev>
[ Upstream commit 9feb069e5ed03582fbf6272539f1caa2a17dc6d5 ]
tty_ldisc_hangup() invokes the hangup callback while holding only a read
lock on tty->ldisc_sem, so it can run concurrently with other line
discipline callbacks. This currently forces async PPP to maintain
separate lifetime protection around tty->disc_data.
Line discipline close is called under the write lock during hangup
processing. Remove the hangup callback and rely on close for teardown,
as done for SLIP by commit 23c53269f2ba ("slip: remove slip_hangup() to
fix use-after-free in slip_receive_buf()"). This serializes teardown
with all other line discipline operations.
disc_data_lock, refcount and completion are redundant with that
serialization. Remove them and access tty->disc_data directly.
This also eliminates a lockdep warning reported by syzbot. The warning
does not indicate a real deadlock because the write side runs only in
process context with hardirqs disabled.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+8e808eb853386f575d86@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/0000000000002fbad30611e25849@google.com/
Signed-off-by: Qingfang Deng <qingfang.deng@linux.dev>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260828073245.126804-1-qingfang.deng@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ppp/ppp_async.c | 82 ++++---------------------------------
1 file changed, 7 insertions(+), 75 deletions(-)
diff --git a/drivers/net/ppp/ppp_async.c b/drivers/net/ppp/ppp_async.c
index aba0744c0ab58..3f3c662550372 100644
--- a/drivers/net/ppp/ppp_async.c
+++ b/drivers/net/ppp/ppp_async.c
@@ -65,8 +65,6 @@ struct asyncppp {
struct tasklet_struct tsk;
- refcount_t refcnt;
- struct completion dead;
struct ppp_channel chan; /* interface to generic ppp layer */
unsigned char obuf[OBUFSIZE];
};
@@ -115,38 +113,6 @@ static const struct ppp_channel_ops async_ops = {
* Routines implementing the PPP line discipline.
*/
-/*
- * We have a potential race on dereferencing tty->disc_data,
- * because the tty layer provides no locking at all - thus one
- * cpu could be running ppp_asynctty_receive while another
- * calls ppp_asynctty_close, which zeroes tty->disc_data and
- * frees the memory that ppp_asynctty_receive is using. The best
- * way to fix this is to use a rwlock in the tty struct, but for now
- * we use a single global rwlock for all ttys in ppp line discipline.
- *
- * FIXME: this is no longer true. The _close path for the ldisc is
- * now guaranteed to be sane.
- */
-static DEFINE_RWLOCK(disc_data_lock);
-
-static struct asyncppp *ap_get(struct tty_struct *tty)
-{
- struct asyncppp *ap;
-
- read_lock(&disc_data_lock);
- ap = tty->disc_data;
- if (ap != NULL)
- refcount_inc(&ap->refcnt);
- read_unlock(&disc_data_lock);
- return ap;
-}
-
-static void ap_put(struct asyncppp *ap)
-{
- if (refcount_dec_and_test(&ap->refcnt))
- complete(&ap->dead);
-}
-
/*
* Called when a tty is put into PPP line discipline. Called in process
* context.
@@ -181,9 +147,6 @@ ppp_asynctty_open(struct tty_struct *tty)
skb_queue_head_init(&ap->rqueue);
tasklet_setup(&ap->tsk, ppp_async_process);
- refcount_set(&ap->refcnt, 1);
- init_completion(&ap->dead);
-
ap->chan.private = ap;
ap->chan.ops = &async_ops;
ap->chan.mtu = PPP_MRU;
@@ -204,34 +167,18 @@ ppp_asynctty_open(struct tty_struct *tty)
}
/*
- * Called when the tty is put into another line discipline
- * or it hangs up. We have to wait for any cpu currently
- * executing in any of the other ppp_asynctty_* routines to
- * finish before we can call ppp_unregister_channel and free
- * the asyncppp struct. This routine must be called from
- * process context, not interrupt or softirq context.
+ * Called when the tty is put into another line discipline or it hangs up.
+ * This call is serialized against other ldisc functions.
*/
static void
ppp_asynctty_close(struct tty_struct *tty)
{
- struct asyncppp *ap;
+ struct asyncppp *ap = tty->disc_data;
- write_lock_irq(&disc_data_lock);
- ap = tty->disc_data;
- tty->disc_data = NULL;
- write_unlock_irq(&disc_data_lock);
if (!ap)
return;
- /*
- * We have now ensured that nobody can start using ap from now
- * on, but we have to wait for all existing users to finish.
- * Note that ppp_unregister_channel ensures that no calls to
- * our channel ops (i.e. ppp_async_send/ioctl) are in progress
- * by the time it returns.
- */
- if (!refcount_dec_and_test(&ap->refcnt))
- wait_for_completion(&ap->dead);
+ tty->disc_data = NULL;
tasklet_kill(&ap->tsk);
ppp_unregister_channel(&ap->chan);
@@ -241,17 +188,6 @@ ppp_asynctty_close(struct tty_struct *tty)
kfree(ap);
}
-/*
- * Called on tty hangup in process context.
- *
- * Wait for I/O to driver to complete and unregister PPP channel.
- * This is already done by the close routine, so just call that.
- */
-static void ppp_asynctty_hangup(struct tty_struct *tty)
-{
- ppp_asynctty_close(tty);
-}
-
/*
* Read does nothing - no data is ever available this way.
* Pppd reads and writes packets via /dev/ppp instead.
@@ -283,7 +219,7 @@ ppp_asynctty_write(struct tty_struct *tty, struct file *file,
static int
ppp_asynctty_ioctl(struct tty_struct *tty, unsigned int cmd, unsigned long arg)
{
- struct asyncppp *ap = ap_get(tty);
+ struct asyncppp *ap = tty->disc_data;
int err, val;
int __user *p = (int __user *)arg;
@@ -324,7 +260,6 @@ ppp_asynctty_ioctl(struct tty_struct *tty, unsigned int cmd, unsigned long arg)
err = tty_mode_ioctl(tty, cmd, arg);
}
- ap_put(ap);
return err;
}
@@ -340,7 +275,7 @@ static void
ppp_asynctty_receive(struct tty_struct *tty, const unsigned char *buf,
const char *cflags, int count)
{
- struct asyncppp *ap = ap_get(tty);
+ struct asyncppp *ap = tty->disc_data;
unsigned long flags;
if (!ap)
@@ -350,21 +285,19 @@ ppp_asynctty_receive(struct tty_struct *tty, const unsigned char *buf,
spin_unlock_irqrestore(&ap->recv_lock, flags);
if (!skb_queue_empty(&ap->rqueue))
tasklet_schedule(&ap->tsk);
- ap_put(ap);
tty_unthrottle(tty);
}
static void
ppp_asynctty_wakeup(struct tty_struct *tty)
{
- struct asyncppp *ap = ap_get(tty);
+ struct asyncppp *ap = tty->disc_data;
clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
if (!ap)
return;
set_bit(XMIT_WAKEUP, &ap->xmit_flags);
tasklet_schedule(&ap->tsk);
- ap_put(ap);
}
@@ -374,7 +307,6 @@ static struct tty_ldisc_ops ppp_ldisc = {
.name = "ppp",
.open = ppp_asynctty_open,
.close = ppp_asynctty_close,
- .hangup = ppp_asynctty_hangup,
.read = ppp_asynctty_read,
.write = ppp_asynctty_write,
.ioctl = ppp_asynctty_ioctl,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 355/982] ipv6: tunnels: use DEV_STATS_INC()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (353 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 354/982] ppp: ppp_async: simplify tty disc_data access Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 356/982] ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit Greg Kroah-Hartman
` (633 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, David S. Miller,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 2fad1ba354d4a82b1b635a78f25d9682d4febb5e ]
Most of code paths in tunnels are lockless (eg NETIF_F_LLTX in tx).
Adopt SMP safe DEV_STATS_{INC|ADD}() to update dev->stats fields.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: 97cc84dad1d7 ("ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ip6_gre.c | 11 ++++-------
net/ipv6/ip6_tunnel.c | 26 ++++++++++++--------------
net/ipv6/ip6_vti.c | 16 +++++++---------
net/ipv6/ip6mr.c | 10 +++++-----
4 files changed, 28 insertions(+), 35 deletions(-)
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index e298981be75f6..a2c4287d3c753 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -918,7 +918,6 @@ static netdev_tx_t ip6gre_tunnel_xmit(struct sk_buff *skb,
struct net_device *dev)
{
struct ip6_tnl *t = netdev_priv(dev);
- struct net_device_stats *stats = &t->dev->stats;
__be16 payload_protocol;
int ret;
@@ -948,8 +947,8 @@ static netdev_tx_t ip6gre_tunnel_xmit(struct sk_buff *skb,
tx_err:
if (!t->parms.collect_md || !IS_ERR(skb_tunnel_info_txcheck(skb)))
- stats->tx_errors++;
- stats->tx_dropped++;
+ DEV_STATS_INC(dev, tx_errors);
+ DEV_STATS_INC(dev, tx_dropped);
kfree_skb(skb);
return NETDEV_TX_OK;
}
@@ -960,7 +959,6 @@ static netdev_tx_t ip6erspan_tunnel_xmit(struct sk_buff *skb,
struct ip_tunnel_info *tun_info = NULL;
struct ip6_tnl *t = netdev_priv(dev);
struct dst_entry *dst = skb_dst(skb);
- struct net_device_stats *stats;
bool truncate = false;
int encap_limit = -1;
__u8 dsfield = false;
@@ -1113,10 +1111,9 @@ static netdev_tx_t ip6erspan_tunnel_xmit(struct sk_buff *skb,
return NETDEV_TX_OK;
tx_err:
- stats = &t->dev->stats;
if (!IS_ERR(tun_info))
- stats->tx_errors++;
- stats->tx_dropped++;
+ DEV_STATS_INC(dev, tx_errors);
+ DEV_STATS_INC(dev, tx_dropped);
kfree_skb(skb);
return NETDEV_TX_OK;
}
diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c
index 8519579be257c..0deea48700574 100644
--- a/net/ipv6/ip6_tunnel.c
+++ b/net/ipv6/ip6_tunnel.c
@@ -811,8 +811,8 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb,
(tunnel->parms.i_flags & TUNNEL_CSUM)) ||
((tpi->flags & TUNNEL_CSUM) &&
!(tunnel->parms.i_flags & TUNNEL_CSUM))) {
- tunnel->dev->stats.rx_crc_errors++;
- tunnel->dev->stats.rx_errors++;
+ DEV_STATS_INC(tunnel->dev, rx_crc_errors);
+ DEV_STATS_INC(tunnel->dev, rx_errors);
goto drop;
}
@@ -820,8 +820,8 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb,
if (!(tpi->flags & TUNNEL_SEQ) ||
(tunnel->i_seqno &&
(s32)(ntohl(tpi->seq) - tunnel->i_seqno) < 0)) {
- tunnel->dev->stats.rx_fifo_errors++;
- tunnel->dev->stats.rx_errors++;
+ DEV_STATS_INC(tunnel->dev, rx_fifo_errors);
+ DEV_STATS_INC(tunnel->dev, rx_errors);
goto drop;
}
tunnel->i_seqno = ntohl(tpi->seq) + 1;
@@ -832,8 +832,8 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb,
/* Warning: All skb pointers will be invalidated! */
if (tunnel->dev->type == ARPHRD_ETHER) {
if (!pskb_may_pull(skb, ETH_HLEN)) {
- tunnel->dev->stats.rx_length_errors++;
- tunnel->dev->stats.rx_errors++;
+ DEV_STATS_INC(tunnel->dev, rx_length_errors);
+ DEV_STATS_INC(tunnel->dev, rx_errors);
goto drop;
}
@@ -872,8 +872,8 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb,
&ipv6h->saddr,
ipv6_get_dsfield(ipv6h));
if (err > 1) {
- ++tunnel->dev->stats.rx_frame_errors;
- ++tunnel->dev->stats.rx_errors;
+ DEV_STATS_INC(tunnel->dev, rx_frame_errors);
+ DEV_STATS_INC(tunnel->dev, rx_errors);
goto drop;
}
}
@@ -1094,7 +1094,6 @@ int ip6_tnl_xmit(struct sk_buff *skb, struct net_device *dev, __u8 dsfield,
{
struct ip6_tnl *t = netdev_priv(dev);
struct net *net = t->net;
- struct net_device_stats *stats = &t->dev->stats;
struct ipv6hdr *ipv6h;
struct ipv6_tel_txoption opt;
struct dst_entry *dst = NULL, *ndst = NULL;
@@ -1189,7 +1188,7 @@ int ip6_tnl_xmit(struct sk_buff *skb, struct net_device *dev, __u8 dsfield,
tdev = dst->dev;
if (tdev == dev) {
- stats->collisions++;
+ DEV_STATS_INC(dev, collisions);
net_warn_ratelimited("%s: Local routing loop detected!\n",
t->parms.name);
goto tx_err_dst_release;
@@ -1276,7 +1275,7 @@ int ip6_tnl_xmit(struct sk_buff *skb, struct net_device *dev, __u8 dsfield,
ip6tunnel_xmit(NULL, skb, dev);
return 0;
tx_err_link_failure:
- stats->tx_carrier_errors++;
+ DEV_STATS_INC(dev, tx_carrier_errors);
dst_link_failure(skb);
tx_err_dst_release:
dst_release(dst);
@@ -1419,7 +1418,6 @@ static netdev_tx_t
ip6_tnl_start_xmit(struct sk_buff *skb, struct net_device *dev)
{
struct ip6_tnl *t = netdev_priv(dev);
- struct net_device_stats *stats = &t->dev->stats;
u8 ipproto;
int ret;
@@ -1449,8 +1447,8 @@ ip6_tnl_start_xmit(struct sk_buff *skb, struct net_device *dev)
return NETDEV_TX_OK;
tx_err:
- stats->tx_errors++;
- stats->tx_dropped++;
+ DEV_STATS_INC(dev, tx_errors);
+ DEV_STATS_INC(dev, tx_dropped);
kfree_skb(skb);
return NETDEV_TX_OK;
}
diff --git a/net/ipv6/ip6_vti.c b/net/ipv6/ip6_vti.c
index 856ceb9551e61..1bdd5e50c9b85 100644
--- a/net/ipv6/ip6_vti.c
+++ b/net/ipv6/ip6_vti.c
@@ -319,7 +319,7 @@ static int vti6_input_proto(struct sk_buff *skb, int nexthdr, __be32 spi,
ipv6h = ipv6_hdr(skb);
if (!ip6_tnl_rcv_ctl(t, &ipv6h->daddr, &ipv6h->saddr)) {
- t->dev->stats.rx_dropped++;
+ DEV_STATS_INC(t->dev, rx_dropped);
rcu_read_unlock();
goto discard;
}
@@ -361,8 +361,8 @@ static int vti6_rcv_cb(struct sk_buff *skb, int err)
dev = t->dev;
if (err) {
- dev->stats.rx_errors++;
- dev->stats.rx_dropped++;
+ DEV_STATS_INC(dev, rx_errors);
+ DEV_STATS_INC(dev, rx_dropped);
return 0;
}
@@ -448,7 +448,6 @@ static int
vti6_xmit(struct sk_buff *skb, struct net_device *dev, struct flowi *fl)
{
struct ip6_tnl *t = netdev_priv(dev);
- struct net_device_stats *stats = &t->dev->stats;
struct dst_entry *dst = skb_dst(skb);
struct net_device *tdev;
struct xfrm_state *x;
@@ -508,7 +507,7 @@ vti6_xmit(struct sk_buff *skb, struct net_device *dev, struct flowi *fl)
tdev = dst->dev;
if (tdev == dev) {
- stats->collisions++;
+ DEV_STATS_INC(dev, collisions);
net_warn_ratelimited("%s: Local routing loop detected!\n",
t->parms.name);
goto tx_err_dst_release;
@@ -546,7 +545,7 @@ vti6_xmit(struct sk_buff *skb, struct net_device *dev, struct flowi *fl)
return 0;
tx_err_link_failure:
- stats->tx_carrier_errors++;
+ DEV_STATS_INC(dev, tx_carrier_errors);
dst_link_failure(skb);
tx_err_dst_release:
dst_release(dst);
@@ -557,7 +556,6 @@ static netdev_tx_t
vti6_tnl_xmit(struct sk_buff *skb, struct net_device *dev)
{
struct ip6_tnl *t = netdev_priv(dev);
- struct net_device_stats *stats = &t->dev->stats;
struct flowi fl;
int ret;
@@ -593,8 +591,8 @@ vti6_tnl_xmit(struct sk_buff *skb, struct net_device *dev)
return NETDEV_TX_OK;
tx_err:
- stats->tx_errors++;
- stats->tx_dropped++;
+ DEV_STATS_INC(dev, tx_errors);
+ DEV_STATS_INC(dev, tx_dropped);
kfree_skb(skb);
return NETDEV_TX_OK;
}
diff --git a/net/ipv6/ip6mr.c b/net/ipv6/ip6mr.c
index 00774cfa011af..3c60a63c9f31f 100644
--- a/net/ipv6/ip6mr.c
+++ b/net/ipv6/ip6mr.c
@@ -622,8 +622,8 @@ static netdev_tx_t reg_vif_xmit(struct sk_buff *skb,
if (ip6mr_fib_lookup(net, &fl6, &mrt) < 0)
goto tx_err;
- dev->stats.tx_bytes += skb->len;
- dev->stats.tx_packets++;
+ DEV_STATS_ADD(dev, tx_bytes, skb->len);
+ DEV_STATS_INC(dev, tx_packets);
rcu_read_lock();
ip6mr_cache_report(mrt, skb, READ_ONCE(mrt->mroute_reg_vif_num),
MRT6MSG_WHOLEPKT);
@@ -632,7 +632,7 @@ static netdev_tx_t reg_vif_xmit(struct sk_buff *skb,
return NETDEV_TX_OK;
tx_err:
- dev->stats.tx_errors++;
+ DEV_STATS_INC(dev, tx_errors);
kfree_skb(skb);
return NETDEV_TX_OK;
}
@@ -2059,8 +2059,8 @@ static int ip6mr_forward2(struct net *net, struct mr_table *mrt,
if (vif->flags & MIFF_REGISTER) {
WRITE_ONCE(vif->pkt_out, vif->pkt_out + 1);
WRITE_ONCE(vif->bytes_out, vif->bytes_out + skb->len);
- vif_dev->stats.tx_bytes += skb->len;
- vif_dev->stats.tx_packets++;
+ DEV_STATS_ADD(vif_dev, tx_bytes, skb->len);
+ DEV_STATS_INC(vif_dev, tx_packets);
ip6mr_cache_report(mrt, skb, vifi, MRT6MSG_WHOLEPKT);
goto out_free;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 356/982] ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (354 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 355/982] ipv6: tunnels: use DEV_STATS_INC() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 357/982] tipc: fix NULL deref in tipc_named_node_up() on empty publication list Greg Kroah-Hartman
` (632 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Davide Caratti,
Eric Dumazet, Ido Schimmel, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 97cc84dad1d7f68a36b71b69b361d88482707673 ]
Shuangpeng Bai reported a KASAN slab-use-after-free in
ip6gre_tunnel_xmit().
The precise KASAN bug was caused by ip6_tnl_xmit() consuming the
skb during headroom expansion and returning an error, while
ip6gre_tunnel_xmit() still held the stale pointer and called
skb_tunnel_info_txcheck(skb) at tx_err. That specific bug was fixed by
commit 87f21b59ddc6 ("ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()").
However, calling skb_tunnel_info_txcheck(skb) at the tx_err label
after the transmission attempt remains problematic:
Downstream helpers like ip6_tnl_xmit() call skb_scrub_packet(),
which drops the skb's metadata_dst before transmission. If an error
occurs later during transmit, inspecting skb at tx_err sees a scrubbed
dst and misclassifies tx_errors vs tx_dropped.
Commit e5f7e211b6aa ("ip6gre: avoid tx_error when sending MLD/DAD on
external tunnels") already handled this correctly in
ip6erspan_tunnel_xmit() by checking and caching tun_info before
transmit.
Align ip6gre_tunnel_xmit() with ip6erspan_tunnel_xmit() by caching
tun_info before xmit and checking it at tx_err.
Fixes: e5f7e211b6aa ("ip6gre: avoid tx_error when sending MLD/DAD on external tunnels")
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Closes: https://lore.kernel.org/netdev/20260819062224.3197349-1-shuangpeng.kernel@gmail.com/
Cc: Davide Caratti <dcaratti@redhat.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260828103731.1951815-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ip6_gre.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index a2c4287d3c753..86d2fbed0a363 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -917,6 +917,7 @@ static int ip6gre_xmit_other(struct sk_buff *skb, struct net_device *dev)
static netdev_tx_t ip6gre_tunnel_xmit(struct sk_buff *skb,
struct net_device *dev)
{
+ struct ip_tunnel_info *tun_info = NULL;
struct ip6_tnl *t = netdev_priv(dev);
__be16 payload_protocol;
int ret;
@@ -927,6 +928,9 @@ static netdev_tx_t ip6gre_tunnel_xmit(struct sk_buff *skb,
if (!ip6_tnl_xmit_ctl(t, &t->parms.laddr, &t->parms.raddr))
goto tx_err;
+ if (t->parms.collect_md)
+ tun_info = skb_tunnel_info_txcheck(skb);
+
payload_protocol = skb_protocol(skb, true);
switch (payload_protocol) {
case htons(ETH_P_IP):
@@ -946,7 +950,7 @@ static netdev_tx_t ip6gre_tunnel_xmit(struct sk_buff *skb,
return NETDEV_TX_OK;
tx_err:
- if (!t->parms.collect_md || !IS_ERR(skb_tunnel_info_txcheck(skb)))
+ if (!IS_ERR(tun_info))
DEV_STATS_INC(dev, tx_errors);
DEV_STATS_INC(dev, tx_dropped);
kfree_skb(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 357/982] tipc: fix NULL deref in tipc_named_node_up() on empty publication list
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (355 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 356/982] ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 358/982] ipv6: sr: restore network header before routing and forwarding Greg Kroah-Hartman
` (631 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi, Tung Nguyen,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tung Nguyen <tung.quang.nguyen@est.tech>
[ Upstream commit b3b76e9f4f2476f1135b2ba7743a821db4a0df4b ]
User-space applications can bind a large number of service addresses to
one or more sockets. Each binding of a local-scope service address inserts
one entry (publication) into the TIPC name table. If the number of these
publications exceeds TIPC_MAX_PUBL (65535), protocol service types
(such as node state and link state) are no longer inserted into the name
table. This causes two issues:
1. User-space applications subscribing to node or link up/down events
stop receiving notifications.
2. A NULL pointer dereference can occur:
BUG: kernel NULL pointer dereference, address: 00000000000000d0
...
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc4-default+ #5 PREEMPT(full)
...
RIP: 0010:tipc_named_node_up (./include/linux/skbuff.h:2251 net/tipc/name_distr.c:195 net/tipc/name_distr.c:221)
...
Call Trace:
<IRQ>
tipc_node_write_unlock (net/tipc/node.c:428)
tipc_rcv (net/tipc/node.c:934 net/tipc/node.c:2189)
tipc_udp_recv (net/tipc/udp_media.c:389)
Thread 1 (tipc_net_finalize) | Thread 2 (named_distribute)
-----------------------------|-----------------------------
| ...
| list_for_each_entry(publ, pls, binding_node) {
| ...
| __skb_queue_tail(list, skb);
| ...
| }
| ...
| hdr = buf_msg(skb_peek_tail(list));
... |
tipc_nametbl_publish(); |
If 'tipc_nametbl_publish()' (Thread 1) fails because the number of
local publications reaches TIPC_MAX_PUBL, list (Thread 2) will be empty. As a
result, NULL is passed to 'buf_msg()', leading to a NULL pointer dereference.
Fix these issues by allowing protocol service types (node state, link state,
and topology server) to be inserted into the name table unconditionally.
This ensures that users subscribing to these types always receive
notifications. In addition, the maximum number of local user publications is
reduced to (TIPC_MAX_PUBL - 1). This ensures that the maximum bulk size
calculated in tipc_link_set_queue_limits() remains valid.
Fixes: a5e7ac5ce134 ("tipc: fix regression bug where node events are not being generated")
Reported-by: Xiang Mei <xmei5@asu.edu>
Tested-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260827111418.164957-1-tung.quang.nguyen@est.tech
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/tipc/name_table.c | 30 ++++++++++++++++++++++++++----
1 file changed, 26 insertions(+), 4 deletions(-)
diff --git a/net/tipc/name_table.c b/net/tipc/name_table.c
index e6555254ddb85..d28fe53d2cb06 100644
--- a/net/tipc/name_table.c
+++ b/net/tipc/name_table.c
@@ -763,21 +763,40 @@ struct publication *tipc_nametbl_publish(struct net *net, struct tipc_uaddr *ua,
struct tipc_socket_addr *sk, u32 key)
{
struct name_table *nt = tipc_name_table(net);
+ u32 max_user_pub = TIPC_MAX_PUBL - 1;
struct tipc_net *tn = tipc_net(net);
struct publication *p = NULL;
struct sk_buff *skb = NULL;
+ bool protocol_type = false;
u32 rc_dests;
+ if (ua->sr.type == TIPC_NODE_STATE || ua->sr.type == TIPC_LINK_STATE ||
+ ua->sr.type == TIPC_TOP_SRV)
+ protocol_type = true;
+
spin_lock_bh(&tn->nametbl_lock);
+ if (protocol_type)
+ goto insert;
- if (nt->local_publ_count >= TIPC_MAX_PUBL) {
- pr_warn("Bind failed, max limit %u reached\n", TIPC_MAX_PUBL);
+ /* Reserve one entry for node state service type because it has cluster
+ * scope and it is distributed in bulk. So, the maximum number of user's
+ * publications is (TIPC_MAX_PUBL - 1).
+ */
+ if (nt->local_publ_count >= max_user_pub) {
+ pr_warn("Bind failed, max limit %u reached\n", max_user_pub);
goto exit;
}
+insert:
p = tipc_nametbl_insert_publ(net, ua, sk, key);
if (p) {
- nt->local_publ_count++;
+ /* Not count node state, link state and topology server types
+ * so that maximum nt->local_publ_count does not prevent
+ * protocol service types from being inserted into the name
+ * table.
+ */
+ if (!protocol_type)
+ nt->local_publ_count++;
skb = tipc_named_publish(net, p);
}
rc_dests = nt->rc_dests;
@@ -810,7 +829,10 @@ void tipc_nametbl_withdraw(struct net *net, struct tipc_uaddr *ua,
p = tipc_nametbl_remove_publ(net, ua, sk, key);
if (p) {
- nt->local_publ_count--;
+ if (p->sr.type != TIPC_NODE_STATE &&
+ p->sr.type != TIPC_LINK_STATE &&
+ p->sr.type != TIPC_TOP_SRV)
+ nt->local_publ_count--;
skb = tipc_named_withdraw(net, p);
list_del_init(&p->binding_sock);
kfree_rcu(p, rcu);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 358/982] ipv6: sr: restore network header before routing and forwarding
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (356 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 357/982] tipc: fix NULL deref in tipc_named_node_up() on empty publication list Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 359/982] af_packet: Dont cast tpacket_hdr.tp_len to int in tpacket_parse_header() Greg Kroah-Hartman
` (630 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI, Jun Yang,
Fourie Zhang, Eric Dumazet, Ido Schimmel, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 975b5b067f525a1b1338c4a3bee1c46545801518 ]
ipv6_srh_rcv() runs with skb->data at the Segment Routing Header (SRH)
while skb_network_header() points at the IPv6 header.
When segments_left > 0, ipv6_srh_rcv() previously restored the skb->data
position by pushing sizeof(struct ipv6hdr), assuming the SRH immediately
followed the fixed IPv6 header. If another extension header (such as a
Hop-by-Hop options header) precedes the SRH, skb_network_offset()
remained negative.
This led to two problems:
1. During ip6_route_input(), fib6_rules_early_flow_dissect() invokes
__skb_flow_dissect() which passes the negative skb_network_offset()
to flow dissection, breaking BPF and C flow dissector logic.
2. If forwarded via ip6_forward() or redirected via act_mirred, downstream
handlers (like sch_fragment() or neighbour output) pass the negative
offset as an unsigned length, triggering OOB memcpy or buffer overflows.
Fix this by pushing -skb_network_offset(skb) before routing, ensuring
skb_network_offset(skb) is 0 for route lookup / flow dissection as well as
downstream forwarding. On the loopback path, pull skb_transport_offset(skb)
to restore skb->data to the SRH before looping back.
Fixes: 1ababeba4a21 ("ipv6: implement dataplane support for rthdr type 4 (Segment Routing Header)")
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Reported-by: Jun Yang <junvyyang@tencent.com>
Reported-by: Fourie Zhang <fouriezhang@tencent.com>
Closes: https://lore.kernel.org/netdev/20260817104128.22681-1-juny24602@gmail.com/
Closes: https://lore.kernel.org/netdev/20260827092345.2301937-1-fouriezhang@tencent.com/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260828141727.2372570-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/exthdrs.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/ipv6/exthdrs.c b/net/ipv6/exthdrs.c
index 823d405069b7d..afed094c8ac02 100644
--- a/net/ipv6/exthdrs.c
+++ b/net/ipv6/exthdrs.c
@@ -462,7 +462,7 @@ static int ipv6_srh_rcv(struct sk_buff *skb)
hdr->segments_left--;
addr = hdr->segments + hdr->segments_left;
- skb_push(skb, sizeof(struct ipv6hdr));
+ skb_push(skb, -skb_network_offset(skb));
if (skb->ip_summed == CHECKSUM_COMPLETE)
seg6_update_csum(skb);
@@ -488,7 +488,7 @@ static int ipv6_srh_rcv(struct sk_buff *skb)
}
ipv6_hdr(skb)->hop_limit--;
- skb_pull(skb, sizeof(struct ipv6hdr));
+ skb_pull(skb, skb_transport_offset(skb));
goto looped_back;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 359/982] af_packet: Dont cast tpacket_hdr.tp_len to int in tpacket_parse_header().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (357 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 358/982] ipv6: sr: restore network header before routing and forwarding Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 360/982] staging: fbtft: make dirty_lock IRQ-safe Greg Kroah-Hartman
` (629 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+73df3f89e1e13089e466,
Kuniyuki Iwashima, Eric Dumazet, Willem de Bruijn, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 73e594c19b4f815d8343461cec7074c4713bbde7 ]
syzbot reported BUG() in sock_sendmsg_nosec(). [0]
The problem is that tpacket_parse_header() casts user-provided
tpacket_hdr.tp_len, which is u32, to int.
If the length is larger than INT_MAX, the following condition
in tpacket_parse_header() passes,
if (unlikely(tp_len > size_max))
and any negative value can be returned to the caller, up to
sock_sendmsg_nosec().
The repro set tpacket_hdr.tp_len to 0xfffffdef, which is cast
to -EIOCBQUEUED (-529), triggering BUG() in sock_sendmsg_nosec().
*(uint64_t*)0x200000000008 = 0xfffffdef;
...
syscall(__NR_write, /*fd=*/r[0], /*buf=*/0x200000000000ul, /*count=*/1ul);
Let's define the local tp_len as u32 in tpacket_parse_header().
[0]:
kernel BUG at net/socket.c:803!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 5628 Comm: syz-executor176 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:sock_sendmsg_nosec+0x145/0x180 net/socket.c:803
Code: 06 67 48 0f b9 3a eb 95 e8 e8 3a 22 f8 48 89 df 4c 89 f6 4c 89 e2 4d 89 fb 2e e8 32 a5 5c 16 e9 51 ff ff ff e8 cc 3a 22 f8 90 <0f> 0b e8 c4 3a 22 f8 48 83 c3 18 48 89 d8 48 c1 e8 03 42 80 3c 28
RSP: 0018:ffffc90003aefb48 EFLAGS: 00010293
RAX: ffffffff89a578d4 RBX: ffff8880764c67c0 RCX: ffff88807fb23e80
RDX: 0000000000000000 RSI: 00000000fffffdef RDI: 00000000fffffdef
RBP: 00000000fffffdef R08: ffffc90003aef747 R09: 1ffff9200075dee8
R10: dffffc0000000000 R11: fffff5200075dee9 R12: 0000000000000001
R13: dffffc0000000000 R14: ffffc90003aefbc0 R15: ffffffff8aac4310
FS: 000055559101b400(0000) GS:ffff888124ce0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000000210 CR3: 0000000073dca000 CR4: 00000000003526f0
Call Trace:
<TASK>
__sock_sendmsg net/socket.c:815 [inline]
sock_write_iter+0x2de/0x3e0 net/socket.c:1266
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f173130ecb9
Code: c0 79 93 eb d5 48 8d 7c 1d 00 eb 99 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 d8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd67e44248 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 0000200000000000 RCX: 00007f173130ecb9
RDX: 0000000000000001 RSI: 0000200000000000 RDI: 0000000000000003
RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffd67e44388
R13: 0000000000000002 R14: 00002000000000c0 R15: 0000000000000002
</TASK>
Fixes: 69e3c75f4d54 ("net: TX_RING and packet mmap")
Reported-by: syzbot+73df3f89e1e13089e466@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a946ffa.1d9ded08.62e62.0123.GAE@google.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260830180915.260225-1-kuniyu@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/packet/af_packet.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index 538fc4075292d..b0588d3e2e51c 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -2723,7 +2723,8 @@ static int tpacket_parse_header(struct packet_sock *po, void *frame,
int size_max, void **data)
{
union tpacket_uhdr ph;
- int tp_len, off;
+ u32 tp_len;
+ int off;
ph.raw = frame;
@@ -2743,7 +2744,7 @@ static int tpacket_parse_header(struct packet_sock *po, void *frame,
break;
}
if (unlikely(tp_len > size_max)) {
- pr_err("packet size is too long (%d > %d)\n", tp_len, size_max);
+ pr_err("packet size is too long (%u > %d)\n", tp_len, size_max);
return -EMSGSIZE;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 360/982] staging: fbtft: make dirty_lock IRQ-safe
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (358 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 359/982] af_packet: Dont cast tpacket_hdr.tp_len to int in tpacket_parse_header() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 361/982] ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits Greg Kroah-Hartman
` (628 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Su, Nam Cao, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Su <sh_def@163.com>
[ Upstream commit f576944a59f31bcffff121117ebf452c5dd162b7 ]
fbtft_mkdirty() can be reached from the fbcon rendering path while
processing printk() in hardirq context. Meanwhile, dirty_lock is also
taken by fbtft_deferred_io() in workqueue context with local interrupts
enabled.
Lockdep reports a possible IRQ lock inversion involving dirty_lock and
console_owner. A hardirq can interrupt a CPU holding dirty_lock and
enter the console rendering path, which can attempt to acquire
dirty_lock again.
The following lockdep report was observed on an RK3566 system with
CONFIG_PROVE_LOCKING enabled:
WARNING: possible irq lock inversion dependency detected
swapper/2/0 just changed the state of lock:
(console_owner){-...}-{0:0}
but this lock took another, HARDIRQ-unsafe lock in the past:
(&par->dirty_lock){+.+.}-{2:2}
CPU0 CPU1
---- ----
lock(&par->dirty_lock);
local_irq_disable();
lock(console_owner);
lock(&par->dirty_lock);
<Interrupt>
lock(console_owner);
*** DEADLOCK ***
Use spin_lock_irqsave() for fbtft_mkdirty() and spin_lock_irq() for
fbtft_deferred_io(). They only access the dirty line range, so the
IRQ-off regions remain short.
Fixes: c296d5f9957c ("staging: fbtft: core support")
Signed-off-by: Hui Su <sh_def@163.com>
Link: https://lore.kernel.org/lkml/20260804173712.176017-1-sh_def@163.com/
Reviewed-by: Nam Cao <namcao@linutronix.de>
Link: https://patch.msgid.link/20260807150953.2811933-3-sh_def@163.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/fbtft/fbtft-core.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/staging/fbtft/fbtft-core.c b/drivers/staging/fbtft/fbtft-core.c
index c20e1afc0ada2..6cf28daed0f37 100644
--- a/drivers/staging/fbtft/fbtft-core.c
+++ b/drivers/staging/fbtft/fbtft-core.c
@@ -302,6 +302,7 @@ static void fbtft_mkdirty(struct fb_info *info, int y, int height)
{
struct fbtft_par *par = info->par;
struct fb_deferred_io *fbdefio = info->fbdefio;
+ unsigned long flags;
/* special case, needed ? */
if (y == -1) {
@@ -310,12 +311,12 @@ static void fbtft_mkdirty(struct fb_info *info, int y, int height)
}
/* Mark display lines/area as dirty */
- spin_lock(&par->dirty_lock);
+ spin_lock_irqsave(&par->dirty_lock, flags);
if (y < par->dirty_lines_start)
par->dirty_lines_start = y;
if (y + height - 1 > par->dirty_lines_end)
par->dirty_lines_end = y + height - 1;
- spin_unlock(&par->dirty_lock);
+ spin_unlock_irqrestore(&par->dirty_lock, flags);
/* Schedule deferred_io to update display (no-op if already on queue)*/
schedule_delayed_work(&info->deferred_work, fbdefio->delay);
@@ -329,13 +330,13 @@ static void fbtft_deferred_io(struct fb_info *info, struct list_head *pagereflis
unsigned int y_low = 0, y_high = 0;
int count = 0;
- spin_lock(&par->dirty_lock);
+ spin_lock_irq(&par->dirty_lock);
dirty_lines_start = par->dirty_lines_start;
dirty_lines_end = par->dirty_lines_end;
/* set display line markers as clean */
par->dirty_lines_start = par->info->var.yres - 1;
par->dirty_lines_end = 0;
- spin_unlock(&par->dirty_lock);
+ spin_unlock_irq(&par->dirty_lock);
/* Mark display lines as dirty */
list_for_each_entry(pageref, pagereflist, list) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 361/982] ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (359 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 360/982] staging: fbtft: make dirty_lock IRQ-safe Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 362/982] ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() Greg Kroah-Hartman
` (627 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, wangdicheng, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: wangdicheng <wangdicheng@kylinos.cn>
[ Upstream commit 0c06c4ce0206290c9a934a1e7196aaa86adfe018 ]
disable_pdm_interrupts() uses |= ~PDM_DMA_INTR_MASK which sets all
bits except the PDM DMA interrupt bit instead of clearing only the
PDM DMA interrupt bit. Use &= ~PDM_DMA_INTR_MASK to clear only the
target bit.
Fixes: f621a3676d3f ("ASoC: amd: add ACP3x PDM platform driver")
Signed-off-by: wangdicheng <wangdicheng@kylinos.cn>
Link: https://patch.msgid.link/20260824063507.483784-1-wangdich9700@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/renoir/acp3x-pdm-dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/amd/renoir/acp3x-pdm-dma.c b/sound/soc/amd/renoir/acp3x-pdm-dma.c
index 643deed487ab4..617b1fe8b28b9 100644
--- a/sound/soc/amd/renoir/acp3x-pdm-dma.c
+++ b/sound/soc/amd/renoir/acp3x-pdm-dma.c
@@ -98,7 +98,7 @@ static void disable_pdm_interrupts(void __iomem *acp_base)
u32 ext_int_ctrl;
ext_int_ctrl = rn_readl(acp_base + ACP_EXTERNAL_INTR_CNTL);
- ext_int_ctrl |= ~PDM_DMA_INTR_MASK;
+ ext_int_ctrl &= ~PDM_DMA_INTR_MASK;
rn_writel(ext_int_ctrl, acp_base + ACP_EXTERNAL_INTR_CNTL);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 362/982] ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (360 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 361/982] ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 363/982] btrfs: detach failed sprout device from transaction update list Greg Kroah-Hartman
` (626 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, wangdicheng, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: wangdicheng <wangdicheng@kylinos.cn>
[ Upstream commit 1b67e0d3b9691d7b6b74e18960ddd2be24f9dc9d ]
acp6x_pdm_dma_close() does not free the runtime->private_data buffer
allocated in acp6x_pdm_dma_open(). Add the missing kfree.
Fixes: 7610174a5bfe ("ASoC: amd: add acp6x pdm platform driver")
Signed-off-by: wangdicheng <wangdicheng@kylinos.cn>
Link: https://patch.msgid.link/20260824063507.483784-2-wangdich9700@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/yc/acp6x-pdm-dma.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/soc/amd/yc/acp6x-pdm-dma.c b/sound/soc/amd/yc/acp6x-pdm-dma.c
index acecd6a4ec4b1..efdd5c088b883 100644
--- a/sound/soc/amd/yc/acp6x-pdm-dma.c
+++ b/sound/soc/amd/yc/acp6x-pdm-dma.c
@@ -269,9 +269,11 @@ static int acp6x_pdm_dma_close(struct snd_soc_component *component,
struct snd_pcm_substream *substream)
{
struct pdm_dev_data *adata = dev_get_drvdata(component->dev);
+ struct snd_pcm_runtime *runtime = substream->runtime;
acp6x_disable_pdm_interrupts(adata->acp6x_base);
adata->capture_stream = NULL;
+ kfree(runtime->private_data);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 363/982] btrfs: detach failed sprout device from transaction update list
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (361 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 362/982] ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 364/982] btrfs: restore active device pointers after failed sprout Greg Kroah-Hartman
` (625 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Guanghui Yang,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanghui Yang <3497809730@qq.com>
[ Upstream commit c93b3c43df561cd9f592cee20ae058b563f9e5b6 ]
When creating the first metadata chunk for a sprout filesystem,
create_chunk() adds the new device to the transaction dev_update_list
through device->post_commit_list.
If the subsequent system chunk creation fails, btrfs_init_new_device()
aborts the transaction and releases the device while post_commit_list is
still linked. This triggers a warning in btrfs_free_device() and leaves
the transaction list referencing freed memory.
Detach the device while holding chunk_mutex before releasing it.
Fixes: bbbf7243d62d ("btrfs: combine device update operations during transaction commit")
Assisted-by: Codex:gpt-5
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/volumes.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c
index e0a310bd0421f..cddc3d7908a4d 100644
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -2894,6 +2894,8 @@ int btrfs_init_new_device(struct btrfs_fs_info *fs_info, const char *device_path
btrfs_sysfs_remove_device(device);
mutex_lock(&fs_info->fs_devices->device_list_mutex);
mutex_lock(&fs_info->chunk_mutex);
+ if (!list_empty(&device->post_commit_list))
+ list_del_init(&device->post_commit_list);
list_del_rcu(&device->dev_list);
list_del(&device->dev_alloc_list);
fs_info->fs_devices->num_devices--;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 364/982] btrfs: restore active device pointers after failed sprout
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (362 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 363/982] btrfs: detach failed sprout device from transaction update list Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 365/982] bonding: alb: fix uninitialized transport header access in alb_determine_nd() Greg Kroah-Hartman
` (624 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Guanghui Yang,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanghui Yang <3497809730@qq.com>
[ Upstream commit e0b54613aabeb8e9da597f23b90c6a03d0981986 ]
btrfs_init_new_device() switches latest_dev and possibly s_bdev from the
seed device to the new sprout device before creating the first writable
chunks.
If chunk creation or the subsequent sprout setup fails, the error path
releases the new device without switching those pointers back.
btrfs_show_devname() can then dereference the freed latest_dev and crash.
Restore the active device pointers to the latest seed device before
removing and releasing the failed sprout device.
Fixes: b7cb29e666fe ("btrfs: update latest_dev when we create a sprout device")
Assisted-by: Codex:gpt-5
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/volumes.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c
index cddc3d7908a4d..f44a3fc149711 100644
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -2893,6 +2893,8 @@ int btrfs_init_new_device(struct btrfs_fs_info *fs_info, const char *device_path
error_sysfs:
btrfs_sysfs_remove_device(device);
mutex_lock(&fs_info->fs_devices->device_list_mutex);
+ if (seeding_dev)
+ btrfs_assign_next_active_device(device, seed_devices->latest_dev);
mutex_lock(&fs_info->chunk_mutex);
if (!list_empty(&device->post_commit_list))
list_del_init(&device->post_commit_list);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 365/982] bonding: alb: fix uninitialized transport header access in alb_determine_nd()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (363 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 364/982] btrfs: restore active device pointers after failed sprout Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 366/982] scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Greg Kroah-Hartman
` (623 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Joe Damato,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 70f3995830d3f1e79faa14eb0605914f778feca9 ]
alb_determine_nd() uses icmp6_hdr(skb) to inspect ICMPv6 headers.
However, in xmit paths (e.g. packets sent via AF_PACKET / raw sockets
or forwarded packets), skb->transport_header is not guaranteed to be
initialized. While pskb_network_may_pull() ensures the packet data is
linear starting from the network header, it does not set or adjust the
transport header offset.
Dereferencing icmp6_hdr(skb) can therefore access out-of-bounds memory.
Fetch the icmp6hdr directly after ipv6hdr following pskb_network_may_pull(),
and reload ipv6hdr in case pskb_may_pull() reallocated skb->head.
Also remove the unused bond argument from alb_determine_nd().
Fixes: 0da8aa00bfcf ("net: bonding: Add support for IPV6 ns/na to balance-alb/balance-tlb mode")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260831194626.119371-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/bonding/bond_alb.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/net/bonding/bond_alb.c b/drivers/net/bonding/bond_alb.c
index c44a9358f8b27..8930652efe321 100644
--- a/drivers/net/bonding/bond_alb.c
+++ b/drivers/net/bonding/bond_alb.c
@@ -1282,10 +1282,10 @@ static int alb_set_mac_address(struct bonding *bond, void *addr)
}
/* determine if the packet is NA or NS */
-static bool alb_determine_nd(struct sk_buff *skb, struct bonding *bond)
+static bool alb_determine_nd(struct sk_buff *skb)
{
- struct ipv6hdr *ip6hdr;
- struct icmp6hdr *hdr;
+ const struct ipv6hdr *ip6hdr;
+ const struct icmp6hdr *hdr;
if (!pskb_network_may_pull(skb, sizeof(*ip6hdr)))
return true;
@@ -1297,7 +1297,8 @@ static bool alb_determine_nd(struct sk_buff *skb, struct bonding *bond)
if (!pskb_network_may_pull(skb, sizeof(*ip6hdr) + sizeof(*hdr)))
return true;
- hdr = icmp6_hdr(skb);
+ ip6hdr = ipv6_hdr(skb);
+ hdr = (const struct icmp6hdr *)(ip6hdr + 1);
return hdr->icmp6_type == NDISC_NEIGHBOUR_ADVERTISEMENT ||
hdr->icmp6_type == NDISC_NEIGHBOUR_SOLICITATION;
}
@@ -1382,7 +1383,7 @@ struct slave *bond_xmit_tlb_slave_get(struct bonding *bond,
if (!is_multicast_ether_addr(eth_data->h_dest)) {
switch (skb->protocol) {
case htons(ETH_P_IPV6):
- if (alb_determine_nd(skb, bond))
+ if (alb_determine_nd(skb))
break;
fallthrough;
case htons(ETH_P_IP):
@@ -1468,7 +1469,7 @@ struct slave *bond_xmit_alb_slave_get(struct bonding *bond,
break;
}
- if (alb_determine_nd(skb, bond)) {
+ if (alb_determine_nd(skb)) {
do_tx_balance = false;
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 366/982] scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (364 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 365/982] bonding: alb: fix uninitialized transport header access in alb_determine_nd() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 367/982] perf/core: Skip empty AUX records with only format flags Greg Kroah-Hartman
` (622 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Thumshirn, Ivy Lopez,
John Garry, Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivy Lopez <skunkolee@gmail.com>
[ Upstream commit e0d26fe176a8db6ccad4ab38c5bab29391c1946b ]
dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
topology information for the PCI device, such as single-socket boards
that don't expose device-to-node affinity. Passing -1 directly into
cpumask_of_node() indexes node_to_cpumask_map[-1], an out-of-bounds
array read caught by UBSAN:
UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
index -1 is out of range for type 'cpumask *[1024]'
Fall back to cpu_online_mask when no NUMA node is available, rather than
assuming dev_to_node() always returns a valid node index.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
Suggested-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Fixes: 728bbc6cbff7 ("scsi: mpt3sas: Affinity high iops queues IRQs to local node")
Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260825190313.24013-1-skunkolee@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/mpt3sas/mpt3sas_base.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
index 479682770ee51..35d53c86e05e7 100644
--- a/drivers/scsi/mpt3sas/mpt3sas_base.c
+++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
@@ -3228,7 +3228,10 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
* corresponding to high iops queues.
*/
if (ioc->high_iops_queues) {
- mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
+ int node = dev_to_node(&ioc->pdev->dev);
+
+ mask = (node == NUMA_NO_NODE) ?
+ cpu_online_mask : cpumask_of_node(node);
for (index = 0; index < ioc->high_iops_queues;
index++) {
irq = pci_irq_vector(ioc->pdev, index);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 367/982] perf/core: Skip empty AUX records with only format flags
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (365 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 366/982] scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 368/982] locking/lockdep: Introduce lock_sync() Greg Kroah-Hartman
` (621 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tamas Petz, Leo Yan,
Peter Zijlstra (Intel), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Yan <leo.yan@arm.com>
[ Upstream commit 8a7f5b5e860b5c113ca99acd5b1e9074f5c5af3c ]
perf_aux_output_end() emits a PERF_RECORD_AUX when the recorded size is
nonzero or when any flag other than PERF_AUX_FLAG_OVERWRITE is set.
PMU format flags describe how an AUX payload is encoded. TRBE driver
sets PERF_AUX_FLAG_CORESIGHT_FORMAT_RAW for raw trace buffers, causing
an AUX record to be emitted even when no trace data.
This is noticeable when tracing a task with strace. Ptrace stops
repeatedly end empty AUX transactions, producing many zero-sized
PERF_RECORD_AUX records. For example:
perf record -e cs_etm//u -m,128M -- strace ls
perf script -D 2>&1 |
awk '/PERF_RECORD_AUX offset/ {
for (i = 1; i <= NF; i++)
if ($i == "size:" && $(i + 1) == "0")
count++
}
END { print count }'
165
This recording contains 165 zero-sized AUX records which provide no
useful information to userspace.
Ignore PERF_AUX_FLAG_PMU_FORMAT_TYPE_MASK, together with
PERF_AUX_FLAG_OVERWRITE, when deciding whether an empty AUX record is
useful. Zero-sized records carrying TRUNCATED, PARTIAL or COLLISION
are still emitted.
Fixes: 547b60988e63 ("perf: aux: Add flags for the buffer format")
Reported-by: Tamas Petz <tamas.petz@arm.com>
Signed-off-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260825-perf_core_fix_zero_aux_records-v1-1-23b95e8d5df3@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/events/ring_buffer.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/kernel/events/ring_buffer.c b/kernel/events/ring_buffer.c
index 4c4894de6e5d1..865fdc0ec0f65 100644
--- a/kernel/events/ring_buffer.c
+++ b/kernel/events/ring_buffer.c
@@ -502,7 +502,10 @@ void perf_aux_output_end(struct perf_output_handle *handle, unsigned long size)
/*
* Only send RECORD_AUX if we have something useful to communicate
*
- * Note: the OVERWRITE records by themselves are not considered
+ * PMU_FORMAT bits identify the PMU type rather than an AUX event
+ * has occurred, so ignore them for zero-sized records.
+ *
+ * The OVERWRITE records by themselves are not considered
* useful, as they don't communicate any *new* information,
* aside from the short-lived offset, that becomes history at
* the next event sched-in and therefore isn't useful.
@@ -511,7 +514,9 @@ void perf_aux_output_end(struct perf_output_handle *handle, unsigned long size)
* offset. So, from now on we don't output AUX records that
* have *only* OVERWRITE flag set.
*/
- if (size || (handle->aux_flags & ~(u64)PERF_AUX_FLAG_OVERWRITE))
+ if (size ||
+ (handle->aux_flags & ~(u64)(PERF_AUX_FLAG_PMU_FORMAT_TYPE_MASK |
+ PERF_AUX_FLAG_OVERWRITE)))
perf_event_aux_event(handle->event, aux_head, size,
handle->aux_flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 368/982] locking/lockdep: Introduce lock_sync()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (366 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 367/982] perf/core: Skip empty AUX records with only format flags Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 369/982] locking/lockdep: Improve the deadlock scenario print for sync and read lock Greg Kroah-Hartman
` (620 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Boqun Feng, Waiman Long,
Paul E. McKenney, Peter Zijlstra (Intel), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Boqun Feng <boqun.feng@gmail.com>
[ Upstream commit 2f1f043e7bea3fbf4c1869df2f7a0312bc8ca2bf ]
Currently, functions like synchronize_srcu() do not have lockdep
annotations resembling those of other write-side locking primitives.
Such annotations might look as follows:
lock_acquire();
lock_release();
Such annotations would tell lockdep that synchronize_srcu() acts like
an empty critical section that waits for other (read-side) critical
sections to finish. This would definitely catch some deadlock, but
as pointed out by Paul Mckenney [1], this could also introduce false
positives because of irq-safe/unsafe detection. Of course, there are
tricks could help with this:
might_sleep(); // Existing statement in __synchronize_srcu().
if (IS_ENABLED(CONFIG_PROVE_LOCKING)) {
local_irq_disable();
lock_acquire();
lock_release();
local_irq_enable();
}
But it would be better for lockdep to provide a separate annonation for
functions like synchronize_srcu(), so that people won't need to repeat
the ugly tricks above.
Therefore introduce lock_sync(), which is simply an lock+unlock
pair with no irq safe/unsafe deadlock check. This works because the
to-be-annontated functions do not create real critical sections, and
there is therefore no way that irq can create extra dependencies.
[1]: https://lore.kernel.org/lkml/20180412021233.ewncg5jjuzjw3x62@tardis/
Signed-off-by: Boqun Feng <boqun.feng@gmail.com>
Acked-by: Waiman Long <longman@redhat.com>
Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
[ boqun: Fix typos reported by Davidlohr Bueso and Paul E. Mckenney ]
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Boqun Feng <boqun.feng@gmail.com>
Stable-dep-of: 02c6be7d675b ("locking/lockdep: Invalidate stale class_cache entries for zapped classes")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/lockdep.h | 5 +++++
kernel/locking/lockdep.c | 34 ++++++++++++++++++++++++++++++++++
2 files changed, 39 insertions(+)
diff --git a/include/linux/lockdep.h b/include/linux/lockdep.h
index 90aa802a30669..9d8639c6ff21f 100644
--- a/include/linux/lockdep.h
+++ b/include/linux/lockdep.h
@@ -268,6 +268,10 @@ extern void lock_acquire(struct lockdep_map *lock, unsigned int subclass,
extern void lock_release(struct lockdep_map *lock, unsigned long ip);
+extern void lock_sync(struct lockdep_map *lock, unsigned int subclass,
+ int read, int check, struct lockdep_map *nest_lock,
+ unsigned long ip);
+
/* lock_is_held_type() returns */
#define LOCK_STATE_UNKNOWN -1
#define LOCK_STATE_NOT_HELD 0
@@ -569,6 +573,7 @@ do { \
#define lock_map_acquire_read(l) lock_acquire_shared_recursive(l, 0, 0, NULL, _THIS_IP_)
#define lock_map_acquire_tryread(l) lock_acquire_shared_recursive(l, 0, 1, NULL, _THIS_IP_)
#define lock_map_release(l) lock_release(l, _THIS_IP_)
+#define lock_map_sync(l) lock_sync(l, 0, 0, 1, NULL, _THIS_IP_)
#ifdef CONFIG_PROVE_LOCKING
# define might_lock(lock) \
diff --git a/kernel/locking/lockdep.c b/kernel/locking/lockdep.c
index a807773c84c3e..b50dc0b833872 100644
--- a/kernel/locking/lockdep.c
+++ b/kernel/locking/lockdep.c
@@ -5702,6 +5702,40 @@ void lock_release(struct lockdep_map *lock, unsigned long ip)
}
EXPORT_SYMBOL_GPL(lock_release);
+/*
+ * lock_sync() - A special annotation for synchronize_{s,}rcu()-like API.
+ *
+ * No actual critical section is created by the APIs annotated with this: these
+ * APIs are used to wait for one or multiple critical sections (on other CPUs
+ * or threads), and it means that calling these APIs inside these critical
+ * sections is potential deadlock.
+ *
+ * This annotation acts as an acquire+release annotation pair with hardirqoff
+ * being 1. Since there's no critical section, no interrupt can create extra
+ * dependencies "inside" the annotation, hardirqoff == 1 allows us to avoid
+ * false positives.
+ */
+void lock_sync(struct lockdep_map *lock, unsigned subclass, int read,
+ int check, struct lockdep_map *nest_lock, unsigned long ip)
+{
+ unsigned long flags;
+
+ if (unlikely(!lockdep_enabled()))
+ return;
+
+ raw_local_irq_save(flags);
+ check_flags(flags);
+
+ lockdep_recursion_inc();
+ __lock_acquire(lock, subclass, 0, read, check, 1, nest_lock, ip, 0, 0);
+
+ if (__lock_release(lock, ip))
+ check_chain_key(current);
+ lockdep_recursion_finish();
+ raw_local_irq_restore(flags);
+}
+EXPORT_SYMBOL_GPL(lock_sync);
+
noinstr int lock_is_held_type(const struct lockdep_map *lock, int read)
{
unsigned long flags;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 369/982] locking/lockdep: Improve the deadlock scenario print for sync and read lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (367 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 368/982] locking/lockdep: Introduce lock_sync() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 370/982] lockdep: Add lock_set_cmp_fn() annotation Greg Kroah-Hartman
` (619 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Boqun Feng, Paul E. McKenney,
Peter Zijlstra (Intel), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Boqun Feng <boqun.feng@gmail.com>
[ Upstream commit 0471db447cb7de56bbe2fedd9256b4d2b8ef642a ]
Lock scenario print is always a weak spot of lockdep splats. Improvement
can be made if we rework the dependency search and the error printing.
However without touching the graph search, we can improve a little for
the circular deadlock case, since we have the to-be-added lock
dependency, and know whether these two locks are read/write/sync.
In order to know whether a held_lock is sync or not, a bit was
"stolen" from ->references, which reduce our limit for the same lock
class nesting from 2^12 to 2^11, and it should still be good enough.
Besides, since we now have bit in held_lock for sync, we don't need the
"hardirqoffs being 1" trick, and also we can avoid the __lock_release()
if we jump out of __lock_acquire() before the held_lock stored.
With these changes, a deadlock case evolved with read lock and sync gets
a better print-out from:
[...] Possible unsafe locking scenario:
[...]
[...] CPU0 CPU1
[...] ---- ----
[...] lock(srcuA);
[...] lock(srcuB);
[...] lock(srcuA);
[...] lock(srcuB);
to
[...] Possible unsafe locking scenario:
[...]
[...] CPU0 CPU1
[...] ---- ----
[...] rlock(srcuA);
[...] lock(srcuB);
[...] lock(srcuA);
[...] sync(srcuB);
Signed-off-by: Boqun Feng <boqun.feng@gmail.com>
Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Boqun Feng <boqun.feng@gmail.com>
Stable-dep-of: 02c6be7d675b ("locking/lockdep: Invalidate stale class_cache entries for zapped classes")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/lockdep.h | 3 ++-
kernel/locking/lockdep.c | 48 ++++++++++++++++++++++++++--------------
2 files changed, 34 insertions(+), 17 deletions(-)
diff --git a/include/linux/lockdep.h b/include/linux/lockdep.h
index 9d8639c6ff21f..c077aa9b16503 100644
--- a/include/linux/lockdep.h
+++ b/include/linux/lockdep.h
@@ -134,7 +134,8 @@ struct held_lock {
unsigned int read:2; /* see lock_acquire() comment */
unsigned int check:1; /* see lock_acquire() comment */
unsigned int hardirqs_off:1;
- unsigned int references:12; /* 32 bits */
+ unsigned int sync:1;
+ unsigned int references:11; /* 32 bits */
unsigned int pin_count;
};
diff --git a/kernel/locking/lockdep.c b/kernel/locking/lockdep.c
index b50dc0b833872..2a5b17f855c8a 100644
--- a/kernel/locking/lockdep.c
+++ b/kernel/locking/lockdep.c
@@ -1873,6 +1873,8 @@ print_circular_lock_scenario(struct held_lock *src,
struct lock_class *source = hlock_class(src);
struct lock_class *target = hlock_class(tgt);
struct lock_class *parent = prt->class;
+ int src_read = src->read;
+ int tgt_read = tgt->read;
/*
* A direct locking problem where unsafe_class lock is taken
@@ -1900,7 +1902,10 @@ print_circular_lock_scenario(struct held_lock *src,
printk(" Possible unsafe locking scenario:\n\n");
printk(" CPU0 CPU1\n");
printk(" ---- ----\n");
- printk(" lock(");
+ if (tgt_read != 0)
+ printk(" rlock(");
+ else
+ printk(" lock(");
__print_lock_name(target);
printk(KERN_CONT ");\n");
printk(" lock(");
@@ -1909,7 +1914,12 @@ print_circular_lock_scenario(struct held_lock *src,
printk(" lock(");
__print_lock_name(target);
printk(KERN_CONT ");\n");
- printk(" lock(");
+ if (src_read != 0)
+ printk(" rlock(");
+ else if (src->sync)
+ printk(" sync(");
+ else
+ printk(" lock(");
__print_lock_name(source);
printk(KERN_CONT ");\n");
printk("\n *** DEADLOCK ***\n\n");
@@ -4529,7 +4539,13 @@ mark_usage(struct task_struct *curr, struct held_lock *hlock, int check)
return 0;
}
}
- if (!hlock->hardirqs_off) {
+
+ /*
+ * For lock_sync(), don't mark the ENABLED usage, since lock_sync()
+ * creates no critical section and no extra dependency can be introduced
+ * by interrupts
+ */
+ if (!hlock->hardirqs_off && !hlock->sync) {
if (hlock->read) {
if (!mark_lock(curr, hlock,
LOCK_ENABLED_HARDIRQ_READ))
@@ -4917,7 +4933,7 @@ static int __lock_is_held(const struct lockdep_map *lock, int read);
static int __lock_acquire(struct lockdep_map *lock, unsigned int subclass,
int trylock, int read, int check, int hardirqs_off,
struct lockdep_map *nest_lock, unsigned long ip,
- int references, int pin_count)
+ int references, int pin_count, int sync)
{
struct task_struct *curr = current;
struct lock_class *class = NULL;
@@ -4968,7 +4984,8 @@ static int __lock_acquire(struct lockdep_map *lock, unsigned int subclass,
class_idx = class - lock_classes;
- if (depth) { /* we're holding locks */
+ if (depth && !sync) {
+ /* we're holding locks and the new held lock is not a sync */
hlock = curr->held_locks + depth - 1;
if (hlock->class_idx == class_idx && nest_lock) {
if (!references)
@@ -5002,6 +5019,7 @@ static int __lock_acquire(struct lockdep_map *lock, unsigned int subclass,
hlock->trylock = trylock;
hlock->read = read;
hlock->check = check;
+ hlock->sync = !!sync;
hlock->hardirqs_off = !!hardirqs_off;
hlock->references = references;
#ifdef CONFIG_LOCK_STAT
@@ -5063,6 +5081,10 @@ static int __lock_acquire(struct lockdep_map *lock, unsigned int subclass,
if (!validate_chain(curr, hlock, chain_head, chain_key))
return 0;
+ /* For lock_sync(), we are done here since no actual critical section */
+ if (hlock->sync)
+ return 1;
+
curr->curr_chain_key = chain_key;
curr->lockdep_depth++;
check_chain_key(curr);
@@ -5204,7 +5226,7 @@ static int reacquire_held_locks(struct task_struct *curr, unsigned int depth,
hlock->read, hlock->check,
hlock->hardirqs_off,
hlock->nest_lock, hlock->acquire_ip,
- hlock->references, hlock->pin_count)) {
+ hlock->references, hlock->pin_count, 0)) {
case 0:
return 1;
case 1:
@@ -5676,7 +5698,7 @@ void lock_acquire(struct lockdep_map *lock, unsigned int subclass,
lockdep_recursion_inc();
__lock_acquire(lock, subclass, trylock, read, check,
- irqs_disabled_flags(flags), nest_lock, ip, 0, 0);
+ irqs_disabled_flags(flags), nest_lock, ip, 0, 0, 0);
lockdep_recursion_finish();
raw_local_irq_restore(flags);
}
@@ -5709,11 +5731,6 @@ EXPORT_SYMBOL_GPL(lock_release);
* APIs are used to wait for one or multiple critical sections (on other CPUs
* or threads), and it means that calling these APIs inside these critical
* sections is potential deadlock.
- *
- * This annotation acts as an acquire+release annotation pair with hardirqoff
- * being 1. Since there's no critical section, no interrupt can create extra
- * dependencies "inside" the annotation, hardirqoff == 1 allows us to avoid
- * false positives.
*/
void lock_sync(struct lockdep_map *lock, unsigned subclass, int read,
int check, struct lockdep_map *nest_lock, unsigned long ip)
@@ -5727,10 +5744,9 @@ void lock_sync(struct lockdep_map *lock, unsigned subclass, int read,
check_flags(flags);
lockdep_recursion_inc();
- __lock_acquire(lock, subclass, 0, read, check, 1, nest_lock, ip, 0, 0);
-
- if (__lock_release(lock, ip))
- check_chain_key(current);
+ __lock_acquire(lock, subclass, 0, read, check,
+ irqs_disabled_flags(flags), nest_lock, ip, 0, 0, 1);
+ check_chain_key(current);
lockdep_recursion_finish();
raw_local_irq_restore(flags);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 370/982] lockdep: Add lock_set_cmp_fn() annotation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (368 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 369/982] locking/lockdep: Improve the deadlock scenario print for sync and read lock Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 371/982] locking/lockdep: Invalidate stale class_cache entries for zapped classes Greg Kroah-Hartman
` (618 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kent Overstreet,
Peter Zijlstra (Intel), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kent Overstreet <kent.overstreet@linux.dev>
[ Upstream commit eb1cfd09f788e39948a82be8063e54e40dd018d9 ]
This implements a new interface to lockdep, lock_set_cmp_fn(), for
defining a custom ordering when taking multiple locks of the same
class.
This is an alternative to subclasses, but can not fully replace them
since subclasses allow lock hierarchies with other clasees
inter-twined, while this relies on pure class nesting.
Specifically, if A is our nesting class then:
A/0 <- B <- A/1
Would be a valid lock order with subclasses (each subclass really is a
full class from the validation PoV) but not with this annotation,
which requires all nesting to be consecutive.
Example output:
| ============================================
| WARNING: possible recursive locking detected
| 6.2.0-rc8-00003-g7d81e591ca6a-dirty #15 Not tainted
| --------------------------------------------
| kworker/14:3/938 is trying to acquire lock:
| ffff8880143218c8 (&b->lock l=0 0:2803368){++++}-{3:3}, at: bch_btree_node_get.part.0+0x81/0x2b0
|
| but task is already holding lock:
| ffff8880143de8c8 (&b->lock l=1 1048575:9223372036854775807){++++}-{3:3}, at: __bch_btree_map_nodes+0xea/0x1e0
| and the lock comparison function returns 1:
|
| other info that might help us debug this:
| Possible unsafe locking scenario:
|
| CPU0
| ----
| lock(&b->lock l=1 1048575:9223372036854775807);
| lock(&b->lock l=0 0:2803368);
|
| *** DEADLOCK ***
|
| May be due to missing lock nesting notation
|
| 3 locks held by kworker/14:3/938:
| #0: ffff888005ea9d38 ((wq_completion)bcache){+.+.}-{0:0}, at: process_one_work+0x1ec/0x530
| #1: ffff8880098c3e70 ((work_completion)(&cl->work)#3){+.+.}-{0:0}, at: process_one_work+0x1ec/0x530
| #2: ffff8880143de8c8 (&b->lock l=1 1048575:9223372036854775807){++++}-{3:3}, at: __bch_btree_map_nodes+0xea/0x1e0
[peterz: extended changelog]
Signed-off-by: Kent Overstreet <kent.overstreet@linux.dev>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lkml.kernel.org/r/20230509195847.1745548-1-kent.overstreet@linux.dev
Stable-dep-of: 02c6be7d675b ("locking/lockdep: Invalidate stale class_cache entries for zapped classes")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/lockdep.h | 8 +++
include/linux/lockdep_types.h | 8 +++
kernel/locking/lockdep.c | 118 +++++++++++++++++++++++++---------
3 files changed, 103 insertions(+), 31 deletions(-)
diff --git a/include/linux/lockdep.h b/include/linux/lockdep.h
index c077aa9b16503..7eee13aef36ec 100644
--- a/include/linux/lockdep.h
+++ b/include/linux/lockdep.h
@@ -447,6 +447,14 @@ extern int lockdep_is_held(const void *);
#endif /* !LOCKDEP */
+#ifdef CONFIG_PROVE_LOCKING
+void lockdep_set_lock_cmp_fn(struct lockdep_map *, lock_cmp_fn, lock_print_fn);
+
+#define lock_set_cmp_fn(lock, ...) lockdep_set_lock_cmp_fn(&(lock)->dep_map, __VA_ARGS__)
+#else
+#define lock_set_cmp_fn(lock, ...) do { } while (0)
+#endif
+
enum xhlock_context_t {
XHLOCK_HARD,
XHLOCK_SOFT,
diff --git a/include/linux/lockdep_types.h b/include/linux/lockdep_types.h
index 59f4fb1626ea6..2ebc323d345ae 100644
--- a/include/linux/lockdep_types.h
+++ b/include/linux/lockdep_types.h
@@ -85,6 +85,11 @@ struct lock_trace;
#define LOCKSTAT_POINTS 4
+struct lockdep_map;
+typedef int (*lock_cmp_fn)(const struct lockdep_map *a,
+ const struct lockdep_map *b);
+typedef void (*lock_print_fn)(const struct lockdep_map *map);
+
/*
* The lock-class itself. The order of the structure members matters.
* reinit_class() zeroes the key member and all subsequent members.
@@ -110,6 +115,9 @@ struct lock_class {
struct list_head locks_after, locks_before;
const struct lockdep_subclass_key *key;
+ lock_cmp_fn cmp_fn;
+ lock_print_fn print_fn;
+
unsigned int subclass;
unsigned int dep_gen_id;
diff --git a/kernel/locking/lockdep.c b/kernel/locking/lockdep.c
index 2a5b17f855c8a..b16e699cee9fe 100644
--- a/kernel/locking/lockdep.c
+++ b/kernel/locking/lockdep.c
@@ -709,7 +709,7 @@ void get_usage_chars(struct lock_class *class, char usage[LOCK_USAGE_CHARS])
usage[i] = '\0';
}
-static void __print_lock_name(struct lock_class *class)
+static void __print_lock_name(struct held_lock *hlock, struct lock_class *class)
{
char str[KSYM_NAME_LEN];
const char *name;
@@ -724,17 +724,19 @@ static void __print_lock_name(struct lock_class *class)
printk(KERN_CONT "#%d", class->name_version);
if (class->subclass)
printk(KERN_CONT "/%d", class->subclass);
+ if (hlock && class->print_fn)
+ class->print_fn(hlock->instance);
}
}
-static void print_lock_name(struct lock_class *class)
+static void print_lock_name(struct held_lock *hlock, struct lock_class *class)
{
char usage[LOCK_USAGE_CHARS];
get_usage_chars(class, usage);
printk(KERN_CONT " (");
- __print_lock_name(class);
+ __print_lock_name(hlock, class);
printk(KERN_CONT "){%s}-{%d:%d}", usage,
class->wait_type_outer ?: class->wait_type_inner,
class->wait_type_inner);
@@ -772,7 +774,7 @@ static void print_lock(struct held_lock *hlock)
}
printk(KERN_CONT "%px", hlock->instance);
- print_lock_name(lock);
+ print_lock_name(hlock, lock);
printk(KERN_CONT ", at: %pS\n", (void *)hlock->acquire_ip);
}
@@ -1860,7 +1862,7 @@ print_circular_bug_entry(struct lock_list *target, int depth)
if (debug_locks_silent)
return;
printk("\n-> #%u", depth);
- print_lock_name(target->class);
+ print_lock_name(NULL, target->class);
printk(KERN_CONT ":\n");
print_lock_trace(target->trace, 6);
}
@@ -1891,11 +1893,11 @@ print_circular_lock_scenario(struct held_lock *src,
*/
if (parent != source) {
printk("Chain exists of:\n ");
- __print_lock_name(source);
+ __print_lock_name(src, source);
printk(KERN_CONT " --> ");
- __print_lock_name(parent);
+ __print_lock_name(NULL, parent);
printk(KERN_CONT " --> ");
- __print_lock_name(target);
+ __print_lock_name(tgt, target);
printk(KERN_CONT "\n\n");
}
@@ -1906,13 +1908,13 @@ print_circular_lock_scenario(struct held_lock *src,
printk(" rlock(");
else
printk(" lock(");
- __print_lock_name(target);
+ __print_lock_name(tgt, target);
printk(KERN_CONT ");\n");
printk(" lock(");
- __print_lock_name(parent);
+ __print_lock_name(NULL, parent);
printk(KERN_CONT ");\n");
printk(" lock(");
- __print_lock_name(target);
+ __print_lock_name(tgt, target);
printk(KERN_CONT ");\n");
if (src_read != 0)
printk(" rlock(");
@@ -1920,7 +1922,7 @@ print_circular_lock_scenario(struct held_lock *src,
printk(" sync(");
else
printk(" lock(");
- __print_lock_name(source);
+ __print_lock_name(src, source);
printk(KERN_CONT ");\n");
printk("\n *** DEADLOCK ***\n\n");
}
@@ -2146,6 +2148,8 @@ check_path(struct held_lock *target, struct lock_list *src_entry,
return ret;
}
+static void print_deadlock_bug(struct task_struct *, struct held_lock *, struct held_lock *);
+
/*
* Prove that the dependency graph starting at <src> can not
* lead to <target>. If it can, there is a circle when adding
@@ -2177,7 +2181,10 @@ check_noncircular(struct held_lock *src, struct held_lock *target,
*trace = save_trace();
}
- print_circular_bug(&src_entry, target_entry, src, target);
+ if (src->class_idx == target->class_idx)
+ print_deadlock_bug(current, src, target);
+ else
+ print_circular_bug(&src_entry, target_entry, src, target);
}
return ret;
@@ -2338,7 +2345,7 @@ static void print_lock_class_header(struct lock_class *class, int depth)
int bit;
printk("%*s->", depth, "");
- print_lock_name(class);
+ print_lock_name(NULL, class);
#ifdef CONFIG_DEBUG_LOCKDEP
printk(KERN_CONT " ops: %lu", debug_class_ops_read(class));
#endif
@@ -2520,11 +2527,11 @@ print_irq_lock_scenario(struct lock_list *safe_entry,
*/
if (middle_class != unsafe_class) {
printk("Chain exists of:\n ");
- __print_lock_name(safe_class);
+ __print_lock_name(NULL, safe_class);
printk(KERN_CONT " --> ");
- __print_lock_name(middle_class);
+ __print_lock_name(NULL, middle_class);
printk(KERN_CONT " --> ");
- __print_lock_name(unsafe_class);
+ __print_lock_name(NULL, unsafe_class);
printk(KERN_CONT "\n\n");
}
@@ -2532,18 +2539,18 @@ print_irq_lock_scenario(struct lock_list *safe_entry,
printk(" CPU0 CPU1\n");
printk(" ---- ----\n");
printk(" lock(");
- __print_lock_name(unsafe_class);
+ __print_lock_name(NULL, unsafe_class);
printk(KERN_CONT ");\n");
printk(" local_irq_disable();\n");
printk(" lock(");
- __print_lock_name(safe_class);
+ __print_lock_name(NULL, safe_class);
printk(KERN_CONT ");\n");
printk(" lock(");
- __print_lock_name(middle_class);
+ __print_lock_name(NULL, middle_class);
printk(KERN_CONT ");\n");
printk(" <Interrupt>\n");
printk(" lock(");
- __print_lock_name(safe_class);
+ __print_lock_name(NULL, safe_class);
printk(KERN_CONT ");\n");
printk("\n *** DEADLOCK ***\n\n");
}
@@ -2580,20 +2587,20 @@ print_bad_irq_dependency(struct task_struct *curr,
pr_warn("\nand this task is already holding:\n");
print_lock(prev);
pr_warn("which would create a new lock dependency:\n");
- print_lock_name(hlock_class(prev));
+ print_lock_name(prev, hlock_class(prev));
pr_cont(" ->");
- print_lock_name(hlock_class(next));
+ print_lock_name(next, hlock_class(next));
pr_cont("\n");
pr_warn("\nbut this new dependency connects a %s-irq-safe lock:\n",
irqclass);
- print_lock_name(backwards_entry->class);
+ print_lock_name(NULL, backwards_entry->class);
pr_warn("\n... which became %s-irq-safe at:\n", irqclass);
print_lock_trace(backwards_entry->class->usage_traces[bit1], 1);
pr_warn("\nto a %s-irq-unsafe lock:\n", irqclass);
- print_lock_name(forwards_entry->class);
+ print_lock_name(NULL, forwards_entry->class);
pr_warn("\n... which became %s-irq-unsafe at:\n", irqclass);
pr_warn("...");
@@ -2963,10 +2970,10 @@ print_deadlock_scenario(struct held_lock *nxt, struct held_lock *prv)
printk(" CPU0\n");
printk(" ----\n");
printk(" lock(");
- __print_lock_name(prev);
+ __print_lock_name(prv, prev);
printk(KERN_CONT ");\n");
printk(" lock(");
- __print_lock_name(next);
+ __print_lock_name(nxt, next);
printk(KERN_CONT ");\n");
printk("\n *** DEADLOCK ***\n\n");
printk(" May be due to missing lock nesting notation\n\n");
@@ -2976,6 +2983,8 @@ static void
print_deadlock_bug(struct task_struct *curr, struct held_lock *prev,
struct held_lock *next)
{
+ struct lock_class *class = hlock_class(prev);
+
if (!debug_locks_off_graph_unlock() || debug_locks_silent)
return;
@@ -2990,6 +2999,11 @@ print_deadlock_bug(struct task_struct *curr, struct held_lock *prev,
pr_warn("\nbut task is already holding lock:\n");
print_lock(prev);
+ if (class->cmp_fn) {
+ pr_warn("and the lock comparison function returns %i:\n",
+ class->cmp_fn(prev->instance, next->instance));
+ }
+
pr_warn("\nother info that might help us debug this:\n");
print_deadlock_scenario(next, prev);
lockdep_print_held_locks(curr);
@@ -3011,6 +3025,7 @@ print_deadlock_bug(struct task_struct *curr, struct held_lock *prev,
static int
check_deadlock(struct task_struct *curr, struct held_lock *next)
{
+ struct lock_class *class;
struct held_lock *prev;
struct held_lock *nest = NULL;
int i;
@@ -3031,6 +3046,12 @@ check_deadlock(struct task_struct *curr, struct held_lock *next)
if ((next->read == 2) && prev->read)
continue;
+ class = hlock_class(prev);
+
+ if (class->cmp_fn &&
+ class->cmp_fn(prev->instance, next->instance) < 0)
+ continue;
+
/*
* We're holding the nest_lock, which serializes this lock's
* nesting behaviour.
@@ -3092,6 +3113,14 @@ check_prev_add(struct task_struct *curr, struct held_lock *prev,
return 2;
}
+ if (prev->class_idx == next->class_idx) {
+ struct lock_class *class = hlock_class(prev);
+
+ if (class->cmp_fn &&
+ class->cmp_fn(prev->instance, next->instance) < 0)
+ return 2;
+ }
+
/*
* Prove that the new <prev> -> <next> dependency would not
* create a circular dependency in the graph. (We do this by
@@ -3569,7 +3598,7 @@ static void print_chain_keys_chain(struct lock_chain *chain)
hlock_id = chain_hlocks[chain->base + i];
chain_key = print_chain_key_iteration(hlock_id, chain_key);
- print_lock_name(lock_classes + chain_hlock_class_idx(hlock_id));
+ print_lock_name(NULL, lock_classes + chain_hlock_class_idx(hlock_id));
printk("\n");
}
}
@@ -3926,11 +3955,11 @@ static void print_usage_bug_scenario(struct held_lock *lock)
printk(" CPU0\n");
printk(" ----\n");
printk(" lock(");
- __print_lock_name(class);
+ __print_lock_name(lock, class);
printk(KERN_CONT ");\n");
printk(" <Interrupt>\n");
printk(" lock(");
- __print_lock_name(class);
+ __print_lock_name(lock, class);
printk(KERN_CONT ");\n");
printk("\n *** DEADLOCK ***\n\n");
}
@@ -4016,7 +4045,7 @@ print_irq_inversion_bug(struct task_struct *curr,
pr_warn("but this lock took another, %s-unsafe lock in the past:\n", irqclass);
else
pr_warn("but this lock was taken by another, %s-safe lock in the past:\n", irqclass);
- print_lock_name(other->class);
+ print_lock_name(NULL, other->class);
pr_warn("\n\nand interrupts could create inverse lock ordering between them.\n\n");
pr_warn("\nother info that might help us debug this:\n");
@@ -4889,6 +4918,33 @@ EXPORT_SYMBOL_GPL(lockdep_init_map_type);
struct lock_class_key __lockdep_no_validate__;
EXPORT_SYMBOL_GPL(__lockdep_no_validate__);
+#ifdef CONFIG_PROVE_LOCKING
+void lockdep_set_lock_cmp_fn(struct lockdep_map *lock, lock_cmp_fn cmp_fn,
+ lock_print_fn print_fn)
+{
+ struct lock_class *class = lock->class_cache[0];
+ unsigned long flags;
+
+ raw_local_irq_save(flags);
+ lockdep_recursion_inc();
+
+ if (!class)
+ class = register_lock_class(lock, 0, 0);
+
+ if (class) {
+ WARN_ON(class->cmp_fn && class->cmp_fn != cmp_fn);
+ WARN_ON(class->print_fn && class->print_fn != print_fn);
+
+ class->cmp_fn = cmp_fn;
+ class->print_fn = print_fn;
+ }
+
+ lockdep_recursion_finish();
+ raw_local_irq_restore(flags);
+}
+EXPORT_SYMBOL_GPL(lockdep_set_lock_cmp_fn);
+#endif
+
static void
print_lock_nested_lock_not_held(struct task_struct *curr,
struct held_lock *hlock)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 371/982] locking/lockdep: Invalidate stale class_cache entries for zapped classes
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (369 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 370/982] lockdep: Add lock_set_cmp_fn() annotation Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 372/982] ASoC: ux500: Fix MSP stream lifecycle handling Greg Kroah-Hartman
` (617 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+2d770620059281e225a4,
Eric Dumazet, Peter Zijlstra (Intel), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 02c6be7d675b21d81f0ba3a524346850a8c0e3bf ]
syzbot reported a lockdep splat hitting DEBUG_LOCKS_WARN_ON(1) in
hlock_class() due to an invalid class_idx:
WARNING: kernel/locking/lockdep.c:238 at __lock_acquire+0x382/0x2cf0 kernel/locking/lockdep.c:5203
Workqueue: wg-crypt-wg0 wg_packet_tx_worker
RIP: 0010:hlock_class kernel/locking/lockdep.c:238 [inline]
RIP: 0010:check_wait_context kernel/locking/lockdep.c:4870 [inline]
RIP: 0010:__lock_acquire+0x389/0x2cf0 kernel/locking/lockdep.c:5203
Call Trace:
<IRQ>
lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5886
_raw_spin_lock+0x2e/0x40 kernel/locking/spinlock.c:173
tcp_tsq_handler+0x29/0x200 net/ipv4/tcp_output.c:1291
tcp_tsq_workfn+0x384/0x410 net/ipv4/tcp_output.c:1325
...
When a lock class is zapped (e.g. during module unload or key
unregistration), zap_class() clears the class's bit in
lock_classes_in_use and removes it from the class hash table.
However, existing lockdep_map instances embedded in data structures
may still retain a pointer to the zapped class in their class_cache[]
array.
When __lock_acquire() subsequently runs on such a lock, it finds
lock->class_cache[subclass] != NULL, skipping register_lock_class()
and assigning hlock->class_idx to the index of the zapped class. When
check_wait_context() or hlock_class() inspects the held_lock, it finds
!test_bit(class_idx, lock_classes_in_use) and warns. Furthermore, if
the zapped slot is subsequently re-allocated to an unrelated lock key,
the stale class_cache entry would erroneously match the unrelated
class (ABA issue).
Add lock_class_cache_is_valid() to validate that the cached class is
within lock_classes bounds, still allocated in lock_classes_in_use
(using uninstrumented arch_test_bit() in __always_inline context so it
is safe in noinstr contexts like match_held_lock()), and that
class->key matches the expected subkey (taking lockdep_set_subclass()
overrides into account). Also use READ_ONCE()/WRITE_ONCE() when
accessing class_cache[]. If the entry is invalid or stale, fall back
to register_lock_class() / look_up_lock_class().
Fixes: a0b0fd53e1e6 ("locking/lockdep: Free lock classes that are no longer in use")
Closes: https://lore.kernel.org/netdev/6a8c66dc.4d75e56a.c9a88.0050.GAE@google.com/T/#u
Reported-by: syzbot+2d770620059281e225a4@syzkaller.appspotmail.com
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260824155129.676096-1-edumazet@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/locking/lockdep.c | 50 +++++++++++++++++++++++++++++++++-------
1 file changed, 42 insertions(+), 8 deletions(-)
diff --git a/kernel/locking/lockdep.c b/kernel/locking/lockdep.c
index b16e699cee9fe..dcc768d47649a 100644
--- a/kernel/locking/lockdep.c
+++ b/kernel/locking/lockdep.c
@@ -940,6 +940,34 @@ look_up_lock_class(const struct lockdep_map *lock, unsigned int subclass)
return NULL;
}
+static __always_inline bool lock_class_cache_is_valid(const struct lockdep_map *lock,
+ const struct lock_class *class,
+ unsigned int subclass)
+{
+ unsigned int class_subclass;
+
+ if (!class)
+ return false;
+
+ if (unlikely(class < lock_classes || class >= lock_classes + MAX_LOCKDEP_KEYS))
+ return false;
+
+ if (unlikely(!arch_test_bit(class - lock_classes, lock_classes_in_use)))
+ return false;
+
+ if (unlikely(!lock->key))
+ return false;
+
+ class_subclass = subclass ? subclass : class->subclass;
+ if (unlikely(class_subclass >= MAX_LOCKDEP_SUBCLASSES))
+ return false;
+
+ if (unlikely(READ_ONCE(class->key) != lock->key->subkeys + class_subclass))
+ return false;
+
+ return true;
+}
+
/*
* Static locks do not have their class-keys yet - for them the key is
* the lock object itself. If the lock is in the per cpu area, the
@@ -1365,9 +1393,9 @@ register_lock_class(struct lockdep_map *lock, unsigned int subclass, int force)
out_set_class_cache:
if (!subclass || force)
- lock->class_cache[0] = class;
+ WRITE_ONCE(lock->class_cache[0], class);
else if (subclass < NR_LOCKDEP_CACHING_CLASSES)
- lock->class_cache[subclass] = class;
+ WRITE_ONCE(lock->class_cache[subclass], class);
/*
* Hash collision, did we smoke some? We found a class with a matching
@@ -4860,7 +4888,7 @@ void lockdep_init_map_type(struct lockdep_map *lock, const char *name,
int i;
for (i = 0; i < NR_LOCKDEP_CACHING_CLASSES; i++)
- lock->class_cache[i] = NULL;
+ WRITE_ONCE(lock->class_cache[i], NULL);
#ifdef CONFIG_LOCK_STAT
lock->cpu = raw_smp_processor_id();
@@ -4922,12 +4950,15 @@ EXPORT_SYMBOL_GPL(__lockdep_no_validate__);
void lockdep_set_lock_cmp_fn(struct lockdep_map *lock, lock_cmp_fn cmp_fn,
lock_print_fn print_fn)
{
- struct lock_class *class = lock->class_cache[0];
+ struct lock_class *class = READ_ONCE(lock->class_cache[0]);
unsigned long flags;
raw_local_irq_save(flags);
lockdep_recursion_inc();
+ if (!lock_class_cache_is_valid(lock, class, 0))
+ class = NULL;
+
if (!class)
class = register_lock_class(lock, 0, 0);
@@ -5005,8 +5036,11 @@ static int __lock_acquire(struct lockdep_map *lock, unsigned int subclass,
if (!prove_locking || lock->key == &__lockdep_no_validate__)
check = 0;
- if (subclass < NR_LOCKDEP_CACHING_CLASSES)
- class = lock->class_cache[subclass];
+ if (subclass < NR_LOCKDEP_CACHING_CLASSES) {
+ class = READ_ONCE(lock->class_cache[subclass]);
+ if (!lock_class_cache_is_valid(lock, class, subclass))
+ class = NULL;
+ }
/*
* Not cached?
*/
@@ -5201,9 +5235,9 @@ static noinstr int match_held_lock(const struct held_lock *hlock,
return 1;
if (hlock->references) {
- const struct lock_class *class = lock->class_cache[0];
+ const struct lock_class *class = READ_ONCE(lock->class_cache[0]);
- if (!class)
+ if (!lock_class_cache_is_valid(lock, class, 0))
class = look_up_lock_class(lock, 0);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 372/982] ASoC: ux500: Fix MSP stream lifecycle handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (370 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 371/982] locking/lockdep: Invalidate stale class_cache entries for zapped classes Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 373/982] ASoC: ux500: remove platform_data support Greg Kroah-Hartman
` (616 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit c37ba8fe00f264eee2fd18b0bff7c5f188136c51 ]
The trigger stop path drops the direction busy flag even though ALSA
still owns the stream until shutdown. A later trigger cannot reliably
restart it, shutdown may leave the block configured, and a second
stream may overwrite shared duplex configuration.
Keep configured and running directions as separate state. Program
shared settings only for the first direction, require a compatible
configuration for the other half of a duplex stream, and enable the
frame generator only while a provider stream is running. Also fix the
RX-disable direction test and preserve the other direction multichannel
setup.
Fixes: 3592b7f69a54 ("ASoC: Ux500: Add MSP I2S-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260902-ux500-msp-fixes-v2-1-4b60b002d55a@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_dai.c | 8 +-
sound/soc/ux500/ux500_msp_i2s.c | 183 ++++++++++++++++++++++++--------
sound/soc/ux500/ux500_msp_i2s.h | 4 +
3 files changed, 149 insertions(+), 46 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_dai.c b/sound/soc/ux500/ux500_msp_dai.c
index 9d99ea6d7f30e..ae266927c0306 100644
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -35,8 +35,10 @@ static int setup_pcm_multichan(struct snd_soc_dai *dai,
if (drvdata->slots > 1) {
msp_config->multichannel_configured = 1;
- multi->tx_multichannel_enable = true;
- multi->rx_multichannel_enable = true;
+ multi->tx_multichannel_enable =
+ msp_config->direction & MSP_DIR_TX;
+ multi->rx_multichannel_enable =
+ msp_config->direction & MSP_DIR_RX;
multi->rx_comparison_enable_mode = MSP_COMPARISON_DISABLED;
multi->tx_channel_0_enable = drvdata->tx_mask;
@@ -193,6 +195,7 @@ static int setup_clocking(struct snd_soc_dai *dai,
case SND_SOC_DAIFMT_BC_FC:
dev_dbg(dai->dev, "%s: Codec is master.\n", __func__);
+ msp_config->clock_provider = false;
msp_config->iodelay = 0x20;
msp_config->rx_fsync_sel = 0;
msp_config->tx_fsync_sel = 1 << TFSSEL_SHIFT;
@@ -205,6 +208,7 @@ static int setup_clocking(struct snd_soc_dai *dai,
case SND_SOC_DAIFMT_BP_FP:
dev_dbg(dai->dev, "%s: Codec is slave.\n", __func__);
+ msp_config->clock_provider = true;
msp_config->tx_clk_sel = TX_CLK_SEL_SRG;
msp_config->tx_fsync_sel = TX_SYNC_SRG_PROG;
msp_config->rx_clk_sel = RX_CLK_SEL_SRG;
diff --git a/sound/soc/ux500/ux500_msp_i2s.c b/sound/soc/ux500/ux500_msp_i2s.c
index d113411a19f82..baa5868d626d0 100644
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -345,20 +345,27 @@ static int configure_multichannel(struct ux500_msp *msp,
return 0;
}
-static int enable_msp(struct ux500_msp *msp, struct ux500_msp_config *config)
+static int enable_msp(struct ux500_msp *msp, struct ux500_msp_config *config,
+ bool first)
{
- int status = 0;
- u32 reg_val_DMACR, reg_val_GCR;
+ int status;
+ u32 reg_val_DMACR;
/* Configure msp with protocol dependent settings */
- configure_protocol(msp, config);
- setup_bitclk(msp, config);
+ status = configure_protocol(msp, config);
+ if (status)
+ return status;
+
+ if (first && config->clock_provider) {
+ status = setup_bitclk(msp, config);
+ if (status)
+ return status;
+ }
+
if (config->multichannel_configured == 1) {
status = configure_multichannel(msp, config);
if (status)
- dev_warn(msp->dev,
- "%s: WARN: configure_multichannel failed (%d)!\n",
- __func__, status);
+ return status;
}
/* Make sure the correct DMA-directions are configured */
@@ -384,11 +391,7 @@ static int enable_msp(struct ux500_msp *msp, struct ux500_msp_config *config)
writel(config->iodelay, msp->registers + MSP_IODLY);
- /* Enable frame generation logic */
- reg_val_GCR = readl(msp->registers + MSP_GCR);
- writel(reg_val_GCR | FRAME_GEN_ENABLE, msp->registers + MSP_GCR);
-
- return status;
+ return 0;
}
static void flush_fifo_rx(struct ux500_msp *msp)
@@ -426,12 +429,36 @@ static void flush_fifo_tx(struct ux500_msp *msp)
writel(reg_val_GCR, msp->registers + MSP_GCR);
}
+static bool ux500_msp_config_compatible(struct ux500_msp *msp,
+ struct ux500_msp_config *config)
+{
+ struct ux500_msp_config *active = &msp->config;
+
+ return active->f_inputclk == config->f_inputclk &&
+ active->tx_clk_sel == config->tx_clk_sel &&
+ active->rx_clk_sel == config->rx_clk_sel &&
+ active->srg_clk_sel == config->srg_clk_sel &&
+ active->rx_fsync_pol == config->rx_fsync_pol &&
+ active->tx_fsync_pol == config->tx_fsync_pol &&
+ active->rx_fsync_sel == config->rx_fsync_sel &&
+ active->tx_fsync_sel == config->tx_fsync_sel &&
+ active->default_protdesc == config->default_protdesc &&
+ active->protocol == config->protocol &&
+ active->frame_freq == config->frame_freq &&
+ active->data_size == config->data_size &&
+ active->def_elem_len == config->def_elem_len &&
+ active->clock_provider == config->clock_provider &&
+ !memcmp(&active->protdesc, &config->protdesc,
+ sizeof(active->protdesc));
+}
+
int ux500_msp_i2s_open(struct ux500_msp *msp,
struct ux500_msp_config *config)
{
u32 old_reg, new_reg, mask;
int res;
unsigned int tx_sel, rx_sel, tx_busy, rx_busy;
+ bool first;
if (in_interrupt()) {
dev_err(msp->dev,
@@ -459,40 +486,66 @@ int ux500_msp_i2s_open(struct ux500_msp *msp,
return -EBUSY;
}
- msp->dir_busy |= (tx_sel ? MSP_DIR_TX : 0) | (rx_sel ? MSP_DIR_RX : 0);
-
- /* First do the global config register */
- mask = RX_CLK_SEL_MASK | TX_CLK_SEL_MASK | RX_FSYNC_MASK |
- TX_FSYNC_MASK | RX_SYNC_SEL_MASK | TX_SYNC_SEL_MASK |
- RX_FIFO_ENABLE_MASK | TX_FIFO_ENABLE_MASK | SRG_CLK_SEL_MASK |
- LOOPBACK_MASK | TX_EXTRA_DELAY_MASK;
-
- new_reg = (config->tx_clk_sel | config->rx_clk_sel |
- config->rx_fsync_pol | config->tx_fsync_pol |
- config->rx_fsync_sel | config->tx_fsync_sel |
- config->rx_fifo_config | config->tx_fifo_config |
- config->srg_clk_sel | config->loopback_enable |
- config->tx_data_enable);
+ first = !msp->dir_busy;
+ if (!first && !ux500_msp_config_compatible(msp, config)) {
+ dev_err(msp->dev, "%s: Incompatible duplex configuration\n",
+ __func__);
+ return -EBUSY;
+ }
- old_reg = readl(msp->registers + MSP_GCR);
- old_reg &= ~mask;
- new_reg |= old_reg;
- writel(new_reg, msp->registers + MSP_GCR);
+ if (first) {
+ /* First do the global config register */
+ mask = RX_CLK_SEL_MASK | TX_CLK_SEL_MASK | RX_FSYNC_MASK |
+ TX_FSYNC_MASK | RX_SYNC_SEL_MASK | TX_SYNC_SEL_MASK |
+ RX_FIFO_ENABLE_MASK | TX_FIFO_ENABLE_MASK |
+ SRG_CLK_SEL_MASK | LOOPBACK_MASK | TX_EXTRA_DELAY_MASK;
+
+ new_reg = config->tx_clk_sel | config->rx_clk_sel |
+ config->rx_fsync_pol | config->tx_fsync_pol |
+ config->rx_fsync_sel | config->tx_fsync_sel |
+ config->rx_fifo_config | config->tx_fifo_config |
+ config->srg_clk_sel | config->loopback_enable |
+ config->tx_data_enable;
+
+ old_reg = readl(msp->registers + MSP_GCR);
+ old_reg &= ~mask;
+ new_reg |= old_reg;
+ writel(new_reg, msp->registers + MSP_GCR);
+ }
- res = enable_msp(msp, config);
+ res = enable_msp(msp, config, first);
if (res < 0) {
dev_err(msp->dev, "%s: ERROR: enable_msp failed (%d)!\n",
__func__, res);
- return -EBUSY;
+ if (tx_sel)
+ writel(0, msp->registers + MSP_TCF);
+ if (rx_sel)
+ writel(0, msp->registers + MSP_RCF);
+ if (first) {
+ writel(0, msp->registers + MSP_GCR);
+ writel(0, msp->registers + MSP_DMACR);
+ writel(0, msp->registers + MSP_SRG);
+ writel(0, msp->registers + MSP_MCR);
+ }
+ return res;
+ }
+
+ msp->dir_busy |= config->direction;
+ if (first) {
+ msp->config = *config;
+ msp->clock_provider = config->clock_provider;
}
if (config->loopback_enable & 0x80)
msp->loopback_enable = 1;
/* Flush FIFOs */
- flush_fifo_tx(msp);
- flush_fifo_rx(msp);
+ if (tx_sel)
+ flush_fifo_tx(msp);
+ if (rx_sel)
+ flush_fifo_rx(msp);
- msp->msp_state = MSP_STATE_CONFIGURED;
+ if (!msp->dir_running)
+ msp->msp_state = MSP_STATE_CONFIGURED;
return 0;
}
@@ -509,7 +562,6 @@ static void disable_msp_rx(struct ux500_msp *msp)
~(RX_SERVICE_INT | RX_OVERRUN_ERROR_INT),
msp->registers + MSP_IMSC);
- msp->dir_busy &= ~MSP_DIR_RX;
}
static void disable_msp_tx(struct ux500_msp *msp)
@@ -525,7 +577,6 @@ static void disable_msp_tx(struct ux500_msp *msp)
~(TX_SERVICE_INT | TX_UNDERRUN_ERR_INT),
msp->registers + MSP_IMSC);
- msp->dir_busy &= ~MSP_DIR_TX;
}
static int disable_msp(struct ux500_msp *msp, unsigned int dir)
@@ -535,7 +586,7 @@ static int disable_msp(struct ux500_msp *msp, unsigned int dir)
reg_val_GCR = readl(msp->registers + MSP_GCR);
disable_tx = dir & MSP_DIR_TX;
- disable_rx = dir & MSP_DIR_TX;
+ disable_rx = dir & MSP_DIR_RX;
if (disable_tx && disable_rx) {
reg_val_GCR = readl(msp->registers + MSP_GCR);
writel(reg_val_GCR | LOOPBACK_MASK,
@@ -568,7 +619,15 @@ static int disable_msp(struct ux500_msp *msp, unsigned int dir)
int ux500_msp_i2s_trigger(struct ux500_msp *msp, int cmd, int direction)
{
- u32 reg_val_GCR, enable_bit;
+ u32 reg_val_DMACR, reg_val_GCR, dma_enable_bit, enable_bit;
+ unsigned int dir;
+
+ if (direction == SNDRV_PCM_STREAM_PLAYBACK)
+ dir = MSP_DIR_TX;
+ else if (direction == SNDRV_PCM_STREAM_CAPTURE)
+ dir = MSP_DIR_RX;
+ else
+ return -EINVAL;
if (msp->msp_state == MSP_STATE_IDLE) {
dev_err(msp->dev, "%s: ERROR: MSP is not configured!\n",
@@ -580,21 +639,44 @@ int ux500_msp_i2s_trigger(struct ux500_msp *msp, int cmd, int direction)
case SNDRV_PCM_TRIGGER_START:
case SNDRV_PCM_TRIGGER_RESUME:
case SNDRV_PCM_TRIGGER_PAUSE_RELEASE:
- if (direction == SNDRV_PCM_STREAM_PLAYBACK)
+ if (direction == SNDRV_PCM_STREAM_PLAYBACK) {
enable_bit = TX_ENABLE;
- else
+ dma_enable_bit = TX_DMA_ENABLE;
+ } else {
enable_bit = RX_ENABLE;
+ dma_enable_bit = RX_DMA_ENABLE;
+ }
+ if (!(msp->dir_busy & dir))
+ return -EINVAL;
+ reg_val_DMACR = readl(msp->registers + MSP_DMACR);
+ writel(reg_val_DMACR | dma_enable_bit,
+ msp->registers + MSP_DMACR);
reg_val_GCR = readl(msp->registers + MSP_GCR);
+ if (msp->clock_provider)
+ enable_bit |= FRAME_GEN_ENABLE;
writel(reg_val_GCR | enable_bit, msp->registers + MSP_GCR);
+ msp->dir_running |= dir;
+ msp->msp_state = MSP_STATE_RUNNING;
break;
case SNDRV_PCM_TRIGGER_STOP:
case SNDRV_PCM_TRIGGER_SUSPEND:
case SNDRV_PCM_TRIGGER_PAUSE_PUSH:
- if (direction == SNDRV_PCM_STREAM_PLAYBACK)
+ if (!(msp->dir_busy & dir))
+ return -EINVAL;
+ if (direction == SNDRV_PCM_STREAM_PLAYBACK) {
disable_msp_tx(msp);
- else
+ msp->dir_running &= ~MSP_DIR_TX;
+ } else {
disable_msp_rx(msp);
+ msp->dir_running &= ~MSP_DIR_RX;
+ }
+ if (!msp->dir_running) {
+ reg_val_GCR = readl(msp->registers + MSP_GCR);
+ writel(reg_val_GCR & ~FRAME_GEN_ENABLE,
+ msp->registers + MSP_GCR);
+ msp->msp_state = MSP_STATE_CONFIGURED;
+ }
break;
default:
return -EINVAL;
@@ -609,7 +691,18 @@ int ux500_msp_i2s_close(struct ux500_msp *msp, unsigned int dir)
dev_dbg(msp->dev, "%s: Enter (dir = 0x%01x).\n", __func__, dir);
+ if (!dir || dir & ~(MSP_DIR_TX | MSP_DIR_RX) ||
+ (msp->dir_busy & dir) != dir)
+ return -EINVAL;
+
status = disable_msp(msp, dir);
+ msp->dir_busy &= ~dir;
+ msp->dir_running &= ~dir;
+ if (msp->dir_busy && !msp->dir_running) {
+ writel(readl(msp->registers + MSP_GCR) & ~FRAME_GEN_ENABLE,
+ msp->registers + MSP_GCR);
+ msp->msp_state = MSP_STATE_CONFIGURED;
+ }
if (msp->dir_busy == 0) {
/* disable sample rate and frame generators */
msp->msp_state = MSP_STATE_IDLE;
@@ -633,6 +726,8 @@ int ux500_msp_i2s_close(struct ux500_msp *msp, unsigned int dir)
writel(0, msp->registers + MSP_RCE1);
writel(0, msp->registers + MSP_RCE2);
writel(0, msp->registers + MSP_RCE3);
+ memset(&msp->config, 0, sizeof(msp->config));
+ msp->clock_provider = false;
}
return status;
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index d45b5e2831cc0..ad7977b70d264 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -461,6 +461,7 @@ struct ux500_msp_config {
enum msp_data_size data_size;
unsigned int def_elem_len;
unsigned int iodelay;
+ bool clock_provider;
};
struct ux500_msp_dma_params {
@@ -478,8 +479,11 @@ struct ux500_msp {
enum msp_state msp_state;
int def_elem_len;
unsigned int dir_busy;
+ unsigned int dir_running;
int loopback_enable;
unsigned int f_bitclk;
+ bool clock_provider;
+ struct ux500_msp_config config;
};
struct msp_i2s_platform_data;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 373/982] ASoC: ux500: remove platform_data support
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (371 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 372/982] ASoC: ux500: Fix MSP stream lifecycle handling Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 374/982] ASoC: ux500: Propagate MSP setup errors Greg Kroah-Hartman
` (615 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Linus Walleij,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
[ Upstream commit 1766ac5248063c25d1fe46e04bb936c46313ed89 ]
The platform data definition for ux500 sound devices was removed
six years ago after the DT conversion was completed, see commit
4b483ed0be8b ("ARM: ux500: cut some platform data").
Remove some leftover bits in the ASoC driver and just assume that
it always gets probed using DT.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Reviewed-by: Linus Walleij <linus.walleij@linaro.org>
Link: https://lore.kernel.org/r/20230118161110.521504-3-arnd@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 3415421a2b0b ("ASoC: ux500: Propagate MSP setup errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/platform_data/asoc-ux500-msp.h | 20 ----------
sound/soc/ux500/mop500.c | 8 ++--
sound/soc/ux500/ux500_msp_dai.c | 33 +--------------
sound/soc/ux500/ux500_msp_i2s.c | 33 +++------------
sound/soc/ux500/ux500_msp_i2s.h | 5 +--
sound/soc/ux500/ux500_pcm.c | 42 ++------------------
6 files changed, 15 insertions(+), 126 deletions(-)
delete mode 100644 include/linux/platform_data/asoc-ux500-msp.h
diff --git a/include/linux/platform_data/asoc-ux500-msp.h b/include/linux/platform_data/asoc-ux500-msp.h
deleted file mode 100644
index b8d0f730dda8d..0000000000000
--- a/include/linux/platform_data/asoc-ux500-msp.h
+++ /dev/null
@@ -1,20 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0-only */
-/*
- * Copyright (C) ST-Ericsson SA 2010
- *
- * Author: Rabin Vincent <rabin.vincent@stericsson.com> for ST-Ericsson
- */
-
-#ifndef __MSP_H
-#define __MSP_H
-
-#include <linux/platform_data/dma-ste-dma40.h>
-
-/* Platform data structure for a MSP I2S-device */
-struct msp_i2s_platform_data {
- int id;
- struct stedma40_chan_cfg *msp_i2s_dma_rx;
- struct stedma40_chan_cfg *msp_i2s_dma_tx;
-};
-
-#endif
diff --git a/sound/soc/ux500/mop500.c b/sound/soc/ux500/mop500.c
index fdd55d772b8e2..325e75e961369 100644
--- a/sound/soc/ux500/mop500.c
+++ b/sound/soc/ux500/mop500.c
@@ -109,11 +109,9 @@ static int mop500_probe(struct platform_device *pdev)
mop500_card.dev = &pdev->dev;
- if (np) {
- ret = mop500_of_probe(pdev, np);
- if (ret)
- return ret;
- }
+ ret = mop500_of_probe(pdev, np);
+ if (ret)
+ return ret;
dev_dbg(&pdev->dev, "%s: Card %s: Set platform drvdata.\n",
__func__, mop500_card.name);
diff --git a/sound/soc/ux500/ux500_msp_dai.c b/sound/soc/ux500/ux500_msp_dai.c
index ae266927c0306..39931ecb8ffbd 100644
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -15,7 +15,6 @@
#include <linux/of.h>
#include <linux/regulator/consumer.h>
#include <linux/mfd/dbx500-prcmu.h>
-#include <linux/platform_data/asoc-ux500-msp.h>
#include <sound/soc.h>
#include <sound/soc-dai.h>
@@ -686,26 +685,6 @@ static int ux500_msp_dai_of_probe(struct snd_soc_dai *dai)
return 0;
}
-static int ux500_msp_dai_probe(struct snd_soc_dai *dai)
-{
- struct ux500_msp_i2s_drvdata *drvdata = dev_get_drvdata(dai->dev);
- struct msp_i2s_platform_data *pdata = dai->dev->platform_data;
- int ret;
-
- if (!pdata) {
- ret = ux500_msp_dai_of_probe(dai);
- return ret;
- }
-
- drvdata->msp->playback_dma_data.data_size = drvdata->slot_width;
- drvdata->msp->capture_dma_data.data_size = drvdata->slot_width;
-
- snd_soc_dai_init_dma_data(dai,
- &drvdata->msp->playback_dma_data,
- &drvdata->msp->capture_dma_data);
- return 0;
-}
-
static const struct snd_soc_dai_ops ux500_msp_dai_ops[] = {
{
.set_sysclk = ux500_msp_dai_set_dai_sysclk,
@@ -720,7 +699,7 @@ static const struct snd_soc_dai_ops ux500_msp_dai_ops[] = {
};
static struct snd_soc_dai_driver ux500_msp_dai_drv = {
- .probe = ux500_msp_dai_probe,
+ .probe = ux500_msp_dai_of_probe,
.playback.channels_min = UX500_MSP_MIN_CHANNELS,
.playback.channels_max = UX500_MSP_MAX_CHANNELS,
.playback.rates = UX500_I2S_RATES,
@@ -741,15 +720,8 @@ static const struct snd_soc_component_driver ux500_msp_component = {
static int ux500_msp_drv_probe(struct platform_device *pdev)
{
struct ux500_msp_i2s_drvdata *drvdata;
- struct msp_i2s_platform_data *pdata = pdev->dev.platform_data;
- struct device_node *np = pdev->dev.of_node;
int ret = 0;
- if (!pdata && !np) {
- dev_err(&pdev->dev, "No platform data or Device Tree found\n");
- return -ENODEV;
- }
-
drvdata = devm_kzalloc(&pdev->dev,
sizeof(struct ux500_msp_i2s_drvdata),
GFP_KERNEL);
@@ -791,8 +763,7 @@ static int ux500_msp_drv_probe(struct platform_device *pdev)
return ret;
}
- ret = ux500_msp_i2s_init_msp(pdev, &drvdata->msp,
- pdev->dev.platform_data);
+ ret = ux500_msp_i2s_init_msp(pdev, &drvdata->msp);
if (!drvdata->msp) {
dev_err(&pdev->dev,
"%s: ERROR: Failed to init MSP-struct (%d)!",
diff --git a/sound/soc/ux500/ux500_msp_i2s.c b/sound/soc/ux500/ux500_msp_i2s.c
index baa5868d626d0..3ffbf3721742d 100644
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -14,7 +14,6 @@
#include <linux/slab.h>
#include <linux/io.h>
#include <linux/of.h>
-#include <linux/platform_data/asoc-ux500-msp.h>
#include <sound/soc.h>
@@ -735,18 +734,8 @@ int ux500_msp_i2s_close(struct ux500_msp *msp, unsigned int dir)
}
static int ux500_msp_i2s_of_init_msp(struct platform_device *pdev,
- struct ux500_msp *msp,
- struct msp_i2s_platform_data **platform_data)
+ struct ux500_msp *msp);
{
- struct msp_i2s_platform_data *pdata;
-
- *platform_data = devm_kzalloc(&pdev->dev,
- sizeof(struct msp_i2s_platform_data),
- GFP_KERNEL);
- pdata = *platform_data;
- if (!pdata)
- return -ENOMEM;
-
msp->playback_dma_data.dma_cfg = devm_kzalloc(&pdev->dev,
sizeof(struct stedma40_chan_cfg),
GFP_KERNEL);
@@ -763,11 +752,9 @@ static int ux500_msp_i2s_of_init_msp(struct platform_device *pdev,
}
int ux500_msp_i2s_init_msp(struct platform_device *pdev,
- struct ux500_msp **msp_p,
- struct msp_i2s_platform_data *platform_data)
+ struct ux500_msp **msp_p)
{
struct resource *res = NULL;
- struct device_node *np = pdev->dev.of_node;
struct ux500_msp *msp;
int ret;
@@ -776,19 +763,9 @@ int ux500_msp_i2s_init_msp(struct platform_device *pdev,
if (!msp)
return -ENOMEM;
- if (!platform_data) {
- if (np) {
- ret = ux500_msp_i2s_of_init_msp(pdev, msp,
- &platform_data);
- if (ret)
- return ret;
- } else
- return -EINVAL;
- } else {
- msp->playback_dma_data.dma_cfg = platform_data->msp_i2s_dma_tx;
- msp->capture_dma_data.dma_cfg = platform_data->msp_i2s_dma_rx;
- msp->id = platform_data->id;
- }
+ ret = ux500_msp_i2s_of_init_msp(pdev, msp);
+ if (ret)
+ return ret;
msp->dev = &pdev->dev;
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index ad7977b70d264..09a74be972eca 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -11,7 +11,6 @@
#define UX500_MSP_I2S_H
#include <linux/platform_device.h>
-#include <linux/platform_data/asoc-ux500-msp.h>
#define MSP_INPUT_FREQ_APB 48000000
@@ -486,10 +485,8 @@ struct ux500_msp {
struct ux500_msp_config config;
};
-struct msp_i2s_platform_data;
int ux500_msp_i2s_init_msp(struct platform_device *pdev,
- struct ux500_msp **msp_p,
- struct msp_i2s_platform_data *platform_data);
+ struct ux500_msp **msp_p);
void ux500_msp_i2s_cleanup_msp(struct platform_device *pdev,
struct ux500_msp *msp);
int ux500_msp_i2s_open(struct ux500_msp *msp, struct ux500_msp_config *config);
diff --git a/sound/soc/ux500/ux500_pcm.c b/sound/soc/ux500/ux500_pcm.c
index d3802e5ef196e..ca87517d80c9f 100644
--- a/sound/soc/ux500/ux500_pcm.c
+++ b/sound/soc/ux500/ux500_pcm.c
@@ -29,18 +29,6 @@
#define UX500_PLATFORM_PERIODS_MAX 48
#define UX500_PLATFORM_BUFFER_BYTES_MAX (2048 * PAGE_SIZE)
-static const struct snd_pcm_hardware ux500_pcm_hw = {
- .info = SNDRV_PCM_INFO_INTERLEAVED |
- SNDRV_PCM_INFO_MMAP |
- SNDRV_PCM_INFO_RESUME |
- SNDRV_PCM_INFO_PAUSE,
- .buffer_bytes_max = UX500_PLATFORM_BUFFER_BYTES_MAX,
- .period_bytes_min = UX500_PLATFORM_PERIODS_BYTES_MIN,
- .period_bytes_max = UX500_PLATFORM_PERIODS_BYTES_MAX,
- .periods_min = UX500_PLATFORM_PERIODS_MIN,
- .periods_max = UX500_PLATFORM_PERIODS_MAX,
-};
-
static struct dma_chan *ux500_pcm_request_chan(struct snd_soc_pcm_runtime *rtd,
struct snd_pcm_substream *substream)
{
@@ -84,21 +72,12 @@ static int ux500_pcm_prepare_slave_config(struct snd_pcm_substream *substream,
struct dma_slave_config *slave_config)
{
struct snd_soc_pcm_runtime *rtd = asoc_substream_to_rtd(substream);
- struct msp_i2s_platform_data *pdata = asoc_rtd_to_cpu(rtd, 0)->dev->platform_data;
struct snd_dmaengine_dai_dma_data *snd_dma_params;
- struct ux500_msp_dma_params *ste_dma_params;
dma_addr_t dma_addr;
int ret;
- if (pdata) {
- ste_dma_params =
- snd_soc_dai_get_dma_data(asoc_rtd_to_cpu(rtd, 0), substream);
- dma_addr = ste_dma_params->tx_rx_addr;
- } else {
- snd_dma_params =
- snd_soc_dai_get_dma_data(asoc_rtd_to_cpu(rtd, 0), substream);
- dma_addr = snd_dma_params->addr;
- }
+ snd_dma_params = snd_soc_dai_get_dma_data(asoc_rtd_to_cpu(rtd, 0), substream);
+ dma_addr = snd_dma_params->addr;
ret = snd_hwparams_to_dma_slave_config(substream, params, slave_config);
if (ret)
@@ -118,13 +97,6 @@ static int ux500_pcm_prepare_slave_config(struct snd_pcm_substream *substream,
return 0;
}
-static const struct snd_dmaengine_pcm_config ux500_dmaengine_pcm_config = {
- .pcm_hardware = &ux500_pcm_hw,
- .compat_request_channel = ux500_pcm_request_chan,
- .prealloc_buffer_size = 128 * 1024,
- .prepare_slave_config = ux500_pcm_prepare_slave_config,
-};
-
static const struct snd_dmaengine_pcm_config ux500_dmaengine_of_pcm_config = {
.compat_request_channel = ux500_pcm_request_chan,
.prepare_slave_config = ux500_pcm_prepare_slave_config,
@@ -132,16 +104,10 @@ static const struct snd_dmaengine_pcm_config ux500_dmaengine_of_pcm_config = {
int ux500_pcm_register_platform(struct platform_device *pdev)
{
- const struct snd_dmaengine_pcm_config *pcm_config;
- struct device_node *np = pdev->dev.of_node;
int ret;
- if (np)
- pcm_config = &ux500_dmaengine_of_pcm_config;
- else
- pcm_config = &ux500_dmaengine_pcm_config;
-
- ret = snd_dmaengine_pcm_register(&pdev->dev, pcm_config,
+ ret = snd_dmaengine_pcm_register(&pdev->dev,
+ &ux500_dmaengine_of_pcm_config,
SND_DMAENGINE_PCM_FLAG_COMPAT);
if (ret < 0) {
dev_err(&pdev->dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 374/982] ASoC: ux500: Propagate MSP setup errors
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (372 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 373/982] ASoC: ux500: remove platform_data support Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 375/982] ASoC: ux500: Correct MSP frame and bit clock setup Greg Kroah-Hartman
` (614 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 3415421a2b0bc4e32bb5a9df24ed7863512d47a7 ]
The prepare callback continues with a partly initialized configuration
when format setup fails. Probe likewise tests the allocated pointer
instead of the return value, so an MMIO resource or mapping failure can
be ignored after allocation succeeds.
Return configuration failures from prepare and test the MSP
initialization result directly.
Fixes: 3592b7f69a54 ("ASoC: Ux500: Add MSP I2S-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260902-ux500-msp-fixes-v2-2-4b60b002d55a@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_dai.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_dai.c b/sound/soc/ux500/ux500_msp_dai.c
index 39931ecb8ffbd..d24a3e9707c8d 100644
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -468,7 +468,9 @@ static int ux500_msp_dai_prepare(struct snd_pcm_substream *substream,
dev_dbg(dai->dev, "%s: MSP %d (%s): Enter (rate = %d).\n", __func__,
dai->id, snd_pcm_stream_str(substream), runtime->rate);
- setup_msp_config(substream, dai, &msp_config);
+ ret = setup_msp_config(substream, dai, &msp_config);
+ if (ret)
+ return ret;
ret = ux500_msp_i2s_open(drvdata->msp, &msp_config);
if (ret < 0) {
@@ -764,7 +766,7 @@ static int ux500_msp_drv_probe(struct platform_device *pdev)
}
ret = ux500_msp_i2s_init_msp(pdev, &drvdata->msp);
- if (!drvdata->msp) {
+ if (ret) {
dev_err(&pdev->dev,
"%s: ERROR: Failed to init MSP-struct (%d)!",
__func__, ret);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 375/982] ASoC: ux500: Correct MSP frame and bit clock setup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (373 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 374/982] ASoC: ux500: Propagate MSP setup errors Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 376/982] ASoC: ux500: Validate MSP DAI configuration Greg Kroah-Hartman
` (613 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 94c18cea657c48680e4ee20b635b6c01f3eb352e ]
FRPER plus one is the number of bit clocks in a frame. It must follow
the configured slot count and width. The legacy rate-dependent
constants produce malformed frames; notably, a 16-slot, 16-bit frame
is programmed as 278 rather than 256 clocks.
Derive the frame period from the TDM geometry and use the real
functional clock rate. Validate that the requested bit clock has an
exact, representable divider, program SCKDIV as divider minus one, and
report the resulting bit clock using that same divisor.
Fixes: 3592b7f69a54 ("ASoC: Ux500: Add MSP I2S-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260902-ux500-msp-fixes-v2-3-4b60b002d55a@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_dai.c | 75 +++++++--------------------------
sound/soc/ux500/ux500_msp_dai.h | 11 -----
sound/soc/ux500/ux500_msp_i2s.c | 54 ++++++++++++++----------
sound/soc/ux500/ux500_msp_i2s.h | 2 -
4 files changed, 46 insertions(+), 96 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_dai.c b/sound/soc/ux500/ux500_msp_dai.c
index d24a3e9707c8d..1b01f53aeff6d 100644
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -59,72 +59,21 @@ static int setup_pcm_multichan(struct snd_soc_dai *dai,
return 0;
}
-static int setup_frameper(struct snd_soc_dai *dai, unsigned int rate,
- struct msp_protdesc *prot_desc)
+static void setup_frameper(struct snd_soc_dai *dai,
+ struct msp_protdesc *prot_desc)
{
struct ux500_msp_i2s_drvdata *drvdata = dev_get_drvdata(dai->dev);
- switch (drvdata->slots) {
- case 1:
- switch (rate) {
- case 8000:
- prot_desc->frame_period =
- FRAME_PER_SINGLE_SLOT_8_KHZ;
- break;
-
- case 16000:
- prot_desc->frame_period =
- FRAME_PER_SINGLE_SLOT_16_KHZ;
- break;
-
- case 44100:
- prot_desc->frame_period =
- FRAME_PER_SINGLE_SLOT_44_1_KHZ;
- break;
-
- case 48000:
- prot_desc->frame_period =
- FRAME_PER_SINGLE_SLOT_48_KHZ;
- break;
-
- default:
- dev_err(dai->dev,
- "%s: Error: Unsupported sample-rate (freq = %d)!\n",
- __func__, rate);
- return -EINVAL;
- }
- break;
-
- case 2:
- prot_desc->frame_period = FRAME_PER_2_SLOTS;
- break;
-
- case 8:
- prot_desc->frame_period = FRAME_PER_8_SLOTS;
- break;
-
- case 16:
- prot_desc->frame_period = FRAME_PER_16_SLOTS;
- break;
- default:
- dev_err(dai->dev,
- "%s: Error: Unsupported slot-count (slots = %d)!\n",
- __func__, drvdata->slots);
- return -EINVAL;
- }
-
- prot_desc->clocks_per_frame =
- prot_desc->frame_period+1;
+ prot_desc->clocks_per_frame = drvdata->slots * drvdata->slot_width;
+ prot_desc->frame_period = prot_desc->clocks_per_frame - 1;
dev_dbg(dai->dev, "%s: Clocks per frame: %u\n",
__func__,
prot_desc->clocks_per_frame);
-
- return 0;
}
-static int setup_pcm_framing(struct snd_soc_dai *dai, unsigned int rate,
- struct msp_protdesc *prot_desc)
+static int setup_pcm_framing(struct snd_soc_dai *dai,
+ struct msp_protdesc *prot_desc)
{
struct ux500_msp_i2s_drvdata *drvdata = dev_get_drvdata(dai->dev);
@@ -165,7 +114,9 @@ static int setup_pcm_framing(struct snd_soc_dai *dai, unsigned int rate,
prot_desc->tx_elem_len_2 = MSP_ELEM_LEN_16;
prot_desc->rx_elem_len_2 = MSP_ELEM_LEN_16;
- return setup_frameper(dai, rate, prot_desc);
+ setup_frameper(dai, prot_desc);
+
+ return 0;
}
static int setup_clocking(struct snd_soc_dai *dai,
@@ -366,7 +317,7 @@ static int setup_msp_config(struct snd_pcm_substream *substream,
if (ret < 0)
return ret;
- ret = setup_pcm_framing(dai, runtime->rate, prot_desc);
+ ret = setup_pcm_framing(dai, prot_desc);
if (ret < 0)
return ret;
@@ -735,7 +686,6 @@ static int ux500_msp_drv_probe(struct platform_device *pdev)
drvdata->tx_mask = 0x01;
drvdata->rx_mask = 0x01;
drvdata->slot_width = 16;
- drvdata->master_clk = MSP_INPUT_FREQ_APB;
drvdata->reg_vape = devm_regulator_get(&pdev->dev, "v-ape");
if (IS_ERR(drvdata->reg_vape)) {
@@ -764,6 +714,11 @@ static int ux500_msp_drv_probe(struct platform_device *pdev)
__func__, ret);
return ret;
}
+ drvdata->master_clk = clk_get_rate(drvdata->clk);
+ if (!drvdata->master_clk) {
+ dev_err(&pdev->dev, "MSP clock has no rate\n");
+ return -EINVAL;
+ }
ret = ux500_msp_i2s_init_msp(pdev, &drvdata->msp);
if (ret) {
diff --git a/sound/soc/ux500/ux500_msp_dai.h b/sound/soc/ux500/ux500_msp_dai.h
index 30bf708381961..19058c238420e 100644
--- a/sound/soc/ux500/ux500_msp_dai.h
+++ b/sound/soc/ux500/ux500_msp_dai.h
@@ -22,17 +22,6 @@
#define UX500_I2S_FORMATS (SNDRV_PCM_FMTBIT_S16_LE)
-#define FRAME_PER_SINGLE_SLOT_8_KHZ 31
-#define FRAME_PER_SINGLE_SLOT_16_KHZ 124
-#define FRAME_PER_SINGLE_SLOT_44_1_KHZ 63
-#define FRAME_PER_SINGLE_SLOT_48_KHZ 49
-#define FRAME_PER_2_SLOTS 31
-#define FRAME_PER_8_SLOTS 138
-#define FRAME_PER_16_SLOTS 277
-
-#define UX500_MSP_INTERNAL_CLOCK_FREQ 40000000
-#define UX500_MSP1_INTERNAL_CLOCK_FREQ UX500_MSP_INTERNAL_CLOCK_FREQ
-
#define UX500_MSP_MIN_CHANNELS 1
#define UX500_MSP_MAX_CHANNELS 8
diff --git a/sound/soc/ux500/ux500_msp_i2s.c b/sound/soc/ux500/ux500_msp_i2s.c
index 3ffbf3721742d..d1f00cb7d21ce 100644
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -212,35 +212,20 @@ static int configure_protocol(struct ux500_msp *msp,
static int setup_bitclk(struct ux500_msp *msp, struct ux500_msp_config *config)
{
+ struct msp_protdesc *protdesc;
+ u64 desired_bitclk;
+ unsigned int bitclk;
u32 reg_val_GCR;
- u32 frame_per = 0;
- u32 sck_div = 0;
- u32 frame_width = 0;
- u32 temp_reg = 0;
- struct msp_protdesc *protdesc = NULL;
+ u32 sck_div;
+ u32 temp_reg;
reg_val_GCR = readl(msp->registers + MSP_GCR);
writel(reg_val_GCR & ~SRG_ENABLE, msp->registers + MSP_GCR);
- if (config->default_protdesc)
- protdesc =
- (struct msp_protdesc *)&prot_descs[config->protocol];
- else
- protdesc = (struct msp_protdesc *)&config->protdesc;
-
switch (config->protocol) {
case MSP_PCM_PROTOCOL:
case MSP_PCM_COMPAND_PROTOCOL:
- frame_width = protdesc->frame_width;
- sck_div = config->f_inputclk / (config->frame_freq *
- (protdesc->clocks_per_frame));
- frame_per = protdesc->frame_period;
- break;
case MSP_I2S_PROTOCOL:
- frame_width = protdesc->frame_width;
- sck_div = config->f_inputclk / (config->frame_freq *
- (protdesc->clocks_per_frame));
- frame_per = protdesc->frame_period;
break;
default:
dev_err(msp->dev, "%s: ERROR: Unknown protocol (%d)!\n",
@@ -249,12 +234,35 @@ static int setup_bitclk(struct ux500_msp *msp, struct ux500_msp_config *config)
return -EINVAL;
}
+ if (config->default_protdesc)
+ protdesc = (struct msp_protdesc *)&prot_descs[config->protocol];
+ else
+ protdesc = &config->protdesc;
+
+ if (!config->frame_freq || !protdesc->clocks_per_frame)
+ return -EINVAL;
+
+ desired_bitclk = (u64)config->frame_freq * protdesc->clocks_per_frame;
+ if (desired_bitclk > config->f_inputclk)
+ return -EINVAL;
+ bitclk = desired_bitclk;
+ if (config->f_inputclk % bitclk) {
+ dev_err(msp->dev,
+ "Input clock %u cannot generate bit clock %u\n",
+ config->f_inputclk, bitclk);
+ return -EINVAL;
+ }
+
+ sck_div = config->f_inputclk / bitclk;
+ if (!sck_div || sck_div > SCK_DIV_MASK + 1)
+ return -EINVAL;
+
temp_reg = (sck_div - 1) & SCK_DIV_MASK;
- temp_reg |= FRAME_WIDTH_BITS(frame_width);
- temp_reg |= FRAME_PERIOD_BITS(frame_per);
+ temp_reg |= FRAME_WIDTH_BITS(protdesc->frame_width);
+ temp_reg |= FRAME_PERIOD_BITS(protdesc->frame_period);
writel(temp_reg, msp->registers + MSP_SRG);
- msp->f_bitclk = (config->f_inputclk)/(sck_div + 1);
+ msp->f_bitclk = config->f_inputclk / sck_div;
/* Enable bit-clock */
udelay(100);
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 09a74be972eca..5bba201ebe52a 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -12,8 +12,6 @@
#include <linux/platform_device.h>
-#define MSP_INPUT_FREQ_APB 48000000
-
/*** Stereo mode. Used for APB data accesses as 16 bits accesses (mono),
* 32 bits accesses (stereo).
***/
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 376/982] ASoC: ux500: Validate MSP DAI configuration
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (374 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 375/982] ASoC: ux500: Correct MSP frame and bit clock setup Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 377/982] mfd: db8500-prcmu: Remove unused inline functions Greg Kroah-Hartman
` (612 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 9ccbacf5a0120964fc1ffacb8151e3347bee9287 ]
Installing channel constraints from hw_params is too late to affect the
parameters being committed. The driver consequently accepts channel
counts which disagree with the I2S or TDM setup. It also silently
truncates out-of-range slot masks and accepts inverted bit clock formats
which prepare then rejects.
Validate the selected channel count directly, reject invalid masks
before changing cached TDM state, and implement all four standard clock
and frame inversion combinations. Use the requested format in
validation diagnostics.
Fixes: 3592b7f69a54 ("ASoC: Ux500: Add MSP I2S-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260902-ux500-msp-fixes-v2-4-4b60b002d55a@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_dai.c | 41 ++++++++++++++++++++++-----------
sound/soc/ux500/ux500_msp_i2s.c | 7 ++++--
sound/soc/ux500/ux500_msp_i2s.h | 1 +
3 files changed, 33 insertions(+), 16 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_dai.c b/sound/soc/ux500/ux500_msp_dai.c
index 1b01f53aeff6d..ad26185c54943 100644
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -130,7 +130,16 @@ static int setup_clocking(struct snd_soc_dai *dai,
case SND_SOC_DAIFMT_NB_IF:
msp_config->tx_fsync_pol ^= 1 << TFSPOL_SHIFT;
msp_config->rx_fsync_pol ^= 1 << RFSPOL_SHIFT;
+ break;
+
+ case SND_SOC_DAIFMT_IB_NF:
+ msp_config->bclk_inverted = true;
+ break;
+ case SND_SOC_DAIFMT_IB_IF:
+ msp_config->bclk_inverted = true;
+ msp_config->tx_fsync_pol ^= 1 << TFSPOL_SHIFT;
+ msp_config->rx_fsync_pol ^= 1 << RFSPOL_SHIFT;
break;
default:
@@ -453,7 +462,6 @@ static int ux500_msp_dai_hw_params(struct snd_pcm_substream *substream,
struct snd_soc_dai *dai)
{
unsigned int mask, slots_active;
- struct snd_pcm_runtime *runtime = substream->runtime;
struct ux500_msp_i2s_drvdata *drvdata = dev_get_drvdata(dai->dev);
dev_dbg(dai->dev, "%s: MSP %d (%s): Enter.\n",
@@ -461,9 +469,8 @@ static int ux500_msp_dai_hw_params(struct snd_pcm_substream *substream,
switch (drvdata->fmt & SND_SOC_DAIFMT_FORMAT_MASK) {
case SND_SOC_DAIFMT_I2S:
- snd_pcm_hw_constraint_minmax(runtime,
- SNDRV_PCM_HW_PARAM_CHANNELS,
- 1, 2);
+ if (params_channels(params) < 1 || params_channels(params) > 2)
+ return -EINVAL;
break;
case SND_SOC_DAIFMT_DSP_B:
@@ -475,9 +482,8 @@ static int ux500_msp_dai_hw_params(struct snd_pcm_substream *substream,
slots_active = hweight32(mask);
dev_dbg(dai->dev, "TDM-slots active: %d", slots_active);
- snd_pcm_hw_constraint_single(runtime,
- SNDRV_PCM_HW_PARAM_CHANNELS,
- slots_active);
+ if (!slots_active || params_channels(params) != slots_active)
+ return -EINVAL;
break;
default:
@@ -510,20 +516,21 @@ static int ux500_msp_dai_set_dai_fmt(struct snd_soc_dai *dai,
default:
dev_err(dai->dev,
"%s: Error: Unsupported protocol/master (fmt = 0x%x)!\n",
- __func__, drvdata->fmt);
+ __func__, fmt);
return -EINVAL;
}
switch (fmt & SND_SOC_DAIFMT_INV_MASK) {
case SND_SOC_DAIFMT_NB_NF:
case SND_SOC_DAIFMT_NB_IF:
+ case SND_SOC_DAIFMT_IB_NF:
case SND_SOC_DAIFMT_IB_IF:
break;
default:
dev_err(dai->dev,
"%s: Error: Unsupported inversion (fmt = 0x%x)!\n",
- __func__, drvdata->fmt);
+ __func__, fmt);
return -EINVAL;
}
@@ -557,17 +564,23 @@ static int ux500_msp_dai_set_tdm_slot(struct snd_soc_dai *dai,
__func__, slots);
return -EINVAL;
}
- drvdata->slots = slots;
- if (!(slot_width == 16)) {
+ if (slot_width != 16) {
dev_err(dai->dev, "%s: Error: Unsupported slot-width (%d)!\n",
__func__, slot_width);
return -EINVAL;
}
- drvdata->slot_width = slot_width;
- drvdata->tx_mask = tx_mask & cap;
- drvdata->rx_mask = rx_mask & cap;
+ if ((tx_mask | rx_mask) & ~cap) {
+ dev_err(dai->dev, "%s: Slot mask exceeds %d slots\n",
+ __func__, slots);
+ return -EINVAL;
+ }
+
+ drvdata->slots = slots;
+ drvdata->slot_width = slot_width;
+ drvdata->tx_mask = tx_mask;
+ drvdata->rx_mask = rx_mask;
return 0;
}
diff --git a/sound/soc/ux500/ux500_msp_i2s.c b/sound/soc/ux500/ux500_msp_i2s.c
index d1f00cb7d21ce..81187ed8669c8 100644
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -201,10 +201,12 @@ static int configure_protocol(struct ux500_msp *msp,
/* The code below should not be separated. */
temp_reg = readl(msp->registers + MSP_GCR) & ~TX_CLK_POL_RISING;
- temp_reg |= MSP_TX_CLKPOL_BIT(~protdesc->tx_clk_pol);
+ temp_reg |= MSP_TX_CLKPOL_BIT(!protdesc->tx_clk_pol ^
+ config->bclk_inverted);
writel(temp_reg, msp->registers + MSP_GCR);
temp_reg = readl(msp->registers + MSP_GCR) & ~RX_CLK_POL_RISING;
- temp_reg |= MSP_RX_CLKPOL_BIT(protdesc->rx_clk_pol);
+ temp_reg |= MSP_RX_CLKPOL_BIT(protdesc->rx_clk_pol ^
+ config->bclk_inverted);
writel(temp_reg, msp->registers + MSP_GCR);
return 0;
@@ -455,6 +457,7 @@ static bool ux500_msp_config_compatible(struct ux500_msp *msp,
active->data_size == config->data_size &&
active->def_elem_len == config->def_elem_len &&
active->clock_provider == config->clock_provider &&
+ active->bclk_inverted == config->bclk_inverted &&
!memcmp(&active->protdesc, &config->protdesc,
sizeof(active->protdesc));
}
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 5bba201ebe52a..fd48f85b7bf8d 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -459,6 +459,7 @@ struct ux500_msp_config {
unsigned int def_elem_len;
unsigned int iodelay;
bool clock_provider;
+ bool bclk_inverted;
};
struct ux500_msp_dma_params {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 377/982] mfd: db8500-prcmu: Remove unused inline functions
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (375 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 376/982] ASoC: ux500: Validate MSP DAI configuration Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 378/982] mfd: db8500-prcmu: Remove needless return in three void APIs Greg Kroah-Hartman
` (611 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, YueHaibing, Lee Jones, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: YueHaibing <yuehaibing@huawei.com>
[ Upstream commit 2dfe293bcde2d302c045d0cd536ccb15f86385d2 ]
Since commit b0e846248de5 ("mfd: db8500-prcmu: Remove dead code for a non-existing config")
these inline helpers also no need any more.
Signed-off-by: YueHaibing <yuehaibing@huawei.com>
Link: https://lore.kernel.org/r/20230720143738.13996-1-yuehaibing@huawei.com
Signed-off-by: Lee Jones <lee@kernel.org>
Stable-dep-of: 66ec63e7a90b ("ASoC: ux500: Deassert the MSP reset during probe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/mfd/dbx500-prcmu.h | 21 ---------------------
1 file changed, 21 deletions(-)
diff --git a/include/linux/mfd/dbx500-prcmu.h b/include/linux/mfd/dbx500-prcmu.h
index e7a7e70fdb385..dd0fc891b2289 100644
--- a/include/linux/mfd/dbx500-prcmu.h
+++ b/include/linux/mfd/dbx500-prcmu.h
@@ -556,16 +556,6 @@ static inline void prcmu_clear(unsigned int reg, u32 bits)
#define PRCMU_QOS_ARM_OPP 3
#define PRCMU_QOS_DEFAULT_VALUE -1
-static inline unsigned long prcmu_qos_get_cpufreq_opp_delay(void)
-{
- return 0;
-}
-
-static inline int prcmu_qos_requirement(int prcmu_qos_class)
-{
- return 0;
-}
-
static inline int prcmu_qos_add_requirement(int prcmu_qos_class,
char *name, s32 value)
{
@@ -582,15 +572,4 @@ static inline void prcmu_qos_remove_requirement(int prcmu_qos_class, char *name)
{
}
-static inline int prcmu_qos_add_notifier(int prcmu_qos_class,
- struct notifier_block *notifier)
-{
- return 0;
-}
-static inline int prcmu_qos_remove_notifier(int prcmu_qos_class,
- struct notifier_block *notifier)
-{
- return 0;
-}
-
#endif /* __MACH_PRCMU_H */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 378/982] mfd: db8500-prcmu: Remove needless return in three void APIs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (376 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 377/982] mfd: db8500-prcmu: Remove unused inline functions Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 379/982] arm: Handle KCOV __init vs inline mismatches Greg Kroah-Hartman
` (610 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zijun Hu, Linus Walleij, Lee Jones,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <quic_zijuhu@quicinc.com>
[ Upstream commit c105c555f8b4fd57b09439806b43b97ebc240ee2 ]
Remove needless 'return' in the following void APIs:
prcmu_early_init()
prcmu_system_reset()
prcmu_modem_reset()
Since both the API and callee involved are void functions.
Signed-off-by: Zijun Hu <quic_zijuhu@quicinc.com>
Reviewed-by: Linus Walleij <linus.walleij@linaro.org>
Link: https://lore.kernel.org/r/20250221-rmv_return-v1-15-cc8dff275827@quicinc.com
Signed-off-by: Lee Jones <lee@kernel.org>
Stable-dep-of: 66ec63e7a90b ("ASoC: ux500: Deassert the MSP reset during probe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/mfd/dbx500-prcmu.h | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/include/linux/mfd/dbx500-prcmu.h b/include/linux/mfd/dbx500-prcmu.h
index dd0fc891b2289..98567623c9df6 100644
--- a/include/linux/mfd/dbx500-prcmu.h
+++ b/include/linux/mfd/dbx500-prcmu.h
@@ -215,7 +215,7 @@ struct prcmu_fw_version {
static inline void prcmu_early_init(void)
{
- return db8500_prcmu_early_init();
+ db8500_prcmu_early_init();
}
static inline int prcmu_set_power_state(u8 state, bool keep_ulp_clk,
@@ -302,7 +302,7 @@ static inline int prcmu_request_ape_opp_100_voltage(bool enable)
static inline void prcmu_system_reset(u16 reset_code)
{
- return db8500_prcmu_system_reset(reset_code);
+ db8500_prcmu_system_reset(reset_code);
}
static inline u16 prcmu_get_reset_code(void)
@@ -314,7 +314,7 @@ int prcmu_ac_wake_req(void);
void prcmu_ac_sleep_req(void);
static inline void prcmu_modem_reset(void)
{
- return db8500_prcmu_modem_reset();
+ db8500_prcmu_modem_reset();
}
static inline bool prcmu_is_ac_wake_requested(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 379/982] arm: Handle KCOV __init vs inline mismatches
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (377 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 378/982] mfd: db8500-prcmu: Remove needless return in three void APIs Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 380/982] mfd: db8500-prcmu: Fold dbx500 header into db8500 Greg Kroah-Hartman
` (609 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nishanth Menon, Lee Jones, Kees Cook,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kees Cook <kees@kernel.org>
[ Upstream commit 2424fe1cac4fc8ea0520ba22ede7544c3ddc8dd1 ]
When KCOV is enabled all functions get instrumented, unless
the __no_sanitize_coverage attribute is used. To prepare for
__no_sanitize_coverage being applied to __init functions, we have to
handle differences in how GCC's inline optimizations get resolved. For
arm this exposed several places where __init annotations were missing
but ended up being "accidentally correct". Fix these cases and force
several functions to be inline with __always_inline.
Acked-by: Nishanth Menon <nm@ti.com>
Acked-by: Lee Jones <lee@kernel.org>
Reviewed-by: Nishanth Menon <nm@ti.com>
Link: https://lore.kernel.org/r/20250717232519.2984886-5-kees@kernel.org
Signed-off-by: Kees Cook <kees@kernel.org>
Stable-dep-of: 66ec63e7a90b ("ASoC: ux500: Deassert the MSP reset during probe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mm/cache-feroceon-l2.c | 2 +-
arch/arm/mm/cache-tauros2.c | 2 +-
drivers/clocksource/timer-orion.c | 2 +-
drivers/soc/ti/pm33xx.c | 2 +-
include/linux/mfd/dbx500-prcmu.h | 2 +-
5 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/arch/arm/mm/cache-feroceon-l2.c b/arch/arm/mm/cache-feroceon-l2.c
index 25dbd84a1aafa..2bfefb252ffdd 100644
--- a/arch/arm/mm/cache-feroceon-l2.c
+++ b/arch/arm/mm/cache-feroceon-l2.c
@@ -295,7 +295,7 @@ static inline u32 read_extra_features(void)
return u;
}
-static inline void write_extra_features(u32 u)
+static inline void __init write_extra_features(u32 u)
{
__asm__("mcr p15, 1, %0, c15, c1, 0" : : "r" (u));
}
diff --git a/arch/arm/mm/cache-tauros2.c b/arch/arm/mm/cache-tauros2.c
index b1e1aba602f7f..bfe166ccace05 100644
--- a/arch/arm/mm/cache-tauros2.c
+++ b/arch/arm/mm/cache-tauros2.c
@@ -177,7 +177,7 @@ static inline void __init write_actlr(u32 actlr)
__asm__("mcr p15, 0, %0, c1, c0, 1\n" : : "r" (actlr));
}
-static void enable_extra_feature(unsigned int features)
+static void __init enable_extra_feature(unsigned int features)
{
u32 u;
diff --git a/drivers/clocksource/timer-orion.c b/drivers/clocksource/timer-orion.c
index 49e86cb70a7a8..61f1e27fc41e7 100644
--- a/drivers/clocksource/timer-orion.c
+++ b/drivers/clocksource/timer-orion.c
@@ -43,7 +43,7 @@ static struct delay_timer orion_delay_timer = {
.read_current_timer = orion_read_timer,
};
-static void orion_delay_timer_init(unsigned long rate)
+static void __init orion_delay_timer_init(unsigned long rate)
{
orion_delay_timer.freq = rate;
register_current_timer_delay(&orion_delay_timer);
diff --git a/drivers/soc/ti/pm33xx.c b/drivers/soc/ti/pm33xx.c
index f04c21157904b..4c904a27941ff 100644
--- a/drivers/soc/ti/pm33xx.c
+++ b/drivers/soc/ti/pm33xx.c
@@ -145,7 +145,7 @@ static int am33xx_do_sram_idle(u32 wfi_flags)
return pm_ops->cpu_suspend(am33xx_do_wfi_sram, wfi_flags);
}
-static int __init am43xx_map_gic(void)
+static int am43xx_map_gic(void)
{
gic_dist_base = ioremap(AM43XX_GIC_DIST_BASE, SZ_4K);
diff --git a/include/linux/mfd/dbx500-prcmu.h b/include/linux/mfd/dbx500-prcmu.h
index 98567623c9df6..828362b7860c6 100644
--- a/include/linux/mfd/dbx500-prcmu.h
+++ b/include/linux/mfd/dbx500-prcmu.h
@@ -213,7 +213,7 @@ struct prcmu_fw_version {
#if defined(CONFIG_UX500_SOC_DB8500)
-static inline void prcmu_early_init(void)
+static inline void __init prcmu_early_init(void)
{
db8500_prcmu_early_init();
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 380/982] mfd: db8500-prcmu: Fold dbx500 header into db8500
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (378 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 379/982] arm: Handle KCOV __init vs inline mismatches Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 381/982] ASoC: ux500: remove stedma40 references Greg Kroah-Hartman
` (608 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Linus Walleij,
Brian Masney, Guenter Roeck, Mark Brown, Lee Jones, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit b8bc38bcecb77880a802d0430862b023c0aa7392 ]
Move the DBx500 PRCMU definitions into the DB8500 PRCMU
header and delete the wrapper header.
Convert users of simple PRCMU wrappers to call the DB8500 helpers
directly.
The dbx500-prcmu.h header was the result of an earlier attempt to
abstract several DBx5x SoC PRCMU units to use the same abstract
header. They are deleted from the kernel and this is not just
causing maintenance burden and build errors.
The stub code is using -ENOSYS in a way checkpatch complains about
so replace these with -EINVAL while we're at it.
Assisted-by: Codex:gpt-5-5
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202606180825.vUSQntkJ-lkp@intel.com/
Signed-off-by: Linus Walleij <linusw@kernel.org>
Acked-by: Brian Masney <bmasney@redhat.com>
Acked-by: Guenter Roeck <linux@roeck-us.net>
Acked-by: Mark Brown <broonie@kernel.org>
Link: https://lore.kernel.org/oe-kbuild-all/202606180825.vUSQntkJ-lkp@intel.com/
Link: https://patch.msgid.link/20260619-mfd-prcmu-merge-headers-v1-1-8ea0ee23b4d6@kernel.org
Signed-off-by: Lee Jones <lee@kernel.org>
Stable-dep-of: 66ec63e7a90b ("ASoC: ux500: Deassert the MSP reset during probe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-ux500/cpu-db8500.c | 6 +-
drivers/clk/ux500/clk-prcmu.c | 20 +-
drivers/clk/ux500/u8500_of_clk.c | 2 +-
drivers/cpuidle/cpuidle-ux500.c | 6 +-
drivers/mfd/ab8500-core.c | 2 +-
drivers/mfd/db8500-prcmu.c | 6 +-
drivers/regulator/db8500-prcmu.c | 12 +-
drivers/thermal/db8500_thermal.c | 10 +-
drivers/watchdog/db8500_wdt.c | 22 +-
include/linux/mfd/db8500-prcmu.h | 252 +++++++++++++-
include/linux/mfd/dbx500-prcmu.h | 575 -------------------------------
sound/soc/ux500/ux500_msp_dai.c | 2 +-
12 files changed, 294 insertions(+), 621 deletions(-)
delete mode 100644 include/linux/mfd/dbx500-prcmu.h
diff --git a/arch/arm/mach-ux500/cpu-db8500.c b/arch/arm/mach-ux500/cpu-db8500.c
index e929aaa744c0d..83a6975eab73c 100644
--- a/arch/arm/mach-ux500/cpu-db8500.c
+++ b/arch/arm/mach-ux500/cpu-db8500.c
@@ -12,7 +12,7 @@
#include <linux/irq.h>
#include <linux/irqchip.h>
#include <linux/irqchip/arm-gic.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/platform_data/arm-ux500-pm.h>
#include <linux/platform_device.h>
#include <linux/io.h>
@@ -84,7 +84,7 @@ static void __init ux500_init_irq(void)
struct resource r;
irqchip_init();
- prcmu_early_init();
+ db8500_prcmu_early_init();
np = of_find_compatible_node(NULL, NULL, "stericsson,db8500-prcmu");
of_address_to_resource(np, 0, &r);
of_node_put(np);
@@ -104,7 +104,7 @@ static void ux500_restart(enum reboot_mode mode, const char *cmd)
local_irq_disable();
local_fiq_disable();
- prcmu_system_reset(0);
+ db8500_prcmu_system_reset(0);
}
static const struct of_device_id u8500_local_bus_nodes[] = {
diff --git a/drivers/clk/ux500/clk-prcmu.c b/drivers/clk/ux500/clk-prcmu.c
index 4deb37f19a7ce..1dd3310f69c84 100644
--- a/drivers/clk/ux500/clk-prcmu.c
+++ b/drivers/clk/ux500/clk-prcmu.c
@@ -7,7 +7,7 @@
*/
#include <linux/clk-provider.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/slab.h>
#include <linux/io.h>
#include <linux/err.h>
@@ -35,13 +35,13 @@ static int clk_prcmu_prepare(struct clk_hw *hw)
{
struct clk_prcmu *clk = to_clk_prcmu(hw);
- return prcmu_request_clock(clk->cg_sel, true);
+ return db8500_prcmu_request_clock(clk->cg_sel, true);
}
static void clk_prcmu_unprepare(struct clk_hw *hw)
{
struct clk_prcmu *clk = to_clk_prcmu(hw);
- if (prcmu_request_clock(clk->cg_sel, false))
+ if (db8500_prcmu_request_clock(clk->cg_sel, false))
pr_err("clk_prcmu: %s failed to disable %s.\n", __func__,
clk_hw_get_name(hw));
}
@@ -84,7 +84,7 @@ static int clk_prcmu_opp_prepare(struct clk_hw *hw)
clk->opp_requested = 1;
}
- err = prcmu_request_clock(clk->cg_sel, true);
+ err = db8500_prcmu_request_clock(clk->cg_sel, true);
if (err) {
prcmu_qos_remove_requirement(PRCMU_QOS_APE_OPP,
(char *)clk_hw_get_name(hw));
@@ -99,7 +99,7 @@ static void clk_prcmu_opp_unprepare(struct clk_hw *hw)
{
struct clk_prcmu *clk = to_clk_prcmu(hw);
- if (prcmu_request_clock(clk->cg_sel, false)) {
+ if (db8500_prcmu_request_clock(clk->cg_sel, false)) {
pr_err("clk_prcmu: %s failed to disable %s.\n", __func__,
clk_hw_get_name(hw));
return;
@@ -118,7 +118,7 @@ static int clk_prcmu_opp_volt_prepare(struct clk_hw *hw)
struct clk_prcmu *clk = to_clk_prcmu(hw);
if (!clk->opp_requested) {
- err = prcmu_request_ape_opp_100_voltage(true);
+ err = db8500_prcmu_request_ape_opp_100_voltage(true);
if (err) {
pr_err("clk_prcmu: %s fail req APE OPP VOLT for %s.\n",
__func__, clk_hw_get_name(hw));
@@ -127,9 +127,9 @@ static int clk_prcmu_opp_volt_prepare(struct clk_hw *hw)
clk->opp_requested = 1;
}
- err = prcmu_request_clock(clk->cg_sel, true);
+ err = db8500_prcmu_request_clock(clk->cg_sel, true);
if (err) {
- prcmu_request_ape_opp_100_voltage(false);
+ db8500_prcmu_request_ape_opp_100_voltage(false);
clk->opp_requested = 0;
return err;
}
@@ -141,14 +141,14 @@ static void clk_prcmu_opp_volt_unprepare(struct clk_hw *hw)
{
struct clk_prcmu *clk = to_clk_prcmu(hw);
- if (prcmu_request_clock(clk->cg_sel, false)) {
+ if (db8500_prcmu_request_clock(clk->cg_sel, false)) {
pr_err("clk_prcmu: %s failed to disable %s.\n", __func__,
clk_hw_get_name(hw));
return;
}
if (clk->opp_requested) {
- prcmu_request_ape_opp_100_voltage(false);
+ db8500_prcmu_request_ape_opp_100_voltage(false);
clk->opp_requested = 0;
}
}
diff --git a/drivers/clk/ux500/u8500_of_clk.c b/drivers/clk/ux500/u8500_of_clk.c
index 8e2f6c65db2a7..512b0610d83b5 100644
--- a/drivers/clk/ux500/u8500_of_clk.c
+++ b/drivers/clk/ux500/u8500_of_clk.c
@@ -9,7 +9,7 @@
#include <linux/of.h>
#include <linux/of_address.h>
#include <linux/clk-provider.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include "clk.h"
#include "prcc.h"
diff --git a/drivers/cpuidle/cpuidle-ux500.c b/drivers/cpuidle/cpuidle-ux500.c
index f7d778580e9be..6d6c52c0bcc2d 100644
--- a/drivers/cpuidle/cpuidle-ux500.c
+++ b/drivers/cpuidle/cpuidle-ux500.c
@@ -11,7 +11,7 @@
#include <linux/spinlock.h>
#include <linux/atomic.h>
#include <linux/smp.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/platform_data/arm-ux500-pm.h>
#include <linux/platform_device.h>
@@ -66,7 +66,7 @@ static inline int ux500_enter_idle(struct cpuidle_device *dev,
/* Go to the retention state, the prcmu will wait for the
* cpu to go WFI and this is what happens after exiting this
* 'master' critical section */
- if (prcmu_set_power_state(PRCMU_AP_IDLE, true, true))
+ if (db8500_prcmu_set_power_state(PRCMU_AP_IDLE, true, true))
goto out;
/* When we switch to retention, the prcmu is in charge
@@ -109,7 +109,7 @@ static struct cpuidle_driver ux500_idle_driver = {
static int dbx500_cpuidle_probe(struct platform_device *pdev)
{
/* Configure wake up reasons */
- prcmu_enable_wakeups(PRCMU_WAKEUP(ARM) | PRCMU_WAKEUP(RTC) |
+ db8500_prcmu_enable_wakeups(PRCMU_WAKEUP(ARM) | PRCMU_WAKEUP(RTC) |
PRCMU_WAKEUP(ABB));
return cpuidle_register(&ux500_idle_driver, NULL);
diff --git a/drivers/mfd/ab8500-core.c b/drivers/mfd/ab8500-core.c
index 9d9e9787d5e8a..3052142d91953 100644
--- a/drivers/mfd/ab8500-core.c
+++ b/drivers/mfd/ab8500-core.c
@@ -19,7 +19,7 @@
#include <linux/mfd/core.h>
#include <linux/mfd/abx500.h>
#include <linux/mfd/abx500/ab8500.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/of.h>
#include <linux/of_device.h>
diff --git a/drivers/mfd/db8500-prcmu.c b/drivers/mfd/db8500-prcmu.c
index 27a881da4d6e6..f5a3ca498869f 100644
--- a/drivers/mfd/db8500-prcmu.c
+++ b/drivers/mfd/db8500-prcmu.c
@@ -32,7 +32,7 @@
#include <linux/platform_device.h>
#include <linux/uaccess.h>
#include <linux/mfd/core.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/mfd/abx500/ab8500.h>
#include <linux/regulator/db8500-prcmu.h>
#include <linux/regulator/machine.h>
@@ -2285,7 +2285,7 @@ void db8500_prcmu_system_reset(u16 reset_code)
/**
* db8500_prcmu_get_reset_code - Retrieve SW reset reason code
*
- * Retrieves the reset reason code stored by prcmu_system_reset() before
+ * Retrieves the reset reason code stored by db8500_prcmu_system_reset() before
* last restart.
*/
u16 db8500_prcmu_get_reset_code(void)
@@ -3041,7 +3041,7 @@ static int db8500_prcmu_probe(struct platform_device *pdev)
db8500_irq_init(np);
- prcmu_config_esram0_deep_sleep(ESRAM0_DEEP_SLEEP_STATE_RET);
+ db8500_prcmu_config_esram0_deep_sleep(ESRAM0_DEEP_SLEEP_STATE_RET);
err = mfd_add_devices(&pdev->dev, 0, common_prcmu_devs,
ARRAY_SIZE(common_prcmu_devs), NULL, 0, db8500_irq_domain);
diff --git a/drivers/regulator/db8500-prcmu.c b/drivers/regulator/db8500-prcmu.c
index 0ce6ec4933af3..cfe84ec06f91a 100644
--- a/drivers/regulator/db8500-prcmu.c
+++ b/drivers/regulator/db8500-prcmu.c
@@ -13,7 +13,7 @@
#include <linux/err.h>
#include <linux/spinlock.h>
#include <linux/platform_device.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/regulator/driver.h>
#include <linux/regulator/machine.h>
#include <linux/regulator/db8500-prcmu.h>
@@ -93,13 +93,13 @@ static int enable_epod(u16 epod_id, bool ramret)
if (ramret) {
if (!epod_on[epod_id]) {
- ret = prcmu_set_epod(epod_id, EPOD_STATE_RAMRET);
+ ret = db8500_prcmu_set_epod(epod_id, EPOD_STATE_RAMRET);
if (ret < 0)
return ret;
}
epod_ramret[epod_id] = true;
} else {
- ret = prcmu_set_epod(epod_id, EPOD_STATE_ON);
+ ret = db8500_prcmu_set_epod(epod_id, EPOD_STATE_ON);
if (ret < 0)
return ret;
epod_on[epod_id] = true;
@@ -114,18 +114,18 @@ static int disable_epod(u16 epod_id, bool ramret)
if (ramret) {
if (!epod_on[epod_id]) {
- ret = prcmu_set_epod(epod_id, EPOD_STATE_OFF);
+ ret = db8500_prcmu_set_epod(epod_id, EPOD_STATE_OFF);
if (ret < 0)
return ret;
}
epod_ramret[epod_id] = false;
} else {
if (epod_ramret[epod_id]) {
- ret = prcmu_set_epod(epod_id, EPOD_STATE_RAMRET);
+ ret = db8500_prcmu_set_epod(epod_id, EPOD_STATE_RAMRET);
if (ret < 0)
return ret;
} else {
- ret = prcmu_set_epod(epod_id, EPOD_STATE_OFF);
+ ret = db8500_prcmu_set_epod(epod_id, EPOD_STATE_OFF);
if (ret < 0)
return ret;
}
diff --git a/drivers/thermal/db8500_thermal.c b/drivers/thermal/db8500_thermal.c
index cb10e280681fc..523f84ac7ed47 100644
--- a/drivers/thermal/db8500_thermal.c
+++ b/drivers/thermal/db8500_thermal.c
@@ -10,7 +10,7 @@
#include <linux/cpu_cooling.h>
#include <linux/interrupt.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <linux/module.h>
#include <linux/of.h>
#include <linux/platform_device.h>
@@ -81,7 +81,7 @@ static void db8500_thermal_update_config(struct db8500_thermal_zone *th,
unsigned long next_low,
unsigned long next_high)
{
- prcmu_stop_temp_sense();
+ db8500_prcmu_stop_temp_sense();
th->cur_index = idx;
th->interpolated_temp = (next_low + next_high)/2;
@@ -90,8 +90,8 @@ static void db8500_thermal_update_config(struct db8500_thermal_zone *th,
* The PRCMU accept absolute temperatures in celsius so divide
* down the millicelsius with 1000
*/
- prcmu_config_hotmon((u8)(next_low/1000), (u8)(next_high/1000));
- prcmu_start_temp_sense(PRCMU_DEFAULT_MEASURE_TIME);
+ db8500_prcmu_config_hotmon((u8)(next_low / 1000), (u8)(next_high / 1000));
+ db8500_prcmu_start_temp_sense(PRCMU_DEFAULT_MEASURE_TIME);
}
static irqreturn_t prcmu_low_irq_handler(int irq, void *irq_data)
@@ -201,7 +201,7 @@ static int db8500_thermal_probe(struct platform_device *pdev)
static int db8500_thermal_suspend(struct platform_device *pdev,
pm_message_t state)
{
- prcmu_stop_temp_sense();
+ db8500_prcmu_stop_temp_sense();
return 0;
}
diff --git a/drivers/watchdog/db8500_wdt.c b/drivers/watchdog/db8500_wdt.c
index 6ed8b63d310d1..2b9fd0f16bff8 100644
--- a/drivers/watchdog/db8500_wdt.c
+++ b/drivers/watchdog/db8500_wdt.c
@@ -16,7 +16,7 @@
#include <linux/watchdog.h>
#include <linux/platform_device.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#define WATCHDOG_TIMEOUT 600 /* 10 minutes */
@@ -37,24 +37,24 @@ MODULE_PARM_DESC(nowayout,
static int db8500_wdt_start(struct watchdog_device *wdd)
{
- return prcmu_enable_a9wdog(PRCMU_WDOG_ALL);
+ return db8500_prcmu_enable_a9wdog(PRCMU_WDOG_ALL);
}
static int db8500_wdt_stop(struct watchdog_device *wdd)
{
- return prcmu_disable_a9wdog(PRCMU_WDOG_ALL);
+ return db8500_prcmu_disable_a9wdog(PRCMU_WDOG_ALL);
}
static int db8500_wdt_keepalive(struct watchdog_device *wdd)
{
- return prcmu_kick_a9wdog(PRCMU_WDOG_ALL);
+ return db8500_prcmu_kick_a9wdog(PRCMU_WDOG_ALL);
}
static int db8500_wdt_set_timeout(struct watchdog_device *wdd,
unsigned int timeout)
{
db8500_wdt_stop(wdd);
- prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
+ db8500_prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
db8500_wdt_start(wdd);
return 0;
@@ -91,10 +91,10 @@ static int db8500_wdt_probe(struct platform_device *pdev)
watchdog_set_nowayout(&db8500_wdt, nowayout);
/* disable auto off on sleep */
- prcmu_config_a9wdog(PRCMU_WDOG_CPU1, false);
+ db8500_prcmu_config_a9wdog(PRCMU_WDOG_CPU1, false);
/* set HW initial value */
- prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
+ db8500_prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
ret = devm_watchdog_register_device(dev, &db8500_wdt);
if (ret)
@@ -111,9 +111,9 @@ static int db8500_wdt_suspend(struct platform_device *pdev,
{
if (watchdog_active(&db8500_wdt)) {
db8500_wdt_stop(&db8500_wdt);
- prcmu_config_a9wdog(PRCMU_WDOG_CPU1, true);
+ db8500_prcmu_config_a9wdog(PRCMU_WDOG_CPU1, true);
- prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
+ db8500_prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
db8500_wdt_start(&db8500_wdt);
}
return 0;
@@ -123,9 +123,9 @@ static int db8500_wdt_resume(struct platform_device *pdev)
{
if (watchdog_active(&db8500_wdt)) {
db8500_wdt_stop(&db8500_wdt);
- prcmu_config_a9wdog(PRCMU_WDOG_CPU1, false);
+ db8500_prcmu_config_a9wdog(PRCMU_WDOG_CPU1, false);
- prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
+ db8500_prcmu_load_a9wdog(PRCMU_WDOG_ALL, timeout * 1000);
db8500_wdt_start(&db8500_wdt);
}
return 0;
diff --git a/include/linux/mfd/db8500-prcmu.h b/include/linux/mfd/db8500-prcmu.h
index a62de3d155edc..c939c9a1170a0 100644
--- a/include/linux/mfd/db8500-prcmu.h
+++ b/include/linux/mfd/db8500-prcmu.h
@@ -12,6 +12,9 @@
#include <linux/interrupt.h>
#include <linux/bitops.h>
+#include <linux/err.h>
+
+#include <dt-bindings/mfd/dbx500-prcmu.h> /* For clock identifiers */
/*
* Registers
@@ -24,6 +27,38 @@
#define DB8500_PRCM_DSI_SW_RESET_DSI1_SW_RESETN BIT(1)
#define DB8500_PRCM_DSI_SW_RESET_DSI2_SW_RESETN BIT(2)
+/* Offset for the firmware version within the TCPM */
+#define DB8500_PRCMU_FW_VERSION_OFFSET 0xA4
+
+#define DB8500_PRCMU_LEGACY_OFFSET 0xDD4
+
+/*
+ * CLKOUT sources
+ */
+#define PRCMU_CLKSRC_CLK38M 0x00
+#define PRCMU_CLKSRC_ACLK 0x01
+#define PRCMU_CLKSRC_SYSCLK 0x02
+#define PRCMU_CLKSRC_LCDCLK 0x03
+#define PRCMU_CLKSRC_SDMMCCLK 0x04
+#define PRCMU_CLKSRC_TVCLK 0x05
+#define PRCMU_CLKSRC_TIMCLK 0x06
+#define PRCMU_CLKSRC_CLK009 0x07
+/* These are only valid for CLKOUT1: */
+#define PRCMU_CLKSRC_SIAMMDSPCLK 0x40
+#define PRCMU_CLKSRC_I2CCLK 0x41
+#define PRCMU_CLKSRC_MSP02CLK 0x42
+#define PRCMU_CLKSRC_ARMPLL_OBSCLK 0x43
+#define PRCMU_CLKSRC_HSIRXCLK 0x44
+#define PRCMU_CLKSRC_HSITXCLK 0x45
+#define PRCMU_CLKSRC_ARMCLKFIX 0x46
+#define PRCMU_CLKSRC_HDMICLK 0x47
+
+/*
+ * Definitions for controlling ESRAM0 in deep sleep.
+ */
+#define ESRAM0_DEEP_SLEEP_STATE_OFF 1
+#define ESRAM0_DEEP_SLEEP_STATE_RET 2
+
/* This portion previously known as <mach/prcmu-fw-defs_v1.h> */
/**
@@ -451,10 +486,173 @@ enum prcmu_power_status {
PRCMU_ARMPENDINGIT_ER = 0x93,
};
+/* PRCMU Wakeup defines */
+enum prcmu_wakeup_index {
+ PRCMU_WAKEUP_INDEX_RTC,
+ PRCMU_WAKEUP_INDEX_RTT0,
+ PRCMU_WAKEUP_INDEX_RTT1,
+ PRCMU_WAKEUP_INDEX_HSI0,
+ PRCMU_WAKEUP_INDEX_HSI1,
+ PRCMU_WAKEUP_INDEX_USB,
+ PRCMU_WAKEUP_INDEX_ABB,
+ PRCMU_WAKEUP_INDEX_ABB_FIFO,
+ PRCMU_WAKEUP_INDEX_ARM,
+ PRCMU_WAKEUP_INDEX_CD_IRQ,
+ NUM_PRCMU_WAKEUP_INDICES
+};
+
+#define PRCMU_WAKEUP(_name) (BIT(PRCMU_WAKEUP_INDEX_##_name))
+
+/**
+ * enum prcmu_wdog_id - PRCMU watchdog IDs
+ * @PRCMU_WDOG_ALL: use all timers
+ * @PRCMU_WDOG_CPU1: use first CPU timer only
+ * @PRCMU_WDOG_CPU2: use second CPU timer conly
+ */
+enum prcmu_wdog_id {
+ PRCMU_WDOG_ALL = 0x00,
+ PRCMU_WDOG_CPU1 = 0x01,
+ PRCMU_WDOG_CPU2 = 0x02,
+};
+
+/**
+ * enum ape_opp - APE OPP states definition
+ * @APE_OPP_INIT:
+ * @APE_NO_CHANGE: The APE operating point is unchanged
+ * @APE_100_OPP: The new APE operating point is ape100opp
+ * @APE_50_OPP: 50%
+ * @APE_50_PARTLY_25_OPP: 50%, except some clocks at 25%.
+ */
+enum ape_opp {
+ APE_OPP_INIT = 0x00,
+ APE_NO_CHANGE = 0x01,
+ APE_100_OPP = 0x02,
+ APE_50_OPP = 0x03,
+ APE_50_PARTLY_25_OPP = 0xFF,
+};
+
+/**
+ * enum arm_opp - ARM OPP states definition
+ * @ARM_OPP_INIT:
+ * @ARM_NO_CHANGE: The ARM operating point is unchanged
+ * @ARM_100_OPP: The new ARM operating point is arm100opp
+ * @ARM_50_OPP: The new ARM operating point is arm50opp
+ * @ARM_MAX_OPP: Operating point is "max" (more than 100)
+ * @ARM_MAX_FREQ100OPP: Set max opp if available, else 100
+ * @ARM_EXTCLK: The new ARM operating point is armExtClk
+ */
+enum arm_opp {
+ ARM_OPP_INIT = 0x00,
+ ARM_NO_CHANGE = 0x01,
+ ARM_100_OPP = 0x02,
+ ARM_50_OPP = 0x03,
+ ARM_MAX_OPP = 0x04,
+ ARM_MAX_FREQ100OPP = 0x05,
+ ARM_EXTCLK = 0x07
+};
+
+/**
+ * enum ddr_opp - DDR OPP states definition
+ * @DDR_100_OPP: The new DDR operating point is ddr100opp
+ * @DDR_50_OPP: The new DDR operating point is ddr50opp
+ * @DDR_25_OPP: The new DDR operating point is ddr25opp
+ */
+enum ddr_opp {
+ DDR_100_OPP = 0x00,
+ DDR_50_OPP = 0x01,
+ DDR_25_OPP = 0x02,
+};
+
+/**
+ * enum ddr_pwrst - DDR power states definition
+ * @DDR_PWR_STATE_UNCHANGED: SDRAM and DDR controller state is unchanged
+ * @DDR_PWR_STATE_ON:
+ * @DDR_PWR_STATE_OFFLOWLAT:
+ * @DDR_PWR_STATE_OFFHIGHLAT:
+ */
+enum ddr_pwrst {
+ DDR_PWR_STATE_UNCHANGED = 0x00,
+ DDR_PWR_STATE_ON = 0x01,
+ DDR_PWR_STATE_OFFLOWLAT = 0x02,
+ DDR_PWR_STATE_OFFHIGHLAT = 0x03
+};
+
/*
* Definitions for autonomous power management configuration.
*/
+/* EPOD (power domain) IDs */
+
+/*
+ * DB8500 EPODs
+ * - EPOD_ID_SVAMMDSP: power domain for SVA MMDSP
+ * - EPOD_ID_SVAPIPE: power domain for SVA pipe
+ * - EPOD_ID_SIAMMDSP: power domain for SIA MMDSP
+ * - EPOD_ID_SIAPIPE: power domain for SIA pipe
+ * - EPOD_ID_SGA: power domain for SGA
+ * - EPOD_ID_B2R2_MCDE: power domain for B2R2 and MCDE
+ * - EPOD_ID_ESRAM12: power domain for ESRAM 1 and 2
+ * - EPOD_ID_ESRAM34: power domain for ESRAM 3 and 4
+ * - NUM_EPOD_ID: number of power domains
+ *
+ * TODO: These should be prefixed.
+ */
+#define EPOD_ID_SVAMMDSP 0
+#define EPOD_ID_SVAPIPE 1
+#define EPOD_ID_SIAMMDSP 2
+#define EPOD_ID_SIAPIPE 3
+#define EPOD_ID_SGA 4
+#define EPOD_ID_B2R2_MCDE 5
+#define EPOD_ID_ESRAM12 6
+#define EPOD_ID_ESRAM34 7
+#define NUM_EPOD_ID 8
+
+/*
+ * state definition for EPOD (power domain)
+ * - EPOD_STATE_NO_CHANGE: The EPOD should remain unchanged
+ * - EPOD_STATE_OFF: The EPOD is switched off
+ * - EPOD_STATE_RAMRET: The EPOD is switched off with its internal RAM in
+ * retention
+ * - EPOD_STATE_ON_CLK_OFF: The EPOD is switched on, clock is still off
+ * - EPOD_STATE_ON: Same as above, but with clock enabled
+ */
+#define EPOD_STATE_NO_CHANGE 0x00
+#define EPOD_STATE_OFF 0x01
+#define EPOD_STATE_RAMRET 0x02
+#define EPOD_STATE_ON_CLK_OFF 0x03
+#define EPOD_STATE_ON 0x04
+
+#define PRCMU_FW_PROJECT_U8500 2
+#define PRCMU_FW_PROJECT_U8400 3
+#define PRCMU_FW_PROJECT_U9500 4 /* Customer specific */
+#define PRCMU_FW_PROJECT_U8500_MBB 5
+#define PRCMU_FW_PROJECT_U8500_C1 6
+#define PRCMU_FW_PROJECT_U8500_C2 7
+#define PRCMU_FW_PROJECT_U8500_C3 8
+#define PRCMU_FW_PROJECT_U8500_C4 9
+#define PRCMU_FW_PROJECT_U9500_MBL 10
+#define PRCMU_FW_PROJECT_U8500_SSG1 11 /* Samsung specific */
+#define PRCMU_FW_PROJECT_U8500_MBL2 12 /* Customer specific */
+#define PRCMU_FW_PROJECT_U8520 13
+#define PRCMU_FW_PROJECT_U8420 14
+#define PRCMU_FW_PROJECT_U8500_SSG2 15 /* Samsung specific */
+#define PRCMU_FW_PROJECT_U8420_SYSCLK 17
+#define PRCMU_FW_PROJECT_A9420 20
+/* [32..63] 9540 and derivatives */
+#define PRCMU_FW_PROJECT_U9540 32
+/* [64..95] 8540 and derivatives */
+#define PRCMU_FW_PROJECT_L8540 64
+/* [96..126] 8580 and derivatives */
+#define PRCMU_FW_PROJECT_L8580 96
+
+#define PRCMU_FW_PROJECT_NAME_LEN 20
+
+/* PRCMU QoS APE OPP class */
+#define PRCMU_QOS_APE_OPP 1
+#define PRCMU_QOS_DDR_OPP 2
+#define PRCMU_QOS_ARM_OPP 3
+#define PRCMU_QOS_DEFAULT_VALUE -1
+
#define PRCMU_AUTO_PM_OFF 0
#define PRCMU_AUTO_PM_ON 1
@@ -469,6 +667,14 @@ enum prcmu_auto_pm_policy {
PRCMU_AUTO_PM_POLICY_DSP_CLK_OFF_HWP_CLK_OFF,
};
+struct prcmu_fw_version {
+ u32 project; /* Notice, project shifted with 8 on ux540 */
+ u8 api_version;
+ u8 func_version;
+ u8 errata;
+ char project_name[PRCMU_FW_PROJECT_NAME_LEN];
+};
+
/**
* struct prcmu_auto_pm_config - Autonomous power management configuration.
* @sia_auto_pm_enable: SIA autonomous pm enable. (PRCMU_AUTO_PM_{OFF,ON})
@@ -501,6 +707,9 @@ void prcmu_configure_auto_pm(struct prcmu_auto_pm_config *sleep,
bool prcmu_is_auto_pm_enabled(void);
int prcmu_config_clkout(u8 clkout, u8 source, u8 div);
+unsigned long prcmu_clock_rate(u8 clock);
+long prcmu_round_clock_rate(u8 clock, unsigned long rate);
+int prcmu_set_clock_rate(u8 clock, unsigned long rate);
int prcmu_set_clock_divider(u8 clock, u8 divider);
int db8500_prcmu_config_hotdog(u8 threshold);
int db8500_prcmu_config_hotmon(u8 low, u8 high);
@@ -508,6 +717,8 @@ int db8500_prcmu_start_temp_sense(u16 cycles32k);
int db8500_prcmu_stop_temp_sense(void);
int prcmu_abb_read(u8 slave, u8 reg, u8 *value, u8 size);
int prcmu_abb_write(u8 slave, u8 reg, u8 *value, u8 size);
+int prcmu_abb_write_masked(u8 slave, u8 reg, u8 *value,
+ u8 *mask, u8 size);
int prcmu_ac_wake_req(void);
void prcmu_ac_sleep_req(void);
@@ -610,6 +821,21 @@ static inline int prcmu_config_clkout(u8 clkout, u8 source, u8 div)
return 0;
}
+static inline unsigned long prcmu_clock_rate(u8 clock)
+{
+ return 0;
+}
+
+static inline long prcmu_round_clock_rate(u8 clock, unsigned long rate)
+{
+ return 0;
+}
+
+static inline int prcmu_set_clock_rate(u8 clock, unsigned long rate)
+{
+ return 0;
+}
+
static inline int prcmu_set_clock_divider(u8 clock, u8 divider)
{
return 0;
@@ -637,12 +863,18 @@ static inline int db8500_prcmu_stop_temp_sense(void)
static inline int prcmu_abb_read(u8 slave, u8 reg, u8 *value, u8 size)
{
- return -ENOSYS;
+ return -EINVAL;
}
static inline int prcmu_abb_write(u8 slave, u8 reg, u8 *value, u8 size)
{
- return -ENOSYS;
+ return -EINVAL;
+}
+
+static inline int prcmu_abb_write_masked(u8 slave, u8 reg,
+ u8 *value, u8 *mask, u8 size)
+{
+ return -EINVAL;
}
static inline int prcmu_ac_wake_req(void)
@@ -745,4 +977,20 @@ static inline void db8500_prcmu_write_masked(unsigned int reg, u32 mask,
#endif /* !CONFIG_MFD_DB8500_PRCMU */
+static inline int prcmu_qos_add_requirement(int prcmu_qos_class,
+ char *name, s32 value)
+{
+ return 0;
+}
+
+static inline int prcmu_qos_update_requirement(int prcmu_qos_class,
+ char *name, s32 new_value)
+{
+ return 0;
+}
+
+static inline void prcmu_qos_remove_requirement(int prcmu_qos_class, char *name)
+{
+}
+
#endif /* __MFD_DB8500_PRCMU_H */
diff --git a/include/linux/mfd/dbx500-prcmu.h b/include/linux/mfd/dbx500-prcmu.h
deleted file mode 100644
index 828362b7860c6..0000000000000
--- a/include/linux/mfd/dbx500-prcmu.h
+++ /dev/null
@@ -1,575 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0-only */
-/*
- * Copyright (C) ST Ericsson SA 2011
- *
- * STE Ux500 PRCMU API
- */
-#ifndef __MACH_PRCMU_H
-#define __MACH_PRCMU_H
-
-#include <linux/interrupt.h>
-#include <linux/notifier.h>
-#include <linux/err.h>
-
-#include <dt-bindings/mfd/dbx500-prcmu.h> /* For clock identifiers */
-
-/* Offset for the firmware version within the TCPM */
-#define DB8500_PRCMU_FW_VERSION_OFFSET 0xA4
-#define DBX540_PRCMU_FW_VERSION_OFFSET 0xA8
-
-/* PRCMU Wakeup defines */
-enum prcmu_wakeup_index {
- PRCMU_WAKEUP_INDEX_RTC,
- PRCMU_WAKEUP_INDEX_RTT0,
- PRCMU_WAKEUP_INDEX_RTT1,
- PRCMU_WAKEUP_INDEX_HSI0,
- PRCMU_WAKEUP_INDEX_HSI1,
- PRCMU_WAKEUP_INDEX_USB,
- PRCMU_WAKEUP_INDEX_ABB,
- PRCMU_WAKEUP_INDEX_ABB_FIFO,
- PRCMU_WAKEUP_INDEX_ARM,
- PRCMU_WAKEUP_INDEX_CD_IRQ,
- NUM_PRCMU_WAKEUP_INDICES
-};
-#define PRCMU_WAKEUP(_name) (BIT(PRCMU_WAKEUP_INDEX_##_name))
-
-/* EPOD (power domain) IDs */
-
-/*
- * DB8500 EPODs
- * - EPOD_ID_SVAMMDSP: power domain for SVA MMDSP
- * - EPOD_ID_SVAPIPE: power domain for SVA pipe
- * - EPOD_ID_SIAMMDSP: power domain for SIA MMDSP
- * - EPOD_ID_SIAPIPE: power domain for SIA pipe
- * - EPOD_ID_SGA: power domain for SGA
- * - EPOD_ID_B2R2_MCDE: power domain for B2R2 and MCDE
- * - EPOD_ID_ESRAM12: power domain for ESRAM 1 and 2
- * - EPOD_ID_ESRAM34: power domain for ESRAM 3 and 4
- * - NUM_EPOD_ID: number of power domains
- *
- * TODO: These should be prefixed.
- */
-#define EPOD_ID_SVAMMDSP 0
-#define EPOD_ID_SVAPIPE 1
-#define EPOD_ID_SIAMMDSP 2
-#define EPOD_ID_SIAPIPE 3
-#define EPOD_ID_SGA 4
-#define EPOD_ID_B2R2_MCDE 5
-#define EPOD_ID_ESRAM12 6
-#define EPOD_ID_ESRAM34 7
-#define NUM_EPOD_ID 8
-
-/*
- * state definition for EPOD (power domain)
- * - EPOD_STATE_NO_CHANGE: The EPOD should remain unchanged
- * - EPOD_STATE_OFF: The EPOD is switched off
- * - EPOD_STATE_RAMRET: The EPOD is switched off with its internal RAM in
- * retention
- * - EPOD_STATE_ON_CLK_OFF: The EPOD is switched on, clock is still off
- * - EPOD_STATE_ON: Same as above, but with clock enabled
- */
-#define EPOD_STATE_NO_CHANGE 0x00
-#define EPOD_STATE_OFF 0x01
-#define EPOD_STATE_RAMRET 0x02
-#define EPOD_STATE_ON_CLK_OFF 0x03
-#define EPOD_STATE_ON 0x04
-
-/*
- * CLKOUT sources
- */
-#define PRCMU_CLKSRC_CLK38M 0x00
-#define PRCMU_CLKSRC_ACLK 0x01
-#define PRCMU_CLKSRC_SYSCLK 0x02
-#define PRCMU_CLKSRC_LCDCLK 0x03
-#define PRCMU_CLKSRC_SDMMCCLK 0x04
-#define PRCMU_CLKSRC_TVCLK 0x05
-#define PRCMU_CLKSRC_TIMCLK 0x06
-#define PRCMU_CLKSRC_CLK009 0x07
-/* These are only valid for CLKOUT1: */
-#define PRCMU_CLKSRC_SIAMMDSPCLK 0x40
-#define PRCMU_CLKSRC_I2CCLK 0x41
-#define PRCMU_CLKSRC_MSP02CLK 0x42
-#define PRCMU_CLKSRC_ARMPLL_OBSCLK 0x43
-#define PRCMU_CLKSRC_HSIRXCLK 0x44
-#define PRCMU_CLKSRC_HSITXCLK 0x45
-#define PRCMU_CLKSRC_ARMCLKFIX 0x46
-#define PRCMU_CLKSRC_HDMICLK 0x47
-
-/**
- * enum prcmu_wdog_id - PRCMU watchdog IDs
- * @PRCMU_WDOG_ALL: use all timers
- * @PRCMU_WDOG_CPU1: use first CPU timer only
- * @PRCMU_WDOG_CPU2: use second CPU timer conly
- */
-enum prcmu_wdog_id {
- PRCMU_WDOG_ALL = 0x00,
- PRCMU_WDOG_CPU1 = 0x01,
- PRCMU_WDOG_CPU2 = 0x02,
-};
-
-/**
- * enum ape_opp - APE OPP states definition
- * @APE_OPP_INIT:
- * @APE_NO_CHANGE: The APE operating point is unchanged
- * @APE_100_OPP: The new APE operating point is ape100opp
- * @APE_50_OPP: 50%
- * @APE_50_PARTLY_25_OPP: 50%, except some clocks at 25%.
- */
-enum ape_opp {
- APE_OPP_INIT = 0x00,
- APE_NO_CHANGE = 0x01,
- APE_100_OPP = 0x02,
- APE_50_OPP = 0x03,
- APE_50_PARTLY_25_OPP = 0xFF,
-};
-
-/**
- * enum arm_opp - ARM OPP states definition
- * @ARM_OPP_INIT:
- * @ARM_NO_CHANGE: The ARM operating point is unchanged
- * @ARM_100_OPP: The new ARM operating point is arm100opp
- * @ARM_50_OPP: The new ARM operating point is arm50opp
- * @ARM_MAX_OPP: Operating point is "max" (more than 100)
- * @ARM_MAX_FREQ100OPP: Set max opp if available, else 100
- * @ARM_EXTCLK: The new ARM operating point is armExtClk
- */
-enum arm_opp {
- ARM_OPP_INIT = 0x00,
- ARM_NO_CHANGE = 0x01,
- ARM_100_OPP = 0x02,
- ARM_50_OPP = 0x03,
- ARM_MAX_OPP = 0x04,
- ARM_MAX_FREQ100OPP = 0x05,
- ARM_EXTCLK = 0x07
-};
-
-/**
- * enum ddr_opp - DDR OPP states definition
- * @DDR_100_OPP: The new DDR operating point is ddr100opp
- * @DDR_50_OPP: The new DDR operating point is ddr50opp
- * @DDR_25_OPP: The new DDR operating point is ddr25opp
- */
-enum ddr_opp {
- DDR_100_OPP = 0x00,
- DDR_50_OPP = 0x01,
- DDR_25_OPP = 0x02,
-};
-
-/*
- * Definitions for controlling ESRAM0 in deep sleep.
- */
-#define ESRAM0_DEEP_SLEEP_STATE_OFF 1
-#define ESRAM0_DEEP_SLEEP_STATE_RET 2
-
-/**
- * enum ddr_pwrst - DDR power states definition
- * @DDR_PWR_STATE_UNCHANGED: SDRAM and DDR controller state is unchanged
- * @DDR_PWR_STATE_ON:
- * @DDR_PWR_STATE_OFFLOWLAT:
- * @DDR_PWR_STATE_OFFHIGHLAT:
- */
-enum ddr_pwrst {
- DDR_PWR_STATE_UNCHANGED = 0x00,
- DDR_PWR_STATE_ON = 0x01,
- DDR_PWR_STATE_OFFLOWLAT = 0x02,
- DDR_PWR_STATE_OFFHIGHLAT = 0x03
-};
-
-#define DB8500_PRCMU_LEGACY_OFFSET 0xDD4
-
-#define PRCMU_FW_PROJECT_U8500 2
-#define PRCMU_FW_PROJECT_U8400 3
-#define PRCMU_FW_PROJECT_U9500 4 /* Customer specific */
-#define PRCMU_FW_PROJECT_U8500_MBB 5
-#define PRCMU_FW_PROJECT_U8500_C1 6
-#define PRCMU_FW_PROJECT_U8500_C2 7
-#define PRCMU_FW_PROJECT_U8500_C3 8
-#define PRCMU_FW_PROJECT_U8500_C4 9
-#define PRCMU_FW_PROJECT_U9500_MBL 10
-#define PRCMU_FW_PROJECT_U8500_SSG1 11 /* Samsung specific */
-#define PRCMU_FW_PROJECT_U8500_MBL2 12 /* Customer specific */
-#define PRCMU_FW_PROJECT_U8520 13
-#define PRCMU_FW_PROJECT_U8420 14
-#define PRCMU_FW_PROJECT_U8500_SSG2 15 /* Samsung specific */
-#define PRCMU_FW_PROJECT_U8420_SYSCLK 17
-#define PRCMU_FW_PROJECT_A9420 20
-/* [32..63] 9540 and derivatives */
-#define PRCMU_FW_PROJECT_U9540 32
-/* [64..95] 8540 and derivatives */
-#define PRCMU_FW_PROJECT_L8540 64
-/* [96..126] 8580 and derivatives */
-#define PRCMU_FW_PROJECT_L8580 96
-
-#define PRCMU_FW_PROJECT_NAME_LEN 20
-struct prcmu_fw_version {
- u32 project; /* Notice, project shifted with 8 on ux540 */
- u8 api_version;
- u8 func_version;
- u8 errata;
- char project_name[PRCMU_FW_PROJECT_NAME_LEN];
-};
-
-#include <linux/mfd/db8500-prcmu.h>
-
-#if defined(CONFIG_UX500_SOC_DB8500)
-
-static inline void __init prcmu_early_init(void)
-{
- db8500_prcmu_early_init();
-}
-
-static inline int prcmu_set_power_state(u8 state, bool keep_ulp_clk,
- bool keep_ap_pll)
-{
- return db8500_prcmu_set_power_state(state, keep_ulp_clk,
- keep_ap_pll);
-}
-
-static inline u8 prcmu_get_power_state_result(void)
-{
- return db8500_prcmu_get_power_state_result();
-}
-
-static inline int prcmu_set_epod(u16 epod_id, u8 epod_state)
-{
- return db8500_prcmu_set_epod(epod_id, epod_state);
-}
-
-static inline void prcmu_enable_wakeups(u32 wakeups)
-{
- db8500_prcmu_enable_wakeups(wakeups);
-}
-
-static inline void prcmu_disable_wakeups(void)
-{
- prcmu_enable_wakeups(0);
-}
-
-static inline void prcmu_config_abb_event_readout(u32 abb_events)
-{
- db8500_prcmu_config_abb_event_readout(abb_events);
-}
-
-static inline void prcmu_get_abb_event_buffer(void __iomem **buf)
-{
- db8500_prcmu_get_abb_event_buffer(buf);
-}
-
-int prcmu_abb_read(u8 slave, u8 reg, u8 *value, u8 size);
-int prcmu_abb_write(u8 slave, u8 reg, u8 *value, u8 size);
-int prcmu_abb_write_masked(u8 slave, u8 reg, u8 *value, u8 *mask, u8 size);
-
-int prcmu_config_clkout(u8 clkout, u8 source, u8 div);
-
-static inline int prcmu_request_clock(u8 clock, bool enable)
-{
- return db8500_prcmu_request_clock(clock, enable);
-}
-
-unsigned long prcmu_clock_rate(u8 clock);
-long prcmu_round_clock_rate(u8 clock, unsigned long rate);
-int prcmu_set_clock_rate(u8 clock, unsigned long rate);
-
-static inline int prcmu_get_ddr_opp(void)
-{
- return db8500_prcmu_get_ddr_opp();
-}
-
-static inline int prcmu_set_arm_opp(u8 opp)
-{
- return db8500_prcmu_set_arm_opp(opp);
-}
-
-static inline int prcmu_get_arm_opp(void)
-{
- return db8500_prcmu_get_arm_opp();
-}
-
-static inline int prcmu_set_ape_opp(u8 opp)
-{
- return db8500_prcmu_set_ape_opp(opp);
-}
-
-static inline int prcmu_get_ape_opp(void)
-{
- return db8500_prcmu_get_ape_opp();
-}
-
-static inline int prcmu_request_ape_opp_100_voltage(bool enable)
-{
- return db8500_prcmu_request_ape_opp_100_voltage(enable);
-}
-
-static inline void prcmu_system_reset(u16 reset_code)
-{
- db8500_prcmu_system_reset(reset_code);
-}
-
-static inline u16 prcmu_get_reset_code(void)
-{
- return db8500_prcmu_get_reset_code();
-}
-
-int prcmu_ac_wake_req(void);
-void prcmu_ac_sleep_req(void);
-static inline void prcmu_modem_reset(void)
-{
- db8500_prcmu_modem_reset();
-}
-
-static inline bool prcmu_is_ac_wake_requested(void)
-{
- return db8500_prcmu_is_ac_wake_requested();
-}
-
-static inline int prcmu_config_esram0_deep_sleep(u8 state)
-{
- return db8500_prcmu_config_esram0_deep_sleep(state);
-}
-
-static inline int prcmu_config_hotdog(u8 threshold)
-{
- return db8500_prcmu_config_hotdog(threshold);
-}
-
-static inline int prcmu_config_hotmon(u8 low, u8 high)
-{
- return db8500_prcmu_config_hotmon(low, high);
-}
-
-static inline int prcmu_start_temp_sense(u16 cycles32k)
-{
- return db8500_prcmu_start_temp_sense(cycles32k);
-}
-
-static inline int prcmu_stop_temp_sense(void)
-{
- return db8500_prcmu_stop_temp_sense();
-}
-
-static inline u32 prcmu_read(unsigned int reg)
-{
- return db8500_prcmu_read(reg);
-}
-
-static inline void prcmu_write(unsigned int reg, u32 value)
-{
- db8500_prcmu_write(reg, value);
-}
-
-static inline void prcmu_write_masked(unsigned int reg, u32 mask, u32 value)
-{
- db8500_prcmu_write_masked(reg, mask, value);
-}
-
-static inline int prcmu_enable_a9wdog(u8 id)
-{
- return db8500_prcmu_enable_a9wdog(id);
-}
-
-static inline int prcmu_disable_a9wdog(u8 id)
-{
- return db8500_prcmu_disable_a9wdog(id);
-}
-
-static inline int prcmu_kick_a9wdog(u8 id)
-{
- return db8500_prcmu_kick_a9wdog(id);
-}
-
-static inline int prcmu_load_a9wdog(u8 id, u32 timeout)
-{
- return db8500_prcmu_load_a9wdog(id, timeout);
-}
-
-static inline int prcmu_config_a9wdog(u8 num, bool sleep_auto_off)
-{
- return db8500_prcmu_config_a9wdog(num, sleep_auto_off);
-}
-#else
-
-static inline void prcmu_early_init(void) {}
-
-static inline int prcmu_set_power_state(u8 state, bool keep_ulp_clk,
- bool keep_ap_pll)
-{
- return 0;
-}
-
-static inline int prcmu_set_epod(u16 epod_id, u8 epod_state)
-{
- return 0;
-}
-
-static inline void prcmu_enable_wakeups(u32 wakeups) {}
-
-static inline void prcmu_disable_wakeups(void) {}
-
-static inline int prcmu_abb_read(u8 slave, u8 reg, u8 *value, u8 size)
-{
- return -ENOSYS;
-}
-
-static inline int prcmu_abb_write(u8 slave, u8 reg, u8 *value, u8 size)
-{
- return -ENOSYS;
-}
-
-static inline int prcmu_abb_write_masked(u8 slave, u8 reg, u8 *value, u8 *mask,
- u8 size)
-{
- return -ENOSYS;
-}
-
-static inline int prcmu_config_clkout(u8 clkout, u8 source, u8 div)
-{
- return 0;
-}
-
-static inline int prcmu_request_clock(u8 clock, bool enable)
-{
- return 0;
-}
-
-static inline long prcmu_round_clock_rate(u8 clock, unsigned long rate)
-{
- return 0;
-}
-
-static inline int prcmu_set_clock_rate(u8 clock, unsigned long rate)
-{
- return 0;
-}
-
-static inline unsigned long prcmu_clock_rate(u8 clock)
-{
- return 0;
-}
-
-static inline int prcmu_set_ape_opp(u8 opp)
-{
- return 0;
-}
-
-static inline int prcmu_get_ape_opp(void)
-{
- return APE_100_OPP;
-}
-
-static inline int prcmu_request_ape_opp_100_voltage(bool enable)
-{
- return 0;
-}
-
-static inline int prcmu_set_arm_opp(u8 opp)
-{
- return 0;
-}
-
-static inline int prcmu_get_arm_opp(void)
-{
- return ARM_100_OPP;
-}
-
-static inline int prcmu_get_ddr_opp(void)
-{
- return DDR_100_OPP;
-}
-
-static inline void prcmu_system_reset(u16 reset_code) {}
-
-static inline u16 prcmu_get_reset_code(void)
-{
- return 0;
-}
-
-static inline int prcmu_ac_wake_req(void)
-{
- return 0;
-}
-
-static inline void prcmu_ac_sleep_req(void) {}
-
-static inline void prcmu_modem_reset(void) {}
-
-static inline bool prcmu_is_ac_wake_requested(void)
-{
- return false;
-}
-
-static inline int prcmu_config_esram0_deep_sleep(u8 state)
-{
- return 0;
-}
-
-static inline void prcmu_config_abb_event_readout(u32 abb_events) {}
-
-static inline void prcmu_get_abb_event_buffer(void __iomem **buf)
-{
- *buf = NULL;
-}
-
-static inline int prcmu_config_hotdog(u8 threshold)
-{
- return 0;
-}
-
-static inline int prcmu_config_hotmon(u8 low, u8 high)
-{
- return 0;
-}
-
-static inline int prcmu_start_temp_sense(u16 cycles32k)
-{
- return 0;
-}
-
-static inline int prcmu_stop_temp_sense(void)
-{
- return 0;
-}
-
-static inline u32 prcmu_read(unsigned int reg)
-{
- return 0;
-}
-
-static inline void prcmu_write(unsigned int reg, u32 value) {}
-
-static inline void prcmu_write_masked(unsigned int reg, u32 mask, u32 value) {}
-
-#endif
-
-static inline void prcmu_set(unsigned int reg, u32 bits)
-{
- prcmu_write_masked(reg, bits, bits);
-}
-
-static inline void prcmu_clear(unsigned int reg, u32 bits)
-{
- prcmu_write_masked(reg, bits, 0);
-}
-
-/* PRCMU QoS APE OPP class */
-#define PRCMU_QOS_APE_OPP 1
-#define PRCMU_QOS_DDR_OPP 2
-#define PRCMU_QOS_ARM_OPP 3
-#define PRCMU_QOS_DEFAULT_VALUE -1
-
-static inline int prcmu_qos_add_requirement(int prcmu_qos_class,
- char *name, s32 value)
-{
- return 0;
-}
-
-static inline int prcmu_qos_update_requirement(int prcmu_qos_class,
- char *name, s32 new_value)
-{
- return 0;
-}
-
-static inline void prcmu_qos_remove_requirement(int prcmu_qos_class, char *name)
-{
-}
-
-#endif /* __MACH_PRCMU_H */
diff --git a/sound/soc/ux500/ux500_msp_dai.c b/sound/soc/ux500/ux500_msp_dai.c
index ad26185c54943..2032a5a849157 100644
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -14,7 +14,7 @@
#include <linux/clk.h>
#include <linux/of.h>
#include <linux/regulator/consumer.h>
-#include <linux/mfd/dbx500-prcmu.h>
+#include <linux/mfd/db8500-prcmu.h>
#include <sound/soc.h>
#include <sound/soc-dai.h>
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 381/982] ASoC: ux500: remove stedma40 references
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (379 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 380/982] mfd: db8500-prcmu: Fold dbx500 header into db8500 Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 382/982] ASoC: ux500: Request the MSP MMIO resource Greg Kroah-Hartman
` (607 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Linus Walleij,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
[ Upstream commit aafe9375b386010e28614f58499d199250a16874 ]
ux500_pcm_request_chan() is never called because the dma channels
are already set up from DT. Remove this, along with the
ux500_msp_dma_params structure.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Reviewed-by: Linus Walleij <linus.walleij@linaro.org>
Link: https://lore.kernel.org/r/20230118161110.521504-4-arnd@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 4fb67925f33a ("ASoC: ux500: Request the MSP MMIO resource")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_dai.c | 4 +--
sound/soc/ux500/ux500_msp_i2s.c | 41 --------------------------------------
sound/soc/ux500/ux500_msp_i2s.h | 9 --------
sound/soc/ux500/ux500_pcm.c | 43 ----------------------------------------
4 files changed, 5 insertions(+), 92 deletions(-)
--- a/sound/soc/ux500/ux500_msp_dai.c
+++ b/sound/soc/ux500/ux500_msp_dai.c
@@ -640,8 +640,8 @@ static int ux500_msp_dai_of_probe(struct
if (!capture_dma_data)
return -ENOMEM;
- playback_dma_data->addr = drvdata->msp->playback_dma_data.tx_rx_addr;
- capture_dma_data->addr = drvdata->msp->capture_dma_data.tx_rx_addr;
+ playback_dma_data->addr = drvdata->msp->tx_rx_addr;
+ capture_dma_data->addr = drvdata->msp->tx_rx_addr;
playback_dma_data->maxburst = 4;
capture_dma_data->maxburst = 4;
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -377,20 +377,6 @@ static int enable_msp(struct ux500_msp *
return status;
}
- /* Make sure the correct DMA-directions are configured */
- if ((config->direction & MSP_DIR_RX) &&
- !msp->capture_dma_data.dma_cfg) {
- dev_err(msp->dev, "%s: ERROR: MSP RX-mode is not configured!",
- __func__);
- return -EINVAL;
- }
- if ((config->direction == MSP_DIR_TX) &&
- !msp->playback_dma_data.dma_cfg) {
- dev_err(msp->dev, "%s: ERROR: MSP TX-mode is not configured!",
- __func__);
- return -EINVAL;
- }
-
reg_val_DMACR = readl(msp->registers + MSP_DMACR);
if (config->direction & MSP_DIR_RX)
reg_val_DMACR |= RX_DMA_ENABLE;
@@ -744,40 +730,17 @@ int ux500_msp_i2s_close(struct ux500_msp
}
-static int ux500_msp_i2s_of_init_msp(struct platform_device *pdev,
- struct ux500_msp *msp);
-{
- msp->playback_dma_data.dma_cfg = devm_kzalloc(&pdev->dev,
- sizeof(struct stedma40_chan_cfg),
- GFP_KERNEL);
- if (!msp->playback_dma_data.dma_cfg)
- return -ENOMEM;
-
- msp->capture_dma_data.dma_cfg = devm_kzalloc(&pdev->dev,
- sizeof(struct stedma40_chan_cfg),
- GFP_KERNEL);
- if (!msp->capture_dma_data.dma_cfg)
- return -ENOMEM;
-
- return 0;
-}
-
int ux500_msp_i2s_init_msp(struct platform_device *pdev,
struct ux500_msp **msp_p)
{
struct resource *res = NULL;
struct ux500_msp *msp;
- int ret;
*msp_p = devm_kzalloc(&pdev->dev, sizeof(struct ux500_msp), GFP_KERNEL);
msp = *msp_p;
if (!msp)
return -ENOMEM;
- ret = ux500_msp_i2s_of_init_msp(pdev, msp);
- if (ret)
- return ret;
-
msp->dev = &pdev->dev;
res = platform_get_resource(pdev, IORESOURCE_MEM, 0);
@@ -787,9 +750,7 @@ int ux500_msp_i2s_init_msp(struct platfo
return -ENOMEM;
}
- msp->playback_dma_data.tx_rx_addr = res->start + MSP_DR;
- msp->capture_dma_data.tx_rx_addr = res->start + MSP_DR;
-
+ msp->tx_rx_addr = res->start + MSP_DR;
msp->registers = devm_ioremap(&pdev->dev, res->start,
resource_size(res));
if (msp->registers == NULL) {
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -462,18 +462,11 @@ struct ux500_msp_config {
bool bclk_inverted;
};
-struct ux500_msp_dma_params {
- unsigned int data_size;
- dma_addr_t tx_rx_addr;
- struct stedma40_chan_cfg *dma_cfg;
-};
-
struct ux500_msp {
int id;
void __iomem *registers;
struct device *dev;
- struct ux500_msp_dma_params playback_dma_data;
- struct ux500_msp_dma_params capture_dma_data;
+ dma_addr_t tx_rx_addr;
enum msp_state msp_state;
int def_elem_len;
unsigned int dir_busy;
--- a/sound/soc/ux500/ux500_pcm.c
+++ b/sound/soc/ux500/ux500_pcm.c
@@ -13,7 +13,6 @@
#include <linux/dma-mapping.h>
#include <linux/dmaengine.h>
#include <linux/slab.h>
-#include <linux/platform_data/dma-ste-dma40.h>
#include <sound/pcm.h>
#include <sound/pcm_params.h>
@@ -29,44 +28,6 @@
#define UX500_PLATFORM_PERIODS_MAX 48
#define UX500_PLATFORM_BUFFER_BYTES_MAX (2048 * PAGE_SIZE)
-static struct dma_chan *ux500_pcm_request_chan(struct snd_soc_pcm_runtime *rtd,
- struct snd_pcm_substream *substream)
-{
- struct snd_soc_dai *dai = asoc_rtd_to_cpu(rtd, 0);
- u16 per_data_width, mem_data_width;
- struct stedma40_chan_cfg *dma_cfg;
- struct ux500_msp_dma_params *dma_params;
-
- dma_params = snd_soc_dai_get_dma_data(dai, substream);
- dma_cfg = dma_params->dma_cfg;
-
- mem_data_width = DMA_SLAVE_BUSWIDTH_2_BYTES;
-
- switch (dma_params->data_size) {
- case 32:
- per_data_width = DMA_SLAVE_BUSWIDTH_4_BYTES;
- break;
- case 16:
- per_data_width = DMA_SLAVE_BUSWIDTH_2_BYTES;
- break;
- case 8:
- per_data_width = DMA_SLAVE_BUSWIDTH_1_BYTE;
- break;
- default:
- per_data_width = DMA_SLAVE_BUSWIDTH_4_BYTES;
- }
-
- if (substream->stream == SNDRV_PCM_STREAM_PLAYBACK) {
- dma_cfg->src_info.data_width = mem_data_width;
- dma_cfg->dst_info.data_width = per_data_width;
- } else {
- dma_cfg->src_info.data_width = per_data_width;
- dma_cfg->dst_info.data_width = mem_data_width;
- }
-
- return snd_dmaengine_pcm_request_channel(stedma40_filter, dma_cfg);
-}
-
static int ux500_pcm_prepare_slave_config(struct snd_pcm_substream *substream,
struct snd_pcm_hw_params *params,
struct dma_slave_config *slave_config)
@@ -98,7 +59,6 @@ static int ux500_pcm_prepare_slave_confi
}
static const struct snd_dmaengine_pcm_config ux500_dmaengine_of_pcm_config = {
- .compat_request_channel = ux500_pcm_request_chan,
.prepare_slave_config = ux500_pcm_prepare_slave_config,
};
@@ -107,8 +67,7 @@ int ux500_pcm_register_platform(struct p
int ret;
ret = snd_dmaengine_pcm_register(&pdev->dev,
- &ux500_dmaengine_of_pcm_config,
- SND_DMAENGINE_PCM_FLAG_COMPAT);
+ &ux500_dmaengine_of_pcm_config, 0);
if (ret < 0) {
dev_err(&pdev->dev,
"%s: ERROR: Failed to register platform '%s' (%d)!\n",
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 382/982] ASoC: ux500: Request the MSP MMIO resource
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (380 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 381/982] ASoC: ux500: remove stedma40 references Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 383/982] ASoC: ux500: Program the MSP FIFO watermarks Greg Kroah-Hartman
` (606 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 4fb67925f33ad789e9e00903a73306ed40f7ae32 ]
A bare devm_ioremap() neither reserves the register range nor preserves
the platform resource error. This permits another driver to claim the
same range and reports every mapping failure as an allocation failure.
Use the managed platform resource helper, retaining the resolved
resource only to derive the DMA register address.
Fixes: 3592b7f69a54 ("ASoC: Ux500: Add MSP I2S-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260902-ux500-msp-fixes-v2-6-4b60b002d55a@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_i2s.c | 18 ++++--------------
1 file changed, 4 insertions(+), 14 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_i2s.c b/sound/soc/ux500/ux500_msp_i2s.c
index bc77174e00707..43dc9b3aa4ef5 100644
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -733,7 +733,7 @@ int ux500_msp_i2s_close(struct ux500_msp *msp, unsigned int dir)
int ux500_msp_i2s_init_msp(struct platform_device *pdev,
struct ux500_msp **msp_p)
{
- struct resource *res = NULL;
+ struct resource *res;
struct ux500_msp *msp;
*msp_p = devm_kzalloc(&pdev->dev, sizeof(struct ux500_msp), GFP_KERNEL);
@@ -743,20 +743,10 @@ int ux500_msp_i2s_init_msp(struct platform_device *pdev,
msp->dev = &pdev->dev;
- res = platform_get_resource(pdev, IORESOURCE_MEM, 0);
- if (res == NULL) {
- dev_err(&pdev->dev, "%s: ERROR: Unable to get resource!\n",
- __func__);
- return -ENOMEM;
- }
-
+ msp->registers = devm_platform_get_and_ioremap_resource(pdev, 0, &res);
+ if (IS_ERR(msp->registers))
+ return PTR_ERR(msp->registers);
msp->tx_rx_addr = res->start + MSP_DR;
- msp->registers = devm_ioremap(&pdev->dev, res->start,
- resource_size(res));
- if (msp->registers == NULL) {
- dev_err(&pdev->dev, "%s: ERROR: ioremap failed!\n", __func__);
- return -ENOMEM;
- }
msp->msp_state = MSP_STATE_IDLE;
msp->loopback_enable = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 383/982] ASoC: ux500: Program the MSP FIFO watermarks
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (381 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 382/982] ASoC: ux500: Request the MSP MMIO resource Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 384/982] btrfs: do not force reloc root creation during qgroup_account_snapshot() Greg Kroah-Hartman
` (605 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 2519439b4b5f6ee95879b1a44fc373127291b1e4 ]
The DMA engine is configured for four-element bursts, but the MSP
driver never programs the FIFO watermark register and instead depends
on its previous or reset value. The DB8500 DMA request protocol requires
the peripheral watermark to match the DMA packet size.
Program four-element receive and transmit watermarks when configuring
the first direction, before enabling MSP DMA requests.
Fixes: 3592b7f69a54 ("ASoC: Ux500: Add MSP I2S-driver")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260902-ux500-msp-fixes-v2-9-4b60b002d55a@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_i2s.c | 2 ++
sound/soc/ux500/ux500_msp_i2s.h | 5 +++++
2 files changed, 7 insertions(+)
diff --git a/sound/soc/ux500/ux500_msp_i2s.c b/sound/soc/ux500/ux500_msp_i2s.c
index 43dc9b3aa4ef5..683b485fb5708 100644
--- a/sound/soc/ux500/ux500_msp_i2s.c
+++ b/sound/soc/ux500/ux500_msp_i2s.c
@@ -507,6 +507,8 @@ int ux500_msp_i2s_open(struct ux500_msp *msp,
old_reg &= ~mask;
new_reg |= old_reg;
writel(new_reg, msp->registers + MSP_GCR);
+ writel(MSP_WMRK_TX_4_ELEMENTS | MSP_WMRK_RX_4_ELEMENTS,
+ msp->registers + MSP_WMRK);
}
res = enable_msp(msp, config, first);
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 17b5c37a7e5d5..2bf2699bdc49f 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -62,6 +62,7 @@ enum msp_direction {
#define MSP_SRG 0x10
#define MSP_FLR 0x14
#define MSP_DMACR 0x18
+#define MSP_WMRK 0x1c
#define MSP_IMSC 0x20
#define MSP_RIS 0x24
@@ -228,6 +229,10 @@ enum msp_direction {
#define RDMAE_SHIFT 0
#define TDMAE_SHIFT 1
+/* FIFO watermark register */
+#define MSP_WMRK_RX_4_ELEMENTS BIT(0)
+#define MSP_WMRK_TX_4_ELEMENTS BIT(3)
+
/* Interrupt Register */
#define RX_SERVICE_INT BIT(0)
#define RX_OVERRUN_ERROR_INT BIT(1)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 384/982] btrfs: do not force reloc root creation during qgroup_account_snapshot()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (382 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 383/982] ASoC: ux500: Program the MSP FIFO watermarks Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 385/982] ipvs: fix reversed sequence option serialization Greg Kroah-Hartman
` (604 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Disha Goel, Filipe Manana, Qu Wenruo,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qu Wenruo <wqu@suse.com>
[ Upstream commit cacf35832292997018837e484283f95a9301ebf5 ]
[BUG]
When running btrfs/252 with quota enabled through MKFS_OPTIONS="-O quota",
it has a high chance to trigger the following kernel warning and flips
the fs RO:
BTRFS info (device dm-2): relocating block group 30408704 flags metadata|dup
------------[ cut here ]------------
WARNING: fs/btrfs/extent-tree.c:879 at lookup_inline_extent_backref+0x74b/0x960 [btrfs], CPU#4: btrfs/2173
CPU: 4 UID: 0 PID: 2173 Comm: btrfs Not tainted 7.2.0-rc6-custom+ #457 PREEMPT(full) 3adc6528fb66f7a55fe1095385818e742f200aab
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022
RIP: 0010:lookup_inline_extent_backref+0x74b/0x960 [btrfs]
Call Trace:
<TASK>
insert_inline_extent_backref+0x7c/0x160 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
__btrfs_inc_extent_ref+0xa9/0x270 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
__btrfs_run_delayed_refs+0x4af/0x11c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
btrfs_run_delayed_refs+0x9d/0xf0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
create_pending_snapshot+0x39d/0xf00 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
create_pending_snapshots+0x9b/0xc0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
btrfs_commit_transaction+0x280/0xeb0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
prepare_to_relocate+0x147/0x200 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
relocate_block_group+0x6b/0x5e0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
btrfs_relocate_block_group+0x92c/0x2380 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
btrfs_relocate_chunk+0x3f/0x1a0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
btrfs_balance+0xa2c/0x19c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
btrfs_ioctl+0x2839/0x2d30 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
__x64_sys_ioctl+0x416/0x9a0
do_syscall_64+0xe1/0x790
entry_SYSCALL_64_after_hwframe+0x4b/0x53
</TASK>
---[ end trace 0000000000000000 ]---
BTRFS info (device dm-2): leaf 4593991680 gen 233 total ptrs 175 free space 5953 owner 2
BTRFS info (device dm-2): refs 3 lock_owner 2173 current 2173
item 0 key (166772736 METADATA_ITEM 1) itemoff 16250 itemsize 33
extent refs 1 gen 222 flags 2
ref#0: tree block backref root 266
[ Skip the tree dump ]
item 174 key (263225344 METADATA_ITEM 0) itemoff 10328 itemsize 33
extent refs 1 gen 162 flags 258
ref#0: tree block backref root 267
BTRFS error (device dm-2): extent item not found for insert, bytenr 179847168 num_bytes 16384 parent 4594335744 root_objectid 273 owner 0 offset 0
BTRFS error (device dm-2): failed to run delayed ref for logical 179847168 num_bytes 16384 type 182 action 1 ref_mod 1: -117
[CAUSE]
The above error is showing that there is a tree reference to a metadata
extent that is no longer there.
With "ref_verify" mount option (requires CONFIG_BTRFS_DEBUG), there is
some extra debug output:
BTRFS error (device dm-2): dumping block entry [180961280 16384], num_refs 0, metadata 1, from disk 0
BTRFS error (device dm-2): root entry 256, num_refs 18446744073709551615
BTRFS error (device dm-2): root entry 273, num_refs 18446744073709551615
BTRFS error (device dm-2): Ref action 3, root 273, ref_root 273, parent 0, owner 0, offset 0, num_refs 1
btrfs_force_cow_block+0x129/0x7d0 [btrfs]
btrfs_cow_block+0x10a/0x250 [btrfs]
btrfs_search_slot+0x5eb/0xf40 [btrfs]
btrfs_insert_empty_items+0x3a/0x70 [btrfs]
insert_with_overflow+0x53/0x130 [btrfs]
btrfs_insert_dir_item+0x125/0x290 [btrfs]
btrfs_add_link+0xaa/0x410 [btrfs]
btrfs_rename+0x5ea/0xcd0 [btrfs]
btrfs_rename2+0x28/0x60 [btrfs]
vfs_rename+0x5b2/0xe10
filename_renameat2+0x244/0x430
__x64_sys_rename+0x48/0x70
do_syscall_64+0xe1/0x790
entry_SYSCALL_64_after_hwframe+0x4b/0x53
BTRFS error (device dm-2): Ref action 2, root 273, ref_root 273, parent 0, owner 0, offset 0, num_refs 18446744073709551615
btrfs_force_cow_block+0x327/0x7d0 [btrfs]
btrfs_cow_block+0x10a/0x250 [btrfs]
btrfs_search_slot+0x5eb/0xf40 [btrfs]
btrfs_lookup_file_extent+0x4d/0x70 [btrfs]
btrfs_drop_extents+0x151/0xf00 [btrfs]
insert_reserved_file_extent+0xfe/0x3e0 [btrfs]
btrfs_finish_one_ordered+0x549/0xc40 [btrfs]
btrfs_work_helper+0xde/0x350 [btrfs]
process_one_work+0x198/0x380
worker_thread+0x1c8/0x330
kthread+0xee/0x120
ret_from_fork+0x28f/0x310
ret_from_fork_asm+0x11/0x20
BTRFS error (device dm-2): Ref action 1, root 273, ref_root 0, parent 4594335744, owner 0, offset 0, num_refs 1
__btrfs_mod_ref+0x1c5/0x2d0 [btrfs]
btrfs_copy_root+0x262/0x390 [btrfs]
create_reloc_root+0xb9/0x370 [btrfs]
btrfs_init_reloc_root+0xb0/0x1b0 [btrfs]
record_root_in_trans+0xa6/0xd0 [btrfs]
create_pending_snapshot+0x383/0xf00 [btrfs]
create_pending_snapshots+0x9b/0xc0 [btrfs]
btrfs_commit_transaction+0x280/0xeb0 [btrfs]
prepare_to_relocate+0x147/0x200 [btrfs]
relocate_block_group+0x6b/0x5e0 [btrfs]
btrfs_relocate_block_group+0x92c/0x2380 [btrfs]
btrfs_relocate_chunk+0x3f/0x1a0 [btrfs]
btrfs_balance+0xa2c/0x19c0 [btrfs]
btrfs_ioctl+0x2839/0x2d30 [btrfs]
__x64_sys_ioctl+0x416/0x9a0
do_syscall_64+0xe1/0x790
The above shows the direct cause, Ref action 3 is the oldest operation,
which shows the tree block is created by COW. Then ref action 2 shows
it's COWed away, by a metadata update, meaning the tree block is already
released, should not be referred any more.
Then the final one, is trying to create a reloc tree for subvolume 273,
and that reloc root creation is referring to the already dropped tree
block.
The root cause is that, during qgroup_account_snapshot(), we are calling
record_root_in_trans() with "force = true".
So if the root has no reloc root, we will create one, but at that
timing it's already too late.
Normally reloc root should be created before the commit and current
roots diverge, to avoid the same problem we are hitting.
But during relocation initialization, we are committing the current
running transaction, with a new reloc_control attached halfway.
And if qgroup is enabled, the record_root_in_trans() with "force = true"
calls will force reloc root creation even if we do not and should not
create reloc root at that timing.
[FIX]
Do not force reloc root creation during record_root_in_trans() with
"force = true" cases, which is only called by qgroup_account_snapshot().
If we're really under relocation, the reloc root should be created way
early, before the commit and current root diverge. If the root has no
reloc tree yet, it means we're still initializing the reloc, and do not
need a reloc root.
So skipping the reloc tree creation in qgroup_account_snapshot() should
be safe.
Link: https://bugzilla.suse.com/show_bug.cgi?id=1275740
Fixes: 4d31778aa2fa ("btrfs: qgroup: Fix root item corruption when multiple same source snapshots are created with quota enabled")
Assisted-by: LLM (initial analysis, but incorrect conclusion with too many burnt tokens)
Tested-by: Disha Goel <disgoel@linux.ibm.com>
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/transaction.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/transaction.c b/fs/btrfs/transaction.c
index 336a1799eeddd..af7b5aae842a8 100644
--- a/fs/btrfs/transaction.c
+++ b/fs/btrfs/transaction.c
@@ -439,8 +439,19 @@ static int record_root_in_trans(struct btrfs_trans_handle *trans,
* through btrfs_record_root_in_trans without having to take the
* lock. smp_wmb() makes sure that all the writes above are
* done before we pop in the zero below
+ *
+ * If @force is true, it means the call is from
+ * qgroup_account_snapshot(), which only requires radix tree
+ * tracking.
+ * We should not force reloc root creation here, as the root
+ * may have already been modified, and in that case
+ * root->commit_root has already been dropped.
+ *
+ * Using that commit root will cause the reloc root to refer
+ * to a deleted extent, causing extent tree corruption.
*/
- ret = btrfs_init_reloc_root(trans, root);
+ if (!force)
+ ret = btrfs_init_reloc_root(trans, root);
smp_mb__before_atomic();
clear_bit(BTRFS_ROOT_IN_TRANS_SETUP, &root->state);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 385/982] ipvs: fix reversed sequence option serialization
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (383 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 384/982] btrfs: do not force reloc root creation during qgroup_account_snapshot() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 386/982] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() Greg Kroah-Hartman
` (603 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, Julian Anastasov,
Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
[ Upstream commit b04578b74f2d3755548fe9e829e3b2a6c6f966a1 ]
hton_seq() expects the host-order source first and the unaligned
network-order destination second. The version 1 sync sender passes these
arguments in reverse for both sequence blocks. This leaves 24 bytes of the
kmalloc-backed message unwritten. It may disclose stale heap data and
replace the live connection sequence state with values read from the
buffer.
Pass the connection sequence state as the source and the message payload as
the destination for both blocks.
Fixes: 986a07579533 ("IPVS: Backup, Change sending to Version 1 format")
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Acked-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/ipvs/ip_vs_sync.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
index bade3fa936f13..f8bd07d8f0397 100644
--- a/net/netfilter/ipvs/ip_vs_sync.c
+++ b/net/netfilter/ipvs/ip_vs_sync.c
@@ -748,9 +748,9 @@ void ip_vs_sync_conn(struct netns_ipvs *ipvs, struct ip_vs_conn *cp, int pkts)
if (cp->flags & IP_VS_CONN_F_SEQ_MASK) {
*(p++) = IPVS_OPT_SEQ_DATA;
*(p++) = sizeof(struct ip_vs_sync_conn_options);
- hton_seq((struct ip_vs_seq *)p, &cp->in_seq);
+ hton_seq(&cp->in_seq, (struct ip_vs_seq *)p);
p += sizeof(struct ip_vs_seq);
- hton_seq((struct ip_vs_seq *)p, &cp->out_seq);
+ hton_seq(&cp->out_seq, (struct ip_vs_seq *)p);
p += sizeof(struct ip_vs_seq);
}
/* Handle pe data */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 386/982] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (384 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 385/982] ipvs: fix reversed sequence option serialization Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 387/982] tracing/probes: Fix use-after-free on field name/type of events with multiple probes Greg Kroah-Hartman
` (602 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joas Antonio dos Santos,
Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joas Antonio dos Santos <joasantonio108@gmail.com>
[ Upstream commit e8f8231824b5815f57ce62cba116e511b10196de ]
sip_skip_whitespace() returns dptr unchanged when its own loop
exhausts the buffer (dptr == limit), instead of NULL like its sibling
sip_follow_continuation() returns on its own "no more data" path.
ct_sip_get_header() only checks for NULL after calling it:
dptr = sip_skip_whitespace(dptr, limit);
if (dptr == NULL)
break;
if (*dptr != ':' || ++dptr >= limit)
break;
so a recognized header name followed only by spaces/tabs running to
the exact end of the SIP payload, with no colon, makes the very next
statement read one byte past the buffer.
Make both "no more data" outcomes return NULL, matching the
convention sip_follow_continuation() already uses and that both
existing callers already check for.
Fixes: ea45f12a2766d ("[NETFILTER]: nf_conntrack_sip: parse SIP headers properly")
Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_conntrack_sip.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nf_conntrack_sip.c b/net/netfilter/nf_conntrack_sip.c
index 4f975b83c84f6..2b5f807436e2c 100644
--- a/net/netfilter/nf_conntrack_sip.c
+++ b/net/netfilter/nf_conntrack_sip.c
@@ -429,7 +429,7 @@ static const char *sip_skip_whitespace(const char *dptr, const char *limit)
dptr = sip_follow_continuation(dptr, limit);
break;
}
- return dptr;
+ return dptr < limit ? dptr : NULL;
}
/* Search within a SIP header value, dealing with continuation lines */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 387/982] tracing/probes: Fix use-after-free on field name/type of events with multiple probes
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (385 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 386/982] netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 388/982] bpf: reject BPF_PSEUDO_FUNC reference to the main program Greg Kroah-Hartman
` (601 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Henry Martin,
Masami Hiramatsu (Google), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Henry Martin <bsdhenrymartin@gmail.com>
[ Upstream commit 86b7a239ec6b14a7544200ede85474c6f5526049 ]
The fields of a probe-based dynamic event (kprobe, uprobe, eprobe and
fprobe events) are created in traceprobe_define_arg_fields() by handing
the probe_arg name/type strings to trace_define_field(), which only
stores the pointers without copying. Those strings are owned by the
trace_probe and are freed when that probe is removed.
An event can have several probes attached. The field list is defined
only once, by the first probe that registers the event, but it is kept
alive by any surviving sibling probe. Deleting just that first probe by
symbol -
# primary A: fields are defined from A's args
echo 'p:kprobes/ev vfs_read a1=$arg1' > kprobe_events
# append B: shares A's event call
echo 'p:kprobes/ev vfs_write a1=$arg1' >> kprobe_events
# delete only A (matched by symbol), B survives
echo '-:kprobes/ev vfs_read' >> kprobe_events
frees A's args (trace_probe_cleanup() -> traceprobe_free_probe_arg()),
but trace_probe_unlink() keeps the trace_probe_event because the probe
list is not empty. The event call stays registered via B while its
fields now reference freed memory. Any field lookup then reads it, e.g.
echo 'a1 == 1' > events/kprobes/ev/filter
BUG: KASAN: slab-use-after-free in strcmp+0xa7/0xb0
Call Trace:
strcmp
trace_find_event_field
parse_pred
process_preds
create_filter
apply_event_filter
event_filter_write
field->name references parg->name (kstrdup'd, freed with the probe) and,
for array arguments, field->type references parg->fmt (kmalloc'd, freed
with the probe) - the scalar type otherwise points at the static
fmttype rodata, which is safe.
Have traceprobe_define_arg_fields() duplicate the name and type strings
and anchor the copies on the trace_probe_event, which embeds the event
call and outlives every individual probe; trace_probe_event_free()
releases them.
The reproducer above triggers reliably; the field lookup and the delete
both run under event_mutex, so this is a dangling reference after
removal rather than a race.
The issue was found by the autokbug dynamic kernel fuzzer at Tencent
Yunding Lab.
Link: https://lore.kernel.org/all/20260826030009.1855331-1-bsdhenrymartin@gmail.com/
Fixes: ca89bc071d5e4 ("tracing/kprobe: Add multi-probe per event support")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/trace_probe.c | 48 +++++++++++++++++++++++++++++++++++++-
kernel/trace/trace_probe.h | 2 ++
2 files changed, 49 insertions(+), 1 deletion(-)
diff --git a/kernel/trace/trace_probe.c b/kernel/trace/trace_probe.c
index 758705ffc6a15..f5df2a2d3681d 100644
--- a/kernel/trace/trace_probe.c
+++ b/kernel/trace/trace_probe.c
@@ -993,19 +993,60 @@ int traceprobe_set_print_fmt(struct trace_probe *tp, enum probe_print_type ptype
int traceprobe_define_arg_fields(struct trace_event_call *event_call,
size_t offset, struct trace_probe *tp)
{
+ struct trace_probe_event *tpe = trace_probe_event_from_call(event_call);
int ret, i;
+ /*
+ * A field created by trace_define_field() only stores the name and
+ * type pointers, it does not copy the strings. Here they point into
+ * the probe_arg of @tp, which is freed when @tp is removed. For an
+ * event with multiple probes attached, the field list is defined
+ * once by the first probe but kept alive by the surviving siblings,
+ * so removing that first probe would leave the fields referencing
+ * freed memory. Duplicate the strings and anchor the copies on the
+ * trace_probe_event, which lives as long as the field list itself.
+ *
+ * event_define_fields() ignores the return value of this hook, so
+ * if a previous attempt failed before creating any field, it may
+ * call here again. Release duplicates left behind by such an
+ * attempt before starting over.
+ */
+ for (i = 0; i < tpe->nr_field_strings; i++)
+ kfree(tpe->field_strings[i]);
+ kfree(tpe->field_strings);
+ tpe->field_strings = NULL;
+ tpe->nr_field_strings = 0;
+
+ if (tp->nr_args) {
+ tpe->field_strings = kcalloc(tp->nr_args * 2, sizeof(char *),
+ GFP_KERNEL);
+ if (!tpe->field_strings)
+ return -ENOMEM;
+ }
+
/* Set argument names as fields */
for (i = 0; i < tp->nr_args; i++) {
struct probe_arg *parg = &tp->args[i];
const char *fmt = parg->type->fmttype;
int size = parg->type->size;
+ char *name, *type;
if (parg->fmt)
fmt = parg->fmt;
if (parg->count)
size *= parg->count;
- ret = trace_define_field(event_call, fmt, parg->name,
+
+ name = kstrdup(parg->name, GFP_KERNEL);
+ type = kstrdup(fmt, GFP_KERNEL);
+ if (!name || !type) {
+ kfree(name);
+ kfree(type);
+ return -ENOMEM;
+ }
+ tpe->field_strings[tpe->nr_field_strings++] = name;
+ tpe->field_strings[tpe->nr_field_strings++] = type;
+
+ ret = trace_define_field(event_call, type, name,
offset + parg->offset, size,
parg->type->is_signed,
FILTER_OTHER);
@@ -1017,6 +1058,11 @@ int traceprobe_define_arg_fields(struct trace_event_call *event_call,
static void trace_probe_event_free(struct trace_probe_event *tpe)
{
+ int i;
+
+ for (i = 0; i < tpe->nr_field_strings; i++)
+ kfree(tpe->field_strings[i]);
+ kfree(tpe->field_strings);
kfree(tpe->class.system);
kfree(tpe->call.name);
kfree(tpe->call.print_fmt);
diff --git a/kernel/trace/trace_probe.h b/kernel/trace/trace_probe.h
index aef19096b4dd0..8cf45bbf1ae00 100644
--- a/kernel/trace/trace_probe.h
+++ b/kernel/trace/trace_probe.h
@@ -242,6 +242,8 @@ struct trace_probe_event {
struct trace_event_call call;
struct list_head files;
struct list_head probes;
+ char **field_strings;
+ int nr_field_strings;
struct trace_uprobe_filter filter[];
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 388/982] bpf: reject BPF_PSEUDO_FUNC reference to the main program
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (386 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 387/982] tracing/probes: Fix use-after-free on field name/type of events with multiple probes Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 389/982] bonding: do not clear curr_active_slave prematurely when releasing all slaves Greg Kroah-Hartman
` (600 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini, Eduard Zingerman,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eduard Zingerman <eddyz87@gmail.com>
[ Upstream commit 374b2c5561db80fcdd7cdce44af37a49416f61c7 ]
fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real
function addresses. This function is invoked from bpf_jit_subprogs()
only when env->subprog_cnt > 1. Meaning that for any program like
below:
int main(void *ctx) {
void *ptr = main;
...
bpf_timer_set_callback(..., ptr);
...
}
The 'ptr' won't be ever converted to contain an address.
In combination with e.g. bpf_timer_set_callback() this would lead to a
function call at a bogus address.
Instead of complicating the implementation, just assume that no useful
program needs main to be a sync or async callback and reject
BPF_PSEUDO_FUNC loads for the main subprogram.
Fixes: 69c087ba6225 ("bpf: Add bpf_for_each_map_elem() helper")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260902233658.1186477-1-eddyz87@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 9c7384295f13d..c201435ddafd2 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -10625,6 +10625,15 @@ static int check_ld_imm(struct bpf_verifier_env *env, struct bpf_insn *insn)
verbose(env, "callback function not static\n");
return -EINVAL;
}
+ /*
+ * When env->subprog_cnt == 1 this instruction won't be rewritten
+ * to hold a real function address. Assume that no usable program
+ * combines e.g. main and timer callback and just reject here.
+ */
+ if (subprogno == 0) {
+ verbose(env, "callback function cannot be the main program\n");
+ return -EINVAL;
+ }
dst_reg->type = PTR_TO_FUNC;
dst_reg->subprogno = subprogno;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 389/982] bonding: do not clear curr_active_slave prematurely when releasing all slaves
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (387 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 388/982] bpf: reject BPF_PSEUDO_FUNC reference to the main program Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 390/982] net/rds: use wq_has_sleeper() in release_in_xmit() Greg Kroah-Hartman
` (599 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jay Vosburgh,
Nikolay Aleksandrov, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit af602c7aa5fedc9be3043244017aef4f26c96b70 ]
When releasing all slaves during bond destruction (all == true),
__bond_release_one() unconditionally clears bond->curr_active_slave to
NULL in every iteration.
If a backup slave is released before the active slave,
bond_alb_deinit_slave() triggers rlb_teach_disabled_mac_on_primary(),
which increments the active slave dev promiscuity counter and sets
bond_info->primary_is_promisc = 1.
Because bond->curr_active_slave was prematurely cleared to NULL when
releasing the backup slave, the subsequent iteration releasing the active
slave evaluates oldcurrent as NULL, so bond_change_active_slave(bond, NULL)
is skipped. Consequently, bond_alb_handle_active_change() is never called
to decrement the promiscuity counter, permanently leaking promiscuous
mode on the physical device after bond teardown.
When oldcurrent == slave, bond_change_active_slave(bond, NULL) already sets
bond->curr_active_slave to NULL. We only need to avoid selecting a new
active slave when all == true. Replace the if (all) branch with
if (!all && oldcurrent == slave).
Fixes: 0896341a44bf ("bonding: fix bond_release_all inconsistencies")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260831203042.164466-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/bonding/bond_main.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
index c4f640292bb59..5b8770118c4f0 100644
--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -2485,9 +2485,7 @@ static int __bond_release_one(struct net_device *bond_dev,
bond_alb_deinit_slave(bond, slave);
}
- if (all) {
- RCU_INIT_POINTER(bond->curr_active_slave, NULL);
- } else if (oldcurrent == slave) {
+ if (!all && oldcurrent == slave) {
/* Note that we hold RTNL over this sequence, so there
* is no concern that another slave add/remove event
* will interfere.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 390/982] net/rds: use wq_has_sleeper() in release_in_xmit()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (388 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 389/982] bonding: do not clear curr_active_slave prematurely when releasing all slaves Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 391/982] net/rds: use clear_bit_unlock() in release_refill() Greg Kroah-Hartman
` (598 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 6d0c8b7073913011459cf968cbbadd341e166bc3 ]
release_in_xmit() clears RDS_IN_XMIT with clear_bit_unlock() and then
checks waitqueue_active() to decide whether anyone needs waking.
clear_bit_unlock() is only a release operation: it orders the
critical section before the bit clear, but does not order the
subsequent plain load of the wait queue head after it. The waiter
side does the mirror image - it adds itself to the wait queue and
then tests the bit. That is the classic store-buffering pattern: the
releasing CPU can read the wait queue as empty while the waiting CPU
still reads the bit as set, so the sleeper is never woken.
The waiters are rds_conn_shutdown() and rds_tcp_reset_callbacks(),
both in uninterruptible wait_event() with no timeout. A lost wake-up
strands the shutdown worker on its single-threaded workqueue until
some other sender releases the bit again - and on a connection that
is being torn down precisely because it failed, there may never be
another sender.
The barrier used to be there: release_in_xmit() did clear_bit()
followed by smp_mb__after_atomic() until commit 1422f28826d2 ("rds:
introduce acquire/release ordering in acquire/release_in_xmit()")
folded both into clear_bit_unlock(), which strengthened the lock
hand-off but silently dropped the full barrier the wake-up check
depends on. The refill counterpart, release_refill() in
net/rds/ib_recv.c, still carries its smp_mb__after_atomic() for
exactly this reason.
Use wq_has_sleeper(), which is waitqueue_active() preceded by the
required full barrier.
Fixes: 1422f28826d2 ("rds: introduce acquire/release ordering in acquire/release_in_xmit()")
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-2-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/send.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/net/rds/send.c b/net/rds/send.c
index 2cedcb837b8f3..56090789eb3a2 100644
--- a/net/rds/send.c
+++ b/net/rds/send.c
@@ -114,8 +114,13 @@ static void release_in_xmit(struct rds_conn_path *cp)
* hot path and finding waiters is very rare. We don't want to walk
* the system-wide hashed waitqueue buckets in the fast path only to
* almost never find waiters.
+ *
+ * wq_has_sleeper() supplies the full barrier that orders the wait
+ * queue read after the bit clear; clear_bit_unlock() alone is only
+ * a release and would let this check read a stale empty queue,
+ * losing the wake-up.
*/
- if (waitqueue_active(&cp->cp_waitq))
+ if (wq_has_sleeper(&cp->cp_waitq))
wake_up_all(&cp->cp_waitq);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 391/982] net/rds: use clear_bit_unlock() in release_refill()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (389 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 390/982] net/rds: use wq_has_sleeper() in release_in_xmit() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 392/982] net/rds: clear cp_flags bits individually in rds_conn_path_reset() Greg Kroah-Hartman
` (597 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 17c4476dbb9c3bfd34193a6c22f2c3da8747134a ]
release_refill() drops the RDS_RECV_REFILL bit with a plain
clear_bit(). clear_bit() has no ordering semantics, and the
smp_mb__after_atomic() that follows it sits on the wrong side for a
lock release: it orders the clear against the waitqueue_active() load
below it, but does nothing to order the refill critical section's ring
and descriptor stores before the clear itself.
That matters once connection teardown owns RDS_RECV_REFILL as a lock
across the transport shutdown and path reset, rather than sampling it
clear, which "net/rds: acquire the fastpath locks in
rds_conn_shutdown()" later in this series arranges: on a weakly
ordered architecture the teardown can win the bit and start the
shutdown and reset while some of the refill's stores are not yet
visible to it. The same gap existed under the sample-based scheme - a
waiter that saw the bit clear had no guarantee it also observed the
refill's stores - but taking the bit as a lock makes the missing
release pairing load-bearing.
Switch to clear_bit_unlock(), which orders the critical section before
the release, and replace the open-coded barrier-plus-waitqueue_active()
with wq_has_sleeper(), whose internal full barrier keeps the
store-buffering guarantee between clearing the bit and checking for
sleepers. This mirrors what "net/rds: use wq_has_sleeper() in
release_in_xmit()" does for RDS_IN_XMIT.
The fast-path acquire side, acquire_refill(), uses test_and_set_bit(),
a full-barrier RMW that pairs with this release. The teardown at this
point in the series still samples the bit, so on its own this change
is release-side hardening; the shutdown-conversion patch named above
makes the teardown acquire the bit with the same RMW, completing the
pairing at the end of the series.
Fixes: 73ce4317bf98 ("RDS: make sure we post recv buffers")
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-3-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/ib_recv.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/net/rds/ib_recv.c b/net/rds/ib_recv.c
index cfbf0e129cba5..c3b178231613f 100644
--- a/net/rds/ib_recv.c
+++ b/net/rds/ib_recv.c
@@ -362,15 +362,14 @@ static int acquire_refill(struct rds_connection *conn)
static void release_refill(struct rds_connection *conn)
{
- clear_bit(RDS_RECV_REFILL, &conn->c_flags);
- smp_mb__after_atomic();
+ clear_bit_unlock(RDS_RECV_REFILL, &conn->c_flags);
/* We don't use wait_on_bit()/wake_up_bit() because our waking is in a
* hot path and finding waiters is very rare. We don't want to walk
* the system-wide hashed waitqueue buckets in the fast path only to
* almost never find waiters.
*/
- if (waitqueue_active(&conn->c_waitq))
+ if (wq_has_sleeper(&conn->c_waitq))
wake_up_all(&conn->c_waitq);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 392/982] net/rds: clear cp_flags bits individually in rds_conn_path_reset()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (390 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 391/982] net/rds: use clear_bit_unlock() in release_refill() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 393/982] net/rds: tcp: dont force RDS_CONN_RESETTING over a concurrent shutdown Greg Kroah-Hartman
` (596 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 103c4b13c4f50322910078d1c02f29334a574122 ]
rds_conn_path_reset() wipes the whole flag word with a plain
cp->cp_flags = 0 store. Every other accessor of that word uses
atomic bitops, and some of them can run concurrently with the reset:
RDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from the
transport completion paths, neither of which holds anything that
excludes the shutdown worker. A plain store racing an atomic
read-modify-write on the same word is a data race, and whichever
side loses has its update silently discarded.
Clear the two bits the reset is actually responsible for instead.
RDS_IN_XMIT and RDS_RECV_REFILL need no store at all here: they
belong to the caller, rds_conn_shutdown(), which waits for both to be
clear before calling the transport shutdown and this reset.
This also gives every bit in cp_flags a single well-defined writer
discipline, which the following patches rely on when they turn
RDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across the
teardown: a blanket store mid-teardown would destroy lock ownership
that an atomic clear preserves.
Oracle UEK carries the same conversion ("net/rds: Preserve essential
connection state flags"), motivated by its asynchronous shutdown
state machine, whose progress and destroy flags must survive the
reset. UEK's variant also clears RDS_IN_XMIT and RDS_RECV_REFILL
because there the reset runs as the final step of a teardown that
owns both bits, making those clears its unlock. Upstream that
release belongs in rds_conn_shutdown(): once a later patch in this
series turns the two bits into locks held across the teardown, ending
ownership needs release semantics and a wake-up that a plain clear
inside the reset would not provide.
Based on Oracle UEK commit "net/rds: Preserve essential connection
state flags" by Gerd Rausch.
Fixes: 00e0f34c6166 ("RDS: Connection handling")
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-4-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/connection.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/net/rds/connection.c b/net/rds/connection.c
index beecd408e93ab..9e0c89b7bc4cd 100644
--- a/net/rds/connection.c
+++ b/net/rds/connection.c
@@ -119,7 +119,15 @@ static void rds_conn_path_reset(struct rds_conn_path *cp)
rds_stats_inc(s_conn_reset);
rds_send_path_reset(cp);
- cp->cp_flags = 0;
+
+ /* Clear the bits the reset is responsible for individually: a
+ * blanket cp_flags = 0 is a plain store that can clobber a
+ * concurrent atomic read-modify-write on the same word.
+ * RDS_IN_XMIT and RDS_RECV_REFILL belong to the caller,
+ * rds_conn_shutdown(), and are left alone here.
+ */
+ clear_bit(RDS_LL_SEND_FULL, &cp->cp_flags);
+ clear_bit(RDS_RECONNECT_PENDING, &cp->cp_flags);
/* Do not clear next_rx_seq here, else we cannot distinguish
* retransmitted packets from new packets, and will hand all
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 393/982] net/rds: tcp: dont force RDS_CONN_RESETTING over a concurrent shutdown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (391 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 392/982] net/rds: clear cp_flags bits individually in rds_conn_path_reset() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 394/982] net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() Greg Kroah-Hartman
` (595 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gerd Rausch, Allison Henderson,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gerd Rausch <gerd.rausch@oracle.com>
[ Upstream commit e8e60d74fec49ccae2aea9b04a6eb162feb8d9af ]
rds_tcp_reset_callbacks() resolves a duelling SYN by storing
RDS_CONN_RESETTING into cp_state unconditionally. Nothing serializes
that store against the shutdown path: rds_tcp_accept_one() checks
for RDS_CONN_CONNECTING or RDS_CONN_ERROR under t_conn_path_lock, but
neither rds_conn_path_drop(), which forces RDS_CONN_ERROR, nor
rds_conn_shutdown(), which moves the path to RDS_CONN_DISCONNECTING
under cp_cm_lock, takes that lock. The store can therefore land on
top of a shutdown that is already in progress, or that gets queued
right after the accept-side check.
When it does, the shutdown worker's final DISCONNECTING -> DOWN
transition fails and the path goes through rds_conn_path_error() and
a second drop/shutdown cycle instead of a clean reconnect, tearing
down the socket the accept path has just installed. Before commit
ad22d24be635 ("net/rds: No shortcut out of RDS_CONN_ERROR") a path
found in RDS_CONN_RESETTING even made rds_conn_shutdown() bail out
altogether.
Make the transition conditional: move CONNECTING -> RESETTING (or
stay in RESETTING from an earlier duel), and drop the path in any
other state. The drop has side effects of its own: it replaces the
shutdown's RDS_CONN_DISCONNECTING (or RDS_CONN_ERROR) with
RDS_CONN_ERROR and queues one more cp_down_w run. The difference is
that rds_conn_shutdown() accepts RDS_CONN_ERROR in its final
transition to RDS_CONN_DOWN, so the shutdown in flight completes
normally instead of through rds_conn_path_error(); the extra
down-work pass then finds the path already down and falls through to
the reconnect check, or catches a reconnect that has already started
and restarts it. The accept path still installs the new socket,
rds_connect_path_complete() then fails its RESETTING -> UP transition
and drops it: the raced socket ends up torn down as it does today.
The comment at that call site, which promised that
rds_connect_path_complete() marks the path RDS_CONN_UP, is updated to
name this outcome as well.
The state can change again between the failed transitions and the
drop. That is inherent to rds_conn_path_drop(), which the socket
state-change callbacks also call unconditionally, and costs at most
one extra drop/reconnect cycle.
Based on Oracle UEK commit "net/rds: Don't force state
RDS_CONN_RESETTING" by Gerd Rausch.
Fixes: 9c79440e2c5e ("RDS: TCP: fix race windows in send-path quiescence by rds_tcp_accept_one()")
Signed-off-by: Gerd Rausch <gerd.rausch@oracle.com>
[achender: port to net-next: use the two-argument
rds_conn_path_transition()/rds_conn_path_drop() and rewrite the
changelog for the upstream shutdown path]
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-5-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/tcp.c | 17 +++++++++++++++--
net/rds/tcp_listen.c | 6 +++++-
2 files changed, 20 insertions(+), 3 deletions(-)
diff --git a/net/rds/tcp.c b/net/rds/tcp.c
index 74ad2b5abb3ab..6dd7ef6b33982 100644
--- a/net/rds/tcp.c
+++ b/net/rds/tcp.c
@@ -149,9 +149,22 @@ void rds_tcp_reset_callbacks(struct socket *sock,
* end up deadlocking with tcp_sendmsg(), and the RDS_IN_XMIT
* would not get set. As a result, we set c_state to
* RDS_CONN_RESETTTING, to ensure that rds_tcp_state_change
- * cannot mark rds_conn_path_up() in the window before lock_sock()
+ * cannot mark rds_conn_path_up() in the window before lock_sock().
+ *
+ * Only make that transition if the path is still connecting
+ * (or already resetting from an earlier duel). A path in any
+ * other state - typically RDS_CONN_DISCONNECTING or
+ * RDS_CONN_ERROR with a shutdown in flight - is dropped
+ * instead. That still replaces its state, with RDS_CONN_ERROR,
+ * and queues one more shutdown pass, but rds_conn_shutdown()
+ * accepts RDS_CONN_ERROR in its final transition to
+ * RDS_CONN_DOWN, so the shutdown in flight completes normally.
*/
- atomic_set(&cp->cp_state, RDS_CONN_RESETTING);
+ if (!rds_conn_path_transition(cp, RDS_CONN_CONNECTING,
+ RDS_CONN_RESETTING) &&
+ !rds_conn_path_transition(cp, RDS_CONN_RESETTING,
+ RDS_CONN_RESETTING))
+ rds_conn_path_drop(cp, 0);
wait_event(cp->cp_waitq, !test_bit(RDS_IN_XMIT, &cp->cp_flags));
/* reset receive side state for rds_tcp_data_recv() for osock */
cancel_delayed_work_sync(&cp->cp_send_w);
diff --git a/net/rds/tcp_listen.c b/net/rds/tcp_listen.c
index 353b88833f787..add4e6ed220ec 100644
--- a/net/rds/tcp_listen.c
+++ b/net/rds/tcp_listen.c
@@ -196,7 +196,11 @@ int rds_tcp_accept_one(struct socket *sock)
if (rs_tcp->t_sock) {
/* Duelling SYN has been handled in rds_tcp_accept_one() */
rds_tcp_reset_callbacks(new_sock, cp);
- /* rds_connect_path_complete() marks RDS_CONN_UP */
+ /* rds_connect_path_complete() marks RDS_CONN_UP, or,
+ * if a concurrent shutdown won the duel, drops the
+ * path again and the pass that drop queues reaps the
+ * socket installed above.
+ */
rds_connect_path_complete(cp, RDS_CONN_RESETTING);
} else {
rds_tcp_set_callbacks(new_sock, cp);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 394/982] net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (392 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 393/982] net/rds: tcp: dont force RDS_CONN_RESETTING over a concurrent shutdown Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 395/982] net/rds: acquire the fastpath locks in rds_conn_shutdown() Greg Kroah-Hartman
` (594 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 02c5f9dc2efd823e061954d564ce00bacd1bebeb ]
rds_tcp_reset_callbacks() quiesces the transmit path by setting the
path state to RDS_CONN_RESETTING and then waiting for RDS_IN_XMIT to
be sampled clear before swapping the underlying socket and calling
rds_send_path_reset().
Sampling the bit clear is not the same as owning it: rds_send_xmit()
can re-acquire RDS_IN_XMIT right after the wait_event() returns. Its
state recheck after taking the lock is a store-buffering pattern (the
resetter writes the state and reads the bit, the sender writes the
bit and reads the state) and acquire_in_xmit() is only an acquire
operation, so on weakly ordered architectures both sides can miss
each other's write and the transmit path then runs concurrently with
rds_send_path_reset() rewriting cp_xmit_* state - which is exactly
what the comment above rds_send_path_reset() tells its callers to
prevent.
Take the lock instead, hold it across the socket swap and
rds_send_path_reset(), and release it with a wake-up at the end. The
lock-ordering constraint documented above the wait still holds: the
lock is acquired before lock_sock(), so a sender inside tcp_sendmsg()
can never be waited on while we hold the socket lock.
Two details of the old code go away with the same change:
- t_sock is now read only after the lock is acquired. The old code
cached it before waiting; the teardown in rds_conn_shutdown()
releases that socket and clears t_sock, so a pointer cached before
the wait can be stale by the time the accept path resumes. Reading
it under RDS_IN_XMIT is what makes the exclusion complete once the
teardown owns the same lock, which the next patch arranges; until
then the teardown still only samples the bit, and the two paths
remain as exposed to each other as they are today.
- The old !osock early path called rds_send_path_reset() with no
serialization at all. It now runs under the lock like the normal
path. The conditional RDS_CONN_RESETTING transition of the
previous patch happens before the socket check either way: a path
found without a socket is either still connecting (its reconnect
worker blocked on t_conn_path_lock) and legitimately goes
RESETTING -> UP on the new socket, or it has been torn down
meanwhile and is dropped.
The in-function comment describing the old wait-based quiesce is
rewritten to describe the lock-based one, and the stale block comment
above the function (which still described a return value and an
incomplete list of t_sock writers) is refreshed to name all four
writers - the connect, accept, teardown and swap paths - and what
serializes each of them.
Fixes: 335b48d980f6 ("RDS: TCP: Add/use rds_tcp_reset_callbacks to reset tcp socket safely")
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-6-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/tcp.c | 70 +++++++++++++++++++++++++++++++++------------------
1 file changed, 45 insertions(+), 25 deletions(-)
diff --git a/net/rds/tcp.c b/net/rds/tcp.c
index 6dd7ef6b33982..61263e54f22d2 100644
--- a/net/rds/tcp.c
+++ b/net/rds/tcp.c
@@ -114,42 +114,48 @@ void rds_tcp_restore_callbacks(struct socket *sock,
}
/*
- * rds_tcp_reset_callbacks() switches the to the new sock and
- * returns the existing tc->t_sock.
+ * rds_tcp_reset_callbacks() switches a path to a new socket and
+ * releases the old one it finds in tc->t_sock, resolving a duelling
+ * SYN.
*
- * The only functions that set tc->t_sock are rds_tcp_set_callbacks
- * and rds_tcp_reset_callbacks. Send and receive trust that
- * it is set. The absence of RDS_CONN_UP bit protects those paths
- * from being called while it isn't set.
+ * tc->t_sock is set by rds_tcp_set_callbacks() and cleared by
+ * rds_tcp_restore_callbacks(). Four paths write it: the active
+ * connect in rds_tcp_conn_path_connect(), which sets it and clears it
+ * again on failure; the accept path in rds_tcp_accept_one(), which
+ * sets it for a path with no socket yet; the teardown in
+ * rds_tcp_conn_path_shutdown(), which clears it; and the swap done
+ * here, which does both. The connect and accept paths are serialized
+ * against each other by t_conn_path_lock. Send and receive trust
+ * that it is set: the absence of RDS_CONN_UP protects those paths
+ * from being called while it isn't, and the swap done here runs under
+ * RDS_IN_XMIT so that it cannot interleave with a sender already
+ * inside rds_send_xmit().
*/
void rds_tcp_reset_callbacks(struct socket *sock,
struct rds_conn_path *cp)
{
struct rds_tcp_connection *tc = cp->cp_transport_data;
- struct socket *osock = tc->t_sock;
-
- if (!osock)
- goto newsock;
+ struct socket *osock;
/* Need to resolve a duelling SYN between peers.
* We have an outstanding SYN to this peer, which may
* potentially have transitioned to the RDS_CONN_UP state,
* so we must quiesce any send threads before resetting
- * cp_transport_data. We quiesce these threads by setting
- * cp_state to something other than RDS_CONN_UP, and then
- * waiting for any existing threads in rds_send_xmit to
- * complete release_in_xmit(). (Subsequent threads entering
- * rds_send_xmit() will bail on !rds_conn_up().
+ * cp_transport_data. Setting cp_state to something other
+ * than RDS_CONN_UP stops new senders, and owning RDS_IN_XMIT
+ * excludes any thread already inside rds_send_xmit() for the
+ * whole socket swap and the rds_send_path_reset() below.
*
- * However an incoming syn-ack at this point would end up
- * marking the conn as RDS_CONN_UP, and would again permit
- * rds_send_xmi() threads through, so ideally we would
- * synchronize on RDS_CONN_UP after lock_sock(), but cannot
- * do that: waiting on !RDS_IN_XMIT after lock_sock() may
- * end up deadlocking with tcp_sendmsg(), and the RDS_IN_XMIT
- * would not get set. As a result, we set c_state to
- * RDS_CONN_RESETTTING, to ensure that rds_tcp_state_change
- * cannot mark rds_conn_path_up() in the window before lock_sock().
+ * An incoming syn-ack at this point would end up marking the
+ * conn as RDS_CONN_UP, and would again permit rds_send_xmit()
+ * threads through, so ideally we would synchronize on
+ * RDS_CONN_UP after lock_sock(), but cannot do that: acquiring
+ * RDS_IN_XMIT after lock_sock() may end up deadlocking with
+ * tcp_sendmsg(), which takes the socket lock while holding
+ * RDS_IN_XMIT. As a result, we set c_state to
+ * RDS_CONN_RESETTING, to ensure that rds_tcp_state_change
+ * cannot mark rds_conn_path_up() in the window before
+ * lock_sock().
*
* Only make that transition if the path is still connecting
* (or already resetting from an earlier duel). A path in any
@@ -165,7 +171,18 @@ void rds_tcp_reset_callbacks(struct socket *sock,
!rds_conn_path_transition(cp, RDS_CONN_RESETTING,
RDS_CONN_RESETTING))
rds_conn_path_drop(cp, 0);
- wait_event(cp->cp_waitq, !test_bit(RDS_IN_XMIT, &cp->cp_flags));
+ wait_event(cp->cp_waitq,
+ !test_and_set_bit_lock(RDS_IN_XMIT, &cp->cp_flags));
+
+ /* Read t_sock only while owning RDS_IN_XMIT, never before the
+ * wait: the teardown in rds_conn_shutdown() releases the old
+ * socket and clears t_sock, so a pointer sampled earlier can
+ * be stale by the time we wake up.
+ */
+ osock = tc->t_sock;
+ if (!osock)
+ goto newsock;
+
/* reset receive side state for rds_tcp_data_recv() for osock */
cancel_delayed_work_sync(&cp->cp_send_w);
cancel_delayed_work_sync(&cp->cp_recv_w);
@@ -184,6 +201,9 @@ void rds_tcp_reset_callbacks(struct socket *sock,
lock_sock(sock->sk);
rds_tcp_set_callbacks(sock, cp);
release_sock(sock->sk);
+
+ clear_bit_unlock(RDS_IN_XMIT, &cp->cp_flags);
+ wake_up_all(&cp->cp_waitq);
}
/* Add tc to rds_tcp_tc_list and set tc->t_sock. See comments
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 395/982] net/rds: acquire the fastpath locks in rds_conn_shutdown()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (393 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 394/982] net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 396/982] net/rds: dont let rds_conn_shutdown() consume a concurrent drop Greg Kroah-Hartman
` (593 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Håkon Bugge, Allison Henderson,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Håkon Bugge <haakon.bugge@oracle.com>
[ Upstream commit 813f3582ac7ae9f60f917937d54660e0952d5f2d ]
rds_conn_shutdown() quiesces the transmit and receive-refill paths by
waiting for RDS_IN_XMIT and RDS_RECV_REFILL to be sampled clear, and
then runs the transport shutdown and rds_conn_path_reset(). Sampling
the bits clear is not the same as owning them: the moment after the
wait_event() returns, rds_send_xmit() can re-acquire RDS_IN_XMIT (or
rds_ib_recv_refill() can re-acquire RDS_RECV_REFILL) and run
concurrently with the teardown.
The sender does recheck the connection state after taking the lock,
but that recheck is a classic store-buffering pattern: teardown writes
the state and reads the bit while the sender writes the bit and reads
the state. acquire_in_xmit() is only an acquire operation, so on
weakly ordered architectures both sides can miss each other's write,
and the transmit path then runs while the transport zeroes its rings
(e.g. rds_ib_ring_init()) and rds_send_path_reset() rewrites the
transmit state under it.
Oracle UEK fixed the same class of crashes - a 14-year tail of
BUG_ON()s in rds_ib_sub_signaled(), unexpected op-codes and NULL
dereferences in rds_ib_send_cqe_handler() during failover testing -
by making the teardown path *acquire* the fastpath bit locks instead
of testing them ("rds: Make sure transmit path and connection
tear-down does not run concurrently"). Ownership of a single word is
decided by RMW atomicity, so no cross-variable ordering is needed.
Do the same here: take both locks before calling the transport
shutdown, hold them across rds_conn_path_reset(), and release them
explicitly with a wake-up afterwards. Both are released with
clear_bit_unlock(), so that the ring re-initialization done by the
transport shutdown and the transmit state rewritten by
rds_send_path_reset() are ordered before either bit is seen clear by
the next acquire_in_xmit() or acquire_refill().
The fastpath users of these bits - rds_send_xmit() and
rds_ib_recv_refill() - are trylock style and back off while teardown
owns the locks, so no new lock dependency is introduced for them.
rds_tcp_reset_callbacks() is different: since the previous patch it
acquires RDS_IN_XMIT as well, and it blocks doing so, so its wait now
spans the teardown instead of at most one send batch. That waiter
runs from rds_tcp_accept_one() on the single-threaded krdsd workqueue
and holds rds_tcp_accept_lock and t_conn_path_lock while it waits, so
a duelling SYN accepted while its path is being torn down parks
accept processing for the duration of the teardown - for TCP bounded
by the (up to 5 s) drain loop in rds_tcp_conn_path_shutdown(). An IB
path's drain in rds_ib_conn_path_shutdown() has no round cap, but no
blocking waiter either: rds_tcp_reset_callbacks() is the only blocking
acquirer of these bits and waits only on its own TCP path, and the
fastpaths are trylock-and-back-off on both transports, so a long IB
drain lengthens only that path's own quiesce. The
window is narrow: the accept-side state check has to pass before the
teardown moves the path to RDS_CONN_DISCONNECTING.
Because krdsd is a single global workqueue, everything else queued
there - accept processing for other connections and network
namespaces, and the flush_workqueue(rds_wq) in rds_tcp_listen_stop()
during namespace teardown - waits behind the parked accept worker for
that time. It cannot deadlock, although the waits do point at each
other: the teardown blocks until the bit's holder releases it, and
the holder may be that krdsd accept worker. The holder finishes
without needing anything the teardown owns: the sync cancels
rds_tcp_reset_callbacks() issues target cp_send_w and cp_recv_w on
the path's ordered cp_wq, whose only execution slot is occupied by
the blocked cp_down_w itself, so they are pending at most and cancel
without flushing - a reliance on cp_wq being ordered that is now
noted next to those cancels (on the allocation-failure fallback where
a path shares rds_wq, the work items simply serialize).
Nor is the blocking wait itself new: rds_tcp_reset_callbacks() has
waited on RDS_IN_XMIT from the krdsd work item since
commit 335b48d980f6 ("RDS: TCP: Add/use rds_tcp_reset_callbacks to
reset tcp socket safely"); this patch stretches its worst case from
a sender's batch to the teardown's drain. The alternative to parking
is the accept path racing the teardown, which is what these patches
close; making the teardown itself non-blocking is a separate item.
One observable side effect: the SENDING flag reported by rds-info has
always mirrored RDS_IN_XMIT, so it now also covers the window where
teardown owns the bit.
The comments that describe the old sample-based handshake or name
rds_send_xmit() as the only other holder of these bits - in
rds_send_xmit(), above rds_conn_path_reset(), in rds_ib_recv_refill()
and in rds_tcp_reset_callbacks() - are updated to match.
For anyone backporting this patch standalone: it depends on
"net/rds: clear cp_flags bits individually in rds_conn_path_reset()"
and "net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()"
earlier in this series. Without the former, the blanket cp_flags
clear in rds_conn_path_reset() would drop both held bits in the middle
of the teardown; without the latter, rds_tcp_reset_callbacks() would
still sample t_sock without owning RDS_IN_XMIT. "net/rds: use
clear_bit_unlock() in release_refill()" is needed for the refill
side's release to pair with the acquire added here, and the follow-up
"net/rds: don't let rds_conn_shutdown() consume a concurrent drop"
completes the teardown-state handling for the waiter this patch
parks; a backport should carry all four.
Fixes: 0f4b1c7e89e6 ("rds: fix rds_send_xmit() serialization")
Signed-off-by: Håkon Bugge <haakon.bugge@oracle.com>
[achender: reimplement for net-next shutdown path: acquire the existing
RDS_IN_XMIT/RDS_RECV_REFILL bit locks in rds_conn_shutdown() and release
after teardown; update comments and commit message]
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-7-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/connection.c | 40 ++++++++++++++++++++++++++++++++--------
net/rds/ib_recv.c | 4 +++-
net/rds/send.c | 7 +++++--
net/rds/tcp.c | 19 +++++++++++++++----
4 files changed, 55 insertions(+), 15 deletions(-)
diff --git a/net/rds/connection.c b/net/rds/connection.c
index 9e0c89b7bc4cd..0a0542378f178 100644
--- a/net/rds/connection.c
+++ b/net/rds/connection.c
@@ -105,10 +105,12 @@ static struct rds_connection *rds_conn_lookup(struct net *net,
}
/*
- * This is called by transports as they're bringing down a connection.
- * It clears partial message state so that the transport can start sending
- * and receiving over this connection again in the future. It is up to
- * the transport to have serialized this call with its send and recv.
+ * This is called by rds_conn_shutdown() once the transport has brought
+ * a path down. It clears partial message state so that the transport
+ * can start sending and receiving over this path again in the future.
+ * The caller owns RDS_IN_XMIT and RDS_RECV_REFILL across this call,
+ * which is what serializes it against the send and receive-refill
+ * paths.
*/
static void rds_conn_path_reset(struct rds_conn_path *cp)
{
@@ -123,8 +125,9 @@ static void rds_conn_path_reset(struct rds_conn_path *cp)
/* Clear the bits the reset is responsible for individually: a
* blanket cp_flags = 0 is a plain store that can clobber a
* concurrent atomic read-modify-write on the same word.
- * RDS_IN_XMIT and RDS_RECV_REFILL belong to the caller,
- * rds_conn_shutdown(), and are left alone here.
+ * RDS_IN_XMIT and RDS_RECV_REFILL are held as locks by the
+ * caller, rds_conn_shutdown(), which releases them once the
+ * teardown is complete.
*/
clear_bit(RDS_LL_SEND_FULL, &cp->cp_flags);
clear_bit(RDS_RECONNECT_PENDING, &cp->cp_flags);
@@ -400,14 +403,35 @@ void rds_conn_shutdown(struct rds_conn_path *cp)
}
mutex_unlock(&cp->cp_cm_lock);
+ /* Quiesce the transmit and receive-refill paths by
+ * acquiring their bit locks, not merely waiting for
+ * them to be released: with a plain wait, either path
+ * can re-take its lock the instant after we sample it
+ * clear and then run concurrently with the transport
+ * shutdown and the path reset below. Holding both
+ * locks across the teardown makes that structurally
+ * impossible.
+ */
wait_event(cp->cp_waitq,
- !test_bit(RDS_IN_XMIT, &cp->cp_flags));
+ !test_and_set_bit_lock(RDS_IN_XMIT, &cp->cp_flags));
wait_event(cp->cp_waitq,
- !test_bit(RDS_RECV_REFILL, &cp->cp_flags));
+ !test_and_set_bit(RDS_RECV_REFILL, &cp->cp_flags));
conn->c_trans->conn_path_shutdown(cp);
rds_conn_path_reset(cp);
+ /* Release the two locks and wake any waiter (e.g.
+ * rds_tcp_reset_callbacks()) that blocked on them while
+ * we held them. The unlock orders the transport's ring
+ * re-initialization and the path reset above before
+ * either bit is seen clear. rds_conn_path_reset() leaves
+ * both bits alone: ownership ends here, not inside the
+ * reset.
+ */
+ clear_bit_unlock(RDS_IN_XMIT, &cp->cp_flags);
+ clear_bit_unlock(RDS_RECV_REFILL, &cp->cp_flags);
+ wake_up_all(&cp->cp_waitq);
+
if (!rds_conn_path_transition(cp, RDS_CONN_DISCONNECTING,
RDS_CONN_DOWN) &&
!rds_conn_path_transition(cp, RDS_CONN_ERROR,
diff --git a/net/rds/ib_recv.c b/net/rds/ib_recv.c
index c3b178231613f..89aef2fffc1ed 100644
--- a/net/rds/ib_recv.c
+++ b/net/rds/ib_recv.c
@@ -390,7 +390,9 @@ void rds_ib_recv_refill(struct rds_connection *conn, int prefill, gfp_t gfp)
/* the goal here is to just make sure that someone, somewhere
* is posting buffers. If we can't get the refill lock,
- * let them do their thing
+ * let them do their thing. The holder may also be
+ * rds_conn_shutdown() tearing the path down, in which case
+ * there is nothing to post.
*/
if (!acquire_refill(conn))
return;
diff --git a/net/rds/send.c b/net/rds/send.c
index 56090789eb3a2..c2ef236076188 100644
--- a/net/rds/send.c
+++ b/net/rds/send.c
@@ -185,8 +185,11 @@ int rds_send_xmit(struct rds_conn_path *cp)
WRITE_ONCE(cp->cp_send_gen, send_gen);
/*
- * rds_conn_shutdown() sets the conn state and then tests RDS_IN_XMIT,
- * we do the opposite to avoid races.
+ * rds_conn_shutdown() sets the conn state and then acquires
+ * RDS_IN_XMIT; we take the lock first and then check the state.
+ * Ownership is decided by the atomic RMW on the cp_flags word:
+ * if the teardown won the bit we back off here, and if we won
+ * it the teardown waits until we release it.
*/
if (!rds_conn_path_up(cp)) {
release_in_xmit(cp);
diff --git a/net/rds/tcp.c b/net/rds/tcp.c
index 61263e54f22d2..1ce1a3b260b96 100644
--- a/net/rds/tcp.c
+++ b/net/rds/tcp.c
@@ -143,8 +143,10 @@ void rds_tcp_reset_callbacks(struct socket *sock,
* so we must quiesce any send threads before resetting
* cp_transport_data. Setting cp_state to something other
* than RDS_CONN_UP stops new senders, and owning RDS_IN_XMIT
- * excludes any thread already inside rds_send_xmit() for the
- * whole socket swap and the rds_send_path_reset() below.
+ * excludes any thread already inside rds_send_xmit() - or a
+ * teardown in rds_conn_shutdown(), which holds the same lock
+ * for the duration of the transport shutdown - for the whole
+ * socket swap and the rds_send_path_reset() below.
*
* An incoming syn-ack at this point would end up marking the
* conn as RDS_CONN_UP, and would again permit rds_send_xmit()
@@ -177,13 +179,22 @@ void rds_tcp_reset_callbacks(struct socket *sock,
/* Read t_sock only while owning RDS_IN_XMIT, never before the
* wait: the teardown in rds_conn_shutdown() releases the old
* socket and clears t_sock, so a pointer sampled earlier can
- * be stale by the time we wake up.
+ * be stale by the time we wake up. The teardown holds the
+ * same lock while it does so, so what we read here cannot
+ * change under us until we release it.
*/
osock = tc->t_sock;
if (!osock)
goto newsock;
- /* reset receive side state for rds_tcp_data_recv() for osock */
+ /* reset receive side state for rds_tcp_data_recv() for osock.
+ *
+ * The sync cancels while owning RDS_IN_XMIT rely on cp_wq
+ * being ordered: a teardown blocked on the bit occupies
+ * cp_wq's only execution slot, so cp_send_w and cp_recv_w are
+ * pending at most and the cancels never flush. Nothing here
+ * may flush or wait on cp_wq itself.
+ */
cancel_delayed_work_sync(&cp->cp_send_w);
cancel_delayed_work_sync(&cp->cp_recv_w);
lock_sock(osock->sk);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 396/982] net/rds: dont let rds_conn_shutdown() consume a concurrent drop
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (394 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 395/982] net/rds: acquire the fastpath locks in rds_conn_shutdown() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 397/982] net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after reset Greg Kroah-Hartman
` (592 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 260c6308fe2e19ad519389d44d582e292aecc3af ]
rds_conn_shutdown() finishes by moving the path from
RDS_CONN_DISCONNECTING to RDS_CONN_DOWN, and also accepts
RDS_CONN_ERROR as the starting state of that final transition, so that
a FIN processed in softirq context during the teardown does not derail
the shutdown into a noisy error path.
But consuming that RDS_CONN_ERROR also consumes the shutdown pass that
came with it: rds_conn_path_drop() sets RDS_CONN_ERROR and then queues
cp_down_w, and a pass that starts on a path already in RDS_CONN_DOWN
is a no-op. For the FIN case that is harmless - the socket the FIN
arrived on is the very socket the teardown just released. It is not
harmless for a dropper that attached something to the path first.
rds_tcp_accept_one() is such a dropper. Its path claim in
rds_tcp_accept_one_path() transitions RDS_CONN_DOWN ->
RDS_CONN_CONNECTING, and a concurrent drop - a FIN on a previous
socket in softirq context, an administrative reset - can put the path
into RDS_CONN_ERROR between that claim and the state check that
follows, which accepts RDS_CONN_ERROR. The accept then installs the
freshly accepted socket with rds_tcp_set_callbacks() while the queued
teardown - which sampled tc->t_sock before this socket existed - is
still running. rds_connect_path_complete() fails its transition to
RDS_CONN_UP and drops the path again, queueing the pass that should
reap the socket it just installed. If the in-flight shutdown's final
transition consumes that drop's RDS_CONN_ERROR, the queued pass finds
the path in RDS_CONN_DOWN and does nothing. The installed socket is
never torn down: it sits established with its callbacks armed and its
rds_tcp_connection on rds_tcp_tc_list, the peer sees a connection that
nothing ever reads, and the path is wedged in RDS_CONN_DOWN until some
later event drops it again. Reproduced with widened race windows as
an ever-growing receive queue on a socket owned by a path stuck in
RDS_CONN_DOWN, with the peer's send path wedged behind it.
Make the final transition only DISCONNECTING -> DOWN. If it fails
because the path is in RDS_CONN_ERROR, a drop raced the teardown:
cancel the reconnect timer and clear RDS_RECONNECT_PENDING - the one
piece of the skipped tail that must not be left behind - and return,
letting the pass the drop queued finish the job: it tears down
whatever attached to the path in the meantime, completes the
transition to RDS_CONN_DOWN, and re-arms the reconnect from its own
tail.
The timer quiesce in that branch matters because the racing drop does
not always queue that pass: rds_conn_path_drop() returns without
queueing when a destroy is pending - exactly the situation during a
netns teardown or module unload, when a FIN on the dying socket is
processed while rds_conn_path_destroy() flushes cp_down_w. If the
flushed pass is the one that takes this return, no later pass exists,
and rds_conn_path_destroy() would find cp_conn_w still armed
(WARN_ON) and then free a path whose reconnect timer can still fire.
With the cancel in the branch, every exit of a shutdown pass leaves
the timer quiesced no matter which pass completes the transition.
The FIN case keeps making progress, one pass later and still without
noisy logging. Any other state keeps today's rds_conn_path_error()
handling; no current cp_state writer can leave a DISCONNECTING path
in anything but RDS_CONN_ERROR (every other writer is a cmpxchg from
a non-DISCONNECTING state), so that branch is defensive.
On kernels without the preceding patches the same hazard exists with
the sample-based quiesce; the fix applies there equally.
Fixes: e97656d03ca0 ("rds: tcp: allow progress of rds_conn_shutdown if the rds_connection is marked ERROR by an intervening FIN")
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260828223921.202913-8-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/connection.c | 43 ++++++++++++++++++++++++++++++++-----------
net/rds/tcp.c | 9 ++++++---
2 files changed, 38 insertions(+), 14 deletions(-)
diff --git a/net/rds/connection.c b/net/rds/connection.c
index 0a0542378f178..a273af94df2dd 100644
--- a/net/rds/connection.c
+++ b/net/rds/connection.c
@@ -433,19 +433,40 @@ void rds_conn_shutdown(struct rds_conn_path *cp)
wake_up_all(&cp->cp_waitq);
if (!rds_conn_path_transition(cp, RDS_CONN_DISCONNECTING,
- RDS_CONN_DOWN) &&
- !rds_conn_path_transition(cp, RDS_CONN_ERROR,
RDS_CONN_DOWN)) {
- /* This can happen - eg when we're in the middle of tearing
- * down the connection, and someone unloads the rds module.
- * Quite reproducible with loopback connections.
- * Mostly harmless.
+ /* The path was dropped again while we tore it
+ * down: by a socket state-change callback in
+ * irq context on receipt of a FIN, or by an
+ * accept that claimed the path just before a
+ * drop put it back to RDS_CONN_ERROR and then
+ * installed a fresh socket on it. Unless a
+ * pending destroy suppressed it, the drop also
+ * queued another shutdown pass, and that pass
+ * must run, because it is what tears down
+ * whatever attached to the path after the
+ * transport shutdown above sampled its state.
+ * Consuming the RDS_CONN_ERROR here would turn
+ * that pass into a no-op: leave the state
+ * alone, and let the pass finish the job.
*
- * Note that this also happens with rds-tcp because
- * we could have triggered rds_conn_path_drop in irq
- * mode from rds_tcp_state change on the receipt of
- * a FIN, thus we need to recheck for RDS_CONN_ERROR
- * here.
+ * Quiesce the reconnect timer before bailing
+ * out, though. When a pending destroy did
+ * suppress the queue, no later pass runs, and
+ * rds_conn_path_destroy() is about to flush
+ * cp_down_w and free the path: it must not
+ * find cp_conn_w still armed. A successor
+ * pass, when there is one, re-arms the
+ * reconnect from its own tail.
+ */
+ cancel_delayed_work_sync(&cp->cp_conn_w);
+ clear_bit(RDS_RECONNECT_PENDING, &cp->cp_flags);
+
+ if (rds_conn_path_state(cp) == RDS_CONN_ERROR)
+ return;
+ /* No current cp_state writer leaves a
+ * DISCONNECTING path in any state but
+ * RDS_CONN_ERROR; report loudly if one ever
+ * does.
*/
rds_conn_path_error(cp, "%s: failed to transition "
"to state DOWN, current state "
diff --git a/net/rds/tcp.c b/net/rds/tcp.c
index 1ce1a3b260b96..397953c3048dc 100644
--- a/net/rds/tcp.c
+++ b/net/rds/tcp.c
@@ -164,9 +164,12 @@ void rds_tcp_reset_callbacks(struct socket *sock,
* other state - typically RDS_CONN_DISCONNECTING or
* RDS_CONN_ERROR with a shutdown in flight - is dropped
* instead. That still replaces its state, with RDS_CONN_ERROR,
- * and queues one more shutdown pass, but rds_conn_shutdown()
- * accepts RDS_CONN_ERROR in its final transition to
- * RDS_CONN_DOWN, so the shutdown in flight completes normally.
+ * and, unless a pending destroy is about to reap the whole
+ * connection anyway, queues one more shutdown pass. A shutdown
+ * already in flight leaves that RDS_CONN_ERROR alone when it
+ * finishes; the queued pass then completes the transition to
+ * RDS_CONN_DOWN and tears down anything that attached to the
+ * path in the meantime.
*/
if (!rds_conn_path_transition(cp, RDS_CONN_CONNECTING,
RDS_CONN_RESETTING) &&
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 397/982] net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after reset
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (395 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 396/982] net/rds: dont let rds_conn_shutdown() consume a concurrent drop Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 398/982] selftests/alsa: Fix the step check for INTEGER controls Greg Kroah-Hartman
` (591 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 6b8fed2675fb75d23e6cf2b7e49c94926e884b34 ]
The core software reset issued in stmmac_init_dma_engine() during
ndo_open() callback clears the MTL RX packet parser registers, but
stmmac_rxp_config() is only invoked from the cls_u32 add/delete paths.
After an ifdown/ifup cycle the hardware therefore runs with the default
all-pass table while priv->tc_entries still reports the filters as
installed. Re-apply the RX packet parser table from priv->tc_entries in
stmmac_hw_setup(), right after the software reset, so the filters are
restored when the interface is brought up again.
Fixes: 4dbbe8dde848 ("net: stmmac: Add support for U32 TC filter using Flexible RX Parser")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260831-stmmac_tc_cls32_reconfigure-v1-1-21cb459e64ae@oss.qualcomm.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index 16c4640e8e689..fb8c65c2bc0ef 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -3349,6 +3349,14 @@ static int stmmac_hw_setup(struct net_device *dev, bool ptp_register)
/* Initialize MTL*/
stmmac_mtl_configuration(priv);
+ /* Apply the RX packet parser table */
+ if (priv->tc_entries) {
+ ret = stmmac_rxp_config(priv, priv->hw->pcsr, priv->tc_entries,
+ priv->tc_entries_max);
+ if (ret)
+ return ret;
+ }
+
/* Initialize Safety Features */
stmmac_safety_feat_configuration(priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 398/982] selftests/alsa: Fix the step check for INTEGER controls
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (396 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 397/982] net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after reset Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 399/982] ALSA: caiaq: Fix potential double-free at error path Greg Kroah-Hartman
` (590 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit 8efd5f623c63584c2e284a837a7795d95a0491cb ]
The modulo sits inside the subtraction, so the check evaluates
int_val - (min % step) rather than (int_val - min) % step. The
INTEGER64 branch below it is parenthesised correctly.
The written form passes only when the value equals min % step, and such
a value is always on a step boundary, so it never misses a real
violation. It only reports valid values as invalid.
snd-aloop declares step 1 on four controls, so every non-zero value on
them is reported. Before:
# PCM Rate Shift 100000.0 value 100000 invalid for step 1 minimum 80000
# Totals: pass:660 fail:101 xfail:0 xpass:0 skip:296 error:0
After, same card, nothing else changed:
# Totals: pass:740 fail:21 xfail:0 xpass:0 skip:296 error:0
Eighteen files under sound/ declare a non-zero step.
Fixes: 5aaf9efffc57 ("kselftest: alsa: Add simplistic test for ALSA mixer controls kselftest")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Assisted-by: Claude:claude-opus-5
Link: https://patch.msgid.link/20260903123832.97377-1-sammiee5311@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/alsa/mixer-test.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/alsa/mixer-test.c b/tools/testing/selftests/alsa/mixer-test.c
index 960b137789d25..a3fb3f708f9e7 100644
--- a/tools/testing/selftests/alsa/mixer-test.c
+++ b/tools/testing/selftests/alsa/mixer-test.c
@@ -338,8 +338,8 @@ static bool ctl_value_index_valid(struct ctl_data *ctl,
/* Only check step size if there is one and we're in bounds */
if (snd_ctl_elem_info_get_step(ctl->info) &&
- (int_val - snd_ctl_elem_info_get_min(ctl->info) %
- snd_ctl_elem_info_get_step(ctl->info))) {
+ (int_val - snd_ctl_elem_info_get_min(ctl->info)) %
+ snd_ctl_elem_info_get_step(ctl->info)) {
ksft_print_msg("%s.%d value %ld invalid for step %ld minimum %ld\n",
ctl->name, index, int_val,
snd_ctl_elem_info_get_step(ctl->info),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 399/982] ALSA: caiaq: Fix potential double-free at error path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (397 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 398/982] selftests/alsa: Fix the step check for INTEGER controls Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 400/982] bpf: Fix NULL-ptr-deref when showing a void BTF type Greg Kroah-Hartman
` (589 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 3b26ceef88c110f4d188387cffa0df78657be904 ]
The fix for caiaq driver's resource management to handle the errors
tries to release the resources in a common destructor call, but as a
sashiko review for another patch suggested, some of the audio
resources such as URBs have been already freed, and this may lead to a
double-free.
For addressing the double-free, call the common destructor function
from each place, and assure that the resource pointers get cleared.
Link: https://sashiko.dev/#/patchset/20260903084747.535367-1-eadavis%40sina.com
Fixes: 28abd224db4a ("ALSA: caiaq: Handle probe errors properly")
Link: https://patch.msgid.link/20260903103855.1807838-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/caiaq/audio.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/sound/usb/caiaq/audio.c b/sound/usb/caiaq/audio.c
index 7a89872aa0cbd..11d959887de56 100644
--- a/sound/usb/caiaq/audio.c
+++ b/sound/usb/caiaq/audio.c
@@ -853,16 +853,13 @@ int snd_usb_caiaq_audio_init(struct snd_usb_caiaqdev *cdev)
cdev->data_urbs_in = alloc_urbs(cdev, SNDRV_PCM_STREAM_CAPTURE, &ret);
if (ret < 0) {
- kfree(cdev->data_cb_info);
- free_urbs(cdev->data_urbs_in);
+ snd_usb_caiaq_audio_free(cdev);
return ret;
}
cdev->data_urbs_out = alloc_urbs(cdev, SNDRV_PCM_STREAM_PLAYBACK, &ret);
if (ret < 0) {
- kfree(cdev->data_cb_info);
- free_urbs(cdev->data_urbs_in);
- free_urbs(cdev->data_urbs_out);
+ snd_usb_caiaq_audio_free(cdev);
return ret;
}
@@ -883,6 +880,9 @@ void snd_usb_caiaq_audio_free(struct snd_usb_caiaqdev *cdev)
dev_dbg(dev, "%s(%p)\n", __func__, cdev);
free_urbs(cdev->data_urbs_in);
+ cdev->data_urbs_in = NULL;
free_urbs(cdev->data_urbs_out);
+ cdev->data_urbs_out = NULL;
kfree(cdev->data_cb_info);
+ cdev->data_cb_info = NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 400/982] bpf: Fix NULL-ptr-deref when showing a void BTF type
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (398 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 399/982] ALSA: caiaq: Fix potential double-free at error path Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 401/982] bpf: Fix NULL-ptr-deref in btf_var_show() Greg Kroah-Hartman
` (588 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Ihor Solodrai,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 4ea508b9ebd78bce7f212166d2e2cba66b875f08 ]
btf_modifier_show() resolves the modifier and then calls
btf_type_ops(t)->show() unconditionally. For the void type (type_id 0,
BTF_KIND_UNKN) kind_ops[] has no entry, so ->show is NULL.
A "const void" (a modifier resolving to void) cannot be a map key or
value - map_check_btf() rejects it because void has no size - so the map
dump path does not reach it. But bpf_snprintf_btf() takes a type_id
straight from the BPF program, and passing such a "const void" from the
vmlinux BTF NULL-derefs:
KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
RIP: 0010:btf_modifier_show (kernel/bpf/btf.c:2914)
Call Trace:
<TASK>
btf_type_show (kernel/bpf/btf.c:8251)
btf_type_snprintf_show (kernel/bpf/btf.c:8321)
bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047)
bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829)
__sys_bpf (kernel/bpf/syscall.c:4804)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
</TASK>
Fall back to btf_df_show() when the resolved type has no show op; it
emits the "<unsupported kind:N>" placeholder already used for kinds like
FWD and FUNC. bpf_snprintf_btf() then returns the length as usual.
Fixes: c4d0bfb45068 ("bpf: Add bpf_snprintf_btf helper")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev>
Link: https://lore.kernel.org/r/20260901104924.346187-3-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index d9f6ad515d890..da85fc671023c 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -2668,7 +2668,14 @@ static void btf_modifier_show(const struct btf *btf,
else
t = btf_type_skip_modifiers(btf, type_id, NULL);
- btf_type_ops(t)->show(btf, t, type_id, data, bits_offset, show);
+ /*
+ * A modifier can resolve to void, which has no show op; print a
+ * placeholder rather than dereferencing NULL.
+ */
+ if (!btf_type_ops(t))
+ btf_df_show(btf, t, type_id, data, bits_offset, show);
+ else
+ btf_type_ops(t)->show(btf, t, type_id, data, bits_offset, show);
}
static void btf_var_show(const struct btf *btf, const struct btf_type *t,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 401/982] bpf: Fix NULL-ptr-deref in btf_var_show()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (399 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 400/982] bpf: Fix NULL-ptr-deref when showing a void BTF type Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 402/982] ALSA/ASoC: hda: ext: add ext prefix to snd_hdac_link_free_all Greg Kroah-Hartman
` (587 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Ihor Solodrai,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 5403a383f52fc0905703b488f7c3db4b2447dc58 ]
btf_var_show() calls btf_type_id_resolve() unconditionally, which
dereferences btf->resolved_ids. That is NULL for a base BTF - e.g. the
vmlinux BTF that bpf_snprintf_btf() renders against - since base BTF is
not resolved during parsing. btf_modifier_show() guards this with
'if (btf->resolved_ids)', but btf_var_show() does not.
A BPF program that passes the type_id of a BTF_KIND_VAR from the vmlinux
BTF to bpf_snprintf_btf() thus NULL-derefs:
KASAN: probably user-memory-access in range [0x46638-0x4663f]
RIP: 0010:btf_var_show (kernel/bpf/btf.c:2929)
Call Trace:
<TASK>
btf_type_show (kernel/bpf/btf.c:8259)
btf_type_snprintf_show (kernel/bpf/btf.c:8329)
bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047)
bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829)
__sys_bpf (kernel/bpf/syscall.c:4804)
do_syscall_64 (arch/x86/entry/syscall_64.c:84)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
</TASK>
Resolve the var's type directly with btf_type_skip_modifiers() when
resolved_ids is NULL, mirroring btf_modifier_show().
Fixes: c4d0bfb45068 ("bpf: Add bpf_snprintf_btf helper")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev>
Link: https://lore.kernel.org/r/20260901104924.346187-4-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index da85fc671023c..cf6883e7b158f 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -2682,7 +2682,15 @@ static void btf_var_show(const struct btf *btf, const struct btf_type *t,
u32 type_id, void *data, u8 bits_offset,
struct btf_show *show)
{
- t = btf_type_id_resolve(btf, &type_id);
+ /*
+ * btf_type_id_resolve() dereferences btf->resolved_ids, which is NULL
+ * for a base BTF (e.g. the vmlinux BTF that bpf_snprintf_btf() uses).
+ * Resolve the var's type directly in that case.
+ */
+ if (btf->resolved_ids)
+ t = btf_type_id_resolve(btf, &type_id);
+ else
+ t = btf_type_skip_modifiers(btf, t->type, &type_id);
btf_type_ops(t)->show(btf, t, type_id, data, bits_offset, show);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 402/982] ALSA/ASoC: hda: ext: add ext prefix to snd_hdac_link_free_all
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (400 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 401/982] bpf: Fix NULL-ptr-deref in btf_var_show() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.1 403/982] ASoC: Intel: avs: Clean up the bus when fetching ML caps fails Greg Kroah-Hartman
` (586 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pierre-Louis Bossart, Bard Liao,
Péter Ujfalusi, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pierre-Louis Bossart <pierre-louis.bossart@linux.intel.com>
[ Upstream commit 7f05ca9a7467f05b8703b37bdc1ddddd0e9f8876 ]
No functionality change, just prefix addition to clearly identify that
the helper only applies to the 'ext' part for Intel platforms.
Signed-off-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.intel.com>
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Péter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://lore.kernel.org/r/20221019162115.185917-6-pierre-louis.bossart@linux.intel.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Stable-dep-of: 559ea14b7ae7 ("ASoC: Intel: avs: Clean up the bus when fetching ML caps fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/hdaudio_ext.h | 2 +-
sound/hda/ext/hdac_ext_controller.c | 6 +++---
sound/soc/intel/avs/core.c | 2 +-
sound/soc/intel/skylake/skl.c | 2 +-
sound/soc/sof/intel/hda.c | 2 +-
5 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/include/sound/hdaudio_ext.h b/include/sound/hdaudio_ext.h
index 83aed26ab1433..9c1ec992ab53e 100644
--- a/include/sound/hdaudio_ext.h
+++ b/include/sound/hdaudio_ext.h
@@ -80,7 +80,7 @@ struct hdac_ext_stream {
int snd_hdac_ext_stream_init_all(struct hdac_bus *bus, int start_idx,
int num_stream, int dir);
void snd_hdac_ext_stream_free_all(struct hdac_bus *bus);
-void snd_hdac_link_free_all(struct hdac_bus *bus);
+void snd_hdac_ext_link_free_all(struct hdac_bus *bus);
struct hdac_ext_stream *snd_hdac_ext_stream_assign(struct hdac_bus *bus,
struct snd_pcm_substream *substream,
int type);
diff --git a/sound/hda/ext/hdac_ext_controller.c b/sound/hda/ext/hdac_ext_controller.c
index 80876b9a87f46..a2dae3abd541d 100644
--- a/sound/hda/ext/hdac_ext_controller.c
+++ b/sound/hda/ext/hdac_ext_controller.c
@@ -108,12 +108,12 @@ int snd_hdac_ext_bus_get_ml_capabilities(struct hdac_bus *bus)
EXPORT_SYMBOL_GPL(snd_hdac_ext_bus_get_ml_capabilities);
/**
- * snd_hdac_link_free_all- free hdac extended link objects
+ * snd_hdac_ext_link_free_all- free hdac extended link objects
*
* @bus: the pointer to HDAC bus object
*/
-void snd_hdac_link_free_all(struct hdac_bus *bus)
+void snd_hdac_ext_link_free_all(struct hdac_bus *bus)
{
struct hdac_ext_link *l;
@@ -123,7 +123,7 @@ void snd_hdac_link_free_all(struct hdac_bus *bus)
kfree(l);
}
}
-EXPORT_SYMBOL_GPL(snd_hdac_link_free_all);
+EXPORT_SYMBOL_GPL(snd_hdac_ext_link_free_all);
/**
* snd_hdac_ext_bus_link_at - get link at specified address
diff --git a/sound/soc/intel/avs/core.c b/sound/soc/intel/avs/core.c
index 04d0099adb8fb..44e5d2ed2b95a 100644
--- a/sound/soc/intel/avs/core.c
+++ b/sound/soc/intel/avs/core.c
@@ -528,7 +528,7 @@ static void avs_pci_remove(struct pci_dev *pci)
snd_hdac_bus_free_stream_pages(bus);
snd_hdac_ext_stream_free_all(bus);
/* reverse ml_capabilities */
- snd_hdac_link_free_all(bus);
+ snd_hdac_ext_link_free_all(bus);
snd_hdac_ext_bus_exit(bus);
avs_dsp_core_disable(adev, GENMASK(adev->hw_cfg.dsp_cores - 1, 0));
diff --git a/sound/soc/intel/skylake/skl.c b/sound/soc/intel/skylake/skl.c
index 7f058acd221f0..3d8cb8cb533b9 100644
--- a/sound/soc/intel/skylake/skl.c
+++ b/sound/soc/intel/skylake/skl.c
@@ -445,7 +445,7 @@ static int skl_free(struct hdac_bus *bus)
free_irq(bus->irq, (void *)bus);
snd_hdac_bus_free_stream_pages(bus);
snd_hdac_ext_stream_free_all(bus);
- snd_hdac_link_free_all(bus);
+ snd_hdac_ext_link_free_all(bus);
if (bus->remap_addr)
iounmap(bus->remap_addr);
diff --git a/sound/soc/sof/intel/hda.c b/sound/soc/sof/intel/hda.c
index 63764afdcf617..b7d6a54bbb634 100644
--- a/sound/soc/sof/intel/hda.c
+++ b/sound/soc/sof/intel/hda.c
@@ -1224,7 +1224,7 @@ int hda_dsp_remove(struct snd_sof_dev *sdev)
hda_dsp_stream_free(sdev);
#if IS_ENABLED(CONFIG_SND_SOC_SOF_HDA)
- snd_hdac_link_free_all(bus);
+ snd_hdac_ext_link_free_all(bus);
#endif
iounmap(sdev->bar[HDA_DSP_BAR]);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 403/982] ASoC: Intel: avs: Clean up the bus when fetching ML caps fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (401 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 402/982] ALSA/ASoC: hda: ext: add ext prefix to snd_hdac_link_free_all Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 404/982] bpf: Introduce might_sleep field in bpf_func_proto Greg Kroah-Hartman
` (585 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Amadeusz Sławiński,
Cezary Rojewski, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cezary Rojewski <cezary.rojewski@intel.com>
[ Upstream commit 559ea14b7ae7c7562b48759fa545b64958f35b73 ]
snd_hdac_ext_bus_get_ml_capabilities() may fail and its return code
shall be checked and accounted for. Address the issue by updating the
error-path for avs_pci_probe().
At the same time, if the function in question succeeds but the next part
of avs_pci_probe() fails, the hlink list shall be cleaned up before
leaving the scope.
Fixes: 1affc44ea5dd ("ASoC: Intel: avs: PCI driver implementation")
Co-developed-by: Amadeusz Sławiński <amade@asmblr.net>
Signed-off-by: Amadeusz Sławiński <amade@asmblr.net>
Signed-off-by: Cezary Rojewski <cezary.rojewski@intel.com>
Link: https://patch.msgid.link/20260902081814.1590883-5-cezary.rojewski@intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/intel/avs/core.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/sound/soc/intel/avs/core.c b/sound/soc/intel/avs/core.c
index 44e5d2ed2b95a..102acaa545902 100644
--- a/sound/soc/intel/avs/core.c
+++ b/sound/soc/intel/avs/core.c
@@ -438,8 +438,13 @@ static int avs_pci_probe(struct pci_dev *pci, const struct pci_device_id *id)
}
snd_hdac_bus_parse_capabilities(bus);
- if (bus->mlcap)
- snd_hdac_ext_bus_get_ml_capabilities(bus);
+ if (bus->mlcap) {
+ ret = snd_hdac_ext_bus_get_ml_capabilities(bus);
+ if (ret < 0) {
+ dev_err(dev, "failed to get ml capabilities: %d\n", ret);
+ goto err_ml_cap;
+ }
+ }
if (dma_set_mask_and_coherent(dev, DMA_BIT_MASK(64)))
dma_set_mask_and_coherent(dev, DMA_BIT_MASK(32));
@@ -469,6 +474,8 @@ static int avs_pci_probe(struct pci_dev *pci, const struct pci_device_id *id)
snd_hdac_bus_free_stream_pages(bus);
snd_hdac_ext_stream_free_all(bus);
err_init_streams:
+ snd_hdac_ext_link_free_all(bus);
+err_ml_cap:
iounmap(adev->dsp_ba);
err_remap_bar4:
iounmap(bus->remap_addr);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 404/982] bpf: Introduce might_sleep field in bpf_func_proto
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (402 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.1 403/982] ASoC: Intel: avs: Clean up the bus when fetching ML caps fails Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 405/982] bpf: Mark bpf_btf_find_by_name_kind() as sleepable Greg Kroah-Hartman
` (584 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Martin KaFai Lau, Yonghong Song,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yonghong Song <yhs@fb.com>
[ Upstream commit 01685c5bddaa6df3d662c8afed5e5289fcc68e5a ]
Introduce bpf_func_proto->might_sleep to indicate a particular helper
might sleep. This will make later check whether a helper might be
sleepable or not easier.
Acked-by: Martin KaFai Lau <martin.lau@kernel.org>
Signed-off-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/r/20221124053211.2373553-1-yhs@fb.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Stable-dep-of: 620614bf7672 ("bpf: Mark bpf_btf_find_by_name_kind() as sleepable")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/bpf.h | 1 +
kernel/bpf/bpf_lsm.c | 6 ++++--
kernel/bpf/helpers.c | 2 ++
kernel/bpf/verifier.c | 5 +++++
kernel/trace/bpf_trace.c | 4 ++--
5 files changed, 14 insertions(+), 4 deletions(-)
diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index 436d862682916..92884bf344f8c 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -616,6 +616,7 @@ struct bpf_func_proto {
u64 (*func)(u64 r1, u64 r2, u64 r3, u64 r4, u64 r5);
bool gpl_only;
bool pkt_access;
+ bool might_sleep;
enum bpf_return_type ret_type;
union {
struct {
diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
index 61e93253b6b5e..e7e195a2e5f98 100644
--- a/kernel/bpf/bpf_lsm.c
+++ b/kernel/bpf/bpf_lsm.c
@@ -179,6 +179,7 @@ BTF_ID_LIST_SINGLE(bpf_ima_inode_hash_btf_ids, struct, inode)
static const struct bpf_func_proto bpf_ima_inode_hash_proto = {
.func = bpf_ima_inode_hash,
.gpl_only = false,
+ .might_sleep = true,
.ret_type = RET_INTEGER,
.arg1_type = ARG_PTR_TO_BTF_ID,
.arg1_btf_id = &bpf_ima_inode_hash_btf_ids[0],
@@ -197,6 +198,7 @@ BTF_ID_LIST_SINGLE(bpf_ima_file_hash_btf_ids, struct, file)
static const struct bpf_func_proto bpf_ima_file_hash_proto = {
.func = bpf_ima_file_hash,
.gpl_only = false,
+ .might_sleep = true,
.ret_type = RET_INTEGER,
.arg1_type = ARG_PTR_TO_BTF_ID,
.arg1_btf_id = &bpf_ima_file_hash_btf_ids[0],
@@ -249,9 +251,9 @@ bpf_lsm_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog)
case BPF_FUNC_bprm_opts_set:
return &bpf_bprm_opts_set_proto;
case BPF_FUNC_ima_inode_hash:
- return prog->aux->sleepable ? &bpf_ima_inode_hash_proto : NULL;
+ return &bpf_ima_inode_hash_proto;
case BPF_FUNC_ima_file_hash:
- return prog->aux->sleepable ? &bpf_ima_file_hash_proto : NULL;
+ return &bpf_ima_file_hash_proto;
case BPF_FUNC_get_attach_cookie:
return bpf_prog_has_trampoline(prog) ? &bpf_get_attach_cookie_proto : NULL;
#ifdef CONFIG_NET
diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c
index cf422c80b30b3..4cd7854932944 100644
--- a/kernel/bpf/helpers.c
+++ b/kernel/bpf/helpers.c
@@ -661,6 +661,7 @@ BPF_CALL_3(bpf_copy_from_user, void *, dst, u32, size,
const struct bpf_func_proto bpf_copy_from_user_proto = {
.func = bpf_copy_from_user,
.gpl_only = false,
+ .might_sleep = true,
.ret_type = RET_INTEGER,
.arg1_type = ARG_PTR_TO_UNINIT_MEM,
.arg2_type = ARG_CONST_SIZE_OR_ZERO,
@@ -691,6 +692,7 @@ BPF_CALL_5(bpf_copy_from_user_task, void *, dst, u32, size,
const struct bpf_func_proto bpf_copy_from_user_task_proto = {
.func = bpf_copy_from_user_task,
.gpl_only = true,
+ .might_sleep = true,
.ret_type = RET_INTEGER,
.arg1_type = ARG_PTR_TO_UNINIT_MEM,
.arg2_type = ARG_CONST_SIZE_OR_ZERO,
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index c201435ddafd2..e2ce9f664a40a 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -7504,6 +7504,11 @@ static int check_helper_call(struct bpf_verifier_env *env, struct bpf_insn *insn
return -EINVAL;
}
+ if (!env->prog->aux->sleepable && fn->might_sleep) {
+ verbose(env, "helper call might sleep in a non-sleepable prog\n");
+ return -EINVAL;
+ }
+
/* With LD_ABS/IND some JITs save/restore skb from r1. */
changes_data = bpf_helper_changes_pkt_data(fn->func);
if (changes_data && fn->arg1_type != ARG_PTR_TO_CTX) {
diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
index 1d1a70d561965..fcddc223c3f06 100644
--- a/kernel/trace/bpf_trace.c
+++ b/kernel/trace/bpf_trace.c
@@ -1502,9 +1502,9 @@ bpf_tracing_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog)
case BPF_FUNC_get_task_stack:
return &bpf_get_task_stack_proto;
case BPF_FUNC_copy_from_user:
- return prog->aux->sleepable ? &bpf_copy_from_user_proto : NULL;
+ return &bpf_copy_from_user_proto;
case BPF_FUNC_copy_from_user_task:
- return prog->aux->sleepable ? &bpf_copy_from_user_task_proto : NULL;
+ return &bpf_copy_from_user_task_proto;
case BPF_FUNC_snprintf_btf:
return &bpf_snprintf_btf_proto;
case BPF_FUNC_per_cpu_ptr:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 405/982] bpf: Mark bpf_btf_find_by_name_kind() as sleepable
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (403 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 404/982] bpf: Introduce might_sleep field in bpf_func_proto Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 406/982] selftests/bpf: Update tests for new ct zone opts for nf_conntrack kfuncs Greg Kroah-Hartman
` (583 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Kumar Kartikeya Dwivedi,
Eduard Zingerman, Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 620614bf7672130c43b3cff375525a2202f61979 ]
When bpf_btf_find_by_name_kind() finds a type in module BTF, it
returns a new BTF object fd through __btf_new_fd(). This reaches
anon_inode_getfd(), which can sleep while allocating or expanding the
current task fd table.
The helper prototype does not set might_sleep, so the verifier allows
the helper in non-sleepable contexts such as BPF timer callbacks. The
fd allocation can then sleep in softirq context and install the fd into
the interrupted task.
Mark the helper as sleepable. This preserves calls from the main body
of a sleepable syscall program while rejecting calls from its
non-sleepable regions.
Fixes: 3d78417b60fb ("bpf: Add bpf_btf_find_by_name_kind() helper.")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/bpf/20260903155150.D57251F000E9@smtp.kernel.org
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260903214758.2727663-4-memxor@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index cf6883e7b158f..4fa37f58d97dd 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -7328,6 +7328,7 @@ BPF_CALL_4(bpf_btf_find_by_name_kind, char *, name, int, name_sz, u32, kind, int
const struct bpf_func_proto bpf_btf_find_by_name_kind_proto = {
.func = bpf_btf_find_by_name_kind,
.gpl_only = false,
+ .might_sleep = true,
.ret_type = RET_INTEGER,
.arg1_type = ARG_PTR_TO_MEM | MEM_RDONLY,
.arg2_type = ARG_CONST_SIZE,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 406/982] selftests/bpf: Update tests for new ct zone opts for nf_conntrack kfuncs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (404 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 405/982] bpf: Mark bpf_btf_find_by_name_kind() as sleepable Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 407/982] selftests/bpf: Fix flaky bpf_nf test when random NAT port is 0 Greg Kroah-Hartman
` (582 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Brad Cowie, Martin KaFai Lau,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Brad Cowie <brad@faucet.nz>
[ Upstream commit a87f34e742d279d54d529e4bc4763fdaab32a466 ]
Add test for allocating and looking up ct entry in a
non-default ct zone with kfuncs bpf_{xdp,skb}_ct_alloc
and bpf_{xdp,skb}_ct_lookup.
Add negative tests for looking up ct entry in a different
ct zone to where it was allocated and with a different
direction.
Update reserved test for old struct definition to test for
ct_zone_id being set when opts size isn't NF_BPF_CT_OPTS_SZ (16).
Signed-off-by: Brad Cowie <brad@faucet.nz>
Link: https://lore.kernel.org/r/20240522050712.732558-2-brad@faucet.nz
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
Stable-dep-of: 5e8c349bc8d7 ("selftests/bpf: Fix flaky bpf_nf test when random NAT port is 0")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/config | 1 +
.../testing/selftests/bpf/prog_tests/bpf_nf.c | 7 ++
.../testing/selftests/bpf/progs/test_bpf_nf.c | 108 ++++++++++++++++++
3 files changed, 116 insertions(+)
diff --git a/tools/testing/selftests/bpf/config b/tools/testing/selftests/bpf/config
index 59cec4244b3a7..93cd02c417fc2 100644
--- a/tools/testing/selftests/bpf/config
+++ b/tools/testing/selftests/bpf/config
@@ -62,6 +62,7 @@ CONFIG_NETFILTER_XT_MATCH_STATE=y
CONFIG_NETFILTER_XT_TARGET_CT=y
CONFIG_NF_CONNTRACK=y
CONFIG_NF_CONNTRACK_MARK=y
+CONFIG_NF_CONNTRACK_ZONES=y
CONFIG_NF_DEFRAG_IPV4=y
CONFIG_NF_DEFRAG_IPV6=y
CONFIG_NF_NAT=y
diff --git a/tools/testing/selftests/bpf/prog_tests/bpf_nf.c b/tools/testing/selftests/bpf/prog_tests/bpf_nf.c
index f80660c00a1a7..fad98f01e2c06 100644
--- a/tools/testing/selftests/bpf/prog_tests/bpf_nf.c
+++ b/tools/testing/selftests/bpf/prog_tests/bpf_nf.c
@@ -110,6 +110,7 @@ static void test_bpf_nf_ct(int mode)
ASSERT_EQ(skel->bss->test_einval_bpf_tuple, -EINVAL, "Test EINVAL for NULL bpf_tuple");
ASSERT_EQ(skel->bss->test_einval_reserved, -EINVAL, "Test EINVAL for reserved not set to 0");
+ ASSERT_EQ(skel->bss->test_einval_reserved_new, -EINVAL, "Test EINVAL for reserved in new struct not set to 0");
ASSERT_EQ(skel->bss->test_einval_netns_id, -EINVAL, "Test EINVAL for netns_id < -1");
ASSERT_EQ(skel->bss->test_einval_len_opts, -EINVAL, "Test EINVAL for len__opts != NF_BPF_CT_OPTS_SZ");
ASSERT_EQ(skel->bss->test_eproto_l4proto, -EPROTO, "Test EPROTO for l4proto != TCP or UDP");
@@ -128,6 +129,12 @@ static void test_bpf_nf_ct(int mode)
ASSERT_EQ(skel->bss->test_exist_lookup_mark, 43, "Test existing connection lookup ctmark");
ASSERT_EQ(skel->data->test_snat_addr, 0, "Test for source natting");
ASSERT_EQ(skel->data->test_dnat_addr, 0, "Test for destination natting");
+ ASSERT_EQ(skel->data->test_ct_zone_id_alloc_entry, 0, "Test for alloc new entry in specified ct zone");
+ ASSERT_EQ(skel->data->test_ct_zone_id_insert_entry, 0, "Test for insert new entry in specified ct zone");
+ ASSERT_EQ(skel->data->test_ct_zone_id_succ_lookup, 0, "Test for successful lookup in specified ct_zone");
+ ASSERT_EQ(skel->bss->test_ct_zone_dir_enoent_lookup, -ENOENT, "Test ENOENT for lookup with wrong ct zone dir");
+ ASSERT_EQ(skel->bss->test_ct_zone_id_enoent_lookup, -ENOENT, "Test ENOENT for lookup in wrong ct zone");
+
end:
if (client_fd != -1)
close(client_fd);
diff --git a/tools/testing/selftests/bpf/progs/test_bpf_nf.c b/tools/testing/selftests/bpf/progs/test_bpf_nf.c
index 9fc603c9d673e..87ea551a7db6c 100644
--- a/tools/testing/selftests/bpf/progs/test_bpf_nf.c
+++ b/tools/testing/selftests/bpf/progs/test_bpf_nf.c
@@ -9,10 +9,14 @@
#define EINVAL 22
#define ENOENT 2
+#define NF_CT_ZONE_DIR_ORIG (1 << IP_CT_DIR_ORIGINAL)
+#define NF_CT_ZONE_DIR_REPL (1 << IP_CT_DIR_REPLY)
+
extern unsigned long CONFIG_HZ __kconfig;
int test_einval_bpf_tuple = 0;
int test_einval_reserved = 0;
+int test_einval_reserved_new = 0;
int test_einval_netns_id = 0;
int test_einval_len_opts = 0;
int test_eproto_l4proto = 0;
@@ -22,6 +26,11 @@ int test_eafnosupport = 0;
int test_alloc_entry = -EINVAL;
int test_insert_entry = -EAFNOSUPPORT;
int test_succ_lookup = -ENOENT;
+int test_ct_zone_id_alloc_entry = -EINVAL;
+int test_ct_zone_id_insert_entry = -EAFNOSUPPORT;
+int test_ct_zone_id_succ_lookup = -ENOENT;
+int test_ct_zone_dir_enoent_lookup = 0;
+int test_ct_zone_id_enoent_lookup = 0;
u32 test_delta_timeout = 0;
u32 test_status = 0;
u32 test_insert_lookup_mark = 0;
@@ -45,6 +54,17 @@ struct bpf_ct_opts___local {
s32 netns_id;
s32 error;
u8 l4proto;
+ u8 dir;
+ u8 reserved[2];
+};
+
+struct bpf_ct_opts___new {
+ s32 netns_id;
+ s32 error;
+ u8 l4proto;
+ u8 dir;
+ u16 ct_zone_id;
+ u8 ct_zone_dir;
u8 reserved[3];
} __attribute__((preserve_access_index));
@@ -221,10 +241,97 @@ nf_ct_test(struct nf_conn *(*lookup_fn)(void *, struct bpf_sock_tuple *, u32,
}
}
+static __always_inline void
+nf_ct_opts_new_test(struct nf_conn *(*lookup_fn)(void *, struct bpf_sock_tuple *, u32,
+ struct bpf_ct_opts___new *, u32),
+ struct nf_conn *(*alloc_fn)(void *, struct bpf_sock_tuple *, u32,
+ struct bpf_ct_opts___new *, u32),
+ void *ctx)
+{
+ struct bpf_ct_opts___new opts_def = { .l4proto = IPPROTO_TCP, .netns_id = -1 };
+ struct bpf_sock_tuple bpf_tuple;
+ struct nf_conn *ct;
+
+ __builtin_memset(&bpf_tuple, 0, sizeof(bpf_tuple.ipv4));
+
+ opts_def.reserved[0] = 1;
+ ct = lookup_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4), &opts_def,
+ sizeof(opts_def));
+ opts_def.reserved[0] = 0;
+ if (ct)
+ bpf_ct_release(ct);
+ else
+ test_einval_reserved_new = opts_def.error;
+
+ bpf_tuple.ipv4.saddr = bpf_get_prandom_u32(); /* src IP */
+ bpf_tuple.ipv4.daddr = bpf_get_prandom_u32(); /* dst IP */
+ bpf_tuple.ipv4.sport = bpf_get_prandom_u32(); /* src port */
+ bpf_tuple.ipv4.dport = bpf_get_prandom_u32(); /* dst port */
+
+ /* use non-default ct zone */
+ opts_def.ct_zone_id = 10;
+ opts_def.ct_zone_dir = NF_CT_ZONE_DIR_ORIG;
+ ct = alloc_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4), &opts_def,
+ sizeof(opts_def));
+ if (ct) {
+ __u16 sport = bpf_get_prandom_u32();
+ __u16 dport = bpf_get_prandom_u32();
+ union nf_inet_addr saddr = {};
+ union nf_inet_addr daddr = {};
+ struct nf_conn *ct_ins;
+
+ bpf_ct_set_timeout(ct, 10000);
+
+ /* snat */
+ saddr.ip = bpf_get_prandom_u32();
+ bpf_ct_set_nat_info(ct, &saddr, sport, NF_NAT_MANIP_SRC___local);
+ /* dnat */
+ daddr.ip = bpf_get_prandom_u32();
+ bpf_ct_set_nat_info(ct, &daddr, dport, NF_NAT_MANIP_DST___local);
+
+ ct_ins = bpf_ct_insert_entry(ct);
+ if (ct_ins) {
+ struct nf_conn *ct_lk;
+
+ /* entry should exist in same ct zone we inserted it */
+ ct_lk = lookup_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4),
+ &opts_def, sizeof(opts_def));
+ if (ct_lk) {
+ bpf_ct_release(ct_lk);
+ test_ct_zone_id_succ_lookup = 0;
+ }
+
+ /* entry should not exist with wrong direction */
+ opts_def.ct_zone_dir = NF_CT_ZONE_DIR_REPL;
+ ct_lk = lookup_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4),
+ &opts_def, sizeof(opts_def));
+ opts_def.ct_zone_dir = NF_CT_ZONE_DIR_ORIG;
+ if (ct_lk)
+ bpf_ct_release(ct_lk);
+ else
+ test_ct_zone_dir_enoent_lookup = opts_def.error;
+
+ /* entry should not exist in default ct zone */
+ opts_def.ct_zone_id = 0;
+ ct_lk = lookup_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4),
+ &opts_def, sizeof(opts_def));
+ if (ct_lk)
+ bpf_ct_release(ct_lk);
+ else
+ test_ct_zone_id_enoent_lookup = opts_def.error;
+
+ bpf_ct_release(ct_ins);
+ test_ct_zone_id_insert_entry = 0;
+ }
+ test_ct_zone_id_alloc_entry = 0;
+ }
+}
+
SEC("xdp")
int nf_xdp_ct_test(struct xdp_md *ctx)
{
nf_ct_test((void *)bpf_xdp_ct_lookup, (void *)bpf_xdp_ct_alloc, ctx);
+ nf_ct_opts_new_test((void *)bpf_xdp_ct_lookup, (void *)bpf_xdp_ct_alloc, ctx);
return 0;
}
@@ -232,6 +339,7 @@ SEC("tc")
int nf_skb_ct_test(struct __sk_buff *ctx)
{
nf_ct_test((void *)bpf_skb_ct_lookup, (void *)bpf_skb_ct_alloc, ctx);
+ nf_ct_opts_new_test((void *)bpf_skb_ct_lookup, (void *)bpf_skb_ct_alloc, ctx);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 407/982] selftests/bpf: Fix flaky bpf_nf test when random NAT port is 0
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (405 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 406/982] selftests/bpf: Update tests for new ct zone opts for nf_conntrack kfuncs Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 408/982] nexthop: Initialize extack in remove_nh_grp_entry() Greg Kroah-Hartman
` (581 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Alexei Starovoitov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 5e8c349bc8d790fe031a4332e502f5d4f9878644 ]
The bpf_nf test allocs a ct, sets snat and dnat with random addr and
port via bpf_ct_set_nat_info(), then looks the ct up and checks the
reply tuple against what was set.
The port comes from bpf_get_prandom_u32() and can be 0. For
bpf_ct_set_nat_info(), port 0 means "port not specified", so only the
addr is mapped and the kernel keeps the original port. The check then
compares that port with 0 and fails, which shows up as a flaky
"Test for source natting" failure in CI [1][2].
Keep the random port in 1..65535 so it is always specified.
[1] https://github.com/kernel-patches/bpf/actions/runs/33830002889/job/100893868791
[2] https://github.com/kernel-patches/bpf/actions/runs/33829976794/job/100893220999
Fixes: b06b45e82b59 ("selftests/bpf: add tests for bpf_ct_set_nat_info kfunc")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/20260904073745.363314-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/progs/test_bpf_nf.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/tools/testing/selftests/bpf/progs/test_bpf_nf.c b/tools/testing/selftests/bpf/progs/test_bpf_nf.c
index 87ea551a7db6c..2dc3ee964ee87 100644
--- a/tools/testing/selftests/bpf/progs/test_bpf_nf.c
+++ b/tools/testing/selftests/bpf/progs/test_bpf_nf.c
@@ -171,8 +171,8 @@ nf_ct_test(struct nf_conn *(*lookup_fn)(void *, struct bpf_sock_tuple *, u32,
ct = alloc_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4), &opts_def,
sizeof(opts_def));
if (ct) {
- __u16 sport = bpf_get_prandom_u32();
- __u16 dport = bpf_get_prandom_u32();
+ __u16 sport = bpf_get_prandom_u32() % 65535 + 1;
+ __u16 dport = bpf_get_prandom_u32() % 65535 + 1;
union nf_inet_addr saddr = {};
union nf_inet_addr daddr = {};
struct nf_conn *ct_ins;
@@ -274,8 +274,8 @@ nf_ct_opts_new_test(struct nf_conn *(*lookup_fn)(void *, struct bpf_sock_tuple *
ct = alloc_fn(ctx, &bpf_tuple, sizeof(bpf_tuple.ipv4), &opts_def,
sizeof(opts_def));
if (ct) {
- __u16 sport = bpf_get_prandom_u32();
- __u16 dport = bpf_get_prandom_u32();
+ __u16 sport = bpf_get_prandom_u32() % 65535 + 1;
+ __u16 dport = bpf_get_prandom_u32() % 65535 + 1;
union nf_inet_addr saddr = {};
union nf_inet_addr daddr = {};
struct nf_conn *ct_ins;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 408/982] nexthop: Initialize extack in remove_nh_grp_entry()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (406 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 407/982] selftests/bpf: Fix flaky bpf_nf test when random NAT port is 0 Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 409/982] bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit() Greg Kroah-Hartman
` (580 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit 5bd9e4e7cdaa03879e9b73b12ab52cceb1edd55b ]
remove_nh_grp_entry() prints the extack message when a listener fails
to replace the reduced nexthop group. However, extack is not
initialized and listeners are not required to set a message when
returning an error. Neither netdevsim nor mlxsw do so when an
allocation fails, resulting in the dereference of an uninitialized
stack pointer.
Fix by zero-initializing extack, as was done in commit 6347c5314cee
("nexthop: initialize extack in nh_res_bucket_migrate()").
Fixes: 833a1065eeb1 ("nexthop: Emit a notification when a nexthop group is reduced")
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260903080259.10378-1-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/nexthop.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c
index 13a798f9dc9cb..cd93dd74608ac 100644
--- a/net/ipv4/nexthop.c
+++ b/net/ipv4/nexthop.c
@@ -1736,7 +1736,7 @@ static void remove_nh_grp_entry(struct net *net, struct nh_grp_entry *nhge,
{
struct nh_grp_entry *nhges, *new_nhges;
struct nexthop *nhp = nhge->nh_parent;
- struct netlink_ext_ack extack;
+ struct netlink_ext_ack extack = {};
struct nexthop *nh = nhge->nh;
struct nh_group *nhg, *newg;
int i, j, err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 409/982] bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (407 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 408/982] nexthop: Initialize extack in remove_nh_grp_entry() Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 410/982] net: dsa: bcm_sf2: bound the CFP rule dump by the callers buffer size Greg Kroah-Hartman
` (579 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jay Vosburgh, Nikolay Aleksandrov, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 1746ef2e2df2ad71c66eca56364d56bde284523b ]
In bond_do_alb_xmit() and rlb_arp_xmit(), make sure to unclone
skb head via skb_cow_head() before modifying the source MAC address
(Ethernet header and ARP payload) to avoid silent corruption if
the skb is shared or cloned. Avoid caching the header pointers
across skb_cow_head().
In rlb_arp_xmit(), only modify arp->mac_src if it differs from
tx_slave->dev->dev_addr to avoid an unnecessary copy and head
reallocation.
Also, we should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue,
and remove now redundant skb_reset_mac_header() calls.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Cc: Jay Vosburgh <jv@jvosburgh.net>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260903143940.1180513-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/bonding/bond_alb.c | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/drivers/net/bonding/bond_alb.c b/drivers/net/bonding/bond_alb.c
index 8930652efe321..db2278e7b1330 100644
--- a/drivers/net/bonding/bond_alb.c
+++ b/drivers/net/bonding/bond_alb.c
@@ -678,9 +678,15 @@ static struct slave *rlb_arp_xmit(struct sk_buff *skb, struct bonding *bond)
if (arp->op_code == htons(ARPOP_REPLY)) {
/* the arp must be sent on the selected rx channel */
tx_slave = rlb_choose_channel(skb, bond, arp);
- if (tx_slave)
+ if (tx_slave &&
+ !ether_addr_equal_64bits(arp->mac_src,
+ tx_slave->dev->dev_addr)) {
+ if (unlikely(skb_cow_head(skb, 0)))
+ return NULL;
+ arp = (struct arp_pkt *)skb_network_header(skb);
bond_hw_addr_copy(arp->mac_src, tx_slave->dev->dev_addr,
tx_slave->dev->addr_len);
+ }
netdev_dbg(bond->dev, "(slave %s): Server sent ARP Reply packet\n",
tx_slave ? tx_slave->dev->name : "NULL");
} else if (arp->op_code == htons(ARPOP_REQUEST)) {
@@ -1341,7 +1347,6 @@ static netdev_tx_t bond_do_alb_xmit(struct sk_buff *skb, struct bonding *bond,
struct slave *tx_slave)
{
struct alb_bond_info *bond_info = &(BOND_ALB_INFO(bond));
- struct ethhdr *eth_data = eth_hdr(skb);
if (!tx_slave) {
/* unbalanced or unassigned, send through primary */
@@ -1352,7 +1357,9 @@ static netdev_tx_t bond_do_alb_xmit(struct sk_buff *skb, struct bonding *bond,
if (tx_slave && bond_slave_can_tx(tx_slave)) {
if (tx_slave != rcu_access_pointer(bond->curr_active_slave)) {
- ether_addr_copy(eth_data->h_source,
+ if (unlikely(skb_cow_head(skb, 0)))
+ return bond_tx_drop(bond->dev, skb);
+ ether_addr_copy(skb_eth_hdr(skb)->h_source,
tx_slave->dev->dev_addr);
}
@@ -1376,8 +1383,7 @@ struct slave *bond_xmit_tlb_slave_get(struct bonding *bond,
struct ethhdr *eth_data;
u32 hash_index;
- skb_reset_mac_header(skb);
- eth_data = eth_hdr(skb);
+ eth_data = skb_eth_hdr(skb);
/* Do not TX balance any multicast or broadcast */
if (!is_multicast_ether_addr(eth_data->h_dest)) {
@@ -1429,8 +1435,7 @@ struct slave *bond_xmit_alb_slave_get(struct bonding *bond,
u32 hash_index = 0;
int hash_size = 0;
- skb_reset_mac_header(skb);
- eth_data = eth_hdr(skb);
+ eth_data = skb_eth_hdr(skb);
switch (ntohs(skb->protocol)) {
case ETH_P_IP: {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 410/982] net: dsa: bcm_sf2: bound the CFP rule dump by the callers buffer size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (408 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 409/982] bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit() Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 411/982] net: dsa: mv88e6xxx: bound the policy " Greg Kroah-Hartman
` (578 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jonas Gorski, Florian Fainelli,
Joe Damato, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit cdb719f4b8596d9ccee2d56d204c2c4dce982f46 ]
bcm_sf2_cfp_rule_get_all() walks the whole cfp.unique bitmap into
rule_locs[] without consulting nfc->rule_cnt, which is how many entries
the caller had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN
and the ioctl sizes the buffer from the rule_cnt userspace passes in, so
once an admin has installed CFP rules any user can ask for fewer slots
than there are rules and run off the end of the allocation. A rule_cnt
of 0 leaves the buffer pointer NULL and the walk dereferences it.
Fixes: 7318166cacad ("net: dsa: bcm_sf2: Add support for ethtool::rxnfc")
Reviewed-by: Jonas Gorski <jonas.gorski@gmail.com>
Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260903032611.3000029-2-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/bcm_sf2_cfp.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/dsa/bcm_sf2_cfp.c b/drivers/net/dsa/bcm_sf2_cfp.c
index c4010b7bf0899..f48ac7b021f37 100644
--- a/drivers/net/dsa/bcm_sf2_cfp.c
+++ b/drivers/net/dsa/bcm_sf2_cfp.c
@@ -1088,6 +1088,8 @@ static int bcm_sf2_cfp_rule_get_all(struct bcm_sf2_priv *priv,
unsigned int index = 1, rules_cnt = 0;
for_each_set_bit_from(index, priv->cfp.unique, priv->num_cfp_rules) {
+ if (rules_cnt == nfc->rule_cnt)
+ return -EMSGSIZE;
rule_locs[rules_cnt] = index;
rules_cnt++;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 411/982] net: dsa: mv88e6xxx: bound the policy rule dump by the callers buffer size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (409 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 410/982] net: dsa: bcm_sf2: bound the CFP rule dump by the callers buffer size Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 412/982] octeontx2-af: mcs: Clear stale X2P calibration state before calibration Greg Kroah-Hartman
` (577 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Joe Damato, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit b1fffc273112e7284c5b705e186b43b5770cd3d5 ]
mv88e6xxx_get_rxnfc() uses rxnfc->rule_cnt as the write index while
dumping the policy IDR, clobbering the input value before it has been
looked at. That input is the number of entries the caller had room for.
ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the ioctl sizes the
buffer from the rule_cnt userspace passes in, so once an admin has
installed policy rules any user can ask for fewer slots than there are
rules and run off the end of the allocation. A rule_cnt of 0 leaves the
buffer pointer NULL and the walk dereferences it.
Count into a local so the caller's limit survives the walk, and stop with
-EMSGSIZE once it is reached.
Fixes: da7dc8755304 ("net: dsa: mv88e6xxx: add RXNFC support")
Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260903032611.3000029-5-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mv88e6xxx/chip.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 17390a004c0e9..9ccf9b7cb6256 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -2361,6 +2361,7 @@ static int mv88e6xxx_get_rxnfc(struct dsa_switch *ds, int port,
struct ethtool_rx_flow_spec *fs = &rxnfc->fs;
struct mv88e6xxx_chip *chip = ds->priv;
struct mv88e6xxx_policy *policy;
+ u32 cnt = 0;
int err;
int id;
@@ -2386,11 +2387,18 @@ static int mv88e6xxx_get_rxnfc(struct dsa_switch *ds, int port,
break;
case ETHTOOL_GRXCLSRLALL:
rxnfc->data = 0;
- rxnfc->rule_cnt = 0;
- idr_for_each_entry(&chip->policies, policy, id)
- if (policy->port == port)
- rule_locs[rxnfc->rule_cnt++] = id;
err = 0;
+ idr_for_each_entry(&chip->policies, policy, id) {
+ if (policy->port != port)
+ continue;
+ if (cnt == rxnfc->rule_cnt) {
+ err = -EMSGSIZE;
+ break;
+ }
+ rule_locs[cnt++] = id;
+ }
+ if (!err)
+ rxnfc->rule_cnt = cnt;
break;
default:
err = -EOPNOTSUPP;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 412/982] octeontx2-af: mcs: Clear stale X2P calibration state before calibration
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (410 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 411/982] net: dsa: mv88e6xxx: bound the policy " Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 413/982] net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow Greg Kroah-Hartman
` (576 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nitin Shetty J, Viswajith Murali,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viswajith Murali <viswajithm@marvell.com>
[ Upstream commit 1f29543126dde307e8b5fb6a740c54e59deaa2ff ]
Some firmware versions leave MCSX_MIL_GLOBAL bit 5 set on boot.
If the bit is already set when the driver attempts X2P calibration,
the hardware sees no rising edge and calibration never triggers.
Clear the bit and wait briefly before starting calibration to ensure
a clean rising edge.
Fixes: ca7f49ff8846 ("octeontx2-af: cn10k: Introduce driver for macsec block.")
Signed-off-by: Nitin Shetty J <nshettyj@marvell.com>
Signed-off-by: Viswajith Murali <viswajithm@marvell.com>
Link: https://patch.msgid.link/20260901094318.1395356-1-nshettyj@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/marvell/octeontx2/af/mcs.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/mcs.c b/drivers/net/ethernet/marvell/octeontx2/af/mcs.c
index a07e0b3d8d000..211c10aa5880f 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/mcs.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/mcs.c
@@ -1417,6 +1417,16 @@ static int mcs_x2p_calibration(struct mcs *mcs)
int i, err = 0;
u64 val;
+ /* Clear any stale calibration state left by firmware/bootloader.
+ * Some firmware versions may leave MCSX_MIL_GLOBAL bit 5 set,
+ * preventing the hardware from detecting the rising edge needed to
+ * trigger X2P calibration.
+ */
+ val = mcs_reg_read(mcs, MCSX_MIL_GLOBAL);
+ val &= ~BIT_ULL(5);
+ mcs_reg_write(mcs, MCSX_MIL_GLOBAL, val);
+ usleep_range(100, 200);
+
/* set X2P calibration */
val = mcs_reg_read(mcs, MCSX_MIL_GLOBAL);
val |= BIT_ULL(5);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 413/982] net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (411 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 412/982] octeontx2-af: mcs: Clear stale X2P calibration state before calibration Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 414/982] vxlan: reject dynamic fdb entries that reference a nexthop id Greg Kroah-Hartman
` (575 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Winter, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Winter <jjx@live.nl>
[ Upstream commit 5d50e90add8b4a978395e893e81954d19d58a7c5 ]
The 0xffff length sentinel detects a router reboot and schedules
re-enabling of ethernet mode, but then falls through to the rest
of the loop body. The next check is
} else if (len > CX82310_MTU) {
which is the else of the just-matched if -- it never fires for
len == 0xffff. The MTU bound that normally caps the
incomplete-packet save path is silently bypassed.
With 0xffff > skb->len always true (rx_urb_size is 4096), the
incomplete-packet branch saves dev->partial_len = skb->len bytes
into dev->partial_data. partial_data is kmalloc(hard_mtu) =
kmalloc(CX82310_MTU + 2) = 1516 bytes, but skb->len after the
2-byte header pull can be up to 4094. A device that sends a
4096-byte URB starting with [0xff 0xff] therefore copies 4094
device-provided bytes into a buffer allocated for 1516 bytes,
exceeding its requested size by 2578 bytes.
The next URB then reads dev->partial_len (4094) back from the same
1516-byte buffer and dev->partial_rem (65535 - 4094 = 61441) from
the new URB's ~4KB skb, both well past their allocations, and
delivers the spliced result as a 64KB "frame" to the network
stack.
Bail out of rx_fixup after scheduling the re-enable work; the
remainder of a reboot-marker URB is not meaningful packet data.
This restores the invariant that partial_len < CX82310_MTU + 2 on
the save path, since every other route there has already passed
the MTU check.
Fixes: ca139d76b0d9 ("cx82310_eth: re-enable ethernet mode after router reboot")
Signed-off-by: Jason Winter <jjx@live.nl>
Link: https://patch.msgid.link/BESP194MB283265DDDC63B6B78D8D34FBB8B72@BESP194MB2832.EURP194.PROD.OUTLOOK.COM
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/cx82310_eth.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/usb/cx82310_eth.c b/drivers/net/usb/cx82310_eth.c
index 79a47e2fd4378..840d014ac1aa8 100644
--- a/drivers/net/usb/cx82310_eth.c
+++ b/drivers/net/usb/cx82310_eth.c
@@ -282,6 +282,7 @@ static int cx82310_rx_fixup(struct usbnet *dev, struct sk_buff *skb)
if (len == 0xffff) {
netdev_info(dev->net, "router was rebooted, re-enabling ethernet mode");
schedule_work(&priv->reenable_work);
+ return 0;
} else if (len > CX82310_MTU) {
netdev_err(dev->net, "RX packet too long: %d B\n", len);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 414/982] vxlan: reject dynamic fdb entries that reference a nexthop id
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (412 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 413/982] net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 415/982] net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations Greg Kroah-Hartman
` (574 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Seungwon Bae,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Seungwon Bae <qotmddnjs@ajou.ac.kr>
[ Upstream commit 98fc57d167446b95b4e719815fe79edef93f8e7a ]
The commit cited in the Fixes tag allowed VXLAN FDB entries to point to
FDB nexthops so that overlay traffic could be load balanced across
multiple VTEPs. Such entries can only be configured from user space,
cannot be learned and cannot roam. They only make sense with a user space
control plane such as E-VPN where data plane learning is disabled.
Despite that, the VXLAN driver does not currently prevent such entries
from being configured with the "dynamic" flag. The per-nexthop FDB list
is only protected by the per-device hash lock, which is not sufficient
when two VXLAN devices point to the same FDB nexthop and therefore share
the list. Aging runs in softirq context without RTNL, so an entry deleted
by one device can race with an addition or deletion from the other,
leading to list corruption:
list_del corruption. next->prev should be ffff8881069d9548, but was
dead000000000122. (next=ffff8881069d9448)
WARNING: CPU: 0 PID: 90 at lib/list_debug.c:65
__list_del_entry_valid_or_report+0x1aa/0x210
...
vxlan_fdb_destroy+0x5b8/0xad0
vxlan_cleanup+0x328/0x450
call_timer_fn+0x2a/0x1c0
run_timer_softirq+0x18c/0x210
BUG: KASAN: slab-use-after-free in vxlan_fdb_destroy
Fix this by rejecting the bogus configuration of dynamic FDB entries that
point to FDB nexthops, both when created and when an existing entry is
updated. As such, the per-nexthop FDB list is only ever mutated under the
RTNL lock. Add test cases to make sure that this does not regress in the
future.
Fixes: 1274e1cc4226 ("vxlan: ecmp support for mac fdb entries")
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Seungwon Bae <qotmddnjs@ajou.ac.kr>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260902155956.296699-1-qotmddnjs@ajou.ac.kr
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 11 ++++++++
tools/testing/selftests/net/fib_nexthops.sh | 28 +++++++++++++++++++++
2 files changed, 39 insertions(+)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 9684a3ab081b4..591a2875dfe2f 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -1054,6 +1054,12 @@ static int vxlan_fdb_update_existing(struct vxlan_dev *vxlan,
return -EOPNOTSUPP;
}
+ if (rcu_access_pointer(f->nh) &&
+ !(state & (NUD_PERMANENT | NUD_NOARP))) {
+ NL_SET_ERR_MSG(extack, "Cannot make a nexthop fdb dynamic");
+ return -EOPNOTSUPP;
+ }
+
/* Do not allow an externally learned entry to take over an entry added
* by the user.
*/
@@ -1321,6 +1327,11 @@ static int vxlan_fdb_add(struct ndmsg *ndm, struct nlattr *tb[],
if (err)
return err;
+ if (nhid && !(ndm->ndm_state & (NUD_PERMANENT | NUD_NOARP))) {
+ NL_SET_ERR_MSG(extack, "A nexthop fdb cannot be dynamic");
+ return -EINVAL;
+ }
+
if (vxlan->default_dst.remote_ip.sa.sa_family != ip.sa.sa_family)
return -EAFNOSUPPORT;
diff --git a/tools/testing/selftests/net/fib_nexthops.sh b/tools/testing/selftests/net/fib_nexthops.sh
index 543a35e5c9dfe..14476b96cbf46 100755
--- a/tools/testing/selftests/net/fib_nexthops.sh
+++ b/tools/testing/selftests/net/fib_nexthops.sh
@@ -476,6 +476,20 @@ ipv6_fdb_grp_fcnal()
run_cmd "$BRIDGE fdb add 02:02:00:00:00:14 dev vx10 nhid 61 self"
log_test $? 255 "Fdb mac add with nexthop"
+ # fdb entries with a nexthop group cannot be aged out
+ run_cmd "$BRIDGE fdb add 02:02:00:00:00:15 dev vx10 nhid 102 self static"
+ log_test $? 0 "Fdb mac add with nexthop group and static state"
+
+ run_cmd "$BRIDGE fdb add 02:02:00:00:00:16 dev vx10 nhid 102 self dynamic"
+ log_test $? 255 "Fdb mac add with nexthop group and dynamic state"
+
+ run_cmd "$BRIDGE fdb add 02:02:00:00:00:17 dev vx10 nhid 102 self"
+ run_cmd "$BRIDGE fdb replace 02:02:00:00:00:17 dev vx10 dst 2001:db8:91::11 self dynamic"
+ log_test $? 255 "Fdb mac replace with nexthop group and dynamic state"
+
+ run_cmd "$BRIDGE fdb append 02:02:00:00:00:17 dev vx10 dst 2001:db8:91::11 self dynamic"
+ log_test $? 255 "Fdb mac append with nexthop group and dynamic state"
+
run_cmd "$IP -6 ro add 2001:db8:101::1/128 nhid 66"
log_test $? 2 "Route add with fdb nexthop"
@@ -556,6 +570,20 @@ ipv4_fdb_grp_fcnal()
run_cmd "$BRIDGE fdb add 02:02:00:00:00:14 dev vx10 nhid 12 self"
log_test $? 255 "Fdb mac add with nexthop"
+ # fdb entries with a nexthop group cannot be aged out
+ run_cmd "$BRIDGE fdb add 02:02:00:00:00:15 dev vx10 nhid 102 self static"
+ log_test $? 0 "Fdb mac add with nexthop group and static state"
+
+ run_cmd "$BRIDGE fdb add 02:02:00:00:00:16 dev vx10 nhid 102 self dynamic"
+ log_test $? 255 "Fdb mac add with nexthop group and dynamic state"
+
+ run_cmd "$BRIDGE fdb add 02:02:00:00:00:17 dev vx10 nhid 102 self"
+ run_cmd "$BRIDGE fdb replace 02:02:00:00:00:17 dev vx10 dst 10.0.0.3 self dynamic"
+ log_test $? 255 "Fdb mac replace with nexthop group and dynamic state"
+
+ run_cmd "$BRIDGE fdb append 02:02:00:00:00:17 dev vx10 dst 10.0.0.3 self dynamic"
+ log_test $? 255 "Fdb mac append with nexthop group and dynamic state"
+
run_cmd "$IP ro add 172.16.0.0/22 nhid 16"
log_test $? 2 "Route add with fdb nexthop"
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 415/982] net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (413 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 414/982] vxlan: reject dynamic fdb entries that reference a nexthop id Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 416/982] powerpc/kexec_file: Use inclusive range checks in add_usable_mem() Greg Kroah-Hartman
` (573 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 66ab4c59b74db7ab53a1c9083feaaede393a96a0 ]
Several subsystems allocate ring buffers sized by dev->tx_queue_len
with no upper bound. An unprivileged user (via unshare -Urn) can set a
huge tx_queue_len and exhaust global memory with ring allocations:
- pfifo_fast: pfifo_fast_init() and pfifo_fast_change_tx_queue_len()
allocate 3 skb_array rings of tx_queue_len entries each.
- tun: tun_queue_resize() and the queue-attach path resize ptr_rings
to tx_queue_len on the NETDEV_CHANGE_TX_QUEUE_LEN notifier.
- tap (macvtap/ipvtap): tap_queue_resize() and tap_init() resize/init
ptr_rings to tx_queue_len on the same notifier.
netif_change_tx_queue_len() is the single entry point for IFLA_TXQLEN,
sysfs, and the SIOCSIFTXQLEN ioctl. Cap new_len at S16_MAX (32767)
there so the oversized value is rejected at set time. This takes
effect whether the device is up or down, before dev->tx_queue_len is
written, before any notifier fires, and before any ring is allocated.
The "> S16_MAX" check also subsumes the previous unsigned-long
truncation test, and a negative ifr_qlen from the ioctl lands far
above the cap after conversion, so both old failure modes are covered
by the one comparison.
tx_queue_len is ambigious: both a per-ring sizing multiplier and a
default queue-length/limit knob for consumers that allocate
nothing at set time (pfifo/bfifo/gred/plug/sfb limits, htb
direct_qlen, qfq max_classes, teql). 32767 is chosen as the largest
value NLA_POLICY_FULL_RANGE can express for the u32 IFLA_TXQLEN
policy in patch 2/3 while staying a legitimate queue length on
high-BDP paths; the ring-memory trade-off of a shared knob is
disclosed below.
Conditions to recreate the bug:
- CONFIG_NET_SCHED=y, CONFIG_VETH=y, CONFIG_USER_NS=y, CONFIG_NET_NS=y.
- Unprivileged user in a fresh user+net namespace (unshare -Urn).
- pfifo_fast: create veth pairs, set tx_queue_len to 500000, attach
mq+pfifo_fast. ~28 iterations OOMs a 2GB guest.
- tun: create 50 tun devices with IFF_MULTI_QUEUE, set tx_queue_len to
500000, open 8 queues each. ~1.6GB of ptr_ring allocations OOMs a
512MB guest.
- tap: same as tun with IFF_TAP. ~960MB OOMs a 512MB guest.
- On the fixed kernel the oversized tx_queue_len is rejected with
-ERANGE at set time (all four paths: RTM_SETLINK, RTM_NEWLINK
create, sysfs, ioctl - the latter two via this check, the former
two via this check and the 2/3 parse policy respectively).
Fixes: 6a643ddb5624 ("net: introduce helper dev_change_tx_queue_len()")
Reported-by: Vega <vega@nebusec.ai>
Closes: https://lore.kernel.org/netdev/20260828121902.66837-1-jhs@mojatatu.com/
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-2899.v2.20260901233641@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 87a252b13c5cf..270689c9f351a 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -8854,7 +8854,7 @@ int dev_change_tx_queue_len(struct net_device *dev, unsigned long new_len)
unsigned int orig_len = dev->tx_queue_len;
int res;
- if (new_len != (unsigned int)new_len)
+ if (new_len > S16_MAX)
return -ERANGE;
if (new_len != orig_len) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 416/982] powerpc/kexec_file: Use inclusive range checks in add_usable_mem()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (414 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 415/982] net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 417/982] net/sched: defer qdisc freeing after failed creation Greg Kroah-Hartman
` (572 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Sourabh Jain,
Madhavan Srinivasan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit c6755be4838d6ccd641effbcdc3d917b82631ff9 ]
add_usable_mem() adds usable memory ranges for the kdump kernel.
The ranges are inclusive, but the partial overlap check uses exclusive
comparisons. This skips ranges with base == loc_end or end == loc_base.
Use inclusive comparisons instead.
Fixes: 7c64e21a1c5a ("powerpc/kexec_file: Restrict memory usage of kdump kernel")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260809162403.18142-2-thorsten.blum@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kexec/file_load_64.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/kexec/file_load_64.c b/arch/powerpc/kexec/file_load_64.c
index 9e3382e824311..d2a54bdc48468 100644
--- a/arch/powerpc/kexec/file_load_64.c
+++ b/arch/powerpc/kexec/file_load_64.c
@@ -479,7 +479,7 @@ static int add_usable_mem(struct umem_info *um_info, u64 base, u64 end)
loc_end = um_info->ranges[i].end;
if (loc_base >= base && loc_end <= end)
add = true;
- else if (base < loc_end && end > loc_base) {
+ else if (base <= loc_end && end >= loc_base) {
if (loc_base < base)
loc_base = base;
if (loc_end > end)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 417/982] net/sched: defer qdisc freeing after failed creation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (415 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 416/982] powerpc/kexec_file: Use inclusive range checks in add_usable_mem() Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 418/982] net/mlx5e: Fix setting RS FEC after remapping Greg Kroah-Hartman
` (571 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit e6662f2100f8d33b0f4d0047c219efd6bba186ea ]
An RTM_NEWQDISC request can make clsact bind a populated shared ingress
block during ->init(), publishing an embedded mini_Qdisc to lockless
readers. If the same request has an invalid TCA_RATE, estimator setup
fails after ->init(); the unwind removes the pointer but synchronously
frees its containing qdisc while tc_run() may still hold it.
Retire failed qdiscs through the same RCU helper as normal destruction.
Inline the synchronous free into the callback now that no direct callers
remain.
Fixes: 51ab2994c387 ("net: sched: allow ingress and clsact qdiscs to share filter blocks")
Reported-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/netdev/20260805102505.740806-1-david.lee@trailofbits.com/
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/20260902155231.2149915-2-bestswngs@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/sch_generic.h | 2 +-
net/sched/sch_api.c | 2 +-
net/sched/sch_generic.c | 20 ++++++++++----------
3 files changed, 12 insertions(+), 12 deletions(-)
diff --git a/include/net/sch_generic.h b/include/net/sch_generic.h
index a0499bff7ff40..7ec1f5aa6adaf 100644
--- a/include/net/sch_generic.h
+++ b/include/net/sch_generic.h
@@ -721,7 +721,7 @@ void qdisc_offload_query_caps(struct net_device *dev,
struct Qdisc *qdisc_alloc(struct netdev_queue *dev_queue,
const struct Qdisc_ops *ops,
struct netlink_ext_ack *extack);
-void qdisc_free(struct Qdisc *qdisc);
+void qdisc_free_rcu(struct Qdisc *qdisc);
struct Qdisc *qdisc_create_dflt(struct netdev_queue *dev_queue,
const struct Qdisc_ops *ops, u32 parentid,
struct netlink_ext_ack *extack);
diff --git a/net/sched/sch_api.c b/net/sched/sch_api.c
index 104a186a4dc8b..48e956724d3b2 100644
--- a/net/sched/sch_api.c
+++ b/net/sched/sch_api.c
@@ -1372,7 +1372,7 @@ static struct Qdisc *qdisc_create(struct net_device *dev,
err_out3:
lockdep_unregister_key(&sch->root_lock_key);
netdev_put(dev, &sch->dev_tracker);
- qdisc_free(sch);
+ qdisc_free_rcu(sch);
err_out2:
module_put(ops->owner);
err_out:
diff --git a/net/sched/sch_generic.c b/net/sched/sch_generic.c
index 54041342f1c6d..f58ec57e31f46 100644
--- a/net/sched/sch_generic.c
+++ b/net/sched/sch_generic.c
@@ -1045,21 +1045,21 @@ void qdisc_reset(struct Qdisc *qdisc)
}
EXPORT_SYMBOL(qdisc_reset);
-void qdisc_free(struct Qdisc *qdisc)
+static void qdisc_free_cb(struct rcu_head *head)
{
- if (qdisc_is_percpu_stats(qdisc)) {
- free_percpu(qdisc->cpu_bstats);
- free_percpu(qdisc->cpu_qstats);
+ struct Qdisc *q = container_of(head, struct Qdisc, rcu);
+
+ if (qdisc_is_percpu_stats(q)) {
+ free_percpu(q->cpu_bstats);
+ free_percpu(q->cpu_qstats);
}
- kfree(qdisc);
+ kfree(q);
}
-static void qdisc_free_cb(struct rcu_head *head)
+void qdisc_free_rcu(struct Qdisc *qdisc)
{
- struct Qdisc *q = container_of(head, struct Qdisc, rcu);
-
- qdisc_free(q);
+ call_rcu(&qdisc->rcu, qdisc_free_cb);
}
static void __qdisc_destroy(struct Qdisc *qdisc)
@@ -1084,7 +1084,7 @@ static void __qdisc_destroy(struct Qdisc *qdisc)
trace_qdisc_destroy(qdisc);
- call_rcu(&qdisc->rcu, qdisc_free_cb);
+ qdisc_free_rcu(qdisc);
}
void qdisc_destroy(struct Qdisc *qdisc)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 418/982] net/mlx5e: Fix setting RS FEC after remapping
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (416 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 417/982] net/sched: defer qdisc freeing after failed creation Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 419/982] net/mlx5e: Fix ETS zero BW reporting when one TC holds 100% Greg Kroah-Hartman
` (570 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shahar Shitrit, Dragos Tatulea,
Yael Chemla, Tariq Toukan, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shahar Shitrit <shshitrit@nvidia.com>
[ Upstream commit b9d755c5a37519fb1354034db1dfeb30e1ba6856 ]
When a user sets a FEC mode via ethtool, the driver maps the ethtool
FEC type to the lowest mlx5 bit of that type. For RS FEC, this is
MLX5E_FEC_RS_528_514 (bit 2). The driver then checks whether this
bit is supported by at least one link mode by inspecting the
fec_override_cap fields via mlx5e_fec_in_caps(), and returns
-EOPNOTSUPP if not.
This check is incorrect. RS FEC has three supported hardware variants:
RS_528_514 (bit 2), RS_544_514_INTERLEAVED_QUAD (bit 4), and
RS_544_514 (bit 7). mlx5e_remap_fec_conf_mode() already remaps bit 2
to the appropriate RS variant per link mode when writing the admin
fields, but the early capability check is done against the raw
unmapped bit. As a result, a device that supports RS_544_514 or
RS_544_514_INTERLEAVED_QUAD but not RS_528_514 will incorrectly reject
the user's RS FEC request.
Remove the early support check from mlx5e_set_fec_mode() and fold
it into the existing write loop, checking caps against the remapped
policy per link mode. Return -EOPNOTSUPP before the final register
write if no link mode accepted the policy.
Fixes: 2608a2f831c4 ("net/mlx5e: Fix return status when setting unsupported FEC mode")
Signed-off-by: Shahar Shitrit <shshitrit@nvidia.com>
Reviewed-by: Dragos Tatulea <dtatulea@nvidia.com>
Reviewed-by: Yael Chemla <ychemla@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260902164634.3657606-3-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en/port.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/port.c b/drivers/net/ethernet/mellanox/mlx5/core/en/port.c
index 505ba41195b93..fe1428d3e57a9 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/port.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/port.c
@@ -614,6 +614,7 @@ int mlx5e_set_fec_mode(struct mlx5_core_dev *dev, u16 fec_policy)
u32 in[MLX5_ST_SZ_DW(pplm_reg)] = {};
int sz = MLX5_ST_SZ_BYTES(pplm_reg);
u16 fec_policy_auto = 0;
+ bool fec_set = false;
int err;
int i;
@@ -626,9 +627,6 @@ int mlx5e_set_fec_mode(struct mlx5_core_dev *dev, u16 fec_policy)
if (fec_policy >= (1 << MLX5E_FEC_LLRS_272_257_1) && !fec_50g_per_lane)
return -EOPNOTSUPP;
- if (fec_policy && !mlx5e_fec_in_caps(dev, fec_policy))
- return -EOPNOTSUPP;
-
MLX5_SET(pplm_reg, in, local_port, 1);
err = mlx5_core_access_reg(dev, in, sz, out, sz, MLX5_REG_PPLM, 0, 0);
if (err)
@@ -655,12 +653,17 @@ int mlx5e_set_fec_mode(struct mlx5_core_dev *dev, u16 fec_policy)
mlx5e_get_fec_cap_field(out, &fec_caps, i);
/* policy supported for link speed */
- if (fec_caps & conf_fec)
+ if (fec_caps & conf_fec) {
mlx5e_fec_admin_field(out, &conf_fec, 1, i);
- else
- /* set FEC to auto*/
+ fec_set = true;
+ } else {
+ /* set FEC to auto */
mlx5e_fec_admin_field(out, &fec_policy_auto, 1, i);
+ }
}
+ if (fec_policy && !fec_set)
+ return -EOPNOTSUPP;
+
return mlx5_core_access_reg(dev, out, sz, out, sz, MLX5_REG_PPLM, 0, 1);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 419/982] net/mlx5e: Fix ETS zero BW reporting when one TC holds 100%
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (417 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 418/982] net/mlx5e: Fix setting RS FEC after remapping Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 420/982] net/mlx5e: Fix use-after-free race in sample_restore_put() Greg Kroah-Hartman
` (569 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Carolina Jubran, Alex Lazar,
Tariq Toukan, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carolina Jubran <cjubran@nvidia.com>
[ Upstream commit e7ee89740800a1cf253713e9249c3ee9203ebe91 ]
When ETS TCs with zero bandwidth are configured, the driver programs the
firmware using an alternate representation. On get, it needs
to recognize that representation so those TCs can be translated back and
reported as 0% bandwidth.
The existing detection relied on the programmed bandwidth because it was
enough to identify this representation. However, when a single ETS TC
owns 100% of the bandwidth, its firmware representation becomes the
same as a strict-priority TC, causing zero-bandwidth ETS TCs to be
reported with non-zero bandwidth values.
Use the cached TSA instead to distinguish the ETS and strict-priority
cases.
Fixes: be0f161ef141 ("net/mlx5e: DCBNL, Implement tc with ets type and zero bandwidth")
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Alex Lazar <alazar@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260902193224.3668743-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c b/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c
index 1a73fa436a136..4b331069fbcfe 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c
@@ -133,7 +133,7 @@ static int mlx5e_dcbnl_ieee_getets(struct net_device *netdev,
if (err)
return err;
- if (ets->tc_tx_bw[i] < MLX5E_MAX_BW_ALLOC &&
+ if (priv->dcbx.tc_tsa[i] == IEEE_8021QAZ_TSA_ETS &&
tc_group[i] == (MLX5E_LOWEST_PRIO_GROUP + 1))
is_zero_bw_ets_tc = true;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 420/982] net/mlx5e: Fix use-after-free race in sample_restore_put()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (418 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 419/982] net/mlx5e: Fix ETS zero BW reporting when one TC holds 100% Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 421/982] net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put Greg Kroah-Hartman
` (568 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Carolina Jubran, Shahar Shitrit,
Tariq Toukan, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carolina Jubran <cjubran@nvidia.com>
[ Upstream commit af3aef0245abbab5e9f6302e7a7d6407187afb71 ]
Concurrent teardown of TC sample rules sharing the same restore
context may re-read restore->count after dropping restore_lock.
At that point another thread may already have completed cleanup and
freed the restore object.
Use the result of the refcount decrement while holding restore_lock to
determine whether cleanup is needed.
Fixes: 36a3196256bf ("net/mlx5e: TC, Add sampler restore handle API")
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Shahar Shitrit <shshitrit@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260902193341.3668809-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en/tc/sample.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/tc/sample.c b/drivers/net/ethernet/mellanox/mlx5/core/en/tc/sample.c
index c57b097275241..705455472d96a 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/tc/sample.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/tc/sample.c
@@ -311,12 +311,15 @@ sample_restore_get(struct mlx5e_tc_psample *tc_psample, u32 obj_id,
static void
sample_restore_put(struct mlx5e_tc_psample *tc_psample, struct mlx5e_sample_restore *restore)
{
+ bool last;
+
mutex_lock(&tc_psample->restore_lock);
- if (--restore->count == 0)
+ last = --restore->count == 0;
+ if (last)
hash_del(&restore->hlist);
mutex_unlock(&tc_psample->restore_lock);
- if (!restore->count) {
+ if (last) {
mlx5_del_flow_rules(restore->rule);
mlx5_modify_header_dealloc(tc_psample->esw->dev, restore->modify_hdr);
kfree(restore);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 421/982] net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (419 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 420/982] net/mlx5e: Fix use-after-free race in sample_restore_put() Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 422/982] net/mlx5: E-Switch, prevent mc_list repopulation during vport disable Greg Kroah-Hartman
` (567 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yael Chemla, Dragos Tatulea,
Tariq Toukan, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yael Chemla <ychemla@nvidia.com>
[ Upstream commit 7ee07f601f8f507c9faf25c68a49396ab8950596 ]
In mlx5_eswitch_termtbl_put(), the zero-ref cleanup check reads
tt->ref_count after termtbl_mutex has been released. Two concurrent
callers on the same mlx5_termtbl_handle race: one decrements ref_count
to zero, removes the hash entry, and calls kfree(tt) while the other
has already dropped the mutex and is about to evaluate
if (!tt->ref_count), producing a use-after-free.
Fix this by capturing the result of the decrement into a stack-local
last variable before dropping the mutex. The cleanup decision is now
made entirely under termtbl_mutex, and tt is not touched after
kfree.
Fixes: 10caabdaad5a ("net/mlx5e: Use termination table for VLAN push actions")
Signed-off-by: Yael Chemla <ychemla@nvidia.com>
Reviewed-by: Dragos Tatulea <dtatulea@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260902193514.3668880-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../ethernet/mellanox/mlx5/core/eswitch_offloads_termtbl.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/eswitch_offloads_termtbl.c b/drivers/net/ethernet/mellanox/mlx5/core/eswitch_offloads_termtbl.c
index edd9102583144..cc59ad6d161ab 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/eswitch_offloads_termtbl.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/eswitch_offloads_termtbl.c
@@ -163,12 +163,15 @@ void
mlx5_eswitch_termtbl_put(struct mlx5_eswitch *esw,
struct mlx5_termtbl_handle *tt)
{
+ bool last;
+
mutex_lock(&esw->offloads.termtbl_mutex);
- if (--tt->ref_count == 0)
+ last = (--tt->ref_count == 0);
+ if (last)
hash_del(&tt->termtbl_hlist);
mutex_unlock(&esw->offloads.termtbl_mutex);
- if (!tt->ref_count) {
+ if (last) {
mlx5_del_flow_rules(tt->rule);
mlx5_destroy_flow_table(tt->termtbl);
kfree(tt);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 422/982] net/mlx5: E-Switch, prevent mc_list repopulation during vport disable
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (420 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 421/982] net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 423/982] net_sched: sch_fq_pie: implement lockless fq_pie_dump() Greg Kroah-Hartman
` (566 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lama Kayal, Cosmin Ratiu,
Tariq Toukan, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lama Kayal <lkayal@nvidia.com>
[ Upstream commit c0c6f4ba8a37688f7b4d4044898d88f0450d44c2 ]
In mlx5_esw_vport_disable(), move esw_apply_vport_rx_mode() ahead
of esw_vport_change_handle_locked() so vport->allmulti_rule is
NULL before the change handler observes it.
During FW-fatal recovery the disable runs while dev->state ==
INTERNAL_ERROR. The promisc query inside esw_update_vport_rx_mode()
fails and returns early, leaving vport->allmulti_rule intact, so
esw_update_vport_mc_promisc() runs and adds MLX5_ACTION_ADD entries
to vport->mc_list whose flow rules are then installed in the FDB
by esw_add_mc_addr(). esw_destroy_legacy_table() tears down the
FDB with those refs still held, corrupting the sub-tree and
leaving dangling flow_rule pointers in vport->mc_list.
Two-stage failure on `echo 1 > /sys/bus/pci/devices/<bdf>/reset`:
refcount_t: underflow; use-after-free.
tree_put_node+0xef/0x110 [mlx5_core]
clean_tree+0x44/0xd0 [mlx5_core] (x5)
mlx5_fs_core_cleanup+0x57/0x1c0 [mlx5_core]
mlx5_unload+0x65/0xd0 [mlx5_core]
... mlx5_health_try_recover
BUG: unable to handle page fault for address: 0000000003000055
down_write+0x1c/0x60
mlx5_del_flow_rules+0x33/0x1f0 [mlx5_core]
esw_del_mc_addr+0x7b/0x170 [mlx5_core]
esw_apply_vport_addr_list+0x56/0xf0 [mlx5_core]
esw_vport_change_handle_locked+0x28b/0x310 [mlx5_core]
mlx5_esw_vport_enable+0x270/0x4a0 [mlx5_core]
... mlx5_load ... mlx5_health_try_recover
esw_apply_vport_rx_mode(false, false) clears vport->allmulti_rule
via its local state machine even when the FW del fails. With the
rule NULL the !IS_ERR_OR_NULL(allmulti_rule) gate in the change
handler closes, no rules are installed during disable, and the
reload starts with a clean mc_list.
Fixes: 922f56e9a795 ("net/mlx5: Fix steering rules cleanup")
Signed-off-by: Lama Kayal <lkayal@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260902193854.3669035-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/eswitch.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/eswitch.c b/drivers/net/ethernet/mellanox/mlx5/core/eswitch.c
index 8b2b78f05cbe7..bf9869ee75236 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/eswitch.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/eswitch.c
@@ -910,13 +910,19 @@ void mlx5_esw_vport_disable(struct mlx5_eswitch *esw, u16 vport_num)
MLX5_CAP_GEN(esw->dev, vhca_resource_manager))
mlx5_esw_vport_vhca_id_clear(esw, vport_num);
+ /* Clear rx-mode before esw_vport_change_handle_locked(): on
+ * MLX5_VPORT_PROMISC_CHANGE it calls esw_update_vport_mc_promisc()
+ * when vport->allmulti_rule is set, repopulating mc_list with FDB
+ * rules that dangle once the FDB is destroyed. NULL allmulti_rule
+ * here skips that path.
+ */
+ esw_apply_vport_rx_mode(esw, vport, false, false);
/* We don't assume VFs will cleanup after themselves.
* Calling vport change handler while vport is disabled will cleanup
* the vport resources.
*/
esw_vport_change_handle_locked(vport);
vport->enabled_events = 0;
- esw_apply_vport_rx_mode(esw, vport, false, false);
esw_vport_cleanup(esw, vport);
esw->enabled_vports--;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 423/982] net_sched: sch_fq_pie: implement lockless fq_pie_dump()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (421 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 422/982] net/mlx5: E-Switch, prevent mc_list repopulation during vport disable Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 424/982] net/sched: fq_pie: clamp quantum in change path Greg Kroah-Hartman
` (565 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
David S. Miller, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 13a9965de32457d59aa3162d657aa4c5e512c146 ]
Instead of relying on RTNL, fq_pie_dump() can use READ_ONCE()
annotations, paired with WRITE_ONCE() ones in fq_pie_change().
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: 4864f58c53eb ("net/sched: fq_pie: clamp quantum in change path")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_fq_pie.c | 61 +++++++++++++++++++++++-------------------
1 file changed, 34 insertions(+), 27 deletions(-)
diff --git a/net/sched/sch_fq_pie.c b/net/sched/sch_fq_pie.c
index fc57b1daa235a..f8fb1d1af6abb 100644
--- a/net/sched/sch_fq_pie.c
+++ b/net/sched/sch_fq_pie.c
@@ -298,8 +298,8 @@ static int fq_pie_change(struct Qdisc *sch, struct nlattr *opt,
if (tb[TCA_FQ_PIE_LIMIT]) {
u32 limit = nla_get_u32(tb[TCA_FQ_PIE_LIMIT]);
- q->p_params.limit = limit;
- sch->limit = limit;
+ WRITE_ONCE(q->p_params.limit, limit);
+ WRITE_ONCE(sch->limit, limit);
}
if (tb[TCA_FQ_PIE_FLOWS]) {
if (q->flows) {
@@ -321,39 +321,45 @@ static int fq_pie_change(struct Qdisc *sch, struct nlattr *opt,
u32 target = nla_get_u32(tb[TCA_FQ_PIE_TARGET]);
/* convert to pschedtime */
- q->p_params.target =
- PSCHED_NS2TICKS((u64)target * NSEC_PER_USEC);
+ WRITE_ONCE(q->p_params.target,
+ PSCHED_NS2TICKS((u64)target * NSEC_PER_USEC));
}
/* tupdate is in jiffies */
if (tb[TCA_FQ_PIE_TUPDATE])
- q->p_params.tupdate =
- usecs_to_jiffies(nla_get_u32(tb[TCA_FQ_PIE_TUPDATE]));
+ WRITE_ONCE(q->p_params.tupdate,
+ usecs_to_jiffies(nla_get_u32(tb[TCA_FQ_PIE_TUPDATE])));
if (tb[TCA_FQ_PIE_ALPHA])
- q->p_params.alpha = nla_get_u32(tb[TCA_FQ_PIE_ALPHA]);
+ WRITE_ONCE(q->p_params.alpha,
+ nla_get_u32(tb[TCA_FQ_PIE_ALPHA]));
if (tb[TCA_FQ_PIE_BETA])
- q->p_params.beta = nla_get_u32(tb[TCA_FQ_PIE_BETA]);
+ WRITE_ONCE(q->p_params.beta,
+ nla_get_u32(tb[TCA_FQ_PIE_BETA]));
if (tb[TCA_FQ_PIE_QUANTUM])
- q->quantum = nla_get_u32(tb[TCA_FQ_PIE_QUANTUM]);
+ WRITE_ONCE(q->quantum, nla_get_u32(tb[TCA_FQ_PIE_QUANTUM]));
if (tb[TCA_FQ_PIE_MEMORY_LIMIT])
- q->memory_limit = nla_get_u32(tb[TCA_FQ_PIE_MEMORY_LIMIT]);
+ WRITE_ONCE(q->memory_limit,
+ nla_get_u32(tb[TCA_FQ_PIE_MEMORY_LIMIT]));
if (tb[TCA_FQ_PIE_ECN_PROB])
- q->ecn_prob = nla_get_u32(tb[TCA_FQ_PIE_ECN_PROB]);
+ WRITE_ONCE(q->ecn_prob,
+ nla_get_u32(tb[TCA_FQ_PIE_ECN_PROB]));
if (tb[TCA_FQ_PIE_ECN])
- q->p_params.ecn = nla_get_u32(tb[TCA_FQ_PIE_ECN]);
+ WRITE_ONCE(q->p_params.ecn,
+ nla_get_u32(tb[TCA_FQ_PIE_ECN]));
if (tb[TCA_FQ_PIE_BYTEMODE])
- q->p_params.bytemode = nla_get_u32(tb[TCA_FQ_PIE_BYTEMODE]);
+ WRITE_ONCE(q->p_params.bytemode,
+ nla_get_u32(tb[TCA_FQ_PIE_BYTEMODE]));
if (tb[TCA_FQ_PIE_DQ_RATE_ESTIMATOR])
- q->p_params.dq_rate_estimator =
- nla_get_u32(tb[TCA_FQ_PIE_DQ_RATE_ESTIMATOR]);
+ WRITE_ONCE(q->p_params.dq_rate_estimator,
+ nla_get_u32(tb[TCA_FQ_PIE_DQ_RATE_ESTIMATOR]));
/* Drop excess packets if new limit is lower */
while (sch->q.qlen > sch->limit) {
@@ -471,22 +477,23 @@ static int fq_pie_dump(struct Qdisc *sch, struct sk_buff *skb)
return -EMSGSIZE;
/* convert target from pschedtime to us */
- if (nla_put_u32(skb, TCA_FQ_PIE_LIMIT, sch->limit) ||
- nla_put_u32(skb, TCA_FQ_PIE_FLOWS, q->flows_cnt) ||
+ if (nla_put_u32(skb, TCA_FQ_PIE_LIMIT, READ_ONCE(sch->limit)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_FLOWS, READ_ONCE(q->flows_cnt)) ||
nla_put_u32(skb, TCA_FQ_PIE_TARGET,
- ((u32)PSCHED_TICKS2NS(q->p_params.target)) /
+ ((u32)PSCHED_TICKS2NS(READ_ONCE(q->p_params.target))) /
NSEC_PER_USEC) ||
nla_put_u32(skb, TCA_FQ_PIE_TUPDATE,
- jiffies_to_usecs(q->p_params.tupdate)) ||
- nla_put_u32(skb, TCA_FQ_PIE_ALPHA, q->p_params.alpha) ||
- nla_put_u32(skb, TCA_FQ_PIE_BETA, q->p_params.beta) ||
- nla_put_u32(skb, TCA_FQ_PIE_QUANTUM, q->quantum) ||
- nla_put_u32(skb, TCA_FQ_PIE_MEMORY_LIMIT, q->memory_limit) ||
- nla_put_u32(skb, TCA_FQ_PIE_ECN_PROB, q->ecn_prob) ||
- nla_put_u32(skb, TCA_FQ_PIE_ECN, q->p_params.ecn) ||
- nla_put_u32(skb, TCA_FQ_PIE_BYTEMODE, q->p_params.bytemode) ||
+ jiffies_to_usecs(READ_ONCE(q->p_params.tupdate))) ||
+ nla_put_u32(skb, TCA_FQ_PIE_ALPHA, READ_ONCE(q->p_params.alpha)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_BETA, READ_ONCE(q->p_params.beta)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_QUANTUM, READ_ONCE(q->quantum)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_MEMORY_LIMIT,
+ READ_ONCE(q->memory_limit)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_ECN_PROB, READ_ONCE(q->ecn_prob)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_ECN, READ_ONCE(q->p_params.ecn)) ||
+ nla_put_u32(skb, TCA_FQ_PIE_BYTEMODE, READ_ONCE(q->p_params.bytemode)) ||
nla_put_u32(skb, TCA_FQ_PIE_DQ_RATE_ESTIMATOR,
- q->p_params.dq_rate_estimator))
+ READ_ONCE(q->p_params.dq_rate_estimator)))
goto nla_put_failure;
return nla_nest_end(skb, opts);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 424/982] net/sched: fq_pie: clamp quantum in change path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (422 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 423/982] net_sched: sch_fq_pie: implement lockless fq_pie_dump() Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 425/982] net/sched: sfq: " Greg Kroah-Hartman
` (564 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega,
Toke Høiland-Jørgensen, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 4864f58c53eb47257d55e01f47d4a9f355f7f970 ]
fq_pie_change() accepts any quantum value from userspace, including 1.
With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1
makes the deficit-refill loop spin ~2^31 times under the qdisc lock
(a soft lockup / denial of service).
Add max(256U, ...) matching fq_codel_change().
Conditions to recreate the bug:
CONFIG_NET_SCH_FQ_PIE=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root fq_pie
tc qdisc change dev dummy0 root fq_pie quantum 1 stab data 32768 size_log 15 cell_log 0
Fixes: ec97ecf1ebe4 ("net: sched: add Flow Queue PIE packet scheduler")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.3
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_fq_pie.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/sched/sch_fq_pie.c b/net/sched/sch_fq_pie.c
index f8fb1d1af6abb..75d6e7716ae8e 100644
--- a/net/sched/sch_fq_pie.c
+++ b/net/sched/sch_fq_pie.c
@@ -339,7 +339,8 @@ static int fq_pie_change(struct Qdisc *sch, struct nlattr *opt,
nla_get_u32(tb[TCA_FQ_PIE_BETA]));
if (tb[TCA_FQ_PIE_QUANTUM])
- WRITE_ONCE(q->quantum, nla_get_u32(tb[TCA_FQ_PIE_QUANTUM]));
+ WRITE_ONCE(q->quantum,
+ max(256U, nla_get_u32(tb[TCA_FQ_PIE_QUANTUM])));
if (tb[TCA_FQ_PIE_MEMORY_LIMIT])
WRITE_ONCE(q->memory_limit,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 425/982] net/sched: sfq: clamp quantum in change path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (423 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 424/982] net/sched: fq_pie: clamp quantum in change path Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 426/982] net/sched: hhf: clamp quantum in change and init paths Greg Kroah-Hartman
` (563 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega,
Toke Høiland-Jørgensen, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit fb9f88a33c516ea5c0bcd9a22ca288b246b34567 ]
sfq_change() accepts any non-negative quantum (only rejects
(int)ctl->quantum < 0). With a crafted size table qdisc_pkt_len reaches
~2 GiB, so quantum=1 makes the deficit-refill loop spin ~2^31 times
under the qdisc lock (a soft lockup / denial of service).
Add max(256U, ...) matching fq_codel_change(). Reject quantum > 1<<20
with -EINVAL, matching fq_codel_change() and the init clamp.
Conditions to recreate the bug:
CONFIG_NET_SCH_SFQ=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root sfq
tc qdisc change dev dummy0 root sfq quantum 1 stab data 32768 size_log 15 cell_log 0
Fixes: e4650d7ae425 ("net_sched: sch_sfq: handle bigger packets")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.4
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_sfq.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/net/sched/sch_sfq.c b/net/sched/sch_sfq.c
index a53ea6ac2296f..779e632ede19c 100644
--- a/net/sched/sch_sfq.c
+++ b/net/sched/sch_sfq.c
@@ -657,6 +657,11 @@ static int sfq_change(struct Qdisc *sch, struct nlattr *opt,
return -EINVAL;
}
+ if (ctl->quantum > 1 << 20) {
+ NL_SET_ERR_MSG_MOD(extack, "quantum too large");
+ return -EINVAL;
+ }
+
if (ctl->perturb_period < 0 ||
ctl->perturb_period > INT_MAX / HZ) {
NL_SET_ERR_MSG_MOD(extack, "invalid perturb period");
@@ -685,7 +690,7 @@ static int sfq_change(struct Qdisc *sch, struct nlattr *opt,
/* update and validate configuration */
if (ctl->quantum)
- quantum = ctl->quantum;
+ quantum = max(256U, ctl->quantum);
if (ctl->flows)
maxflows = min_t(u32, ctl->flows, SFQ_MAX_FLOWS);
if (ctl->divisor) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 426/982] net/sched: hhf: clamp quantum in change and init paths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (424 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 425/982] net/sched: sfq: " Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 427/982] net/sched: pie: clamp psched_mtu in pie_drop_early Greg Kroah-Hartman
` (562 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega,
Toke Høiland-Jørgensen, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit eb56a495f59baf6cad5ed80e3ffb9078098b1346 ]
hhf_change() accepts any quantum from userspace, including 1. With a
crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1 makes
the deficit-refill loop spin ~2^31 times under the qdisc lock
(a soft lockup / denial of service).
Add max(256U, ...) in hhf_change() matching fq_codel_change(). Clamp
hhf_init() to [256, 1<<20] matching the siblings, and remove the old
fallback that only set quantum=256 on overflow.
Conditions to recreate the bug:
CONFIG_NET_SCH_HHF=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root hhf
tc qdisc change dev dummy0 root hhf quantum 1 stab data 32768 size_log 15 cell_log 0
Fixes: 10239edf86f1 ("net-qdisc-hhf: Heavy-Hitter Filter (HHF) qdisc")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.5
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_hhf.c | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
diff --git a/net/sched/sch_hhf.c b/net/sched/sch_hhf.c
index f9eab403ac161..fa7480474976f 100644
--- a/net/sched/sch_hhf.c
+++ b/net/sched/sch_hhf.c
@@ -550,7 +550,7 @@ static int hhf_change(struct Qdisc *sch, struct nlattr *opt,
return err;
if (tb[TCA_HHF_QUANTUM])
- new_quantum = nla_get_u32(tb[TCA_HHF_QUANTUM]);
+ new_quantum = max(256U, nla_get_u32(tb[TCA_HHF_QUANTUM]));
if (tb[TCA_HHF_NON_HH_WEIGHT])
new_hhf_non_hh_weight = nla_get_u32(tb[TCA_HHF_NON_HH_WEIGHT]);
@@ -606,7 +606,7 @@ static int hhf_init(struct Qdisc *sch, struct nlattr *opt,
int i;
sch->limit = 1000;
- q->quantum = psched_mtu(qdisc_dev(sch));
+ q->quantum = clamp_t(u32, psched_mtu(qdisc_dev(sch)), 256, 1 << 20);
get_random_bytes(&q->perturbation, sizeof(q->perturbation));
INIT_LIST_HEAD(&q->new_buckets);
INIT_LIST_HEAD(&q->old_buckets);
@@ -617,10 +617,6 @@ static int hhf_init(struct Qdisc *sch, struct nlattr *opt,
q->hhf_evict_timeout = HZ; /* 1 sec */
q->hhf_non_hh_weight = 2;
- if ((int)q->quantum <= 0 ||
- (u64)q->quantum * q->hhf_non_hh_weight > INT_MAX)
- q->quantum = 256;
-
if (opt) {
int err = hhf_change(sch, opt, extack);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 427/982] net/sched: pie: clamp psched_mtu in pie_drop_early
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (425 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 426/982] net/sched: hhf: clamp quantum in change and init paths Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 428/982] net/sched: drr: clamp quantum in change class Greg Kroah-Hartman
` (561 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega,
Toke Høiland-Jørgensen, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 54370e44c002770ae61fc889f28f699e91616ffc ]
pie_drop_early() calls psched_mtu() with no clamp. With mtu=0x80000000
the bytemode divide silently zeroes the drop probability, disabling AQM.
Clamp to [1, 1<<20].
Conditions to recreate the bug:
CONFIG_NET_SCH_PIE=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root pie
tc qdisc change dev dummy0 root pie stab data 32768 size_log 15 cell_log 0
Fixes: d4b36210c2e6 ("net: pkt_sched: PIE AQM scheme")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.7
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_pie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/sched/sch_pie.c b/net/sched/sch_pie.c
index 4ab296678b0b1..1ed6f43c93c4d 100644
--- a/net/sched/sch_pie.c
+++ b/net/sched/sch_pie.c
@@ -35,7 +35,7 @@ bool pie_drop_early(struct Qdisc *sch, struct pie_params *params,
{
u64 rnd;
u64 local_prob = vars->prob;
- u32 mtu = psched_mtu(qdisc_dev(sch));
+ u32 mtu = clamp_t(u32, psched_mtu(qdisc_dev(sch)), 1, 1 << 20);
/* If there is still burst allowance left skip random early drop */
if (vars->burst_time > 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 428/982] net/sched: drr: clamp quantum in change class
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (426 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 427/982] net/sched: pie: clamp psched_mtu in pie_drop_early Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 429/982] net/sched: ets: clamp quantum in parse and fallback paths Greg Kroah-Hartman
` (560 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega,
Toke Høiland-Jørgensen, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 8382abec0f1568d0a5590d75a3df92f23fcf5196 ]
drr_change_class() rejects explicit quantum==0 but falls back to
psched_mtu() with no floor. With a crafted size table qdisc_pkt_len
reaches ~2 GiB, so quantum=1 (or a zero psched_mtu on a headerless
device) makes the deficit-refill loop spin under the qdisc lock.
Add clamp_t(u32, quantum, 256, 1<<20) after the zero reject and on the
fallback path. The explicit-zero reject is preserved.
Conditions to recreate the bug:
CONFIG_NET_SCH_DRR=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root drr
tc class add dev dummy0 parent 1: classid 1:1 drr quantum 1
Fixes: 13d2a1d2b032 ("pkt_sched: add DRR scheduler")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.8
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_drr.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/sched/sch_drr.c b/net/sched/sch_drr.c
index 437b09acef123..63ec888d6b495 100644
--- a/net/sched/sch_drr.c
+++ b/net/sched/sch_drr.c
@@ -83,8 +83,9 @@ static int drr_change_class(struct Qdisc *sch, u32 classid, u32 parentid,
NL_SET_ERR_MSG(extack, "Specified DRR quantum cannot be zero");
return -EINVAL;
}
+ quantum = clamp_t(u32, quantum, 256, 1 << 20);
} else
- quantum = psched_mtu(qdisc_dev(sch));
+ quantum = clamp_t(u32, (u32)psched_mtu(qdisc_dev(sch)), 256, 1 << 20);
if (cl != NULL) {
if (tca[TCA_RATE]) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 429/982] net/sched: ets: clamp quantum in parse and fallback paths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (427 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 428/982] net/sched: drr: clamp quantum in change class Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 430/982] workqueue: Introduce from_work() helper for cleaner callback declarations Greg Kroah-Hartman
` (559 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega,
Toke Høiland-Jørgensen, Victor Nogueira,
Jamal Hadi Salim, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 1c38487f46b243bfeefec0c0c86023a3904f2214 ]
ets_qdisc_change() falls back to psched_mtu() with no floor for bands
without an explicit quantum. With a crafted size table qdisc_pkt_len
reaches ~2 GiB, so a zero psched_mtu on a headerless device makes the
deficit-refill loop spin under the qdisc lock.
Move the floor into ets_quantum_parse() so explicitly configured quanta
are also clamped to [256, 1<<20], not just the fallback path.
Conditions to recreate the bug:
CONFIG_NET_SCH_ETS=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root ets bands 3 strict 2 quanta 1 1
Fixes: dcc68b4d8084 ("net: sch_ets: Add a new Qdisc")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.9
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_ets.c | 12 +++++-------
1 file changed, 5 insertions(+), 7 deletions(-)
diff --git a/net/sched/sch_ets.c b/net/sched/sch_ets.c
index 0a5768d98acac..2f1e8a5d5b37b 100644
--- a/net/sched/sch_ets.c
+++ b/net/sched/sch_ets.c
@@ -83,11 +83,7 @@ static int ets_quantum_parse(struct Qdisc *sch, const struct nlattr *attr,
unsigned int *quantum,
struct netlink_ext_ack *extack)
{
- *quantum = nla_get_u32(attr);
- if (!*quantum) {
- NL_SET_ERR_MSG(extack, "ETS quantum cannot be zero");
- return -EINVAL;
- }
+ *quantum = clamp_t(u32, nla_get_u32(attr), 256, 1 << 20);
return 0;
}
@@ -634,11 +630,13 @@ static int ets_qdisc_change(struct Qdisc *sch, struct nlattr *opt,
return err;
}
/* If there are more bands than strict + quanta provided, the remaining
- * ones are ETS with quantum of MTU. Initialize the missing values here.
+ * ones are ETS with quantum of max(MTU, 256). Initialize the missing
+ * values here.
*/
for (i = nstrict; i < nbands; i++) {
if (!quanta[i])
- quanta[i] = psched_mtu(qdisc_dev(sch));
+ quanta[i] = clamp_t(u32, (u32)psched_mtu(qdisc_dev(sch)),
+ 256, 1 << 20);
}
/* Before commit, make sure we can allocate all new qdiscs */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 430/982] workqueue: Introduce from_work() helper for cleaner callback declarations
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (428 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 429/982] net/sched: ets: clamp quantum in parse and fallback paths Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 431/982] net: macb: rename bp->sgmii_phy field to bp->phy Greg Kroah-Hartman
` (558 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Allen Pais, Tejun Heo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allen Pais <apais@linux.microsoft.com>
[ Upstream commit 60b2ebf48526567b53e0188dbd1a4df8e646bcc1 ]
To streamline the transition from tasklets to worqueues, a new helper
function, from_work(), is introduced. This helper, inspired by existing
from_() patterns, utilizes container_of() and eliminates the redundancy
of declaring variable types, leading to more concise and readable code.
The modified code snippet demonstrates the enhanced clarity achieved
with from_wq():
void callback(struct work_struct *w)
{
- struct some_data_structure *local = container_of(w,
struct some_data_structure,
work);
+ struct some_data_structure *local = from_work(local, w, work);
This change aims to facilitate a smoother transition and uphold code
quality standards.
Based on:
git://git.kernel.org/pub/scm/linux/kernel/git/tj/wq.git disable_work-v3
Signed-off-by: Allen Pais <allen.lkml@gmail.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Stable-dep-of: 38b6be101006 ("net: macb: fix NULL pointer dereference on unbind with fixed-link")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/workqueue.h | 3 +++
1 file changed, 3 insertions(+)
diff --git a/include/linux/workqueue.h b/include/linux/workqueue.h
index 5d052e193a85c..737219d7dd2b6 100644
--- a/include/linux/workqueue.h
+++ b/include/linux/workqueue.h
@@ -436,6 +436,9 @@ alloc_workqueue(const char *fmt, unsigned int flags, int max_active, ...);
#define create_singlethread_workqueue(name) \
alloc_ordered_workqueue("%s", __WQ_LEGACY | WQ_MEM_RECLAIM, name)
+#define from_work(var, callback_work, work_fieldname) \
+ container_of(callback_work, typeof(*var), work_fieldname)
+
extern void destroy_workqueue(struct workqueue_struct *wq);
struct workqueue_attrs *alloc_workqueue_attrs(void);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 431/982] net: macb: rename bp->sgmii_phy field to bp->phy
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (429 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 430/982] workqueue: Introduce from_work() helper for cleaner callback declarations Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 432/982] net: macb: fix NULL pointer dereference on unbind with fixed-link Greg Kroah-Hartman
` (557 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrew Lunn, Maxime Chevallier,
Théo Lebrun, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Théo Lebrun <theo.lebrun@bootlin.com>
[ Upstream commit 3f7e51cd5fbf4d970b14956ee9464515bb40666f ]
The bp->sgmii_phy field is initialised at probe by init_reset_optional()
if bp->phy_interface == PHY_INTERFACE_MODE_SGMII. It gets used by:
- zynqmp_config: "cdns,zynqmp-gem" or "xlnx,zynqmp-gem" compatibles.
- mpfs_config: "microchip,mpfs-macb" compatible.
- versal_config: "xlnx,versal-gem" compatible.
Make name more generic as EyeQ5 requires the PHY in SGMII & RGMII cases.
Drop "for ZynqMP SGMII mode" comment that is already a lie, as it gets
used on Microchip platforms as well. And soon it won't be SGMII-only.
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Signed-off-by: Théo Lebrun <theo.lebrun@bootlin.com>
Link: https://patch.msgid.link/20251023-macb-eyeq5-v3-4-af509422c204@bootlin.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Stable-dep-of: 38b6be101006 ("net: macb: fix NULL pointer dereference on unbind with fixed-link")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb.h | 2 +-
drivers/net/ethernet/cadence/macb_main.c | 26 ++++++++++++------------
2 files changed, 14 insertions(+), 14 deletions(-)
diff --git a/drivers/net/ethernet/cadence/macb.h b/drivers/net/ethernet/cadence/macb.h
index 0d3c6eb72163f..9d825e3b4d945 100644
--- a/drivers/net/ethernet/cadence/macb.h
+++ b/drivers/net/ethernet/cadence/macb.h
@@ -1311,7 +1311,7 @@ struct macb {
struct macb_ptp_info *ptp_info; /* macb-ptp interface */
- struct phy *sgmii_phy; /* for ZynqMP SGMII mode */
+ struct phy *phy;
#ifdef MACB_EXT_DESC
uint8_t hw_dma_cap;
diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index 513a1267a6ef7..e33ff04797f7d 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -3034,7 +3034,7 @@ static int macb_open(struct net_device *dev)
macb_init_hw(bp);
- err = phy_power_on(bp->sgmii_phy);
+ err = phy_power_on(bp->phy);
if (err)
goto reset_hw;
@@ -3050,7 +3050,7 @@ static int macb_open(struct net_device *dev)
return 0;
phy_off:
- phy_power_off(bp->sgmii_phy);
+ phy_power_off(bp->phy);
reset_hw:
macb_reset_hw(bp);
@@ -3081,7 +3081,7 @@ static int macb_close(struct net_device *dev)
phylink_stop(bp->phylink);
phylink_disconnect_phy(bp->phylink);
- phy_power_off(bp->sgmii_phy);
+ phy_power_off(bp->phy);
spin_lock_irqsave(&bp->lock, flags);
macb_reset_hw(bp);
@@ -4780,13 +4780,13 @@ static int init_reset_optional(struct platform_device *pdev)
if (bp->phy_interface == PHY_INTERFACE_MODE_SGMII) {
/* Ensure PHY device used in SGMII mode is ready */
- bp->sgmii_phy = devm_phy_optional_get(&pdev->dev, NULL);
+ bp->phy = devm_phy_optional_get(&pdev->dev, NULL);
- if (IS_ERR(bp->sgmii_phy))
- return dev_err_probe(&pdev->dev, PTR_ERR(bp->sgmii_phy),
+ if (IS_ERR(bp->phy))
+ return dev_err_probe(&pdev->dev, PTR_ERR(bp->phy),
"failed to get SGMII PHY\n");
- ret = phy_init(bp->sgmii_phy);
+ ret = phy_init(bp->phy);
if (ret)
return dev_err_probe(&pdev->dev, ret,
"failed to init SGMII PHY\n");
@@ -4815,7 +4815,7 @@ static int init_reset_optional(struct platform_device *pdev)
/* Fully reset controller at hardware level if mapped in device tree */
ret = device_reset_optional(&pdev->dev);
if (ret) {
- phy_exit(bp->sgmii_phy);
+ phy_exit(bp->phy);
return dev_err_probe(&pdev->dev, ret, "failed to reset controller");
}
@@ -4823,7 +4823,7 @@ static int init_reset_optional(struct platform_device *pdev)
err_out_phy_exit:
if (ret)
- phy_exit(bp->sgmii_phy);
+ phy_exit(bp->phy);
return ret;
}
@@ -5195,7 +5195,7 @@ static int macb_probe(struct platform_device *pdev)
mdiobus_free(bp->mii_bus);
err_out_phy_exit:
- phy_exit(bp->sgmii_phy);
+ phy_exit(bp->phy);
err_out_free_netdev:
free_netdev(dev);
@@ -5219,7 +5219,7 @@ static int macb_remove(struct platform_device *pdev)
if (dev) {
bp = netdev_priv(dev);
unregister_netdev(dev);
- phy_exit(bp->sgmii_phy);
+ phy_exit(bp->phy);
mdiobus_unregister(bp->mii_bus);
mdiobus_free(bp->mii_bus);
@@ -5249,7 +5249,7 @@ static int __maybe_unused macb_suspend(struct device *dev)
u32 tmp;
if (!device_may_wakeup(&bp->dev->dev))
- phy_exit(bp->sgmii_phy);
+ phy_exit(bp->phy);
if (!netif_running(netdev))
return 0;
@@ -5365,7 +5365,7 @@ static int __maybe_unused macb_resume(struct device *dev)
int err;
if (!device_may_wakeup(&bp->dev->dev))
- phy_init(bp->sgmii_phy);
+ phy_init(bp->phy);
if (!netif_running(netdev))
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 432/982] net: macb: fix NULL pointer dereference on unbind with fixed-link
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (430 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 431/982] net: macb: rename bp->sgmii_phy field to bp->phy Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 433/982] ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev Greg Kroah-Hartman
` (556 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vineeth Karumanchi, Xuanqiang Luo,
Nicolai Buchwitz, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Karumanchi <vineeth.karumanchi@amd.com>
[ Upstream commit 38b6be101006d3e7af972999f45d4f1e8250587a ]
When the device tree describes a fixed-link and has no "mdio" child
node, macb_mii_init() returns early without allocating the MDIO bus,
leaving bp->mii_bus as NULL.
Two cleanup paths then dereference this NULL bus:
1. On driver unbind, macb_remove() unconditionally calls
mdiobus_unregister(bp->mii_bus), which oopses:
Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8
pc : mdiobus_unregister+0x14/0xa4
lr : macb_remove+0x38/0xa4
Call trace:
mdiobus_unregister+0x14/0xa4 (P)
macb_remove+0x38/0xa4
platform_remove+0x20/0x30
device_release_driver_internal+0x1c8/0x224
unbind_store+0xb4/0xbc
2. On the probe error path in macb_probe(), reached when
macb_mii_init() has succeeded but a subsequent step fails, the
err_out_unregister_mdio label runs the same unconditional cleanup.
mdiobus_unregister() and mdiobus_free() do not guard against a NULL
bus, so guard the calls in both macb_remove() and the probe error
path.
Fixes: d0c3601f2c4e ("net: macb: Avoid 20s boot delay by skipping MDIO bus registration for fixed-link PHY")
Signed-off-by: Vineeth Karumanchi <vineeth.karumanchi@amd.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Link: https://patch.msgid.link/20260902102836.2019355-1-vineeth.karumanchi@amd.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb_main.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index e33ff04797f7d..ba9032c3542d9 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -5191,8 +5191,10 @@ static int macb_probe(struct platform_device *pdev)
return 0;
err_out_unregister_mdio:
- mdiobus_unregister(bp->mii_bus);
- mdiobus_free(bp->mii_bus);
+ if (bp->mii_bus) {
+ mdiobus_unregister(bp->mii_bus);
+ mdiobus_free(bp->mii_bus);
+ }
err_out_phy_exit:
phy_exit(bp->phy);
@@ -5220,8 +5222,10 @@ static int macb_remove(struct platform_device *pdev)
bp = netdev_priv(dev);
unregister_netdev(dev);
phy_exit(bp->phy);
- mdiobus_unregister(bp->mii_bus);
- mdiobus_free(bp->mii_bus);
+ if (bp->mii_bus) {
+ mdiobus_unregister(bp->mii_bus);
+ mdiobus_free(bp->mii_bus);
+ }
tasklet_kill(&bp->hresp_err_tasklet);
pm_runtime_disable(&pdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 433/982] ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (431 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 432/982] net: macb: fix NULL pointer dereference on unbind with fixed-link Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 434/982] ASoC: bcm: bcm63xx: Publish the OF module aliases Greg Kroah-Hartman
` (555 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+832ce9fa3face1b7d44d,
Edward Adam Davis, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Edward Adam Davis <eadavis@sina.com>
[ Upstream commit 402a9d6aab7ac787ab075adeb562c3db8b8f564b ]
The epq_in_urb object belonging to the caiaq device is coupled within
the struct snd_usb_caiaqdev. After usb_submit_urb(epq_in_urb, GFP_KERNEL)
executes successfully, epq_in_urb is successfully added to the urbp_list
queue of the dummy HCD driver (userspace specifies dummy_hcd as the HCD
layer driver for the caiaq USB device).
When init_card() calls snd_usb_caiaq_send_command() which subsequently
fails due to a timeout, and proceeds to call snd_card_free() to release
the card, the embedded ep1_in_urb object is also freed. When the dummy
HCD driver detects that the URB has been unlinked, it returns the URB
(by usb_hcd_giveback_urb()), which triggers [1].
Decouple the ep1_in_urb object from the struct snd_usb_caiaqdev and switch
to using a pointer instead. Separately allocate and manage the memory for
ep1_in_urb to prevent the release of the snd_card memory object from
interfering with it.
midi_out_urb has the same issue as ep1_in_urb and is handled in the same
way.
[1]
BUG: KASAN: slab-use-after-free in usb_free_urb+0x24/0x120 drivers/usb/core/urb.c:96
Write of size 4 at addr ffff88803cee1050 by task ktimers/1/29
Call Trace:
usb_free_urb+0x24/0x120 drivers/usb/core/urb.c:96
dummy_timer+0xaac/0x4d50 drivers/usb/gadget/udc/dummy_hcd.c:2019
__run_hrtimer kernel/time/hrtimer.c:2067 [inline]
__hrtimer_run_queues+0x3eb/0xaf0 kernel/time/hrtimer.c:2124
hrtimer_run_softirq+0x1e1/0x2e0 kernel/time/hrtimer.c:2141
Allocated by task 36:
snd_card_new+0x7b/0x110 sound/core/init.c:184
create_card sound/usb/caiaq/device.c:429 [inline]
snd_probe+0x236/0x1af0 sound/usb/caiaq/device.c:544
Freed by task 36:
snd_card_free_when_closed sound/core/init.c:630 [inline]
snd_card_free+0x138/0x1d0 sound/core/init.c:662
snd_probe+0x162b/0x1af0 sound/usb/caiaq/device.c:553
Fixes: 523f1dce3743 ("[ALSA] Add Native Instrument usb audio device support")
Reported-by: syzbot+832ce9fa3face1b7d44d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=832ce9fa3face1b7d44d
Tested-by: syzbot+832ce9fa3face1b7d44d@syzkaller.appspotmail.com
Signed-off-by: Edward Adam Davis <eadavis@sina.com>
Link: https://patch.msgid.link/20260903130521.554840-1-eadavis@sina.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/caiaq/device.c | 36 ++++++++++++++++++++++++------------
sound/usb/caiaq/device.h | 4 ++--
sound/usb/caiaq/midi.c | 6 +++---
3 files changed, 29 insertions(+), 17 deletions(-)
diff --git a/sound/usb/caiaq/device.c b/sound/usb/caiaq/device.c
index 7ad64d23269fe..b4b4765725ce7 100644
--- a/sound/usb/caiaq/device.c
+++ b/sound/usb/caiaq/device.c
@@ -192,8 +192,8 @@ static void usb_ep1_command_reply_dispatch (struct urb* urb)
break;
}
- cdev->ep1_in_urb.actual_length = 0;
- ret = usb_submit_urb(&cdev->ep1_in_urb, GFP_ATOMIC);
+ cdev->ep1_in_urb->actual_length = 0;
+ ret = usb_submit_urb(cdev->ep1_in_urb, GFP_ATOMIC);
if (ret < 0)
dev_err(dev, "unable to submit urb. OOM!?\n");
}
@@ -408,6 +408,10 @@ static void card_free(struct snd_card *card)
#endif
snd_usb_caiaq_audio_free(cdev);
usb_put_dev(cdev->chip.dev);
+ usb_free_urb(cdev->ep1_in_urb);
+ cdev->ep1_in_urb = NULL;
+ usb_free_urb(cdev->midi_out_urb);
+ cdev->midi_out_urb = NULL;
}
static int create_card(struct usb_device *usb_dev,
@@ -457,22 +461,30 @@ static int init_card(struct snd_usb_caiaqdev *cdev)
return -EIO;
}
- usb_init_urb(&cdev->ep1_in_urb);
- usb_init_urb(&cdev->midi_out_urb);
+ cdev->ep1_in_urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!cdev->ep1_in_urb)
+ return -ENOMEM;
- usb_fill_bulk_urb(&cdev->ep1_in_urb, usb_dev,
+ cdev->midi_out_urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!cdev->midi_out_urb) {
+ usb_free_urb(cdev->ep1_in_urb);
+ cdev->ep1_in_urb = NULL;
+ return -ENOMEM;
+ }
+
+ usb_fill_bulk_urb(cdev->ep1_in_urb, usb_dev,
usb_rcvbulkpipe(usb_dev, 0x1),
cdev->ep1_in_buf, EP1_BUFSIZE,
usb_ep1_command_reply_dispatch, cdev);
- usb_fill_bulk_urb(&cdev->midi_out_urb, usb_dev,
+ usb_fill_bulk_urb(cdev->midi_out_urb, usb_dev,
usb_sndbulkpipe(usb_dev, 0x1),
cdev->midi_out_buf, EP1_BUFSIZE,
snd_usb_caiaq_midi_output_done, cdev);
/* sanity checks of EPs before actually submitting */
- if (usb_urb_ep_type_check(&cdev->ep1_in_urb) ||
- usb_urb_ep_type_check(&cdev->midi_out_urb)) {
+ if (usb_urb_ep_type_check(cdev->ep1_in_urb) ||
+ usb_urb_ep_type_check(cdev->midi_out_urb)) {
dev_err(dev, "invalid EPs\n");
return -EINVAL;
}
@@ -480,7 +492,7 @@ static int init_card(struct snd_usb_caiaqdev *cdev)
init_waitqueue_head(&cdev->ep1_wait_queue);
init_waitqueue_head(&cdev->prepare_wait_queue);
- if (usb_submit_urb(&cdev->ep1_in_urb, GFP_KERNEL) != 0)
+ if (usb_submit_urb(cdev->ep1_in_urb, GFP_KERNEL) != 0)
return -EIO;
err = snd_usb_caiaq_send_command(cdev, EP1_CMD_GET_DEVICE_INFO, NULL, 0);
@@ -530,7 +542,7 @@ static int init_card(struct snd_usb_caiaqdev *cdev)
return 0;
err_kill_urb:
- usb_kill_urb(&cdev->ep1_in_urb);
+ usb_kill_urb(cdev->ep1_in_urb);
return err;
}
@@ -576,8 +588,8 @@ static void snd_disconnect(struct usb_interface *intf)
#endif
snd_usb_caiaq_audio_disconnect(cdev);
- usb_kill_urb(&cdev->ep1_in_urb);
- usb_kill_urb(&cdev->midi_out_urb);
+ usb_kill_urb(cdev->ep1_in_urb);
+ usb_kill_urb(cdev->midi_out_urb);
snd_card_free_when_closed(card);
}
diff --git a/sound/usb/caiaq/device.h b/sound/usb/caiaq/device.h
index 50fea085765b2..5ad6cebd639c0 100644
--- a/sound/usb/caiaq/device.h
+++ b/sound/usb/caiaq/device.h
@@ -60,8 +60,8 @@ struct snd_usb_caiaq_cb_info;
struct snd_usb_caiaqdev {
struct snd_usb_audio chip;
- struct urb ep1_in_urb;
- struct urb midi_out_urb;
+ struct urb *ep1_in_urb;
+ struct urb *midi_out_urb;
struct urb **data_urbs_in;
struct urb **data_urbs_out;
struct snd_usb_caiaq_cb_info *data_cb_info;
diff --git a/sound/usb/caiaq/midi.c b/sound/usb/caiaq/midi.c
index c656d01624321..18529484c8dcc 100644
--- a/sound/usb/caiaq/midi.c
+++ b/sound/usb/caiaq/midi.c
@@ -43,7 +43,7 @@ static int snd_usb_caiaq_midi_output_close(struct snd_rawmidi_substream *substre
{
struct snd_usb_caiaqdev *cdev = substream->rmidi->private_data;
if (cdev->midi_out_active) {
- usb_kill_urb(&cdev->midi_out_urb);
+ usb_kill_urb(cdev->midi_out_urb);
cdev->midi_out_active = 0;
}
return 0;
@@ -64,9 +64,9 @@ static void snd_usb_caiaq_midi_send(struct snd_usb_caiaqdev *cdev,
return;
cdev->midi_out_buf[2] = len;
- cdev->midi_out_urb.transfer_buffer_length = len+3;
+ cdev->midi_out_urb->transfer_buffer_length = len+3;
- ret = usb_submit_urb(&cdev->midi_out_urb, GFP_ATOMIC);
+ ret = usb_submit_urb(cdev->midi_out_urb, GFP_ATOMIC);
if (ret < 0)
dev_err(dev,
"snd_usb_caiaq_midi_send(%p): usb_submit_urb() failed,"
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 434/982] ASoC: bcm: bcm63xx: Publish the OF module aliases
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (432 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 433/982] ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 435/982] ASoC: Intel: SST: Publish the PCI " Greg Kroah-Hartman
` (554 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, hpp.iscas, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: hpp.iscas <hppiscas@163.com>
[ Upstream commit 32689f0fc54fd801f1cd11637666e534984cb04a ]
The BCM63xx I2S platform driver matches brcm,bcm63xx-i2s using
snd_soc_bcm_audio_match. With SND_BCM63XX_I2S_WHISTLER=m, the platform
bus emits an OF modalias but snd-soc-63xx does not publish that table.
Export the existing OF IDs for module autoloading. The PCM companion
and the probe path remain unchanged.
Fixes: 88eb404ccc3e ("ASoC: brcm: Add DSL/PON SoC audio driver")
Signed-off-by: hpp.iscas <hppiscas@163.com>
Link: https://patch.msgid.link/20260905133103.63432-1-hppiscas@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/bcm/bcm63xx-i2s-whistler.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/soc/bcm/bcm63xx-i2s-whistler.c b/sound/soc/bcm/bcm63xx-i2s-whistler.c
index 2da1384ffe911..7ae46863d0070 100644
--- a/sound/soc/bcm/bcm63xx-i2s-whistler.c
+++ b/sound/soc/bcm/bcm63xx-i2s-whistler.c
@@ -300,6 +300,7 @@ static const struct of_device_id snd_soc_bcm_audio_match[] = {
{.compatible = "brcm,bcm63xx-i2s"},
{ }
};
+MODULE_DEVICE_TABLE(of, snd_soc_bcm_audio_match);
#endif
static struct platform_driver bcm63xx_i2s_driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 435/982] ASoC: Intel: SST: Publish the PCI module aliases
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (433 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 434/982] ASoC: bcm: bcm63xx: Publish the OF module aliases Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 436/982] netfilter: nfnetlink_log: cope with concurrent instance destruction Greg Kroah-Hartman
` (553 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, hpp.iscas, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: hpp.iscas <hppiscas@163.com>
[ Upstream commit d112159df5c6cc5ee6ab91cc32bf6ed29939df38 ]
The legacy SST PCI driver matches Intel Tangier devices using
intel_sst_ids, but its only explicit module alias is "sst". That alias
does not match PCI modalias events when this driver is built as a module.
Publish its PCI table. The independently configurable SOF driver does
not provide aliases for the legacy SST module.
Fixes: f533a035e4da ("ASoC: Intel: mrfld - create separate module for pci part")
Signed-off-by: hpp.iscas <hppiscas@163.com>
Link: https://patch.msgid.link/20260905133133.63661-1-hppiscas@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/intel/atom/sst/sst_pci.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/soc/intel/atom/sst/sst_pci.c b/sound/soc/intel/atom/sst/sst_pci.c
index f7ad991bf04d5..900e3d42e3d5e 100644
--- a/sound/soc/intel/atom/sst/sst_pci.c
+++ b/sound/soc/intel/atom/sst/sst_pci.c
@@ -179,6 +179,7 @@ static const struct pci_device_id intel_sst_ids[] = {
{ PCI_VDEVICE(INTEL, SST_MRFLD_PCI_ID), 0},
{ 0, }
};
+MODULE_DEVICE_TABLE(pci, intel_sst_ids);
static struct pci_driver sst_driver = {
.name = SST_DRV_NAME,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 436/982] netfilter: nfnetlink_log: cope with concurrent instance destruction
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (434 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 435/982] ASoC: Intel: SST: Publish the PCI " Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 437/982] netfilter: ip6_tables: set F_PROTO when proto value is nonzero Greg Kroah-Hartman
` (552 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eulgyu Kim, Jaeyoung Chung,
Florian Westphal, Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 387d744fa7e499d2c3748a4e60e02ebb24e7fb16 ]
Instances are refcounted. However, only memory release happens on the
1 -> 0 transition; the unlink from hashes can occur with any refcount.
Uncooperative userspace can force a situation where a queue is pending
for destruction from netlink event while a different socket with same
portid processes an UNBIND request.
With right timing, this will unhash the instance again:
Oops: general protection fault, [..]
Call Trace:
<TASK>
nfulnl_recv_config+0x31a/0xd50
nfnetlink_rcv_msg+0x7c2/0xeb0
Fixes: 0597f2680d66 ("[NETFILTER]: Add new "nfnetlink_log" userspace packet logging facility")
Reported-by: Eulgyu Kim <eulgyukim@snu.ac.kr>
Reported-by: Jaeyoung Chung <jjy600901@snu.ac.kr>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nfnetlink_log.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nfnetlink_log.c b/net/netfilter/nfnetlink_log.c
index d3c43897250a5..60c73d3188896 100644
--- a/net/netfilter/nfnetlink_log.c
+++ b/net/netfilter/nfnetlink_log.c
@@ -218,13 +218,18 @@ static void __nfulnl_flush(struct nfulnl_instance *inst);
static void
__instance_destroy(struct nfulnl_instance *inst)
{
+ spin_lock(&inst->lock);
+ if (inst->copy_mode == NFULNL_COPY_DISABLED) {
+ /* attempt to UNBIND a queue already pending
+ * destruction via netlink close event. Ignore.
+ */
+ spin_unlock(&inst->lock);
+ return;
+ }
+
/* first pull it out of the global list */
hlist_del_rcu(&inst->hlist);
- /* then flush all pending packets from skb */
-
- spin_lock(&inst->lock);
-
/* lockless readers wont be able to use us */
inst->copy_mode = NFULNL_COPY_DISABLED;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 437/982] netfilter: ip6_tables: set F_PROTO when proto value is nonzero
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (435 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 436/982] netfilter: nfnetlink_log: cope with concurrent instance destruction Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 438/982] ASoC: mt6351: Publish the OF module alias Greg Kroah-Hartman
` (551 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhiling Zou, Florian Westphal,
Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit da4afc5a956d407443988e97a4d4ca14c2e999c7 ]
The ip6tables traverser doesn't search the extension header chain unless
userspace did set the IP6T_F_PROTO flag.
This also means that userspace that sets the e->ipv6.proto flag can bypass
the protocol check for the rule by not setting this flag.
That in turn means that all ip6_tables modules and targets that want to
reject rules without '-p' flag MUST also check for that flag.
Not all do, likely because they got copied from iptables which lacks
this flag (no extension headers).
Instead of fixing up all the relevant targets, emulate ip6tables behaviour
in the kernel (like nft_compat.c) and set the flag if the protocol is set.
Reported-by: Zhiling Zou <zhilinz@nebusec.ai>
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/netfilter/ip6_tables.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c
index 333115dff69ae..ad559d4a877a3 100644
--- a/net/ipv6/netfilter/ip6_tables.c
+++ b/net/ipv6/netfilter/ip6_tables.c
@@ -649,6 +649,11 @@ check_entry_size_and_hooks(struct ip6t_entry *e,
/* Clear counters and comefrom */
e->counters = ((struct xt_counters) { 0, 0 });
e->comefrom = 0;
+
+ /* set F_PROTO, else ip6_packet_match won't do the right thing. */
+ if (e->ipv6.proto)
+ e->ipv6.flags |= IP6T_F_PROTO;
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 438/982] ASoC: mt6351: Publish the OF module alias
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (436 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 437/982] netfilter: ip6_tables: set F_PROTO when proto value is nonzero Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 439/982] virtio-console: call scheduler when we free unused buffs Greg Kroah-Hartman
` (550 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, hpp.iscas, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: hpp.iscas <hppiscas@163.com>
[ Upstream commit 9c3882ec10399c14c59b7e4599d33c4395367c37 ]
The MT6351 codec platform driver uses mt6351_of_match to bind devices
with compatible mediatek,mt6351-sound. The codec can be a separate
module, but the OF table is not exported to module alias metadata.
Publish the existing table without changing codec matching, register
access or the machine-driver configuration.
Fixes: a74d51ba0e17 ("ASoC: add mt6351 codec driver")
Signed-off-by: hpp.iscas <hppiscas@163.com>
Link: https://patch.msgid.link/20260905133210.63803-1-hppiscas@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/mt6351.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/soc/codecs/mt6351.c b/sound/soc/codecs/mt6351.c
index d2cf4847eead1..c333393ce6f26 100644
--- a/sound/soc/codecs/mt6351.c
+++ b/sound/soc/codecs/mt6351.c
@@ -1479,6 +1479,7 @@ static const struct of_device_id mt6351_of_match[] = {
{.compatible = "mediatek,mt6351-sound",},
{}
};
+MODULE_DEVICE_TABLE(of, mt6351_of_match);
static struct platform_driver mt6351_codec_driver = {
.driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 439/982] virtio-console: call scheduler when we free unused buffs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (437 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 438/982] ASoC: mt6351: Publish the OF module alias Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 440/982] virtio_console: do not free control-out buffers on remove Greg Kroah-Hartman
` (549 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xianting Tian, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xianting Tian <xianting.tian@linux.alibaba.com>
[ Upstream commit 56b5e65efe0001fb5f95e412ee4167363debfc46 ]
For virtio-net we were getting CPU stall warnings, and fixed it by
calling the scheduler: see f8bb51043945 ("virtio_net: suppress cpu stall
when free_unused_bufs").
This driver is similar so theoretically the same logic applies.
Signed-off-by: Xianting Tian <xianting.tian@linux.alibaba.com>
Message-Id: <20230609131817.712867-3-xianting.tian@linux.alibaba.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Stable-dep-of: 894f98e73983 ("virtio_console: do not free control-out buffers on remove")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/virtio_console.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/char/virtio_console.c b/drivers/char/virtio_console.c
index a4786f8108e35..fd3c83ccecc46 100644
--- a/drivers/char/virtio_console.c
+++ b/drivers/char/virtio_console.c
@@ -1941,6 +1941,7 @@ static void remove_vqs(struct ports_device *portdev)
flush_bufs(vq, true);
while ((buf = virtqueue_detach_unused_buf(vq)))
free_buf(buf, true);
+ cond_resched();
}
portdev->vdev->config->del_vqs(portdev->vdev);
kfree(portdev->in_vqs);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 440/982] virtio_console: do not free control-out buffers on remove
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (438 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 439/982] virtio-console: call scheduler when we free unused buffs Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 441/982] vhost-vdpa: dont install the eventfd_ctx_fdget() error in config_ctx Greg Kroah-Hartman
` (548 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jia Jia, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jia Jia <physicalmtea@gmail.com>
[ Upstream commit 894f98e73983f37354214a89a3a7fd35bf9e3072 ]
__send_control_msg() publishes &portdev->cpkt as the control-out
virtqueue cookie. remove_vqs() walks every virtqueue and passes leftover
cookies to free_buf(), which treats them as struct port_buffer and
reads sgpages.
If a control message is still on c_ovq when the device is unbound,
free_buf() reads past the ports_device object.
KASAN reported slab-out-of-bounds in free_buf():
free_buf
remove_vqs
virtcons_remove
unbind_store
The object was the ports_device allocated in virtcons_probe().
Drain c_ovq without freeing. The packet lives in portdev and is released
with it.
Fixes: a7a69ec0d8e4 ("virtio_console: free buffers after reset")
Signed-off-by: Jia Jia <physicalmtea@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260819021230.292696-1-physicalmtea@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/virtio_console.c | 21 ++++++++++++++++++---
1 file changed, 18 insertions(+), 3 deletions(-)
diff --git a/drivers/char/virtio_console.c b/drivers/char/virtio_console.c
index fd3c83ccecc46..4e790f6fe0c3f 100644
--- a/drivers/char/virtio_console.c
+++ b/drivers/char/virtio_console.c
@@ -1934,13 +1934,28 @@ static const struct file_operations portdev_fops = {
static void remove_vqs(struct ports_device *portdev)
{
struct virtqueue *vq;
+ bool multiport = use_multiport(portdev);
virtio_device_for_each_vq(portdev->vdev, vq) {
struct port_buffer *buf;
+ unsigned int len;
- flush_bufs(vq, true);
- while ((buf = virtqueue_detach_unused_buf(vq)))
- free_buf(buf, true);
+ /*
+ * c_ovq cookies are &portdev->cpkt, not port_buffer.
+ * Detach them but do not free_buf().
+ */
+ if (multiport && vq == portdev->c_ovq) {
+ spin_lock(&portdev->c_ovq_lock);
+ while (virtqueue_get_buf(vq, &len))
+ ;
+ while (virtqueue_detach_unused_buf(vq))
+ ;
+ spin_unlock(&portdev->c_ovq_lock);
+ } else {
+ flush_bufs(vq, true);
+ while ((buf = virtqueue_detach_unused_buf(vq)))
+ free_buf(buf, true);
+ }
cond_resched();
}
portdev->vdev->config->del_vqs(portdev->vdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 441/982] vhost-vdpa: dont install the eventfd_ctx_fdget() error in config_ctx
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (439 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 440/982] virtio_console: do not free control-out buffers on remove Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 442/982] vdpa_sim_blk: reject out-of-range sector starts Greg Kroah-Hartman
` (547 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yu Zhang, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Zhang <yuz08559@gmail.com>
[ Upstream commit e74a9fa50749b9940b4fb13199652325e08d3c4a ]
vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value
into v->config_ctx before checking it, so on failure the field briefly
holds an ERR_PTR:
ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);
swap(ctx, v->config_ctx);
if (!IS_ERR_OR_NULL(ctx))
eventfd_ctx_put(ctx);
if (IS_ERR(v->config_ctx)) {
long ret = PTR_ERR(v->config_ctx);
v->config_ctx = NULL;
return ret;
}
Commit 0bde59c1723a ("vhost-vdpa: set v->config_ctx to NULL if
eventfd_ctx_fdget() fails") added that clearing, and spelled out the
invariant the rest of the file relies on: "we consider 'v->config_ctx'
valid if it is not NULL". The window between the swap and the clearing
still breaks it. vhost_vdpa_config_cb() only tests for NULL, so a config
interrupt delivered inside the window hands the ERR_PTR to
eventfd_signal().
Check the fd before installing it instead. That closes the window and
matches how vhost_vring_ioctl() handles the same failure for the vq call
fd.
It also stops a rejected fd from tearing down a config interrupt that was
working: until now the swap replaced the live context and put it, so
after an EBADF the device silently stopped delivering config interrupts
until userspace installed a new fd.
Fixes: 776f395004d8 ("vhost_vdpa: Support config interrupt in vdpa")
Signed-off-by: Yu Zhang <yuz08559@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260807100025.19750-2-yuz08559@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/vhost/vdpa.c | 12 ++++--------
1 file changed, 4 insertions(+), 8 deletions(-)
diff --git a/drivers/vhost/vdpa.c b/drivers/vhost/vdpa.c
index df71ca25a1012..40c43e0611ca2 100644
--- a/drivers/vhost/vdpa.c
+++ b/drivers/vhost/vdpa.c
@@ -440,18 +440,14 @@ static long vhost_vdpa_set_config_call(struct vhost_vdpa *v, u32 __user *argp)
return -EFAULT;
ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);
+ if (IS_ERR(ctx))
+ return PTR_ERR(ctx);
+
swap(ctx, v->config_ctx);
- if (!IS_ERR_OR_NULL(ctx))
+ if (ctx)
eventfd_ctx_put(ctx);
- if (IS_ERR(v->config_ctx)) {
- long ret = PTR_ERR(v->config_ctx);
-
- v->config_ctx = NULL;
- return ret;
- }
-
v->vdpa->config->set_config_cb(v->vdpa, &cb);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 442/982] vdpa_sim_blk: reject out-of-range sector starts
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (440 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 441/982] vhost-vdpa: dont install the eventfd_ctx_fdget() error in config_ctx Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 443/982] virtio-pci: return IRQ_HANDLED after non-zero ISR Greg Kroah-Hartman
` (546 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linfeng Sun, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linfeng Sun <linfeng.sun.dev@gmail.com>
[ Upstream commit 0a8693f00c408d85f086ad85d29e7030bf1e2055 ]
vdpasim_blk_check_range() logs an invalid start sector but continues
validating the request. The subsequent unsigned capacity subtraction can
underflow and let an out-of-range buffer offset reach the data path.
The invalid offset is used by three request paths. VIRTIO_BLK_T_OUT
copies guest data to blk->buffer + offset through
vringh_iov_pull_iotlb(), causing an out-of-bounds write in
_copy_from_iter() or memcpy(). VIRTIO_BLK_T_IN copies from
blk->buffer + offset to the guest through vringh_iov_push_iotlb(),
causing an out-of-bounds read in _copy_to_iter().
VIRTIO_BLK_T_WRITE_ZEROES passes blk->buffer + offset to memset(),
causing an out-of-bounds write.
Reject starts at or beyond the capacity before the subtraction. Treat the
capacity boundary as invalid because the IN and OUT paths round byte counts
down to sectors for validation but later copy the original byte counts. A
sub-sector request at the capacity boundary would otherwise still access
past the end of the buffer.
I found this bug myself, though the patch was written with AI assistance.
Fixes: 7d189f617f83 ("vdpa_sim_blk: implement ramdisk behaviour")
Assisted-by: OpenAI-Codex:GPT-5
Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260901094800.25475-1-linfeng.sun.dev@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/vdpa/vdpa_sim/vdpa_sim_blk.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/vdpa/vdpa_sim/vdpa_sim_blk.c b/drivers/vdpa/vdpa_sim/vdpa_sim_blk.c
index f745926237a88..8b5b04a0b85ce 100644
--- a/drivers/vdpa/vdpa_sim/vdpa_sim_blk.c
+++ b/drivers/vdpa/vdpa_sim/vdpa_sim_blk.c
@@ -49,10 +49,11 @@ static char vdpasim_blk_id[VIRTIO_BLK_ID_BYTES] = "vdpa_blk_sim";
static bool vdpasim_blk_check_range(struct vdpasim *vdpasim, u64 start_sector,
u64 num_sectors, u64 max_sectors)
{
- if (start_sector > VDPASIM_BLK_CAPACITY) {
+ if (start_sector >= VDPASIM_BLK_CAPACITY) {
dev_dbg(&vdpasim->vdpa.dev,
"starting sector exceeds the capacity - start: 0x%llx capacity: 0x%x\n",
start_sector, VDPASIM_BLK_CAPACITY);
+ return false;
}
if (num_sectors > max_sectors) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 443/982] virtio-pci: return IRQ_HANDLED after non-zero ISR
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (441 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 442/982] vdpa_sim_blk: reject out-of-range sector starts Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 444/982] virtio_input: reset device if input_register_device() fails Greg Kroah-Hartman
` (545 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael S. Tsirkin, Andrew Stellman,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrew Stellman <astellman@stellman-greene.com>
[ Upstream commit 93fa09455fb1a9624b73d42ac1f83771f4818e80 ]
vp_interrupt() reads the ISR before dispatching config-change and
vring handling. Reading the ISR also clears it, so once the read
returns non-zero the interrupt was from this device and has already
been consumed.
Currently vp_interrupt() returns the result of vp_vring_interrupt().
For a config-change interrupt with no vring work, that can return
IRQ_NONE even though the ISR was non-zero and the interrupt was
handled.
Call vp_vring_interrupt() for any queue work, but once the ISR is
non-zero return IRQ_HANDLED.
Tested with QEMU virtio-blk-pci forced to INTx using vectors=0 and
pci=nomsi. On an idle device, 200 config-change interrupts were
generated using QMP block_resize.
Before this change, irq_handler_exit reported ret=unhandled and
/proc/irq/11/spurious increased from 0 to 200 unhandled interrupts.
After this change, irq_handler_exit reported ret=handled and the
unhandled count remained at 0.
The issue was found during an LLM-assisted Quality Playbook review.
Fixes: 77cf524654a8 ("virtio_pci: split up vp_interrupt")
Suggested-by: Michael S. Tsirkin <mst@redhat.com>
Assisted-by: LLM
Signed-off-by: Andrew Stellman <astellman@stellman-greene.com>
Message-ID: <20260904141318.30278-1-astellman@stellman-greene.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/virtio/virtio_pci_common.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/virtio/virtio_pci_common.c b/drivers/virtio/virtio_pci_common.c
index 6bfb67d4866c3..578806c4c2ae1 100644
--- a/drivers/virtio/virtio_pci_common.c
+++ b/drivers/virtio/virtio_pci_common.c
@@ -96,7 +96,9 @@ static irqreturn_t vp_interrupt(int irq, void *opaque)
if (isr & VIRTIO_PCI_ISR_CONFIG)
vp_config_changed(irq, opaque);
- return vp_vring_interrupt(irq, opaque);
+ vp_vring_interrupt(irq, opaque);
+
+ return IRQ_HANDLED;
}
static int vp_request_msix_vectors(struct virtio_device *vdev, int nvectors,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 444/982] virtio_input: reset device if input_register_device() fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (442 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 443/982] virtio-pci: return IRQ_HANDLED after non-zero ISR Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 445/982] virtio_input: stop callbacks before unregistering input device Greg Kroah-Hartman
` (544 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiong Weimin, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiong Weimin <xiongweimin@kylinos.cn>
[ Upstream commit 81489b32a21c9360f8750d1fb600155d27452e19 ]
Probe marks the device DRIVER_OK with virtio_device_ready() before
calling input_register_device(). If registration fails, the error path
cleared vi->ready and called del_vqs() while the device was still live,
so the device could keep DMA to queues that were already torn down.
Match remove/freeze: call virtio_reset_device() on that path before
tearing down the virtqueues.
Fixes: 271c865161c5 ("Add virtio-input driver.")
Signed-off-by: Xiong Weimin <xiongweimin@kylinos.cn>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260805032931.1606652-1-xiongweimin@kylinos.cn>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/virtio/virtio_input.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/virtio/virtio_input.c b/drivers/virtio/virtio_input.c
index 3aa46703872dc..54d90006e598f 100644
--- a/drivers/virtio/virtio_input.c
+++ b/drivers/virtio/virtio_input.c
@@ -327,6 +327,7 @@ static int virtinput_probe(struct virtio_device *vdev)
spin_lock_irqsave(&vi->lock, flags);
vi->ready = false;
spin_unlock_irqrestore(&vi->lock, flags);
+ virtio_reset_device(vdev);
err_mt_init_slots:
input_free_device(vi->idev);
err_input_alloc:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 445/982] virtio_input: stop callbacks before unregistering input device
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (443 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 444/982] virtio_input: reset device if input_register_device() fails Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 446/982] net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward Greg Kroah-Hartman
` (543 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Michael S. Tsirkin,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit d7808b37da0a619cf1fa541c2384e783fecc2480 ]
virtinput_remove() unregisters the input device before resetting the
virtio device. virtinput_recv_events() drops vi->lock around input_event(),
so clearing vi->ready does not stop a callback that passed the entry check.
It can still use vi->idev, requeue buffers and kick the queue.
Reset first, as virtinput_freeze() already does. With the preceding core
change, reset waits for callbacks before input_unregister_device() can
free vi->idev. Recheck vi->ready after taking the lock again: keep draining
completed events so an input packet is not truncated, but stop requeueing
buffers and kicking the queue.
With evdev attached, input_unregister_handle() currently waits for an RCU
grace period, which also waits out IRQ callbacks. This masks the lifetime
bug on PCI and MMIO, but does not protect sleepable callbacks on other
transports.
Fixes: 271c865161c5 ("Add virtio-input driver.")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260905152059.89560-3-kmehltretter@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/virtio/virtio_input.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/virtio/virtio_input.c b/drivers/virtio/virtio_input.c
index 54d90006e598f..cf8f179c896b8 100644
--- a/drivers/virtio/virtio_input.c
+++ b/drivers/virtio/virtio_input.c
@@ -46,9 +46,12 @@ static void virtinput_recv_events(struct virtqueue *vq)
le16_to_cpu(event->code),
le32_to_cpu(event->value));
spin_lock_irqsave(&vi->lock, flags);
+ if (!vi->ready)
+ continue;
virtinput_queue_evtbuf(vi, event);
}
- virtqueue_kick(vq);
+ if (vi->ready)
+ virtqueue_kick(vq);
}
spin_unlock_irqrestore(&vi->lock, flags);
}
@@ -347,8 +350,9 @@ static void virtinput_remove(struct virtio_device *vdev)
vi->ready = false;
spin_unlock_irqrestore(&vi->lock, flags);
- input_unregister_device(vi->idev);
+ /* Callbacks use vi->idev. */
virtio_reset_device(vdev);
+ input_unregister_device(vi->idev);
while ((buf = virtqueue_detach_unused_buf(vi->sts)) != NULL)
kfree(buf);
vdev->config->del_vqs(vdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 446/982] net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (444 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 445/982] virtio_input: stop callbacks before unregistering input device Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 447/982] net: ethernet: cortina: Fix budget accounting Greg Kroah-Hartman
` (542 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alice Mikityanska, Willem de Bruijn,
Willem de Bruijn, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alice Mikityanska <alice@isovalent.com>
[ Upstream commit 199271ebc71c1e0913b2fad988a7bff330a8828a ]
Commit 427faee167bc ("net: ipv6: introduce ip6_dst_mtu_maybe_forward")
dropped the IP6_MAX_MTU clamp that used to be present in ip6_mtu(). A
similar IPv4 commit ac6627a28dbf ("net: ipv4: Consolidate ipv4_mtu and
ip_dst_mtu_maybe_forward") preserves the IP_MAX_MTU clamp.
Restore the upper bound in the IPv6 flow to avoid potential 16-bit
overflows in forwarding paths.
Fixes: 427faee167bc ("net: ipv6: introduce ip6_dst_mtu_maybe_forward")
Signed-off-by: Alice Mikityanska <alice@isovalent.com>
Suggested-by: Willem de Bruijn <willemdebruijn.kernel@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260901195714.673548-5-alice.kernel@fastmail.im
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip6_route.h | 2 ++
1 file changed, 2 insertions(+)
diff --git a/include/net/ip6_route.h b/include/net/ip6_route.h
index 7c0184c09392f..9df55c2ee058c 100644
--- a/include/net/ip6_route.h
+++ b/include/net/ip6_route.h
@@ -343,6 +343,8 @@ static inline unsigned int ip6_dst_mtu_maybe_forward(const struct dst_entry *dst
rcu_read_unlock();
out:
+ mtu = min_t(unsigned int, mtu, IP6_MAX_MTU);
+
return mtu - lwtunnel_headroom(dst->lwtstate, mtu);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 447/982] net: ethernet: cortina: Fix budget accounting
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (445 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 446/982] net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 448/982] net: ethernet: cortina: Finish RX updates before NAPI completion Greg Kroah-Hartman
` (541 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joe Damato, Linus Walleij,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit a0de06d0da78a3db53de65dfd7452cc6d111f703 ]
The gmac_rx() function returns the remaining NAPI budget, but its
caller treats the return value as the number of packets received. An
idle poll therefore reports a full budget and remains scheduled.
Return the number of received packets instead. Preserve the existing
free queue refill accounting by adding that count directly; continuing
to subtract it from the budget would invert the refill behavior.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Link: https://lore.kernel.org/r/20260509-gemini-ethernet-fixes-v1-4-6c5d20ddc35b@kernel.org
Link: https://lore.kernel.org/r/20260512131456.189452-1-pabeni@redhat.com
Assisted-by: LLM
Reviewed-by: Joe Damato <joe@dama.to>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260903-gemini-ethernet-fixes-v2-1-2bbbd598ca6e@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 3f0e63c7342bd..b8e4045d9821c 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1455,6 +1455,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
unsigned int frame_len, frag_len;
struct gmac_rxdesc *rx = NULL;
struct gmac_queue_page *gpage;
+ unsigned int received = 0;
union gmac_rxdesc_0 word0;
union gmac_rxdesc_1 word1;
union gmac_rxdesc_3 word3;
@@ -1550,7 +1551,8 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
napi_gro_frags(&port->napi);
skb = NULL;
frag_nr = 0;
- --budget;
+ budget--;
+ received++;
}
continue;
@@ -1570,7 +1572,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
port->rx_skb = skb;
port->rx_frag_nr = frag_nr;
writew(r, ptr_reg);
- return budget;
+ return received;
}
static int gmac_napi_poll(struct napi_struct *napi, int budget)
@@ -1591,7 +1593,7 @@ static int gmac_napi_poll(struct napi_struct *napi, int budget)
++port->rx_napi_exits;
}
- port->freeq_refill += (budget - received);
+ port->freeq_refill += received;
if (port->freeq_refill > freeq_threshold) {
port->freeq_refill -= freeq_threshold;
geth_fill_freeq(geth, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 448/982] net: ethernet: cortina: Finish RX updates before NAPI completion
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (446 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 447/982] net: ethernet: cortina: Fix budget accounting Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 449/982] net: ethernet: cortina: Count dropped frames as NAPI work Greg Kroah-Hartman
` (540 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joe Damato, Linus Walleij,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit baa26841cb9a2cdc7e0e99d6854a4e3359bf7393 ]
napi_complete_done() releases ownership of the NAPI instance, but the
Gemini poll keeps the RX statistics writer section open and updates the
free queue after calling it. A new poll can therefore start while the old
writer is still active.
Finish the statistics and free queue updates before releasing ownership.
Only re-enable RX interrupts when napi_complete_done() reports successful
completion.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Suggested-by: Joe Damato <joe@dama.to>
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260903-gemini-ethernet-fixes-v2-2-2bbbd598ca6e@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index b8e4045d9821c..1092f558bc34f 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1586,12 +1586,10 @@ static int gmac_napi_poll(struct napi_struct *napi, int budget)
u64_stats_update_begin(&port->rx_stats_syncp);
received = gmac_rx(napi->dev, budget);
- if (received < budget) {
- napi_gro_flush(napi, false);
- napi_complete_done(napi, received);
- gmac_enable_rx_irq(napi->dev, 1);
+ if (received < budget)
++port->rx_napi_exits;
- }
+
+ u64_stats_update_end(&port->rx_stats_syncp);
port->freeq_refill += received;
if (port->freeq_refill > freeq_threshold) {
@@ -1599,7 +1597,9 @@ static int gmac_napi_poll(struct napi_struct *napi, int budget)
geth_fill_freeq(geth, true);
}
- u64_stats_update_end(&port->rx_stats_syncp);
+ if (received < budget && napi_complete_done(napi, received))
+ gmac_enable_rx_irq(napi->dev, 1);
+
return received;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 449/982] net: ethernet: cortina: Count dropped frames as NAPI work
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (447 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 448/982] net: ethernet: cortina: Finish RX updates before NAPI completion Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 450/982] net: ethernet: cortina: No mapping is a dropped rx Greg Kroah-Hartman
` (539 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit b856c552f556bc0341c1dbe0bf88e630fd1dc4b7 ]
The RX loop only consumes budget when it successfully delivers a frame.
Error paths keep consuming descriptors without reducing the budget, so a
stream of bad frames can process the entire receive ring in one poll.
Move the budget accounting to a common end-of-frame path. This counts
each completed frame as NAPI work whether it was delivered or dropped,
matching the behavior of the vendor driver.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260903-gemini-ethernet-fixes-v2-3-2bbbd598ca6e@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 1092f558bc34f..62ddaf3e99775 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1506,7 +1506,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
skb = NULL;
frag_nr = 0;
}
- continue;
+ goto next_desc;
}
page = gpage->page;
@@ -1528,7 +1528,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
} else if (!skb) {
put_page(page);
- continue;
+ goto next_desc;
}
if (word3.bits32 & EOF_BIT)
@@ -1551,10 +1551,8 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
napi_gro_frags(&port->napi);
skb = NULL;
frag_nr = 0;
- budget--;
- received++;
}
- continue;
+ goto next_desc;
err_drop:
if (skb) {
@@ -1567,6 +1565,13 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
put_page(page);
port->stats.rx_dropped++;
+
+next_desc:
+ /* Final or single-descriptor fragment, advance things */
+ if (word3.bits32 & EOF_BIT) {
+ budget--;
+ received++;
+ }
}
port->rx_skb = skb;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 450/982] net: ethernet: cortina: No mapping is a dropped rx
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (448 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 449/982] net: ethernet: cortina: Count dropped frames as NAPI work Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 451/982] net: ethernet: cortina: Count RX drops once per frame Greg Kroah-Hartman
` (538 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linus Walleij, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 2cb156213093a62b80cf40b1ec71738e93491971 ]
Increase stats.rx_dropped++ even if this is the first fragment
(skb == NULL) so we are doing proper accounting.
Fixes: b266bacba796 ("net: ethernet: cortina: Drop half-assembled SKB")
Link: https://sashiko.dev/#/patchset/20260505-gemini-ethernet-fix-v2-1-997c31d06079%40kernel.org
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260509-gemini-ethernet-fixes-v1-1-6c5d20ddc35b@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Stable-dep-of: 6520198c430c ("net: ethernet: cortina: Count RX drops once per frame")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 62ddaf3e99775..85d476301f3ea 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1500,9 +1500,9 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
gpage = gmac_get_queue_page(geth, port, mapping + PAGE_SIZE);
if (!gpage) {
dev_err(geth->dev, "could not find mapping\n");
+ port->stats.rx_dropped++;
if (skb) {
napi_free_frags(&port->napi);
- port->stats.rx_dropped++;
skb = NULL;
frag_nr = 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 451/982] net: ethernet: cortina: Count RX drops once per frame
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (449 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 450/982] net: ethernet: cortina: No mapping is a dropped rx Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 452/982] net: ethernet: cortina: Count RX descriptors for freeq refill Greg Kroah-Hartman
` (537 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joe Damato, Linus Walleij,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 6520198c430c81bcc367f0dd5e32f2fb740b9d51 ]
The absence of a partial skb means either that the driver is not
assembling a frame or that the current frame was already dropped.
Consequently, repeated descriptor errors can increment rx_dropped more
than once, while an orphaned descriptor chain can reach EOF without being
counted at all.
Track the dropping state across NAPI polls. Clear it at frame boundaries
and route mapping failures and orphaned continuations through the common
drop path so each discarded frame is counted exactly once.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Reported-by: Joe Damato <joe@dama.to>
Closes: https://lore.kernel.org/netdev/apdK5aMmvYssz35F@devvm20253.cco0.facebook.com/
Assisted-by: LLM
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260903-gemini-ethernet-fixes-v2-4-2bbbd598ca6e@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 41 +++++++++++++++------------
1 file changed, 23 insertions(+), 18 deletions(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 85d476301f3ea..03f8546bc224a 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -123,6 +123,7 @@ struct gemini_ethernet_port {
unsigned int rx_coalesce_nsecs;
struct sk_buff *rx_skb;
unsigned int rx_frag_nr;
+ bool rx_dropping;
unsigned int freeq_refill;
struct gmac_txq txq[TX_QUEUE_NUM];
@@ -1456,6 +1457,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
struct gmac_rxdesc *rx = NULL;
struct gmac_queue_page *gpage;
unsigned int received = 0;
+ bool dropping = port->rx_dropping;
union gmac_rxdesc_0 word0;
union gmac_rxdesc_1 word1;
union gmac_rxdesc_3 word3;
@@ -1477,6 +1479,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
w = rw.bits.wptr;
while (budget && w != r) {
+ page = NULL;
rx = port->rxq_ring + r;
word0 = rx->word0;
word1 = rx->word1;
@@ -1490,6 +1493,16 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
frame_len = word1.bits.byte_count;
page_offs = mapping & ~PAGE_MASK;
+ if (word3.bits32 & SOF_BIT) {
+ if (skb) {
+ napi_free_frags(&port->napi);
+ port->stats.rx_dropped++;
+ skb = NULL;
+ frag_nr = 0;
+ }
+ dropping = false;
+ }
+
if (!mapping) {
netdev_err(netdev,
"rxq[%u]: HW BUG: zero DMA desc\n", r);
@@ -1500,24 +1513,11 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
gpage = gmac_get_queue_page(geth, port, mapping + PAGE_SIZE);
if (!gpage) {
dev_err(geth->dev, "could not find mapping\n");
- port->stats.rx_dropped++;
- if (skb) {
- napi_free_frags(&port->napi);
- skb = NULL;
- frag_nr = 0;
- }
- goto next_desc;
+ goto err_drop;
}
page = gpage->page;
if (word3.bits32 & SOF_BIT) {
- if (skb) {
- napi_free_frags(&port->napi);
- port->stats.rx_dropped++;
- skb = NULL;
- frag_nr = 0;
- }
-
skb = gmac_skb_if_good_frame(port, word0, frame_len);
if (!skb)
goto err_drop;
@@ -1527,8 +1527,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
frag_nr = 0;
} else if (!skb) {
- put_page(page);
- goto next_desc;
+ goto err_drop;
}
if (word3.bits32 & EOF_BIT)
@@ -1561,21 +1560,26 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
frag_nr = 0;
}
- if (mapping)
+ if (page)
put_page(page);
- port->stats.rx_dropped++;
+ if (!dropping) {
+ port->stats.rx_dropped++;
+ dropping = true;
+ }
next_desc:
/* Final or single-descriptor fragment, advance things */
if (word3.bits32 & EOF_BIT) {
budget--;
received++;
+ dropping = false;
}
}
port->rx_skb = skb;
port->rx_frag_nr = frag_nr;
+ port->rx_dropping = dropping;
writew(r, ptr_reg);
return received;
}
@@ -1906,6 +1910,7 @@ static int gmac_stop(struct net_device *netdev)
napi_disable(&port->napi);
port->rx_skb = NULL;
port->rx_frag_nr = 0;
+ port->rx_dropping = false;
gmac_enable_irq(netdev, 0);
gmac_cleanup_rxq(netdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 452/982] net: ethernet: cortina: Count RX descriptors for freeq refill
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (450 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 451/982] net: ethernet: cortina: Count RX drops once per frame Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 453/982] drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER Greg Kroah-Hartman
` (536 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joe Damato, Linus Walleij,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit e89e88ad41d9f31c829c2af39c48313e8e48d5b0 ]
The software free queue provides one buffer fragment for every descriptor
moved to an RX queue. The refill heuristic instead advances by NAPI work,
which counts frames. A fragmented or discarded frame can consume several
queue entries while adding only one to the refill count.
Count the RX descriptors as they are consumed and report that separately
from NAPI work. Use the descriptor count to drive free queue refills.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Assisted-by: LLM
Reviewed-by: Joe Damato <joe@dama.to>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260903-gemini-ethernet-fixes-v2-5-2bbbd598ca6e@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 03f8546bc224a..fcc6018067226 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1445,7 +1445,8 @@ static struct sk_buff *gmac_skb_if_good_frame(struct gemini_ethernet_port *port,
return skb;
}
-static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
+static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget,
+ unsigned int *freeq_consumed)
{
struct gemini_ethernet_port *port = netdev_priv(netdev);
unsigned short m = (1 << port->rxq_order) - 1;
@@ -1453,6 +1454,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
void __iomem *ptr_reg = port->rxq_rwptr;
unsigned int frag_nr = port->rx_frag_nr;
struct sk_buff *skb = port->rx_skb;
+ unsigned int consumed = 0;
unsigned int frame_len, frag_len;
struct gmac_rxdesc *rx = NULL;
struct gmac_queue_page *gpage;
@@ -1488,6 +1490,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
r++;
r &= m;
+ consumed++;
frag_len = word0.bits.buffer_size;
frame_len = word1.bits.byte_count;
@@ -1580,6 +1583,7 @@ static unsigned int gmac_rx(struct net_device *netdev, unsigned int budget)
port->rx_skb = skb;
port->rx_frag_nr = frag_nr;
port->rx_dropping = dropping;
+ *freeq_consumed = consumed;
writew(r, ptr_reg);
return received;
}
@@ -1589,18 +1593,19 @@ static int gmac_napi_poll(struct napi_struct *napi, int budget)
struct gemini_ethernet_port *port = netdev_priv(napi->dev);
struct gemini_ethernet *geth = port->geth;
unsigned int freeq_threshold;
+ unsigned int freeq_consumed;
unsigned int received;
freeq_threshold = 1 << (geth->freeq_order - 1);
u64_stats_update_begin(&port->rx_stats_syncp);
- received = gmac_rx(napi->dev, budget);
+ received = gmac_rx(napi->dev, budget, &freeq_consumed);
if (received < budget)
++port->rx_napi_exits;
u64_stats_update_end(&port->rx_stats_syncp);
- port->freeq_refill += received;
+ port->freeq_refill += freeq_consumed;
if (port->freeq_refill > freeq_threshold) {
port->freeq_refill -= freeq_threshold;
geth_fill_freeq(geth, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 453/982] drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (451 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 452/982] net: ethernet: cortina: Count RX descriptors for freeq refill Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 454/982] ALSA: hda: Introduce auto cleanup macros for PM Greg Kroah-Hartman
` (535 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Thomas Zimmermann,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit f97802dd98b27e45c04293f9926f07642578b23f ]
CONFIG_DRM_KMS_CMA_HELPER was removed by commit 09717af7d13d ("drm:
Remove CONFIG_DRM_KMS_CMA_HELPER option"). When commit 6bcfe8eaeef0
("drm/fb: rename FB CMA helpers to FB DMA helpers") later renamed the
select in this Kconfig to CONFIG_DRM_KMS_DMA_HELPER, no symbol of that
name existed, and git log -S finds no Kconfig file that has defined one
since. The select is silently ignored. The driver already selects
CONFIG_DRM_GEM_DMA_HELPER, which is what it needs.
Remove the dead line.
Fixes: 6bcfe8eaeef0 ("drm/fb: rename FB CMA helpers to FB DMA helpers")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260905080344.34077-1-kmehltretter@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/logicvc/Kconfig | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/gpu/drm/logicvc/Kconfig b/drivers/gpu/drm/logicvc/Kconfig
index 1df22a852a23e..283dca51e4bdd 100644
--- a/drivers/gpu/drm/logicvc/Kconfig
+++ b/drivers/gpu/drm/logicvc/Kconfig
@@ -3,7 +3,6 @@ config DRM_LOGICVC
depends on DRM
depends on OF || COMPILE_TEST
select DRM_KMS_HELPER
- select DRM_KMS_DMA_HELPER
select DRM_GEM_DMA_HELPER
select REGMAP
select REGMAP_MMIO
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 454/982] ALSA: hda: Introduce auto cleanup macros for PM
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (452 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 453/982] drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 455/982] ALSA: hda/common: Use cleanup macros for PM controls Greg Kroah-Hartman
` (534 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 5d8c9c987fbdd65677315198c2b1f35a440d7cdf ]
The temporary power up/down of the codec via snd_hda_power_up() and
_down() (or snd_hda_power_up_pm() and _down_pm()) is seen in various
places. This patch introduces simple auto-cleanup macros for those
call patterns, so that the drivers don't have to call the
corresponding power-down calls explicitly.
Namely,
err = snd_hda_power_up(codec);
if (err < 0)
return err;
....
snd_power_down(codec);
can drop the *_down() call by replacing with
CLASS(snd_hda_power, pm)(codec);
if (pm.err < 0)
return pm.err;
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20250827072916.31933-2-tiwai@suse.de
Stable-dep-of: 728478874312 ("ALSA: hda: Report a change when only the channel status bytes move")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/hda_codec.h | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/include/sound/hda_codec.h b/include/sound/hda_codec.h
index 4ca45d5895dfd..5788cec54a378 100644
--- a/include/sound/hda_codec.h
+++ b/include/sound/hda_codec.h
@@ -512,6 +512,36 @@ static inline bool hda_codec_need_resume(struct hda_codec *codec)
return !codec->relaxed_resume && codec->jacktbl.used;
}
+/*
+ * PM with auto-cleanup: call like CLASS(snd_hda_power, pm)(codec)
+ * If the error handling is needed, refer pm.err.
+ */
+struct __hda_power_obj {
+ struct hda_codec *codec;
+ int err;
+};
+
+static inline struct __hda_power_obj __snd_hda_power_up(struct hda_codec *codec)
+{
+ struct __hda_power_obj T = { .codec = codec };
+ T.err = snd_hda_power_up(codec);
+ return T;
+}
+
+static inline struct __hda_power_obj __snd_hda_power_up_pm(struct hda_codec *codec)
+{
+ struct __hda_power_obj T = { .codec = codec };
+ T.err = snd_hda_power_up_pm(codec);
+ return T;
+}
+
+DEFINE_CLASS(snd_hda_power, struct __hda_power_obj,
+ snd_hda_power_down((_T).codec), __snd_hda_power_up(codec),
+ struct hda_codec *codec)
+DEFINE_CLASS(snd_hda_power_pm, struct __hda_power_obj,
+ snd_hda_power_down_pm((_T).codec), __snd_hda_power_up_pm(codec),
+ struct hda_codec *codec)
+
#ifdef CONFIG_SND_HDA_PATCH_LOADER
/*
* patch firmware
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 455/982] ALSA: hda/common: Use cleanup macros for PM controls
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (453 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 454/982] ALSA: hda: Introduce auto cleanup macros for PM Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 456/982] ALSA: hda/common: Use guard() for mutex locks Greg Kroah-Hartman
` (533 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 8dad6b3dac2794c52d63b2336138392eddc17936 ]
The new macro CLASS(snd_hda_power_pm) can replace the manual
snd_hda_power_up_pm() and _down() calls gracefully.
A part of the code in codec_exec_verb() is factored out to a function,
so that the auto-cleanup can be well scoped.
Merely cleanups and no functional changes.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20250827072916.31933-6-tiwai@suse.de
Stable-dep-of: 728478874312 ("ALSA: hda: Report a change when only the channel status bytes move")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/hda_codec.c | 30 +++++++++++++++++++-----------
sound/pci/hda/hda_proc.c | 4 +---
sound/pci/hda/hda_sysfs.c | 11 ++++-------
3 files changed, 24 insertions(+), 21 deletions(-)
diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c
index aef60044cb8a2..360ffe6af5a42 100644
--- a/sound/pci/hda/hda_codec.c
+++ b/sound/pci/hda/hda_codec.c
@@ -31,6 +31,23 @@
#define codec_has_clkstop(codec) \
((codec)->core.power_caps & AC_PWRST_CLKSTOP)
+static int call_exec_verb(struct hda_bus *bus, struct hda_codec *codec,
+ unsigned int cmd, unsigned int flags,
+ unsigned int *res)
+{
+ int err;
+
+ CLASS(snd_hda_power_pm, pm)(codec);
+ mutex_lock(&bus->core.cmd_mutex);
+ if (flags & HDA_RW_NO_RESPONSE_FALLBACK)
+ bus->no_response_fallback = 1;
+ err = snd_hdac_bus_exec_verb_unlocked(&bus->core, codec->core.addr,
+ cmd, res);
+ bus->no_response_fallback = 0;
+ mutex_unlock(&bus->core.cmd_mutex);
+ return err;
+}
+
/*
* Send and receive a verb - passed to exec_verb override for hdac_device
*/
@@ -45,15 +62,7 @@ static int codec_exec_verb(struct hdac_device *dev, unsigned int cmd,
return -1;
again:
- snd_hda_power_up_pm(codec);
- mutex_lock(&bus->core.cmd_mutex);
- if (flags & HDA_RW_NO_RESPONSE_FALLBACK)
- bus->no_response_fallback = 1;
- err = snd_hdac_bus_exec_verb_unlocked(&bus->core, codec->core.addr,
- cmd, res);
- bus->no_response_fallback = 0;
- mutex_unlock(&bus->core.cmd_mutex);
- snd_hda_power_down_pm(codec);
+ err = call_exec_verb(bus, codec, cmd, flags, res);
if (!codec_in_pm(codec) && res && err == -EAGAIN) {
if (bus->response_reset) {
codec_dbg(codec,
@@ -645,12 +654,11 @@ static void hda_jackpoll_work(struct work_struct *work)
return;
/* the power-up/down sequence triggers the runtime resume */
- snd_hda_power_up(codec);
+ CLASS(snd_hda_power, pm)(codec);
/* update jacks manually if polling is required, too */
snd_hda_jack_set_dirty_all(codec);
snd_hda_jack_poll_all(codec);
schedule_delayed_work(&codec->jackpoll_work, codec->jackpoll_interval);
- snd_hda_power_down(codec);
}
/* release all pincfg lists */
diff --git a/sound/pci/hda/hda_proc.c b/sound/pci/hda/hda_proc.c
index e8a4cf3c84d82..f7ad5a18c8797 100644
--- a/sound/pci/hda/hda_proc.c
+++ b/sound/pci/hda/hda_proc.c
@@ -782,7 +782,7 @@ static void print_codec_info(struct snd_info_entry *entry,
fg = codec->core.afg;
if (!fg)
return;
- snd_hda_power_up(codec);
+ CLASS(snd_hda_power, pm)(codec);
snd_iprintf(buffer, "Default PCM:\n");
print_pcm_caps(buffer, codec, fg);
snd_iprintf(buffer, "Default Amp-In caps: ");
@@ -795,7 +795,6 @@ static void print_codec_info(struct snd_info_entry *entry,
nodes = snd_hda_get_sub_nodes(codec, fg, &nid);
if (! nid || nodes < 0) {
snd_iprintf(buffer, "Invalid AFG subtree\n");
- snd_hda_power_down(codec);
return;
}
@@ -932,7 +931,6 @@ static void print_codec_info(struct snd_info_entry *entry,
kfree(conn);
}
- snd_hda_power_down(codec);
}
/*
diff --git a/sound/pci/hda/hda_sysfs.c b/sound/pci/hda/hda_sysfs.c
index 69ebc37a4d6f3..80359e518ee55 100644
--- a/sound/pci/hda/hda_sysfs.c
+++ b/sound/pci/hda/hda_sysfs.c
@@ -131,21 +131,18 @@ static int reconfig_codec(struct hda_codec *codec)
{
int err;
- snd_hda_power_up(codec);
+ CLASS(snd_hda_power, pm)(codec);
codec_info(codec, "hda-codec: reconfiguring\n");
err = snd_hda_codec_reset(codec);
if (err < 0) {
codec_err(codec,
"The codec is being used, can't reconfigure.\n");
- goto error;
+ return err;
}
err = device_reprobe(hda_codec_dev(codec));
if (err < 0)
- goto error;
- err = snd_card_register(codec->card);
- error:
- snd_hda_power_down(codec);
- return err;
+ return err;
+ return snd_card_register(codec->card);
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 456/982] ALSA: hda/common: Use guard() for mutex locks
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (454 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 455/982] ALSA: hda/common: Use cleanup macros for PM controls Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 457/982] ALSA: hda: Report a change when only the channel status bytes move Greg Kroah-Hartman
` (532 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 62dd3851d2450a5fb2259da1f0391b5870e07577 ]
Replace the manual mutex lock/unlock pairs with guard().
Only code refactoring, and no behavior change.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20250827072916.31933-8-tiwai@suse.de
Stable-dep-of: 728478874312 ("ALSA: hda: Report a change when only the channel status bytes move")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/hda_codec.c | 89 ++++++++++++++--------------------
sound/pci/hda/hda_controller.c | 24 ++++-----
sound/pci/hda/hda_sysfs.c | 66 ++++++++++---------------
3 files changed, 74 insertions(+), 105 deletions(-)
diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c
index 360ffe6af5a42..600714881335b 100644
--- a/sound/pci/hda/hda_codec.c
+++ b/sound/pci/hda/hda_codec.c
@@ -38,13 +38,12 @@ static int call_exec_verb(struct hda_bus *bus, struct hda_codec *codec,
int err;
CLASS(snd_hda_power_pm, pm)(codec);
- mutex_lock(&bus->core.cmd_mutex);
+ guard(mutex)(&bus->core.cmd_mutex);
if (flags & HDA_RW_NO_RESPONSE_FALLBACK)
bus->no_response_fallback = 1;
err = snd_hdac_bus_exec_verb_unlocked(&bus->core, codec->core.addr,
cmd, res);
bus->no_response_fallback = 0;
- mutex_unlock(&bus->core.cmd_mutex);
return err;
}
@@ -541,11 +540,11 @@ unsigned int snd_hda_codec_get_pincfg(struct hda_codec *codec, hda_nid_t nid)
#ifdef CONFIG_SND_HDA_RECONFIG
{
unsigned int cfg = 0;
- mutex_lock(&codec->user_mutex);
- pin = look_up_pincfg(codec, &codec->user_pins, nid);
- if (pin)
- cfg = pin->cfg;
- mutex_unlock(&codec->user_mutex);
+ scoped_guard(mutex, &codec->user_mutex) {
+ pin = look_up_pincfg(codec, &codec->user_pins, nid);
+ if (pin)
+ cfg = pin->cfg;
+ }
if (cfg)
return cfg;
}
@@ -2213,13 +2212,12 @@ static int snd_hda_spdif_default_get(struct snd_kcontrol *kcontrol,
if (WARN_ON(codec->spdif_out.used <= idx))
return -EINVAL;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
ucontrol->value.iec958.status[0] = spdif->status & 0xff;
ucontrol->value.iec958.status[1] = (spdif->status >> 8) & 0xff;
ucontrol->value.iec958.status[2] = (spdif->status >> 16) & 0xff;
ucontrol->value.iec958.status[3] = (spdif->status >> 24) & 0xff;
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
@@ -2322,7 +2320,7 @@ static int snd_hda_spdif_default_put(struct snd_kcontrol *kcontrol,
if (WARN_ON(codec->spdif_out.used <= idx))
return -EINVAL;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
nid = spdif->nid;
spdif->status = ucontrol->value.iec958.status[0] |
@@ -2335,7 +2333,6 @@ static int snd_hda_spdif_default_put(struct snd_kcontrol *kcontrol,
spdif->ctls = val;
if (change && nid != (u16)-1)
set_dig_out_convert(codec, nid, val & 0xff, (val >> 8) & 0xff);
- mutex_unlock(&codec->spdif_mutex);
return change;
}
@@ -2350,10 +2347,9 @@ static int snd_hda_spdif_out_switch_get(struct snd_kcontrol *kcontrol,
if (WARN_ON(codec->spdif_out.used <= idx))
return -EINVAL;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
ucontrol->value.integer.value[0] = spdif->ctls & AC_DIG1_ENABLE;
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
@@ -2380,7 +2376,7 @@ static int snd_hda_spdif_out_switch_put(struct snd_kcontrol *kcontrol,
if (WARN_ON(codec->spdif_out.used <= idx))
return -EINVAL;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
nid = spdif->nid;
val = spdif->ctls & ~AC_DIG1_ENABLE;
@@ -2390,7 +2386,6 @@ static int snd_hda_spdif_out_switch_put(struct snd_kcontrol *kcontrol,
spdif->ctls = val;
if (change && nid != (u16)-1)
set_spdif_ctls(codec, nid, val & 0xff, -1);
- mutex_unlock(&codec->spdif_mutex);
return change;
}
@@ -2535,10 +2530,9 @@ void snd_hda_spdif_ctls_unassign(struct hda_codec *codec, int idx)
if (WARN_ON(codec->spdif_out.used <= idx))
return;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
spdif->nid = (u16)-1;
- mutex_unlock(&codec->spdif_mutex);
}
EXPORT_SYMBOL_GPL(snd_hda_spdif_ctls_unassign);
@@ -2557,14 +2551,13 @@ void snd_hda_spdif_ctls_assign(struct hda_codec *codec, int idx, hda_nid_t nid)
if (WARN_ON(codec->spdif_out.used <= idx))
return;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
if (spdif->nid != nid) {
spdif->nid = nid;
val = spdif->ctls;
set_spdif_ctls(codec, nid, val & 0xff, (val >> 8) & 0xff);
}
- mutex_unlock(&codec->spdif_mutex);
}
EXPORT_SYMBOL_GPL(snd_hda_spdif_ctls_assign);
@@ -2639,14 +2632,13 @@ static int snd_hda_spdif_in_switch_put(struct snd_kcontrol *kcontrol,
unsigned int val = !!ucontrol->value.integer.value[0];
int change;
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
change = codec->spdif_in_enable != val;
if (change) {
codec->spdif_in_enable = val;
snd_hdac_regmap_write(&codec->core, nid,
AC_VERB_SET_DIGI_CONVERT_1, val);
}
- mutex_unlock(&codec->spdif_mutex);
return change;
}
@@ -3205,7 +3197,8 @@ int snd_hda_codec_prepare(struct hda_codec *codec,
struct snd_pcm_substream *substream)
{
int ret;
- mutex_lock(&codec->bus->prepare_mutex);
+
+ guard(mutex)(&codec->bus->prepare_mutex);
if (hinfo->ops.prepare)
ret = hinfo->ops.prepare(hinfo, codec, stream, format,
substream);
@@ -3213,7 +3206,6 @@ int snd_hda_codec_prepare(struct hda_codec *codec,
ret = -ENODEV;
if (ret >= 0)
purify_inactive_streams(codec);
- mutex_unlock(&codec->bus->prepare_mutex);
return ret;
}
EXPORT_SYMBOL_GPL(snd_hda_codec_prepare);
@@ -3230,10 +3222,9 @@ void snd_hda_codec_cleanup(struct hda_codec *codec,
struct hda_pcm_stream *hinfo,
struct snd_pcm_substream *substream)
{
- mutex_lock(&codec->bus->prepare_mutex);
+ guard(mutex)(&codec->bus->prepare_mutex);
if (hinfo->ops.cleanup)
hinfo->ops.cleanup(hinfo, codec, substream);
- mutex_unlock(&codec->bus->prepare_mutex);
}
EXPORT_SYMBOL_GPL(snd_hda_codec_cleanup);
@@ -3664,12 +3655,11 @@ static void cleanup_dig_out_stream(struct hda_codec *codec, hda_nid_t nid)
int snd_hda_multi_out_dig_open(struct hda_codec *codec,
struct hda_multi_out *mout)
{
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
if (mout->dig_out_used == HDA_DIG_ANALOG_DUP)
/* already opened as analog dup; reset it once */
cleanup_dig_out_stream(codec, mout->dig_out_nid);
mout->dig_out_used = HDA_DIG_EXCLUSIVE;
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
EXPORT_SYMBOL_GPL(snd_hda_multi_out_dig_open);
@@ -3688,9 +3678,8 @@ int snd_hda_multi_out_dig_prepare(struct hda_codec *codec,
unsigned int format,
struct snd_pcm_substream *substream)
{
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
setup_dig_out_stream(codec, mout->dig_out_nid, stream_tag, format);
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
EXPORT_SYMBOL_GPL(snd_hda_multi_out_dig_prepare);
@@ -3703,9 +3692,8 @@ EXPORT_SYMBOL_GPL(snd_hda_multi_out_dig_prepare);
int snd_hda_multi_out_dig_cleanup(struct hda_codec *codec,
struct hda_multi_out *mout)
{
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
cleanup_dig_out_stream(codec, mout->dig_out_nid);
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
EXPORT_SYMBOL_GPL(snd_hda_multi_out_dig_cleanup);
@@ -3718,9 +3706,8 @@ EXPORT_SYMBOL_GPL(snd_hda_multi_out_dig_cleanup);
int snd_hda_multi_out_dig_close(struct hda_codec *codec,
struct hda_multi_out *mout)
{
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
mout->dig_out_used = 0;
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
EXPORT_SYMBOL_GPL(snd_hda_multi_out_dig_close);
@@ -3759,7 +3746,7 @@ int snd_hda_multi_out_analog_open(struct hda_codec *codec,
&mout->spdif_formats,
&mout->spdif_maxbps);
}
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
if (mout->share_spdif) {
if ((runtime->hw.rates & mout->spdif_rates) &&
(runtime->hw.formats & mout->spdif_formats)) {
@@ -3772,7 +3759,6 @@ int snd_hda_multi_out_analog_open(struct hda_codec *codec,
/* FIXME: need notify? */
}
}
- mutex_unlock(&codec->spdif_mutex);
}
return snd_pcm_hw_constraint_step(substream->runtime, 0,
SNDRV_PCM_HW_PARAM_CHANNELS, 2);
@@ -3801,23 +3787,23 @@ int snd_hda_multi_out_analog_prepare(struct hda_codec *codec,
struct hda_spdif_out *spdif;
int i;
- mutex_lock(&codec->spdif_mutex);
- spdif = snd_hda_spdif_out_of_nid(codec, mout->dig_out_nid);
- if (mout->dig_out_nid && mout->share_spdif &&
- mout->dig_out_used != HDA_DIG_EXCLUSIVE) {
- if (chs == 2 && spdif != NULL &&
- snd_hda_is_supported_format(codec, mout->dig_out_nid,
- format) &&
- !(spdif->status & IEC958_AES0_NONAUDIO)) {
- mout->dig_out_used = HDA_DIG_ANALOG_DUP;
- setup_dig_out_stream(codec, mout->dig_out_nid,
- stream_tag, format);
- } else {
- mout->dig_out_used = 0;
- cleanup_dig_out_stream(codec, mout->dig_out_nid);
+ scoped_guard(mutex, &codec->spdif_mutex) {
+ spdif = snd_hda_spdif_out_of_nid(codec, mout->dig_out_nid);
+ if (mout->dig_out_nid && mout->share_spdif &&
+ mout->dig_out_used != HDA_DIG_EXCLUSIVE) {
+ if (chs == 2 && spdif != NULL &&
+ snd_hda_is_supported_format(codec, mout->dig_out_nid,
+ format) &&
+ !(spdif->status & IEC958_AES0_NONAUDIO)) {
+ mout->dig_out_used = HDA_DIG_ANALOG_DUP;
+ setup_dig_out_stream(codec, mout->dig_out_nid,
+ stream_tag, format);
+ } else {
+ mout->dig_out_used = 0;
+ cleanup_dig_out_stream(codec, mout->dig_out_nid);
+ }
}
}
- mutex_unlock(&codec->spdif_mutex);
/* front */
snd_hda_codec_setup_stream(codec, nids[HDA_FRONT], stream_tag,
@@ -3884,12 +3870,11 @@ int snd_hda_multi_out_analog_cleanup(struct hda_codec *codec,
if (mout->extra_out_nid[i])
snd_hda_codec_cleanup_stream(codec,
mout->extra_out_nid[i]);
- mutex_lock(&codec->spdif_mutex);
+ guard(mutex)(&codec->spdif_mutex);
if (mout->dig_out_nid && mout->dig_out_used == HDA_DIG_ANALOG_DUP) {
cleanup_dig_out_stream(codec, mout->dig_out_nid);
mout->dig_out_used = 0;
}
- mutex_unlock(&codec->spdif_mutex);
return 0;
}
EXPORT_SYMBOL_GPL(snd_hda_multi_out_analog_cleanup);
diff --git a/sound/pci/hda/hda_controller.c b/sound/pci/hda/hda_controller.c
index 083df287c1a48..16ff8e510996b 100644
--- a/sound/pci/hda/hda_controller.c
+++ b/sound/pci/hda/hda_controller.c
@@ -92,12 +92,12 @@ static int azx_pcm_close(struct snd_pcm_substream *substream)
struct azx_dev *azx_dev = get_azx_dev(substream);
trace_azx_pcm_close(chip, azx_dev);
- mutex_lock(&chip->open_mutex);
- azx_release_device(azx_dev);
- if (hinfo->ops.close)
- hinfo->ops.close(hinfo, apcm->codec, substream);
- snd_hda_power_down(apcm->codec);
- mutex_unlock(&chip->open_mutex);
+ scoped_guard(mutex, &chip->open_mutex) {
+ azx_release_device(azx_dev);
+ if (hinfo->ops.close)
+ hinfo->ops.close(hinfo, apcm->codec, substream);
+ snd_hda_power_down(apcm->codec);
+ }
snd_hda_codec_pcm_put(apcm->info);
return 0;
}
@@ -1132,12 +1132,12 @@ static int probe_codec(struct azx *chip, int addr)
int err;
unsigned int res = -1;
- mutex_lock(&bus->cmd_mutex);
- chip->probing = 1;
- azx_send_cmd(bus, cmd);
- err = azx_get_response(bus, addr, &res);
- chip->probing = 0;
- mutex_unlock(&bus->cmd_mutex);
+ scoped_guard(mutex, &bus->cmd_mutex) {
+ chip->probing = 1;
+ azx_send_cmd(bus, cmd);
+ err = azx_get_response(bus, addr, &res);
+ chip->probing = 0;
+ }
if (err < 0 || res == -1)
return -EIO;
dev_dbg(chip->card->dev, "codec #%d probed OK\n", addr);
diff --git a/sound/pci/hda/hda_sysfs.c b/sound/pci/hda/hda_sysfs.c
index 80359e518ee55..5d95f24135dc1 100644
--- a/sound/pci/hda/hda_sysfs.c
+++ b/sound/pci/hda/hda_sysfs.c
@@ -83,12 +83,12 @@ static ssize_t pin_configs_show(struct hda_codec *codec,
{
const struct hda_pincfg *pin;
int i, len = 0;
- mutex_lock(&codec->user_mutex);
+
+ guard(mutex)(&codec->user_mutex);
snd_array_for_each(list, i, pin) {
len += sysfs_emit_at(buf, len, "0x%02x 0x%08x\n",
pin->nid, pin->cfg);
}
- mutex_unlock(&codec->user_mutex);
return len;
}
@@ -217,12 +217,12 @@ static ssize_t init_verbs_show(struct device *dev,
struct hda_codec *codec = dev_get_drvdata(dev);
const struct hda_verb *v;
int i, len = 0;
- mutex_lock(&codec->user_mutex);
+
+ guard(mutex)(&codec->user_mutex);
snd_array_for_each(&codec->init_verbs, i, v) {
len += sysfs_emit_at(buf, len, "0x%02x 0x%03x 0x%04x\n",
v->nid, v->verb, v->param);
}
- mutex_unlock(&codec->user_mutex);
return len;
}
@@ -235,16 +235,13 @@ static int parse_init_verbs(struct hda_codec *codec, const char *buf)
return -EINVAL;
if (!nid || !verb)
return -EINVAL;
- mutex_lock(&codec->user_mutex);
+ guard(mutex)(&codec->user_mutex);
v = snd_array_new(&codec->init_verbs);
- if (!v) {
- mutex_unlock(&codec->user_mutex);
+ if (!v)
return -ENOMEM;
- }
v->nid = nid;
v->verb = verb;
v->param = param;
- mutex_unlock(&codec->user_mutex);
return 0;
}
@@ -266,12 +263,12 @@ static ssize_t hints_show(struct device *dev,
struct hda_codec *codec = dev_get_drvdata(dev);
const struct hda_hint *hint;
int i, len = 0;
- mutex_lock(&codec->user_mutex);
+
+ guard(mutex)(&codec->user_mutex);
snd_array_for_each(&codec->hints, i, hint) {
len += sysfs_emit_at(buf, len, "%s = %s\n",
hint->key, hint->val);
}
- mutex_unlock(&codec->user_mutex);
return len;
}
@@ -326,7 +323,7 @@ static int parse_hints(struct hda_codec *codec, const char *buf)
val = skip_spaces(val);
remove_trail_spaces(key);
remove_trail_spaces(val);
- mutex_lock(&codec->user_mutex);
+ guard(mutex)(&codec->user_mutex);
hint = get_hint(codec, key);
if (hint) {
/* replace */
@@ -347,7 +344,6 @@ static int parse_hints(struct hda_codec *codec, const char *buf)
err = -ENOMEM;
}
unlock:
- mutex_unlock(&codec->user_mutex);
if (err)
kfree(key);
return err;
@@ -374,16 +370,14 @@ static ssize_t user_pin_configs_show(struct device *dev,
static int parse_user_pin_configs(struct hda_codec *codec, const char *buf)
{
- int nid, cfg, err;
+ int nid, cfg;
if (sscanf(buf, "%i %i", &nid, &cfg) != 2)
return -EINVAL;
if (!nid)
return -EINVAL;
- mutex_lock(&codec->user_mutex);
- err = snd_hda_add_pincfg(codec, &codec->user_pins, nid, cfg);
- mutex_unlock(&codec->user_mutex);
- return err;
+ guard(mutex)(&codec->user_mutex);
+ return snd_hda_add_pincfg(codec, &codec->user_pins, nid, cfg);
}
static ssize_t user_pin_configs_store(struct device *dev,
@@ -431,26 +425,19 @@ EXPORT_SYMBOL_GPL(snd_hda_get_hint);
int snd_hda_get_bool_hint(struct hda_codec *codec, const char *key)
{
const char *p;
- int ret;
- mutex_lock(&codec->user_mutex);
+ guard(mutex)(&codec->user_mutex);
p = snd_hda_get_hint(codec, key);
if (!p || !*p)
- ret = -ENOENT;
- else {
- switch (toupper(*p)) {
- case 'T': /* true */
- case 'Y': /* yes */
- case '1':
- ret = 1;
- break;
- default:
- ret = 0;
- break;
- }
+ return -ENOENT;
+ switch (toupper(*p)) {
+ case 'T': /* true */
+ case 'Y': /* yes */
+ case '1':
+ return 1;
+ default:
+ return 0;
}
- mutex_unlock(&codec->user_mutex);
- return ret;
}
EXPORT_SYMBOL_GPL(snd_hda_get_bool_hint);
@@ -468,20 +455,17 @@ int snd_hda_get_int_hint(struct hda_codec *codec, const char *key, int *valp)
{
const char *p;
unsigned long val;
- int ret;
- mutex_lock(&codec->user_mutex);
+ guard(mutex)(&codec->user_mutex);
p = snd_hda_get_hint(codec, key);
if (!p)
- ret = -ENOENT;
+ return -ENOENT;
else if (kstrtoul(p, 0, &val))
- ret = -EINVAL;
+ return -EINVAL;
else {
*valp = val;
- ret = 0;
+ return 0;
}
- mutex_unlock(&codec->user_mutex);
- return ret;
}
EXPORT_SYMBOL_GPL(snd_hda_get_int_hint);
#endif /* CONFIG_SND_HDA_RECONFIG */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 457/982] ALSA: hda: Report a change when only the channel status bytes move
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (455 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 456/982] ALSA: hda/common: Use guard() for mutex locks Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 458/982] ice: add missing xa_destroy for sched_node_ids Greg Kroah-Hartman
` (531 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit 7284788743121ec8bed556b00f830dc52ad9955d ]
The put() callback of "IEC958 Playback Default" returns whether the
converted register value moved. The convert_from_spdif_status() helper
reads part of the first two channel status bytes and none of the last
two, while the get() callback returns all four. So a write that lands
only in the bits it does not read changes what userspace reads back and
reports no change. Of the 31 bits above the mode bit, 20 are such bits
in consumer mode and 29 in professional mode. The core notifies only on
a positive return.
Toggling status[2] bit 0 on an HDA HDMI codec moves the read-back from
04 00 00 00 to 04 00 01 00 with no event. Toggling the non-audio bit
in status[0] gives one.
Compare the stored status as well, the way the ac97 code does. The
write to the codec stays gated on the converted value.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Assisted-by: Claude:claude-opus-5
Link: https://patch.msgid.link/20260908134153.1614273-1-sammiee5311@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/hda_codec.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c
index 600714881335b..b715a6c366a8c 100644
--- a/sound/pci/hda/hda_codec.c
+++ b/sound/pci/hda/hda_codec.c
@@ -2315,6 +2315,7 @@ static int snd_hda_spdif_default_put(struct snd_kcontrol *kcontrol,
int idx = kcontrol->private_value;
struct hda_spdif_out *spdif;
hda_nid_t nid;
+ unsigned int old_status;
unsigned short val;
int change;
@@ -2323,6 +2324,7 @@ static int snd_hda_spdif_default_put(struct snd_kcontrol *kcontrol,
guard(mutex)(&codec->spdif_mutex);
spdif = snd_array_elem(&codec->spdif_out, idx);
nid = spdif->nid;
+ old_status = spdif->status;
spdif->status = ucontrol->value.iec958.status[0] |
((unsigned int)ucontrol->value.iec958.status[1] << 8) |
((unsigned int)ucontrol->value.iec958.status[2] << 16) |
@@ -2333,7 +2335,7 @@ static int snd_hda_spdif_default_put(struct snd_kcontrol *kcontrol,
spdif->ctls = val;
if (change && nid != (u16)-1)
set_dig_out_convert(codec, nid, val & 0xff, (val >> 8) & 0xff);
- return change;
+ return change || spdif->status != old_status;
}
#define snd_hda_spdif_out_switch_info snd_ctl_boolean_mono_info
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 458/982] ice: add missing xa_destroy for sched_node_ids
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (456 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 457/982] ALSA: hda: Report a change when only the channel status bytes move Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 459/982] Bluetooth: btusb: Fix UAF of btusb_data by rx_work Greg Kroah-Hartman
` (530 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Keller, Aleksandr Loktionov,
Tony Nguyen, Sasha Levin, Rinitha S
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Keller <jacob.e.keller@intel.com>
[ Upstream commit 53432c4c3e869076350aef319534431af8ba99c1 ]
Commit 16dfa49406bc ("ice: Introduce new parameters in ice_sched_node")
added a sched_node_ids xarray to the port info structure, but never called
xa_destroy on it.
Since xarrays can allocate internal memory, this can result in a memory
leak even if every element in the xarray has been removed.
The xarray is currently embedded in the port_info structure. This appears
to have been done because its use is within functions that take the
port_info as a primary argument.
However, this complicates managing the lifecycle of the field. The
port_info structure is allocated in ice_init_hw() using devm, and it is
not released until the devm cleanup when the driver is unloaded.
The ice_init_hw() function is called in many places, including devlink
reload, and possibly during DDP load after updating the Tx scheduler
layout.
Adding a call of xa_destroy to the ice_deinit_hw() causes Sashiko to raise
multiple concerns due to potential ordering issues and possible ways that
port_info could be a dangling reference.
To handle this, move the sched_node_ids out of port_info and into the hw
structure. All users of the array already have a pointer to hw anyways, and
there is only one sched_node_ids per adapter. While here, remove the overly
verbose comment explaining the nature of the sched_node_ids xarray.
Add the missing xa_destroy to the cleanup path and to ice_deinit_hw(),
ensuring that we properly release the xarray memory.
This was caught by Sashiko during development of unrelated code.
Fixes: 16dfa49406bc ("ice: Introduce new parameters in ice_sched_node")
Signed-off-by: Jacob Keller <jacob.e.keller@intel.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Tested-by: Rinitha S <sx.rinitha@intel.com> (A Contingent worker at Intel)
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/ice/ice_common.c | 9 ++++++---
drivers/net/ethernet/intel/ice/ice_sched.c | 4 ++--
drivers/net/ethernet/intel/ice/ice_type.h | 2 +-
3 files changed, 9 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_common.c b/drivers/net/ethernet/intel/ice/ice_common.c
index b917cfba1f4ed..a7c76e0adfb6b 100644
--- a/drivers/net/ethernet/intel/ice/ice_common.c
+++ b/drivers/net/ethernet/intel/ice/ice_common.c
@@ -1103,14 +1103,13 @@ int ice_init_hw(struct ice_hw *hw)
hw->evb_veb = true;
- /* init xarray for identifying scheduling nodes uniquely */
- xa_init_flags(&hw->port_info->sched_node_ids, XA_FLAGS_ALLOC);
+ xa_init_flags(&hw->sched_node_ids, XA_FLAGS_ALLOC);
/* Query the allocated resources for Tx scheduler */
status = ice_sched_query_res_alloc(hw);
if (status) {
ice_debug(hw, ICE_DBG_SCHED, "Failed to get scheduler allocated resources\n");
- goto err_unroll_alloc;
+ goto err_unroll_xarray;
}
ice_sched_get_psm_clk_freq(hw);
@@ -1189,6 +1188,8 @@ int ice_init_hw(struct ice_hw *hw)
ice_cleanup_fltr_mgmt_struct(hw);
err_unroll_sched:
ice_sched_cleanup_all(hw);
+err_unroll_xarray:
+ xa_destroy(&hw->sched_node_ids);
err_unroll_alloc:
devm_kfree(ice_hw_to_dev(hw), hw->port_info);
err_unroll_cqinit:
@@ -1226,6 +1227,8 @@ void ice_deinit_hw(struct ice_hw *hw)
/* Clear VSI contexts if not already cleared */
ice_clear_all_vsi_ctx(hw);
+
+ xa_destroy(&hw->sched_node_ids);
}
/**
diff --git a/drivers/net/ethernet/intel/ice/ice_sched.c b/drivers/net/ethernet/intel/ice/ice_sched.c
index f8f2f657bf9b6..bf4df5f6eaa75 100644
--- a/drivers/net/ethernet/intel/ice/ice_sched.c
+++ b/drivers/net/ethernet/intel/ice/ice_sched.c
@@ -374,7 +374,7 @@ void ice_free_sched_node(struct ice_port_info *pi, struct ice_sched_node *node)
devm_kfree(ice_hw_to_dev(hw), node->children);
kfree(node->name);
- xa_erase(&pi->sched_node_ids, node->id);
+ xa_erase(&hw->sched_node_ids, node->id);
devm_kfree(ice_hw_to_dev(hw), node);
}
@@ -965,7 +965,7 @@ ice_sched_add_elems(struct ice_port_info *pi, struct ice_sched_node *tc_node,
if (!new_node->name)
return -ENOMEM;
- status = xa_alloc(&pi->sched_node_ids, &new_node->id, NULL, XA_LIMIT(0, UINT_MAX),
+ status = xa_alloc(&hw->sched_node_ids, &new_node->id, NULL, XA_LIMIT(0, UINT_MAX),
GFP_KERNEL);
if (status) {
ice_debug(hw, ICE_DBG_SCHED, "xa_alloc failed for sched node status =%d\n",
diff --git a/drivers/net/ethernet/intel/ice/ice_type.h b/drivers/net/ethernet/intel/ice/ice_type.h
index daf86cf561bc7..3374673a81f93 100644
--- a/drivers/net/ethernet/intel/ice/ice_type.h
+++ b/drivers/net/ethernet/intel/ice/ice_type.h
@@ -713,7 +713,6 @@ struct ice_port_info {
/* List contain profile ID(s) and other params per layer */
struct list_head rl_prof_list[ICE_AQC_TOPO_MAX_LEVEL_NUM];
struct ice_qos_cfg qos_cfg;
- struct xarray sched_node_ids;
u8 is_vf:1;
};
@@ -850,6 +849,7 @@ struct ice_hw {
u8 sw_entry_point_layer;
u16 max_children[ICE_AQC_TOPO_MAX_LEVEL_NUM];
struct list_head agg_list; /* lists all aggregator */
+ struct xarray sched_node_ids;
struct ice_vsi_ctx *vsi_ctx[ICE_MAX_VSI];
u8 evb_veb; /* true for VEB, false for VEPA */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 459/982] Bluetooth: btusb: Fix UAF of btusb_data by rx_work
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (457 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 458/982] ice: add missing xa_destroy for sched_node_ids Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 460/982] net: macb: destroy the phylink instance on the probe error path Greg Kroah-Hartman
` (529 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit 1c12c3117639e78940959d956519c758c57d0849 ]
btusb_close() and btusb_flush() cancel data->rx_work with the
asynchronous cancel_delayed_work(), so if btusb_rx_work() is already
running on another CPU it keeps running after the cancel returns.
btusb_disconnect() calls hci_unregister_dev(), which invokes
btusb_close(), and then frees the btusb_data. A still running
btusb_rx_work() then dereferences the freed data:
while ((skb = skb_dequeue(&data->acl_q)))
data->recv_acl(data->hdev, skb);
Use cancel_delayed_work_sync() instead. In btusb_close() the cancel also
has to happen after btusb_stop_traffic(), otherwise an URB completion
racing with the cancel can requeue the work right after it has been
waited for.
Fixes: 800fe5ec302e ("Bluetooth: btusb: Add support for queuing during polling interval")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index e545cf1abd0ea..42efd84c975a4 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -1738,18 +1738,24 @@ static int btusb_close(struct hci_dev *hdev)
BT_DBG("%s", hdev->name);
- cancel_delayed_work(&data->rx_work);
cancel_work_sync(&data->work);
cancel_work_sync(&data->waker);
- skb_queue_purge(&data->acl_q);
-
clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
clear_bit(BTUSB_BULK_RUNNING, &data->flags);
clear_bit(BTUSB_INTR_RUNNING, &data->flags);
clear_bit(BTUSB_DIAG_RUNNING, &data->flags);
btusb_stop_traffic(data);
+
+ /* rx_work must only be canceled once the URBs that can rearm it are
+ * gone, and it must be canceled synchronously since btusb_disconnect()
+ * frees the btusb_data it dereferences right after hci_unregister_dev().
+ */
+ cancel_delayed_work_sync(&data->rx_work);
+
+ skb_queue_purge(&data->acl_q);
+
btusb_free_frags(data);
err = usb_autopm_get_interface(data->intf);
@@ -1775,7 +1781,7 @@ static int btusb_flush(struct hci_dev *hdev)
BT_DBG("%s", hdev->name);
- cancel_delayed_work(&data->rx_work);
+ cancel_delayed_work_sync(&data->rx_work);
skb_queue_purge(&data->acl_q);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 460/982] net: macb: destroy the phylink instance on the probe error path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (458 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 459/982] Bluetooth: btusb: Fix UAF of btusb_data by rx_work Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 461/982] watchdog: fix hrtimer start when pretimeout is zero Greg Kroah-Hartman
` (528 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolai Buchwitz <nb@tipi-net.de>
[ Upstream commit 7d059f390750152b9bd69df934198651b94fc26d ]
macb_mii_init() creates a phylink instance on both of its success paths,
but the probe unwind frees the netdev without destroying it, so a failing
macb_alloc_tieoff() or register_netdev() leaks the instance.
Destroy it at err_out_unregister_mdio, which is only reachable once
macb_mii_init() has succeeded, so bp->phylink is valid there.
Fixes: 7897b071ac3b ("net: macb: convert to phylink")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Link: https://patch.msgid.link/20260907210856.1673589-2-nb@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb_main.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index ba9032c3542d9..61f85b54afc9c 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -5195,6 +5195,7 @@ static int macb_probe(struct platform_device *pdev)
mdiobus_unregister(bp->mii_bus);
mdiobus_free(bp->mii_bus);
}
+ phylink_destroy(bp->phylink);
err_out_phy_exit:
phy_exit(bp->phy);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 461/982] watchdog: fix hrtimer start when pretimeout is zero
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (459 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 460/982] net: macb: destroy the phylink instance on the probe error path Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 462/982] watchdog: msc313e: Avoid division by zero Greg Kroah-Hartman
` (527 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Arcari, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Arcari <darcari@redhat.com>
[ Upstream commit 0fa37512eb747e4ffdcf367274f9e72845f1bca4 ]
Per the watchdog API, a pretimeout value of 0 disables the feature.
However, watchdog_hrtimer_pretimeout_start() fails to verify if the
pretimeout is non-zero before arming the timer.
This omission inadvertently starts the software pretimeout timer,
which could result in the pretimeout handler executing incorrectly
when the watchdog timeout is reached.
Fix this by adding a check for wdd->pretimeout before calling
hrtimer_start(), ensuring the disabled state is respected.
Fixes: 7b7d2fdc8c3e ("watchdog: Add hrtimer-based pretimeout feature")
Signed-off-by: David Arcari <darcari@redhat.com>
Link: https://patch.msgid.link/20260903182029.936030-1-darcari@redhat.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/watchdog_hrtimer_pretimeout.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/watchdog/watchdog_hrtimer_pretimeout.c b/drivers/watchdog/watchdog_hrtimer_pretimeout.c
index 940b53718a91e..7572489e647f2 100644
--- a/drivers/watchdog/watchdog_hrtimer_pretimeout.c
+++ b/drivers/watchdog/watchdog_hrtimer_pretimeout.c
@@ -30,6 +30,7 @@ void watchdog_hrtimer_pretimeout_init(struct watchdog_device *wdd)
void watchdog_hrtimer_pretimeout_start(struct watchdog_device *wdd)
{
if (!(wdd->info->options & WDIOF_PRETIMEOUT) &&
+ wdd->pretimeout &&
!watchdog_pretimeout_invalid(wdd, wdd->pretimeout))
hrtimer_start(&wdd->wd_data->pretimeout_timer,
ktime_set(wdd->timeout - wdd->pretimeout, 0),
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 462/982] watchdog: msc313e: Avoid division by zero
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (460 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 461/982] watchdog: fix hrtimer start when pretimeout is zero Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:19 ` [PATCH 6.1 463/982] watchdog: msc313e: Fix clock leak and spurious timer in settimeout() Greg Kroah-Hartman
` (526 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 3c73a37f5e40972ce26d8eeb98e8b938d719b069 ]
clk_get_rate() could return 0. Avoid a division by zero panic.
Fixes: e9800b799464 ("watchdog: Add Mstar MSC313e WDT driver")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260828161348.13212-3-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 3b62650375628..072bfcea85c24 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -98,6 +98,7 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
struct msc313e_wdt_priv *priv;
+ unsigned long rate;
priv = devm_kzalloc(&pdev->dev, sizeof(*priv), GFP_KERNEL);
if (!priv)
@@ -117,7 +118,10 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
priv->wdev.ops = &msc313e_wdt_ops,
priv->wdev.parent = dev;
priv->wdev.min_timeout = MSC313E_WDT_MIN_TIMEOUT;
- priv->wdev.max_timeout = U32_MAX / clk_get_rate(priv->clk);
+ rate = clk_get_rate(priv->clk);
+ if (!rate)
+ return -EINVAL;
+ priv->wdev.max_timeout = U32_MAX / rate;
priv->wdev.timeout = MSC313E_WDT_DEFAULT_TIMEOUT;
/* If the period is non-zero the WDT is running */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 463/982] watchdog: msc313e: Fix clock leak and spurious timer in settimeout()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (461 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 462/982] watchdog: msc313e: Avoid division by zero Greg Kroah-Hartman
@ 2026-09-30 15:19 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 464/982] watchdog: msc313e: Enable clock before accessing hardware registers Greg Kroah-Hartman
` (525 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:19 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 3db30f315935c2fb0d95f46b7a593b5b4d3ec3d0 ]
msc313e_wdt_settimeout() unconditionally calls msc313e_wdt_start() which
introduces two severe bugs:
1. If the watchdog is already active, calling start() again will
increase the reference count of the clock again. However stop() is
only called once, the reference count is unbalance.
2. If the watchdog is stopped, calling settimeout() will start
the hardware timer accidentally.
Factor out the register-writing logic into a helper function. Only call
it in settimeout() if the watchdog is running. Otherwise, simply update
`wdev->timeout`.
Fixes: e9800b799464 ("watchdog: Add Mstar MSC313e WDT driver")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260828161348.13212-4-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 072bfcea85c24..5dc5e3ab7001e 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -32,20 +32,26 @@ struct msc313e_wdt_priv {
struct clk *clk;
};
+static void msc313e_wdt_set_hw_timeout(struct msc313e_wdt_priv *priv,
+ unsigned int timeout)
+{
+ u32 t = timeout * clk_get_rate(priv->clk);
+
+ writew(t & 0xffff, priv->base + REG_WDT_MAX_PRD_L);
+ writew((t >> 16) & 0xffff, priv->base + REG_WDT_MAX_PRD_H);
+ writew(1, priv->base + REG_WDT_CLR);
+}
+
static int msc313e_wdt_start(struct watchdog_device *wdev)
{
struct msc313e_wdt_priv *priv = watchdog_get_drvdata(wdev);
- u32 timeout;
int err;
err = clk_prepare_enable(priv->clk);
if (err)
return err;
- timeout = wdev->timeout * clk_get_rate(priv->clk);
- writew(timeout & 0xffff, priv->base + REG_WDT_MAX_PRD_L);
- writew((timeout >> 16) & 0xffff, priv->base + REG_WDT_MAX_PRD_H);
- writew(1, priv->base + REG_WDT_CLR);
+ msc313e_wdt_set_hw_timeout(priv, wdev->timeout);
return 0;
}
@@ -70,9 +76,13 @@ static int msc313e_wdt_stop(struct watchdog_device *wdev)
static int msc313e_wdt_settimeout(struct watchdog_device *wdev, unsigned int new_time)
{
+ struct msc313e_wdt_priv *priv = watchdog_get_drvdata(wdev);
+
wdev->timeout = new_time;
- return msc313e_wdt_start(wdev);
+ if (watchdog_hw_running(wdev) || watchdog_active(wdev))
+ msc313e_wdt_set_hw_timeout(priv, wdev->timeout);
+ return 0;
}
static const struct watchdog_info msc313e_wdt_ident = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 464/982] watchdog: msc313e: Enable clock before accessing hardware registers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (462 preceding siblings ...)
2026-09-30 15:19 ` [PATCH 6.1 463/982] watchdog: msc313e: Fix clock leak and spurious timer in settimeout() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 465/982] watchdog: msc313e: Fix spurious reset on suspend Greg Kroah-Hartman
` (524 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 3db2df24e7f11fb117718f6abe326628d91bc500 ]
msc313e_wdt_probe() reads from hardware registers without ensuring the
required clock is enabled. Furthermore, if the bootloader leaves the
watchdog running, msc313e_wdt_probe() sets WDOG_HW_RUNNING without
increasing the clock's reference count.
While the clock is currently supplied as a fixed clock by the device
tree (`xtal_div2` in arch/arm/boot/dts/sigmastar/mstar-v7.dtsi) which
masks the physical issue, this still violates the API usage.
Call clk_prepare_enable() before reading WDT registers. If the WDT is
running, leave the clock enabled so the CCF reference counter is
balanced.
Fixes: ffd264bd152c ("watchdog: msc313e: Check if the WDT was running at boot")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260828161348.13212-5-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 23 +++++++++++++++++++++--
1 file changed, 21 insertions(+), 2 deletions(-)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 5dc5e3ab7001e..86e72aea96855 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -109,6 +109,7 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
struct device *dev = &pdev->dev;
struct msc313e_wdt_priv *priv;
unsigned long rate;
+ int ret;
priv = devm_kzalloc(&pdev->dev, sizeof(*priv), GFP_KERNEL);
if (!priv)
@@ -134,9 +135,21 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
priv->wdev.max_timeout = U32_MAX / rate;
priv->wdev.timeout = MSC313E_WDT_DEFAULT_TIMEOUT;
+ ret = clk_prepare_enable(priv->clk);
+ if (ret)
+ return ret;
+
/* If the period is non-zero the WDT is running */
- if (readw(priv->base + REG_WDT_MAX_PRD_L) | (readw(priv->base + REG_WDT_MAX_PRD_H) << 16))
+ if (readw(priv->base + REG_WDT_MAX_PRD_L) | (readw(priv->base + REG_WDT_MAX_PRD_H) << 16)) {
set_bit(WDOG_HW_RUNNING, &priv->wdev.status);
+ /*
+ * Keep the clock enabled. The watchdog core will skip the next
+ * start() and a future stop() will balance the CCF reference
+ * count.
+ */
+ } else {
+ clk_disable_unprepare(priv->clk);
+ }
watchdog_set_drvdata(&priv->wdev, priv);
platform_set_drvdata(pdev, priv);
@@ -145,7 +158,13 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
watchdog_stop_on_reboot(&priv->wdev);
watchdog_stop_on_unregister(&priv->wdev);
- return devm_watchdog_register_device(dev, &priv->wdev);
+ ret = devm_watchdog_register_device(dev, &priv->wdev);
+
+ /* If the WDT is running and anything goes wrong, disable the clock. */
+ if (ret && test_bit(WDOG_HW_RUNNING, &priv->wdev.status))
+ clk_disable_unprepare(priv->clk);
+
+ return ret;
}
static int __maybe_unused msc313e_wdt_suspend(struct device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 465/982] watchdog: msc313e: Fix spurious reset on suspend
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (463 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 464/982] watchdog: msc313e: Enable clock before accessing hardware registers Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 466/982] watchdog: msc313e: Fix undefined behavior Greg Kroah-Hartman
` (523 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 4f6817c9eff4aa1078e16652d82e4b7ef4ffae3e ]
If the hardware watchdog was started by the bootloader and the device is
suspended before userspace opens it, the ping worker (from watchdog
core) is frozen and the active hardware timer continues running. This
leads to a spurious system reset.
Check both watchdog_active() and watchdog_hw_running() when deciding
whether to start or stop the watchdog during suspend and resume.
Additionally, call watchdog_stop_ping_on_suspend() to ensure the ping
worker be correctly paused and restarted during suspend and resume.
Fixes: ffd264bd152c ("watchdog: msc313e: Check if the WDT was running at boot")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260828161348.13212-6-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 86e72aea96855..9cfe059fd31a7 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -157,6 +157,7 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
watchdog_init_timeout(&priv->wdev, timeout, dev);
watchdog_stop_on_reboot(&priv->wdev);
watchdog_stop_on_unregister(&priv->wdev);
+ watchdog_stop_ping_on_suspend(&priv->wdev);
ret = devm_watchdog_register_device(dev, &priv->wdev);
@@ -171,7 +172,7 @@ static int __maybe_unused msc313e_wdt_suspend(struct device *dev)
{
struct msc313e_wdt_priv *priv = dev_get_drvdata(dev);
- if (watchdog_active(&priv->wdev))
+ if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev))
msc313e_wdt_stop(&priv->wdev);
return 0;
@@ -181,7 +182,7 @@ static int __maybe_unused msc313e_wdt_resume(struct device *dev)
{
struct msc313e_wdt_priv *priv = dev_get_drvdata(dev);
- if (watchdog_active(&priv->wdev))
+ if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev))
msc313e_wdt_start(&priv->wdev);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 466/982] watchdog: msc313e: Fix undefined behavior
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (464 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 465/982] watchdog: msc313e: Fix spurious reset on suspend Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 467/982] watchdog: msc313e: Sync timeout value if WDT was running at boot Greg Kroah-Hartman
` (522 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit ab390021b2a3bb4cc875f28a6f76d13de90d7457 ]
readw() returns a u16. Left shifting a u16 by 16 bits yields undefined
behavior.
Cast to u32 explicitly before the shift.
Fixes: ffd264bd152c ("watchdog: msc313e: Check if the WDT was running at boot")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260828161348.13212-7-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 9cfe059fd31a7..72620adec641a 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -32,6 +32,16 @@ struct msc313e_wdt_priv {
struct clk *clk;
};
+static u32 msc313e_wdt_get_hw_timeout(struct msc313e_wdt_priv *priv)
+{
+ u16 low, high;
+
+ low = readw(priv->base + REG_WDT_MAX_PRD_L);
+ high = readw(priv->base + REG_WDT_MAX_PRD_H);
+
+ return ((u32)high << 16) | low;
+}
+
static void msc313e_wdt_set_hw_timeout(struct msc313e_wdt_priv *priv,
unsigned int timeout)
{
@@ -140,7 +150,7 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
return ret;
/* If the period is non-zero the WDT is running */
- if (readw(priv->base + REG_WDT_MAX_PRD_L) | (readw(priv->base + REG_WDT_MAX_PRD_H) << 16)) {
+ if (msc313e_wdt_get_hw_timeout(priv)) {
set_bit(WDOG_HW_RUNNING, &priv->wdev.status);
/*
* Keep the clock enabled. The watchdog core will skip the next
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 467/982] watchdog: msc313e: Sync timeout value if WDT was running at boot
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (465 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 466/982] watchdog: msc313e: Fix undefined behavior Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 468/982] net/micrel: Fix typos in micrel driver code comments Greg Kroah-Hartman
` (521 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 01504d14e47b34779911250dd308a03f6ef681c2 ]
If WDT was running at boot, the hardware timeout might be set to values
other than the final software timeout.
To be consistent, set the hardware timeout to match the final software
timeout (i.e., after watchdog_init_timeout()) if WDT was running.
Fixes: ffd264bd152c ("watchdog: msc313e: Check if the WDT was running at boot")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260828161348.13212-8-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/msc313e_wdt.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/drivers/watchdog/msc313e_wdt.c b/drivers/watchdog/msc313e_wdt.c
index 72620adec641a..eea26c6c95d84 100644
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -145,12 +145,21 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
priv->wdev.max_timeout = U32_MAX / rate;
priv->wdev.timeout = MSC313E_WDT_DEFAULT_TIMEOUT;
+ watchdog_set_drvdata(&priv->wdev, priv);
+ platform_set_drvdata(pdev, priv);
+
+ watchdog_init_timeout(&priv->wdev, timeout, dev);
+ watchdog_stop_on_reboot(&priv->wdev);
+ watchdog_stop_on_unregister(&priv->wdev);
+ watchdog_stop_ping_on_suspend(&priv->wdev);
+
ret = clk_prepare_enable(priv->clk);
if (ret)
return ret;
/* If the period is non-zero the WDT is running */
if (msc313e_wdt_get_hw_timeout(priv)) {
+ msc313e_wdt_set_hw_timeout(priv, priv->wdev.timeout);
set_bit(WDOG_HW_RUNNING, &priv->wdev.status);
/*
* Keep the clock enabled. The watchdog core will skip the next
@@ -161,14 +170,6 @@ static int msc313e_wdt_probe(struct platform_device *pdev)
clk_disable_unprepare(priv->clk);
}
- watchdog_set_drvdata(&priv->wdev, priv);
- platform_set_drvdata(pdev, priv);
-
- watchdog_init_timeout(&priv->wdev, timeout, dev);
- watchdog_stop_on_reboot(&priv->wdev);
- watchdog_stop_on_unregister(&priv->wdev);
- watchdog_stop_ping_on_suspend(&priv->wdev);
-
ret = devm_watchdog_register_device(dev, &priv->wdev);
/* If the WDT is running and anything goes wrong, disable the clock. */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 468/982] net/micrel: Fix typos in micrel driver code comments
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (466 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 467/982] watchdog: msc313e: Sync timeout value if WDT was running at boot Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 469/982] net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down Greg Kroah-Hartman
` (520 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yicong Hui, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yicong Hui <yiconghui@gmail.com>
[ Upstream commit c2b733da93bf607d6c6f925b4d40598e6bb516be ]
Fix various typos and misspellings in code comments in the
drivers/net/ethernet/micrel directory
Signed-off-by: Yicong Hui <yiconghui@gmail.com>
Link: https://patch.msgid.link/20260118121001.136806-3-yiconghui@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 66ef5adb7544 ("net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/micrel/ks8842.c | 4 ++--
drivers/net/ethernet/micrel/ks8851_common.c | 2 +-
drivers/net/ethernet/micrel/ks8851_spi.c | 4 ++--
drivers/net/ethernet/micrel/ksz884x.c | 4 ++--
4 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/micrel/ks8842.c b/drivers/net/ethernet/micrel/ks8842.c
index c11b118dc4158..de2ef3c1150d7 100644
--- a/drivers/net/ethernet/micrel/ks8842.c
+++ b/drivers/net/ethernet/micrel/ks8842.c
@@ -242,7 +242,7 @@ static void ks8842_reset(struct ks8842_adapter *adapter)
msleep(10);
iowrite16(0, adapter->hw_addr + REG_GRR);
} else {
- /* The KS8842 goes haywire when doing softare reset
+ /* The KS8842 goes haywire when doing software reset
* a work around in the timberdale IP is implemented to
* do a hardware reset instead
ks8842_write16(adapter, 3, 1, REG_GRR);
@@ -312,7 +312,7 @@ static void ks8842_reset_hw(struct ks8842_adapter *adapter)
/* aggressive back off in half duplex */
ks8842_enable_bits(adapter, 32, 1 << 8, REG_SGCR1);
- /* enable no excessive collison drop */
+ /* enable no excessive collision drop */
ks8842_enable_bits(adapter, 32, 1 << 3, REG_SGCR2);
/* Enable port 1 force flow control / back pressure / transmit / recv */
diff --git a/drivers/net/ethernet/micrel/ks8851_common.c b/drivers/net/ethernet/micrel/ks8851_common.c
index b1e9d1495c019..7c336e0a4b8ae 100644
--- a/drivers/net/ethernet/micrel/ks8851_common.c
+++ b/drivers/net/ethernet/micrel/ks8851_common.c
@@ -493,7 +493,7 @@ static int ks8851_net_open(struct net_device *dev)
* ks8851_net_stop - close network device
* @dev: The device being closed.
*
- * Called to close down a network device which has been active. Cancell any
+ * Called to close down a network device which has been active. Cancel any
* work, shutdown the RX and TX process and then place the chip into a low
* power state whilst it is not being used.
*/
diff --git a/drivers/net/ethernet/micrel/ks8851_spi.c b/drivers/net/ethernet/micrel/ks8851_spi.c
index 50afe8c11178e..a1d0918b8edd4 100644
--- a/drivers/net/ethernet/micrel/ks8851_spi.c
+++ b/drivers/net/ethernet/micrel/ks8851_spi.c
@@ -41,7 +41,7 @@ static int msg_enable;
*
* The @lock ensures that the chip is protected when certain operations are
* in progress. When the read or write packet transfer is in progress, most
- * of the chip registers are not ccessible until the transfer is finished and
+ * of the chip registers are not accessible until the transfer is finished and
* the DMA has been de-asserted.
*/
struct ks8851_net_spi {
@@ -298,7 +298,7 @@ static unsigned int calc_txlen(unsigned int len)
/**
* ks8851_tx_work - process tx packet(s)
- * @work: The work strucutre what was scheduled.
+ * @work: The work structure what was scheduled.
*
* This is called when a number of packets have been scheduled for
* transmission and need to be sent to the device.
diff --git a/drivers/net/ethernet/micrel/ksz884x.c b/drivers/net/ethernet/micrel/ksz884x.c
index e6acd1e7b263a..4b35b7f1e6ad3 100644
--- a/drivers/net/ethernet/micrel/ksz884x.c
+++ b/drivers/net/ethernet/micrel/ksz884x.c
@@ -1166,7 +1166,7 @@ struct ksz_port_info {
* @tx_cfg: Cached transmit control settings.
* @rx_cfg: Cached receive control settings.
* @intr_mask: Current interrupt mask.
- * @intr_set: Current interrup set.
+ * @intr_set: Current interrupt set.
* @intr_blocked: Interrupt blocked.
* @rx_desc_info: Receive descriptor information.
* @tx_desc_info: Transmit descriptor information.
@@ -2181,7 +2181,7 @@ static void sw_dis_prio_rate(struct ksz_hw *hw, int port)
}
/**
- * sw_init_prio_rate - initialize switch prioirty rate
+ * sw_init_prio_rate - initialize switch priority rate
* @hw: The hardware instance.
*
* This routine initializes the priority rate function of the switch.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 469/982] net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (467 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 468/982] net/micrel: Fix typos in micrel driver code comments Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 470/982] hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() Greg Kroah-Hartman
` (519 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sebastian Andrzej Siewior,
Marek Vasut, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marek Vasut <marex@nabladev.com>
[ Upstream commit 66ef5adb75446627f8b6c26cd04f2adc86d4de56 ]
KSZ8851 errata sheet DS80000716D-page 4 Module 3 [1] states that,
when issuing a software power-down (PMECR[1:0] = 10) followed by a
power-on (PMECR[1:0] = 00), the receiver circuit can fail to start
properly preventing communication. The Transmitter will still send
data, but no data will be received.
The errata sheet also includes a workaround, which states that,
it is recommended that the software power-down feature not be used.
Implement that workaround and drop the entry into software power-down
mode. The ks8851_write_mac_addr() calls entry into normal power-on
mode at the very beginning of the function, therefore dropping the
second call to enter software power-down mode is sufficient here.
The ks8851_net_stop() can only be called after ks8851_net_start()
was already called, and ks8851_net_start() also makes the MAC enter
normal power-on mode, therefore it is also fine to drop the call to
enter software power-down mode from ks8851_net_stop().
This will lead to a slight increase in power consumption, but it also
fixes a sporadic reliability problem on at least KSZ8851-16MLL, which
is where the problem was reported and this fix was tested.
[1] https://ww1.microchip.com/downloads/en/DeviceDoc/80000716D.pdf
Fixes: 3ba81f3ece3c ("net: Micrel KS8851 SPI network driver")
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Marek Vasut <marex@nabladev.com>
Link: https://patch.msgid.link/20260905130327.203851-1-marex@nabladev.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/micrel/ks8851_common.c | 8 +-------
1 file changed, 1 insertion(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/micrel/ks8851_common.c b/drivers/net/ethernet/micrel/ks8851_common.c
index 7c336e0a4b8ae..4267c4cb1acdc 100644
--- a/drivers/net/ethernet/micrel/ks8851_common.c
+++ b/drivers/net/ethernet/micrel/ks8851_common.c
@@ -143,9 +143,6 @@ static int ks8851_write_mac_addr(struct net_device *dev)
ks8851_wrreg16(ks, KS_MAR(i), val);
}
- if (!netif_running(dev))
- ks8851_set_powermode(ks, PMECR_PM_SOFTDOWN);
-
ks8851_unlock(ks);
return 0;
@@ -494,8 +491,7 @@ static int ks8851_net_open(struct net_device *dev)
* @dev: The device being closed.
*
* Called to close down a network device which has been active. Cancel any
- * work, shutdown the RX and TX process and then place the chip into a low
- * power state whilst it is not being used.
+ * work and shutdown the RX and TX process.
*/
static int ks8851_net_stop(struct net_device *dev)
{
@@ -522,8 +518,6 @@ static int ks8851_net_stop(struct net_device *dev)
/* shutdown TX process */
ks8851_wrreg16(ks, KS_TXCR, 0x0000);
- /* set powermode to soft power down to save power */
- ks8851_set_powermode(ks, PMECR_PM_SOFTDOWN);
ks8851_unlock(ks);
/* ensure any queued tx buffers are dumped */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 470/982] hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (468 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 469/982] net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 471/982] hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors Greg Kroah-Hartman
` (518 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI review, Cong Nguyen,
Guenter Roeck, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit bb2424c3502cc72292eedade46960c331d5f28fb ]
set_fan_speed() writes the control GPIOs one bit at a time. Every
other caller locks around it; gpio_fan_shutdown() doesn't. If it races
a locked caller, the GPIO writes can interleave and leave the fan at a
speed neither caller asked for.
Fixes: b95579cd8795 ("hwmon: (gpio-fan) Add a shutdown handler to poweroff the fans")
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/r/20260830152150.27F5F1F000E9@smtp.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Link: https://patch.msgid.link/20260901155404.1532092-1-congnt264@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/gpio-fan.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/hwmon/gpio-fan.c b/drivers/hwmon/gpio-fan.c
index f1926b9171e0c..9abd6f7d45194 100644
--- a/drivers/hwmon/gpio-fan.c
+++ b/drivers/hwmon/gpio-fan.c
@@ -560,8 +560,11 @@ static void gpio_fan_shutdown(struct platform_device *pdev)
{
struct gpio_fan_data *fan_data = platform_get_drvdata(pdev);
- if (fan_data->gpios)
+ if (fan_data->gpios) {
+ mutex_lock(&fan_data->lock);
set_fan_speed(fan_data, 0);
+ mutex_unlock(&fan_data->lock);
+ }
}
static int gpio_fan_suspend(struct device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 471/982] hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (469 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 470/982] hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 472/982] vxlan: use generic function for tunnel IPv4 route lookup Greg Kroah-Hartman
` (517 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Guenter Roeck,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 09a9e1746a87845d7d8e2b4e23bb613306effdff ]
aspeed_pwm_tacho_probe() installs its reset cleanup action and configures
the
controller after an unchecked reset deassertion.
Stop probing when the reset controller rejects the transition, before the
hwmon device becomes visible.
Fixes: 18c514cc0e02 ("hwmon: (aspeed-pwm-tacho) Deassert reset in probe")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260830125044.97718-1-pengpeng@iscas.ac.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/aspeed-pwm-tacho.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/hwmon/aspeed-pwm-tacho.c b/drivers/hwmon/aspeed-pwm-tacho.c
index 51f321bcd778a..133453938e9ad 100644
--- a/drivers/hwmon/aspeed-pwm-tacho.c
+++ b/drivers/hwmon/aspeed-pwm-tacho.c
@@ -922,7 +922,9 @@ static int aspeed_pwm_tacho_probe(struct platform_device *pdev)
"missing or invalid reset controller device tree entry");
return PTR_ERR(priv->rst);
}
- reset_control_deassert(priv->rst);
+ ret = reset_control_deassert(priv->rst);
+ if (ret)
+ return ret;
ret = devm_add_action_or_reset(dev, aspeed_pwm_tacho_remove, priv);
if (ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 472/982] vxlan: use generic function for tunnel IPv4 route lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (470 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 471/982] hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 473/982] ipv6: remove "proto" argument from udp_tunnel6_dst_lookup() Greg Kroah-Hartman
` (516 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guillaume Nault, Beniamino Galvani,
David S. Miller, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Beniamino Galvani <b.galvani@gmail.com>
[ Upstream commit 6f19b2c136d98a84d79030b53e23d405edfdc783 ]
The route lookup can be done now via generic function
udp_tunnel_dst_lookup() to replace the custom implementations in
vxlan_get_route().
Note that this patch only touches IPv4, while IPv6 still uses
vxlan6_get_route(). After IPv6 route lookup gets converted as well,
vxlan_xmit_one() can be simplified by removing local variables that
will be passed via "struct ip_tunnel_key", such as remote_ip,
local_ip, flow_flags, label.
Suggested-by: Guillaume Nault <gnault@redhat.com>
Signed-off-by: Beniamino Galvani <b.galvani@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: be83178bfc44 ("vxlan: initialize _md in vxlan_xmit_one()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 114 ++++++++++++---------------------
1 file changed, 41 insertions(+), 73 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 591a2875dfe2f..5d24ed25b68b0 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2332,57 +2332,6 @@ static int vxlan_build_skb(struct sk_buff *skb, struct dst_entry *dst,
return 0;
}
-static struct rtable *vxlan_get_route(struct vxlan_dev *vxlan, struct net_device *dev,
- struct vxlan_sock *sock4,
- struct sk_buff *skb, int oif, u8 tos,
- __be32 daddr, __be32 *saddr, __be16 dport, __be16 sport,
- __u8 flow_flags, struct dst_cache *dst_cache,
- const struct ip_tunnel_info *info)
-{
- bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
- struct rtable *rt = NULL;
- struct flowi4 fl4;
-
- if (!sock4)
- return ERR_PTR(-EIO);
-
- if (tos && !info)
- use_cache = false;
- if (use_cache) {
- rt = dst_cache_get_ip4(dst_cache, saddr);
- if (rt)
- return rt;
- }
-
- memset(&fl4, 0, sizeof(fl4));
- fl4.flowi4_oif = oif;
- fl4.flowi4_tos = RT_TOS(tos);
- fl4.flowi4_mark = skb->mark;
- fl4.flowi4_proto = IPPROTO_UDP;
- fl4.daddr = daddr;
- fl4.saddr = *saddr;
- fl4.fl4_dport = dport;
- fl4.fl4_sport = sport;
- fl4.flowi4_flags = flow_flags;
-
- rt = ip_route_output_key(vxlan->net, &fl4);
- if (!IS_ERR(rt)) {
- if (rt->dst.dev == dev) {
- netdev_dbg(dev, "circular route to %pI4\n", &daddr);
- ip_rt_put(rt);
- return ERR_PTR(-ELOOP);
- }
-
- *saddr = fl4.saddr;
- if (use_cache)
- dst_cache_set_ip4(dst_cache, &rt->dst, fl4.saddr);
- } else {
- netdev_dbg(dev, "no route to %pI4\n", &daddr);
- return ERR_PTR(-ENETUNREACH);
- }
- return rt;
-}
-
#if IS_ENABLED(CONFIG_IPV6)
static struct dst_entry *vxlan6_get_route(struct vxlan_dev *vxlan,
struct net_device *dev,
@@ -2544,30 +2493,38 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
{
struct dst_cache *dst_cache;
struct ip_tunnel_info *info;
+ struct ip_tunnel_key *pkey;
+ struct ip_tunnel_key key;
struct vxlan_dev *vxlan = netdev_priv(dev);
const struct iphdr *old_iph = ip_hdr(skb);
union vxlan_addr *dst;
- union vxlan_addr remote_ip, local_ip;
+ union vxlan_addr remote_ip;
struct vxlan_metadata _md;
struct vxlan_metadata *md = &_md;
unsigned int pkt_len = skb->len;
__be16 src_port = 0, dst_port;
struct dst_entry *ndst = NULL;
- __u8 tos, ttl, flow_flags = 0;
+ __u8 tos, ttl;
int ifindex;
int err;
u32 flags = vxlan->cfg.flags;
+ bool use_cache;
bool udp_sum = false;
bool xnet = !net_eq(vxlan->net, dev_net(vxlan->dev));
__be32 vni = 0;
#if IS_ENABLED(CONFIG_IPV6)
+ union vxlan_addr local_ip;
__be32 label;
#endif
info = skb_tunnel_info(skb);
+ use_cache = ip_tunnel_dst_cache_usable(skb, info);
if (rdst) {
dst = &rdst->remote_ip;
+ memset(&key, 0, sizeof(key));
+ pkey = &key;
+
if (vxlan_addr_any(dst)) {
if (did_rsc) {
/* short-circuited back to local bridge */
@@ -2581,7 +2538,15 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
dst_port = rdst->remote_port ? rdst->remote_port : vxlan->cfg.dst_port;
vni = (rdst->remote_vni) ? : default_vni;
ifindex = rdst->remote_ifindex;
- local_ip = vxlan->cfg.saddr;
+
+ if (dst->sa.sa_family == AF_INET) {
+ key.u.ipv4.src = vxlan->cfg.saddr.sin.sin_addr.s_addr;
+ key.u.ipv4.dst = rdst->remote_ip.sin.sin_addr.s_addr;
+ } else {
+ key.u.ipv6.src = vxlan->cfg.saddr.sin6.sin6_addr;
+ key.u.ipv6.dst = rdst->remote_ip.sin6.sin6_addr;
+ }
+
dst_cache = &rdst->dst_cache;
md->gbp = skb->mark;
if (flags & VXLAN_F_TTL_INHERIT) {
@@ -2595,12 +2560,15 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
tos = vxlan->cfg.tos;
if (tos == 1)
tos = ip_tunnel_get_dsfield(old_iph, skb);
+ if (tos && !info)
+ use_cache = false;
if (dst->sa.sa_family == AF_INET)
udp_sum = !(flags & VXLAN_F_UDP_ZERO_CSUM_TX);
else
udp_sum = !(flags & VXLAN_F_UDP_ZERO_CSUM6_TX);
#if IS_ENABLED(CONFIG_IPV6)
+ local_ip = vxlan->cfg.saddr;
label = vxlan->cfg.label;
#endif
} else {
@@ -2612,14 +2580,15 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
remote_ip.sa.sa_family = ip_tunnel_info_af(info);
if (remote_ip.sa.sa_family == AF_INET) {
remote_ip.sin.sin_addr.s_addr = info->key.u.ipv4.dst;
- local_ip.sin.sin_addr.s_addr = info->key.u.ipv4.src;
} else {
remote_ip.sin6.sin6_addr = info->key.u.ipv6.dst;
+#if IS_ENABLED(CONFIG_IPV6)
local_ip.sin6.sin6_addr = info->key.u.ipv6.src;
+#endif
}
dst = &remote_ip;
+ pkey = &info->key;
dst_port = info->key.tp_dst ? : vxlan->cfg.dst_port;
- flow_flags = info->key.flow_flags;
vni = tunnel_id_to_key32(info->key.tun_id);
ifindex = 0;
dst_cache = &info->dst_cache;
@@ -2643,15 +2612,14 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
struct vxlan_sock *sock4 = rcu_dereference(vxlan->vn4_sock);
struct rtable *rt;
__be16 df = 0;
+ __be32 saddr;
if (!ifindex)
ifindex = sock4->sock->sk->sk_bound_dev_if;
- rt = vxlan_get_route(vxlan, dev, sock4, skb, ifindex, tos,
- dst->sin.sin_addr.s_addr,
- &local_ip.sin.sin_addr.s_addr,
- dst_port, src_port, flow_flags,
- dst_cache, info);
+ rt = udp_tunnel_dst_lookup(skb, dev, vxlan->net, ifindex,
+ &saddr, pkey, src_port, dst_port,
+ tos, use_cache ? dst_cache : NULL);
if (IS_ERR(rt)) {
err = PTR_ERR(rt);
goto tx_error;
@@ -2687,16 +2655,13 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
} else if (err) {
if (info) {
struct ip_tunnel_info *unclone;
- struct in_addr src, dst;
unclone = skb_tunnel_info_unclone(skb);
if (unlikely(!unclone))
goto tx_error;
- src = remote_ip.sin.sin_addr;
- dst = local_ip.sin.sin_addr;
- unclone->key.u.ipv4.src = src.s_addr;
- unclone->key.u.ipv4.dst = dst.s_addr;
+ unclone->key.u.ipv4.src = pkey->u.ipv4.dst;
+ unclone->key.u.ipv4.dst = saddr;
}
vxlan_encap_bypass(skb, vxlan, vxlan, vni, false);
dst_release(ndst);
@@ -2710,8 +2675,8 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
if (err < 0)
goto tx_error;
- udp_tunnel_xmit_skb(rt, sock4->sock->sk, skb, local_ip.sin.sin_addr.s_addr,
- dst->sin.sin_addr.s_addr, tos, ttl, df,
+ udp_tunnel_xmit_skb(rt, sock4->sock->sk, skb, saddr,
+ pkey->u.ipv4.dst, tos, ttl, df,
src_port, dst_port, xnet, !udp_sum);
#if IS_ENABLED(CONFIG_IPV6)
} else {
@@ -3164,11 +3129,14 @@ static int vxlan_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb)
struct vxlan_sock *sock4 = rcu_dereference(vxlan->vn4_sock);
struct rtable *rt;
- rt = vxlan_get_route(vxlan, dev, sock4, skb, 0, info->key.tos,
- info->key.u.ipv4.dst,
- &info->key.u.ipv4.src, dport, sport,
- info->key.flow_flags, &info->dst_cache,
- info);
+ if (!sock4)
+ return -EIO;
+
+ rt = udp_tunnel_dst_lookup(skb, dev, vxlan->net, 0,
+ &info->key.u.ipv4.src,
+ &info->key,
+ sport, dport, info->key.tos,
+ &info->dst_cache);
if (IS_ERR(rt))
return PTR_ERR(rt);
ip_rt_put(rt);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 473/982] ipv6: remove "proto" argument from udp_tunnel6_dst_lookup()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (471 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 472/982] vxlan: use generic function for tunnel IPv4 route lookup Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 474/982] ipv6: add new arguments to udp_tunnel6_dst_lookup() Greg Kroah-Hartman
` (515 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guillaume Nault, Beniamino Galvani,
David Ahern, David S. Miller, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Beniamino Galvani <b.galvani@gmail.com>
[ Upstream commit 7e937dcf96d0489b3cdd1cff9dfd049617d28492 ]
The function is now UDP-specific, the protocol is always IPPROTO_UDP.
This is similar to what already done for IPv4 in commit 78f3655adcb5
("ipv4: remove "proto" argument from udp_tunnel_dst_lookup()").
Suggested-by: Guillaume Nault <gnault@redhat.com>
Signed-off-by: Beniamino Galvani <b.galvani@gmail.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: be83178bfc44 ("vxlan: initialize _md in vxlan_xmit_one()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/bareudp.c | 5 ++---
include/net/udp_tunnel.h | 2 +-
net/ipv6/ip6_udp_tunnel.c | 4 +---
3 files changed, 4 insertions(+), 7 deletions(-)
diff --git a/drivers/net/bareudp.c b/drivers/net/bareudp.c
index b181c03368153..eaaa7bf89accf 100644
--- a/drivers/net/bareudp.c
+++ b/drivers/net/bareudp.c
@@ -394,7 +394,7 @@ static int bareudp6_xmit_skb(struct sk_buff *skb, struct net_device *dev,
return -ESHUTDOWN;
dst = udp_tunnel6_dst_lookup(skb, dev, bareudp->net, sock, &saddr, info,
- IPPROTO_UDP, use_cache);
+ use_cache);
if (IS_ERR(dst))
return PTR_ERR(dst);
@@ -524,8 +524,7 @@ static int bareudp_fill_metadata_dst(struct net_device *dev,
return -ESHUTDOWN;
dst = udp_tunnel6_dst_lookup(skb, dev, bareudp->net, sock,
- &saddr, info, IPPROTO_UDP,
- use_cache);
+ &saddr, info, use_cache);
if (IS_ERR(dst))
return PTR_ERR(dst);
diff --git a/include/net/udp_tunnel.h b/include/net/udp_tunnel.h
index 7421fa1d5ec96..8409a5429349b 100644
--- a/include/net/udp_tunnel.h
+++ b/include/net/udp_tunnel.h
@@ -174,7 +174,7 @@ struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
struct socket *sock,
struct in6_addr *saddr,
const struct ip_tunnel_info *info,
- u8 protocol, bool use_cache);
+ bool use_cache);
struct metadata_dst *udp_tun_rx_dst(struct sk_buff *skb, unsigned short family,
__be16 flags, __be64 tunnel_id,
diff --git a/net/ipv6/ip6_udp_tunnel.c b/net/ipv6/ip6_udp_tunnel.c
index 7aef559e60ec5..812fc284cf36e 100644
--- a/net/ipv6/ip6_udp_tunnel.c
+++ b/net/ipv6/ip6_udp_tunnel.c
@@ -120,7 +120,6 @@ EXPORT_SYMBOL_GPL(udp_tunnel6_xmit_skb);
* @sock: Socket which provides route info
* @saddr: Memory to store the src ip address
* @info: Tunnel information
- * @protocol: IP protocol
* @use_cache: Flag to enable cache usage
* This function performs a route lookup on a UDP tunnel
*
@@ -134,7 +133,6 @@ struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
struct socket *sock,
struct in6_addr *saddr,
const struct ip_tunnel_info *info,
- u8 protocol,
bool use_cache)
{
struct dst_entry *dst = NULL;
@@ -154,7 +152,7 @@ struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
#endif
memset(&fl6, 0, sizeof(fl6));
fl6.flowi6_mark = skb->mark;
- fl6.flowi6_proto = protocol;
+ fl6.flowi6_proto = IPPROTO_UDP;
fl6.daddr = info->key.u.ipv6.dst;
fl6.saddr = info->key.u.ipv6.src;
prio = info->key.tos;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 474/982] ipv6: add new arguments to udp_tunnel6_dst_lookup()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (472 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 473/982] ipv6: remove "proto" argument from udp_tunnel6_dst_lookup() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 475/982] vxlan: use generic function for tunnel IPv6 route lookup Greg Kroah-Hartman
` (514 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guillaume Nault, Beniamino Galvani,
David Ahern, David S. Miller, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Beniamino Galvani <b.galvani@gmail.com>
[ Upstream commit 946fcfdbc5b97e26d31339ebca2d9a51a4f975ff ]
We want to make the function more generic so that it can be used by
other UDP tunnel implementations such as geneve and vxlan. To do that,
add the following arguments:
- source and destination UDP port;
- ifindex of the output interface, needed by vxlan;
- the tos, because in some cases it is not taken from struct
ip_tunnel_info (for example, when it's inherited from the inner
packet);
- the dst cache, because not all tunnel types (e.g. vxlan) want to
use the one from struct ip_tunnel_info.
With these parameters, the function no longer needs the full struct
ip_tunnel_info as argument and we can pass only the relevant part of
it (struct ip_tunnel_key).
This is similar to what already done for IPv4 in commit 72fc68c6356b
("ipv4: add new arguments to udp_tunnel_dst_lookup()").
Suggested-by: Guillaume Nault <gnault@redhat.com>
Signed-off-by: Beniamino Galvani <b.galvani@gmail.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: be83178bfc44 ("vxlan: initialize _md in vxlan_xmit_one()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/bareudp.c | 10 +++++++---
include/net/udp_tunnel.h | 7 ++++---
net/ipv6/ip6_udp_tunnel.c | 33 ++++++++++++++++++---------------
3 files changed, 29 insertions(+), 21 deletions(-)
diff --git a/drivers/net/bareudp.c b/drivers/net/bareudp.c
index eaaa7bf89accf..338958d2c1531 100644
--- a/drivers/net/bareudp.c
+++ b/drivers/net/bareudp.c
@@ -393,8 +393,10 @@ static int bareudp6_xmit_skb(struct sk_buff *skb, struct net_device *dev,
if (!sock)
return -ESHUTDOWN;
- dst = udp_tunnel6_dst_lookup(skb, dev, bareudp->net, sock, &saddr, info,
- use_cache);
+ dst = udp_tunnel6_dst_lookup(skb, dev, bareudp->net, sock, 0, &saddr,
+ key, 0, 0, key->tos,
+ use_cache ?
+ (struct dst_cache *) &info->dst_cache : NULL);
if (IS_ERR(dst))
return PTR_ERR(dst);
@@ -524,7 +526,9 @@ static int bareudp_fill_metadata_dst(struct net_device *dev,
return -ESHUTDOWN;
dst = udp_tunnel6_dst_lookup(skb, dev, bareudp->net, sock,
- &saddr, info, use_cache);
+ 0, &saddr, &info->key,
+ 0, 0, info->key.tos,
+ use_cache ? &info->dst_cache : NULL);
if (IS_ERR(dst))
return PTR_ERR(dst);
diff --git a/include/net/udp_tunnel.h b/include/net/udp_tunnel.h
index 8409a5429349b..a5fae599eaa9f 100644
--- a/include/net/udp_tunnel.h
+++ b/include/net/udp_tunnel.h
@@ -171,10 +171,11 @@ struct rtable *udp_tunnel_dst_lookup(struct sk_buff *skb,
struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
struct net_device *dev,
struct net *net,
- struct socket *sock,
+ struct socket *sock, int oif,
struct in6_addr *saddr,
- const struct ip_tunnel_info *info,
- bool use_cache);
+ const struct ip_tunnel_key *key,
+ __be16 sport, __be16 dport, u8 dsfield,
+ struct dst_cache *dst_cache);
struct metadata_dst *udp_tun_rx_dst(struct sk_buff *skb, unsigned short family,
__be16 flags, __be64 tunnel_id,
diff --git a/net/ipv6/ip6_udp_tunnel.c b/net/ipv6/ip6_udp_tunnel.c
index 812fc284cf36e..fe7a92cbbd449 100644
--- a/net/ipv6/ip6_udp_tunnel.c
+++ b/net/ipv6/ip6_udp_tunnel.c
@@ -118,9 +118,13 @@ EXPORT_SYMBOL_GPL(udp_tunnel6_xmit_skb);
* @dev: Tunnel device
* @net: Network namespace of tunnel device
* @sock: Socket which provides route info
+ * @oif: Index of the output interface
* @saddr: Memory to store the src ip address
- * @info: Tunnel information
- * @use_cache: Flag to enable cache usage
+ * @key: Tunnel information
+ * @sport: UDP source port
+ * @dport: UDP destination port
+ * @dsfield: The traffic class field
+ * @dst_cache: The dst cache to use for lookup
* This function performs a route lookup on a UDP tunnel
*
* It returns a valid dst pointer and stores src address to be used in
@@ -131,20 +135,17 @@ struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
struct net_device *dev,
struct net *net,
struct socket *sock,
+ int oif,
struct in6_addr *saddr,
- const struct ip_tunnel_info *info,
- bool use_cache)
+ const struct ip_tunnel_key *key,
+ __be16 sport, __be16 dport, u8 dsfield,
+ struct dst_cache *dst_cache)
{
struct dst_entry *dst = NULL;
-#ifdef CONFIG_DST_CACHE
- struct dst_cache *dst_cache;
-#endif
struct flowi6 fl6;
- __u8 prio;
#ifdef CONFIG_DST_CACHE
- dst_cache = (struct dst_cache *)&info->dst_cache;
- if (use_cache) {
+ if (dst_cache) {
dst = dst_cache_get_ip6(dst_cache, saddr);
if (dst)
return dst;
@@ -153,10 +154,12 @@ struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
memset(&fl6, 0, sizeof(fl6));
fl6.flowi6_mark = skb->mark;
fl6.flowi6_proto = IPPROTO_UDP;
- fl6.daddr = info->key.u.ipv6.dst;
- fl6.saddr = info->key.u.ipv6.src;
- prio = info->key.tos;
- fl6.flowlabel = ip6_make_flowinfo(prio, info->key.label);
+ fl6.flowi6_oif = oif;
+ fl6.daddr = key->u.ipv6.dst;
+ fl6.saddr = key->u.ipv6.src;
+ fl6.fl6_sport = sport;
+ fl6.fl6_dport = dport;
+ fl6.flowlabel = ip6_make_flowinfo(dsfield, key->label);
dst = ipv6_stub->ipv6_dst_lookup_flow(net, sock->sk, &fl6,
NULL);
@@ -170,7 +173,7 @@ struct dst_entry *udp_tunnel6_dst_lookup(struct sk_buff *skb,
return ERR_PTR(-ELOOP);
}
#ifdef CONFIG_DST_CACHE
- if (use_cache)
+ if (dst_cache)
dst_cache_set_ip6(dst_cache, dst, &fl6.saddr);
#endif
*saddr = fl6.saddr;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 475/982] vxlan: use generic function for tunnel IPv6 route lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (473 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 474/982] ipv6: add new arguments to udp_tunnel6_dst_lookup() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 476/982] vxlan: Pull inner IP header in vxlan_xmit_one() Greg Kroah-Hartman
` (513 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guillaume Nault, Beniamino Galvani,
David Ahern, David S. Miller, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Beniamino Galvani <b.galvani@gmail.com>
[ Upstream commit 2aceb896ee18ae35b21b14c978d8c2ef8c7b439d ]
The route lookup can be done now via generic function
udp_tunnel6_dst_lookup() to replace the custom implementation in
vxlan6_get_route().
This is similar to what already done for IPv4 in commit 6f19b2c136d9
("vxlan: use generic function for tunnel IPv4 route lookup").
Suggested-by: Guillaume Nault <gnault@redhat.com>
Signed-off-by: Beniamino Galvani <b.galvani@gmail.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: be83178bfc44 ("vxlan: initialize _md in vxlan_xmit_one()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 136 ++++++++-------------------------
1 file changed, 30 insertions(+), 106 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 5d24ed25b68b0..34cdc9b4221bc 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2332,63 +2332,6 @@ static int vxlan_build_skb(struct sk_buff *skb, struct dst_entry *dst,
return 0;
}
-#if IS_ENABLED(CONFIG_IPV6)
-static struct dst_entry *vxlan6_get_route(struct vxlan_dev *vxlan,
- struct net_device *dev,
- struct vxlan_sock *sock6,
- struct sk_buff *skb, int oif, u8 tos,
- __be32 label,
- const struct in6_addr *daddr,
- struct in6_addr *saddr,
- __be16 dport, __be16 sport,
- struct dst_cache *dst_cache,
- const struct ip_tunnel_info *info)
-{
- bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
- struct dst_entry *ndst;
- struct flowi6 fl6;
-
- if (!sock6)
- return ERR_PTR(-EIO);
-
- if (tos && !info)
- use_cache = false;
- if (use_cache) {
- ndst = dst_cache_get_ip6(dst_cache, saddr);
- if (ndst)
- return ndst;
- }
-
- memset(&fl6, 0, sizeof(fl6));
- fl6.flowi6_oif = oif;
- fl6.daddr = *daddr;
- fl6.saddr = *saddr;
- fl6.flowlabel = ip6_make_flowinfo(tos, label);
- fl6.flowi6_mark = skb->mark;
- fl6.flowi6_proto = IPPROTO_UDP;
- fl6.fl6_dport = dport;
- fl6.fl6_sport = sport;
-
- ndst = ipv6_stub->ipv6_dst_lookup_flow(vxlan->net, sock6->sock->sk,
- &fl6, NULL);
- if (IS_ERR(ndst)) {
- netdev_dbg(dev, "no route to %pI6\n", daddr);
- return ERR_PTR(-ENETUNREACH);
- }
-
- if (unlikely(ndst->dev == dev)) {
- netdev_dbg(dev, "circular route to %pI6\n", daddr);
- dst_release(ndst);
- return ERR_PTR(-ELOOP);
- }
-
- *saddr = fl6.saddr;
- if (use_cache)
- dst_cache_set_ip6(dst_cache, ndst, saddr);
- return ndst;
-}
-#endif
-
/* Bypass encapsulation if the destination is local */
static void vxlan_encap_bypass(struct sk_buff *skb, struct vxlan_dev *src_vxlan,
struct vxlan_dev *dst_vxlan, __be32 vni,
@@ -2451,7 +2394,7 @@ static void vxlan_encap_bypass(struct sk_buff *skb, struct vxlan_dev *src_vxlan,
static int encap_bypass_if_local(struct sk_buff *skb, struct net_device *dev,
struct vxlan_dev *vxlan,
- union vxlan_addr *daddr,
+ int addr_family,
__be16 dst_port, int dst_ifindex, __be32 vni,
struct dst_entry *dst,
u32 rt_flags)
@@ -2470,7 +2413,7 @@ static int encap_bypass_if_local(struct sk_buff *skb, struct net_device *dev,
dst_release(dst);
dst_vxlan = vxlan_find_vni(vxlan->net, dst_ifindex, vni,
- daddr->sa.sa_family, dst_port,
+ addr_family, dst_port,
vxlan->cfg.flags);
if (!dst_vxlan) {
dev->stats.tx_errors++;
@@ -2497,13 +2440,12 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
struct ip_tunnel_key key;
struct vxlan_dev *vxlan = netdev_priv(dev);
const struct iphdr *old_iph = ip_hdr(skb);
- union vxlan_addr *dst;
- union vxlan_addr remote_ip;
struct vxlan_metadata _md;
struct vxlan_metadata *md = &_md;
unsigned int pkt_len = skb->len;
__be16 src_port = 0, dst_port;
struct dst_entry *ndst = NULL;
+ int addr_family;
__u8 tos, ttl;
int ifindex;
int err;
@@ -2512,20 +2454,15 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
bool udp_sum = false;
bool xnet = !net_eq(vxlan->net, dev_net(vxlan->dev));
__be32 vni = 0;
-#if IS_ENABLED(CONFIG_IPV6)
- union vxlan_addr local_ip;
- __be32 label;
-#endif
info = skb_tunnel_info(skb);
use_cache = ip_tunnel_dst_cache_usable(skb, info);
if (rdst) {
- dst = &rdst->remote_ip;
memset(&key, 0, sizeof(key));
pkey = &key;
- if (vxlan_addr_any(dst)) {
+ if (vxlan_addr_any(&rdst->remote_ip)) {
if (did_rsc) {
/* short-circuited back to local bridge */
vxlan_encap_bypass(skb, vxlan, vxlan,
@@ -2535,11 +2472,12 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
goto drop;
}
+ addr_family = vxlan->cfg.saddr.sa.sa_family;
dst_port = rdst->remote_port ? rdst->remote_port : vxlan->cfg.dst_port;
vni = (rdst->remote_vni) ? : default_vni;
ifindex = rdst->remote_ifindex;
- if (dst->sa.sa_family == AF_INET) {
+ if (addr_family == AF_INET) {
key.u.ipv4.src = vxlan->cfg.saddr.sin.sin_addr.s_addr;
key.u.ipv4.dst = rdst->remote_ip.sin.sin_addr.s_addr;
} else {
@@ -2553,23 +2491,21 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
ttl = ip_tunnel_get_ttl(old_iph, skb);
} else {
ttl = vxlan->cfg.ttl;
- if (!ttl && vxlan_addr_multicast(dst))
+ if (!ttl && vxlan_addr_multicast(&rdst->remote_ip))
ttl = 1;
}
-
tos = vxlan->cfg.tos;
if (tos == 1)
tos = ip_tunnel_get_dsfield(old_iph, skb);
if (tos && !info)
use_cache = false;
- if (dst->sa.sa_family == AF_INET)
+ if (addr_family == AF_INET)
udp_sum = !(flags & VXLAN_F_UDP_ZERO_CSUM_TX);
else
udp_sum = !(flags & VXLAN_F_UDP_ZERO_CSUM6_TX);
#if IS_ENABLED(CONFIG_IPV6)
- local_ip = vxlan->cfg.saddr;
- label = vxlan->cfg.label;
+ key.label = vxlan->cfg.label;
#endif
} else {
if (!info) {
@@ -2577,17 +2513,8 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
dev->name);
goto drop;
}
- remote_ip.sa.sa_family = ip_tunnel_info_af(info);
- if (remote_ip.sa.sa_family == AF_INET) {
- remote_ip.sin.sin_addr.s_addr = info->key.u.ipv4.dst;
- } else {
- remote_ip.sin6.sin6_addr = info->key.u.ipv6.dst;
-#if IS_ENABLED(CONFIG_IPV6)
- local_ip.sin6.sin6_addr = info->key.u.ipv6.src;
-#endif
- }
- dst = &remote_ip;
pkey = &info->key;
+ addr_family = ip_tunnel_info_af(info);
dst_port = info->key.tp_dst ? : vxlan->cfg.dst_port;
vni = tunnel_id_to_key32(info->key.tun_id);
ifindex = 0;
@@ -2599,16 +2526,13 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
}
ttl = info->key.ttl;
tos = info->key.tos;
-#if IS_ENABLED(CONFIG_IPV6)
- label = info->key.label;
-#endif
udp_sum = !!(info->key.tun_flags & TUNNEL_CSUM);
}
src_port = udp_flow_src_port(dev_net(dev), skb, vxlan->cfg.port_min,
vxlan->cfg.port_max, true);
rcu_read_lock();
- if (dst->sa.sa_family == AF_INET) {
+ if (addr_family == AF_INET) {
struct vxlan_sock *sock4 = rcu_dereference(vxlan->vn4_sock);
struct rtable *rt;
__be16 df = 0;
@@ -2627,7 +2551,7 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
if (!info) {
/* Bypass encapsulation if the destination is local */
- err = encap_bypass_if_local(skb, dev, vxlan, dst,
+ err = encap_bypass_if_local(skb, dev, vxlan, AF_INET,
dst_port, ifindex, vni,
&rt->dst, rt->rt_flags);
if (err)
@@ -2681,15 +2605,15 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
#if IS_ENABLED(CONFIG_IPV6)
} else {
struct vxlan_sock *sock6 = rcu_dereference(vxlan->vn6_sock);
+ struct in6_addr saddr;
if (!ifindex)
ifindex = sock6->sock->sk->sk_bound_dev_if;
- ndst = vxlan6_get_route(vxlan, dev, sock6, skb, ifindex, tos,
- label, &dst->sin6.sin6_addr,
- &local_ip.sin6.sin6_addr,
- dst_port, src_port,
- dst_cache, info);
+ ndst = udp_tunnel6_dst_lookup(skb, dev, vxlan->net, sock6->sock,
+ ifindex, &saddr, pkey,
+ src_port, dst_port, tos,
+ use_cache ? dst_cache : NULL);
if (IS_ERR(ndst)) {
err = PTR_ERR(ndst);
ndst = NULL;
@@ -2699,7 +2623,7 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
if (!info) {
u32 rt6i_flags = dst_rt6_info(ndst)->rt6i_flags;
- err = encap_bypass_if_local(skb, dev, vxlan, dst,
+ err = encap_bypass_if_local(skb, dev, vxlan, AF_INET6,
dst_port, ifindex, vni,
ndst, rt6i_flags);
if (err)
@@ -2714,16 +2638,13 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
} else if (err) {
if (info) {
struct ip_tunnel_info *unclone;
- struct in6_addr src, dst;
unclone = skb_tunnel_info_unclone(skb);
if (unlikely(!unclone))
goto tx_error;
- src = remote_ip.sin6.sin6_addr;
- dst = local_ip.sin6.sin6_addr;
- unclone->key.u.ipv6.src = src;
- unclone->key.u.ipv6.dst = dst;
+ unclone->key.u.ipv6.src = pkey->u.ipv6.dst;
+ unclone->key.u.ipv6.dst = saddr;
}
vxlan_encap_bypass(skb, vxlan, vxlan, vni, false);
@@ -2740,9 +2661,8 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
goto tx_error;
udp_tunnel6_xmit_skb(ndst, sock6->sock->sk, skb, dev,
- &local_ip.sin6.sin6_addr,
- &dst->sin6.sin6_addr, tos, ttl,
- label, src_port, dst_port, !udp_sum);
+ &saddr, &pkey->u.ipv6.dst, tos, ttl,
+ pkey->label, src_port, dst_port, !udp_sum);
#endif
}
vxlan_vnifilter_count(vxlan, vni, NULL, VXLAN_VNI_STATS_TX, pkt_len);
@@ -3145,10 +3065,14 @@ static int vxlan_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb)
struct vxlan_sock *sock6 = rcu_dereference(vxlan->vn6_sock);
struct dst_entry *ndst;
- ndst = vxlan6_get_route(vxlan, dev, sock6, skb, 0, info->key.tos,
- info->key.label, &info->key.u.ipv6.dst,
- &info->key.u.ipv6.src, dport, sport,
- &info->dst_cache, info);
+ if (!sock6)
+ return -EIO;
+
+ ndst = udp_tunnel6_dst_lookup(skb, dev, vxlan->net, sock6->sock,
+ 0, &info->key.u.ipv6.src,
+ &info->key,
+ sport, dport, info->key.tos,
+ &info->dst_cache);
if (IS_ERR(ndst))
return PTR_ERR(ndst);
dst_release(ndst);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 476/982] vxlan: Pull inner IP header in vxlan_xmit_one().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (474 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 475/982] vxlan: use generic function for tunnel IPv6 route lookup Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 477/982] vxlan: initialize _md " Greg Kroah-Hartman
` (512 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guillaume Nault, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guillaume Nault <gnault@redhat.com>
[ Upstream commit 31392048f55f98cb01ca709d32d06d926ab9760a ]
Ensure the inner IP header is part of the skb's linear data before
setting old_iph. Otherwise, on a non-linear skb, old_iph could point
outside of the packet data.
Unlike classical VXLAN, which always encapsulates Ethernet packets,
VXLAN-GPE can transport IP packets directly. In that case, we need to
look at skb->protocol to figure out if an Ethernet header is present.
Fixes: d342894c5d2f ("vxlan: virtual extensible lan")
Signed-off-by: Guillaume Nault <gnault@redhat.com>
Link: https://patch.msgid.link/2aa75f6fa62ac9dbe4f16ad5ba75dd04a51d4b99.1718804000.git.gnault@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: be83178bfc44 ("vxlan: initialize _md in vxlan_xmit_one()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 34cdc9b4221bc..6659a7df23a17 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2439,7 +2439,7 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
struct ip_tunnel_key *pkey;
struct ip_tunnel_key key;
struct vxlan_dev *vxlan = netdev_priv(dev);
- const struct iphdr *old_iph = ip_hdr(skb);
+ const struct iphdr *old_iph;
struct vxlan_metadata _md;
struct vxlan_metadata *md = &_md;
unsigned int pkt_len = skb->len;
@@ -2453,8 +2453,15 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
bool use_cache;
bool udp_sum = false;
bool xnet = !net_eq(vxlan->net, dev_net(vxlan->dev));
+ bool no_eth_encap;
__be32 vni = 0;
+ no_eth_encap = flags & VXLAN_F_GPE && skb->protocol != htons(ETH_P_TEB);
+ if (!skb_vlan_inet_prepare(skb, no_eth_encap))
+ goto drop;
+
+ old_iph = ip_hdr(skb);
+
info = skb_tunnel_info(skb);
use_cache = ip_tunnel_dst_cache_usable(skb, info);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 477/982] vxlan: initialize _md in vxlan_xmit_one()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (475 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 476/982] vxlan: Pull inner IP header in vxlan_xmit_one() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 478/982] ppp_synctty: ensure a writeable skb header Greg Kroah-Hartman
` (511 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Kuniyuki Iwashima,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit be83178bfc44588f6e3adb827ed874c683193466 ]
If a VXLAN device is configured with both VXLAN_F_COLLECT_METADATA and
VXLAN_F_GBP, and a packet is transmitted through it using an external
ip_tunnel_info that lacks the IP_TUNNEL_VXLAN_OPT_BIT flag, md is left
pointing to the uninitialized _md stack variable:
if (test_bit(IP_TUNNEL_VXLAN_OPT_BIT, info->key.tun_flags)) {
if (info->options_len < sizeof(*md))
goto drop;
md = ip_tunnel_info_opts(info);
}
Because IP_TUNNEL_VXLAN_OPT_BIT is not set, md is not updated and remains
pointing to _md. Later, vxlan_build_skb() is called with md, which
eventually calls vxlan_build_gbp_hdr():
if (vxflags & VXLAN_F_GBP)
vxlan_build_gbp_hdr(vxh, md);
Inside vxlan_build_gbp_hdr(), md->gbp is read:
if (!md->gbp)
return;
gbp = (struct vxlanhdr_gbp *)vxh;
...
if (md->gbp & VXLAN_GBP_DONT_LEARN)
gbp->dont_learn = 1;
If the stack contains garbage, this causes:
1) VXLAN_HF_GBP flag to be spuriously set in the VXLAN header.
2) gbp->dont_learn and gbp->policy_applied to be set from stack bits.
3) gbp->policy_id to receive 16 bits of uninitialized kernel stack data,
leaking it onto the wire.
Fix this by zero-initializing _md. If IP_TUNNEL_VXLAN_OPT_BIT is not
present, md->gbp remains 0, and vxlan_build_gbp_hdr() returns early
without modifying the VXLAN header.
Fixes: ee122c79d422 ("vxlan: Flow based tunneling")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260906180111.1973188-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 6659a7df23a17..9327b38fb6fde 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2440,7 +2440,7 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
struct ip_tunnel_key key;
struct vxlan_dev *vxlan = netdev_priv(dev);
const struct iphdr *old_iph;
- struct vxlan_metadata _md;
+ struct vxlan_metadata _md = {};
struct vxlan_metadata *md = &_md;
unsigned int pkt_len = skb->len;
__be16 src_port = 0, dst_port;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 478/982] ppp_synctty: ensure a writeable skb header
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (476 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 477/982] vxlan: initialize _md " Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 479/982] net: stmmac: initialize ptp_lock at probe time Greg Kroah-Hartman
` (510 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qingfang Deng, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qingfang Deng <qingfang.deng@linux.dev>
[ Upstream commit 8aaeb56aff2a557a88f83ae866da2c91ad247e59 ]
ppp_sync_txmunge() checks headroom before prepending the address and
control bytes, but does not ensure that the skb header is writable.
A received skb can reach this function through PPP channel bridging
without passing through ppp_start_xmit(), which calls skb_cow_head().
For example, a PPPoE frame may share its buffer with a clone queued to
an AF_PACKET socket. If it is bridged to a synchronous tty channel, the
address/control bytes can overwrite data still visible to that socket.
Use skb_cow_head() to ensure both sufficient headroom and a writable
header.
Fixes: 4cf476ced45d ("ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls")
Signed-off-by: Qingfang Deng <qingfang.deng@linux.dev>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260908072135.877364-1-qingfang.deng@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ppp/ppp_synctty.c | 14 +++-----------
1 file changed, 3 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ppp/ppp_synctty.c b/drivers/net/ppp/ppp_synctty.c
index fb533c43deeea..1ee9143b5f9c7 100644
--- a/drivers/net/ppp/ppp_synctty.c
+++ b/drivers/net/ppp/ppp_synctty.c
@@ -535,17 +535,9 @@ ppp_sync_txmunge(struct syncppp *ap, struct sk_buff *skb)
/* prepend address/control fields if necessary */
if ((ap->flags & SC_COMP_AC) == 0 || islcp) {
- if (skb_headroom(skb) < 2) {
- struct sk_buff *npkt = dev_alloc_skb(skb->len + 2);
- if (npkt == NULL) {
- kfree_skb(skb);
- return NULL;
- }
- skb_reserve(npkt,2);
- skb_copy_from_linear_data(skb,
- skb_put(npkt, skb->len), skb->len);
- consume_skb(skb);
- skb = npkt;
+ if (skb_cow_head(skb, 2)) {
+ kfree_skb(skb);
+ return NULL;
}
skb_push(skb,2);
skb->data[0] = PPP_ALLSTATIONS;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 479/982] net: stmmac: initialize ptp_lock at probe time
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (477 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 478/982] ppp_synctty: ensure a writeable skb header Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 480/982] selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value Greg Kroah-Hartman
` (509 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 0338c68e22abd2ee509ec2e32508a50896618c32 ]
priv->ptp_lock is only initialized in stmmac_ptp_register(), which runs
during __stmmac_open(). However, the lock is also used while the
interface is down and has never been opened: tc_taprio_configure()
invokes the PTP gettime64() callback to compute the EST base time when
offloading a TAPRIO schedule, and stmmac_get_time() takes
priv->ptp_lock. Using an uninitialized rwlock is undefined behaviour.
Move the rwlock_init() to __stmmac_dvr_probe(), together with the other
private locks, so that ptp_lock is always valid regardless of the
interface state.
Fixes: b60189e0392f ("net: stmmac: Integrate EST with TAPRIO scheduler API")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260904-stmmac-fix-ptp-clock-init-v1-1-df70eb1eb04d@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 1 +
drivers/net/ethernet/stmicro/stmmac/stmmac_ptp.c | 1 -
2 files changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index fb8c65c2bc0ef..5ca6157208864 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -7417,6 +7417,7 @@ int stmmac_dvr_probe(struct device *device,
stmmac_napi_add(ndev);
mutex_init(&priv->lock);
+ rwlock_init(&priv->ptp_lock);
/* If a specific clk_csr value is passed from the platform
* this means that the CSR Clock Range selection cannot be
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_ptp.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_ptp.c
index cc223fe086484..d1ad9161de3ae 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_ptp.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_ptp.c
@@ -307,7 +307,6 @@ void stmmac_ptp_register(struct stmmac_priv *priv)
stmmac_ptp_clock_ops.n_per_out = priv->dma_cap.pps_out_num;
stmmac_ptp_clock_ops.n_ext_ts = priv->dma_cap.aux_snapshot_n;
- rwlock_init(&priv->ptp_lock);
mutex_init(&priv->aux_ts_lock);
priv->ptp_clock_ops = stmmac_ptp_clock_ops;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 480/982] selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (478 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 479/982] net: stmmac: initialize ptp_lock at probe time Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 481/982] net/sched: cls_route: free emptied bucket on filter move Greg Kroah-Hartman
` (508 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thibault Ferrante,
Venkat Rao Bagalkote, Madhavan Srinivasan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thibault Ferrante <thibault.ferrante@canonical.com>
[ Upstream commit ed28b16eab705071d28edaace47189c2eb3aa108 ]
tcheck() is used to check the current transaction state (active,
suspended, doomed) via the "tcheck" instruction, which writes its
result into CR field 0. The inline asm declared a GPR output operand
for this result but never actually moved the CR into it.
Every caller (tcheck_doomed(), tcheck_active(), tcheck_suspended(),
tcheck_transactional()) has effectively been testing bits of an unrelated,
arbitrary register value since this helper was introduced.
The "& 4" mask discards the TDOOMED and TS_lsb (suspended) bits before
they ever reach the callers, so tcheck_doomed() and tcheck_suspended()
can never return true, and tcheck_transactional() degrades to being
equivalent to tcheck_active().
Fix tcheck() to actually move CR into the output register with mfcr,
and widen the mask from "& 4" to "& 0xf" so the full CR0 nibble
(TDOOMED | TS_msb | TS_lsb | reserved) is preserved for the callers.
This bug has been present since tcheck() was introduced.
Link: https://bugs.launchpad.net/bugs/2107442
Fixes: 8e03bd4e70b6 ("selftests/powerpc: Add TM tcheck helpers in C")
Signed-off-by: Thibault Ferrante <thibault.ferrante@canonical.com>
Reported-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
Tested-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
Closes: https://lore.kernel.org/all/364996ce-aba2-4213-8d20-7dd481b43fe6@linux.ibm.com/
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260907215420.1258678-1-thibault.ferrante@canonical.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/powerpc/tm/tm.h | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/powerpc/tm/tm.h b/tools/testing/selftests/powerpc/tm/tm.h
index c03c6e7788767..6024ce4ba6ffd 100644
--- a/tools/testing/selftests/powerpc/tm/tm.h
+++ b/tools/testing/selftests/powerpc/tm/tm.h
@@ -105,8 +105,12 @@ static inline bool failure_is_nesting(void)
static inline int tcheck(void)
{
long cr;
- asm volatile ("tcheck 0" : "=r"(cr) : : "cr0");
- return (cr >> 28) & 4;
+ asm volatile("tcheck 0;"
+ "mfcr %0;"
+ : "=r"(cr)
+ :
+ : "cr0");
+ return (cr >> 28) & 0xf;
}
static inline bool tcheck_doomed(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 481/982] net/sched: cls_route: free emptied bucket on filter move
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (479 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 480/982] selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 482/982] net/sched: cls_api: Dont replay RTM_GETCHAIN in tc_ctl_chain() Greg Kroah-Hartman
` (507 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Jamal Hadi Salim,
Victor Nogueira, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Victor Nogueira <victor@mojatatu.com>
[ Upstream commit 1853f30cf5c84971f99788a76207c6f745380896 ]
route4_change can move an existing filter to a different top-level
bucket: route4_set_parms recomputes the handle from TCA_ROUTE4_TO/
FROM/IIF, and the handle-mismatch check is gated on the 'new' flag, so
for an existing filter the new handle may differ from the old one and
land in a different bucket. When this happens, the filter is unlinked
from the old bucket, but the bucket itself is never freed once it goes
empty. The stale empty bucket remains in head->table[], causing
route4_delete to report *last=false even after the last live filter is
gone. That pins the empty tcf_proto and causes a leak.
Fix this by refcounting the filters linked to a bucket and freeing the
bucket when the count drops to zero. The existing scan in route4_delete
goes away with it.
The count is updated at all sites that link or unlink a filter during add,
change and delete, and the bucket is dropped from head->table[] as soon as
it reaches zero.
Conditions to recreate the bug:
CONFIG_NET_CLS_ROUTE4=y, CONFIG_NET_SCH_INGRESS=y, CONFIG_NET_CLS_ACT=y.
tc qdisc replace dev lo clsact
tc filter add dev lo ingress protocol ip pref 100 route from 1 to 1
tc filter change dev lo ingress protocol ip pref 100 handle 0x10001 \
route from 1 to 2
tc filter del dev lo ingress protocol ip pref 100 handle 0x10002 \
route from 1 to 2
tc filter show dev lo ingress | grep -c 'pref 100 route chain 0 '
Fixes: 1e052be69d04 ("net_sched: destroy proto tp when all filters are gone")
Reported-by: Vega <vega@nebusec.ai>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260907192133.2639067-2-victor@mojatatu.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/cls_route.c | 45 +++++++++++++++++++++----------------------
1 file changed, 22 insertions(+), 23 deletions(-)
diff --git a/net/sched/cls_route.c b/net/sched/cls_route.c
index 6c205fcb65475..c7fe52f59521c 100644
--- a/net/sched/cls_route.c
+++ b/net/sched/cls_route.c
@@ -11,6 +11,7 @@
#include <linux/kernel.h>
#include <linux/string.h>
#include <linux/errno.h>
+#include <linux/refcount.h>
#include <linux/skbuff.h>
#include <net/dst.h>
#include <net/route.h>
@@ -40,6 +41,7 @@ struct route4_head {
struct route4_bucket {
/* 16 FROM buckets + 16 IIF buckets + 1 wildcard bucket */
struct route4_filter __rcu *ht[16 + 16 + 1];
+ refcount_t filters_ref;
struct rcu_head rcu;
};
@@ -334,7 +336,7 @@ static int route4_delete(struct tcf_proto *tp, void *arg, bool *last,
struct route4_filter *nf;
struct route4_bucket *b;
unsigned int h = 0;
- int i, h1;
+ int h1;
if (!head || !f)
return -EINVAL;
@@ -360,23 +362,14 @@ static int route4_delete(struct tcf_proto *tp, void *arg, bool *last,
tcf_exts_get_net(&f->exts);
tcf_queue_work(&f->rwork, route4_delete_filter_work);
- /* Strip RTNL protected tree */
- for (i = 0; i <= 32; i++) {
- struct route4_filter *rt;
-
- rt = rtnl_dereference(b->ht[i]);
- if (rt)
- goto out;
+ if (refcount_dec_and_test(&b->filters_ref)) {
+ RCU_INIT_POINTER(head->table[to_hash(h)], NULL);
+ kfree_rcu(b, rcu);
}
-
- /* OK, session has no flows */
- RCU_INIT_POINTER(head->table[to_hash(h)], NULL);
- kfree_rcu(b, rcu);
break;
}
}
-out:
*last = true;
for (h1 = 0; h1 <= 256; h1++) {
if (rcu_access_pointer(head->table[h1])) {
@@ -453,6 +446,7 @@ static int route4_set_parms(struct net *net, struct tcf_proto *tp,
if (b == NULL)
return -ENOBUFS;
+ refcount_set(&b->filters_ref, 1);
rcu_assign_pointer(head->table[h1], b);
} else {
unsigned int h2 = from_hash(nhandle >> 16);
@@ -462,6 +456,8 @@ static int route4_set_parms(struct net *net, struct tcf_proto *tp,
fp = rtnl_dereference(fp->next))
if (fp->handle == f->handle)
return -EEXIST;
+
+ refcount_inc(&b->filters_ref);
}
if (tb[TCA_ROUTE4_TO])
@@ -495,7 +491,7 @@ static int route4_change(struct net *net, struct sk_buff *in_skb,
struct route4_bucket *b;
struct nlattr *opt = tca[TCA_OPTIONS];
struct nlattr *tb[TCA_ROUTE4_MAX + 1];
- unsigned int h, th;
+ unsigned int h;
int err;
bool new = true;
@@ -553,17 +549,20 @@ static int route4_change(struct net *net, struct sk_buff *in_skb,
rcu_assign_pointer(*fp, f);
if (fold) {
- th = to_hash(fold->handle);
+ b = fold->bkt;
h = from_hash(fold->handle >> 16);
- b = rtnl_dereference(head->table[th]);
- if (b) {
- fp = &b->ht[h];
- for (pfp = rtnl_dereference(*fp); pfp;
- fp = &pfp->next, pfp = rtnl_dereference(*fp)) {
- if (pfp == fold) {
- rcu_assign_pointer(*fp, fold->next);
- break;
+ fp = &b->ht[h];
+ for (pfp = rtnl_dereference(*fp); pfp;
+ fp = &pfp->next, pfp = rtnl_dereference(*fp)) {
+ if (pfp == fold) {
+ rcu_assign_pointer(*fp, fold->next);
+ if (refcount_dec_and_test(&b->filters_ref)) {
+ unsigned int th = to_hash(fold->handle);
+
+ RCU_INIT_POINTER(head->table[th], NULL);
+ kfree_rcu(b, rcu);
}
+ break;
}
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 482/982] net/sched: cls_api: Dont replay RTM_GETCHAIN in tc_ctl_chain().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (480 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 481/982] net/sched: cls_route: free emptied bucket on filter move Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 483/982] net: sun4i-emac: fix missing of_node_put() for phy_node Greg Kroah-Hartman
` (506 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taras Madan, Kuniyuki Iwashima,
Jamal Hadi Salim, hybris, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit dff39930ad5e53d202bfdfb14687d1d2fd753b4d ]
If a netlink socket sends RTM_GETCHAIN requests repeatedly
without recv()ing the responses, tc_ctl_chain() hogs CPU and
triggers Hung Task splat. [0]
As caught in the stack trace, netlink_attachskb() could confuse
tc_ctl_chain() by returning -EAGAIN when the userspace netlink
socket's receive buffer is full.
The replay: label exists since commit 32a4f5ecd738 ("net: sched:
introduce chain object to uapi") but was not used initially.
Since commit 9f407f1768d3 ("net: sched: introduce chain templates"),
the label is needed for RTM_NEWCHAIN because tcf_proto_lookup_ops()
may release RTNL to call request_module().
However, the replay logic is unnecessary for RTM_GETCHAIN.
Let's apply the replay logic only for RTM_NEWCHAIN.
[0]:
INFO: task repro:1018 is blocked on a mutex likely owned by task repro:1022.
task:repro state:R running task stack:14096 pid:1022 tgid:1014 ppid:961 task_flags:0x400040 flags:0x00080000
Call Trace:
<TASK>
? clockevents_program_event (kernel/time/clockevents.c:372)
? pskb_expand_head (net/core/skbuff.c:615)
? skb_release_data (net/core/skbuff.c:1122)
? netlink_attachskb (./include/linux/skbuff.h:1323 ./include/linux/skbuff.h:1332 net/netlink/af_netlink.c:1232)
? __netlink_lookup (./include/linux/rcupdate.h:882 ./include/linux/rhashtable.h:711 net/netlink/af_netlink.c:499)
? tc_chain_notify (net/sched/cls_api.c:3045)
? tc_chain_notify (./include/linux/skbuff.h:1384 net/sched/cls_api.c:3041)
? netlink_unicast (net/netlink/af_netlink.c:1335)
? rtnl_unicast (./include/net/netlink.h:1198 net/core/rtnetlink.c:985)
? tc_ctl_chain (net/sched/cls_api.c:3242)
? rtnetlink_rcv_msg (net/core/rtnetlink.c:7146)
? netlink_unicast (net/netlink/af_netlink.c:1354)
? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:7177)
? netlink_rcv_skb (net/netlink/af_netlink.c:2556)
? netlink_unicast (net/netlink/af_netlink.c:1319)
? netlink_sendmsg (net/netlink/af_netlink.c:1900)
? __sock_sendmsg (net/socket.c:800)
? __sys_sendto (net/socket.c:2281)
? __x64_sys_sendto (net/socket.c:2288 net/socket.c:2284 net/socket.c:2284)
? do_syscall_64 (arch/x86/entry/syscall_64.c:61 arch/x86/entry/syscall_64.c:84)
? entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
</TASK>
Fixes: 2ed9db3074fc ("net: sched: cls_api: fix dead code in switch")
Reported-by: Taras Madan <tarasmadan@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Tested-by: hybris@mojatatu.ai
Link: https://patch.msgid.link/20260908205537.863484-1-kuniyu@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/cls_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/sched/cls_api.c b/net/sched/cls_api.c
index 0db96c920ea58..341128a00420c 100644
--- a/net/sched/cls_api.c
+++ b/net/sched/cls_api.c
@@ -2998,7 +2998,7 @@ static int tc_ctl_chain(struct sk_buff *skb, struct nlmsghdr *n,
tcf_chain_put(chain);
errout_block:
tcf_block_release(q, block, true);
- if (err == -EAGAIN)
+ if (err == -EAGAIN && n->nlmsg_type == RTM_NEWCHAIN)
/* Replay the request. */
goto replay;
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 483/982] net: sun4i-emac: fix missing of_node_put() for phy_node
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (481 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 482/982] net/sched: cls_api: Dont replay RTM_GETCHAIN in tc_ctl_chain() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 484/982] net: hinic: fix mailbox segment buffer overflow Greg Kroah-Hartman
` (505 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Youhong, Simon Horman,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Youhong <liyouhong@kylinos.cn>
[ Upstream commit af406abfecad2f48d8f1fc646d3994f0982bac62 ]
of_parse_phandle() returns a node pointer with an elevated refcount.
Add the missing of_node_put() on the probe error path after
register_netdev() fails and in emac_remove().
Fixes: 492205050d77 ("net: Add EMAC ethernet driver found on Allwinner A10 SoC's")
Signed-off-by: Li Youhong <liyouhong@kylinos.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260904080758.2432748-1-dayou5941@163.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/allwinner/sun4i-emac.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/allwinner/sun4i-emac.c b/drivers/net/ethernet/allwinner/sun4i-emac.c
index 9a6948cde2403..789a5008fe61e 100644
--- a/drivers/net/ethernet/allwinner/sun4i-emac.c
+++ b/drivers/net/ethernet/allwinner/sun4i-emac.c
@@ -1067,6 +1067,7 @@ static int emac_probe(struct platform_device *pdev)
return 0;
out_release_sram:
+ of_node_put(db->phy_node);
sunxi_sram_release(&pdev->dev);
out_clk_disable_unprepare:
clk_disable_unprepare(db->clk);
@@ -1094,6 +1095,7 @@ static int emac_remove(struct platform_device *pdev)
}
unregister_netdev(ndev);
+ of_node_put(db->phy_node);
sunxi_sram_release(&pdev->dev);
clk_disable_unprepare(db->clk);
irq_dispose_mapping(ndev->irq);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 484/982] net: hinic: fix mailbox segment buffer overflow
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (482 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 483/982] net: sun4i-emac: fix missing of_node_put() for phy_node Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 485/982] octeontx2-af: fix PF/CGX debugfs PCI bus lookup Greg Kroah-Hartman
` (504 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
[ Upstream commit 5d4d985957434867bbe85e4fa5e638f3e48ad522 ]
check_mbox_seq_id_and_seg_len() validates that seq_id does not
exceed SEQ_ID_MAX_VAL (42) and seg_len does not exceed
MBOX_SEG_LEN (48). However, this allows the last segment
(seq_id=42) to carry a full 48-byte payload, writing to offset
42*48=2016 for 48 bytes (ending at byte 2064). The receive
buffer is only MBOX_MAX_BUF_SZ (2048) bytes, resulting in a
16-byte heap buffer overflow.
The hinic3 driver already handles this correctly by defining
MBOX_LAST_SEG_MAX_LEN and rejecting the last segment when it
exceeds the remaining buffer space. Apply the same fix to the
hinic driver.
Fixes: a425b6e1c69b ("hinic: add mailbox function support")
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Link: https://patch.msgid.link/AS8P251MB0001AE870B09020B46B5D7DBC8B22@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/huawei/hinic/hinic_hw_mbox.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/huawei/hinic/hinic_hw_mbox.c b/drivers/net/ethernet/huawei/hinic/hinic_hw_mbox.c
index 3f9c31d292158..420fb64460e10 100644
--- a/drivers/net/ethernet/huawei/hinic/hinic_hw_mbox.c
+++ b/drivers/net/ethernet/huawei/hinic/hinic_hw_mbox.c
@@ -128,6 +128,7 @@ enum hinic_mbox_tx_status {
#define SEQ_ID_START_VAL 0
#define SEQ_ID_MAX_VAL 42
+#define MBOX_LAST_SEG_MAX_LEN (MBOX_MAX_BUF_SZ - SEQ_ID_MAX_VAL * MBOX_SEG_LEN)
#define NO_DMA_ATTRIBUTE_VAL 0
@@ -372,7 +373,8 @@ recv_pf_from_vf_mbox_handler(struct hinic_mbox_func_to_func *func_to_func,
static bool check_mbox_seq_id_and_seg_len(struct hinic_recv_mbox *recv_mbox,
u8 seq_id, u8 seg_len)
{
- if (seq_id > SEQ_ID_MAX_VAL || seg_len > MBOX_SEG_LEN)
+ if (seq_id > SEQ_ID_MAX_VAL || seg_len > MBOX_SEG_LEN ||
+ (seq_id == SEQ_ID_MAX_VAL && seg_len > MBOX_LAST_SEG_MAX_LEN))
return false;
if (seq_id == 0) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 485/982] octeontx2-af: fix PF/CGX debugfs PCI bus lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (483 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 484/982] net: hinic: fix mailbox segment buffer overflow Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 486/982] net/rds: fix tcp stream corruption with large pages Greg Kroah-Hartman
` (503 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Subbaraya Sundeep, Ratheesh Kannoth,
Simon Horman, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ratheesh Kannoth <rkannoth@marvell.com>
[ Upstream commit 4f4b743c2d2bbc336cb164d9d3d2ed6956ad8437 ]
rvu_dbg_rvu_pf_cgx_map_display() locates each RVU PF PCI device via
pci_get_domain_bus_and_slot() when printing the PF-to-CGX map. It
assumed PF0 always sits on PCI bus 1 and derived other PF bus numbers
as pf + 1, but the AF device can be enumerated on a different bus.
Use rvu->pdev->bus->number as the base bus instead, so each PF lookup
uses pf + start on systems where RVU functions are on contiguous buses
but do not start at bus 1.
Fixes: e2fb373038654 ("octeontx2-af: Display CGX, NIX and PF map in debugfs.")
Signed-off-by: Subbaraya Sundeep <sbhatta@marvell.com>
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260904085114.3385530-1-rkannoth@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/marvell/octeontx2/af/rvu_debugfs.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c
index d6d73316b7dba..fe987f51a5dbb 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c
@@ -852,19 +852,25 @@ static int rvu_dbg_rvu_pf_cgx_map_display(struct seq_file *filp, void *unused)
int pf, domain, blkid;
u8 cgx_id, lmac_id;
u16 pcifunc;
+ u8 start;
- domain = 2;
+ domain = pci_domain_nr(rvu->pdev->bus);
mac_ops = get_mac_ops(rvu_first_cgx_pdata(rvu));
/* There can be no CGX devices at all */
if (!mac_ops)
return 0;
seq_printf(filp, "PCI dev\t\tRVU PF Func\tNIX block\t%s\tLMAC\n",
mac_ops->name);
+
+ /* All the PF devices are on contiguous PCI bus numbers, but the PF0(AF)
+ * may not start from 1 always. Hence get domain and bus from PCI device.
+ */
+ start = rvu->pdev->bus->number;
for (pf = 0; pf < rvu->hw->total_pfs; pf++) {
if (!is_pf_cgxmapped(rvu, pf))
continue;
- pdev = pci_get_domain_bus_and_slot(domain, pf + 1, 0);
+ pdev = pci_get_domain_bus_and_slot(domain, pf + start, 0);
if (!pdev)
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 486/982] net/rds: fix tcp stream corruption with large pages
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (484 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 485/982] octeontx2-af: fix PF/CGX debugfs PCI bus lookup Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 487/982] openvswitch: fix wrong flag value in get_ipv6_ext_hdrs() Greg Kroah-Hartman
` (502 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Greg Marsden, Allison Henderson,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Greg Marsden <greg.marsden@oracle.com>
[ Upstream commit 2ac09b5353fe6858411fdc8c6efa60d832e20f13 ]
rds_message_map_pages() assigns PAGE_SIZE bytes to every
scatterlist entry, even when total_len ends in a partial page. The RDS
congestion map is defined as 8192 bytes, so on systems with PAGE_SIZE
greater than 8192 the scatterlist maps bytes beyond the end of the
congestion map. RDS-TCP transmits the SG contents according to those
lengths, so the extra bytes become part of the TCP RDS stream and are
interpreted as subsequent RDS message headers, corrupting the stream.
Limit the final scatterlist mapping to the number of bytes remaining.
This has no effect on systems with a 4K page size and allows RDS-TCP to
be used on systems with 16K and larger page sizes.
The RDS selftest, which previously hung on 16K pages, now passes.
Fixes: 7875e18e0996 ("RDS: Message parsing")
Signed-off-by: Greg Marsden <greg.marsden@oracle.com>
Reviewed-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/apxJjxvStibPI0AS@oracle.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/message.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/net/rds/message.c b/net/rds/message.c
index 09ee4532376b1..26ff222abafc6 100644
--- a/net/rds/message.c
+++ b/net/rds/message.c
@@ -365,7 +365,9 @@ struct rds_message *rds_message_map_pages(unsigned long *page_addrs, unsigned in
for (i = 0; i < rm->data.op_nents; ++i) {
sg_set_page(&rm->data.op_sg[i],
virt_to_page((void *)page_addrs[i]),
- PAGE_SIZE, 0);
+ i == rm->data.op_nents - 1
+ ? total_len - (i * PAGE_SIZE)
+ : PAGE_SIZE, 0);
}
return rm;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 487/982] openvswitch: fix wrong flag value in get_ipv6_ext_hdrs()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (485 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 486/982] net/rds: fix tcp stream corruption with large pages Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 488/982] sunvdc: unmap LDC cookies when the descriptor send fails Greg Kroah-Hartman
` (501 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paolo Abeni, Aaron Conole,
Ilya Maximets, Eelco Chaudron, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eelco Chaudron <echaudro@redhat.com>
[ Upstream commit e184a4a6f423550a25adce867036cdb1ff471745 ]
The ESP and AH cases in get_ipv6_ext_hdrs() used IPPROTO_FRAGMENT instead
of OFPIEH12_FRAG when checking for out-of-order extension headers, causing
the fragment header to not be recognised as a valid predecessor.
The original code used IPPROTO_FRAGMENT (44) as a bitmask constant where
OFPIEH12_FRAG (1 << 4 = 16) was intended. IPPROTO_FRAGMENT encodes bits
2, 3 and 5 (OFPIEH12_AUTH | OFPIEH12_DEST | OFPIEH12_ROUTER), but not
bit 4 (OFPIEH12_FRAG). This caused incorrect OFPIEH12_UNSEQ verdicts in
both the ESP and AH arms: the ESP arm failed to whitelist OFPIEH12_FRAG,
while the AH arm accidentally whitelisted OFPIEH12_AUTH.
With the fix, a packet with two AH headers now also gets OFPIEH12_UNSEQ
in addition to OFPIEH12_UNREP, matching the ESP arm which already sets
UNSEQ on a repeat, which is the intended behavior.
Fixes: 28a3f0601727 ("net: openvswitch: IPv6: Add IPv6 extension header support")
Reported-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Signed-off-by: Eelco Chaudron <echaudro@redhat.com>
Link: https://patch.msgid.link/1b1582eb07550d71f3cbe210e5cb31eeb8d0ad86.1788876917.git.echaudro@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/openvswitch/flow.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/openvswitch/flow.c b/net/openvswitch/flow.c
index 3111817293aa0..bfb96f0876900 100644
--- a/net/openvswitch/flow.c
+++ b/net/openvswitch/flow.c
@@ -289,7 +289,7 @@ static void get_ipv6_ext_hdrs(struct sk_buff *skb, struct ipv6hdr *nh,
if (*ext_hdrs & OFPIEH12_ESP)
*ext_hdrs |= OFPIEH12_UNREP;
if ((*ext_hdrs & ~(OFPIEH12_HOP | OFPIEH12_DEST |
- OFPIEH12_ROUTER | IPPROTO_FRAGMENT |
+ OFPIEH12_ROUTER | OFPIEH12_FRAG |
OFPIEH12_AUTH | OFPIEH12_UNREP)) ||
dest_options_header_count >= 2) {
*ext_hdrs |= OFPIEH12_UNSEQ;
@@ -302,7 +302,7 @@ static void get_ipv6_ext_hdrs(struct sk_buff *skb, struct ipv6hdr *nh,
*ext_hdrs |= OFPIEH12_UNREP;
if ((*ext_hdrs &
~(OFPIEH12_HOP | OFPIEH12_DEST | OFPIEH12_ROUTER |
- IPPROTO_FRAGMENT | OFPIEH12_UNREP)) ||
+ OFPIEH12_FRAG | OFPIEH12_UNREP)) ||
dest_options_header_count >= 2) {
*ext_hdrs |= OFPIEH12_UNSEQ;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 488/982] sunvdc: unmap LDC cookies when the descriptor send fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (486 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 487/982] openvswitch: fix wrong flag value in get_ipv6_ext_hdrs() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 489/982] drm/amd/display: set new_stream to NULL after release Greg Kroah-Hartman
` (500 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Stian Halseth, Jens Axboe, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stian Halseth <stian@itx.no>
[ Upstream commit 0c6da21fa35e03fc74f09895433ccd6d4a9c3530 ]
__send_request() maps the request's pages into the LDC channel's map
table (ldc_map_sg()), fills in the descriptor and marks it
VIO_DESC_READY before ringing the doorbell via __vdc_tx_trigger().
When the trigger fails, the error path only prints a message: the
descriptor stays READY and the cookies are never unmapped. The
mapping is normally released in vdc_end_one() when the peer completes
the descriptor - but a descriptor whose doorbell was never sent will
never complete, and since dr->prod is not advanced on failure, the
reset path (vdc_requeue_inflight(), which walks [cons, prod)) never
visits it either. The map table entries are leaked permanently.
Since commit a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop
when vio_ldc_send() returns EAGAIN") trigger failures occur in
practice under load, so every resulting I/O error also leaks one
request's worth of entries from the fixed-size (8192 entries per
channel) map table. Because the allocator hands out contiguous
ranges, fragmentation makes large multi-segment requests fail first
as the table drains, until ldc_map_sg() fails permanently and the
disk is dead until reboot.
It also makes any retry-based recovery unusable: requeuing the
request on -EAGAIN remaps the pages on every attempt, overwriting
desc->cookies and orphaning the previous mapping, so the table
drains at the retry rate. This is the memory exhaustion observed
when the requeue approach was first tested in October 2025.
Roll back on failure: unmap the cookies, mark the descriptor FREE
again and clear the request entry. If the trigger failed with
-ENOTCONN, __vdc_tx_trigger() has already reset the port, which
tears down and reallocates both the dring and the LDC channel
including its map table - nothing to roll back, and the stale
descriptor must not be touched.
Fixes: a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN")
Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://github.com/sparclinux/issues/issues/2
Signed-off-by: Stian Halseth <stian@itx.no>
Link: https://patch.msgid.link/20260901173947.3292110-2-stian@itx.no
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/sunvdc.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/block/sunvdc.c b/drivers/block/sunvdc.c
index afdf3119e119d..f03bf77da8c4d 100644
--- a/drivers/block/sunvdc.c
+++ b/drivers/block/sunvdc.c
@@ -526,6 +526,23 @@ static int __send_request(struct request *req)
err = __vdc_tx_trigger(port);
if (err < 0) {
printk(KERN_ERR PFX "vdc_tx_trigger() failure, err=%d\n", err);
+ /*
+ * If the port was reset (-ENOTCONN), the dring and the
+ * LDC channel including all of its mappings are already
+ * torn down and reallocated - there is nothing to undo
+ * and @desc must not be touched.
+ *
+ * For any other failure the descriptor was never handed
+ * to the peer: unmap the cookies and free the descriptor
+ * again, so that a later retry of the request does not
+ * leak LDC map table entries.
+ */
+ if (err != -ENOTCONN) {
+ ldc_unmap(port->vio.lp, desc->cookies,
+ desc->ncookies);
+ desc->hdr.state = VIO_DESC_FREE;
+ rqe->req = NULL;
+ }
} else {
port->req_id++;
dr->prod = vio_dring_next(dr, dr->prod);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 489/982] drm/amd/display: set new_stream to NULL after release
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (487 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 488/982] sunvdc: unmap LDC cookies when the descriptor send fails Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 490/982] scsi: target: iscsi: Handle abort for WRITE_PENDING cmds Greg Kroah-Hartman
` (499 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, WenTao Liang, George Zhang,
Alex Deucher, Roman Demidov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: WenTao Liang <vulab@iscas.ac.cn>
commit 9fa26b9eed6195bf840f39ac183b9a6237548755 upstream.
In dm_update_crtc_state(), the skip_modeset path releases new_stream
via dc_stream_release() but does not set the pointer to NULL.
If a later error (e.g., color management failure) triggers the fail
label, the error path calls dc_stream_release() again on the same
dangling pointer, causing a double release and potential use-after-free.
Fix this by setting new_stream to NULL after the initial release.
Fixes: 9b690ef3c704 ("drm/amd/display: Avoid full modeset when not required")
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
Reviewed-by: George Zhang <george.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index bb5e3a6086f2e..deaf98957cb76 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -9293,6 +9293,7 @@ static int dm_update_crtc_state(struct amdgpu_display_manager *dm,
/* Release extra reference */
if (new_stream)
dc_stream_release(new_stream);
+ new_stream = NULL;
/*
* We want to do dc stream updates that do not require a
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 490/982] scsi: target: iscsi: Handle abort for WRITE_PENDING cmds
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (488 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 489/982] drm/amd/display: set new_stream to NULL after release Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 491/982] scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands Greg Kroah-Hartman
` (498 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Bogdanov, Mike Christie,
Martin K. Petersen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Bogdanov <d.bogdanov@yadro.com>
[ Upstream commit ea87981a0ee8fb8ced1c87d004a541b60623ff97 ]
Sometimes an initiator does not send data for a WRITE command and tries to
abort it. The abort hangs waiting for frontend driver completion. iSCSI
driver waits for data and that timeout eventually initiates connection
reinstatment. The connection closing releases the commands in the
connection, but those aborted commands still did not handle the abort and
did not decrease a command ref counter. Because of that the connection
reinstatement hangs indefinitely and prevents re-login for that initiator.
Add handling in TCM of the abort for the WRITE_PENDING commands at
connection closing moment to make it possible to release them.
Signed-off-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
[mnc: Rebase and expand comment]
Signed-off-by: Mike Christie <michael.christie@oracle.com>
Link: https://lore.kernel.org/r/20230319015620.96006-10-michael.christie@oracle.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/target/iscsi/iscsi_target.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/target/iscsi/iscsi_target.c b/drivers/target/iscsi/iscsi_target.c
index 0e16a29e8ef67..8806be03c304f 100644
--- a/drivers/target/iscsi/iscsi_target.c
+++ b/drivers/target/iscsi/iscsi_target.c
@@ -26,6 +26,7 @@
#include <target/target_core_base.h>
#include <target/target_core_fabric.h>
+#include <target/target_core_backend.h>
#include <target/iscsi/iscsi_target_core.h>
#include "iscsi_target_parameters.h"
#include "iscsi_target_seq_pdu_list.h"
@@ -4238,6 +4239,16 @@ static void iscsit_release_commands_from_conn(struct iscsit_conn *conn)
} else {
se_cmd->transport_state |= CMD_T_FABRIC_STOP;
}
+
+ if (cmd->se_cmd.t_state == TRANSPORT_WRITE_PENDING) {
+ /*
+ * We never submitted the cmd to LIO core, so we have
+ * to tell LIO to perform the completion process.
+ */
+ spin_unlock_irq(&se_cmd->t_state_lock);
+ target_complete_cmd(&cmd->se_cmd, SAM_STAT_TASK_ABORTED);
+ continue;
+ }
spin_unlock_irq(&se_cmd->t_state_lock);
}
spin_unlock_bh(&conn->cmd_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 491/982] scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (489 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 490/982] scsi: target: iscsi: Handle abort for WRITE_PENDING cmds Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 492/982] ksmbd: prevent out-of-bounds reads in share config responses Greg Kroah-Hartman
` (497 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maurizio Lombardi, Laurence Oberman,
Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maurizio Lombardi <mlombard@redhat.com>
[ Upstream commit d5869dae5080e976d4b03cc33eb7ceb527f242bf ]
When a LUN_RESET aborts a WRITE command that is in the
TRANSPORT_WRITE_PENDING state, the target core sets CMD_T_ABORTED and
waits for the frontend to finish processing.
If the initiator subsequently sends the remaining dataout PDUs,
__iscsit_check_dataout_hdr() catches the payload, stops the dataout
timer if the sequence is final and finally dumps the data. However, the
iSCSI target doesn't trigger the completion process for these aborted
commands. Because of this, the abort path hangs indefinitely in
target_put_cmd_and_wait(), leading to a deadlocked target worker thread.
Fix this by explicitly calling target_complete_cmd() when the final
dataout PDU is received for an aborted WRITE command.
target_complete_cmd() detects the CMD_T_ABORTED flag and cleanly routes
the command into target_abort_work, allowing the abort completion to
successfully unblock.
Signed-off-by: Maurizio Lombardi <mlombard@redhat.com>
Reviewed-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260717143828.76291-2-mlombard@redhat.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/target/iscsi/iscsi_target.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/target/iscsi/iscsi_target.c b/drivers/target/iscsi/iscsi_target.c
index 8806be03c304f..fea642ab87779 100644
--- a/drivers/target/iscsi/iscsi_target.c
+++ b/drivers/target/iscsi/iscsi_target.c
@@ -1569,8 +1569,10 @@ __iscsit_check_dataout_hdr(struct iscsit_conn *conn, void *buf,
*/
if (se_cmd->transport_state & CMD_T_ABORTED) {
if (hdr->flags & ISCSI_FLAG_CMD_FINAL &&
- --cmd->outstanding_r2ts < 1)
+ --cmd->outstanding_r2ts < 1) {
iscsit_stop_dataout_timer(cmd);
+ target_complete_cmd(se_cmd, SAM_STAT_TASK_ABORTED);
+ }
return iscsit_dump_data_payload(conn, payload_length, 1);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 492/982] ksmbd: prevent out-of-bounds reads in share config responses
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (490 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 491/982] scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 493/982] net: dst: add four helpers to annotate data-races around dst->dev Greg Kroah-Hartman
` (496 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kanishka De Silva, Farhad Alemi,
Namjae Jeon, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit f25e93768fcc5d8287e50b1ec52a42e4c276df34 ]
Validate IPC share configuration payload sizes before consuming
variable-length fields. Bound veto list parsing and account for
the separator byte when deriving the path length.
Fixes: a677ebd8ca2f ("ksmbd: validate payload size in ipc response")
Reported-by: Kanishka De Silva <kpskanna1915@gmail.com>
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/mgmt/share_config.c | 38 +++++++++++++++++++++++--------
fs/smb/server/transport_ipc.c | 24 ++++++++++++++-----
2 files changed, 46 insertions(+), 16 deletions(-)
diff --git a/fs/smb/server/mgmt/share_config.c b/fs/smb/server/mgmt/share_config.c
index d8d03070ae44b..7db7345f1af94 100644
--- a/fs/smb/server/mgmt/share_config.c
+++ b/fs/smb/server/mgmt/share_config.c
@@ -88,9 +88,9 @@ static struct ksmbd_share_config *__share_lookup(const char *name)
static int parse_veto_list(struct ksmbd_share_config *share,
char *veto_list,
- int veto_list_sz)
+ size_t veto_list_sz)
{
- int sz = 0;
+ size_t sz;
if (!veto_list_sz)
return 0;
@@ -98,7 +98,7 @@ static int parse_veto_list(struct ksmbd_share_config *share,
while (veto_list_sz > 0) {
struct ksmbd_veto_pattern *p;
- sz = strlen(veto_list);
+ sz = strnlen(veto_list, veto_list_sz);
if (!sz)
break;
@@ -106,7 +106,7 @@ static int parse_veto_list(struct ksmbd_share_config *share,
if (!p)
return -ENOMEM;
- p->pattern = kstrdup(veto_list, GFP_KERNEL);
+ p->pattern = kstrndup(veto_list, sz, GFP_KERNEL);
if (!p->pattern) {
kfree(p);
return -ENOMEM;
@@ -114,6 +114,9 @@ static int parse_veto_list(struct ksmbd_share_config *share,
list_add(&p->list, &share->veto_list);
+ if (sz == veto_list_sz)
+ break;
+
veto_list += sz + 1;
veto_list_sz -= (sz + 1);
}
@@ -160,13 +163,27 @@ static struct ksmbd_share_config *share_config_request(struct ksmbd_work *work,
share->name = kstrdup(name, GFP_KERNEL);
if (!test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) {
- int path_len = PATH_MAX;
+ size_t path_len;
- if (resp->payload_sz)
+ if (resp->payload_sz <= resp->veto_list_sz) {
+ ret = -EINVAL;
+ } else {
path_len = resp->payload_sz - resp->veto_list_sz;
-
- share->path = kstrndup(ksmbd_share_config_path(resp), path_len,
- GFP_KERNEL);
+ if (resp->veto_list_sz)
+ path_len--;
+
+ if (!path_len) {
+ ret = -EINVAL;
+ } else {
+ share->path = kstrndup(
+ ksmbd_share_config_path(resp),
+ path_len, GFP_KERNEL);
+ if (!share->path)
+ ret = -ENOMEM;
+ else
+ ret = 0;
+ }
+ }
if (share->path) {
share->path_sz = strlen(share->path);
while (share->path_sz > 1 &&
@@ -179,7 +196,8 @@ static struct ksmbd_share_config *share_config_request(struct ksmbd_work *work,
share->force_directory_mode = resp->force_directory_mode;
share->force_uid = resp->force_uid;
share->force_gid = resp->force_gid;
- ret = parse_veto_list(share,
+ if (!ret)
+ ret = parse_veto_list(share,
KSMBD_SHARE_CONFIG_VETO_LIST(resp),
resp->veto_list_sz);
if (!ret && share->path) {
diff --git a/fs/smb/server/transport_ipc.c b/fs/smb/server/transport_ipc.c
index ed423d0ca99d6..89fae5e1886ae 100644
--- a/fs/smb/server/transport_ipc.c
+++ b/fs/smb/server/transport_ipc.c
@@ -487,13 +487,25 @@ static int ipc_validate_msg(struct ipc_msg_table_entry *entry)
} else if (entry->type == KSMBD_EVENT_SHARE_CONFIG_REQUEST) {
struct ksmbd_share_config_response *resp = entry->response;
- if (resp->payload_sz) {
- if (resp->payload_sz < resp->veto_list_sz)
- return -EINVAL;
+ if (entry->msg_sz < sizeof(struct ksmbd_share_config_response))
+ return -EINVAL;
+
+ if (strnlen(resp->share_name, sizeof(resp->share_name)) ==
+ sizeof(resp->share_name))
+ return -EINVAL;
+
+ if (resp->veto_list_sz > resp->payload_sz)
+ return -EINVAL;
+
+ if (resp->flags != KSMBD_SHARE_FLAG_INVALID &&
+ !(resp->flags & KSMBD_SHARE_FLAG_PIPE) &&
+ resp->payload_sz <= resp->veto_list_sz)
+ return -EINVAL;
+
+ if (check_add_overflow(sizeof(struct ksmbd_share_config_response),
+ resp->payload_sz, &msg_sz))
+ return -EINVAL;
- msg_sz = sizeof(struct ksmbd_share_config_response) +
- resp->payload_sz;
- }
}
return entry->msg_sz != msg_sz ? -EINVAL : 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 493/982] net: dst: add four helpers to annotate data-races around dst->dev
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (491 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 492/982] ksmbd: prevent out-of-bounds reads in share config responses Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 494/982] ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] Greg Kroah-Hartman
` (495 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Kuniyuki Iwashima,
Jakub Kicinski, Miguel Gazquez, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 88fe14253e181878c2ddb51a298ae8c468a63010 ]
dst->dev is read locklessly in many contexts,
and written in dst_dev_put().
Fixing all the races is going to need many changes.
We probably will have to add full RCU protection.
Add three helpers to ease this painful process.
static inline struct net_device *dst_dev(const struct dst_entry *dst)
{
return READ_ONCE(dst->dev);
}
static inline struct net_device *skb_dst_dev(const struct sk_buff *skb)
{
return dst_dev(skb_dst(skb));
}
static inline struct net *skb_dst_dev_net(const struct sk_buff *skb)
{
return dev_net(skb_dst_dev(skb));
}
static inline struct net *skb_dst_dev_net_rcu(const struct sk_buff *skb)
{
return dev_net_rcu(skb_dst_dev(skb));
}
Fixes: 4a6ce2b6f2ec ("net: introduce a new function dst_dev_put()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250630121934.3399505-7-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ minor modifications to fix conflict ]
Signed-off-by: Miguel Gazquez <miguel.gazquez@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/dst.h | 20 ++++++++++++++++++++
net/core/dst.c | 4 ++--
net/core/sock.c | 6 +++---
3 files changed, 25 insertions(+), 5 deletions(-)
diff --git a/include/net/dst.h b/include/net/dst.h
index 20a76e532afbb..7c0cf856154de 100644
--- a/include/net/dst.h
+++ b/include/net/dst.h
@@ -555,6 +555,11 @@ static inline void skb_dst_update_pmtu_no_confirm(struct sk_buff *skb, u32 mtu)
dst->ops->update_pmtu(dst, NULL, skb, mtu, false);
}
+static inline struct net_device *dst_dev(const struct dst_entry *dst)
+{
+ return READ_ONCE(dst->dev);
+}
+
static inline struct net_device *dst_dev_rcu(const struct dst_entry *dst)
{
/* In the future, use rcu_dereference(dst->dev) */
@@ -562,11 +567,26 @@ static inline struct net_device *dst_dev_rcu(const struct dst_entry *dst)
return READ_ONCE(dst->dev);
}
+static inline struct net_device *skb_dst_dev(const struct sk_buff *skb)
+{
+ return dst_dev(skb_dst(skb));
+}
+
static inline struct net_device *skb_dst_dev_rcu(const struct sk_buff *skb)
{
return dst_dev_rcu(skb_dst(skb));
}
+static inline struct net *skb_dst_dev_net(const struct sk_buff *skb)
+{
+ return dev_net(skb_dst_dev(skb));
+}
+
+static inline struct net *skb_dst_dev_net_rcu(const struct sk_buff *skb)
+{
+ return dev_net_rcu(skb_dst_dev(skb));
+}
+
struct dst_entry *dst_blackhole_check(struct dst_entry *dst, u32 cookie);
void dst_blackhole_update_pmtu(struct dst_entry *dst, struct sock *sk,
struct sk_buff *skb, u32 mtu, bool confirm_neigh);
diff --git a/net/core/dst.c b/net/core/dst.c
index 8db87258d1450..24a1cc3d2a084 100644
--- a/net/core/dst.c
+++ b/net/core/dst.c
@@ -151,7 +151,7 @@ void dst_dev_put(struct dst_entry *dst)
dst->ops->ifdown(dst, dev, true);
dst->input = dst_discard;
dst->output = dst_discard_out;
- dst->dev = blackhole_netdev;
+ WRITE_ONCE(dst->dev, blackhole_netdev);
netdev_ref_replace(dev, blackhole_netdev, &dst->dev_tracker,
GFP_ATOMIC);
}
@@ -272,7 +272,7 @@ unsigned int dst_blackhole_mtu(const struct dst_entry *dst)
{
unsigned int mtu = dst_metric_raw(dst, RTAX_MTU);
- return mtu ? : dst->dev->mtu;
+ return mtu ? : dst_dev(dst)->mtu;
}
EXPORT_SYMBOL_GPL(dst_blackhole_mtu);
diff --git a/net/core/sock.c b/net/core/sock.c
index 2a701e0b052b7..64f9d77bfaec7 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -2397,7 +2397,7 @@ void sk_setup_caps(struct sock *sk, struct dst_entry *dst)
{
u32 max_segs = 1;
- sk->sk_route_caps = dst->dev->features;
+ sk->sk_route_caps = dst_dev(dst)->features;
if (sk_is_tcp(sk))
sk->sk_route_caps |= NETIF_F_GSO;
if (sk->sk_route_caps & NETIF_F_GSO)
@@ -2410,11 +2410,11 @@ void sk_setup_caps(struct sock *sk, struct dst_entry *dst)
} else {
sk->sk_route_caps |= NETIF_F_SG | NETIF_F_HW_CSUM;
/* pairs with the WRITE_ONCE() in netif_set_gso_max_size() */
- sk->sk_gso_max_size = READ_ONCE(dst->dev->gso_max_size);
+ sk->sk_gso_max_size = READ_ONCE(dst_dev(dst)->gso_max_size);
sk_trim_gso_size(sk);
sk->sk_gso_max_size -= (MAX_TCP_HEADER + 1);
/* pairs with the WRITE_ONCE() in netif_set_gso_max_segs() */
- max_segs = max_t(u32, READ_ONCE(dst->dev->gso_max_segs), 1);
+ max_segs = max_t(u32, READ_ONCE(dst_dev(dst)->gso_max_segs), 1);
}
}
sk->sk_gso_max_segs = max_segs;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 494/982] ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu]
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (492 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 493/982] net: dst: add four helpers to annotate data-races around dst->dev Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 495/982] net: dst: introduce dst->dev_rcu Greg Kroah-Hartman
` (494 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Kuniyuki Iwashima,
Jakub Kicinski, Miguel Gazquez, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit a74fc62eec155ca5a6da8ff3856f3dc87fe24558 ]
Use the new helpers as a first step to deal with
potential dst->dev races.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250630121934.3399505-8-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ minor modifications to fix conflict ]
Signed-off-by: Miguel Gazquez <miguel.gazquez@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/inet_hashtables.h | 2 +-
include/net/ip.h | 11 ++++++-----
include/net/route.h | 2 +-
net/ipv4/icmp.c | 24 +++++++++++++-----------
net/ipv4/igmp.c | 2 +-
net/ipv4/ip_fragment.c | 2 +-
net/ipv4/ip_output.c | 4 ++--
net/ipv4/ip_vti.c | 4 ++--
net/ipv4/netfilter.c | 4 ++--
net/ipv4/route.c | 8 ++++----
net/ipv4/tcp_fastopen.c | 4 +++-
net/ipv4/tcp_ipv4.c | 3 ++-
net/ipv4/tcp_metrics.c | 8 ++++----
net/ipv4/xfrm4_output.c | 2 +-
14 files changed, 43 insertions(+), 37 deletions(-)
diff --git a/include/net/inet_hashtables.h b/include/net/inet_hashtables.h
index ce58cf10ecb43..ac85405308c9c 100644
--- a/include/net/inet_hashtables.h
+++ b/include/net/inet_hashtables.h
@@ -470,7 +470,7 @@ static inline struct sock *__inet_lookup_skb(struct inet_hashinfo *hashinfo,
if (sk)
return sk;
- return __inet_lookup(dev_net(skb_dst(skb)->dev), hashinfo, skb,
+ return __inet_lookup(skb_dst_dev_net(skb), hashinfo, skb,
doff, iph->saddr, sport,
iph->daddr, dport, inet_iif(skb), sdif,
refcounted);
diff --git a/include/net/ip.h b/include/net/ip.h
index 05ce8b38e3dab..414772ca7bb77 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -452,7 +452,7 @@ static inline unsigned int ip_dst_mtu_maybe_forward(const struct dst_entry *dst,
bool forwarding)
{
const struct rtable *rt = container_of(dst, struct rtable, dst);
- struct net *net = dev_net(dst->dev);
+ struct net *net = dev_net(dst_dev(dst));
unsigned int mtu;
if (READ_ONCE(net->ipv4.sysctl_ip_fwd_use_pmtu) ||
@@ -468,7 +468,7 @@ static inline unsigned int ip_dst_mtu_maybe_forward(const struct dst_entry *dst,
if (mtu)
goto out;
- mtu = READ_ONCE(dst->dev->mtu);
+ mtu = READ_ONCE(dst_dev(dst)->mtu);
if (unlikely(ip_mtu_locked(dst))) {
if (rt->rt_uses_gateway && mtu > 576)
@@ -484,16 +484,17 @@ static inline unsigned int ip_dst_mtu_maybe_forward(const struct dst_entry *dst,
static inline unsigned int ip_skb_dst_mtu(struct sock *sk,
const struct sk_buff *skb)
{
+ const struct dst_entry *dst = skb_dst(skb);
unsigned int mtu;
if (!sk || !sk_fullsock(sk) || ip_sk_use_pmtu(sk)) {
bool forwarding = IPCB(skb)->flags & IPSKB_FORWARDED;
- return ip_dst_mtu_maybe_forward(skb_dst(skb), forwarding);
+ return ip_dst_mtu_maybe_forward(dst, forwarding);
}
- mtu = min(READ_ONCE(skb_dst(skb)->dev->mtu), IP_MAX_MTU);
- return mtu - lwtunnel_headroom(skb_dst(skb)->lwtstate, mtu);
+ mtu = min(READ_ONCE(dst_dev(dst)->mtu), IP_MAX_MTU);
+ return mtu - lwtunnel_headroom(dst->lwtstate, mtu);
}
struct dst_metrics *ip_fib_metrics_init(struct net *net, struct nlattr *fc_mx,
diff --git a/include/net/route.h b/include/net/route.h
index 4fa45dda2bb32..ce608f8830401 100644
--- a/include/net/route.h
+++ b/include/net/route.h
@@ -362,7 +362,7 @@ static inline int ip4_dst_hoplimit(const struct dst_entry *dst)
const struct net *net;
rcu_read_lock();
- net = dev_net_rcu(dst->dev);
+ net = dev_net_rcu(dst_dev(dst));
hoplimit = READ_ONCE(net->ipv4.sysctl_ip_default_ttl);
rcu_read_unlock();
}
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
index 7c4c7b7fe3846..f0c8c3366740a 100644
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -313,18 +313,20 @@ static bool icmpv4_xrlim_allow(struct net *net, struct rtable *rt,
{
struct dst_entry *dst = &rt->dst;
struct inet_peer *peer;
+ struct net_device *dev;
bool rc = true;
if (!apply_ratelimit)
return true;
/* No rate limit on loopback */
- if (dst->dev && (dst->dev->flags&IFF_LOOPBACK))
+ dev = dst_dev(dst);
+ if (dev && (dev->flags & IFF_LOOPBACK))
goto out;
rcu_read_lock();
peer = inet_getpeer_v4(net->ipv4.peers, fl4->daddr,
- l3mdev_master_ifindex_rcu(dst->dev));
+ l3mdev_master_ifindex_rcu(dev));
rc = inet_peer_xrlim_allow(peer,
READ_ONCE(net->ipv4.sysctl_icmp_ratelimit));
rcu_read_unlock();
@@ -472,13 +474,13 @@ static void icmp_reply(struct icmp_bxm *icmp_param, struct sk_buff *skb)
*/
static struct net_device *icmp_get_route_lookup_dev(struct sk_buff *skb)
{
- struct net_device *route_lookup_dev = NULL;
+ struct net_device *dev = skb->dev;
+ const struct dst_entry *dst;
- if (skb->dev)
- route_lookup_dev = skb->dev;
- else if (skb_dst(skb))
- route_lookup_dev = skb_dst(skb)->dev;
- return route_lookup_dev;
+ if (dev)
+ return dev;
+ dst = skb_dst(skb);
+ return dst ? dst_dev(dst) : NULL;
}
static struct rtable *icmp_route_lookup(struct net *net, struct flowi4 *fl4,
@@ -911,7 +913,7 @@ static enum skb_drop_reason icmp_unreach(struct sk_buff *skb)
struct net *net;
u32 info = 0;
- net = dev_net_rcu(skb_dst(skb)->dev);
+ net = skb_dst_dev_net_rcu(skb);
/*
* Incomplete header ?
@@ -1054,7 +1056,7 @@ static enum skb_drop_reason icmp_echo(struct sk_buff *skb)
struct icmp_bxm icmp_param;
struct net *net;
- net = dev_net_rcu(skb_dst(skb)->dev);
+ net = skb_dst_dev_net_rcu(skb);
/* should there be an ICMP stat for ignored echos? */
if (READ_ONCE(net->ipv4.sysctl_icmp_echo_ignore_all))
return SKB_NOT_DROPPED_YET;
@@ -1231,7 +1233,7 @@ static enum skb_drop_reason icmp_timestamp(struct sk_buff *skb)
return SKB_NOT_DROPPED_YET;
out_err:
- __ICMP_INC_STATS(dev_net_rcu(skb_dst(skb)->dev), ICMP_MIB_INERRORS);
+ __ICMP_INC_STATS(skb_dst_dev_net_rcu(skb), ICMP_MIB_INERRORS);
return SKB_DROP_REASON_PKT_TOO_SMALL;
}
diff --git a/net/ipv4/igmp.c b/net/ipv4/igmp.c
index ede991885b1f8..1b8adf5fbf8a4 100644
--- a/net/ipv4/igmp.c
+++ b/net/ipv4/igmp.c
@@ -428,7 +428,7 @@ static int igmpv3_sendpack(struct sk_buff *skb)
pig->csum = ip_compute_csum(igmp_hdr(skb), igmplen);
- return ip_local_out(dev_net(skb_dst(skb)->dev), skb->sk, skb);
+ return ip_local_out(skb_dst_dev_net(skb), skb->sk, skb);
}
static int grec_size(struct ip_mc_list *pmc, int type, int gdel, int sdel)
diff --git a/net/ipv4/ip_fragment.c b/net/ipv4/ip_fragment.c
index 0ed999fdca2d7..a70ede523297c 100644
--- a/net/ipv4/ip_fragment.c
+++ b/net/ipv4/ip_fragment.c
@@ -481,7 +481,7 @@ static int ip_frag_reasm(struct ipq *qp, struct sk_buff *skb,
/* Process an incoming IP datagram fragment. */
int ip_defrag(struct net *net, struct sk_buff *skb, u32 user)
{
- struct net_device *dev = skb->dev ? : skb_dst(skb)->dev;
+ struct net_device *dev = skb->dev ? : skb_dst_dev(skb);
int vif = l3mdev_master_ifindex_rcu(dev);
struct ipq *qp;
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index 6fd7995ff8dd1..707c634c0305a 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -113,7 +113,7 @@ int __ip_local_out(struct net *net, struct sock *sk, struct sk_buff *skb)
skb->protocol = htons(ETH_P_IP);
return nf_hook(NFPROTO_IPV4, NF_INET_LOCAL_OUT,
- net, sk, skb, NULL, skb_dst(skb)->dev,
+ net, sk, skb, NULL, skb_dst_dev(skb),
dst_output);
}
@@ -195,7 +195,7 @@ static int ip_finish_output2(struct net *net, struct sock *sk, struct sk_buff *s
{
struct dst_entry *dst = skb_dst(skb);
struct rtable *rt = (struct rtable *)dst;
- struct net_device *dev = dst->dev;
+ struct net_device *dev = dst_dev(dst);
unsigned int hh_len = LL_RESERVED_SPACE(dev);
struct neighbour *neigh;
bool is_v6gw = false;
diff --git a/net/ipv4/ip_vti.c b/net/ipv4/ip_vti.c
index 7daf01af6295a..2e07592d8b966 100644
--- a/net/ipv4/ip_vti.c
+++ b/net/ipv4/ip_vti.c
@@ -226,7 +226,7 @@ static netdev_tx_t vti_xmit(struct sk_buff *skb, struct net_device *dev,
goto tx_error_icmp;
}
- tdev = dst->dev;
+ tdev = dst_dev(dst);
if (tdev == dev) {
dst_release(dst);
@@ -256,7 +256,7 @@ static netdev_tx_t vti_xmit(struct sk_buff *skb, struct net_device *dev,
xmit:
skb_scrub_packet(skb, !net_eq(tunnel->net, dev_net(dev)));
skb_dst_set(skb, dst);
- skb->dev = skb_dst(skb)->dev;
+ skb->dev = skb_dst_dev(skb);
err = dst_output(tunnel->net, skb->sk, skb);
if (net_xmit_eval(err) == 0)
diff --git a/net/ipv4/netfilter.c b/net/ipv4/netfilter.c
index bd135165482aa..c450509d6efde 100644
--- a/net/ipv4/netfilter.c
+++ b/net/ipv4/netfilter.c
@@ -19,12 +19,12 @@
/* route_me_harder function, used by iptable_nat, iptable_mangle + ip_queue */
int ip_route_me_harder(struct net *net, struct sock *sk, struct sk_buff *skb, unsigned int addr_type)
{
+ struct net_device *dev = skb_dst_dev(skb);
const struct iphdr *iph = ip_hdr(skb);
struct rtable *rt;
struct flowi4 fl4 = {};
__be32 saddr = iph->saddr;
__u8 flags;
- struct net_device *dev = skb_dst(skb)->dev;
struct flow_keys flkeys;
unsigned int hh_len;
@@ -73,7 +73,7 @@ int ip_route_me_harder(struct net *net, struct sock *sk, struct sk_buff *skb, un
#endif
/* Change in oif may mean change in hh_len. */
- hh_len = skb_dst(skb)->dev->hard_header_len;
+ hh_len = skb_dst_dev(skb)->hard_header_len;
if (skb_headroom(skb) < hh_len &&
pskb_expand_head(skb, HH_DATA_ALIGN(hh_len - skb_headroom(skb)),
0, GFP_ATOMIC))
diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 783460ebfc471..a2985265c7929 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -416,7 +416,7 @@ static struct neighbour *ipv4_neigh_lookup(const struct dst_entry *dst,
const void *daddr)
{
const struct rtable *rt = container_of(dst, struct rtable, dst);
- struct net_device *dev = dst->dev;
+ struct net_device *dev = dst_dev(dst);
struct neighbour *n;
rcu_read_lock();
@@ -443,7 +443,7 @@ static struct neighbour *ipv4_neigh_lookup(const struct dst_entry *dst,
static void ipv4_confirm_neigh(const struct dst_entry *dst, const void *daddr)
{
const struct rtable *rt = container_of(dst, struct rtable, dst);
- struct net_device *dev = dst->dev;
+ struct net_device *dev = dst_dev(dst);
const __be32 *pkey = daddr;
if (rt->rt_gw_family == AF_INET) {
@@ -1069,7 +1069,7 @@ static void __ip_rt_update_pmtu(struct rtable *rt, struct flowi4 *fl4, u32 mtu)
return;
rcu_read_lock();
- net = dev_net_rcu(dst->dev);
+ net = dev_net_rcu(dst_dev(dst));
if (mtu < net->ipv4.ip_rt_min_pmtu) {
lock = true;
mtu = min(old_mtu, net->ipv4.ip_rt_min_pmtu);
@@ -1367,7 +1367,7 @@ static unsigned int ipv4_default_advmss(const struct dst_entry *dst)
struct net *net;
rcu_read_lock();
- net = dev_net_rcu(dst->dev);
+ net = dev_net_rcu(dst_dev(dst));
advmss = max_t(unsigned int, ipv4_mtu(dst) - header_size,
net->ipv4.ip_rt_min_advmss);
rcu_read_unlock();
diff --git a/net/ipv4/tcp_fastopen.c b/net/ipv4/tcp_fastopen.c
index c99f10786c1f9..156685b4ae68a 100644
--- a/net/ipv4/tcp_fastopen.c
+++ b/net/ipv4/tcp_fastopen.c
@@ -558,6 +558,7 @@ bool tcp_fastopen_active_should_disable(struct sock *sk)
void tcp_fastopen_active_disable_ofo_check(struct sock *sk)
{
struct tcp_sock *tp = tcp_sk(sk);
+ struct net_device *dev;
struct dst_entry *dst;
struct sk_buff *skb;
@@ -575,7 +576,8 @@ void tcp_fastopen_active_disable_ofo_check(struct sock *sk)
} else if (tp->syn_fastopen_ch &&
atomic_read(&sock_net(sk)->ipv4.tfo_active_disable_times)) {
dst = sk_dst_get(sk);
- if (!(dst && dst->dev && (dst->dev->flags & IFF_LOOPBACK)))
+ dev = dst ? dst_dev(dst) : NULL;
+ if (!(dev && (dev->flags & IFF_LOOPBACK)))
atomic_set(&sock_net(sk)->ipv4.tfo_active_disable_times, 0);
dst_release(dst);
}
diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
index ec3b0aa0a6260..9c5d227b749c4 100644
--- a/net/ipv4/tcp_ipv4.c
+++ b/net/ipv4/tcp_ipv4.c
@@ -733,7 +733,8 @@ static void tcp_v4_send_reset(const struct sock *sk, struct sk_buff *skb)
arg.iov[0].iov_base = (unsigned char *)&rep;
arg.iov[0].iov_len = sizeof(rep.th);
- net = sk ? sock_net(sk) : dev_net(skb_dst(skb)->dev);
+ net = sk ? sock_net(sk) : skb_dst_dev_net(skb);
+
#ifdef CONFIG_TCP_MD5SIG
rcu_read_lock();
hash_location = tcp_parse_md5sig_option(th);
diff --git a/net/ipv4/tcp_metrics.c b/net/ipv4/tcp_metrics.c
index a4e03a7a2c030..8bf1118e04c66 100644
--- a/net/ipv4/tcp_metrics.c
+++ b/net/ipv4/tcp_metrics.c
@@ -166,11 +166,11 @@ static struct tcp_metrics_block *tcpm_new(struct dst_entry *dst,
unsigned int hash)
{
struct tcp_metrics_block *tm;
- struct net *net;
bool reclaim = false;
+ struct net *net;
spin_lock_bh(&tcp_metrics_lock);
- net = dev_net(dst->dev);
+ net = dev_net(dst_dev(dst));
/* While waiting for the spin-lock the cache might have been populated
* with this entry and so we have to check again.
@@ -273,7 +273,7 @@ static struct tcp_metrics_block *__tcp_get_metrics_req(struct request_sock *req,
return NULL;
}
- net = dev_net(dst->dev);
+ net = dev_net(dst_dev(dst));
hash ^= net_hash_mix(net);
hash = hash_32(hash, tcp_metrics_hash_log);
@@ -318,7 +318,7 @@ static struct tcp_metrics_block *tcp_get_metrics(struct sock *sk,
else
return NULL;
- net = dev_net(dst->dev);
+ net = dev_net(dst_dev(dst));
hash ^= net_hash_mix(net);
hash = hash_32(hash, tcp_metrics_hash_log);
diff --git a/net/ipv4/xfrm4_output.c b/net/ipv4/xfrm4_output.c
index 3cff51ba72bb0..0ae67d537499a 100644
--- a/net/ipv4/xfrm4_output.c
+++ b/net/ipv4/xfrm4_output.c
@@ -31,7 +31,7 @@ static int __xfrm4_output(struct net *net, struct sock *sk, struct sk_buff *skb)
int xfrm4_output(struct net *net, struct sock *sk, struct sk_buff *skb)
{
return NF_HOOK_COND(NFPROTO_IPV4, NF_INET_POST_ROUTING,
- net, sk, skb, skb->dev, skb_dst(skb)->dev,
+ net, sk, skb, skb->dev, skb_dst_dev(skb),
__xfrm4_output,
!(IPCB(skb)->flags & IPSKB_REROUTED));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 495/982] net: dst: introduce dst->dev_rcu
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (493 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 494/982] ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 496/982] ipv4: start using dst_dev_rcu() Greg Kroah-Hartman
` (493 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, David Ahern,
Jakub Kicinski, Miguel Gazquez, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit caedcc5b6df1b2e2b5f39079e3369c1d4d5c5f50 ]
Followup of commit 88fe14253e18 ("net: dst: add four helpers
to annotate data-races around dst->dev").
We want to gradually add explicit RCU protection to dst->dev,
including lockdep support.
Add an union to alias dst->dev_rcu and dst->dev.
Add dst_dev_net_rcu() helper.
Fixes: 4a6ce2b6f2ec ("net: introduce a new function dst_dev_put()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20250828195823.3958522-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Miguel Gazquez <miguel.gazquez@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/dst.h | 16 +++++++++++-----
net/core/dst.c | 2 +-
net/ipv4/route.c | 4 ++--
3 files changed, 14 insertions(+), 8 deletions(-)
diff --git a/include/net/dst.h b/include/net/dst.h
index 7c0cf856154de..96dd65a941c51 100644
--- a/include/net/dst.h
+++ b/include/net/dst.h
@@ -23,7 +23,10 @@
struct sk_buff;
struct dst_entry {
- struct net_device *dev;
+ union {
+ struct net_device *dev;
+ struct net_device __rcu *dev_rcu;
+ };
struct dst_ops *ops;
unsigned long _metrics;
unsigned long expires;
@@ -562,9 +565,12 @@ static inline struct net_device *dst_dev(const struct dst_entry *dst)
static inline struct net_device *dst_dev_rcu(const struct dst_entry *dst)
{
- /* In the future, use rcu_dereference(dst->dev) */
- WARN_ON_ONCE(!rcu_read_lock_held());
- return READ_ONCE(dst->dev);
+ return rcu_dereference(dst->dev_rcu);
+}
+
+static inline struct net *dst_dev_net_rcu(const struct dst_entry *dst)
+{
+ return dev_net_rcu(dst_dev_rcu(dst));
}
static inline struct net_device *skb_dst_dev(const struct sk_buff *skb)
@@ -584,7 +590,7 @@ static inline struct net *skb_dst_dev_net(const struct sk_buff *skb)
static inline struct net *skb_dst_dev_net_rcu(const struct sk_buff *skb)
{
- return dev_net_rcu(skb_dst_dev(skb));
+ return dev_net_rcu(skb_dst_dev_rcu(skb));
}
struct dst_entry *dst_blackhole_check(struct dst_entry *dst, u32 cookie);
diff --git a/net/core/dst.c b/net/core/dst.c
index 24a1cc3d2a084..cbb6888aa32ba 100644
--- a/net/core/dst.c
+++ b/net/core/dst.c
@@ -151,7 +151,7 @@ void dst_dev_put(struct dst_entry *dst)
dst->ops->ifdown(dst, dev, true);
dst->input = dst_discard;
dst->output = dst_discard_out;
- WRITE_ONCE(dst->dev, blackhole_netdev);
+ rcu_assign_pointer(dst->dev_rcu, blackhole_netdev);
netdev_ref_replace(dev, blackhole_netdev, &dst->dev_tracker,
GFP_ATOMIC);
}
diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index a2985265c7929..e3cce307e0e9c 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -1069,7 +1069,7 @@ static void __ip_rt_update_pmtu(struct rtable *rt, struct flowi4 *fl4, u32 mtu)
return;
rcu_read_lock();
- net = dev_net_rcu(dst_dev(dst));
+ net = dst_dev_net_rcu(dst);
if (mtu < net->ipv4.ip_rt_min_pmtu) {
lock = true;
mtu = min(old_mtu, net->ipv4.ip_rt_min_pmtu);
@@ -1367,7 +1367,7 @@ static unsigned int ipv4_default_advmss(const struct dst_entry *dst)
struct net *net;
rcu_read_lock();
- net = dev_net_rcu(dst_dev(dst));
+ net = dst_dev_net_rcu(dst);
advmss = max_t(unsigned int, ipv4_mtu(dst) - header_size,
net->ipv4.ip_rt_min_advmss);
rcu_read_unlock();
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 496/982] ipv4: start using dst_dev_rcu()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (494 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 495/982] net: dst: introduce dst->dev_rcu Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 497/982] powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver Greg Kroah-Hartman
` (492 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, David Ahern,
Jakub Kicinski, Miguel Gazquez (Schneider Electric), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8 ]
Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.
Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(),
ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().
Fixes: 4a6ce2b6f2ec ("net: introduce a new function dst_dev_put()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20250828195823.3958522-9-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ minor modifications to fix conflict, added rcu_read_lock and unlock
to ip_defrag function ]
Signed-off-by: Miguel Gazquez (Schneider Electric) <miguel.gazquez@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/icmp.c | 6 +++---
net/ipv4/ip_fragment.c | 9 +++++++--
net/ipv4/ipmr.c | 2 +-
net/ipv4/route.c | 4 ++--
4 files changed, 13 insertions(+), 8 deletions(-)
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
index f0c8c3366740a..5c38af80bc14e 100644
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -320,17 +320,17 @@ static bool icmpv4_xrlim_allow(struct net *net, struct rtable *rt,
return true;
/* No rate limit on loopback */
- dev = dst_dev(dst);
+ rcu_read_lock();
+ dev = dst_dev_rcu(dst);
if (dev && (dev->flags & IFF_LOOPBACK))
goto out;
- rcu_read_lock();
peer = inet_getpeer_v4(net->ipv4.peers, fl4->daddr,
l3mdev_master_ifindex_rcu(dev));
rc = inet_peer_xrlim_allow(peer,
READ_ONCE(net->ipv4.sysctl_icmp_ratelimit));
- rcu_read_unlock();
out:
+ rcu_read_unlock();
if (!rc)
__ICMP_INC_STATS(net, ICMP_MIB_RATELIMITHOST);
else
diff --git a/net/ipv4/ip_fragment.c b/net/ipv4/ip_fragment.c
index a70ede523297c..43b1265f5ac19 100644
--- a/net/ipv4/ip_fragment.c
+++ b/net/ipv4/ip_fragment.c
@@ -481,13 +481,16 @@ static int ip_frag_reasm(struct ipq *qp, struct sk_buff *skb,
/* Process an incoming IP datagram fragment. */
int ip_defrag(struct net *net, struct sk_buff *skb, u32 user)
{
- struct net_device *dev = skb->dev ? : skb_dst_dev(skb);
- int vif = l3mdev_master_ifindex_rcu(dev);
+ struct net_device *dev;
struct ipq *qp;
+ int vif;
__IP_INC_STATS(net, IPSTATS_MIB_REASMREQDS);
/* Lookup (or create) queue header */
+ rcu_read_lock();
+ dev = skb->dev ? : skb_dst_dev_rcu(skb);
+ vif = l3mdev_master_ifindex_rcu(dev);
qp = ip_find(net, ip_hdr(skb), user, vif);
if (qp) {
int ret;
@@ -497,9 +500,11 @@ int ip_defrag(struct net *net, struct sk_buff *skb, u32 user)
ret = ip_frag_queue(qp, skb);
spin_unlock(&qp->q.lock);
+ rcu_read_unlock();
ipq_put(qp);
return ret;
}
+ rcu_read_unlock();
__IP_INC_STATS(net, IPSTATS_MIB_REASMFAILS);
kfree_skb(skb);
diff --git a/net/ipv4/ipmr.c b/net/ipv4/ipmr.c
index f64651c0dea6c..8d4f556fced2c 100644
--- a/net/ipv4/ipmr.c
+++ b/net/ipv4/ipmr.c
@@ -1879,7 +1879,7 @@ static void ipmr_queue_xmit(struct net *net, struct mr_table *mrt,
goto out_free;
}
- dev = rt->dst.dev;
+ dev = dst_dev_rcu(&rt->dst);
if (skb->len+encap > dst_mtu(&rt->dst) && (ntohs(iph->frag_off) & IP_DF)) {
/* Do not fragment multicasts. Alas, IPv4 does not
diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index e3cce307e0e9c..5528a5543df51 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -416,11 +416,11 @@ static struct neighbour *ipv4_neigh_lookup(const struct dst_entry *dst,
const void *daddr)
{
const struct rtable *rt = container_of(dst, struct rtable, dst);
- struct net_device *dev = dst_dev(dst);
+ struct net_device *dev;
struct neighbour *n;
rcu_read_lock();
-
+ dev = dst_dev_rcu(dst);
if (likely(rt->rt_gw_family == AF_INET)) {
n = ip_neigh_gw4(dev, rt->rt_gw4);
} else if (rt->rt_gw_family == AF_INET6) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 497/982] powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (495 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 496/982] ipv4: start using dst_dev_rcu() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 498/982] ipv6: fix fib6 walker UAF on seq stop Greg Kroah-Hartman
` (491 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable, Ritesh Harjani (IBM),
Shivaprasad G Bhat, Amit Machhiwal, Madhavan Srinivasan
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivaprasad G Bhat <sbhat@linux.ibm.com>
commit c5e68706527968282e49de205cc2b935823cb88a upstream.
The commit 1010b4c012b0 ("powerpc/eeh: Make EEH driver device hotplug
safe") refactored the EEH code such that the pci_rescan_remove_lock is
held at the beginning of eeh_handle_normal_event() and the
eeh_reset_device() is called with that lock being held. Looks like the
commit missed to remove the existing lock/unlock inside eeh_rmv_device()
which is no longer necessary. This is causing the eehd to hang on the
lock which it actually holds when that code path is taken.
[<0>] 0xc00000011c78f870
[<0>] __switch_to+0xfc/0x1a0
[<0>] pci_lock_rescan_remove+0x30/0x44
[<0>] eeh_rmv_device+0x290/0x2e0
[<0>] eeh_pe_dev_traverse+0x80/0x130
[<0>] eeh_reset_device+0xcc/0x23c
[<0>] eeh_handle_normal_event+0x830/0xa80
[<0>] eeh_event_handler+0xf8/0x190
[<0>] kthread+0x194/0x1b0
[<0>] start_kernel_thread+0x14/0x18
The issue is seen for cases where the errors are detected on the PHB
directly AND|OR for devices where the driver error_detected() returns
PCI_ERS_RESULT_NEED_RESET, and driver being not EEH sensitive(i.e no
error handlers like slot_reset(), resume() etc defined).
Fixes: 1010b4c012b0 ("powerpc/eeh: Make EEH driver device hotplug safe")
Cc: stable <stable@kernel.org>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Shivaprasad G Bhat <sbhat@linux.ibm.com>
Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/178404937381.913.2759874335293830160.stgit@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/powerpc/kernel/eeh_driver.c | 2 --
1 file changed, 2 deletions(-)
--- a/arch/powerpc/kernel/eeh_driver.c
+++ b/arch/powerpc/kernel/eeh_driver.c
@@ -533,9 +533,7 @@ static void eeh_rmv_device(struct eeh_de
if (rmv_data)
list_add(&edev->rmv_entry, &rmv_data->removed_vf_list);
} else {
- pci_lock_rescan_remove();
pci_stop_and_remove_bus_device(dev);
- pci_unlock_rescan_remove();
}
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 498/982] ipv6: fix fib6 walker UAF on seq stop
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (496 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 497/982] powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 499/982] ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough Greg Kroah-Hartman
` (490 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Ido Schimmel, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit 19b4ed644d68098cc62ab612727f40d30f43476c upstream.
ipv6_route_iter_active() treats a walker in FWS_U at the table root as
already unlinked. fib6_del_route() can move a still-linked walker into
that same state when the current leaf is the last route at the root,
so ipv6_route_native_seq_stop() skips fib6_walker_unlink(). The seq
private object can then be freed while it remains on
net->ipv6.fib6_walkers. A later route deletion walks the dangling list
and uses the freed walker.
Use the list head as membership state and reinitialize it when
unlinking. Keep the existing w->node check so a never-started iterator
with a zeroed private object is not treated as linked.
The same stop helper is used by /proc/net/ipv6_route and by the BPF
ipv6_route iterator. The BPF show path only widens the race.
Fixes: 8d2ca1d7b5c3 ("ipv6: avoid high order memory allocations for /proc/net/ipv6_route")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/89699735763f6c297584d7c2ff106239cc1e8ce0.1788837093.git.zihanx@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/ip6_fib.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/ipv6/ip6_fib.c
+++ b/net/ipv6/ip6_fib.c
@@ -85,7 +85,7 @@ static void fib6_walker_link(struct net
static void fib6_walker_unlink(struct net *net, struct fib6_walker *w)
{
write_lock_bh(&net->ipv6.fib6_walker_lock);
- list_del(&w->lh);
+ list_del_init(&w->lh);
write_unlock_bh(&net->ipv6.fib6_walker_lock);
}
@@ -2650,7 +2650,7 @@ static void *ipv6_route_seq_start(struct
static bool ipv6_route_iter_active(struct ipv6_route_iter *iter)
{
struct fib6_walker *w = &iter->w;
- return w->node && !(w->state == FWS_U && w->node == w->root);
+ return w->node && !list_empty(&w->lh);
}
static void ipv6_route_native_seq_stop(struct seq_file *seq, void *v)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 499/982] ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (497 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 498/982] ipv6: fix fib6 walker UAF on seq stop Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 500/982] ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf Greg Kroah-Hartman
` (489 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Roman Prucha, Takashi Iwai
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roman Prucha <zorgan.roman@gmail.com>
commit b26a7a80e6bbf8dd17dacb127d12435d79375cf2 upstream.
dao_rsc_init() encodes the DAIO configuration as
conf = (desc->msr & 0x7) | (desc->passthru << 3);
S/PDIF passthrough uses msr=1 and passthru=1, resulting in
conf=9.
daio_mgr_dao_init() masks conf with 0xf, but handles only values
1, 2, 4 and 8 when programming ATXCTL_NUC. As a result, conf=9
falls through to the default case and leaves NUC at its previous
setting.
On a Creative X-Fi Titanium HD SB1270 (CA20K2), this breaks AC3
IEC61937 passthrough when snd_ctxfi runs with
reference_rate=48000,multiple=2. The receiver detects a non-audio
stream but cannot decode the AC3 payload.
With the unmodified driver, multiple=1 makes the same stream work.
Handle conf=9 through the same NUC=0 path as conf=1.
The change was runtime tested on the SB1270 with multiple=2 using
IEC958 stereo PCM, pre-encoded AC3 IEC61937 passthrough and ALSA
A52 live 5.1 encoding.
Fixes: 26a9630c72eb ("ALSA: ctxfi: cthw20k2: fix mask on conf to allow 4 bits")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Roman Prucha <zorgan.roman@gmail.com>
Link: https://patch.msgid.link/20260903-ctxfi-spdif-conf9-fix-v1-1-5e4e3e1f801c@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/pci/ctxfi/cthw20k2.c | 1 +
1 file changed, 1 insertion(+)
--- a/sound/pci/ctxfi/cthw20k2.c
+++ b/sound/pci/ctxfi/cthw20k2.c
@@ -993,6 +993,7 @@ static int daio_mgr_dao_init(void *blk,
/* S/PDIF output */
switch ((conf & 0xf)) {
case 1:
+ case 9:
set_field(&ctl->txctl[idx], ATXCTL_NUC, 0);
break;
case 2:
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 500/982] ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (498 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 499/982] ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 501/982] dm/amdgpu: fix malformed link_settings debugfs output Greg Kroah-Hartman
` (488 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tristan Madani, Takashi Iwai
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tristan Madani <tristan@talencesecurity.com>
commit 861111a14740e12c36d363e9830f8daa734279c9 upstream.
The in04_last array in struct usx2ydev is declared as char[24], but
in04_buf is allocated as sizeof(struct us428_ctls) which is 21 bytes.
In i_usx2y_in04_int(), when ctl_snapshot_last == -2 (initialization
path):
memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));
This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes
past the end of the source object.
Introduce a USX2Y_IN04_SIZE constant defined as sizeof(struct
us428_ctls) and use it consistently for the in04_last array, the
in04_buf allocation, the URB transfer length, and the comparison loop,
replacing the bare 24 and 21 literals throughout.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Link: https://patch.msgid.link/20260904205826.4071119-1-tristmd@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/usx2y/usbusx2y.c | 6 +++---
sound/usb/usx2y/usbusx2y.h | 4 +++-
2 files changed, 6 insertions(+), 4 deletions(-)
--- a/sound/usb/usx2y/usbusx2y.c
+++ b/sound/usb/usx2y/usbusx2y.c
@@ -197,7 +197,7 @@ static void i_usx2y_in04_int(struct urb
memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));
us428ctls->ctl_snapshot_last = -1;
} else {
- for (i = 0; i < 21; i++) {
+ for (i = 0; i < USX2Y_IN04_SIZE; i++) {
if (usx2y->in04_last[i] != ((char *)usx2y->in04_buf)[i]) {
if (diff < 0)
diff = i;
@@ -306,7 +306,7 @@ int usx2y_in04_init(struct usx2ydev *usx
goto error;
}
- usx2y->in04_buf = kmalloc(21, GFP_KERNEL);
+ usx2y->in04_buf = kmalloc(USX2Y_IN04_SIZE, GFP_KERNEL);
if (!usx2y->in04_buf) {
err = -ENOMEM;
goto error;
@@ -314,7 +314,7 @@ int usx2y_in04_init(struct usx2ydev *usx
init_waitqueue_head(&usx2y->in04_wait_queue);
usb_fill_int_urb(usx2y->in04_urb, usx2y->dev, usb_rcvintpipe(usx2y->dev, 0x4),
- usx2y->in04_buf, 21,
+ usx2y->in04_buf, USX2Y_IN04_SIZE,
i_usx2y_in04_int, usx2y,
10);
if (usb_urb_ep_type_check(usx2y->in04_urb)) {
--- a/sound/usb/usx2y/usbusx2y.h
+++ b/sound/usb/usx2y/usbusx2y.h
@@ -5,6 +5,8 @@
#include "../midi.h"
#include "usbus428ctldefs.h"
+#define USX2Y_IN04_SIZE sizeof(struct us428_ctls)
+
#define NRURBS 2
/* Default value used for nr of packs per urb.
@@ -55,7 +57,7 @@ struct usx2ydev {
int stride;
struct urb *in04_urb;
void *in04_buf;
- char in04_last[24];
+ char in04_last[USX2Y_IN04_SIZE];
unsigned int in04_int_calls;
struct snd_usx2y_urb_seq *us04;
wait_queue_head_t in04_wait_queue;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 501/982] dm/amdgpu: fix malformed link_settings debugfs output
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (499 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 500/982] ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 502/982] watchdog: sunxi_wdt: preserve boot-enabled watchdog Greg Kroah-Hartman
` (487 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Harry Wentland, Alex Hung,
Alex Deucher
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harry Wentland <harry.wentland@amd.com>
commit 622b4e8505aa7453a53d17fa3a288871f270fc8b upstream.
[Why]
dp_link_settings_read() passed strlen() of each format string as the size
argument to snprintf() and then advanced rd_buf_ptr by that same fixed amount.
The format-string length has no relation to the formatted output length, so
snprintf() truncated each field at a NUL it wrote inside the buffer while the
pointer was advanced past it. The result is a buffer peppered with embedded NUL
bytes and fields that are silently cut short, so the data read back from the
debugfs node does not reflect the actual link settings.
[How]
Use scnprintf() with the real remaining buffer size
(rd_buf_size - (rd_buf_ptr - rd_buf)) and advance rd_buf_ptr by its return
value, which is the number of characters actually written. This both bounds
each write to the space left in rd_buf and keeps the output a single,
properly terminated string. The now-unused str_len local is removed.
Fixes: 41db5f1931ec ("drm/amd/display: set-read link rate and lane count through debugfs")
Assisted-by: Copilot:claude-opus-4.8
Signed-off-by: Harry Wentland <harry.wentland@amd.com>
Reviewed-by: Alex Hung <alex.hung@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 43b9f0f18693c7f7b75613f3aeae25fa2b4e2f76)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c | 20 +++++---------
1 file changed, 8 insertions(+), 12 deletions(-)
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c
@@ -186,7 +186,6 @@ static ssize_t dp_link_settings_read(str
char *rd_buf_ptr = NULL;
const uint32_t rd_buf_size = 100;
uint32_t result = 0;
- uint8_t str_len = 0;
int r;
if (*pos & 3 || size & 3)
@@ -198,29 +197,26 @@ static ssize_t dp_link_settings_read(str
rd_buf_ptr = rd_buf;
- str_len = strlen("Current: %d 0x%x %d ");
- snprintf(rd_buf_ptr, str_len, "Current: %d 0x%x %d ",
+ rd_buf_ptr += scnprintf(rd_buf_ptr, rd_buf_size - (rd_buf_ptr - rd_buf),
+ "Current: %d 0x%x %d ",
link->cur_link_settings.lane_count,
link->cur_link_settings.link_rate,
link->cur_link_settings.link_spread);
- rd_buf_ptr += str_len;
- str_len = strlen("Verified: %d 0x%x %d ");
- snprintf(rd_buf_ptr, str_len, "Verified: %d 0x%x %d ",
+ rd_buf_ptr += scnprintf(rd_buf_ptr, rd_buf_size - (rd_buf_ptr - rd_buf),
+ "Verified: %d 0x%x %d ",
link->verified_link_cap.lane_count,
link->verified_link_cap.link_rate,
link->verified_link_cap.link_spread);
- rd_buf_ptr += str_len;
- str_len = strlen("Reported: %d 0x%x %d ");
- snprintf(rd_buf_ptr, str_len, "Reported: %d 0x%x %d ",
+ rd_buf_ptr += scnprintf(rd_buf_ptr, rd_buf_size - (rd_buf_ptr - rd_buf),
+ "Reported: %d 0x%x %d ",
link->reported_link_cap.lane_count,
link->reported_link_cap.link_rate,
link->reported_link_cap.link_spread);
- rd_buf_ptr += str_len;
- str_len = strlen("Preferred: %d 0x%x %d ");
- snprintf(rd_buf_ptr, str_len, "Preferred: %d 0x%x %d\n",
+ rd_buf_ptr += scnprintf(rd_buf_ptr, rd_buf_size - (rd_buf_ptr - rd_buf),
+ "Preferred: %d 0x%x %d\n",
link->preferred_link_setting.lane_count,
link->preferred_link_setting.link_rate,
link->preferred_link_setting.link_spread);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 502/982] watchdog: sunxi_wdt: preserve boot-enabled watchdog
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (500 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 501/982] dm/amdgpu: fix malformed link_settings debugfs output Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 503/982] ufs: create the root dentry after loading cylinder metadata Greg Kroah-Hartman
` (486 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, James Hilliard, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Hilliard <james.hilliard1@gmail.com>
commit aab55360fa11a2c054798a484ac67ad606f563e4 upstream.
sunxi_wdt_probe() unconditionally stops the watchdog even when firmware
left it running. This opens an unprotected interval during boot and
prevents CONFIG_WATCHDOG_HANDLE_BOOT_ENABLED from taking over the active
watchdog.
Detect an enabled watchdog and decode its programmed interval. Preserve
representable timeouts, and round the 0.5-second interval up to the
minimum representable one-second timeout. Use the configured timeout for
reserved interval encodings. Set the Linux reset mode and ping the
watchdog without clearing its enable bit, then mark it hardware-running
before registration so the watchdog core services it until userspace
takes control. Leave disabled watchdogs untouched.
Fixes: d00680ed0026 ("watchdog: sunxi: New watchdog driver for Allwinner A10/A13")
Cc: stable@vger.kernel.org
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Link: https://patch.msgid.link/20260827-submit-sunxi-wdt-boot-enabled-v1-v2-1-610d37dccc97@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/sunxi_wdt.c | 45 ++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 44 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/sunxi_wdt.c
+++ b/drivers/watchdog/sunxi_wdt.c
@@ -129,6 +129,38 @@ static int sunxi_wdt_ping(struct watchdo
return 0;
}
+static bool sunxi_wdt_is_running(struct watchdog_device *wdt_dev)
+{
+ struct sunxi_wdt_dev *sunxi_wdt = watchdog_get_drvdata(wdt_dev);
+ const struct sunxi_wdt_reg *regs = sunxi_wdt->wdt_regs;
+
+ return readl(sunxi_wdt->wdt_base + regs->wdt_mode) & WDT_MODE_EN;
+}
+
+static unsigned int sunxi_wdt_get_timeout(struct watchdog_device *wdt_dev)
+{
+ struct sunxi_wdt_dev *sunxi_wdt = watchdog_get_drvdata(wdt_dev);
+ const struct sunxi_wdt_reg *regs = sunxi_wdt->wdt_regs;
+ unsigned int timeout;
+ u32 interval;
+
+ interval = readl(sunxi_wdt->wdt_base + regs->wdt_mode);
+ interval >>= regs->wdt_timeout_shift;
+ interval &= WDT_TIMEOUT_MASK;
+ /* Round the 0.5-second interval up to the minimum representable timeout. */
+ if (!interval)
+ return WDT_MIN_TIMEOUT;
+
+ for (timeout = WDT_MIN_TIMEOUT;
+ timeout < ARRAY_SIZE(wdt_timeout_map); timeout++) {
+ if (wdt_timeout_map[timeout] == interval)
+ return timeout;
+ }
+
+ /* Reserved interval encoding. */
+ return 0;
+}
+
static int sunxi_wdt_set_timeout(struct watchdog_device *wdt_dev,
unsigned int timeout)
{
@@ -249,6 +281,7 @@ static int sunxi_wdt_probe(struct platfo
{
struct device *dev = &pdev->dev;
struct sunxi_wdt_dev *sunxi_wdt;
+ unsigned int running_timeout;
int err;
sunxi_wdt = devm_kzalloc(dev, sizeof(*sunxi_wdt), GFP_KERNEL);
@@ -276,7 +309,17 @@ static int sunxi_wdt_probe(struct platfo
watchdog_set_drvdata(&sunxi_wdt->wdt_dev, sunxi_wdt);
- sunxi_wdt_stop(&sunxi_wdt->wdt_dev);
+ if (sunxi_wdt_is_running(&sunxi_wdt->wdt_dev)) {
+ running_timeout = sunxi_wdt_get_timeout(&sunxi_wdt->wdt_dev);
+ if (running_timeout)
+ sunxi_wdt->wdt_dev.timeout = running_timeout;
+
+ err = sunxi_wdt_start(&sunxi_wdt->wdt_dev);
+ if (err)
+ return err;
+
+ set_bit(WDOG_HW_RUNNING, &sunxi_wdt->wdt_dev.status);
+ }
watchdog_stop_on_reboot(&sunxi_wdt->wdt_dev);
err = devm_watchdog_register_device(dev, &sunxi_wdt->wdt_dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 503/982] ufs: create the root dentry after loading cylinder metadata
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (501 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 502/982] watchdog: sunxi_wdt: preserve boot-enabled watchdog Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 504/982] ufs: validate cylinder group metadata before caching it Greg Kroah-Hartman
` (485 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ali Ahmet Memis, Jan Kara,
Christian Brauner (Amutable)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Ahmet Memis <ali@iusegentoo.com>
commit 55a4c98abb9694b067c6a031d11501f06b6b523c upstream.
ufs_fill_super() installed sb->s_root before it loaded the cylinder
group structures for a writable mount:
sb->s_root = d_make_root(inode);
...
if (!sb_rdonly(sb))
if (!ufs_read_cylinder_structures(sb))
goto failed;
When ufs_read_cylinder_structures() failed, the error path freed the
in-core superblock information and set sb->s_fs_info to NULL while
sb->s_root stayed installed. get_tree_bdev() then reached
deactivate_locked_super(), and because s_root was present,
generic_shutdown_super() called sync_filesystem() and the put_super
operation. Both dereference UFS_SB(sb), which is now NULL, so a mount
that fails only while reading the cylinder groups oopses during
teardown. A crafted image whose first cylinder group cannot be read
reaches this path.
Load the cylinder group metadata first and create the root dentry last,
so the superblock is published to the VFS only once it is fully set up.
ufs_setup_cstotal() and ufs_read_cylinder_structures() take only the
super_block and do not use the root inode, so the reordering is safe.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Link: https://patch.msgid.link/20260801071306.59484-2-ali@iusegentoo.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/ufs/super.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
--- a/fs/ufs/super.c
+++ b/fs/ufs/super.c
@@ -1268,6 +1268,15 @@ magic_found:
sb->s_maxbytes = ufs_max_bytes(sb);
sb->s_max_links = UFS_LINK_MAX;
+ ufs_setup_cstotal(sb);
+ /*
+ * Read cylinder group structures
+ */
+ if (!sb_rdonly(sb))
+ if (!ufs_read_cylinder_structures(sb))
+ goto failed;
+
+ /* create the root dentry last, once UFS_SB(sb) is fully set up */
inode = ufs_iget(sb, UFS_ROOTINO);
if (IS_ERR(inode)) {
ret = PTR_ERR(inode);
@@ -1279,14 +1288,6 @@ magic_found:
goto failed;
}
- ufs_setup_cstotal(sb);
- /*
- * Read cylinder group structures
- */
- if (!sb_rdonly(sb))
- if (!ufs_read_cylinder_structures(sb))
- goto failed;
-
UFSD("EXIT\n");
return 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 504/982] ufs: validate cylinder group metadata before caching it
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (502 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 503/982] ufs: create the root dentry after loading cylinder metadata Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 505/982] tunnels: Drop stale dst when building an ICMP error for PMTUD Greg Kroah-Hartman
` (484 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ali Ahmet Memis, Jan Kara,
Christian Brauner (Amutable)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Ahmet Memis <ali@iusegentoo.com>
commit c9d263be26806d388129fab8c6904bed197fc6af upstream.
ufs_read_cylinder() copies the cylinder group index and the rotor
positions straight from the on-disk group and caches them without any
check:
ucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx);
ucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor);
ucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);
ucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);
They are then used as indices during allocation and free:
- c_cgx indexes the cylinder summary array as
UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32
bit count outside the s_csp allocation.
- c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and
then length = ((s_fpg + 7) >> 3) - start. A start beyond the block
bitmap wraps the unsigned length to a huge value, so ubh_scanc()
walks far past the cylinder group buffers. c_irotor drives the
inode bitmap the same way.
A crafted image can set any of these freely, turning an ordinary
allocation into an out of bounds access.
Reject a cylinder group whose recorded index does not match the group
being read, or whose rotors fall outside the group, before the metadata
is cached. Valid filesystems keep cg_cgx equal to the group number and
the rotors within the group, so only malformed images are rejected.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Link: https://patch.msgid.link/20260801071306.59484-3-ali@iusegentoo.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/ufs/cylinder.c | 10 ++++++++++
1 file changed, 10 insertions(+)
--- a/fs/ufs/cylinder.c
+++ b/fs/ufs/cylinder.c
@@ -66,6 +66,16 @@ static void ufs_read_cylinder (struct su
ucpi->c_clustersumoff = fs32_to_cpu(sb, ucg->cg_u.cg_44.cg_clustersumoff);
ucpi->c_clusteroff = fs32_to_cpu(sb, ucg->cg_u.cg_44.cg_clusteroff);
ucpi->c_nclusterblks = fs32_to_cpu(sb, ucg->cg_u.cg_44.cg_nclusterblks);
+
+ /* these on-disk values become array and bitmap indices */
+ if (ucpi->c_cgx != cgno ||
+ ucpi->c_rotor >= uspi->s_fpg ||
+ ucpi->c_frotor >= uspi->s_fpg ||
+ ucpi->c_irotor >= uspi->s_ipg) {
+ ufs_error(sb, __func__,
+ "inconsistent metadata in cylinder group %u\n", cgno);
+ goto failed;
+ }
UFSD("EXIT\n");
return;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 505/982] tunnels: Drop stale dst when building an ICMP error for PMTUD
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (503 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 504/982] ufs: validate cylinder group metadata before caching it Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 506/982] tick/broadcast: Plug clockevents replacement race Greg Kroah-Hartman
` (483 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Laika Price, Yaroslav Dudkov,
Charles Bordet, Ido Schimmel, David Ahern, Stefano Brivio,
Guillaume Nault, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
commit b58d749633203d92c265317b45fccee555090352 upstream.
Bridged UDP tunnels such as VXLAN and GENEVE build an ICMP error packet
around an overlay packet if the packet is going to exceed the underlay
path MTU. The ICMP error packet is then injected back into the Rx path
with the source and destination addresses swapped, so that it will be
delivered to the overlay source.
If the overlay packet was routed to the UDP tunnel or locally generated,
then it is already carrying a valid dst entry and this entry is not
dropped when transforming the packet to an ICMP error packet. This
causes the IP layer to reuse the dst entry, leading to the ICMP error
packet being dropped or routed out of the UDP tunnel interface in case
of forwarding.
Prior to the blamed commit this could not happen, as
skb_tunnel_check_pmtu() did not build ICMP errors for PACKET_HOST
packets. Such packets were instead encapsulated and, unless the DF bit
was set in the outer header, fragmented by the underlay.
Fix this by making sure that the ICMP error packet does not have a valid
dst entry, thereby forcing the IP layer to perform a route lookup.
Adjust the bridged PMTU exception selftests accordingly. When the
local sender in ns_a pings the overlay destination with a deadline
(-w), ping exits on the first socket error before any reply is
received and returns a non-zero exit code. The test therefore only
passed because the ICMP error was never delivered. Use a packet count
(-c) like the ns_c line above it, so that the ICMP error counts
against the packet budget and the exit code depends on whether echo
replies were received. This passes with and without the fix.
Fixes: 8930424777e4 ("tunnels: Accept PACKET_HOST in skb_tunnel_check_pmtu().")
Cc: stable@vger.kernel.org
Reported-by: Laika Price <laikabcprice@gmail.com>
Closes: https://lore.kernel.org/netdev/20260614-master-v3-1-9f5060ba1ed1@gmail.com/
Reported-by: Yaroslav Dudkov <aroslavdudkov622@gmail.com>
Closes: https://lore.kernel.org/netdev/20260901081825.287173-1-aroslavdudkov622@gmail.com/
Reported-by: Charles Bordet <rough.rock3059@datachamp.fr>
Closes: https://lore.kernel.org/netdev/aHVhQLPJIhq-SYPM@eldamar.lan/
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Tested-by: Yaroslav Dudkov <aroslavdudkov622@gmail.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Reviewed-by: Guillaume Nault <gnault@redhat.com>
Link: https://patch.msgid.link/20260902190112.4126199-1-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/ip_tunnel_core.c | 6 ++++++
tools/testing/selftests/net/pmtu.sh | 2 +-
2 files changed, 7 insertions(+), 1 deletion(-)
--- a/net/ipv4/ip_tunnel_core.c
+++ b/net/ipv4/ip_tunnel_core.c
@@ -250,6 +250,9 @@ static int iptunnel_pmtud_build_icmp(str
eth_header(skb, skb->dev, ntohs(eh.h_proto), eh.h_source, eh.h_dest, 0);
skb_reset_mac_header(skb);
+ if (skb_valid_dst(skb))
+ skb_dst_drop(skb);
+
return skb->len;
}
@@ -353,6 +356,9 @@ static int iptunnel_pmtud_build_icmpv6(s
eth_header(skb, skb->dev, ntohs(eh.h_proto), eh.h_source, eh.h_dest, 0);
skb_reset_mac_header(skb);
+ if (skb_valid_dst(skb))
+ skb_dst_drop(skb);
+
return skb->len;
}
--- a/tools/testing/selftests/net/pmtu.sh
+++ b/tools/testing/selftests/net/pmtu.sh
@@ -1369,7 +1369,7 @@ test_pmtu_ipvX_over_bridged_vxlanY_or_ge
mtu "${ns_b}" ${type}_b $((${ll_mtu} + 1000))
run_cmd ${ns_c} ${ping} -q -M want -i 0.1 -c 10 -s $((${ll_mtu} + 500)) ${dst} || return 1
- run_cmd ${ns_a} ${ping} -q -M want -i 0.1 -w 1 -s $((${ll_mtu} + 500)) ${dst} || return 1
+ run_cmd ${ns_a} ${ping} -q -M want -i 0.1 -c 10 -s $((${ll_mtu} + 500)) ${dst} || return 1
# Check that exceptions were created
pmtu="$(route_get_dst_pmtu_from_exception "${ns_c}" ${dst})"
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 506/982] tick/broadcast: Plug clockevents replacement race
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (504 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 505/982] tunnels: Drop stale dst when building an ICMP error for PMTUD Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 507/982] tracing: Free histogram the var ref when its initialization fails Greg Kroah-Hartman
` (482 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, 朱恺乾,
Thomas Gleixner, Thomas Gleixner, Bradley Morgan,
刘术高
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@linutronix.de>
commit 113a9796effe3376d2ec5aabcca1fef4fef4cd62 upstream.
朱恺乾 reported and decoded the following race condition when a broadcast
device is replaced:
CPUA CPUB
__tick_broadcast_oneshot_control()
bc = tick_broadcast_device.evtdev;
tick_install_broadcast_device(dev)
clockevents_exchange_device(cur, dev)
shutdown(cur);
detach(cur);
cur->handler = noop;
tick_broadcast_device.evtdev = dev;
tick_broadcast_set_event(bc, next_event); <- FAIL: arms a detached device.
If the original broadcast device has a restricted interrupt affinity mask
and the last CPU in that mask goes offline then the BUG() in
tick_cleanup_dead_cpu() triggers because the clockevent device is not in
detached state.
The reason for this is that tick_install_broadcast_device() is not
serialized vs. tick broadcast operations.
The obvious cure is to serialize tick_install_broadcast_device() with
tick_broadcast_lock against a concurrent tick broadcast operation.
That requires to split clockevents_exchange_device() into two parts, one
which does the exchange, shutdown and detach operation and the other which
drops the module reference count. This is required because the module
reference cannot be dropped while holding tick_broadcast_lock.
Let clockevents_exchange_device() do both operations as before, but let the
broadcast device code take the two step approach and do the device
exchange under tick_broadcast_lock and drop the module reference count
after releasing it.
Fixes: f8381cba04ba ("[PATCH] tick-management: broadcast functionality")
Reported-by: 朱恺乾 <zhukaiqian@xiaomi.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Bradley Morgan <brads@mainlining.org>
Tested-by: 刘术高 <liushugao@xiaomi.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/87cymdsu0r.ffs@tglx
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/time/clockevents.c | 33 ++++++++++++++++++++-------------
kernel/time/tick-broadcast.c | 36 ++++++++++++++++++++++--------------
kernel/time/tick-internal.h | 2 ++
3 files changed, 44 insertions(+), 27 deletions(-)
--- a/kernel/time/clockevents.c
+++ b/kernel/time/clockevents.c
@@ -557,34 +557,41 @@ void clockevents_handle_noop(struct cloc
{
}
-/**
- * clockevents_exchange_device - release and request clock devices
- * @old: device to release (can be NULL)
- * @new: device to request (can be NULL)
- *
- * Called from various tick functions with clockevents_lock held and
- * interrupts disabled.
- */
-void clockevents_exchange_device(struct clock_event_device *old,
- struct clock_event_device *new)
+void __clockevents_exchange_device(struct clock_event_device *old,
+ struct clock_event_device *new)
{
/*
* Caller releases a clock event device. We queue it into the
* released list and do a notify add later.
*/
if (old) {
- module_put(old->owner);
clockevents_switch_state(old, CLOCK_EVT_STATE_DETACHED);
list_move(&old->list, &clockevents_released);
}
if (new) {
- BUG_ON(!clockevent_state_detached(new));
+ WARN_ON(!clockevent_state_detached(new));
clockevents_shutdown(new);
}
}
/**
+ * clockevents_exchange_device - release and request clock devices
+ * @old: device to release (can be NULL)
+ * @new: device to request (can be NULL)
+ *
+ * Called from various tick functions with clockevents_lock held and
+ * interrupts disabled.
+ */
+void clockevents_exchange_device(struct clock_event_device *old,
+ struct clock_event_device *new)
+{
+ __clockevents_exchange_device(old, new);
+ if (old)
+ module_put(old->owner);
+}
+
+/**
* clockevents_suspend - suspend clock devices
*/
void clockevents_suspend(void)
@@ -650,7 +657,7 @@ void tick_cleanup_dead_cpu(int cpu)
if (cpumask_test_cpu(cpu, dev->cpumask) &&
cpumask_weight(dev->cpumask) == 1 &&
!tick_is_broadcast_device(dev)) {
- BUG_ON(!clockevent_state_detached(dev));
+ WARN_ON(!clockevent_state_detached(dev));
list_del(&dev->list);
}
}
--- a/kernel/time/tick-broadcast.c
+++ b/kernel/time/tick-broadcast.c
@@ -162,23 +162,31 @@ static bool tick_set_oneshot_wakeup_devi
*/
void tick_install_broadcast_device(struct clock_event_device *dev, int cpu)
{
- struct clock_event_device *cur = tick_broadcast_device.evtdev;
+ struct clock_event_device *cur;
- if (tick_set_oneshot_wakeup_device(dev, cpu))
- return;
+ scoped_guard(raw_spinlock_irqsave, &tick_broadcast_lock) {
- if (!tick_check_broadcast_device(cur, dev))
- return;
+ if (tick_set_oneshot_wakeup_device(dev, cpu))
+ return;
- if (!try_module_get(dev->owner))
- return;
+ cur = tick_broadcast_device.evtdev;
+ if (!tick_check_broadcast_device(cur, dev))
+ return;
- clockevents_exchange_device(cur, dev);
+ if (!try_module_get(dev->owner))
+ return;
+
+ __clockevents_exchange_device(cur, dev);
+ if (cur)
+ cur->event_handler = clockevents_handle_noop;
+ WRITE_ONCE(tick_broadcast_device.evtdev, dev);
+ if (!cpumask_empty(tick_broadcast_mask))
+ tick_broadcast_start_periodic(dev);
+ }
+
+ /* Module release must be outside of the lock */
if (cur)
- cur->event_handler = clockevents_handle_noop;
- tick_broadcast_device.evtdev = dev;
- if (!cpumask_empty(tick_broadcast_mask))
- tick_broadcast_start_periodic(dev);
+ module_put(cur->owner);
if (!(dev->features & CLOCK_EVT_FEAT_ONESHOT))
return;
@@ -1205,7 +1213,7 @@ int tick_broadcast_oneshot_active(void)
*/
bool tick_broadcast_oneshot_available(void)
{
- struct clock_event_device *bc = tick_broadcast_device.evtdev;
+ struct clock_event_device *bc = READ_ONCE(tick_broadcast_device.evtdev);
return bc ? bc->features & CLOCK_EVT_FEAT_ONESHOT : false;
}
@@ -1213,7 +1221,7 @@ bool tick_broadcast_oneshot_available(vo
#else
int __tick_broadcast_oneshot_control(enum tick_broadcast_state state)
{
- struct clock_event_device *bc = tick_broadcast_device.evtdev;
+ struct clock_event_device *bc = READ_ONCE(tick_broadcast_device.evtdev);
if (!bc || (bc->features & CLOCK_EVT_FEAT_HRTIMER))
return -EBUSY;
--- a/kernel/time/tick-internal.h
+++ b/kernel/time/tick-internal.h
@@ -48,6 +48,8 @@ static inline void clockevent_set_state(
}
extern void clockevents_shutdown(struct clock_event_device *dev);
+extern void __clockevents_exchange_device(struct clock_event_device *old,
+ struct clock_event_device *new);
extern void clockevents_exchange_device(struct clock_event_device *old,
struct clock_event_device *new);
extern void clockevents_switch_state(struct clock_event_device *dev,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 507/982] tracing: Free histogram the var ref when its initialization fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (505 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 506/982] tick/broadcast: Plug clockevents replacement race Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 508/982] tracing: Free histogram var refs regardless of how often they are referenced Greg Kroah-Hartman
` (481 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Steven Rostedt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit 516001d53e6b2ea95a251ee2ef54a1a689a3fd58 upstream.
create_var_ref() allocates a VAR_REF hist_field and then calls
init_var_ref() to fill it in. When that fails the field is leaked.
commit 656fe2ba85e8 ("tracing: Use hist trigger's var_ref array to destroy
var_refs") made destroy_hist_field() return early for
HIST_FIELD_FL_VAR_REF, since var refs are freed by walking the trigger's
var_refs[] array instead. create_var_ref() adds the field to that array
only after init_var_ref() has succeeded, so on this path the field is in
neither place and nothing frees it. The call was correct when it was
written, before var refs were taken out of destroy_hist_field().
init_var_ref() cannot free it either. The caller owns the field, so
init_var_ref() undoes only its own string allocations and leaves the
field alone. Freeing it there would leave create_var_ref() passing freed
memory to destroy_hist_field(), which reads its flags.
Call __destroy_hist_field(), which frees the field without consulting
the flag.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260906133352.3815019-1-donggeunyoo.kernel@gmail.com
Fixes: 656fe2ba85e8 ("tracing: Use hist trigger's var_ref array to destroy var_refs")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events_hist.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -2179,7 +2179,7 @@ static struct hist_field *create_var_ref
ref_field = create_hist_field(var_field->hist_data, NULL, flags, NULL);
if (ref_field) {
if (init_var_ref(ref_field, var_field, system, event_name)) {
- destroy_hist_field(ref_field, 0);
+ __destroy_hist_field(ref_field);
return NULL;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 508/982] tracing: Free histogram var refs regardless of how often they are referenced
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (506 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 507/982] tracing: Free histogram the var ref when its initialization fails Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 509/982] tracing: Free histogram the field rejected for a bad modifier Greg Kroah-Hartman
` (480 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Steven Rostedt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit 4bddcb346a6cf4615ca77f69a589623b877ca267 upstream.
Using the same variable three or more times in one hist trigger leaks the
variable reference and its strings when the trigger is removed.
commit 656fe2ba85e8 ("tracing: Use hist trigger's var_ref array to destroy
var_refs") made a trigger's var_refs[] array the only owner of a var ref:
destroy_hist_field() returns early for HIST_FIELD_FL_VAR_REF, so the field
expressions never destroy one. One entry, freed once, no count needed.
commit 8bcebc77e85f ("tracing: Fix histogram code when expression has same
var as value") then made repeated references share one object and added a
count of them. Only the increment side exists, since those expressions
still return early and never drop a reference, so __destroy_hist_field()
sees how many references were created rather than how many are left. It
frees when the decremented count is 0 or 1, so two references work and
three or more leak.
Sharing kept one array entry per object, and create_var_ref() searches and
appends within a single trigger, so nothing outside it holds the object.
Removing a trigger whose variables are still referenced is already refused
by check_var_refs() with -EBUSY. Drop the count and free unconditionally.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260906124025.3550596-1-donggeunyoo.kernel@gmail.com
Fixes: 8bcebc77e85f ("tracing: Fix histogram code when expression has same var as value")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events_hist.c | 16 +---------------
1 file changed, 1 insertion(+), 15 deletions(-)
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -160,7 +160,6 @@ struct hist_field {
struct hist_field *operands[HIST_FIELD_OPERANDS_MAX];
struct hist_trigger_data *hist_data;
enum hist_field_fn fn_num;
- unsigned int ref;
unsigned int size;
unsigned int offset;
unsigned int is_signed;
@@ -1879,16 +1878,8 @@ out:
return field_op;
}
-static void get_hist_field(struct hist_field *hist_field)
-{
- hist_field->ref++;
-}
-
static void __destroy_hist_field(struct hist_field *hist_field)
{
- if (--hist_field->ref > 1)
- return;
-
kfree(hist_field->var.name);
kfree(hist_field->name);
@@ -1935,8 +1926,6 @@ static struct hist_field *create_hist_fi
if (!hist_field)
return NULL;
- hist_field->ref = 1;
-
hist_field->hist_data = hist_data;
if (flags & HIST_FIELD_FL_EXPR || flags & HIST_FIELD_FL_ALIAS)
@@ -2168,10 +2157,8 @@ static struct hist_field *create_var_ref
for (i = 0; i < hist_data->n_var_refs; i++) {
ref_field = hist_data->var_refs[i];
if (ref_field->var.idx == var_field->var.idx &&
- ref_field->var.hist_data == var_field->hist_data) {
- get_hist_field(ref_field);
+ ref_field->var.hist_data == var_field->hist_data)
return ref_field;
- }
}
/* Sanity check to avoid out-of-bound write on 'hist_data->var_refs' */
if (hist_data->n_var_refs >= TRACING_MAP_VARS_MAX)
@@ -3160,7 +3147,6 @@ static struct hist_field *create_var(str
goto out;
}
- var->ref = 1;
var->flags = HIST_FIELD_FL_VAR;
var->var.idx = idx;
var->var.hist_data = var->hist_data = hist_data;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 509/982] tracing: Free histogram the field rejected for a bad modifier
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (507 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 508/982] tracing: Free histogram var refs regardless of how often they are referenced Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 510/982] tracing: Let histogram values keep the percent and graph modifiers Greg Kroah-Hartman
` (479 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Steven Rostedt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit 230234d12ce42ab04132a32c3a848f07a5d27a71 upstream.
Writing a hist trigger whose value or variable carries a modifier that is
not allowed there leaks the fields that were built for it.
__create_val_field() takes the field from parse_expr() and stores it in
hist_data->fields[] only after the modifier checks have run:
hist_field = parse_expr(hist_data, file, field_str, flags, var_name,
&n_subexprs);
...
if (hist_field->flags & HIST_FIELD_FL_VAR) {
if (hist_field->flags & (...))
goto err;
} else {
if (hist_field->flags & (...))
goto err;
}
hist_data->fields[val_idx] = hist_field;
Both checks jump past that store, and the err label returns without
freeing anything. The error unwinds to create_hist_data(), which calls
destroy_hist_data() -> destroy_hist_fields(), and that reaches a field
only by walking fields[]. A field that never got there is unreachable.
commit e0213434fe3e ("tracing: Do not let histogram values have some
modifiers") set ret to -EINVAL and fell through to the store, which left
the field owned by fields[] and freed along with the rest of hist_data.
Splitting the check into a value case and a variable case replaced that
fall-through with a goto that skips it.
With CONFIG_DEBUG_KMEMLEAK, 200 writes of
# echo 'hist:keys=prev_pid:vals=next_pid.log2' > \
events/sched/sched_switch/trigger
each correctly rejected with -EINVAL, leave 332 unreferenced objects
(63744 bytes) reported at create_hist_field(); 200 install and remove
cycles of a valid trigger leave none. A '.log2' field is two
allocations, since create_hist_field() puts the plain field in
operands[0] of the log2 field, and both are reported.
Use destroy_hist_field() rather than __destroy_hist_field() so that
operands[0] is freed as well. It returns early for HIST_FIELD_FL_VAR_REF,
which is what an operand owned by hist_data->var_refs[] needs; the
rejected field itself is never a var ref, because a var ref never carries
a modifier flag.
Cc: stable@vger.kernel.org
Fixes: e30fbc618e97 ("tracing/histograms: Allow variables to have some modifiers")
Link: https://patch.msgid.link/20260907034948.240387-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events_hist.c | 1 +
1 file changed, 1 insertion(+)
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -4199,6 +4199,7 @@ static int __create_val_field(struct his
return ret;
err:
hist_err(file->tr, HIST_ERR_BAD_FIELD_MODIFIER, errpos(field_str));
+ destroy_hist_field(hist_field, 0);
return -EINVAL;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 510/982] tracing: Let histogram values keep the percent and graph modifiers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (508 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 509/982] tracing: Free histogram the field rejected for a bad modifier Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 511/982] tracing: Keep the entry count when the histogram stats allocation fails Greg Kroah-Hartman
` (478 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Steven Rostedt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit 3d617bfd79330ae3acf94862c18bb3ccf5f5a0f9 upstream.
The .percent and .graph modifiers exist only for histogram values, but a
value carrying either of them has been rejected since v6.3. The example
in Documentation/trace/histogram.rst,
# echo 'hist:keys=prev_comm:vals=hitcount.percent:nohitcount' > \
events/sched/sched_switch/trigger
returns -EINVAL.
parse_field() sets the two flags only when the field is neither a key nor
a variable, that is, only on a value:
} else if (strncmp(modifier, "percent", 7) == 0) {
if (*flags & (HIST_FIELD_FL_VAR | HIST_FIELD_FL_KEY))
goto error;
*flags |= HIST_FIELD_FL_PERCENT;
__create_val_field() then rejects a value for carrying them, so no field
can reach hist_trigger_print_val(), where both are implemented.
commit e0213434fe3e ("tracing: Do not let histogram values have some
modifiers") added the check after a value with .buckets oopsed in
hist_field_name(). That happens because .buckets and .log2 make
create_hist_field() build a nested field in operands[0] which
hist_field_name() then walks into. The percent and graph flags do not
create an operand and are not read by hist_field_name(); they are only
used when printing a value.
Stop rejecting the two flags on a value. The check for variables is left
alone, where they are unreachable anyway because parse_field() rejects a
variable carrying them first.
With the two flags removed, the trigger above installs and prints as
documented:
{ prev_comm: rcu_preempt } hitcount (%): 0.00
{ prev_comm: init } hitcount (%): 99.98
Totals:
Hits: 237896
Cc: stable@vger.kernel.org
Fixes: e0213434fe3e ("tracing: Do not let histogram values have some modifiers")
Link: https://patch.msgid.link/20260907052113.430818-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events_hist.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -4181,8 +4181,7 @@ static int __create_val_field(struct his
goto err;
} else {
/* Value */
- if (hist_field->flags & (HIST_FIELD_FL_GRAPH | HIST_FIELD_FL_PERCENT |
- HIST_FIELD_FL_BUCKET | HIST_FIELD_FL_LOG2 |
+ if (hist_field->flags & (HIST_FIELD_FL_BUCKET | HIST_FIELD_FL_LOG2 |
HIST_FIELD_FL_SYM | HIST_FIELD_FL_SYM_OFFSET |
HIST_FIELD_FL_SYSCALL | HIST_FIELD_FL_STACKTRACE))
goto err;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 511/982] tracing: Keep the entry count when the histogram stats allocation fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (509 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 510/982] tracing: Let histogram values keep the percent and graph modifiers Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 512/982] ASoC: sprd: validate compress buffer sizes against fixed allocations Greg Kroah-Hartman
` (477 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Donggeun Yoo,
Masami Hiramatsu (Google), Steven Rostedt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit 06f5634ec5584954177f9a22e36b3bfb398a971b upstream.
print_entries() uses n_entries both as the number of sort entries and as
its own return value, so the -ENOMEM it stores when the stats allocation
fails overwrites the count that the cleanup still needs:
n_entries = tracing_map_sort_entries(map, ...);
if (n_entries < 0)
return n_entries;
...
if (!stats) {
n_entries = -ENOMEM;
goto out;
}
...
out:
tracing_map_destroy_sort_entries(sort_entries, n_entries);
tracing_map_destroy_sort_entries() takes an unsigned int and loops up to
it, so -ENOMEM arrives as 4294967284. It walks an array of at most
map->max_elts pointers and calls destroy_sort_entry(), which dereferences
and frees, on whatever lies past the end.
Reading the hist file of a trigger with a .percent value, with that
allocation forced to fail:
BUG: KASAN: vmalloc-out-of-bounds in tracing_map_destroy_sort_entries+0xa0/0xb0
Read of size 8 at addr ffffc90000045000 by task init/1
tracing_map_destroy_sort_entries+0xa0/0xb0
hist_show+0x6f7/0x1df0
seq_read_iter+0x2b8/0x1190
vfs_read+0x176/0xa40
The buggy address belongs to a 4-page vmalloc region starting at
ffffc90000041000 allocated at tracing_map_sort_entries+0x5c/0xd50
A few pages further the fault is fatal. The registers at the oops confirm
the bound: the loop's end pointer less the array start, over the pointer
size, is 4294967284.
Return the error in a separate variable and leave n_entries holding the
count, the way tracing_map_sort_entries() does on its own error path.
The stats block is only entered for a value carrying .percent or .graph,
which __create_val_field() has rejected since v6.3, so this cannot be
reached in mainline as it stands. It becomes reachable again with
"tracing: hist: let values keep the percent and graph modifiers", so it
should be applied first.
Cc: stable@vger.kernel.org
Fixes: abaa5258ce5e ("tracing: Add .percent suffix option to histogram values")
Link: https://patch.msgid.link/20260907060323.480728-1-donggeunyoo.kernel@gmail.com
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/all/20260907053113.1CED91F00A3A@smtp.kernel.org/
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_events_hist.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -5416,7 +5416,7 @@ static int print_entries(struct seq_file
{
struct tracing_map_sort_entry **sort_entries = NULL;
struct tracing_map *map = hist_data->map;
- int i, j, n_entries;
+ int i, j, n_entries, ret;
struct hist_val_stat *stats = NULL;
u64 val;
@@ -5426,6 +5426,8 @@ static int print_entries(struct seq_file
if (n_entries < 0)
return n_entries;
+ ret = n_entries;
+
/* Calculate the max and the total for each field if needed. */
for (j = 0; j < hist_data->n_vals; j++) {
if (!(hist_data->fields[j]->flags &
@@ -5435,7 +5437,7 @@ static int print_entries(struct seq_file
stats = kcalloc(hist_data->n_vals, sizeof(*stats),
GFP_KERNEL);
if (!stats) {
- n_entries = -ENOMEM;
+ ret = -ENOMEM;
goto out;
}
}
@@ -5456,7 +5458,7 @@ static int print_entries(struct seq_file
out:
tracing_map_destroy_sort_entries(sort_entries, n_entries);
- return n_entries;
+ return ret;
}
static void hist_trigger_show(struct seq_file *m,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 512/982] ASoC: sprd: validate compress buffer sizes against fixed allocations
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (510 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 511/982] tracing: Keep the entry count when the histogram stats allocation fails Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 513/982] ASoC: sti: initialize IRQ lock before requesting IRQ Greg Kroah-Hartman
` (476 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Mark Brown
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit 7a4ce92d150b9e7ecf1a710a34d8cdeb590d3751 upstream.
sprd_platform_compr_open() allocates the stage 0 IRAM buffer (32K data
area) and the stage 1 DDR buffer (2M data area) with fixed sizes, but
sprd_platform_compr_copy() derives all copy lengths from the user
controlled runtime->fragment_size and the write() count, never
comparing them against the physical buffer sizes. The compress core
only checks fragment_size * fragments for an u32 overflow in
snd_compress_check_input(), so a local user can configure a logical
buffer of up to ~4GB via SNDRV_COMPRESS_SET_PARAMS, far exceeding the
fixed allocations.
A fragment_size larger than the 32K IRAM data area makes the stage 0
copy_from_user() overflow past the IRAM allocation, and a buffer_size
larger than the 2M DDR buffer makes the wrapping copy at the end of
sprd_platform_compr_copy() write fully user controlled data past the
buffer. No SNDRV_PCM_TRIGGER_START is needed, a write() in SETUP
state reaches the copy callback directly.
Reject parameters that do not fit into the fixed buffers in
set_params(), and fix the advertised max fragment size: 128K never
fitted into the 32K IRAM buffer. The caps values may have been carried over
from the qdsp6 driver, which allocates its buffers according to the
advertised maxima, unlike this driver. With 32K as max fragment size
the advertised limits are self-consistent: 32K * 64 = 2M equals the
DDR buffer size.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: cce1396936ef ("ASoC: sprd: Add Spreadtrum audio compress offload support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/4386bc53631b052c1866a91061715b009d98b04f@linux.dev
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/sprd/sprd-pcm-compress.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
--- a/sound/soc/sprd/sprd-pcm-compress.c
+++ b/sound/soc/sprd/sprd-pcm-compress.c
@@ -17,7 +17,7 @@
/* Default values if userspace does not set */
#define SPRD_COMPR_MIN_FRAGMENT_SIZE SZ_8K
-#define SPRD_COMPR_MAX_FRAGMENT_SIZE SZ_128K
+#define SPRD_COMPR_MAX_FRAGMENT_SIZE SZ_32K
#define SPRD_COMPR_MIN_NUM_FRAGMENTS 4
#define SPRD_COMPR_MAX_NUM_FRAGMENTS 64
@@ -272,6 +272,19 @@ static int sprd_platform_compr_set_param
int ret;
/*
+ * The stage 0 IRAM buffer and the stage 1 DDR buffer are allocated
+ * with fixed sizes at open time, so the requested fragment size and
+ * fragments must fit into them, otherwise sprd_platform_compr_copy()
+ * would overflow the buffers. Note the compress core only checks the
+ * fragment size and fragments against an u32 overflow, not against
+ * the buffer sizes advertised by get_caps.
+ */
+ if (params->buffer.fragment_size > SPRD_COMPR_IRAM_BUF_SIZE ||
+ (u64)params->buffer.fragment_size * params->buffer.fragments >
+ SPRD_COMPR_AREA_BUF_SIZE)
+ return -EINVAL;
+
+ /*
* Configure the DMA engine 2-stage transfer mode. Channel 1 set as the
* destination channel, and channel 0 set as the source channel, that
* means once the source channel's transaction is done, it will trigger
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 513/982] ASoC: sti: initialize IRQ lock before requesting IRQ
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (511 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 512/982] ASoC: sprd: validate compress buffer sizes against fixed allocations Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 514/982] cpufreq: zero-initialize policy cpumask before sysfs publication Greg Kroah-Hartman
` (475 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Mark Brown
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 04405aeef4f8d7bcac6dcb1947acafdb4420c2c3 upstream.
uni_reader_init() registers the shared IRQ before initializing
reader->irq_lock. A pending interrupt can invoke the handler while the
lock is still uninitialized.
Initialize the lock before registering the IRQ so the interrupt path
always sees valid lock state.
Fixes: d05d862ead8e ("ASoC: STI: Fix null ptr deference in IRQ handler")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260830142026.2666914-1-runyu.xiao@seu.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/sti/uniperif_reader.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/sound/soc/sti/uniperif_reader.c
+++ b/sound/soc/sti/uniperif_reader.c
@@ -421,6 +421,8 @@ int uni_reader_init(struct platform_devi
else
reader->hw = &uni_reader_pcm_hw;
+ spin_lock_init(&reader->irq_lock);
+
ret = devm_request_irq(&pdev->dev, reader->irq,
uni_reader_irq_handler, IRQF_SHARED,
dev_name(&pdev->dev), reader);
@@ -429,8 +431,6 @@ int uni_reader_init(struct platform_devi
return -EBUSY;
}
- spin_lock_init(&reader->irq_lock);
-
return 0;
}
EXPORT_SYMBOL_GPL(uni_reader_init);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 514/982] cpufreq: zero-initialize policy cpumask before sysfs publication
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (512 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 513/982] ASoC: sti: initialize IRQ lock before requesting IRQ Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 515/982] cpufreq: initialize policy rwsem " Greg Kroah-Hartman
` (474 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Viresh Kumar,
Rafael J. Wysocki
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
commit 54d37bcf2f497140b9207968557ddb484058e749 upstream.
cpufreq_policy_alloc() allocates policy->cpus with alloc_cpumask_var(),
i.e. without __GFP_ZERO, unlike the sibling related_cpus and real_cpus
masks. With CONFIG_CPUMASK_OFFSTACK=y the mask is a separate
kmalloc_node() allocation, so its bitmap holds whatever the slab allocator
left behind:
cpufreq_online()
cpufreq_policy_alloc()
alloc_cpumask_var(&policy->cpus) /* bitmap is uninitialized */
kobject_init_and_add() /* policy%u/ appears in sysfs */
cpufreq_policy_online()
cpumask_copy(policy->cpus, cpumask_of(cpu)) /* first valid value */
This leaves a window in which the sysfs attributes are already reachable
while policy->cpus is still garbage. show()/store() gate on
policy_is_inactive(), i.e. cpumask_empty(policy->cpus), so a non-zero
bitmap makes them run the attribute callbacks on a policy that is not
initialized yet.
Fix this by using zalloc_cpumask_var() for policy->cpus.
Fixes: 2fc3384dc75b ("cpufreq: Initialize policy->kobj while allocating policy")
Cc: All applicable <stable@vger.kernel.org>
Signed-off-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Acked-by: Viresh Kumar <viresh.kumar@linaro.org>
Link: https://patch.msgid.link/20260901143635.4106960-1-zhongqiu.han@oss.qualcomm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/cpufreq/cpufreq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/cpufreq/cpufreq.c
+++ b/drivers/cpufreq/cpufreq.c
@@ -1216,7 +1216,7 @@ static struct cpufreq_policy *cpufreq_po
if (!policy)
return NULL;
- if (!alloc_cpumask_var(&policy->cpus, GFP_KERNEL))
+ if (!zalloc_cpumask_var(&policy->cpus, GFP_KERNEL))
goto err_free_policy;
if (!zalloc_cpumask_var(&policy->related_cpus, GFP_KERNEL))
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 515/982] cpufreq: initialize policy rwsem before sysfs publication
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (513 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 514/982] cpufreq: zero-initialize policy cpumask before sysfs publication Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 516/982] exec: do_close_on_exec() before taking exec_update_lock Greg Kroah-Hartman
` (473 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Runyu Xiao,
Viresh Kumar, Rafael J. Wysocki
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 3e5d1bf4bd687beb2cb4e32a07af695455925588 upstream.
cpufreq_policy_alloc() initializes policy->rwsem after
kobject_init_and_add() has created the policy sysfs directory and its
default attributes. A sysfs access can therefore reach a policy callback
before the semaphore has been initialized.
Initialize policy->rwsem before publishing the policy kobject so sysfs
callbacks always see an initialized semaphore.
Fixes: 2fc3384dc75b ("cpufreq: Initialize policy->kobj while allocating policy")
Cc: All Applicable <stable@vger.kernel.org>
Link: https://lore.kernel.org/all/20260830155301.2713780-1-runyu.xiao@seu.edu.cn/
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Acked-by: Viresh Kumar <viresh.kumar@linaro.org>
Link: https://patch.msgid.link/20260902041915.3453421-1-runyu.xiao@seu.edu.cn
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/cpufreq/cpufreq.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/cpufreq/cpufreq.c
+++ b/drivers/cpufreq/cpufreq.c
@@ -1225,6 +1225,8 @@ static struct cpufreq_policy *cpufreq_po
if (!zalloc_cpumask_var(&policy->real_cpus, GFP_KERNEL))
goto err_free_rcpumask;
+ init_rwsem(&policy->rwsem);
+
init_completion(&policy->kobj_unregister);
ret = kobject_init_and_add(&policy->kobj, &ktype_cpufreq,
cpufreq_global_kobject, "policy%u", cpu);
@@ -1239,8 +1241,6 @@ static struct cpufreq_policy *cpufreq_po
goto err_free_real_cpus;
}
- init_rwsem(&policy->rwsem);
-
freq_constraints_init(&policy->constraints);
policy->nb_min.notifier_call = cpufreq_notifier_min;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 516/982] exec: do_close_on_exec() before taking exec_update_lock
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (514 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 515/982] cpufreq: initialize policy rwsem " Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 517/982] drm/i915: Fix memory leak in query_perf_config_list() Greg Kroah-Hartman
` (472 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Peterson, Jann Horn,
Jan Kara, Christian Brauner (Amutable)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jann Horn <jannh@google.com>
commit e780259b54e618ceb4763fbc21314acf3565e813 upstream.
do_close_on_exec() currently happens while holding the exec_update_lock,
which is used in a lot of places that access process state to
synchronize access checks.
I recently added another such use of exec_update_lock, causing a
regression.
do_close_on_exec() can block waiting for a reply from a filesystem.
That means a hung filesystem can block codepaths that use
exec_update_lock; and it also means that a FUSE filesystem which
attempts to inspect the calling process can deadlock.
To avoid such problems, move do_close_on_exec() before the
exec_update_lock is taken, but after the FD table has been copied if
necessary.
I have looked through all the calls between the old and new position of
the do_close_on_exec() call; there seems to be no file descriptor table
access in between.
Reported-by: Benjamin Peterson <benjamin@locrian.net>
Closes: https://lore.kernel.org/r/f5e8166a-88be-46c5-8939-1e5227ffe4c2@app.fastmail.com
Fixes: 6650527444da ("proc: protect ptrace_may_access() with exec_update_lock (part 1)")
Cc: stable@vger.kernel.org
Signed-off-by: Jann Horn <jannh@google.com>
Link: https://patch.msgid.link/20260907-cloexec-before-exec-update-lock-v1-1-8018c201a7df@google.com
Tested-by: Benjamin Peterson <benjamin@locrian.net>
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/exec.c | 22 ++++++++++++++--------
1 file changed, 14 insertions(+), 8 deletions(-)
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1279,6 +1279,20 @@ int begin_new_exec(struct linux_binprm *
goto out;
/*
+ * We have to apply CLOEXEC before we change whether the process is
+ * dumpable (in setup_new_exec) to avoid a race with a process in userspace
+ * trying to access the should-be-closed file descriptors of a process
+ * undergoing exec(2).
+ *
+ * This can block on filesystem ->flush() handlers, including waiting
+ * for FUSE daemons, so do it before exec_mmap takes the
+ * exec_update_lock.
+ * This must happen after the point of no return, and after unsharing
+ * the FD table.
+ */
+ do_close_on_exec(me->files);
+
+ /*
* Must be called _before_ exec_mmap() as bprm->mm is
* not visible until then. This also enables the update
* to be lockless.
@@ -1324,14 +1338,6 @@ int begin_new_exec(struct linux_binprm *
clear_syscall_work_syscall_user_dispatch(me);
- /*
- * We have to apply CLOEXEC before we change whether the process is
- * dumpable (in setup_new_exec) to avoid a race with a process in userspace
- * trying to access the should-be-closed file descriptors of a process
- * undergoing exec(2).
- */
- do_close_on_exec(me->files);
-
if (bprm->secureexec) {
/* Make sure parent cannot signal privileged process. */
me->pdeath_signal = 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 517/982] drm/i915: Fix memory leak in query_perf_config_list()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (515 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 516/982] exec: do_close_on_exec() before taking exec_update_lock Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 518/982] ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters() Greg Kroah-Hartman
` (471 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Andi Shyti,
Jani Nikula
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
commit cbd3dafc2003db679ccd2f6c6a2551db79657049 upstream.
When krealloc() fails, free the original oa_config_ids before returning
to avoid a memory leak.
Fixes: 4f6ccc74a85c ("drm/i915: add support for perf configuration queries")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Cc: <stable@vger.kernel.org> # v5.5+
Reviewed-by: Andi Shyti <andi.shyti@linux.intel.com>
Signed-off-by: Andi Shyti <andi.shyti@linux.intel.com>
Link: https://patch.msgid.link/20260823205028.178597-2-thorsten.blum@linux.dev
(cherry picked from commit 9977e9d84f46d4f12ad35fbbc0ec4638554bce87)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/i915_query.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/i915/i915_query.c
+++ b/drivers/gpu/drm/i915/i915_query.c
@@ -400,8 +400,10 @@ static int query_perf_config_list(struct
ids = krealloc(oa_config_ids,
n_configs * sizeof(*oa_config_ids),
GFP_KERNEL);
- if (!ids)
+ if (!ids) {
+ kfree(oa_config_ids);
return -ENOMEM;
+ }
alloc = fetch_and_zero(&n_configs);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 518/982] ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (516 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 517/982] drm/i915: Fix memory leak in query_perf_config_list() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 519/982] net: hso: fix TIOCMIWAIT race Greg Kroah-Hartman
` (470 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vincent Donnefort,
Sebastian Andrzej Siewior, Steven Rostedt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
commit 815e07c8fe885a87751c2496a30ae0dcd4118210 upstream.
rb_wake_up_waiters() is a irq_work callback which is initialized with
init_irq_work(). As such it will be invoked in thread context on
PREEMPT_RT. Invoking the callback in IRQ context on PREEMPT_RT is not an
option due its usage of wake_up_all(). Since this callback may run in
thread context, it needs to acquire ring_buffer_per_cpu::reader_lock with
disabling interrupts and may not assume that they are disabled.
Use raw_spinlock_irqsave() to acquire ring_buffer_per_cpu::reader_lock.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260911102152.YEtwkBj9@linutronix.de
Fixes: 68282dd930ea3 ("ring-buffer: Fix resetting of shortest_full")
Reviewed-by: Vincent Donnefort <vdonnefort@google.com>
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/ring_buffer.c | 13 ++++++-------
1 file changed, 6 insertions(+), 7 deletions(-)
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -912,14 +912,13 @@ static void rb_wake_up_waiters(struct ir
struct ring_buffer_per_cpu *cpu_buffer =
container_of(rbwork, struct ring_buffer_per_cpu, irq_work);
- /* Called from interrupt context */
- raw_spin_lock(&cpu_buffer->reader_lock);
- rbwork->wakeup_full = false;
- rbwork->full_waiters_pending = false;
+ scoped_guard(raw_spinlock_irqsave, &cpu_buffer->reader_lock) {
+ rbwork->wakeup_full = false;
+ rbwork->full_waiters_pending = false;
- /* Waking up all waiters, they will reset the shortest full */
- cpu_buffer->shortest_full = 0;
- raw_spin_unlock(&cpu_buffer->reader_lock);
+ /* Waking up all waiters, they will reset the shortest full */
+ cpu_buffer->shortest_full = 0;
+ }
wake_up_all(&rbwork->full_waiters);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 519/982] net: hso: fix TIOCMIWAIT race
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (517 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 518/982] ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters() Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 520/982] net: mpls: clear inner_protocol when the last label is popped Greg Kroah-Hartman
` (469 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johan Hovold, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit 00f9fbc12320253bfc576fb7539d860029c82d0f upstream.
The task state must be updated before checking the wakeup condition to
avoid missing a racing modem status update.
Fixes: 542f54823614 ("tty: Modem functions for the HSO driver")
Cc: stable@vger.kernel.org # 2.6.29
Signed-off-by: Johan Hovold <johan@kernel.org>
Link: https://patch.msgid.link/20260907065235.100848-1-johan@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/hso.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/usb/hso.c
+++ b/drivers/net/usb/hso.c
@@ -1555,10 +1555,10 @@ hso_wait_modem_status(struct hso_serial
spin_unlock_irq(&serial->serial_lock);
add_wait_queue(&tiocmget->waitq, &wait);
for (;;) {
+ set_current_state(TASK_INTERRUPTIBLE);
spin_lock_irq(&serial->serial_lock);
memcpy(&cnow, &tiocmget->icount, sizeof(struct uart_icount));
spin_unlock_irq(&serial->serial_lock);
- set_current_state(TASK_INTERRUPTIBLE);
if (((arg & TIOCM_RNG) && (cnow.rng != cprev.rng)) ||
((arg & TIOCM_DSR) && (cnow.dsr != cprev.dsr)) ||
((arg & TIOCM_CD) && (cnow.dcd != cprev.dcd))) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 520/982] net: mpls: clear inner_protocol when the last label is popped
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (518 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 519/982] net: hso: fix TIOCMIWAIT race Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 521/982] net: openvswitch: fix use-after-free of the flow table mask array Greg Kroah-Hartman
` (468 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fourie Zhang, Jiri Benc,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fourie Zhang <littleddfu@gmail.com>
commit 78a86d75a70e1e227711c72865c59b1422d0a5ae upstream.
skb_mpls_push() records the pre-encapsulation network header once, gated
on !skb->inner_protocol. skb_mpls_pop() never clears that record, so it
outlives the encapsulation it describes.
Open vSwitch can then re-push MPLS onto a packet whose
inner_network_header still points at the older, deeper offset: push a
label, pop every label, recirculate (ovs_flow_key_update() re-derives
key->eth.type and resets network_header, but leaves inner_*), then push
again. ovs_fragment() trusts the record:
skb->network_header = skb->inner_network_header;
so skb_network_offset() goes negative. The bound check is signed:
if (skb_network_offset(skb) > MAX_L2_LEN)
a negative offset passes it, and prepare_frag() widens the value:
unsigned int hlen = skb_network_offset(skb);
memcpy(&data->l2_data, skb->data, hlen);
which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.
Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):
BUG: unable to handle page fault for address: ffffe8ffffc16000
#PF: supervisor write access in kernel mode
Oops: 0002 [#1] SMP KASAN NOPTI
RIP: 0010:memcpy+0x8/0x20
RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000
prepare_frag+0x3df/0x4e0
ovs_fragment+0x589/0x7e0
do_output+0x4ce/0x5e0
do_execute_actions+0x55d2/0x7b30
ovs_execute_actions+0xea/0x450
Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network
header before routing and forwarding"): a stale network header offset
reaching a consumer that widens it. Here it originates in the MPLS
push/pop path.
Clear inner_protocol once the packet is no longer MPLS, so a later push
re-records the current header. net/sched/act_mpls.c is the only other
skb_mpls_pop() caller and gets the same fix; sch_frag.c saves and
restores inner_protocol around fragmentation in the same way OVS does.
Fixes: 48d2ab609b6b ("net: mpls: Fixups for GSO")
Cc: stable@vger.kernel.org
Signed-off-by: Fourie Zhang <fouriezhang@tencent.com>
Acked-by: Jiri Benc <jbenc@redhat.com>
Link: https://patch.msgid.link/20260902092719.2874481-1-fouriezhang@tencent.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/core/skbuff.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -6085,6 +6085,13 @@ int skb_mpls_pop(struct sk_buff *skb, __
}
skb->protocol = next_proto;
+ /* The last label is gone, so the inner header recorded by
+ * skb_mpls_push() no longer describes this packet. Drop it, or a
+ * later push keeps the stale offset.
+ */
+ if (!eth_p_mpls(next_proto))
+ skb->inner_protocol = 0;
+
return 0;
}
EXPORT_SYMBOL_GPL(skb_mpls_pop);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 521/982] net: openvswitch: fix use-after-free of the flow table mask array
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (519 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 520/982] net: mpls: clear inner_protocol when the last label is popped Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 522/982] netfilter: nf_log: unregister loggers before per-net teardown Greg Kroah-Hartman
` (467 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Ilya Maximets,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
commit ba4ba11ed6eb8972c69070417fc27b48deb002e8 upstream.
tbl_mask_array_realloc() retires the old mask_array before it stops being
reachable:
old = ovsl_dereference(tbl->mask_array);
if (old) {
...
call_rcu(&old->rcu, mask_array_rcu_cb);
}
rcu_assign_pointer(tbl->mask_array, new);
call_rcu() only waits for read-side critical sections already in flight.
tbl->mask_array still points at old between the call_rcu() and the
rcu_assign_pointer(), so a reader entering ovs_flow_tbl_lookup_stats() in
that window picks up old in a fresh critical section that the pending
grace period does not cover.
tbl_mask_array_realloc() runs in process context under ovs_mutex, so the
window is preemptible and can outlast the grace period. Then
mask_array_rcu_cb() frees old before the swap runs:
BUG: KASAN: slab-use-after-free in flow_lookup.constprop.0+0x2bf/0x2f0
Read of size 8 at addr ffff888020b3e018 by task poc/741
flow_lookup.constprop.0+0x2bf/0x2f0
ovs_flow_tbl_lookup_stats+0x4a3/0x5c0
ovs_dp_process_packet+0x19c/0x710
ovs_vport_receive+0x243/0x390
internal_dev_xmit+0x81/0x170
Freed by task 728:
kfree+0x16a/0x4e0
rcu_core+0x853/0x1030
Publish the new array before retiring the old one. The kfree_rcu() that
call_rcu() replaced ran after the swap.
Fixes: eac87c413bf9 ("net: openvswitch: reorder masks array based on usage")
Cc: stable@vger.kernel.org
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Acked-by: Eelco Chaudron echaudro@redhat.com
Link: https://patch.msgid.link/DE115F9C-2545-423E-A702-986FC952FD62@doyensec.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/flow_table.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/openvswitch/flow_table.c
+++ b/net/openvswitch/flow_table.c
@@ -261,11 +261,13 @@ static int tbl_mask_array_realloc(struct
if (ovsl_dereference(old->masks[i]))
new->masks[new->count++] = old->masks[i];
}
- call_rcu(&old->rcu, mask_array_rcu_cb);
}
rcu_assign_pointer(tbl->mask_array, new);
+ if (old)
+ call_rcu(&old->rcu, mask_array_rcu_cb);
+
return 0;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 522/982] netfilter: nf_log: unregister loggers before per-net teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (520 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 521/982] net: openvswitch: fix use-after-free of the flow table mask array Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:20 ` [PATCH 6.1 523/982] netfilter: report NLM_F_DUMP_FILTERED when all is filtered out Greg Kroah-Hartman
` (466 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Pablo Neira Ayuso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 2c018cc4842c33f0c732962e2ab58635e8ae5823 upstream.
nf_log_syslog and nfnetlink_log unregister their per-network namespace
operations before unregistering their global logger backends. This
leaves a window where a sysctl or netlink writer can rebind the still-
registered logger after the per-net pre-exit callback cleared the old
selection.
The race looks like this:
CPU 0 CPU 1
---- ----
unregister_pernet_subsys()
nf_log_unset(net, logger)
net->nf.nf_loggers[pf] = NULL
lock nf_log_mutex
find logger in loggers[][]
net->nf.nf_loggers[pf] = logger
unlock nf_log_mutex
nf_log_unregister(logger)
lock nf_log_mutex
loggers[pf][type] = NULL
unlock nf_log_mutex
synchronize_rcu()
module exit returns
module core frees backend memory
Later, a sysctl read or packet logging operation can dereference the
stale per-net logger pointer.
Fix this by unregistering the global logger backends before tearing down
per-net state. Once the global registrations are gone, later writers can
no longer rebind the logger. unregister_pernet_subsys() already waits
for an RCU grace period after the pre-exit callback clears the per-net
selection, while nf_log_unregister() continues to cover readers of the
global logger table.
Apply this ordering fix to both nf_log backends that combine per-net
teardown with global logger registration.
Fixes: 5b023fc8d8e0 ("netfilter: enable per netns support for nf_loggers")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/nf_log_syslog.c | 2 +-
net/netfilter/nfnetlink_log.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
--- a/net/netfilter/nf_log_syslog.c
+++ b/net/netfilter/nf_log_syslog.c
@@ -1063,12 +1063,12 @@ err1:
static void __exit nf_log_syslog_exit(void)
{
- unregister_pernet_subsys(&nf_log_syslog_net_ops);
nf_log_unregister(&nf_ip_logger);
nf_log_unregister(&nf_arp_logger);
nf_log_unregister(&nf_ip6_logger);
nf_log_unregister(&nf_netdev_logger);
nf_log_unregister(&nf_bridge_logger);
+ unregister_pernet_subsys(&nf_log_syslog_net_ops);
}
module_init(nf_log_syslog_init);
--- a/net/netfilter/nfnetlink_log.c
+++ b/net/netfilter/nfnetlink_log.c
@@ -1197,8 +1197,8 @@ static void __exit nfnetlink_log_fini(vo
{
nfnetlink_subsys_unregister(&nfulnl_subsys);
netlink_unregister_notifier(&nfulnl_rtnl_notifier);
- unregister_pernet_subsys(&nfnl_log_net_ops);
nf_log_unregister(&nfulnl_logger);
+ unregister_pernet_subsys(&nfnl_log_net_ops);
}
MODULE_DESCRIPTION("netfilter userspace logging");
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 523/982] netfilter: report NLM_F_DUMP_FILTERED when all is filtered out
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (521 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 522/982] netfilter: nf_log: unregister loggers before per-net teardown Greg Kroah-Hartman
@ 2026-09-30 15:20 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 524/982] fbdev: vfb: defer cleanup until the last reference Greg Kroah-Hartman
` (465 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:20 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Florian Westphal,
Pablo Neira Ayuso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit 7a099b347fef536a84068076e2d384f044e5cfc5 upstream.
NLM_F_DUMP_FILTERED is only set on data elements in the conntrack dump.
But when everything is filtered out it is confusing for the user space,
since the flag is not reported anymore and it looks like the table was
empty, which may or may not be the case.
'answer_flags' were introduced precisely for this use case, and the
conntrack dump should set the flag in there in case the filtering was
applied.
This is important, for example, to be able to tell if the filters are
supported or not by the kernel without modifying the kernel state.
With the proper reporting of NLM_F_DUMP_FILTERED on NLMSG_DONE, an
application in user space can just try and dump with an arbitrary
filter without worrying that there could be no matching entry. The
reported flag will signal that the filtering was applied and therefore
supported.
Fixes: cb8aa9a3affb ("netfilter: ctnetlink: add kernel side filtering for dump")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/nf_conntrack_netlink.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -1048,6 +1048,8 @@ static int ctnetlink_start(struct netlin
}
cb->data = filter;
+ if (filter)
+ cb->answer_flags = NLM_F_DUMP_FILTERED;
return 0;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 524/982] fbdev: vfb: defer cleanup until the last reference
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (522 preceding siblings ...)
2026-09-30 15:20 ` [PATCH 6.1 523/982] netfilter: report NLM_F_DUMP_FILTERED when all is filtered out Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 525/982] ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink Greg Kroah-Hartman
` (464 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+c25629c98ba36ebe, stable,
Weiming Shi, Helge Deller
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit a0a34a40ed299c9c7cff6af163a5b883ee9d6d73 upstream.
FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the
usercopy after dropping info->lock. vfb_remove() frees the colormap
immediately after unregistering the framebuffer, even when an open file
still holds a reference to fb_info. A concurrent driver unbind can
therefore free the colormap while the ioctl copies it to userspace.
KASAN reports:
BUG: KASAN: slab-use-after-free in _copy_to_user
Read of size 512 by task poc/125
_copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24)
fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211)
do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114)
Allocated by task 1:
fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108)
vfb_probe (drivers/video/fbdev/vfb.c:459)
Freed by task 124:
fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151)
vfb_remove (drivers/video/fbdev/vfb.c:489)
unregister_framebuffer() drops the registration reference, and fbdev calls
fb_destroy after the last put_fb_info(). Move the registered framebuffer's
cleanup into an fb_destroy callback so its colormap and screen buffer stay
alive until all file references have been released.
Fixes: 5e266e2e0e19 ("vfb: fix memory leaks in removal path")
Reported-by: co+c25629c98ba36ebe@bugs.sh
Cc: stable@kernel.org
Closes: https://lore.kernel.org/linux-fbdev/f2Kf9GYn1lKR5S1dbvGVtykMxK1RlgP5z8sW@bugs.sh/
Assisted-by: Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://lore.kernel.org/linux-fbdev/f2Kf9GYn1lKR5S1dbvGVtykMxK1RlgP5z8sW@bugs.sh/
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/video/fbdev/vfb.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/drivers/video/fbdev/vfb.c
+++ b/drivers/video/fbdev/vfb.c
@@ -78,6 +78,13 @@ static int vfb_pan_display(struct fb_var
static int vfb_mmap(struct fb_info *info,
struct vm_area_struct *vma);
+static void vfb_destroy(struct fb_info *info)
+{
+ vfree(info->screen_buffer);
+ fb_dealloc_cmap(&info->cmap);
+ framebuffer_release(info);
+}
+
static const struct fb_ops vfb_ops = {
.fb_read = fb_sys_read,
.fb_write = fb_sys_write,
@@ -89,6 +96,7 @@ static const struct fb_ops vfb_ops = {
.fb_copyarea = sys_copyarea,
.fb_imageblit = sys_imageblit,
.fb_mmap = vfb_mmap,
+ .fb_destroy = vfb_destroy,
};
/*
@@ -485,9 +493,6 @@ static int vfb_remove(struct platform_de
if (info) {
unregister_framebuffer(info);
- vfree(videomemory);
- fb_dealloc_cmap(&info->cmap);
- framebuffer_release(info);
}
return 0;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 525/982] ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (523 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 524/982] fbdev: vfb: defer cleanup until the last reference Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 526/982] ipv4: fib: bound automatic table ID allocation Greg Kroah-Hartman
` (463 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Stefan Schmidt
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit bf79662bc85e820ac3b846e2f347da29fbf6ac95 upstream.
TUNSETLINK allows a TUN device to change its link-layer type to
ARPHRD_IEEE802154 without initializing ieee802154_ptr. lowpan_newlink()
checks only the device type before dereferencing the pointer, so an
RTM_NEWLINK request can trigger a NULL pointer dereference.
Reject devices without ieee802154_ptr along with devices of the wrong type.
Fixes: 51e0e5d8124e ("ieee802154: 6lowpan: remove multiple lowpan per wpan support")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Link: https://lore.kernel.org/0b715da69bd15a86ddc47dad5cf12da648211050.1787997209.git.zhilinz@nebusec.ai
Signed-off-by: Stefan Schmidt <stefan@datenfreihafen.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ieee802154/6lowpan/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/ieee802154/6lowpan/core.c
+++ b/net/ieee802154/6lowpan/core.c
@@ -146,7 +146,7 @@ static int lowpan_newlink(struct net *sr
wdev = dev_get_by_index(dev_net(ldev), nla_get_u32(tb[IFLA_LINK]));
if (!wdev)
return -ENODEV;
- if (wdev->type != ARPHRD_IEEE802154) {
+ if (wdev->type != ARPHRD_IEEE802154 || !wdev->ieee802154_ptr) {
dev_put(wdev);
return -EINVAL;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 526/982] ipv4: fib: bound automatic table ID allocation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (524 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 525/982] ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 527/982] ipvs: reject invalid states in connection template sync records Greg Kroah-Hartman
` (462 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Ido Schimmel, Zihan Xi,
Petr Vorel, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit efdfb1e27a3328085b79540dfe781d537b576ea1 upstream.
fib_empty_table() probes every table ID from 1 until it finds a
free one. IPv4 tables are stored in a 256-bucket hash table, so a
dense set of IDs makes each probe walk a growing hash chain while
RTNL is held.
Automatic table assignment ("ip rule ... table 0") is an IPv4-only
legacy path. Bound the automatically allocated ID to 4096 so the
RTNL hold stays bounded, without changing lookups of explicitly
specified table IDs.
This changes user-visible behavior. A table-0 rule previously
received the lowest free ID in 1..RT_TABLE_MAX (0xFFFFFFFF). After
this patch the search stops at 4096 and the rule add fails with
ENOBUFS if that range is fully occupied. Explicit table IDs above
4096 remain usable.
The automatic path is unused in practice: it is IPv4-only, not
documented by ip-rule, uncovered by kernel selftests, and both
NetworkManager and systemd refuse table 0.
Fixes: b801f54917b7 ("[NET]: Increate RT_TABLE_MAX to 2^32")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Petr Vorel <pvorel@suse.cz>
Link: https://patch.msgid.link/6f2f2a7a136aee005512a2e1ac8ede62ac8c7bb6.1788258884.git.zihanx@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/fib_rules.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/ipv4/fib_rules.c
+++ b/net/ipv4/fib_rules.c
@@ -203,6 +203,8 @@ INDIRECT_CALLABLE_SCOPE int fib4_rule_ma
return 1;
}
+#define FIB_MAX_AUTO_TABLE_ID 4096
+
static struct fib_table *fib_empty_table(struct net *net)
{
u32 id = 1;
@@ -211,7 +213,7 @@ static struct fib_table *fib_empty_table
if (!fib_get_table(net, id))
return fib_new_table(net, id);
- if (id++ == RT_TABLE_MAX)
+ if (id++ == FIB_MAX_AUTO_TABLE_ID)
break;
}
return NULL;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 527/982] ipvs: reject invalid states in connection template sync records
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (525 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 526/982] ipv4: fib: bound automatic table ID allocation Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 528/982] KVM: PPC: Book3S HV: Set irqfd->producer only on success Greg Kroah-Hartman
` (461 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, Julian Anastasov,
Pablo Neira Ayuso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
commit 74cb39735b6cd0aff4b5584158f09376fd97aadf upstream.
IPVS sync receivers validate protocol states before creating or updating a
connection. For connection templates, however, they only log states outside
the template state range and still store the value in the connection.
A template can be returned by ordinary connection lookup. TCP and SCTP then
use the invalid state as an index into their transition tables.
Reject invalid template states in both sync protocol versions before
looking up or modifying a connection. The version 1 path handles both
IPv4 and IPv6 records.
Fixes: 275411430f89 ("ipvs: add assured state for conn templates")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Acked-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/ipvs/ip_vs_sync.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
--- a/net/netfilter/ipvs/ip_vs_sync.c
+++ b/net/netfilter/ipvs/ip_vs_sync.c
@@ -1000,10 +1000,10 @@ static void ip_vs_process_message_v0(str
pp->name, state);
continue;
}
- } else {
- if (state >= IP_VS_CTPL_S_LAST)
- IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
- state);
+ } else if (state >= IP_VS_CTPL_S_LAST) {
+ IP_VS_DBG(7, "BACKUP v0, Invalid tpl state %u\n",
+ state);
+ continue;
}
ip_vs_conn_fill_param(ipvs, AF_INET, s->protocol,
@@ -1160,10 +1160,10 @@ static inline int ip_vs_proc_sync_conn(s
retc = 40;
goto out;
}
- } else {
- if (state >= IP_VS_CTPL_S_LAST)
- IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n",
- state);
+ } else if (state >= IP_VS_CTPL_S_LAST) {
+ IP_VS_DBG(7, "BACKUP, Invalid tpl state %u\n", state);
+ retc = 40;
+ goto out;
}
if (ip_vs_conn_fill_param_sync(ipvs, af, s, ¶m, pe_data,
pe_data_len, pe_name, pe_name_len)) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 528/982] KVM: PPC: Book3S HV: Set irqfd->producer only on success
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (526 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 527/982] ipvs: reject invalid states in connection template sync records Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 529/982] s390/qeth: allow bridgeport queries despite OS_MISMATCH Greg Kroah-Hartman
` (460 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson, leixiang,
Amit Machhiwal, Vaibhav Jain, Madhavan Srinivasan
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: leixiang <leixiang@kylinos.cn>
commit 1144454ea22290d7c6998a2af6239e5995476afc upstream.
Set irqfd->producer only after kvmppc_set_passthru_irq() succeeds to
avoid leaving a dangling pointer on failure. The bypass manager does
not register a failed producer, so the pointer is never cleared.
Fixes: c57875f5f9be ("KVM: PPC: Book3S HV: Enable IRQ bypass")
Suggested-by: Sean Christopherson <seanjc@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: leixiang <leixiang@kylinos.cn>
Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Reviewed-by: Vaibhav Jain <vaibhav@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260709055755.31297-1-leixiang@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/powerpc/kvm/book3s_hv.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/powerpc/kvm/book3s_hv.c
+++ b/arch/powerpc/kvm/book3s_hv.c
@@ -5756,12 +5756,12 @@ static int kvmppc_irq_bypass_add_produce
struct kvm_kernel_irqfd *irqfd =
container_of(cons, struct kvm_kernel_irqfd, consumer);
- irqfd->producer = prod;
-
ret = kvmppc_set_passthru_irq(irqfd->kvm, prod->irq, irqfd->gsi);
if (ret)
pr_info("kvmppc_set_passthru_irq (irq %d, gsi %d) fails: %d\n",
prod->irq, irqfd->gsi, ret);
+ else
+ irqfd->producer = prod;
return ret;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 529/982] s390/qeth: allow bridgeport queries despite OS_MISMATCH
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (527 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 528/982] KVM: PPC: Book3S HV: Set irqfd->producer only on success Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 530/982] s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm Greg Kroah-Hartman
` (459 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Halil Pasic, Alexandra Winter,
Nagamani PV, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nagamani PV <nagamani@linux.ibm.com>
commit 74f27fc8642b7e8d139796f8c18ee46df393c2b2 upstream.
When HiperSockets interfaces on the same VCHID span different OS
families, reads of the sysfs attributes bridge_role and bridge_state
fail with -EPERM if bridge port ownership belongs to another OS family.
As a result, userspace tools such as 'lszdev -ii' cannot retrieve
bridge_role and bridge_state, even though firmware returns valid bridge
port data for QUERY_BRIDGE_PORTS requests.
The firmware reports IPA_RC_SBP_IQD_OS_MISMATCH (0x0010) to indicate
that bridge port ownership belongs to a different OS family. For
QUERY_BRIDGE_PORTS operations, firmware still returns valid bridge port
data (role=none, state=inactive) together with a primary return code of
0x0000 (success).
Allow QUERY_BRIDGE_PORTS requests to return the bridge port data
provided by the firmware despite OS_MISMATCH. To make the OS family
mismatch visible to userspace, represent the firmware-reported role
"none" as "none (OS family mismatch)" while preserving the reported
bridge_state.
The behavior for non-QUERY bridge port commands is unchanged; SET
operations continue to return -EPERM when another OS family owns the
bridge port.
This restores readability of bridge_role and bridge_state.
Fixes: 1b05cf6285c1 ("qeth: Include error message for "OS Mismatch"")
Cc: stable@vger.kernel.org
Suggested-by: Halil Pasic <pasic@linux.ibm.com>
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Signed-off-by: Nagamani PV <nagamani@linux.ibm.com>
Link: https://patch.msgid.link/20260901155344.3561483-1-nagamani@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/net/qeth_l2.h | 3 ++-
drivers/s390/net/qeth_l2_main.c | 26 ++++++++++++++++++++++----
drivers/s390/net/qeth_l2_sys.c | 7 ++++++-
3 files changed, 30 insertions(+), 6 deletions(-)
--- a/drivers/s390/net/qeth_l2.h
+++ b/drivers/s390/net/qeth_l2.h
@@ -13,7 +13,8 @@ extern const struct attribute_group *qet
int qeth_bridgeport_query_ports(struct qeth_card *card,
enum qeth_sbp_roles *role,
- enum qeth_sbp_states *state);
+ enum qeth_sbp_states *state,
+ bool *os_mismatch);
int qeth_bridgeport_setrole(struct qeth_card *card, enum qeth_sbp_roles role);
int qeth_bridgeport_an_set(struct qeth_card *card, int enable);
--- a/drivers/s390/net/qeth_l2_main.c
+++ b/drivers/s390/net/qeth_l2_main.c
@@ -1157,7 +1157,7 @@ static void qeth_l2_setup_bridgeport_att
qeth_bridgeport_setrole(card, card->options.sbp.role);
/* Let the callback function refresh the stored role value. */
qeth_bridgeport_query_ports(card, &card->options.sbp.role,
- NULL);
+ NULL, NULL);
}
if (card->options.sbp.hostnotification) {
if (qeth_bridgeport_an_set(card, 1))
@@ -1543,6 +1543,7 @@ struct _qeth_sbp_cbctl {
struct {
enum qeth_sbp_roles *role;
enum qeth_sbp_states *state;
+ bool *os_mismatch;
} qports;
} data;
};
@@ -1719,10 +1720,19 @@ static int qeth_bridgeport_query_ports_c
struct qeth_ipa_cmd *cmd = (struct qeth_ipa_cmd *) data;
struct _qeth_sbp_cbctl *cbctl = (struct _qeth_sbp_cbctl *)reply->param;
struct qeth_sbp_port_data *qports;
+ u16 sbp_rc;
int rc;
QETH_CARD_TEXT(card, 2, "brqprtcb");
- rc = qeth_bridgeport_makerc(card, cmd);
+ sbp_rc = cmd->data.sbp.hdr.return_code;
+
+ /* on OS family mismatch, query still returns valid port data;
+ * treat as success
+ */
+ if (sbp_rc == IPA_RC_SBP_IQD_OS_MISMATCH && !cmd->hdr.return_code)
+ rc = 0;
+ else
+ rc = qeth_bridgeport_makerc(card, cmd);
if (rc)
return rc;
@@ -1738,6 +1748,9 @@ static int qeth_bridgeport_query_ports_c
if (cbctl->data.qports.state)
*cbctl->data.qports.state = qports->entry[0].state;
}
+ if (cbctl->data.qports.os_mismatch)
+ *cbctl->data.qports.os_mismatch =
+ (sbp_rc == IPA_RC_SBP_IQD_OS_MISMATCH);
return 0;
}
@@ -1746,13 +1759,17 @@ static int qeth_bridgeport_query_ports_c
* @card: qeth_card structure pointer.
* @role: Role of the port: 0-none, 1-primary, 2-secondary.
* @state: State of the port: 0-inactive, 1-standby, 2-active.
+ * @os_mismatch: if non-NULL, set to true when firmware reports
+ * OS family mismatch.
*
* Returns negative errno-compatible error indication or 0 on success.
*
- * 'role' and 'state' are not updated in case of hardware operation failure.
+ * 'role', 'state' and 'os_mismatch' are not updated in case of
+ * hardware operation failure.
*/
int qeth_bridgeport_query_ports(struct qeth_card *card,
- enum qeth_sbp_roles *role, enum qeth_sbp_states *state)
+ enum qeth_sbp_roles *role, enum qeth_sbp_states *state,
+ bool *os_mismatch)
{
struct qeth_cmd_buffer *iob;
struct _qeth_sbp_cbctl cbctl = {
@@ -1760,6 +1777,7 @@ int qeth_bridgeport_query_ports(struct q
.qports = {
.role = role,
.state = state,
+ .os_mismatch = os_mismatch,
},
},
};
--- a/drivers/s390/net/qeth_l2_sys.c
+++ b/drivers/s390/net/qeth_l2_sys.c
@@ -15,6 +15,7 @@ static ssize_t qeth_bridge_port_role_sta
{
struct qeth_card *card = dev_get_drvdata(dev);
enum qeth_sbp_states state = QETH_SBP_STATE_INACTIVE;
+ bool os_mismatch = false;
int rc = 0;
char *word;
@@ -25,7 +26,7 @@ static ssize_t qeth_bridge_port_role_sta
if (qeth_card_hw_is_reachable(card) &&
card->options.sbp.supported_funcs)
rc = qeth_bridgeport_query_ports(card,
- &card->options.sbp.role, &state);
+ &card->options.sbp.role, &state, &os_mismatch);
if (!rc) {
if (show_state)
switch (state) {
@@ -52,6 +53,10 @@ static ssize_t qeth_bridge_port_role_sta
if (rc)
QETH_CARD_TEXT_(card, 2, "SBP%02x:%02x",
card->options.sbp.role, state);
+ else if (!show_state &&
+ card->options.sbp.role == QETH_SBP_ROLE_NONE &&
+ os_mismatch)
+ rc = sysfs_emit(buf, "%s (OS family mismatch)\n", word);
else
rc = sprintf(buf, "%s\n", word);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 530/982] s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (528 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 529/982] s390/qeth: allow bridgeport queries despite OS_MISMATCH Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 531/982] hwmon: (applesmc) fix key backlight workqueue leak on register failure Greg Kroah-Hartman
` (458 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Harald Freudenberger, Holger Dengler,
Heiko Carstens, Vasily Gorbik
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Harald Freudenberger <freude@linux.ibm.com>
commit 8b7c3b6914f19caf648d05726a86af6326d3c2c6 upstream.
In function ctr_aes_crypt() there is a buffer used to process
remaining bytes < AES_BLOCK_SIZE. This buffer was not scrubbed and
thus could lead to expose of unwanted data. When the buffer is used
explicitly scrub it at the end of the code block to avoid exposure of
maybe sensitive data.
In a similar way the function gcm_aes_crypt() hat an error path where
the CPACF param block was not scrubbed. Instead of return early now
these error paths go to end of function where explicit scrubbing is
done. Similar with the buffers which are part of the gcm_sg_walk
structs from the variables gw_in and gw_out.
Fixes: d07f951903fa ("crypto: s390/aes - Fix buffer overread in CTR mode")
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Reviewed-by: Holger Dengler <dengler@linux.ibm.com>
Cc: stable@vger.kernel.org # 6.8+
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/crypto/aes_s390.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
--- a/arch/s390/crypto/aes_s390.c
+++ b/arch/s390/crypto/aes_s390.c
@@ -608,6 +608,7 @@ static int ctr_aes_crypt(struct skcipher
memcpy(walk.dst.virt.addr, buf, nbytes);
crypto_inc(walk.iv, AES_BLOCK_SIZE);
ret = skcipher_walk_done(&walk, 0);
+ memzero_explicit(buf, sizeof(buf));
}
return ret;
@@ -909,10 +910,14 @@ static int gcm_aes_crypt(struct aead_req
gw_in.ptr, aad_bytes);
n = aad_bytes + pc_bytes;
- if (gcm_in_walk_done(&gw_in, n) != n)
- return -ENOMEM;
- if (gcm_out_walk_done(&gw_out, n) != n)
- return -ENOMEM;
+ if (gcm_in_walk_done(&gw_in, n) != n) {
+ ret = -ENOMEM;
+ goto out;
+ }
+ if (gcm_out_walk_done(&gw_out, n) != n) {
+ ret = -ENOMEM;
+ goto out;
+ }
aadlen -= aad_bytes;
pclen -= pc_bytes;
} while (aadlen + pclen > 0);
@@ -924,7 +929,10 @@ static int gcm_aes_crypt(struct aead_req
} else
scatterwalk_map_and_copy(param.t, req->dst, len, taglen, 1);
+out:
memzero_explicit(¶m, sizeof(param));
+ memzero_explicit(gw_in.buf, sizeof(gw_in.buf));
+ memzero_explicit(gw_out.buf, sizeof(gw_out.buf));
return ret;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 531/982] hwmon: (applesmc) fix key backlight workqueue leak on register failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (529 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 530/982] s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 532/982] hwmon: (gpio-fan) Fix use-after-free in alarm work Greg Kroah-Hartman
` (457 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
commit 5a0aacaa2d593d7582ecfe289529b937b6dc5d3c upstream.
applesmc_create_key_backlight() allocates applesmc_led_wq before calling
led_classdev_register(). When register fails, the error is returned to
applesmc_init(), which jumps to out_light_sysfs and skips
applesmc_release_key_backlight(), leaking the workqueue.
Destroy the workqueue on the register failure path. The bug was introduced
when the inline init block was refactored into a helper that returns errors
directly, dropping the old out_light_wq unwind label.
Fixes: 0b0b5dff8967 ("hwmon: (applesmc) Simplify feature sysfs handling")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Link: https://patch.msgid.link/20260828105413.2401385-1-congnt264@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/applesmc.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/applesmc.c
+++ b/drivers/hwmon/applesmc.c
@@ -1249,12 +1249,17 @@ static void applesmc_release_light_senso
static int applesmc_create_key_backlight(void)
{
+ int ret;
+
if (!smcreg.has_key_backlight)
return 0;
applesmc_led_wq = create_singlethread_workqueue("applesmc-led");
if (!applesmc_led_wq)
return -ENOMEM;
- return led_classdev_register(&pdev->dev, &applesmc_backlight);
+ ret = led_classdev_register(&pdev->dev, &applesmc_backlight);
+ if (ret)
+ destroy_workqueue(applesmc_led_wq);
+ return ret;
}
static void applesmc_release_key_backlight(void)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 532/982] hwmon: (gpio-fan) Fix use-after-free in alarm work
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (530 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 531/982] hwmon: (applesmc) fix key backlight workqueue leak on register failure Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 533/982] hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS Greg Kroah-Hartman
` (456 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit a2471ed17b0e6ff7bfb6b2ea8e6e5b04c309d293 upstream.
fan_alarm_irq_handler() queues fan_data->alarm_work, but nothing
cancels it. fan_alarm_notify() dereferences fan_data and its hwmon
device. On unbind, devres frees the interrupt, which only waits for
the handler itself, and then releases the hwmon device and fan_data,
so a pending fan_alarm_notify() can run after those frees.
Replace INIT_WORK() with devm_work_autocancel(), registered before
devm_request_irq(). The devres cleanup then frees the interrupt
first, so no new work can be queued, and cancels the work while
fan_data and the hwmon device are still alive.
This issue was found by an in-house static analysis tool.
Fixes: d6fe1360f42e ("hwmon: add generic GPIO fan driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Link: https://patch.msgid.link/20260819033317.446191-1-fanwu01@zju.edu.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/gpio-fan.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/gpio-fan.c
+++ b/drivers/hwmon/gpio-fan.c
@@ -12,6 +12,7 @@
#include <linux/slab.h>
#include <linux/interrupt.h>
#include <linux/irq.h>
+#include <linux/devm-helpers.h>
#include <linux/platform_device.h>
#include <linux/err.h>
#include <linux/mutex.h>
@@ -79,6 +80,7 @@ static DEVICE_ATTR_RO(fan1_alarm);
static int fan_alarm_init(struct gpio_fan_data *fan_data)
{
int alarm_irq;
+ int err;
struct device *dev = fan_data->dev;
/*
@@ -89,7 +91,11 @@ static int fan_alarm_init(struct gpio_fa
if (alarm_irq <= 0)
return 0;
- INIT_WORK(&fan_data->alarm_work, fan_alarm_notify);
+ err = devm_work_autocancel(dev, &fan_data->alarm_work,
+ fan_alarm_notify);
+ if (err)
+ return err;
+
irq_set_irq_type(alarm_irq, IRQ_TYPE_EDGE_BOTH);
return devm_request_irq(dev, alarm_irq, fan_alarm_irq_handler,
IRQF_SHARED, "GPIO fan alarm", fan_data);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 533/982] hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (531 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 532/982] hwmon: (gpio-fan) Fix use-after-free in alarm work Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 534/982] media: hevc: add bounded tile-count helpers Greg Kroah-Hartman
` (455 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vishnu Razdan, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vishnu Razdan <vrazdan@openai.com>
commit 6d760f8b41aed74de4402440e4db663d261478bd upstream.
Some hwmon alarms fall back to STATUS_WORD summary bits when no
individual limit alarm is available. On PMBus 1.2 and newer devices,
pmbus_get_boolean() acknowledges these alarms with the same byte-data
write used for detailed status registers. For example, PB_STATUS_INPUT
is 0x2000, so it is truncated to zero when passed to
_pmbus_write_byte_data(). The resulting write cannot acknowledge the
input alarm.
PMBus 1.3 Part II, sections 10.2.4 and 10.2.5, excludes ordinary
STATUS_BYTE and STATUS_WORD summary bits from individual clearing.
Their summary bits clear when the underlying status bits clear, so
changing this to a word-data write would not fix the generic input
alarm either.
Use the existing page CLEAR_FAULTS path for generic STATUS_WORD
alarms, including devices whose status accessor uses STATUS_BYTE.
Keep individual byte writes for detailed status registers on PMBus
1.2 and newer devices. As with the existing older-device fallback,
CLEAR_FAULTS can clear other latched status; an active condition can
reassert its status.
Fixes: 35f165f08950 ("hwmon: (pmbus) Clear pmbus fault/warning bits after read")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Vishnu Razdan <vrazdan@openai.com>
Link: https://patch.msgid.link/20260824-vrazdan-pmbus-status-word-b4-v1-1-2606ecd0c029@openai.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/pmbus_core.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/pmbus_core.c
+++ b/drivers/hwmon/pmbus/pmbus_core.c
@@ -1095,7 +1095,9 @@ static int pmbus_get_boolean(struct i2c_
regval = status & mask;
if (regval) {
- if (data->revision >= PMBUS_REV_12) {
+ /* Generic STATUS_WORD alarms are not individually clearable. */
+ if (data->revision >= PMBUS_REV_12 &&
+ reg != PMBUS_STATUS_WORD) {
ret = _pmbus_write_byte_data(client, page, reg, regval);
if (ret)
goto unlock;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 534/982] media: hevc: add bounded tile-count helpers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (532 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 533/982] hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 535/982] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Greg Kroah-Hartman
` (454 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Benjamin Gaignard,
Hans Verkuil
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
commit 592dd4f8442a13bed6e946d73d3164ba38b33bbd upstream.
The stateless HEVC decoders compute the number of tile columns and rows
from num_tile_columns_minus1 / num_tile_rows_minus1 and clamp it to the
column_width_minus1[] / row_height_minus1[] capacity before using it as a
loop bound. Add shared helpers in a new <media/v4l2-hevc.h> so the rkvdec
and hantro drivers do not each open-code the min_t() clamp.
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Fixes: 256fa3920874 ("media: v4l: Add definitions for HEVC stateless decoding")
Cc: stable@vger.kernel.org
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/media/v4l2-hevc.h | 41 +++++++++++++++++++++++++++++++++++++++++
1 file changed, 41 insertions(+)
create mode 100644 include/media/v4l2-hevc.h
--- /dev/null
+++ b/include/media/v4l2-hevc.h
@@ -0,0 +1,41 @@
+/* SPDX-License-Identifier: GPL-2.0-or-later */
+/*
+ * Helper functions for HEVC stateless codecs.
+ */
+
+#ifndef _MEDIA_V4L2_HEVC_H
+#define _MEDIA_V4L2_HEVC_H
+
+#include <linux/minmax.h>
+#include <media/v4l2-ctrls.h>
+
+/**
+ * v4l2_hevc_pps_num_tile_columns - number of HEVC tile columns, bounded
+ * @pps: the V4L2 HEVC PPS control
+ *
+ * Return the number of tile columns (num_tile_columns_minus1 + 1) clamped to
+ * the capacity of column_width_minus1[]. The control validation already
+ * rejects out-of-range counts; this keeps the consuming drivers bounded too.
+ */
+static inline unsigned int
+v4l2_hevc_pps_num_tile_columns(const struct v4l2_ctrl_hevc_pps *pps)
+{
+ return min_t(unsigned int, pps->num_tile_columns_minus1 + 1,
+ ARRAY_SIZE(pps->column_width_minus1));
+}
+
+/**
+ * v4l2_hevc_pps_num_tile_rows - number of HEVC tile rows, bounded
+ * @pps: the V4L2 HEVC PPS control
+ *
+ * Return the number of tile rows (num_tile_rows_minus1 + 1) clamped to the
+ * capacity of row_height_minus1[].
+ */
+static inline unsigned int
+v4l2_hevc_pps_num_tile_rows(const struct v4l2_ctrl_hevc_pps *pps)
+{
+ return min_t(unsigned int, pps->num_tile_rows_minus1 + 1,
+ ARRAY_SIZE(pps->row_height_minus1));
+}
+
+#endif /* _MEDIA_V4L2_HEVC_H */
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 535/982] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (533 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 534/982] media: hevc: add bounded tile-count helpers Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 536/982] media: v4l2-h264: Fix memcmp() size in B1 reference list comparison Greg Kroah-Hartman
` (453 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Benjamin Gaignard,
Hans Verkuil
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
commit 06236b094c899c22c12ac5097935eb6719293de8 upstream.
prepare_tile_info_buffer() writes one entry per tile into the tile_sizes
DMA buffer, sized for a grid equal to the PPS uAPI array capacity. Use the
bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows()
helpers so the loops stay inside the buffer.
Fixes: cb5dd5a0fa51 ("media: hantro: Introduce G2/HEVC decoder")
Assisted-by: Claude:claude-opus-4-8
Cc: stable@vger.kernel.org
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c
+++ b/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c
@@ -5,6 +5,8 @@
* Copyright (C) 2020 Safran Passenger Innovations LLC
*/
+#include <media/v4l2-hevc.h>
+
#include "hantro_hw.h"
#include "hantro_g2_regs.h"
@@ -29,8 +31,8 @@ static void prepare_tile_info_buffer(str
const struct v4l2_ctrl_hevc_pps *pps = ctrls->pps;
const struct v4l2_ctrl_hevc_sps *sps = ctrls->sps;
u16 *p = (u16 *)((u8 *)ctx->hevc_dec.tile_sizes.cpu);
- unsigned int num_tile_rows = pps->num_tile_rows_minus1 + 1;
- unsigned int num_tile_cols = pps->num_tile_columns_minus1 + 1;
+ unsigned int num_tile_rows = v4l2_hevc_pps_num_tile_rows(pps);
+ unsigned int num_tile_cols = v4l2_hevc_pps_num_tile_columns(pps);
unsigned int pic_width_in_ctbs, pic_height_in_ctbs;
unsigned int max_log2_ctb_size, ctb_size;
bool tiles_enabled, uniform_spacing;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 536/982] media: v4l2-h264: Fix memcmp() size in B1 reference list comparison
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (534 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 535/982] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 537/982] media: v4l2-ctrls: validate HEVC tile counts Greg Kroah-Hartman
` (452 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolas Dufresne, Haotian Zhang,
Nicolas Dufresne, Hans Verkuil
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haotian Zhang <vulab@iscas.ac.cn>
commit 10e59fbdef13597836bd6459095caa02c80af3d7 upstream.
In v4l2_h264_build_b_ref_lists(), the B0/B1 list equality
check passes the entry count builder->num_valid to memcmp()
instead of a byte size. Since struct v4l2_h264_reference is
two bytes (fields and index), only half of each list is
compared, so distinct lists can be wrongly treated as equal
and trigger an incorrect swap(b1_reflist[0], b1_reflist[1]).
Change the memcmp() size argument to sizeof(b1_reflist[0]) *
builder->num_valid so that the full byte length of both
reference lists is compared.
Fixes: 624922a2739b ("media: v4l2-core: Add helpers to build the H264 P/B0/B1 reflists")
Suggested-by: Nicolas Dufresne <nicolas@ndufresne.ca>
Cc: stable@vger.kernel.org
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/media/v4l2-core/v4l2-h264.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/media/v4l2-core/v4l2-h264.c
+++ b/drivers/media/v4l2-core/v4l2-h264.c
@@ -440,7 +440,8 @@ v4l2_h264_build_b_ref_lists(const struct
}
if (builder->num_valid > 1 &&
- !memcmp(b1_reflist, b0_reflist, builder->num_valid))
+ !memcmp(b1_reflist, b0_reflist,
+ sizeof(b1_reflist[0]) * builder->num_valid))
swap(b1_reflist[0], b1_reflist[1]);
print_ref_list_b(builder, b0_reflist, 0);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 537/982] media: v4l2-ctrls: validate HEVC tile counts
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (535 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 536/982] media: v4l2-h264: Fix memcmp() size in B1 reference list comparison Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 538/982] bnxt_en: Only restore LRO if the device supports TPA Greg Kroah-Hartman
` (451 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Benjamin Gaignard,
Hans Verkuil
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
commit dc694a9929f7cb9c88ef91e45eb982b7bbe5a477 upstream.
The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from
column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[]
and use them as tile-loop bounds, but std_validate_compound() does not
bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling
enabled whose tile counts exceed the uAPI array capacity, mirroring the
existing compound-control range checks.
Fixes: 256fa3920874 ("media: v4l: Add definitions for HEVC stateless decoding")
Assisted-by: Claude:claude-opus-4-8
Cc: stable@vger.kernel.org
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/media/v4l2-core/v4l2-ctrls-core.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
+++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
@@ -837,6 +837,18 @@ static int std_validate_compound(const s
p_hevc_pps->flags &=
~V4L2_HEVC_PPS_FLAG_LOOP_FILTER_ACROSS_TILES_ENABLED;
+ } else {
+ /*
+ * These count the entries the stateless HEVC drivers
+ * read from column_width_minus1[] / row_height_minus1[]
+ * and use as tile-loop bounds.
+ */
+ if (p_hevc_pps->num_tile_columns_minus1 >=
+ ARRAY_SIZE(p_hevc_pps->column_width_minus1))
+ return -EINVAL;
+ if (p_hevc_pps->num_tile_rows_minus1 >=
+ ARRAY_SIZE(p_hevc_pps->row_height_minus1))
+ return -EINVAL;
}
if (p_hevc_pps->flags &
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 538/982] bnxt_en: Only restore LRO if the device supports TPA
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (536 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 537/982] media: v4l2-ctrls: validate HEVC tile counts Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 539/982] bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() Greg Kroah-Hartman
` (450 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Joe Damato, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joe Damato <joe@dama.to>
commit 4e17b5007b6664559cdad2b2fe270526cf786b5b upstream.
With a P5+ device with firmware that reports max_aggs_supported == 0, it is
possible to make LRO settable by attaching and detaching an XDP program
even though the device does not support TPA.
Fix this by testing BNXT_SUPPORTS_TPA before restoring the feature bit.
Fixes: f0aa6a37a3db ("eth: bnxt: always recalculate features after XDP clearing, fix null-deref")
Reported-by: Sashiko <sashiko-bot+sashiko@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.1767611-1-joe%40dama.to
Cc: stable@vger.kernel.org
Signed-off-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260902015652.2421609-2-joe@dama.to
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
@@ -4094,7 +4094,8 @@ void bnxt_set_rx_skb_mode(struct bnxt *b
bnxt_get_max_rings(bp, &rx, &tx, true);
if (rx > 1) {
bp->flags &= ~BNXT_FLAG_NO_AGG_RINGS;
- bp->dev->hw_features |= NETIF_F_LRO;
+ if (BNXT_SUPPORTS_TPA(bp))
+ bp->dev->hw_features |= NETIF_F_LRO;
}
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 539/982] bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (537 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 538/982] bnxt_en: Only restore LRO if the device supports TPA Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 540/982] bnxt_en: Propagate RX ring init failures in bnxt_init_nic() Greg Kroah-Hartman
` (449 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Joe Damato, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joe Damato <joe@dama.to>
commit 961e2a17c5e3559b3f8654d2daabdd25a42e770a upstream.
bnxt_rx_ring_reset() frees the ring buffers and then reallocates them,
ignoring the result.
bnxt_alloc_one_rx_ring() can fail in bnxt_alloc_one_tpa_info_data(), which
returns -ENOMEM on the first failed allocation and leaves the remaining
rxr->rx_tpa[] entries zeroed.
The error isn't propagated up, so the loop in bnxt_rx_ring_reset
continues and at the end the code re-enables TPA with partially
unallocated rx_tpa array.
This means that when the agg_id from hardware is mapped to a SW index in
rxr->rx_tpa[], an uninitialized slot can be chosen which would hand a
zero DMA address to the device.
Fix this by falling back to a global reset, which is what the existing
code already does when other functions fail, but unlike the other
failure cases this particular failure has to return because TPA can't
be re-enabled since the allocation failed.
Fixes: 8fbf58e17dce ("bnxt_en: Implement RX ring reset in response to buffer errors.")
Reported-by: Sashiko <sashiko-bot+sashiko@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.1767611-1-joe%40dama.to
Cc: stable@vger.kernel.org
Signed-off-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260902015652.2421609-5-joe@dama.to
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
@@ -11827,7 +11827,14 @@ static void bnxt_rx_ring_reset(struct bn
rxr->rx_sw_agg_prod = 0;
rxr->rx_next_cons = 0;
rxr->bnapi->in_reset = false;
- bnxt_alloc_one_rx_ring(bp, i);
+ rc = bnxt_alloc_one_rx_ring(bp, i);
+ if (rc) {
+ netdev_warn(bp->dev, "RX ring reset failed to allocate buffers, rc = %d, falling back to global reset\n",
+ rc);
+ bnxt_reset_task(bp, true);
+ bnxt_rtnl_unlock_sp(bp);
+ return;
+ }
cpr = &rxr->bnapi->cp_ring;
cpr->sw_stats.rx.rx_resets++;
if (bp->flags & BNXT_FLAG_AGG_RINGS)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 540/982] bnxt_en: Propagate RX ring init failures in bnxt_init_nic()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (538 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 539/982] bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 541/982] mptcp: options: handle MPC data + csum reqd + no csum Greg Kroah-Hartman
` (448 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Joe Damato, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joe Damato <joe@dama.to>
commit 8e6a850c0746bb4be167aedf1ee57469fcda09a9 upstream.
bnxt_init_rx_rings() returns an error when bnxt_alloc_one_rx_ring()
fails, but bnxt_init_nic() discards that return value and calls
bnxt_init_chip(), which enables TPA.
If an allocation fails, this could leave rxr->rx_tpa[] partially zeroed
and TPA would be enabled over an array with zeroed entries. This would
lead to a zeroed DMA address being handed out if the agg_idx is
translated to a SW index at a zeroed entry.
Fix this by propagating the error out of bnxt_init_nic(). Both callers
already check its return value and unwind with bnxt_free_skbs() and
bnxt_free_mem(), which tolerate a partially initialized RX ring.
Fixes: c0c050c58d84 ("bnxt_en: New Broadcom ethernet driver.")
Reported-by: Sashiko <sashiko-bot+sashiko@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.1767611-1-joe%40dama.to
Cc: stable@vger.kernel.org
Signed-off-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260902015652.2421609-6-joe@dama.to
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
@@ -8964,8 +8964,13 @@ static int bnxt_shutdown_nic(struct bnxt
static int bnxt_init_nic(struct bnxt *bp, bool irq_re_init)
{
+ int rc;
+
bnxt_init_cp_rings(bp);
- bnxt_init_rx_rings(bp);
+ rc = bnxt_init_rx_rings(bp);
+ if (rc)
+ return rc;
+
bnxt_init_tx_rings(bp);
bnxt_init_ring_grps(bp, irq_re_init);
bnxt_init_vnics(bp);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 541/982] mptcp: options: handle MPC data + csum reqd + no csum
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (539 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 540/982] bnxt_en: Propagate RX ring init failures in bnxt_init_nic() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 542/982] mptcp: subflow: no need to copy thmac during ulp_clone Greg Kroah-Hartman
` (447 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mat Martineau,
Matthieu Baerts (NGI0), Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Baerts (NGI0) <matttbe@kernel.org>
commit ab36b1a80942c78ddb04d006ff38aa7ed3ec0e5e upstream.
Before this modification, a remote peer could send an MP_CAPABLE with
data, with the checksum flag set, but without adding the actual 2 bytes
of checksum. As a result, uninitialised bytes could be used for the
'csum' field.
That was not a critical issue, because this 'csum' field is only used to
compare with the expected one, if previously negotiated in the 3WHS.
Worst case, the checksum is likely wrong, a fallback is done without a
reject if the negotiation was done earlier. That's OK.
Yet, better to take the expected path with this case: only look at the
checksum flag for MP_CAPABLEs not carrying a data-len.
Such packet can be seen as a 3rd or 4th ACK. The RFC8684 mentions [1]
that the 3rd packet should have the checksum flag set. When an MPC + ACK
contains data, the checksum flag is redundant with the checksum field.
It is not clear what should be done for the 4th ACK, nor if the flag has
to be set if the checksum field is set.
Therefore, it seems fine to only look at the presence of the checksum
field, not to break the interaction with stacks that were not setting
both.
Note that linked to this checksum flag on the 3rd ACK, with the current
implementation, we can have a situation where the SYN packets have no
checksum flag, but the 3rd ACK has one, and this is the one that will be
taken into account. First, that's clearly not directly linked to this
patch, but Clashiko forced us to look at that. At the end, that seems
fine to act like that: yes that's not how the negotiation should work,
but being flexible without introducing side effects is also fine: fixing
this would mean increasing the complexity, and that's not worth it.
Fixes: 208e8f66926c ("mptcp: receive checksum for MP_CAPABLE with data")
Cc: stable@vger.kernel.org
Link: https://datatracker.ietf.org/doc/html/rfc8684#section-3.1-23 [1]
Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260803-net-mptcp-misc-fixes-7-2-rc6-v2-0-b8f496d71664%40kernel.org?part=1
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260908-net-mptcp-misc-fixes-7-3-rc1-v2-5-df1de70348b6@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/options.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/mptcp/options.c
+++ b/net/mptcp/options.c
@@ -80,7 +80,8 @@ static void mptcp_parse_option(const str
* In other words, the only way for checksums not to be used
* is if both hosts in their SYNs set A=0."
*/
- if (flags & MPTCP_CAP_CHECKSUM_REQD)
+ if ((flags & MPTCP_CAP_CHECKSUM_REQD) &&
+ opsize < TCPOLEN_MPTCP_MPC_ACK_DATA)
mp_opt->suboptions |= OPTION_MPTCP_CSUMREQD;
mp_opt->deny_join_id0 = !!(flags & MPTCP_CAP_DENY_JOIN_ID0);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 542/982] mptcp: subflow: no need to copy thmac during ulp_clone
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (540 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 541/982] mptcp: options: handle MPC data + csum reqd + no csum Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 543/982] mptcp: syncookies: remember the request backup flag Greg Kroah-Hartman
` (446 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geliang Tang, Matthieu Baerts (NGI0),
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Baerts (NGI0) <matttbe@kernel.org>
commit 29f641951be0d91036d77edf677807f1447dbe65 upstream.
'thmac' is not used after that point.
Indeed, subflow_ulp_clone() is called when the request on the passive
side is over, so when the truncated HMAC is no longer needed.
Note that in case of SYN cookies, thmac will not be initialised. So
better to remove it to avoid a warning from debug tools like KMSAN for
reading uninitialised data.
Fixes: f296234c98a8 ("mptcp: Add handling of incoming MP_JOIN requests")
Cc: stable@vger.kernel.org
Reviewed-by: Geliang Tang <geliang@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260908-net-mptcp-misc-fixes-7-3-rc1-v2-2-df1de70348b6@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/subflow.c | 1 -
1 file changed, 1 deletion(-)
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1910,7 +1910,6 @@ static void subflow_ulp_clone(const stru
new_ctx->request_bkup = subflow_req->request_bkup;
WRITE_ONCE(new_ctx->remote_id, subflow_req->remote_id);
new_ctx->token = subflow_req->token;
- new_ctx->thmac = subflow_req->thmac;
/* the subflow req id is valid, fetched via subflow_check_req()
* and subflow_token_join_request()
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 543/982] mptcp: syncookies: remember the request backup flag
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (541 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 542/982] mptcp: subflow: no need to copy thmac during ulp_clone Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 544/982] selftests: mptcp: fix an UAF in mptcp_connect.c Greg Kroah-Hartman
` (445 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geliang Tang, Matthieu Baerts (NGI0),
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Baerts (NGI0) <matttbe@kernel.org>
commit b76c0e28b392620dfbaf92cdeedbf115820b44cb upstream.
Instead of using an uninitialised bit when copying the info in
subflow_ulp_clone().
To fix this, no need to extend the join_entry structure: backup is
coming from struct mptcp_subflow_request_sock, only one bit. Do the same
here by using one bit for both.
Fixes: efd340bf3d77 ("mptcp: distinguish rcv vs sent backup flag in requests")
Cc: stable@vger.kernel.org
Reviewed-by: Geliang Tang <geliang@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260908-net-mptcp-misc-fixes-7-3-rc1-v2-3-df1de70348b6@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/syncookies.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/net/mptcp/syncookies.c
+++ b/net/mptcp/syncookies.c
@@ -26,7 +26,8 @@ struct join_entry {
u32 local_nonce;
u8 join_id;
u8 local_id;
- u8 backup;
+ u8 backup:1,
+ request_bkup:1;
u8 valid;
};
@@ -63,6 +64,7 @@ static void mptcp_join_store_state(struc
entry->remote_nonce = subflow_req->remote_nonce;
entry->local_nonce = subflow_req->local_nonce;
entry->backup = subflow_req->backup;
+ entry->request_bkup = subflow_req->request_bkup;
entry->join_id = subflow_req->remote_id;
entry->local_id = subflow_req->local_id;
entry->valid = 1;
@@ -117,6 +119,7 @@ bool mptcp_token_join_cookie_init_state(
subflow_req->remote_nonce = e->remote_nonce;
subflow_req->local_nonce = e->local_nonce;
subflow_req->backup = e->backup;
+ subflow_req->request_bkup = e->request_bkup;
subflow_req->remote_id = e->join_id;
subflow_req->local_id = e->local_id;
subflow_req->token = e->token;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 544/982] selftests: mptcp: fix an UAF in mptcp_connect.c
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (542 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 543/982] mptcp: syncookies: remember the request backup flag Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 545/982] smb: client: reject userspace cifs.idmap descriptions Greg Kroah-Hartman
` (444 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paolo Abeni, Gang Yan,
Matthieu Baerts (NGI0), Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gang Yan <yangang@kylinos.cn>
commit 730444f094b12052916ebd7e14fe57bc3d47bf38 upstream.
At the end of 'sock_connect_mptcp()', it calls 'freeaddrinfo(addr)',
the 'peer' pointer (which points into 'addr') remains. Later, the main
loop uses this peer pointer for reconnection attempts. If the memory has
been freed and reused, the address data could be overwritten, resulting
in an invalid remote address.
This patch keeps the addrinfo list allocated for the whole process
lifetime so "peer" remains valid across reconnects; the memory will be
released at exit() time.
Fixes: 05be5e273c84 ("selftests: mptcp: add disconnect tests")
Cc: stable@vger.kernel.org
Suggested-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Gang Yan <yangang@kylinos.cn>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260908-net-mptcp-misc-fixes-7-3-rc1-v2-7-df1de70348b6@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/net/mptcp/mptcp_connect.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/tools/testing/selftests/net/mptcp/mptcp_connect.c
+++ b/tools/testing/selftests/net/mptcp/mptcp_connect.c
@@ -344,6 +344,9 @@ static int sock_connect_mptcp(const char
hints.ai_family = pf;
+ /* Keep the resolved address alive for the whole execution: it is
+ * used again when reconnecting, and will be released at exit time.
+ */
xgetaddrinfo(remoteaddr, port, &hints, &addr);
for (a = addr; a; a = a->ai_next) {
sock = socket(a->ai_family, a->ai_socktype, proto);
@@ -367,7 +370,6 @@ static int sock_connect_mptcp(const char
sock = -1;
}
- freeaddrinfo(addr);
if (sock != -1)
SOCK_TEST_TCPULP(sock, proto);
return sock;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 545/982] smb: client: reject userspace cifs.idmap descriptions
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (543 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 544/982] selftests: mptcp: fix an UAF in mptcp_connect.c Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 546/982] smb: client: avoid leaking refcount in cifs_queue_oplock_break() Greg Kroah-Hartman
` (443 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI, Aohan Mei,
David Howells, Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit d9d7eeb0cea5b55b82888f443622fd8d4ee064f3 upstream.
cifs.idmap key descriptions carry authority-bearing fields (owner and
group SIDs and uid/gid values in "os:"/"gs:"/"oi:"/"gi:" form) that the
cifs.idmap upcall helper treats as kernel-originating inputs. Unlike
its sibling cifs.spnego, the cifs.idmap key type has no vet_description
hook, so userspace can create keys of this type through
request_key(2)/add_key(2) and supply those fields without CIFS origin.
A request_key(2) call with a non-NULL callout then drives a root
usermodehelper upcall (/sbin/request-key -> cifs.idmap) that consumes
the unvetted description in root context.
Only accept cifs.idmap descriptions while CIFS is using its private
root_cred to request the key. id_to_sid()/sid_to_id() already run
under override_creds(root_cred), so the kernel-originated path is
unaffected.
This mirrors commit 3da1fdf4efbc ("smb: client: reject userspace
cifs.spnego descriptions"), which applied the same restriction to
cifs.spnego.
Fixes: 4d79dba0e007 ("cifs: Add idmap key and related data structures and functions (try #17 repost)")
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Assisted-by: CodeBuddy:Kimi-K3
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Acked-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/cifsacl.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
--- a/fs/smb/client/cifsacl.c
+++ b/fs/smb/client/cifsacl.c
@@ -96,8 +96,23 @@ cifs_idmap_key_destroy(struct key *key)
kfree(key->payload.data[0]);
}
+static int
+cifs_idmap_key_vet_description(const char *description)
+{
+ /*
+ * cifs.idmap descriptions are authority-bearing inputs to the
+ * cifs.idmap upcall helper. Only allow the kernel to create this
+ * type of key using the private root_cred installed in
+ * init_cifs_idmap; reject userspace request_key(2)/add_key(2).
+ */
+ if (current_cred() != root_cred)
+ return -EPERM;
+ return 0;
+}
+
static struct key_type cifs_idmap_key_type = {
.name = "cifs.idmap",
+ .vet_description = cifs_idmap_key_vet_description,
.instantiate = cifs_idmap_key_instantiate,
.destroy = cifs_idmap_key_destroy,
.describe = user_describe,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 546/982] smb: client: avoid leaking refcount in cifs_queue_oplock_break()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (544 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 545/982] smb: client: reject userspace cifs.idmap descriptions Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 547/982] smb: client: avoid leaking refcount when cifs_sb_tlink() fails Greg Kroah-Hartman
` (442 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjoern Doebel, Namjae Jeon,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjoern Doebel <doebel@amazon.de>
commit 9f2e63f1b2d5fc5b5423424902c091123e220e7e upstream.
cifs_queue_oplock_break() unconditionally takes a reference on the
target file before queueing cifs_oplock_break(). Only that work item
decreases the reference counter again.
If another oplock break arrives while that work is still queued,
queue_work() will return false and not queue this second work item. As a
result, we will never reach the point to drop the file reference again
and are leaking this reference. This can be triggered when interacting
with a slow-responding server.
As a result, later unmount operations for this file system will fail with
BUG: Dentry ... still in use (1) [unmount of cifs cifs]
VFS: Busy inodes after unmount of cifs (cifs)
kernel BUG at fs/super.c:777!
Fix this by only incrementing the reference count if the work has been
queued successfully. Taking it after queue_work() is safe because all
three callers hold tcon->open_file_lock across the call and
_cifsFileInfo_put() decrements under that same lock, so a worker that
starts the handler in the window cannot drop the reference before it has
been taken.
Fixes: b98749cac4a69 ("CIFS: keep FileInfo handle live during oplock break")
Cc: stable@vger.kernel.org
Assisted-by: Kiro:claude-opus-5
Signed-off-by: Bjoern Doebel <doebel@amazon.de>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/misc.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/fs/smb/client/misc.c
+++ b/fs/smb/client/misc.c
@@ -639,10 +639,11 @@ void cifs_queue_oplock_break(struct cifs
* open_file_lock to enforce the validity of it for the oplock
* break handler. The matching put is done at the end of the
* handler.
+ *
+ * Only take a reference if the work is actually queued.
*/
- cifsFileInfo_get(cfile);
-
- queue_work(cifsoplockd_wq, &cfile->oplock_break);
+ if (queue_work(cifsoplockd_wq, &cfile->oplock_break))
+ cifsFileInfo_get(cfile);
}
void cifs_done_oplock_break(struct cifsInodeInfo *cinode)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 547/982] smb: client: avoid leaking refcount when cifs_sb_tlink() fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (545 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 546/982] smb: client: avoid leaking refcount in cifs_queue_oplock_break() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 548/982] bpftool: remove duplicate free_btf_vmlinux() definition Greg Kroah-Hartman
` (441 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjoern Doebel, Namjae Jeon,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjoern Doebel <doebel@amazon.de>
commit 23b26f4408ac3f35a482d2e5cf6fc865d4201b71 upstream.
cifs_oplock_break() takes over the reference that
cifs_queue_oplock_break() acquired when it queued the work, and drops it
with _cifsFileInfo_put() once the break has been processed.
Only in setups with "-o multiuser", cifs_sb_tlink() may fail, at which
point cifs_oplock_break() returns without putting the file reference,
mirroring the reference leak we already fixed in the companion patch to
cifs_queue_oplock_break().
This would trigger a crash due to busy inodes on the next unmount:
BUG: Dentry ... still in use (1) [unmount of cifs cifs]
VFS: Busy inodes after unmount of cifs (cifs)
Drop the reference on that path as well. Doing so before the out label
mirrors the normal path, which also puts the reference before
cifs_done_oplock_break().
Found by Sashiko code review. The failure path was not exercised at
runtime.
Fixes: e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break")
Cc: stable@vger.kernel.org
Assisted-by: Kiro:claude-opus-5
Signed-off-by: Bjoern Doebel <doebel@amazon.de>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/file.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/fs/smb/client/file.c
+++ b/fs/smb/client/file.c
@@ -5188,8 +5188,11 @@ void cifs_oplock_break(struct work_struc
TASK_UNINTERRUPTIBLE);
tlink = cifs_sb_tlink(cifs_sb);
- if (IS_ERR(tlink))
+ if (IS_ERR(tlink)) {
+ /* drop the reference taken when the break was queued */
+ _cifsFileInfo_put(cfile, false /* do not wait for ourself */, false);
goto out;
+ }
tcon = tlink_tcon(tlink);
server = tcon->ses->server;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 548/982] bpftool: remove duplicate free_btf_vmlinux() definition
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (546 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 547/982] smb: client: avoid leaking refcount when cifs_sb_tlink() fails Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 549/982] Revert "arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries" Greg Kroah-Hartman
` (440 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Suraj Jitindar Singh, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Suraj Jitindar Singh <surajjs@amazon.com>
v6.1.188 backported
660a19e46942 ("tools/bpf/bpftool: Reset vmlinux BTF after map commands")
[ upstream commit 66d7e39e49b0 ]
which re-adds free_btf_vmlinux(). However, the prerequisite cleanup
52df1a8aabad ("bpftool: remove function free_btf_vmlinux()")
was never backported to 6.1.y, so the tree still carried the original
free_btf_vmlinux() definition. The backport therefore produced two
identical-signature static definitions in tools/bpf/bpftool/map.c and
the build fails:
map.c: error: redefinition of 'free_btf_vmlinux'
Remove the stale pre-existing definition, keeping the one reintroduced
by 660a19e46942 (which also resets btf_vmlinux = NULL). This matches the
current mainline end state.
Fixes: 660a19e46942 ("tools/bpf/bpftool: Reset vmlinux BTF after map commands")
Signed-off-by: Suraj Jitindar Singh <surajjs@amazon.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/bpf/bpftool/map.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/tools/bpf/bpftool/map.c b/tools/bpf/bpftool/map.c
index a77bf45d6f834..748b3def6b2c2 100644
--- a/tools/bpf/bpftool/map.c
+++ b/tools/bpf/bpftool/map.c
@@ -817,11 +817,6 @@ static void free_map_kv_btf(struct btf *btf)
btf__free(btf);
}
-static void free_btf_vmlinux(void)
-{
- btf__free(btf_vmlinux);
-}
-
static int
map_dump(int fd, struct bpf_map_info *info, json_writer_t *wtr,
bool show_header)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 549/982] Revert "arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (547 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 548/982] bpftool: remove duplicate free_btf_vmlinux() definition Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 550/982] Revert "arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
` (439 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit d831304f2079e114fa74e585bf667a83fdbc25c8.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8550.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8550.dtsi b/arch/arm64/boot/dts/qcom/sm8550.dtsi
index 45fb37bf08f66..18134a7e69745 100644
--- a/arch/arm64/boot/dts/qcom/sm8550.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8550.dtsi
@@ -1432,8 +1432,8 @@ pcie0: pci@1c00000 {
msi-map = <0x0 &gic_its 0x1400 0x1>,
<0x100 &gic_its 0x1401 0x1>;
- iommu-map = <0x0 &apps_smmu 0x1400 0x0 0x1>,
- <0x100 &apps_smmu 0x1401 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1400 0x1>,
+ <0x100 &apps_smmu 0x1401 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1537,8 +1537,8 @@ pcie1: pci@1c08000 {
msi-map = <0x0 &gic_its 0x1480 0x1>,
<0x100 &gic_its 0x1481 0x1>;
- iommu-map = <0x0 &apps_smmu 0x1480 0x0 0x1>,
- <0x100 &apps_smmu 0x1481 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1480 0x1>,
+ <0x100 &apps_smmu 0x1481 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>,
<&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 550/982] Revert "arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (548 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 549/982] Revert "arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 551/982] Revert "arm64: dts: qcom: sm8350: " Greg Kroah-Hartman
` (438 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 2eec945bc94f35ae597e4ce49bc4f4b581ee82a0.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8450.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8450.dtsi b/arch/arm64/boot/dts/qcom/sm8450.dtsi
index 4911f2be3e7c7..653998706b7ff 100644
--- a/arch/arm64/boot/dts/qcom/sm8450.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8450.dtsi
@@ -1759,8 +1759,8 @@ pcie0: pci@1c00000 {
"aggre0",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
- <0x100 &apps_smmu 0x1c01 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1865,8 +1865,8 @@ pcie1: pci@1c08000 {
"ddrss_sf_tbu",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
- <0x100 &apps_smmu 0x1c81 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 551/982] Revert "arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (549 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 550/982] Revert "arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 552/982] Revert "arm64: dts: qcom: sm8250: " Greg Kroah-Hartman
` (437 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 98d41e690de05a6367300ab85bdeddff1af933a4.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8350.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8350.dtsi b/arch/arm64/boot/dts/qcom/sm8350.dtsi
index 28224a4818534..bb556fdc66664 100644
--- a/arch/arm64/boot/dts/qcom/sm8350.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8350.dtsi
@@ -1635,8 +1635,8 @@ pcie0: pci@1c00000 {
"aggre1",
"aggre0";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
- <0x100 &apps_smmu 0x1c01 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1718,8 +1718,8 @@ pcie1: pci@1c08000 {
"ddrss_sf_tbu",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
- <0x100 &apps_smmu 0x1c81 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 552/982] Revert "arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (550 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 551/982] Revert "arm64: dts: qcom: sm8350: " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 553/982] Revert "arm64: dts: qcom: sm8150: " Greg Kroah-Hartman
` (436 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 6a8666fc1c629863022899046f8c46f3bb45a68e.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8250.dtsi | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8250.dtsi b/arch/arm64/boot/dts/qcom/sm8250.dtsi
index 7020f32e59d05..fbda1925f8e03 100644
--- a/arch/arm64/boot/dts/qcom/sm8250.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8250.dtsi
@@ -1850,8 +1850,8 @@ pcie0: pci@1c00000 {
"tbu",
"ddrss_sf_tbu";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
- <0x100 &apps_smmu 0x1c01 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1956,8 +1956,8 @@ pcie1: pci@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
- <0x100 &apps_smmu 0x1c81 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
@@ -2064,8 +2064,8 @@ pcie2: pci@1c10000 {
assigned-clocks = <&gcc GCC_PCIE_2_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1d00 0x0 0x1>,
- <0x100 &apps_smmu 0x1d01 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1d00 0x1>,
+ <0x100 &apps_smmu 0x1d01 0x1>;
resets = <&gcc GCC_PCIE_2_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 553/982] Revert "arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (551 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 552/982] Revert "arm64: dts: qcom: sm8250: " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 554/982] Revert "arm64: dts: qcom: sdm845: " Greg Kroah-Hartman
` (435 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 7312115432d2ad14ccf92b2359d57bb039a239e3.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8150.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8150.dtsi b/arch/arm64/boot/dts/qcom/sm8150.dtsi
index 1ea6a09b57bc2..9168173dd0e3e 100644
--- a/arch/arm64/boot/dts/qcom/sm8150.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8150.dtsi
@@ -1810,8 +1810,8 @@ pcie0: pci@1c00000 {
"slave_q2a",
"tbu";
- iommu-map = <0x0 &apps_smmu 0x1d80 0x0 0x1>,
- <0x100 &apps_smmu 0x1d81 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1d80 0x1>,
+ <0x100 &apps_smmu 0x1d81 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1912,8 +1912,8 @@ pcie1: pci@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1e00 0x0 0x1>,
- <0x100 &apps_smmu 0x1e01 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1e00 0x1>,
+ <0x100 &apps_smmu 0x1e01 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 554/982] Revert "arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (552 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 553/982] Revert "arm64: dts: qcom: sm8150: " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 555/982] ipv6: mcast: extend RCU protection in igmp6_send() Greg Kroah-Hartman
` (434 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 34c6835023896943696e4f2c192dc850240982cc.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sdm845.dtsi | 64 ++++++++++++++--------------
1 file changed, 32 insertions(+), 32 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sdm845.dtsi b/arch/arm64/boot/dts/qcom/sdm845.dtsi
index 10b0956f48c20..71d2ecbec22b0 100644
--- a/arch/arm64/boot/dts/qcom/sdm845.dtsi
+++ b/arch/arm64/boot/dts/qcom/sdm845.dtsi
@@ -2254,22 +2254,22 @@ pcie0: pci@1c00000 {
"slave_q2a",
"tbu";
- iommu-map = <0x0 &apps_smmu 0x1c10 0x0 0x1>,
- <0x100 &apps_smmu 0x1c11 0x0 0x1>,
- <0x200 &apps_smmu 0x1c12 0x0 0x1>,
- <0x300 &apps_smmu 0x1c13 0x0 0x1>,
- <0x400 &apps_smmu 0x1c14 0x0 0x1>,
- <0x500 &apps_smmu 0x1c15 0x0 0x1>,
- <0x600 &apps_smmu 0x1c16 0x0 0x1>,
- <0x700 &apps_smmu 0x1c17 0x0 0x1>,
- <0x800 &apps_smmu 0x1c18 0x0 0x1>,
- <0x900 &apps_smmu 0x1c19 0x0 0x1>,
- <0xa00 &apps_smmu 0x1c1a 0x0 0x1>,
- <0xb00 &apps_smmu 0x1c1b 0x0 0x1>,
- <0xc00 &apps_smmu 0x1c1c 0x0 0x1>,
- <0xd00 &apps_smmu 0x1c1d 0x0 0x1>,
- <0xe00 &apps_smmu 0x1c1e 0x0 0x1>,
- <0xf00 &apps_smmu 0x1c1f 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c10 0x1>,
+ <0x100 &apps_smmu 0x1c11 0x1>,
+ <0x200 &apps_smmu 0x1c12 0x1>,
+ <0x300 &apps_smmu 0x1c13 0x1>,
+ <0x400 &apps_smmu 0x1c14 0x1>,
+ <0x500 &apps_smmu 0x1c15 0x1>,
+ <0x600 &apps_smmu 0x1c16 0x1>,
+ <0x700 &apps_smmu 0x1c17 0x1>,
+ <0x800 &apps_smmu 0x1c18 0x1>,
+ <0x900 &apps_smmu 0x1c19 0x1>,
+ <0xa00 &apps_smmu 0x1c1a 0x1>,
+ <0xb00 &apps_smmu 0x1c1b 0x1>,
+ <0xc00 &apps_smmu 0x1c1c 0x1>,
+ <0xd00 &apps_smmu 0x1c1d 0x1>,
+ <0xe00 &apps_smmu 0x1c1e 0x1>,
+ <0xf00 &apps_smmu 0x1c1f 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2363,22 +2363,22 @@ pcie1: pci@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
- <0x100 &apps_smmu 0x1c01 0x0 0x1>,
- <0x200 &apps_smmu 0x1c02 0x0 0x1>,
- <0x300 &apps_smmu 0x1c03 0x0 0x1>,
- <0x400 &apps_smmu 0x1c04 0x0 0x1>,
- <0x500 &apps_smmu 0x1c05 0x0 0x1>,
- <0x600 &apps_smmu 0x1c06 0x0 0x1>,
- <0x700 &apps_smmu 0x1c07 0x0 0x1>,
- <0x800 &apps_smmu 0x1c08 0x0 0x1>,
- <0x900 &apps_smmu 0x1c09 0x0 0x1>,
- <0xa00 &apps_smmu 0x1c0a 0x0 0x1>,
- <0xb00 &apps_smmu 0x1c0b 0x0 0x1>,
- <0xc00 &apps_smmu 0x1c0c 0x0 0x1>,
- <0xd00 &apps_smmu 0x1c0d 0x0 0x1>,
- <0xe00 &apps_smmu 0x1c0e 0x0 0x1>,
- <0xf00 &apps_smmu 0x1c0f 0x0 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x1>,
+ <0x200 &apps_smmu 0x1c02 0x1>,
+ <0x300 &apps_smmu 0x1c03 0x1>,
+ <0x400 &apps_smmu 0x1c04 0x1>,
+ <0x500 &apps_smmu 0x1c05 0x1>,
+ <0x600 &apps_smmu 0x1c06 0x1>,
+ <0x700 &apps_smmu 0x1c07 0x1>,
+ <0x800 &apps_smmu 0x1c08 0x1>,
+ <0x900 &apps_smmu 0x1c09 0x1>,
+ <0xa00 &apps_smmu 0x1c0a 0x1>,
+ <0xb00 &apps_smmu 0x1c0b 0x1>,
+ <0xc00 &apps_smmu 0x1c0c 0x1>,
+ <0xd00 &apps_smmu 0x1c0d 0x1>,
+ <0xe00 &apps_smmu 0x1c0e 0x1>,
+ <0xf00 &apps_smmu 0x1c0f 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 555/982] ipv6: mcast: extend RCU protection in igmp6_send()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (553 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 554/982] Revert "arm64: dts: qcom: sdm845: " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 556/982] Revert "nvme-apple: Reset q->sq_tail during queue init" Greg Kroah-Hartman
` (433 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, David Ahern,
Kuniyuki Iwashima, Jakub Kicinski, Shun Ota, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 087c1faa594fa07a66933d750c0b2610aa1a2946 ]
igmp6_send() can be called without RTNL or RCU being held.
Extend RCU protection so that we can safely fetch the net pointer
and avoid a potential UAF.
Note that we no longer can use sock_alloc_send_skb() because
ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.
Instead use alloc_skb() and charge the net->ipv6.igmp_sk
socket under RCU protection.
Fixes: b8ad0cbc58f7 ("[NETNS][IPV6] mcast - handle several network namespace")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20250207135841.1948589-9-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ use IP6_UPD_PO_STATS(net, idev, IPSTATS_MIB_OUT, full_len)
instead of upstream's IP6_INC_STATS(net, idev, IPSTATS_MIB_OUTPKTS).
Older LTS kernels do not have commit b4a11b2033b7 ("net: fix
IPSTATS_MIB_OUTPKGS increment in OutForwDatagrams"), so the legacy
byte-based counter logic must be preserved. ]
Signed-off-by: Shun Ota <shun.ota@miraclelinux.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/mcast.c | 32 +++++++++++++++-----------------
1 file changed, 15 insertions(+), 17 deletions(-)
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index 35fb4f624d59e..4ef73d68f6d11 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -2154,21 +2154,21 @@ static void mld_send_cr(struct inet6_dev *idev)
static void igmp6_send(struct in6_addr *addr, struct net_device *dev, int type)
{
- struct net *net = dev_net(dev);
- struct sock *sk = net->ipv6.igmp_sk;
+ const struct in6_addr *snd_addr, *saddr;
+ int err, len, payload_len, full_len;
+ struct in6_addr addr_buf;
struct inet6_dev *idev;
struct sk_buff *skb;
struct mld_msg *hdr;
- const struct in6_addr *snd_addr, *saddr;
- struct in6_addr addr_buf;
int hlen = LL_RESERVED_SPACE(dev);
int tlen = dev->needed_tailroom;
- int err, len, payload_len, full_len;
u8 ra[8] = { IPPROTO_ICMPV6, 0,
IPV6_TLV_ROUTERALERT, 2, 0, 0,
IPV6_TLV_PADN, 0 };
- struct flowi6 fl6;
struct dst_entry *dst;
+ struct flowi6 fl6;
+ struct net *net;
+ struct sock *sk;
if (type == ICMPV6_MGM_REDUCTION)
snd_addr = &in6addr_linklocal_allrouters;
@@ -2179,20 +2179,21 @@ static void igmp6_send(struct in6_addr *addr, struct net_device *dev, int type)
payload_len = len + sizeof(ra);
full_len = sizeof(struct ipv6hdr) + payload_len;
- rcu_read_lock();
- IP6_UPD_PO_STATS(net, __in6_dev_get(dev),
- IPSTATS_MIB_OUT, full_len);
- rcu_read_unlock();
+ skb = alloc_skb(hlen + tlen + full_len, GFP_KERNEL);
- skb = sock_alloc_send_skb(sk, hlen + tlen + full_len, 1, &err);
+ rcu_read_lock();
+ net = dev_net_rcu(dev);
+ idev = __in6_dev_get(dev);
+ IP6_UPD_PO_STATS(net, idev, IPSTATS_MIB_OUT, full_len);
if (!skb) {
- rcu_read_lock();
- IP6_INC_STATS(net, __in6_dev_get(dev),
- IPSTATS_MIB_OUTDISCARDS);
+ IP6_INC_STATS(net, idev, IPSTATS_MIB_OUTDISCARDS);
rcu_read_unlock();
return;
}
+ sk = net->ipv6.igmp_sk;
+ skb_set_owner_w(skb, sk);
+
skb->priority = TC_PRIO_CONTROL;
skb_reserve(skb, hlen);
@@ -2217,9 +2218,6 @@ static void igmp6_send(struct in6_addr *addr, struct net_device *dev, int type)
IPPROTO_ICMPV6,
csum_partial(hdr, len, 0));
- rcu_read_lock();
- idev = __in6_dev_get(skb->dev);
-
icmpv6_flow_init(sk, &fl6, type,
&ipv6_hdr(skb)->saddr, &ipv6_hdr(skb)->daddr,
skb->dev->ifindex);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 556/982] Revert "nvme-apple: Reset q->sq_tail during queue init"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (554 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 555/982] ipv6: mcast: extend RCU protection in igmp6_send() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 557/982] Revert "nvme-apple: Prevent shared tags across queues on Apple A11" Greg Kroah-Hartman
` (432 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 225b7af1dbd589c33faabe90b5bd85bd6a73b8b6.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/apple.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/nvme/host/apple.c b/drivers/nvme/host/apple.c
index e46048b755d17..060f80c5ebeda 100644
--- a/drivers/nvme/host/apple.c
+++ b/drivers/nvme/host/apple.c
@@ -1009,7 +1009,6 @@ static void apple_nvme_init_queue(struct apple_nvme_queue *q)
unsigned int depth = apple_nvme_queue_depth(q);
struct apple_nvme *anv = queue_to_apple_nvme(q);
- q->sq_tail = 0;
q->cq_head = 0;
q->cq_phase = 1;
if (anv->hw->has_lsq_nvmmu)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 557/982] Revert "nvme-apple: Prevent shared tags across queues on Apple A11"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (555 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 556/982] Revert "nvme-apple: Reset q->sq_tail during queue init" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 558/982] Revert "nvme-apple: Drop the PRP null check chicken bit" Greg Kroah-Hartman
` (431 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 91d3b243bffe5c94503c9a8ea478a080f79ec58e.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/apple.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/nvme/host/apple.c b/drivers/nvme/host/apple.c
index 060f80c5ebeda..6fb881f3807c5 100644
--- a/drivers/nvme/host/apple.c
+++ b/drivers/nvme/host/apple.c
@@ -239,7 +239,7 @@ static unsigned int apple_nvme_queue_depth(struct apple_nvme_queue *q)
{
struct apple_nvme *anv = queue_to_apple_nvme(q);
- if (q->is_adminq)
+ if (q->is_adminq && anv->hw->has_lsq_nvmmu)
return APPLE_NVME_AQ_DEPTH;
return anv->hw->max_queue_depth;
@@ -317,7 +317,7 @@ static void apple_nvme_submit_cmd_t8015(struct apple_nvme_queue *q,
memcpy((void *)q->sqes + (q->sq_tail << APPLE_NVME_IOSQES),
cmd, sizeof(*cmd));
- if (++q->sq_tail == apple_nvme_queue_depth(q))
+ if (++q->sq_tail == anv->hw->max_queue_depth)
q->sq_tail = 0;
writel(q->sq_tail, q->sq_db);
@@ -1114,7 +1114,10 @@ static void apple_nvme_reset_work(struct work_struct *work)
}
/* Setup the admin queue */
- aqa = APPLE_NVME_AQ_DEPTH - 1;
+ if (anv->hw->has_lsq_nvmmu)
+ aqa = APPLE_NVME_AQ_DEPTH - 1;
+ else
+ aqa = anv->hw->max_queue_depth - 1;
aqa |= aqa << 16;
writel(aqa, anv->mmio_nvme + NVME_REG_AQA);
writeq(anv->adminq.sq_dma_addr, anv->mmio_nvme + NVME_REG_ASQ);
@@ -1297,7 +1300,8 @@ static int apple_nvme_alloc_tagsets(struct apple_nvme *anv)
* both queues. The admin queue gets the first APPLE_NVME_AQ_DEPTH which
* must be marked as reserved in the IO queue.
*/
- anv->tagset.reserved_tags = APPLE_NVME_AQ_DEPTH;
+ if (anv->hw->has_lsq_nvmmu)
+ anv->tagset.reserved_tags = APPLE_NVME_AQ_DEPTH;
anv->tagset.queue_depth = anv->hw->max_queue_depth - 1;
anv->tagset.timeout = NVME_IO_TIMEOUT;
anv->tagset.numa_node = NUMA_NO_NODE;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 558/982] Revert "nvme-apple: Drop the PRP null check chicken bit"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (556 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 557/982] Revert "nvme-apple: Prevent shared tags across queues on Apple A11" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 559/982] Revert "nvme: apple: Add Apple A11 support" Greg Kroah-Hartman
` (430 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 201edb5f22d4d126a48fb69850a2a7f190982e59.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/apple.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/drivers/nvme/host/apple.c b/drivers/nvme/host/apple.c
index 6fb881f3807c5..778cd619aeebd 100644
--- a/drivers/nvme/host/apple.c
+++ b/drivers/nvme/host/apple.c
@@ -47,6 +47,9 @@
#define APPLE_ANS_BOOT_STATUS 0x1300
#define APPLE_ANS_BOOT_STATUS_OK 0xde71ce55
+#define APPLE_ANS_UNKNOWN_CTRL 0x24008
+#define APPLE_ANS_PRP_NULL_CHECK BIT(11)
+
#define APPLE_ANS_LINEAR_SQ_CTRL 0x24908
#define APPLE_ANS_LINEAR_SQ_EN BIT(0)
@@ -1111,6 +1114,17 @@ static void apple_nvme_reset_work(struct work_struct *work)
/* Setup the NVMMU for the maximum admin and IO queue depth */
writel(anv->hw->max_queue_depth - 1,
anv->mmio_nvme + APPLE_NVMMU_NUM_TCBS);
+
+ /*
+ * This is probably a chicken bit: without it all commands
+ * where any PRP is set to zero (including those that don't use
+ * that field) fail and the co-processor complains about
+ * "completed with err BAD_CMD-" or a "NULL_PRP_PTR_ERR" in the
+ * syslog
+ */
+ writel(readl(anv->mmio_nvme + APPLE_ANS_UNKNOWN_CTRL) &
+ ~APPLE_ANS_PRP_NULL_CHECK,
+ anv->mmio_nvme + APPLE_ANS_UNKNOWN_CTRL);
}
/* Setup the admin queue */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 559/982] Revert "nvme: apple: Add Apple A11 support"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (557 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 558/982] Revert "nvme-apple: Drop the PRP null check chicken bit" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 560/982] Revert "perf tests: Fix flakiness in BPF counters test on hybrid systems" Greg Kroah-Hartman
` (429 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 655b6743bd900df39354e8bb6f1f2f8671fca004.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/apple.c | 197 ++++++++++++--------------------------
1 file changed, 60 insertions(+), 137 deletions(-)
diff --git a/drivers/nvme/host/apple.c b/drivers/nvme/host/apple.c
index 778cd619aeebd..994cf755de093 100644
--- a/drivers/nvme/host/apple.c
+++ b/drivers/nvme/host/apple.c
@@ -35,6 +35,7 @@
#include "nvme.h"
#define APPLE_ANS_BOOT_TIMEOUT USEC_PER_SEC
+#define APPLE_ANS_MAX_QUEUE_DEPTH 64
#define APPLE_ANS_COPROC_CPU_CONTROL 0x44
#define APPLE_ANS_COPROC_CPU_CONTROL_RUN BIT(4)
@@ -74,8 +75,6 @@
#define APPLE_NVME_AQ_DEPTH 2
#define APPLE_NVME_AQ_MQ_TAG_DEPTH (APPLE_NVME_AQ_DEPTH - 1)
-#define APPLE_NVME_IOSQES 7
-
/*
* These can be higher, but we need to ensure that any command doesn't
* require an sg allocation that needs more than a page of data.
@@ -143,7 +142,6 @@ struct apple_nvme_queue {
u32 __iomem *sq_db;
u32 __iomem *cq_db;
- u16 sq_tail;
u16 cq_head;
u8 cq_phase;
@@ -185,17 +183,11 @@ struct apple_nvme_iod {
struct scatterlist *sg;
};
-struct apple_nvme_hw {
- bool has_lsq_nvmmu;
- u32 max_queue_depth;
-};
-
struct apple_nvme {
struct device *dev;
void __iomem *mmio_coproc;
void __iomem *mmio_nvme;
- const struct apple_nvme_hw *hw;
struct device **pd_dev;
struct device_link **pd_link;
@@ -240,12 +232,10 @@ static inline struct apple_nvme *queue_to_apple_nvme(struct apple_nvme_queue *q)
static unsigned int apple_nvme_queue_depth(struct apple_nvme_queue *q)
{
- struct apple_nvme *anv = queue_to_apple_nvme(q);
-
- if (q->is_adminq && anv->hw->has_lsq_nvmmu)
+ if (q->is_adminq)
return APPLE_NVME_AQ_DEPTH;
- return anv->hw->max_queue_depth;
+ return APPLE_ANS_MAX_QUEUE_DEPTH;
}
static void apple_nvme_rtkit_crashed(void *cookie)
@@ -307,28 +297,7 @@ static void apple_nvmmu_inval(struct apple_nvme_queue *q, unsigned int tag)
"NVMMU TCB invalidation failed\n");
}
-static void apple_nvme_submit_cmd_t8015(struct apple_nvme_queue *q,
- struct nvme_command *cmd)
-{
- struct apple_nvme *anv = queue_to_apple_nvme(q);
-
- spin_lock_irq(&anv->lock);
-
- if (q->is_adminq)
- memcpy(&q->sqes[q->sq_tail], cmd, sizeof(*cmd));
- else
- memcpy((void *)q->sqes + (q->sq_tail << APPLE_NVME_IOSQES),
- cmd, sizeof(*cmd));
-
- if (++q->sq_tail == anv->hw->max_queue_depth)
- q->sq_tail = 0;
-
- writel(q->sq_tail, q->sq_db);
- spin_unlock_irq(&anv->lock);
-}
-
-
-static void apple_nvme_submit_cmd_t8103(struct apple_nvme_queue *q,
+static void apple_nvme_submit_cmd(struct apple_nvme_queue *q,
struct nvme_command *cmd)
{
struct apple_nvme *anv = queue_to_apple_nvme(q);
@@ -640,8 +609,7 @@ static inline void apple_nvme_handle_cqe(struct apple_nvme_queue *q,
__u16 command_id = READ_ONCE(cqe->command_id);
struct request *req;
- if (anv->hw->has_lsq_nvmmu)
- apple_nvmmu_inval(q, command_id);
+ apple_nvmmu_inval(q, command_id);
req = nvme_find_rq(apple_nvme_queue_tagset(anv, q), command_id);
if (unlikely(!req)) {
@@ -735,7 +703,7 @@ static int apple_nvme_create_cq(struct apple_nvme *anv)
c.create_cq.opcode = nvme_admin_create_cq;
c.create_cq.prp1 = cpu_to_le64(anv->ioq.cq_dma_addr);
c.create_cq.cqid = cpu_to_le16(1);
- c.create_cq.qsize = cpu_to_le16(anv->hw->max_queue_depth - 1);
+ c.create_cq.qsize = cpu_to_le16(APPLE_ANS_MAX_QUEUE_DEPTH - 1);
c.create_cq.cq_flags = cpu_to_le16(NVME_QUEUE_PHYS_CONTIG | NVME_CQ_IRQ_ENABLED);
c.create_cq.irq_vector = cpu_to_le16(0);
@@ -763,7 +731,7 @@ static int apple_nvme_create_sq(struct apple_nvme *anv)
c.create_sq.opcode = nvme_admin_create_sq;
c.create_sq.prp1 = cpu_to_le64(anv->ioq.sq_dma_addr);
c.create_sq.sqid = cpu_to_le16(1);
- c.create_sq.qsize = cpu_to_le16(anv->hw->max_queue_depth - 1);
+ c.create_sq.qsize = cpu_to_le16(APPLE_ANS_MAX_QUEUE_DEPTH - 1);
c.create_sq.sq_flags = cpu_to_le16(NVME_QUEUE_PHYS_CONTIG);
c.create_sq.cqid = cpu_to_le16(1);
@@ -815,12 +783,7 @@ static blk_status_t apple_nvme_queue_rq(struct blk_mq_hw_ctx *hctx,
}
nvme_start_request(req);
-
- if (anv->hw->has_lsq_nvmmu)
- apple_nvme_submit_cmd_t8103(q, cmnd);
- else
- apple_nvme_submit_cmd_t8015(q, cmnd);
-
+ apple_nvme_submit_cmd(q, cmnd);
return BLK_STS_OK;
out_free_cmd:
@@ -1010,13 +973,11 @@ static const struct blk_mq_ops apple_nvme_mq_ops = {
static void apple_nvme_init_queue(struct apple_nvme_queue *q)
{
unsigned int depth = apple_nvme_queue_depth(q);
- struct apple_nvme *anv = queue_to_apple_nvme(q);
q->cq_head = 0;
q->cq_phase = 1;
- if (anv->hw->has_lsq_nvmmu)
- memset(q->tcbs, 0, anv->hw->max_queue_depth
- * sizeof(struct apple_nvmmu_tcb));
+ memset(q->tcbs, 0,
+ APPLE_ANS_MAX_QUEUE_DEPTH * sizeof(struct apple_nvmmu_tcb));
memset(q->cqes, 0, depth * sizeof(struct nvme_completion));
apple_nvme_enable_queue(q);
}
@@ -1098,55 +1059,49 @@ static void apple_nvme_reset_work(struct work_struct *work)
dma_set_max_seg_size(anv->dev, 0xffffffff);
- if (anv->hw->has_lsq_nvmmu) {
- /*
- * Enable NVMMU and linear submission queues which is required
- * since T6000.
- */
- writel(APPLE_ANS_LINEAR_SQ_EN,
- anv->mmio_nvme + APPLE_ANS_LINEAR_SQ_CTRL);
+ /*
+ * Enable NVMMU and linear submission queues.
+ * While we could keep those disabled and pretend this is slightly
+ * more common NVMe controller we'd still need some quirks (e.g.
+ * sq entries will be 128 bytes) and Apple might drop support for
+ * that mode in the future.
+ */
+ writel(APPLE_ANS_LINEAR_SQ_EN,
+ anv->mmio_nvme + APPLE_ANS_LINEAR_SQ_CTRL);
- /* Allow as many pending command as possible for both queues */
- writel(anv->hw->max_queue_depth
- | (anv->hw->max_queue_depth << 16), anv->mmio_nvme
- + APPLE_ANS_MAX_PEND_CMDS_CTRL);
+ /* Allow as many pending command as possible for both queues */
+ writel(APPLE_ANS_MAX_QUEUE_DEPTH | (APPLE_ANS_MAX_QUEUE_DEPTH << 16),
+ anv->mmio_nvme + APPLE_ANS_MAX_PEND_CMDS_CTRL);
- /* Setup the NVMMU for the maximum admin and IO queue depth */
- writel(anv->hw->max_queue_depth - 1,
- anv->mmio_nvme + APPLE_NVMMU_NUM_TCBS);
+ /* Setup the NVMMU for the maximum admin and IO queue depth */
+ writel(APPLE_ANS_MAX_QUEUE_DEPTH - 1,
+ anv->mmio_nvme + APPLE_NVMMU_NUM_TCBS);
- /*
- * This is probably a chicken bit: without it all commands
- * where any PRP is set to zero (including those that don't use
- * that field) fail and the co-processor complains about
- * "completed with err BAD_CMD-" or a "NULL_PRP_PTR_ERR" in the
- * syslog
- */
- writel(readl(anv->mmio_nvme + APPLE_ANS_UNKNOWN_CTRL) &
- ~APPLE_ANS_PRP_NULL_CHECK,
- anv->mmio_nvme + APPLE_ANS_UNKNOWN_CTRL);
- }
+ /*
+ * This is probably a chicken bit: without it all commands where any PRP
+ * is set to zero (including those that don't use that field) fail and
+ * the co-processor complains about "completed with err BAD_CMD-" or
+ * a "NULL_PRP_PTR_ERR" in the syslog
+ */
+ writel(readl(anv->mmio_nvme + APPLE_ANS_UNKNOWN_CTRL) &
+ ~APPLE_ANS_PRP_NULL_CHECK,
+ anv->mmio_nvme + APPLE_ANS_UNKNOWN_CTRL);
/* Setup the admin queue */
- if (anv->hw->has_lsq_nvmmu)
- aqa = APPLE_NVME_AQ_DEPTH - 1;
- else
- aqa = anv->hw->max_queue_depth - 1;
+ aqa = APPLE_NVME_AQ_DEPTH - 1;
aqa |= aqa << 16;
writel(aqa, anv->mmio_nvme + NVME_REG_AQA);
writeq(anv->adminq.sq_dma_addr, anv->mmio_nvme + NVME_REG_ASQ);
writeq(anv->adminq.cq_dma_addr, anv->mmio_nvme + NVME_REG_ACQ);
- if (anv->hw->has_lsq_nvmmu) {
- /* Setup NVMMU for both queues */
- writeq(anv->adminq.tcb_dma_addr,
- anv->mmio_nvme + APPLE_NVMMU_ASQ_TCB_BASE);
- writeq(anv->ioq.tcb_dma_addr,
- anv->mmio_nvme + APPLE_NVMMU_IOSQ_TCB_BASE);
- }
+ /* Setup NVMMU for both queues */
+ writeq(anv->adminq.tcb_dma_addr,
+ anv->mmio_nvme + APPLE_NVMMU_ASQ_TCB_BASE);
+ writeq(anv->ioq.tcb_dma_addr,
+ anv->mmio_nvme + APPLE_NVMMU_IOSQ_TCB_BASE);
anv->ctrl.sqsize =
- anv->hw->max_queue_depth - 1; /* 0's based queue depth */
+ APPLE_ANS_MAX_QUEUE_DEPTH - 1; /* 0's based queue depth */
anv->ctrl.cap = readq(anv->mmio_nvme + NVME_REG_CAP);
dev_dbg(anv->dev, "Enabling controller now");
@@ -1314,9 +1269,8 @@ static int apple_nvme_alloc_tagsets(struct apple_nvme *anv)
* both queues. The admin queue gets the first APPLE_NVME_AQ_DEPTH which
* must be marked as reserved in the IO queue.
*/
- if (anv->hw->has_lsq_nvmmu)
- anv->tagset.reserved_tags = APPLE_NVME_AQ_DEPTH;
- anv->tagset.queue_depth = anv->hw->max_queue_depth - 1;
+ anv->tagset.reserved_tags = APPLE_NVME_AQ_DEPTH;
+ anv->tagset.queue_depth = APPLE_ANS_MAX_QUEUE_DEPTH - 1;
anv->tagset.timeout = NVME_IO_TIMEOUT;
anv->tagset.numa_node = NUMA_NO_NODE;
anv->tagset.cmd_size = sizeof(struct apple_nvme_iod);
@@ -1341,7 +1295,6 @@ static int apple_nvme_queue_alloc(struct apple_nvme *anv,
struct apple_nvme_queue *q)
{
unsigned int depth = apple_nvme_queue_depth(q);
- size_t iosq_size;
q->cqes = dmam_alloc_coherent(anv->dev,
depth * sizeof(struct nvme_completion),
@@ -1349,28 +1302,22 @@ static int apple_nvme_queue_alloc(struct apple_nvme *anv,
if (!q->cqes)
return -ENOMEM;
- if (anv->hw->has_lsq_nvmmu)
- iosq_size = depth * sizeof(struct nvme_command);
- else
- iosq_size = depth << APPLE_NVME_IOSQES;
-
- q->sqes = dmam_alloc_coherent(anv->dev, iosq_size,
+ q->sqes = dmam_alloc_coherent(anv->dev,
+ depth * sizeof(struct nvme_command),
&q->sq_dma_addr, GFP_KERNEL);
if (!q->sqes)
return -ENOMEM;
- if (anv->hw->has_lsq_nvmmu) {
- /*
- * We need the maximum queue depth here because the NVMMU only
- * has a single depth configuration shared between both queues.
- */
- q->tcbs = dmam_alloc_coherent(anv->dev,
- anv->hw->max_queue_depth *
- sizeof(struct apple_nvmmu_tcb),
- &q->tcb_dma_addr, GFP_KERNEL);
- if (!q->tcbs)
- return -ENOMEM;
- }
+ /*
+ * We need the maximum queue depth here because the NVMMU only has a
+ * single depth configuration shared between both queues.
+ */
+ q->tcbs = dmam_alloc_coherent(anv->dev,
+ APPLE_ANS_MAX_QUEUE_DEPTH *
+ sizeof(struct apple_nvmmu_tcb),
+ &q->tcb_dma_addr, GFP_KERNEL);
+ if (!q->tcbs)
+ return -ENOMEM;
/*
* initialize phase to make sure the allocated and empty memory
@@ -1454,12 +1401,6 @@ static int apple_nvme_probe(struct platform_device *pdev)
anv->adminq.is_adminq = true;
platform_set_drvdata(pdev, anv);
- anv->hw = of_device_get_match_data(&pdev->dev);
- if (!anv->hw) {
- ret = -ENODEV;
- goto put_dev;
- }
-
ret = apple_nvme_attach_genpd(anv);
if (ret < 0) {
dev_err_probe(dev, ret, "Failed to attach power domains");
@@ -1491,17 +1432,10 @@ static int apple_nvme_probe(struct platform_device *pdev)
goto put_dev;
}
- if (anv->hw->has_lsq_nvmmu) {
- anv->adminq.sq_db = anv->mmio_nvme + APPLE_ANS_LINEAR_ASQ_DB;
- anv->adminq.cq_db = anv->mmio_nvme + APPLE_ANS_ACQ_DB;
- anv->ioq.sq_db = anv->mmio_nvme + APPLE_ANS_LINEAR_IOSQ_DB;
- anv->ioq.cq_db = anv->mmio_nvme + APPLE_ANS_IOCQ_DB;
- } else {
- anv->adminq.sq_db = anv->mmio_nvme + NVME_REG_DBS;
- anv->adminq.cq_db = anv->mmio_nvme + APPLE_ANS_ACQ_DB;
- anv->ioq.sq_db = anv->mmio_nvme + NVME_REG_DBS + 8;
- anv->ioq.cq_db = anv->mmio_nvme + APPLE_ANS_IOCQ_DB;
- }
+ anv->adminq.sq_db = anv->mmio_nvme + APPLE_ANS_LINEAR_ASQ_DB;
+ anv->adminq.cq_db = anv->mmio_nvme + APPLE_ANS_ACQ_DB;
+ anv->ioq.sq_db = anv->mmio_nvme + APPLE_ANS_LINEAR_IOSQ_DB;
+ anv->ioq.cq_db = anv->mmio_nvme + APPLE_ANS_IOCQ_DB;
anv->sart = devm_apple_sart_get(dev);
if (IS_ERR(anv->sart)) {
@@ -1659,19 +1593,8 @@ static int apple_nvme_suspend(struct device *dev)
static DEFINE_SIMPLE_DEV_PM_OPS(apple_nvme_pm_ops, apple_nvme_suspend,
apple_nvme_resume);
-static const struct apple_nvme_hw apple_nvme_t8015_hw = {
- .has_lsq_nvmmu = false,
- .max_queue_depth = 16,
-};
-
-static const struct apple_nvme_hw apple_nvme_t8103_hw = {
- .has_lsq_nvmmu = true,
- .max_queue_depth = 64,
-};
-
static const struct of_device_id apple_nvme_of_match[] = {
- { .compatible = "apple,t8015-nvme-ans2", .data = &apple_nvme_t8015_hw },
- { .compatible = "apple,nvme-ans2", .data = &apple_nvme_t8103_hw },
+ { .compatible = "apple,nvme-ans2" },
{},
};
MODULE_DEVICE_TABLE(of, apple_nvme_of_match);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 560/982] Revert "perf tests: Fix flakiness in BPF counters test on hybrid systems"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (558 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 559/982] Revert "nvme: apple: Add Apple A11 support" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 561/982] usb: xusbatm: dont rely on id table pointer arithmetic Greg Kroah-Hartman
` (428 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 08c1316f983d3e1777f9087bb466dc5cf9a476f8.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/stat_bpf_counters.sh | 28 ++++++++-------------
1 file changed, 10 insertions(+), 18 deletions(-)
diff --git a/tools/perf/tests/shell/stat_bpf_counters.sh b/tools/perf/tests/shell/stat_bpf_counters.sh
index 76d4a7f15a43d..b776ee2e445a6 100755
--- a/tools/perf/tests/shell/stat_bpf_counters.sh
+++ b/tools/perf/tests/shell/stat_bpf_counters.sh
@@ -4,26 +4,21 @@
set -e
-# Get the first allowed CPU
-CPU=$(taskset -c -p $$ | awk -F': ' '{print $2}' | awk -F'[,-]' '{print $1}')
-if [ -z "$CPU" ]; then
- CPU=0
-fi
-workload=(taskset -c "$CPU" awk 'BEGIN { for (i=0; i<10000000; i++) sum+=i }')
+workload="perf test -w sqrtloop"
-# check whether $2 is within +/- 15% of $1
+# check whether $2 is within +/- 20% of $1
compare_number()
{
first_num=$1
second_num=$2
- # upper bound is first_num * 115%
- upper=$(expr $first_num + $first_num / 20 \* 3 )
- # lower bound is first_num * 85%
- lower=$(expr $first_num - $first_num / 20 \* 3 )
+ # upper bound is first_num * 120%
+ upper=$(expr $first_num + $first_num / 5 )
+ # lower bound is first_num * 80%
+ lower=$(expr $first_num - $first_num / 5 )
if [ $second_num -gt $upper ] || [ $second_num -lt $lower ]; then
- echo "The difference between $first_num and $second_num are greater than 15%."
+ echo "The difference between $first_num and $second_num are greater than 20%."
exit 1
fi
}
@@ -46,12 +41,11 @@ check_counts()
test_bpf_counters()
{
printf "Testing --bpf-counters "
- base_instructions=$(perf stat --no-big-num -e instructions:u -- "${workload[@]}" 2>&1 | \
+ base_instructions=$(perf stat --no-big-num -e instructions -- $workload 2>&1 | \
awk -v i=0 -v c=0 '/instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
} END { if (i > 0) printf "%.0f", c; else print "<not" }')
- bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions:u \
- -- "${workload[@]}" 2>&1 | \
+ bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions -- $workload 2>&1 | \
awk -v i=0 -v c=0 '/instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
} END { if (i > 0) printf "%.0f", c; else print "<not" }')
@@ -63,9 +57,7 @@ test_bpf_counters()
test_bpf_modifier()
{
printf "Testing bpf event modifier "
- stat_output=$(perf stat --no-big-num \
- -e instructions/name=base_instructions/u,instructions/name=bpf_instructions/bu \
- -- "${workload[@]}" 2>&1)
+ stat_output=$(perf stat --no-big-num -e instructions/name=base_instructions/,instructions/name=bpf_instructions/b -- $workload 2>&1)
base_instructions=$(echo "$stat_output"| \
awk -v i=0 -v c=0 '/base_instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 561/982] usb: xusbatm: dont rely on id table pointer arithmetic
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (559 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 560/982] Revert "perf tests: Fix flakiness in BPF counters test on hybrid systems" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 562/982] wifi: ath9k_htc: dont store usb_device_id Greg Kroah-Hartman
` (427 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gary Guo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gary Guo <gary@garyguo.net>
[ Upstream commit eb6cd6d3d8abeac5d7e8251b898067184afdad8a ]
The current code is broken when dynamic ID is involved; in such cases
usb_device_id parameter of probe lives on the heap and the pointer
arithmetic will get an index that is wildly out of bound. xusbatm
initialize the USB device IDs dynamically so it can just use driver_info
too.
Even with conversion, xusbatm still cannot support dynamic IDs, so also set
no_dynamic_id.
Signed-off-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-6-632dcf3adfba@garyguo.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/atm/xusbatm.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/usb/atm/xusbatm.c b/drivers/usb/atm/xusbatm.c
index 0befbf63d1cc8..5c1e1f5215555 100644
--- a/drivers/usb/atm/xusbatm.c
+++ b/drivers/usb/atm/xusbatm.c
@@ -79,7 +79,7 @@ static int xusbatm_bind(struct usbatm_data *usbatm,
struct usb_interface *intf, const struct usb_device_id *id)
{
struct usb_device *usb_dev = interface_to_usbdev(intf);
- int drv_ix = id - xusbatm_usb_ids;
+ int drv_ix = id->driver_info;
int rx_alt = rx_altsetting[drv_ix];
int tx_alt = tx_altsetting[drv_ix];
struct usb_interface *rx_intf = xusbatm_find_intf(usb_dev, rx_alt, rx_endpoint[drv_ix]);
@@ -168,7 +168,8 @@ static struct usb_driver xusbatm_usb_driver = {
.name = xusbatm_driver_name,
.probe = xusbatm_usb_probe,
.disconnect = usbatm_usb_disconnect,
- .id_table = xusbatm_usb_ids
+ .id_table = xusbatm_usb_ids,
+ .no_dynamic_id = 1,
};
static int __init xusbatm_init(void)
@@ -190,6 +191,7 @@ static int __init xusbatm_init(void)
xusbatm_usb_ids[i].match_flags = USB_DEVICE_ID_MATCH_DEVICE;
xusbatm_usb_ids[i].idVendor = vendor[i];
xusbatm_usb_ids[i].idProduct = product[i];
+ xusbatm_usb_ids[i].driver_info = i;
xusbatm_drivers[i].driver_name = xusbatm_driver_name;
xusbatm_drivers[i].bind = xusbatm_bind;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 562/982] wifi: ath9k_htc: dont store usb_device_id
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (560 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 561/982] usb: xusbatm: dont rely on id table pointer arithmetic Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 563/982] usb: usbtmc: " Greg Kroah-Hartman
` (426 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gary Guo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gary Guo <gary@garyguo.net>
[ Upstream commit 14d2ac442d660e112efc0ce87ad10085013ed2b1 ]
usb_device_id is not guaranteed to live longer than probe due to presence
of dynamic ID. All information apart from driver_data can be easily
retrieved from usb_device, so just store driver_data.
Signed-off-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-1-632dcf3adfba@garyguo.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath9k/hif_usb.c | 12 ++++++------
drivers/net/wireless/ath/ath9k/hif_usb.h | 2 +-
2 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/drivers/net/wireless/ath/ath9k/hif_usb.c b/drivers/net/wireless/ath/ath9k/hif_usb.c
index 7650f14dca8da..0a36fe39d5a25 100644
--- a/drivers/net/wireless/ath/ath9k/hif_usb.c
+++ b/drivers/net/wireless/ath/ath9k/hif_usb.c
@@ -1099,7 +1099,7 @@ static int ath9k_hif_usb_download_fw(struct hif_device_usb *hif_dev)
}
kfree(buf);
- if (IS_AR7010_DEVICE(hif_dev->usb_device_id->driver_info))
+ if (IS_AR7010_DEVICE(hif_dev->id_info))
firm_offset = AR7010_FIRMWARE_TEXT;
else
firm_offset = AR9271_FIRMWARE_TEXT;
@@ -1194,7 +1194,7 @@ static int ath9k_hif_request_firmware(struct hif_device_usb *hif_dev,
if (MAJOR_VERSION_REQ == 1 && hif_dev->fw_minor_index == 3) {
const char *filename;
- if (IS_AR7010_DEVICE(hif_dev->usb_device_id->driver_info))
+ if (IS_AR7010_DEVICE(hif_dev->id_info))
filename = FIRMWARE_AR7010_1_1;
else
filename = FIRMWARE_AR9271;
@@ -1210,7 +1210,7 @@ static int ath9k_hif_request_firmware(struct hif_device_usb *hif_dev,
return -ENOENT;
} else {
- if (IS_AR7010_DEVICE(hif_dev->usb_device_id->driver_info))
+ if (IS_AR7010_DEVICE(hif_dev->id_info))
chip = "7010";
else
chip = "9271";
@@ -1267,9 +1267,9 @@ static void ath9k_hif_usb_firmware_cb(const struct firmware *fw, void *context)
ret = ath9k_htc_hw_init(hif_dev->htc_handle,
&hif_dev->interface->dev,
- hif_dev->usb_device_id->idProduct,
+ le16_to_cpu(hif_dev->udev->descriptor.idProduct),
hif_dev->udev->product,
- hif_dev->usb_device_id->driver_info);
+ hif_dev->id_info);
if (ret) {
ret = -EINVAL;
goto err_htc_hw_init;
@@ -1383,7 +1383,7 @@ static int ath9k_hif_usb_probe(struct usb_interface *interface,
hif_dev->udev = udev;
hif_dev->interface = interface;
- hif_dev->usb_device_id = id;
+ hif_dev->id_info = id->driver_info;
#ifdef CONFIG_PM
udev->reset_resume = 1;
#endif
diff --git a/drivers/net/wireless/ath/ath9k/hif_usb.h b/drivers/net/wireless/ath/ath9k/hif_usb.h
index 5985aa15ca931..96c59af629982 100644
--- a/drivers/net/wireless/ath/ath9k/hif_usb.h
+++ b/drivers/net/wireless/ath/ath9k/hif_usb.h
@@ -115,7 +115,7 @@ struct cmd_buf {
struct hif_device_usb {
struct usb_device *udev;
struct usb_interface *interface;
- const struct usb_device_id *usb_device_id;
+ int id_info;
const void *fw_data;
size_t fw_size;
struct completion fw_done;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 563/982] usb: usbtmc: dont store usb_device_id
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (561 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 562/982] wifi: ath9k_htc: dont store usb_device_id Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 564/982] media: as102: do not rely on id table address comparison Greg Kroah-Hartman
` (425 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manuel Ebner, Danilo Krummrich,
Gary Guo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gary Guo <gary@garyguo.net>
[ Upstream commit fc045acec1a501c97f84ae184aadce9dae4ba9b2 ]
usb_device_id is not guaranteed to live longer than probe due to presence
of dynamic ID. This stored ID is unused so remove it.
Reviewed-by: Manuel Ebner <manuelebner@mailbox.org>
Reviewed-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-2-632dcf3adfba@garyguo.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/class/usbtmc.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/usb/class/usbtmc.c b/drivers/usb/class/usbtmc.c
index 593db4491ff72..ac2683a976fa6 100644
--- a/drivers/usb/class/usbtmc.c
+++ b/drivers/usb/class/usbtmc.c
@@ -71,7 +71,6 @@ struct usbtmc_dev_capabilities {
* allocated for each USBTMC device in the driver's probe function.
*/
struct usbtmc_device_data {
- const struct usb_device_id *id;
struct usb_device *usb_dev;
struct usb_interface *intf;
struct list_head file_list;
@@ -2398,7 +2397,6 @@ static int usbtmc_probe(struct usb_interface *intf,
return -ENOMEM;
data->intf = intf;
- data->id = id;
data->usb_dev = usb_get_dev(interface_to_usbdev(intf));
usb_set_intfdata(intf, data);
kref_init(&data->kref);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 564/982] media: as102: do not rely on id table address comparison
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (562 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 563/982] usb: usbtmc: " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 565/982] net: usb: pegasus: dont rely on id table pointer arithmetic Greg Kroah-Hartman
` (424 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gary Guo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gary Guo <gary@garyguo.net>
[ Upstream commit 91a8c8c718889fc8ccf5c38b750d790e9f36f92d ]
The driver info should be retrieved using the driver_info field, not by
address comparison.
Signed-off-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-4-632dcf3adfba@garyguo.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/usb/as102/as102_usb_drv.c | 73 ++++++++++---------------
1 file changed, 30 insertions(+), 43 deletions(-)
diff --git a/drivers/media/usb/as102/as102_usb_drv.c b/drivers/media/usb/as102/as102_usb_drv.c
index 07f6d0331e4d9..083f1535e862f 100644
--- a/drivers/media/usb/as102/as102_usb_drv.c
+++ b/drivers/media/usb/as102/as102_usb_drv.c
@@ -24,35 +24,33 @@ static void as102_usb_stop_stream(struct as102_dev_t *dev);
static int as102_open(struct inode *inode, struct file *file);
static int as102_release(struct inode *inode, struct file *file);
-static const struct usb_device_id as102_usb_id_table[] = {
- { USB_DEVICE(AS102_USB_DEVICE_VENDOR_ID, AS102_USB_DEVICE_PID_0001) },
- { USB_DEVICE(PCTV_74E_USB_VID, PCTV_74E_USB_PID) },
- { USB_DEVICE(ELGATO_EYETV_DTT_USB_VID, ELGATO_EYETV_DTT_USB_PID) },
- { USB_DEVICE(NBOX_DVBT_DONGLE_USB_VID, NBOX_DVBT_DONGLE_USB_PID) },
- { USB_DEVICE(SKY_IT_DIGITAL_KEY_USB_VID, SKY_IT_DIGITAL_KEY_USB_PID) },
- { } /* Terminating entry */
+struct as102_dev_info {
+ const char *name;
+ /*
+ * eLNA configuration: devices built on the reference design work best
+ * with 0xA0, while custom designs seem to require 0xC0
+ */
+ uint8_t elna_cfg;
};
-/* Note that this table must always have the same number of entries as the
- as102_usb_id_table struct */
-static const char * const as102_device_names[] = {
- AS102_REFERENCE_DESIGN,
- AS102_PCTV_74E,
- AS102_ELGATO_EYETV_DTT_NAME,
- AS102_NBOX_DVBT_DONGLE_NAME,
- AS102_SKY_IT_DIGITAL_KEY_NAME,
- NULL /* Terminating entry */
-};
+#define DRIVER_INFO(dev_name, dev_elna_cfg) \
+ .driver_info = (kernel_ulong_t)&(const struct as102_dev_info){ \
+ .name = (dev_name), \
+ .elna_cfg = (dev_elna_cfg), \
+ }
-/* eLNA configuration: devices built on the reference design work best
- with 0xA0, while custom designs seem to require 0xC0 */
-static uint8_t const as102_elna_cfg[] = {
- 0xA0,
- 0xC0,
- 0xC0,
- 0xA0,
- 0xA0,
- 0x00 /* Terminating entry */
+static const struct usb_device_id as102_usb_id_table[] = {
+ { USB_DEVICE(AS102_USB_DEVICE_VENDOR_ID, AS102_USB_DEVICE_PID_0001),
+ DRIVER_INFO(AS102_REFERENCE_DESIGN, 0xA0) },
+ { USB_DEVICE(PCTV_74E_USB_VID, PCTV_74E_USB_PID),
+ DRIVER_INFO(AS102_PCTV_74E, 0xC0) },
+ { USB_DEVICE(ELGATO_EYETV_DTT_USB_VID, ELGATO_EYETV_DTT_USB_PID),
+ DRIVER_INFO(AS102_ELGATO_EYETV_DTT_NAME, 0xC0) },
+ { USB_DEVICE(NBOX_DVBT_DONGLE_USB_VID, NBOX_DVBT_DONGLE_USB_PID),
+ DRIVER_INFO(AS102_NBOX_DVBT_DONGLE_NAME, 0xA0) },
+ { USB_DEVICE(SKY_IT_DIGITAL_KEY_USB_VID, SKY_IT_DIGITAL_KEY_USB_PID),
+ DRIVER_INFO(AS102_SKY_IT_DIGITAL_KEY_NAME, 0xA0) },
+ { } /* Terminating entry */
};
struct usb_driver as102_usb_driver = {
@@ -338,29 +336,18 @@ static int as102_usb_probe(struct usb_interface *intf,
{
int ret;
struct as102_dev_t *as102_dev;
- int i;
-
- /* This should never actually happen */
- if (ARRAY_SIZE(as102_usb_id_table) !=
- (sizeof(as102_device_names) / sizeof(const char *))) {
- pr_err("Device names table invalid size");
- return -EINVAL;
- }
+ const struct as102_dev_info *info = (const struct as102_dev_info *)id->driver_info;
as102_dev = kzalloc(sizeof(struct as102_dev_t), GFP_KERNEL);
if (as102_dev == NULL)
return -ENOMEM;
- /* Assign the user-friendly device name */
- for (i = 0; i < ARRAY_SIZE(as102_usb_id_table); i++) {
- if (id == &as102_usb_id_table[i]) {
- as102_dev->name = as102_device_names[i];
- as102_dev->elna_cfg = as102_elna_cfg[i];
- }
- }
-
- if (as102_dev->name == NULL)
+ if (info) {
+ as102_dev->name = info->name;
+ as102_dev->elna_cfg = info->elna_cfg;
+ } else {
as102_dev->name = "Unknown AS102 device";
+ }
/* set private callback functions */
as102_dev->bus_adap.ops = &as102_priv_ops;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 565/982] net: usb: pegasus: dont rely on id table pointer arithmetic
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (563 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 564/982] media: as102: do not rely on id table address comparison Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 566/982] ALSA: us122l: Prevent write upgrades for read mappings Greg Kroah-Hartman
` (423 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gary Guo, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gary Guo <gary@garyguo.net>
[ Upstream commit ce8101c331956bbd3e20681331dfd22eb7c1c1ea ]
The current code is broken when dynamic ID is involved; in such cases
usb_device_id parameter of probe lives on the heap and the pointer
arithmetic will get an index that is wildly out of bound. Instead of
keeping a side table for additional information, use driver_info field of
the usb_device_id.
The dynamic ID parsing code needs to be updated for this; convert it to
just write to the reserved entry for dynamic ID and remove the weird loop.
Signed-off-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-5-632dcf3adfba@garyguo.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/pegasus.c | 54 ++++++++++++++++-----------------------
drivers/net/usb/pegasus.h | 3 ---
2 files changed, 22 insertions(+), 35 deletions(-)
diff --git a/drivers/net/usb/pegasus.c b/drivers/net/usb/pegasus.c
index 475b066081c7f..8ec798f97f99b 100644
--- a/drivers/net/usb/pegasus.c
+++ b/drivers/net/usb/pegasus.c
@@ -46,21 +46,12 @@ static bool loopback;
static bool mii_mode;
static char *devid;
-static struct usb_eth_dev usb_dev_id[] = {
-#define PEGASUS_DEV(pn, vid, pid, flags) \
- {.name = pn, .vendor = vid, .device = pid, .private = flags},
-#define PEGASUS_DEV_CLASS(pn, vid, pid, dclass, flags) \
- PEGASUS_DEV(pn, vid, pid, flags)
-#include "pegasus.h"
-#undef PEGASUS_DEV
-#undef PEGASUS_DEV_CLASS
- {NULL, 0, 0, 0},
- {NULL, 0, 0, 0}
-};
+static struct usb_eth_dev dynamic_id_info = {};
static struct usb_device_id pegasus_ids[] = {
#define PEGASUS_DEV(pn, vid, pid, flags) \
- {.match_flags = USB_DEVICE_ID_MATCH_DEVICE, .idVendor = vid, .idProduct = pid},
+ {.match_flags = USB_DEVICE_ID_MATCH_DEVICE, .idVendor = vid, .idProduct = pid, \
+ .driver_info = (kernel_ulong_t)&(const struct usb_eth_dev) {.name = pn, .private = flags}},
/*
* The Belkin F8T012xx1 bluetooth adaptor has the same vendor and product
* IDs as the Belkin F5D5050, so we need to teach the pegasus driver to
@@ -69,7 +60,8 @@ static struct usb_device_id pegasus_ids[] = {
*/
#define PEGASUS_DEV_CLASS(pn, vid, pid, dclass, flags) \
{.match_flags = (USB_DEVICE_ID_MATCH_DEVICE | USB_DEVICE_ID_MATCH_DEV_CLASS), \
- .idVendor = vid, .idProduct = pid, .bDeviceClass = dclass},
+ .idVendor = vid, .idProduct = pid, .bDeviceClass = dclass, \
+ .driver_info = (kernel_ulong_t)&(const struct usb_eth_dev) {.name = pn, .private = flags}},
#include "pegasus.h"
#undef PEGASUS_DEV
#undef PEGASUS_DEV_CLASS
@@ -405,12 +397,12 @@ static inline int reset_mac(pegasus_t *pegasus)
if (i == REG_TIMEOUT)
return -ETIMEDOUT;
- if (usb_dev_id[pegasus->dev_index].vendor == VENDOR_LINKSYS ||
- usb_dev_id[pegasus->dev_index].vendor == VENDOR_DLINK) {
+ if (le16_to_cpu(pegasus->usb->descriptor.idVendor) == VENDOR_LINKSYS ||
+ le16_to_cpu(pegasus->usb->descriptor.idVendor) == VENDOR_DLINK) {
set_register(pegasus, Gpio0, 0x24);
set_register(pegasus, Gpio0, 0x26);
}
- if (usb_dev_id[pegasus->dev_index].vendor == VENDOR_ELCON) {
+ if (le16_to_cpu(pegasus->usb->descriptor.idVendor) == VENDOR_ELCON) {
__u16 auxmode;
ret = read_mii_word(pegasus, 3, 0x1b, &auxmode);
if (ret < 0)
@@ -448,9 +440,9 @@ static int enable_net_traffic(struct net_device *dev, struct usb_device *usb)
memcpy(pegasus->eth_regs, data, sizeof(data));
ret = set_registers(pegasus, EthCtrl0, 3, data);
- if (usb_dev_id[pegasus->dev_index].vendor == VENDOR_LINKSYS ||
- usb_dev_id[pegasus->dev_index].vendor == VENDOR_LINKSYS2 ||
- usb_dev_id[pegasus->dev_index].vendor == VENDOR_DLINK) {
+ if (le16_to_cpu(pegasus->usb->descriptor.idVendor) == VENDOR_LINKSYS ||
+ le16_to_cpu(pegasus->usb->descriptor.idVendor) == VENDOR_LINKSYS2 ||
+ le16_to_cpu(pegasus->usb->descriptor.idVendor) == VENDOR_DLINK) {
u16 auxmode;
ret = read_mii_word(pegasus, 0, 0x1b, &auxmode);
if (ret < 0)
@@ -1156,7 +1148,7 @@ static int pegasus_probe(struct usb_interface *intf,
struct usb_device *dev = interface_to_usbdev(intf);
struct net_device *net;
pegasus_t *pegasus;
- int dev_index = id - pegasus_ids;
+ const struct usb_eth_dev *info = (const struct usb_eth_dev *)id->driver_info;
int res = -ENOMEM;
static const u8 bulk_ep_addr[] = {
PEGASUS_USB_EP_BULK_IN | USB_DIR_IN,
@@ -1181,7 +1173,6 @@ static int pegasus_probe(struct usb_interface *intf,
goto out;
pegasus = netdev_priv(net);
- pegasus->dev_index = dev_index;
pegasus->intf = intf;
res = alloc_urbs(pegasus);
@@ -1209,7 +1200,7 @@ static int pegasus_probe(struct usb_interface *intf,
pegasus->msg_enable = netif_msg_init(msg_level, NETIF_MSG_DRV
| NETIF_MSG_PROBE | NETIF_MSG_LINK);
- pegasus->features = usb_dev_id[dev_index].private;
+ pegasus->features = info ? info->private : DEFAULT_GPIO_RESET;
res = get_interrupt_interval(pegasus);
if (res)
goto out2;
@@ -1238,7 +1229,7 @@ static int pegasus_probe(struct usb_interface *intf,
queue_delayed_work(system_long_wq, &pegasus->carrier_check,
CARRIER_CHECK_DELAY);
dev_info(&intf->dev, "%s, %s, %pM\n", net->name,
- usb_dev_id[dev_index].name, net->dev_addr);
+ info ? info->name : "(unknown)", net->dev_addr);
return 0;
out3:
@@ -1328,8 +1319,9 @@ static struct usb_driver pegasus_driver = {
static void __init parse_id(char *id)
{
- unsigned int vendor_id = 0, device_id = 0, flags = 0, i = 0;
+ unsigned int vendor_id = 0, device_id = 0, flags = 0;
char *token, *name = NULL;
+ int dyn_id_index = ARRAY_SIZE(pegasus_ids) - 2;
if ((token = strsep(&id, ":")) != NULL)
name = token;
@@ -1347,14 +1339,12 @@ static void __init parse_id(char *id)
if (device_id > 0x10000 || device_id == 0)
return;
- for (i = 0; usb_dev_id[i].name; i++);
- usb_dev_id[i].name = name;
- usb_dev_id[i].vendor = vendor_id;
- usb_dev_id[i].device = device_id;
- usb_dev_id[i].private = flags;
- pegasus_ids[i].match_flags = USB_DEVICE_ID_MATCH_DEVICE;
- pegasus_ids[i].idVendor = vendor_id;
- pegasus_ids[i].idProduct = device_id;
+ dynamic_id_info.name = name;
+ dynamic_id_info.private = flags;
+ pegasus_ids[dyn_id_index].match_flags = USB_DEVICE_ID_MATCH_DEVICE;
+ pegasus_ids[dyn_id_index].idVendor = vendor_id;
+ pegasus_ids[dyn_id_index].idProduct = device_id;
+ pegasus_ids[dyn_id_index].driver_info = (kernel_ulong_t)&dynamic_id_info;
}
static int __init pegasus_init(void)
diff --git a/drivers/net/usb/pegasus.h b/drivers/net/usb/pegasus.h
index a05b143155ba8..ccdedcef52e76 100644
--- a/drivers/net/usb/pegasus.h
+++ b/drivers/net/usb/pegasus.h
@@ -85,7 +85,6 @@ typedef struct pegasus {
unsigned features;
u32 msg_enable;
u32 wolopts;
- int dev_index;
int intr_interval;
struct tasklet_struct rx_tl;
struct delayed_work carrier_check;
@@ -102,8 +101,6 @@ typedef struct pegasus {
struct usb_eth_dev {
char *name;
- __u16 vendor;
- __u16 device;
__u32 private; /* LSB is gpio reset value */
};
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 566/982] ALSA: us122l: Prevent write upgrades for read mappings
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (564 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 565/982] net: usb: pegasus: dont rely on id table pointer arithmetic Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 567/982] i2c: smbus: reject oversized block transfers in the common path Greg Kroah-Hartman
` (422 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kazuki Hanai, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kazuki Hanai <hnkz.64@gmail.com>
[ Upstream commit 71c610aeb1770302ac9c9e0b9a4ecd37f1311928 ]
The hwdep mmap callback rejects read-buffer mappings that are initially
writable, but leaves VM_MAYWRITE set on mappings created with PROT_READ.
A process that can open the hwdep node O_RDWR can later use mprotect() to
make the mapping writable.
The read allocation begins with struct usb_stream. Its read_size member is
used by the fault handler to decide which pages belong to the read buffer.
The read VMA intentionally remains expandable because pcm_usb_stream uses
mremap() after reading that size. Changing read_size first can therefore
map and access pages beyond the allocation. The same member is also
consumed by usb_stream_free(), where changing it can make
free_pages_exact() release pages outside the allocation.
Clear VM_MAYWRITE for read-buffer mappings after rejecting an initially
writable VMA. This keeps the separate output-buffer mapping writable while
preventing later permission upgrades.
Fixes: 030a07e44129 ("ALSA: Add USB US122L driver")
Cc: stable@vger.kernel.org
Signed-off-by: Kazuki Hanai <hnkz.64@gmail.com>
Link: https://patch.msgid.link/20260908110053.2950767-1-hnkz.64@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/usx2y/us122l.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/sound/usb/usx2y/us122l.c b/sound/usb/usx2y/us122l.c
index 23d7d542a3de6..21c5a7fcea768 100644
--- a/sound/usb/usx2y/us122l.c
+++ b/sound/usb/usx2y/us122l.c
@@ -209,9 +209,12 @@ static int usb_stream_hwdep_mmap(struct snd_hwdep *hw,
mutex_lock(&us122l->mutex);
s = us122l->sk.s;
read = offset < s->read_size;
- if (read && area->vm_flags & VM_WRITE) {
- err = -EPERM;
- goto out;
+ if (read) {
+ if (area->vm_flags & VM_WRITE) {
+ err = -EPERM;
+ goto out;
+ }
+ area->vm_flags &= ~VM_MAYWRITE;
}
snd_printdd(KERN_DEBUG "%lu %u\n", size,
read ? s->read_size : s->write_size);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 567/982] i2c: smbus: reject oversized block transfers in the common path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (565 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 566/982] ALSA: us122l: Prevent write upgrades for read mappings Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 568/982] net: appletalk: fix NULL pointer dereference in aarp_send_ddp() Greg Kroah-Hartman
` (421 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi, Wolfram Sang
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit 3051cd060fa496df42954291fa2306ed2eab4ecc upstream.
The SMBus block transfer length data->block[0] is validated in
i2c_smbus_xfer_emulated() but that check runs too late for tracepoints
and is skipped entirely when the adapter provides a native smbus_xfer
implementation. This allows user-controlled oversized block lengths to
reach tracepoint memcpy calls and driver callbacks unchecked.
Add an early validation in __i2c_smbus_xfer() that rejects block
transfers whose caller-supplied length is zero or exceeds
I2C_SMBUS_BLOCK_MAX before any tracepoint fires or driver callback
runs. data->block[0] is filled in by the device on SMBus block reads,
so the check is scoped to operations where the length is actually
supplied by the caller. This is consistent with the existing -EINVAL
convention in the emulated path and protects all downstream consumers
at once: the smbus_write tracepoint, all native smbus_xfer driver
implementations, and the emulated path.
Two distinct bugs are fixed by this change:
Bug 1: smbus_write tracepoint OOB (include/trace/events/smbus.h)
trace_smbus_write() fires before any validation and copies
data->block[0]+1 bytes into a 34-byte event buffer. With
block[0]=0xfe the tracepoint copies 255 bytes, overflowing by 221.
BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_smbus_write+0x27c/0x530
Read of size 255 at addr ffff88800d98fcf8 by task poc_smbus/91
Call Trace:
<TASK>
__asan_memcpy+0x23/0x80
trace_event_raw_event_smbus_write+0x27c/0x530
__i2c_smbus_xfer+0x43a/0xa40
i2c_smbus_xfer+0x19e/0x340
i2cdev_ioctl_smbus+0x38f/0x7f0
i2cdev_ioctl+0x35e/0x680
__x64_sys_ioctl+0x147/0x1e0
do_syscall_64+0xcf/0x15a0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>
Bug 2: i2c-stub I2C_SMBUS_I2C_BLOCK_DATA OOB (drivers/i2c/i2c-stub.c)
stub_xfer() implements .smbus_xfer directly and only clamps
block[0] against 256-command, not I2C_SMBUS_BLOCK_MAX. With
block[0]=0xff and command=0 the loop accesses block[1+i] for
i up to 254, far past the 34-byte union.
UBSAN: array-index-out-of-bounds in drivers/i2c/i2c-stub.c:223:44
index 34 is out of range for type '__u8 [34]'
Call Trace:
<TASK>
__ubsan_handle_out_of_bounds+0xd7/0x120
stub_xfer+0x1971/0x198f [i2c_stub]
__i2c_smbus_xfer+0x306/0xa40
i2c_smbus_xfer+0x19e/0x340
i2cdev_ioctl_smbus+0x38f/0x7f0
i2cdev_ioctl+0x35e/0x680
__x64_sys_ioctl+0x147/0x1e0
do_syscall_64+0xcf/0x15a0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>
Both traces reproduced on v7.0-rc6+i2c/for-current with KASAN+UBSAN.
Fixes: 8a325997d95d ("i2c: Add message transfer tracepoints for SMBUS [ver #2]")
Fixes: 4710317891e4 ("i2c-stub: Implement I2C block support")
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/i2c-core-smbus.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
--- a/drivers/i2c/i2c-core-smbus.c
+++ b/drivers/i2c/i2c-core-smbus.c
@@ -565,6 +565,18 @@ s32 __i2c_smbus_xfer(struct i2c_adapter
if (res)
return res;
+ /* Reject invalid caller-supplied block lengths before any
+ * tracepoint or native smbus_xfer callback runs.
+ */
+ if (data &&
+ (protocol == I2C_SMBUS_I2C_BLOCK_DATA ||
+ protocol == I2C_SMBUS_BLOCK_PROC_CALL ||
+ (protocol == I2C_SMBUS_BLOCK_DATA &&
+ read_write == I2C_SMBUS_WRITE)) &&
+ (data->block[0] == 0 ||
+ data->block[0] > I2C_SMBUS_BLOCK_MAX))
+ return -EINVAL;
+
/* If enabled, the following two tracepoints are conditional on
* read_write and protocol.
*/
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 568/982] net: appletalk: fix NULL pointer dereference in aarp_send_ddp()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (566 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 567/982] i2c: smbus: reject oversized block transfers in the common path Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 569/982] fou: Fix use-after-free in fou_create() Greg Kroah-Hartman
` (420 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit 9e7f36ab5b7bf68463faa5f7b926fea8f35597bb upstream.
aarp_send_ddp() calls atalk_find_dev_addr(dev) in the LocalTalk fast
path without checking for NULL. When the device has no AppleTalk
interface configured (dev->atalk_ptr == NULL), this leads to a NULL
pointer dereference at the at->s_net access.
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: 0010:aarp_send_ddp (net/appletalk/aarp.c:552 (discriminator 2))
Call Trace:
<TASK>
atalk_sendmsg (net/appletalk/ddp.c:1715)
__sys_sendto (net/socket.c:2265 (discriminator 1))
__x64_sys_sendto (net/socket.c:2272)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Add a NULL check consistent with the other callers of
atalk_find_dev_addr().
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/20260514123806.3085961-3-bestswngs@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/appletalk/aarp.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/net/appletalk/aarp.c
+++ b/net/appletalk/aarp.c
@@ -573,6 +573,11 @@ int aarp_send_ddp(struct net_device *dev
struct ddpehdr *ddp = (struct ddpehdr *)skb->data;
int ft = 2;
+ if (!at) {
+ kfree_skb(skb);
+ return NET_XMIT_DROP;
+ }
+
/*
* Compressible ?
*
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 569/982] fou: Fix use-after-free in fou_create()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (567 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 568/982] net: appletalk: fix NULL pointer dereference in aarp_send_ddp() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 570/982] crypto: sun8i-ce - Remove crypto_rng interface Greg Kroah-Hartman
` (419 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Xuanqiang Luo,
Paolo Abeni, Dmitriy Okunev
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
commit b14361aca6350ff7907b0e9903c7b94dc7d5d4a0 upstream.
fou_create() publishes struct fou through sk_user_data before adding the
new FOU port to the per-netns list. If fou_add_to_port_list() fails,
the error path frees fou while it is still reachable through
sk_user_data. A concurrent receive can then dereference the freed
object in fou_from_sock().
This ordering issue was previously noted in the linked discussion.
The failure is reachable when local port 0 is requested. Each socket
binds to a different ephemeral port, but fou_cfg_cmp() compares the
requested port 0 and reports -EALREADY once an entry already exists.
Release the tunnel socket before freeing fou so sk_user_data is cleared
first, and defer reclamation with kfree_rcu() to protect concurrent RCU
readers. This matches the lifetime handling in fou_release().
Fixes: 23461551c006 ("fou: Support for foo-over-udp RX path")
Suggested-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://lore.kernel.org/netdev/20260502031401.3557229-12-kuniyu@google.com/
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260722083858.182506-1-xuanqiang.luo@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Dmitriy Okunev <dokunevdmitriy@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/fou_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/ipv4/fou_core.c
+++ b/net/ipv4/fou_core.c
@@ -636,9 +636,9 @@ static int fou_create(struct net *net, s
return 0;
error:
- kfree(fou);
if (sock)
udp_tunnel_sock_release(sock);
+ kfree_rcu(fou, rcu);
return err;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 570/982] crypto: sun8i-ce - Remove crypto_rng interface
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (568 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 569/982] fou: Fix use-after-free in fou_create() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 571/982] crypto: sun8i-ss " Greg Kroah-Hartman
` (418 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Corentin Labbe, Eric Biggers,
Herbert Xu
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Biggers <ebiggers@kernel.org>
commit 011556f71d094da61379ae3672692cae2795304e upstream.
Since the crypto_rng interface for hardware PRNGs is unused and is
redundant with hwrng and the actual Linux RNG, it's being phased out.
Most drivers for it were already removed. Go ahead and remove the
sun8i-ce support which is one of the only remaining ones.
Note that the sun8i-ce support for hwrng remains in place. That is the
interface that actually matters.
As usual for crypto_rng, this driver was also buggy: its ->generate()
function had a use-after-free vulnerability due to using
wait_for_completion_interruptible_timeout() without handling shutting
down the DMA operation if a signal is sent. There's no point in fixing
this separately only to remove the code anyway, so this commit is marked
with Fixes and Cc stable.
Fixes: 5eb7e9468884 ("crypto: sun8i-ce - Add support for the PRNG")
Cc: stable@vger.kernel.org
Cc: Corentin Labbe <clabbe.montjoie@gmail.com>
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/crypto/allwinner/Kconfig | 8 -
drivers/crypto/allwinner/sun8i-ce/Makefile | 1
drivers/crypto/allwinner/sun8i-ce/sun8i-ce-core.c | 55 -------
drivers/crypto/allwinner/sun8i-ce/sun8i-ce-prng.c | 160 ----------------------
drivers/crypto/allwinner/sun8i-ce/sun8i-ce.h | 29 ---
5 files changed, 253 deletions(-)
delete mode 100644 drivers/crypto/allwinner/sun8i-ce/sun8i-ce-prng.c
--- a/drivers/crypto/allwinner/Kconfig
+++ b/drivers/crypto/allwinner/Kconfig
@@ -70,14 +70,6 @@ config CRYPTO_DEV_SUN8I_CE_HASH
help
Say y to enable support for hash algorithms.
-config CRYPTO_DEV_SUN8I_CE_PRNG
- bool "Support for Allwinner Crypto Engine PRNG"
- depends on CRYPTO_DEV_SUN8I_CE
- select CRYPTO_RNG
- help
- Select this option if you want to provide kernel-side support for
- the Pseudo-Random Number Generator found in the Crypto Engine.
-
config CRYPTO_DEV_SUN8I_CE_TRNG
bool "Support for Allwinner Crypto Engine TRNG"
depends on CRYPTO_DEV_SUN8I_CE
--- a/drivers/crypto/allwinner/sun8i-ce/Makefile
+++ b/drivers/crypto/allwinner/sun8i-ce/Makefile
@@ -1,5 +1,4 @@
obj-$(CONFIG_CRYPTO_DEV_SUN8I_CE) += sun8i-ce.o
sun8i-ce-y += sun8i-ce-core.o sun8i-ce-cipher.o
sun8i-ce-$(CONFIG_CRYPTO_DEV_SUN8I_CE_HASH) += sun8i-ce-hash.o
-sun8i-ce-$(CONFIG_CRYPTO_DEV_SUN8I_CE_PRNG) += sun8i-ce-prng.o
sun8i-ce-$(CONFIG_CRYPTO_DEV_SUN8I_CE_TRNG) += sun8i-ce-trng.o
--- a/drivers/crypto/allwinner/sun8i-ce/sun8i-ce-core.c
+++ b/drivers/crypto/allwinner/sun8i-ce/sun8i-ce-core.c
@@ -22,7 +22,6 @@
#include <linux/platform_device.h>
#include <linux/pm_runtime.h>
#include <linux/reset.h>
-#include <crypto/internal/rng.h>
#include <crypto/internal/skcipher.h>
#include "sun8i-ce.h"
@@ -46,7 +45,6 @@ static const struct ce_variant ce_h3_var
{ "mod", 50000000, 0 },
},
.esr = ESR_H3,
- .prng = CE_ALG_PRNG,
.trng = CE_ID_NOTSUPP,
};
@@ -63,7 +61,6 @@ static const struct ce_variant ce_h5_var
{ "mod", 300000000, 0 },
},
.esr = ESR_H5,
- .prng = CE_ALG_PRNG,
.trng = CE_ID_NOTSUPP,
};
@@ -77,7 +74,6 @@ static const struct ce_variant ce_h6_var
},
.cipher_t_dlen_in_bytes = true,
.hash_t_dlen_in_bits = true,
- .prng_t_dlen_in_bytes = true,
.trng_t_dlen_in_bytes = true,
.ce_clks = {
{ "bus", 0, 200000000 },
@@ -85,7 +81,6 @@ static const struct ce_variant ce_h6_var
{ "ram", 0, 400000000 },
},
.esr = ESR_H6,
- .prng = CE_ALG_PRNG_V2,
.trng = CE_ALG_TRNG_V2,
};
@@ -102,7 +97,6 @@ static const struct ce_variant ce_a64_va
{ "mod", 300000000, 0 },
},
.esr = ESR_A64,
- .prng = CE_ALG_PRNG,
.trng = CE_ID_NOTSUPP,
};
@@ -120,7 +114,6 @@ static const struct ce_variant ce_d1_var
{ "ram", 0, 400000000 },
},
.esr = ESR_D1,
- .prng = CE_ALG_PRNG,
.trng = CE_ALG_TRNG,
};
@@ -137,7 +130,6 @@ static const struct ce_variant ce_r40_va
{ "mod", 300000000, 0 },
},
.esr = ESR_R40,
- .prng = CE_ALG_PRNG,
.trng = CE_ID_NOTSUPP,
};
@@ -560,25 +552,6 @@ static struct sun8i_ce_alg_template ce_a
}
},
#endif
-#ifdef CONFIG_CRYPTO_DEV_SUN8I_CE_PRNG
-{
- .type = CRYPTO_ALG_TYPE_RNG,
- .alg.rng = {
- .base = {
- .cra_name = "stdrng",
- .cra_driver_name = "sun8i-ce-prng",
- .cra_priority = 300,
- .cra_ctxsize = sizeof(struct sun8i_ce_rng_tfm_ctx),
- .cra_module = THIS_MODULE,
- .cra_init = sun8i_ce_prng_init,
- .cra_exit = sun8i_ce_prng_exit,
- },
- .generate = sun8i_ce_prng_generate,
- .seed = sun8i_ce_prng_seed,
- .seedsize = PRNG_SEED_SIZE,
- }
-},
-#endif
};
#ifdef CONFIG_CRYPTO_DEV_SUN8I_CE_DEBUG
@@ -634,12 +607,6 @@ static int sun8i_ce_debugfs_show(struct
seq_printf(seq, "\tFallback due to SG numbers: %lu\n",
ce_algs[i].stat_fb_maxsg);
break;
- case CRYPTO_ALG_TYPE_RNG:
- seq_printf(seq, "%s %s reqs=%lu bytes=%lu\n",
- ce_algs[i].alg.rng.base.cra_driver_name,
- ce_algs[i].alg.rng.base.cra_name,
- ce_algs[i].stat_req, ce_algs[i].stat_bytes);
- break;
}
}
#ifdef CONFIG_CRYPTO_DEV_SUN8I_CE_TRNG
@@ -880,23 +847,6 @@ static int sun8i_ce_register_algs(struct
return err;
}
break;
- case CRYPTO_ALG_TYPE_RNG:
- if (ce->variant->prng == CE_ID_NOTSUPP) {
- dev_info(ce->dev,
- "DEBUG: Algo of %s not supported\n",
- ce_algs[i].alg.rng.base.cra_name);
- ce_algs[i].ce = NULL;
- break;
- }
- dev_info(ce->dev, "Register %s\n",
- ce_algs[i].alg.rng.base.cra_name);
- err = crypto_register_rng(&ce_algs[i].alg.rng);
- if (err) {
- dev_err(ce->dev, "Fail to register %s\n",
- ce_algs[i].alg.rng.base.cra_name);
- ce_algs[i].ce = NULL;
- }
- break;
default:
ce_algs[i].ce = NULL;
dev_err(ce->dev, "ERROR: tried to register an unknown algo\n");
@@ -923,11 +873,6 @@ static void sun8i_ce_unregister_algs(str
ce_algs[i].alg.hash.halg.base.cra_name);
crypto_unregister_ahash(&ce_algs[i].alg.hash);
break;
- case CRYPTO_ALG_TYPE_RNG:
- dev_info(ce->dev, "Unregister %d %s\n", i,
- ce_algs[i].alg.rng.base.cra_name);
- crypto_unregister_rng(&ce_algs[i].alg.rng);
- break;
}
}
}
--- a/drivers/crypto/allwinner/sun8i-ce/sun8i-ce-prng.c
+++ /dev/null
@@ -1,160 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0
-/*
- * sun8i-ce-prng.c - hardware cryptographic offloader for
- * Allwinner H3/A64/H5/H2+/H6/R40 SoC
- *
- * Copyright (C) 2015-2020 Corentin Labbe <clabbe@baylibre.com>
- *
- * This file handle the PRNG
- *
- * You could find a link for the datasheet in Documentation/arm/sunxi.rst
- */
-#include "sun8i-ce.h"
-#include <linux/dma-mapping.h>
-#include <linux/pm_runtime.h>
-#include <crypto/internal/rng.h>
-
-int sun8i_ce_prng_init(struct crypto_tfm *tfm)
-{
- struct sun8i_ce_rng_tfm_ctx *ctx = crypto_tfm_ctx(tfm);
-
- memset(ctx, 0, sizeof(struct sun8i_ce_rng_tfm_ctx));
- return 0;
-}
-
-void sun8i_ce_prng_exit(struct crypto_tfm *tfm)
-{
- struct sun8i_ce_rng_tfm_ctx *ctx = crypto_tfm_ctx(tfm);
-
- kfree_sensitive(ctx->seed);
- ctx->seed = NULL;
- ctx->slen = 0;
-}
-
-int sun8i_ce_prng_seed(struct crypto_rng *tfm, const u8 *seed,
- unsigned int slen)
-{
- struct sun8i_ce_rng_tfm_ctx *ctx = crypto_rng_ctx(tfm);
-
- if (ctx->seed && ctx->slen != slen) {
- kfree_sensitive(ctx->seed);
- ctx->slen = 0;
- ctx->seed = NULL;
- }
- if (!ctx->seed)
- ctx->seed = kmalloc(slen, GFP_KERNEL | GFP_DMA);
- if (!ctx->seed)
- return -ENOMEM;
-
- memcpy(ctx->seed, seed, slen);
- ctx->slen = slen;
-
- return 0;
-}
-
-int sun8i_ce_prng_generate(struct crypto_rng *tfm, const u8 *src,
- unsigned int slen, u8 *dst, unsigned int dlen)
-{
- struct sun8i_ce_rng_tfm_ctx *ctx = crypto_rng_ctx(tfm);
- struct rng_alg *alg = crypto_rng_alg(tfm);
- struct sun8i_ce_alg_template *algt;
- struct sun8i_ce_dev *ce;
- dma_addr_t dma_iv, dma_dst;
- int err = 0;
- int flow = 3;
- unsigned int todo;
- struct sun8i_ce_flow *chan;
- struct ce_task *cet;
- u32 common, sym;
- void *d;
-
- algt = container_of(alg, struct sun8i_ce_alg_template, alg.rng);
- ce = algt->ce;
-
- if (ctx->slen == 0) {
- dev_err(ce->dev, "not seeded\n");
- return -EINVAL;
- }
-
- /* we want dlen + seedsize rounded up to a multiple of PRNG_DATA_SIZE */
- todo = dlen + ctx->slen + PRNG_DATA_SIZE * 2;
- todo -= todo % PRNG_DATA_SIZE;
-
- d = kzalloc(todo, GFP_KERNEL | GFP_DMA);
- if (!d) {
- err = -ENOMEM;
- goto err_mem;
- }
-
- dev_dbg(ce->dev, "%s PRNG slen=%u dlen=%u todo=%u multi=%u\n", __func__,
- slen, dlen, todo, todo / PRNG_DATA_SIZE);
-
-#ifdef CONFIG_CRYPTO_DEV_SUN8I_CE_DEBUG
- algt->stat_req++;
- algt->stat_bytes += todo;
-#endif
-
- dma_iv = dma_map_single(ce->dev, ctx->seed, ctx->slen, DMA_TO_DEVICE);
- if (dma_mapping_error(ce->dev, dma_iv)) {
- dev_err(ce->dev, "Cannot DMA MAP IV\n");
- err = -EFAULT;
- goto err_iv;
- }
-
- dma_dst = dma_map_single(ce->dev, d, todo, DMA_FROM_DEVICE);
- if (dma_mapping_error(ce->dev, dma_dst)) {
- dev_err(ce->dev, "Cannot DMA MAP DST\n");
- err = -EFAULT;
- goto err_dst;
- }
-
- err = pm_runtime_resume_and_get(ce->dev);
- if (err < 0)
- goto err_pm;
-
- mutex_lock(&ce->rnglock);
- chan = &ce->chanlist[flow];
-
- cet = &chan->tl[0];
- memset(cet, 0, sizeof(struct ce_task));
-
- cet->t_id = cpu_to_le32(flow);
- common = ce->variant->prng | CE_COMM_INT;
- cet->t_common_ctl = cpu_to_le32(common);
-
- /* recent CE (H6) need length in bytes, in word otherwise */
- if (ce->variant->prng_t_dlen_in_bytes)
- cet->t_dlen = cpu_to_le32(todo);
- else
- cet->t_dlen = cpu_to_le32(todo / 4);
-
- sym = PRNG_LD;
- cet->t_sym_ctl = cpu_to_le32(sym);
- cet->t_asym_ctl = 0;
-
- cet->t_key = cpu_to_le32(dma_iv);
- cet->t_iv = cpu_to_le32(dma_iv);
-
- cet->t_dst[0].addr = cpu_to_le32(dma_dst);
- cet->t_dst[0].len = cpu_to_le32(todo / 4);
- ce->chanlist[flow].timeout = 2000;
-
- err = sun8i_ce_run_task(ce, 3, "PRNG");
- mutex_unlock(&ce->rnglock);
-
- pm_runtime_put(ce->dev);
-
-err_pm:
- dma_unmap_single(ce->dev, dma_dst, todo, DMA_FROM_DEVICE);
-err_dst:
- dma_unmap_single(ce->dev, dma_iv, ctx->slen, DMA_TO_DEVICE);
-
- if (!err) {
- memcpy(dst, d, dlen);
- memcpy(ctx->seed, d + dlen, ctx->slen);
- }
-err_iv:
- kfree_sensitive(d);
-err_mem:
- return err;
-}
--- a/drivers/crypto/allwinner/sun8i-ce/sun8i-ce.h
+++ b/drivers/crypto/allwinner/sun8i-ce/sun8i-ce.h
@@ -15,7 +15,6 @@
#include <linux/hw_random.h>
#include <crypto/internal/hash.h>
#include <crypto/md5.h>
-#include <crypto/rng.h>
#include <crypto/sha1.h>
#include <crypto/sha2.h>
@@ -58,9 +57,7 @@
#define CE_ALG_SHA384 20
#define CE_ALG_SHA512 21
#define CE_ALG_TRNG 48
-#define CE_ALG_PRNG 49
#define CE_ALG_TRNG_V2 0x1c
-#define CE_ALG_PRNG_V2 0x1d
/* Used in ce_variant */
#define CE_ID_NOTSUPP 0xFF
@@ -96,10 +93,6 @@
#define ESR_H6 4
#define ESR_D1 5
-#define PRNG_DATA_SIZE (160 / 8)
-#define PRNG_SEED_SIZE DIV_ROUND_UP(175, 8)
-#define PRNG_LD BIT(17)
-
#define CE_DIE_ID_SHIFT 16
#define CE_DIE_ID_MASK 0x07
@@ -132,13 +125,10 @@ struct ce_clock {
* bytes or words
* @hash_t_dlen_in_bytes: Does the request size for hash is in
* bits or words
- * @prng_t_dlen_in_bytes: Does the request size for PRNG is in
- * bytes or words
* @trng_t_dlen_in_bytes: Does the request size for TRNG is in
* bytes or words
* @ce_clks: list of clocks needed by this variant
* @esr: The type of error register
- * @prng: The CE_ALG_XXX value for the PRNG
* @trng: The CE_ALG_XXX value for the TRNG
*/
struct ce_variant {
@@ -147,11 +137,9 @@ struct ce_variant {
u32 op_mode[CE_ID_OP_MAX];
bool cipher_t_dlen_in_bytes;
bool hash_t_dlen_in_bits;
- bool prng_t_dlen_in_bytes;
bool trng_t_dlen_in_bytes;
struct ce_clock ce_clks[CE_MAX_CLOCKS];
int esr;
- unsigned char prng;
unsigned char trng;
};
@@ -302,16 +290,6 @@ struct sun8i_ce_hash_reqctx {
};
/*
- * struct sun8i_ce_prng_ctx - context for PRNG TFM
- * @seed: The seed to use
- * @slen: The size of the seed
- */
-struct sun8i_ce_rng_tfm_ctx {
- void *seed;
- unsigned int slen;
-};
-
-/*
* struct sun8i_ce_alg_template - crypto_alg template
* @type: the CRYPTO_ALG_TYPE for this template
* @ce_algo_id: the CE_ID for this template
@@ -331,7 +309,6 @@ struct sun8i_ce_alg_template {
union {
struct skcipher_alg skcipher;
struct ahash_alg hash;
- struct rng_alg rng;
} alg;
unsigned long stat_req;
unsigned long stat_fb;
@@ -374,11 +351,5 @@ int sun8i_ce_hash_finup(struct ahash_req
int sun8i_ce_hash_digest(struct ahash_request *areq);
int sun8i_ce_hash_run(struct crypto_engine *engine, void *breq);
-int sun8i_ce_prng_generate(struct crypto_rng *tfm, const u8 *src,
- unsigned int slen, u8 *dst, unsigned int dlen);
-int sun8i_ce_prng_seed(struct crypto_rng *tfm, const u8 *seed, unsigned int slen);
-void sun8i_ce_prng_exit(struct crypto_tfm *tfm);
-int sun8i_ce_prng_init(struct crypto_tfm *tfm);
-
int sun8i_ce_hwrng_register(struct sun8i_ce_dev *ce);
void sun8i_ce_hwrng_unregister(struct sun8i_ce_dev *ce);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 571/982] crypto: sun8i-ss - Remove crypto_rng interface
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (569 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 570/982] crypto: sun8i-ce - Remove crypto_rng interface Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 572/982] netfilter: nft_set_pipapo_avx2: add missing vzeroupper Greg Kroah-Hartman
` (417 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Corentin Labbe, Eric Biggers,
Herbert Xu
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Biggers <ebiggers@kernel.org>
commit a78446ee6fae86ac8733f120e3ffce2e5d9384f5 upstream.
Since the crypto_rng interface for hardware PRNGs is unused and is
redundant with hwrng and the actual Linux RNG, it's being phased out.
Most drivers for it were already removed. Go ahead and remove the
sun8i-ss support which is one of the only remaining ones.
As usual for crypto_rng, this driver was also buggy: its ->generate()
function had a use-after-free vulnerability due to using
wait_for_completion_interruptible_timeout() without handling shutting
down the DMA operation if a signal is sent. Also, it had a buffer
overread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'.
There's no point in fixing these bugs separately only to remove the code
anyway, so this commit is marked with Fixes and Cc stable.
Fixes: ac2614d721de ("crypto: sun8i-ss - Add support for the PRNG")
Cc: stable@vger.kernel.org
Cc: Corentin Labbe <clabbe.montjoie@gmail.com>
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/crypto/allwinner/Kconfig | 8 -
drivers/crypto/allwinner/sun8i-ss/Makefile | 1
drivers/crypto/allwinner/sun8i-ss/sun8i-ss-core.c | 39 -----
drivers/crypto/allwinner/sun8i-ss/sun8i-ss-prng.c | 170 ----------------------
drivers/crypto/allwinner/sun8i-ss/sun8i-ss.h | 23 --
5 files changed, 241 deletions(-)
delete mode 100644 drivers/crypto/allwinner/sun8i-ss/sun8i-ss-prng.c
--- a/drivers/crypto/allwinner/Kconfig
+++ b/drivers/crypto/allwinner/Kconfig
@@ -105,14 +105,6 @@ config CRYPTO_DEV_SUN8I_SS_DEBUG
This will create /sys/kernel/debug/sun8i-ss/stats for displaying
the number of requests per flow and per algorithm.
-config CRYPTO_DEV_SUN8I_SS_PRNG
- bool "Support for Allwinner Security System PRNG"
- depends on CRYPTO_DEV_SUN8I_SS
- select CRYPTO_RNG
- help
- Select this option if you want to provide kernel-side support for
- the Pseudo-Random Number Generator found in the Security System.
-
config CRYPTO_DEV_SUN8I_SS_HASH
bool "Enable support for hash on sun8i-ss"
depends on CRYPTO_DEV_SUN8I_SS
--- a/drivers/crypto/allwinner/sun8i-ss/Makefile
+++ b/drivers/crypto/allwinner/sun8i-ss/Makefile
@@ -1,4 +1,3 @@
obj-$(CONFIG_CRYPTO_DEV_SUN8I_SS) += sun8i-ss.o
sun8i-ss-y += sun8i-ss-core.o sun8i-ss-cipher.o
-sun8i-ss-$(CONFIG_CRYPTO_DEV_SUN8I_SS_PRNG) += sun8i-ss-prng.o
sun8i-ss-$(CONFIG_CRYPTO_DEV_SUN8I_SS_HASH) += sun8i-ss-hash.o
--- a/drivers/crypto/allwinner/sun8i-ss/sun8i-ss-core.c
+++ b/drivers/crypto/allwinner/sun8i-ss/sun8i-ss-core.c
@@ -22,7 +22,6 @@
#include <linux/platform_device.h>
#include <linux/pm_runtime.h>
#include <linux/reset.h>
-#include <crypto/internal/rng.h>
#include <crypto/internal/skcipher.h>
#include "sun8i-ss.h"
@@ -269,25 +268,6 @@ static struct sun8i_ss_alg_template ss_a
.decrypt = sun8i_ss_skdecrypt,
}
},
-#ifdef CONFIG_CRYPTO_DEV_SUN8I_SS_PRNG
-{
- .type = CRYPTO_ALG_TYPE_RNG,
- .alg.rng = {
- .base = {
- .cra_name = "stdrng",
- .cra_driver_name = "sun8i-ss-prng",
- .cra_priority = 300,
- .cra_ctxsize = sizeof(struct sun8i_ss_rng_tfm_ctx),
- .cra_module = THIS_MODULE,
- .cra_init = sun8i_ss_prng_init,
- .cra_exit = sun8i_ss_prng_exit,
- },
- .generate = sun8i_ss_prng_generate,
- .seed = sun8i_ss_prng_seed,
- .seedsize = PRNG_SEED_SIZE,
- }
-},
-#endif
#ifdef CONFIG_CRYPTO_DEV_SUN8I_SS_HASH
{ .type = CRYPTO_ALG_TYPE_AHASH,
.ss_algo_id = SS_ID_HASH_MD5,
@@ -473,12 +453,6 @@ static int sun8i_ss_debugfs_show(struct
seq_printf(seq, "\tFallback due to SG numbers: %lu\n",
ss_algs[i].stat_fb_sgnum);
break;
- case CRYPTO_ALG_TYPE_RNG:
- seq_printf(seq, "%s %s reqs=%lu tsize=%lu\n",
- ss_algs[i].alg.rng.base.cra_driver_name,
- ss_algs[i].alg.rng.base.cra_name,
- ss_algs[i].stat_req, ss_algs[i].stat_bytes);
- break;
case CRYPTO_ALG_TYPE_AHASH:
seq_printf(seq, "%s %s reqs=%lu fallback=%lu\n",
ss_algs[i].alg.hash.halg.base.cra_driver_name,
@@ -678,14 +652,6 @@ static int sun8i_ss_register_algs(struct
return err;
}
break;
- case CRYPTO_ALG_TYPE_RNG:
- err = crypto_register_rng(&ss_algs[i].alg.rng);
- if (err) {
- dev_err(ss->dev, "Fail to register %s\n",
- ss_algs[i].alg.rng.base.cra_name);
- ss_algs[i].ss = NULL;
- }
- break;
case CRYPTO_ALG_TYPE_AHASH:
id = ss_algs[i].ss_algo_id;
ss_method = ss->variant->alg_hash[id];
@@ -727,11 +693,6 @@ static void sun8i_ss_unregister_algs(str
ss_algs[i].alg.skcipher.base.cra_name);
crypto_unregister_skcipher(&ss_algs[i].alg.skcipher);
break;
- case CRYPTO_ALG_TYPE_RNG:
- dev_info(ss->dev, "Unregister %d %s\n", i,
- ss_algs[i].alg.rng.base.cra_name);
- crypto_unregister_rng(&ss_algs[i].alg.rng);
- break;
case CRYPTO_ALG_TYPE_AHASH:
dev_info(ss->dev, "Unregister %d %s\n", i,
ss_algs[i].alg.hash.halg.base.cra_name);
--- a/drivers/crypto/allwinner/sun8i-ss/sun8i-ss-prng.c
+++ /dev/null
@@ -1,170 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0
-/*
- * sun8i-ss-prng.c - hardware cryptographic offloader for
- * Allwinner A80/A83T SoC
- *
- * Copyright (C) 2015-2020 Corentin Labbe <clabbe@baylibre.com>
- *
- * This file handle the PRNG found in the SS
- *
- * You could find a link for the datasheet in Documentation/arm/sunxi.rst
- */
-#include "sun8i-ss.h"
-#include <linux/dma-mapping.h>
-#include <linux/pm_runtime.h>
-#include <crypto/internal/rng.h>
-
-int sun8i_ss_prng_seed(struct crypto_rng *tfm, const u8 *seed,
- unsigned int slen)
-{
- struct sun8i_ss_rng_tfm_ctx *ctx = crypto_rng_ctx(tfm);
-
- if (ctx->seed && ctx->slen != slen) {
- kfree_sensitive(ctx->seed);
- ctx->slen = 0;
- ctx->seed = NULL;
- }
- if (!ctx->seed)
- ctx->seed = kmalloc(slen, GFP_KERNEL | GFP_DMA);
- if (!ctx->seed)
- return -ENOMEM;
-
- memcpy(ctx->seed, seed, slen);
- ctx->slen = slen;
-
- return 0;
-}
-
-int sun8i_ss_prng_init(struct crypto_tfm *tfm)
-{
- struct sun8i_ss_rng_tfm_ctx *ctx = crypto_tfm_ctx(tfm);
-
- memset(ctx, 0, sizeof(struct sun8i_ss_rng_tfm_ctx));
- return 0;
-}
-
-void sun8i_ss_prng_exit(struct crypto_tfm *tfm)
-{
- struct sun8i_ss_rng_tfm_ctx *ctx = crypto_tfm_ctx(tfm);
-
- kfree_sensitive(ctx->seed);
- ctx->seed = NULL;
- ctx->slen = 0;
-}
-
-int sun8i_ss_prng_generate(struct crypto_rng *tfm, const u8 *src,
- unsigned int slen, u8 *dst, unsigned int dlen)
-{
- struct sun8i_ss_rng_tfm_ctx *ctx = crypto_rng_ctx(tfm);
- struct rng_alg *alg = crypto_rng_alg(tfm);
- struct sun8i_ss_alg_template *algt;
- struct sun8i_ss_dev *ss;
- dma_addr_t dma_iv, dma_dst;
- unsigned int todo;
- int err = 0;
- int flow;
- void *d;
- u32 v;
-
- algt = container_of(alg, struct sun8i_ss_alg_template, alg.rng);
- ss = algt->ss;
-
- if (ctx->slen == 0) {
- dev_err(ss->dev, "The PRNG is not seeded\n");
- return -EINVAL;
- }
-
- /* The SS does not give an updated seed, so we need to get a new one.
- * So we will ask for an extra PRNG_SEED_SIZE data.
- * We want dlen + seedsize rounded up to a multiple of PRNG_DATA_SIZE
- */
- todo = dlen + PRNG_SEED_SIZE + PRNG_DATA_SIZE;
- todo -= todo % PRNG_DATA_SIZE;
-
- d = kzalloc(todo, GFP_KERNEL | GFP_DMA);
- if (!d)
- return -ENOMEM;
-
- flow = sun8i_ss_get_engine_number(ss);
-
-#ifdef CONFIG_CRYPTO_DEV_SUN8I_SS_DEBUG
- algt->stat_req++;
- algt->stat_bytes += todo;
-#endif
-
- v = SS_ALG_PRNG | SS_PRNG_CONTINUE | SS_START;
- if (flow)
- v |= SS_FLOW1;
- else
- v |= SS_FLOW0;
-
- dma_iv = dma_map_single(ss->dev, ctx->seed, ctx->slen, DMA_TO_DEVICE);
- if (dma_mapping_error(ss->dev, dma_iv)) {
- dev_err(ss->dev, "Cannot DMA MAP IV\n");
- err = -EFAULT;
- goto err_free;
- }
-
- dma_dst = dma_map_single(ss->dev, d, todo, DMA_FROM_DEVICE);
- if (dma_mapping_error(ss->dev, dma_dst)) {
- dev_err(ss->dev, "Cannot DMA MAP DST\n");
- err = -EFAULT;
- goto err_iv;
- }
-
- err = pm_runtime_resume_and_get(ss->dev);
- if (err < 0)
- goto err_pm;
- err = 0;
-
- mutex_lock(&ss->mlock);
- writel(dma_iv, ss->base + SS_IV_ADR_REG);
- /* the PRNG act badly (failing rngtest) without SS_KEY_ADR_REG set */
- writel(dma_iv, ss->base + SS_KEY_ADR_REG);
- writel(dma_dst, ss->base + SS_DST_ADR_REG);
- writel(todo / 4, ss->base + SS_LEN_ADR_REG);
-
- reinit_completion(&ss->flows[flow].complete);
- ss->flows[flow].status = 0;
- /* Be sure all data is written before enabling the task */
- wmb();
-
- writel(v, ss->base + SS_CTL_REG);
-
- wait_for_completion_interruptible_timeout(&ss->flows[flow].complete,
- msecs_to_jiffies(todo));
- if (ss->flows[flow].status == 0) {
- dev_err(ss->dev, "DMA timeout for PRNG (size=%u)\n", todo);
- err = -EFAULT;
- }
- /* Since cipher and hash use the linux/cryptoengine and that we have
- * a cryptoengine per flow, we are sure that they will issue only one
- * request per flow.
- * Since the cryptoengine wait for completion before submitting a new
- * one, the mlock could be left just after the final writel.
- * But cryptoengine cannot handle crypto_rng, so we need to be sure
- * nothing will use our flow.
- * The easiest way is to grab mlock until the hardware end our requests.
- * We could have used a per flow lock, but this would increase
- * complexity.
- * The drawback is that no request could be handled for the other flow.
- */
- mutex_unlock(&ss->mlock);
-
- pm_runtime_put(ss->dev);
-
-err_pm:
- dma_unmap_single(ss->dev, dma_dst, todo, DMA_FROM_DEVICE);
-err_iv:
- dma_unmap_single(ss->dev, dma_iv, ctx->slen, DMA_TO_DEVICE);
-
- if (!err) {
- memcpy(dst, d, dlen);
- /* Update seed */
- memcpy(ctx->seed, d + dlen, ctx->slen);
- }
-err_free:
- kfree_sensitive(d);
-
- return err;
-}
--- a/drivers/crypto/allwinner/sun8i-ss/sun8i-ss.h
+++ b/drivers/crypto/allwinner/sun8i-ss/sun8i-ss.h
@@ -8,7 +8,6 @@
#include <crypto/aes.h>
#include <crypto/des.h>
#include <crypto/engine.h>
-#include <crypto/rng.h>
#include <crypto/skcipher.h>
#include <linux/atomic.h>
#include <linux/debugfs.h>
@@ -27,7 +26,6 @@
#define SS_ALG_DES (1 << 2)
#define SS_ALG_3DES (2 << 2)
#define SS_ALG_MD5 (3 << 2)
-#define SS_ALG_PRNG (4 << 2)
#define SS_ALG_SHA1 (6 << 2)
#define SS_ALG_SHA224 (7 << 2)
#define SS_ALG_SHA256 (8 << 2)
@@ -68,8 +66,6 @@
#define SS_FLOW0 BIT(30)
#define SS_FLOW1 BIT(31)
-#define SS_PRNG_CONTINUE BIT(18)
-
#define MAX_SG 8
#define MAXFLOW 2
@@ -79,9 +75,6 @@
#define SS_DIE_ID_SHIFT 20
#define SS_DIE_ID_MASK 0x07
-#define PRNG_DATA_SIZE (160 / 8)
-#define PRNG_SEED_SIZE DIV_ROUND_UP(175, 8)
-
#define MAX_PAD_SIZE 4096
/*
@@ -218,16 +211,6 @@ struct sun8i_cipher_tfm_ctx {
};
/*
- * struct sun8i_ss_prng_ctx - context for PRNG TFM
- * @seed: The seed to use
- * @slen: The size of the seed
- */
-struct sun8i_ss_rng_tfm_ctx {
- void *seed;
- unsigned int slen;
-};
-
-/*
* struct sun8i_ss_hash_tfm_ctx - context for an ahash TFM
* @enginectx: crypto_engine used by this TFM
* @fallback_tfm: pointer to the fallback TFM
@@ -280,7 +263,6 @@ struct sun8i_ss_alg_template {
struct sun8i_ss_dev *ss;
union {
struct skcipher_alg skcipher;
- struct rng_alg rng;
struct ahash_alg hash;
} alg;
unsigned long stat_req;
@@ -307,11 +289,6 @@ int sun8i_ss_skencrypt(struct skcipher_r
int sun8i_ss_get_engine_number(struct sun8i_ss_dev *ss);
int sun8i_ss_run_task(struct sun8i_ss_dev *ss, struct sun8i_cipher_req_ctx *rctx, const char *name);
-int sun8i_ss_prng_generate(struct crypto_rng *tfm, const u8 *src,
- unsigned int slen, u8 *dst, unsigned int dlen);
-int sun8i_ss_prng_seed(struct crypto_rng *tfm, const u8 *seed, unsigned int slen);
-int sun8i_ss_prng_init(struct crypto_tfm *tfm);
-void sun8i_ss_prng_exit(struct crypto_tfm *tfm);
int sun8i_ss_hash_crainit(struct crypto_tfm *tfm);
void sun8i_ss_hash_craexit(struct crypto_tfm *tfm);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 572/982] netfilter: nft_set_pipapo_avx2: add missing vzeroupper
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (570 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 571/982] crypto: sun8i-ss " Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 573/982] mptcp: consolidate subflow cleanup Greg Kroah-Hartman
` (416 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Biggers, Stefano Brivio,
Pablo Neira Ayuso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Biggers <ebiggers@kernel.org>
commit 55dd20f0f4b1be5c9c8a0275d8d763c86563eac2 upstream.
Since pipapo_get_avx2() uses YMM registers, execute vzeroupper before
returning from it. This is needed to avoid degrading the performance of
any later SSE code that may happen to be executed.
Fixes: 7400b063969b ("nft_set_pipapo: Introduce AVX2-based lookup implementation")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/nft_set_pipapo_avx2.c | 1 +
1 file changed, 1 insertion(+)
--- a/net/netfilter/nft_set_pipapo_avx2.c
+++ b/net/netfilter/nft_set_pipapo_avx2.c
@@ -1261,6 +1261,7 @@ next_match:
out:
if (i % 2)
scratch->map_index = !map_index;
+ asm volatile("vzeroupper");
kernel_fpu_end();
local_bh_enable();
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 573/982] mptcp: consolidate subflow cleanup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (571 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 572/982] netfilter: nft_set_pipapo_avx2: add missing vzeroupper Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 574/982] mptcp: avoid unneeded actions on subflow reset Greg Kroah-Hartman
` (415 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paolo Abeni, Mat Martineau,
Matthieu Baerts (NGI0), Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paolo Abeni <pabeni@redhat.com>
commit c3349a22c2002947d29a98a77bfb36d97cfbfac1 upstream.
Consolidate all the cleanup actions requiring the worker in a single
helper and ensure the dummy data fin creation for fallback socket is
performed only when the tcp rx queue is empty.
There are no functional changes intended, but this will simplify the
next patch, when the tcp rx queue spooling could be delayed at release_cb
time.
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
[ Note: also remove struct mptcp_sock *msk from subflow_state_change: it
is no longer used after this modification. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/subflow.c | 35 ++++++++++++++++++-----------------
1 file changed, 18 insertions(+), 17 deletions(-)
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1159,7 +1159,12 @@ out:
subflow->map_valid = 0;
}
-/* sched mptcp worker to remove the subflow if no more data is pending */
+static bool subflow_is_done(const struct sock *sk)
+{
+ return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
+}
+
+/* sched mptcp worker for subflow cleanup if no more data is pending */
static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ssk)
{
struct sock *sk = (struct sock *)msk;
@@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed
inet_sk_state_load(sk) != TCP_ESTABLISHED)))
return;
- if (skb_queue_empty(&ssk->sk_receive_queue) &&
- !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+ if (!skb_queue_empty(&ssk->sk_receive_queue))
+ return;
+
+ if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+ mptcp_schedule_work(sk);
+
+ /* when the fallback subflow closes the rx side, trigger a 'dummy'
+ * ingress data fin, so that the msk state will follow along
+ */
+ if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) &&
+ msk->first == ssk &&
+ mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
mptcp_schedule_work(sk);
}
@@ -1688,20 +1703,13 @@ static void __subflow_state_change(struc
rcu_read_unlock();
}
-static bool subflow_is_done(const struct sock *sk)
-{
- return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
-}
-
static void subflow_state_change(struct sock *sk)
{
struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk);
struct sock *parent = subflow->conn;
- struct mptcp_sock *msk;
__subflow_state_change(sk);
- msk = mptcp_sk(parent);
/* as recvmsg() does not acquire the subflow socket for ssk selection
* a fin packet carrying a DSS can be unnoticed if we don't trigger
* the data available machinery here.
@@ -1712,13 +1720,6 @@ static void subflow_state_change(struct
subflow_error_report(sk);
subflow_sched_work_if_closed(mptcp_sk(parent), sk);
-
- /* when the fallback subflow closes the rx side, trigger a 'dummy'
- * ingress data fin, so that the msk state will follow along
- */
- if (__mptcp_check_fallback(msk) && subflow_is_done(sk) && msk->first == sk &&
- mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
- mptcp_schedule_work(parent);
}
void mptcp_subflow_queue_clean(struct sock *listener_sk, struct sock *listener_ssk)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 574/982] mptcp: avoid unneeded actions on subflow reset
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (572 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 573/982] mptcp: consolidate subflow cleanup Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 575/982] mptcp: close race between scheduler and state change Greg Kroah-Hartman
` (414 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xinyang Ge, Paolo Abeni,
Matthieu Baerts (NGI0), Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paolo Abeni <pabeni@redhat.com>
commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream.
Once in a blue moon, the mptcp receive path can recursively call
mptcp_data_ready() via state change under unlucky error conditions, and
then try to hold the data lock again.
Break the recursion loop explicitly checking for the exceptional
condition.
Add a new flag instead of using an existing one like 'closing', to exit
early in subflow_state_change(), and explicitly flush the RX queue at
reset time.
This avoids unneeded processing to check for available data -- calling
get_mapping_status() and more on a dying subflow -- but also in error
reporting and worker scheduling.
Note that we must consume the currently peeked skb before invoking
mptcp_dss_corruption to avoid consuming it again after the eventual
reset has freed it.
Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption")
Cc: stable@vger.kernel.org
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp:
micro-optimize __mptcp_move_skb()") is not in this version, and is
part of a consequent rx path refactor. The conflict is in the context,
and is easy to resolve, "done = true" can be moved along without
consequences.
Also a conflict in protocol.h, because __unused is at a different
number. Decrement the one from this version and add the new flag
above. The context is also a bit different with data_avail being an
enum, but that's without consequences here. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/protocol.c | 6 +++---
net/mptcp/protocol.h | 3 ++-
net/mptcp/subflow.c | 11 +++++++++++
3 files changed, 16 insertions(+), 4 deletions(-)
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -754,13 +754,13 @@ static bool __mptcp_move_skbs_from_subfl
mptcp_dss_corruption(msk, ssk);
}
} else {
+ sk_eat_skb(ssk, skb);
+ done = true;
+
if (unlikely(!fin)) {
DEBUG_NET_WARN_ON_ONCE(1);
mptcp_dss_corruption(msk, ssk);
}
-
- sk_eat_skb(ssk, skb);
- done = true;
}
WRITE_ONCE(tp->copied_seq, seq);
--- a/net/mptcp/protocol.h
+++ b/net/mptcp/protocol.h
@@ -492,7 +492,8 @@ struct mptcp_subflow_context {
stale : 1, /* unable to snd/rcv data, do not use for xmit */
valid_csum_seen : 1, /* at least one csum validated */
close_event_done : 1, /* has done the post-closed part */
- __unused : 9;
+ resetting : 1, /* subflow is resetting */
+ __unused : 8;
enum mptcp_data_avail data_avail;
bool pm_listener; /* a listener managed by the kernel PM? */
u32 remote_nonce;
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -379,6 +379,10 @@ void mptcp_subflow_reset(struct sock *ss
/* must hold: tcp_done() could drop last reference on parent */
sock_hold(sk);
+ subflow->resetting = 1;
+
+ /* No need to delay the actual close for to-be discarded data. */
+ __skb_queue_purge(&ssk->sk_receive_queue);
tcp_send_active_reset(ssk, GFP_ATOMIC);
tcp_done(ssk);
if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags))
@@ -1710,6 +1714,13 @@ static void subflow_state_change(struct
__subflow_state_change(sk);
+ /* Rx queue processing is unneeded, error reporting will take place at
+ * __mptcp_close_ssk() time and subflow reset can't happen in case of
+ * fallback: subflow_sched_work_if_closed() would be a no-op.
+ */
+ if (subflow->resetting)
+ return;
+
/* as recvmsg() does not acquire the subflow socket for ssk selection
* a fin packet carrying a DSS can be unnoticed if we don't trigger
* the data available machinery here.
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 575/982] mptcp: close race between scheduler and state change
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (573 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 574/982] mptcp: avoid unneeded actions on subflow reset Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 576/982] landlock: Fix handling of disconnected directories Greg Kroah-Hartman
` (413 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shardul Bankar, Xinyang Ge,
Paolo Abeni, Matthieu Baerts (NGI0), Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paolo Abeni <pabeni@redhat.com>
commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream.
The mptcp scheduler may race with subflow sockets state change: data
transmission on the selected socket may fail and a later release could
try to use mss_now reset to 0 for a divide operation.
Address the issue by explicitly checking for the critical scenario.
Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows")
Cc: stable@vger.kernel.org
Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/protocol.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -1636,7 +1636,9 @@ static struct sock *mptcp_subflow_get_se
static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info)
{
- tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal);
+ if (info->mss_now)
+ tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle,
+ info->size_goal);
release_sock(ssk);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 576/982] landlock: Fix handling of disconnected directories
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (574 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 575/982] mptcp: close race between scheduler and state change Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 577/982] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
` (412 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Brauner,
Günther Noack, Song Liu, Tingmao Wang,
Mickaël Salaün, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit 49c9e09d961025b22e61ef9ad56aa1c21b6ce2f1 ]
Disconnected files or directories can appear when they are visible and
opened from a bind mount, but have been renamed or moved from the source
of the bind mount in a way that makes them inaccessible from the mount
point (i.e. out of scope).
Previously, access rights tied to files or directories opened through a
disconnected directory were collected by walking the related hierarchy
down to the root of the filesystem, without taking into account the
mount point because it couldn't be found. This could lead to
inconsistent access results, potential access right widening, and
hard-to-debug renames, especially since such paths cannot be printed.
For a sandboxed task to create a disconnected directory, it needs to
have write access (i.e. FS_MAKE_REG, FS_REMOVE_FILE, and FS_REFER) to
the underlying source of the bind mount, and read access to the related
mount point. Because a sandboxed task cannot acquire more access
rights than those defined by its Landlock domain, this could lead to
inconsistent access rights due to missing permissions that should be
inherited from the mount point hierarchy, while inheriting permissions
from the filesystem hierarchy hidden by this mount point instead.
Landlock now handles files and directories opened from disconnected
directories by taking into account the filesystem hierarchy when the
mount point is not found in the hierarchy walk, and also always taking
into account the mount point from which these disconnected directories
were opened. This ensures that a rename is not allowed if it would
widen access rights [1].
The rationale is that, even if disconnected hierarchies might not be
visible or accessible to a sandboxed task, relying on the collected
access rights from them improves the guarantee that access rights will
not be widened during a rename because of the access right comparison
between the source and the destination (see LANDLOCK_ACCESS_FS_REFER).
It may look like this would grant more access on disconnected files and
directories, but the security policies are always enforced for all the
evaluated hierarchies. This new behavior should be less surprising to
users and safer from an access control perspective.
Remove a wrong WARN_ON_ONCE() canary in collect_domain_accesses() and
fix the related comment.
Because opened files have their access rights stored in the related file
security properties, there is no impact for disconnected or unlinked
files.
Cc: Christian Brauner <brauner@kernel.org>
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Reported-by: Tingmao Wang <m@maowtm.org>
Closes: https://lore.kernel.org/r/027d5190-b37a-40a8-84e9-4ccbc352bcdf@maowtm.org
Closes: https://lore.kernel.org/r/09b24128f86973a6022e6aa8338945fcfb9a33e4.1749925391.git.m@maowtm.org
Fixes: b91c3e4ea756 ("landlock: Add support for file reparenting with LANDLOCK_ACCESS_FS_REFER")
Fixes: cb2c7d1a1776 ("landlock: Support filesystem access-control")
Link: https://lore.kernel.org/r/b0f46246-f2c5-42ca-93ce-0d629702a987@maowtm.org [1]
Reviewed-by: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-2-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adjust the filesystem walk and errata insertion context]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/landlock/errata/abi-1.h | 15 ++++++++++++
security/landlock/fs.c | 40 +++++++++++++++++++++++---------
2 files changed, 44 insertions(+), 11 deletions(-)
diff --git a/security/landlock/errata/abi-1.h b/security/landlock/errata/abi-1.h
index 53c96c2057fa0..80930957e84d2 100644
--- a/security/landlock/errata/abi-1.h
+++ b/security/landlock/errata/abi-1.h
@@ -1,5 +1,20 @@
/* SPDX-License-Identifier: GPL-2.0-only */
+/**
+ * DOC: erratum_3
+ *
+ * Erratum 3: Disconnected directory handling
+ * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ *
+ * This fix addresses an issue with disconnected directories that occur when a
+ * directory is moved outside the scope of a bind mount. The change ensures
+ * that evaluated access rights include both those from the disconnected file
+ * hierarchy down to its filesystem root and those from the related mount point
+ * hierarchy. This prevents access right widening through rename or link
+ * actions.
+ */
+LANDLOCK_ERRATUM(3)
+
/**
* DOC: erratum_4
*
diff --git a/security/landlock/fs.c b/security/landlock/fs.c
index dd7f0fd921cf6..8f20a146648cf 100644
--- a/security/landlock/fs.c
+++ b/security/landlock/fs.c
@@ -607,19 +607,31 @@ static int check_access_path_dual(
break;
}
}
+
if (unlikely(IS_ROOT(walker_path.dentry))) {
+ if (likely(walker_path.mnt->mnt_flags & MNT_INTERNAL)) {
+ /*
+ * Stops and allows access when reaching disconnected root
+ * directories that are part of internal filesystems (e.g. nsfs,
+ * which is reachable through /proc/<pid>/ns/<namespace>).
+ */
+ allowed_parent1 = true;
+ allowed_parent2 = true;
+ break;
+ }
+
/*
- * Stops at disconnected root directories. Only allows
- * access to internal filesystems (e.g. nsfs, which is
- * reachable through /proc/<pid>/ns/<namespace>).
+ * We reached a disconnected root directory from a bind mount.
+ * Let's continue the walk with the mount point we missed.
*/
- allowed_parent1 = allowed_parent2 =
- !!(walker_path.mnt->mnt_flags & MNT_INTERNAL);
- break;
+ dput(walker_path.dentry);
+ walker_path.dentry = walker_path.mnt->mnt_root;
+ dget(walker_path.dentry);
+ } else {
+ parent_dentry = dget_parent(walker_path.dentry);
+ dput(walker_path.dentry);
+ walker_path.dentry = parent_dentry;
}
- parent_dentry = dget_parent(walker_path.dentry);
- dput(walker_path.dentry);
- walker_path.dentry = parent_dentry;
}
path_put(&walker_path);
@@ -721,6 +733,9 @@ static inline access_mask_t maybe_remove(const struct dentry *const dentry)
* file. While walking from @dir to @mnt_root, we record all the domain's
* allowed accesses in @layer_masks_dom.
*
+ * Because of disconnected directories, this walk may not reach @mnt_dir. In
+ * this case, the walk will continue to @mnt_dir after this call.
+ *
* This is similar to check_access_path_dual() but much simpler because it only
* handles walking on the same mount point and only checks one set of accesses.
*
@@ -759,8 +774,11 @@ static bool collect_domain_accesses(
break;
}
- /* We should not reach a root other than @mnt_root. */
- if (dir == mnt_root || WARN_ON_ONCE(IS_ROOT(dir)))
+ /*
+ * Stops at the mount point or the filesystem root for a disconnected
+ * directory.
+ */
+ if (dir == mnt_root || unlikely(IS_ROOT(dir)))
break;
parent_dentry = dget_parent(dir);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 577/982] selftests/landlock: Add tests for access through disconnected paths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (575 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 576/982] landlock: Fix handling of disconnected directories Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 578/982] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
` (411 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Song Liu,
Tingmao Wang, Mickaël Salaün, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tingmao Wang <m@maowtm.org>
[ Upstream commit a18ee3f31fd714173a62515d049d77e76ab55649 ]
This adds tests for the edge case discussed in [1], with specific ones
for rename and link operations when the operands are through
disconnected paths, as that go through a separate code path in Landlock.
This has resulted in a warning, due to collect_domain_accesses() not
expecting to reach a different root from path->mnt:
# RUN layout1_bind.path_disconnected ...
# OK layout1_bind.path_disconnected
ok 96 layout1_bind.path_disconnected
# RUN layout1_bind.path_disconnected_rename ...
[..] ------------[ cut here ]------------
[..] WARNING: CPU: 3 PID: 385 at security/landlock/fs.c:1065 collect_domain_accesses
[..] ...
[..] RIP: 0010:collect_domain_accesses (security/landlock/fs.c:1065 (discriminator 2) security/landlock/fs.c:1031 (discriminator 2))
[..] current_check_refer_path (security/landlock/fs.c:1205)
[..] ...
[..] hook_path_rename (security/landlock/fs.c:1526)
[..] security_path_rename (security/security.c:2026 (discriminator 1))
[..] do_renameat2 (fs/namei.c:5264)
# OK layout1_bind.path_disconnected_rename
ok 97 layout1_bind.path_disconnected_rename
Move the const char definitions a bit above so that we can use the path
for s4d1 in cleanup code.
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Link: https://lore.kernel.org/r/027d5190-b37a-40a8-84e9-4ccbc352bcdf@maowtm.org [1]
Signed-off-by: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-4-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the tests to the older fixture teardown]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 423 ++++++++++++++++++++-
1 file changed, 415 insertions(+), 8 deletions(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 864309ebb0b4c..4c855292113fc 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -3195,6 +3195,18 @@ TEST_F_FORK(layout1, proc_pipe)
FIXTURE(layout1_bind) {};
/* clang-format on */
+static const char bind_dir_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3";
+static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
+
+/* Move targets for disconnected path tests. */
+static const char dir_s4d1[] = TMP_DIR "/s4d1";
+static const char file1_s4d1[] = TMP_DIR "/s4d1/f1";
+static const char file2_s4d1[] = TMP_DIR "/s4d1/f2";
+static const char dir_s4d2[] = TMP_DIR "/s4d1/s4d2";
+static const char file1_s4d2[] = TMP_DIR "/s4d1/s4d2/f1";
+static const char file1_name[] = "f1";
+static const char file2_name[] = "f2";
+
FIXTURE_SETUP(layout1_bind)
{
prepare_layout(_metadata);
@@ -3212,14 +3224,14 @@ FIXTURE_TEARDOWN(layout1_bind)
EXPECT_EQ(0, umount(dir_s2d2));
clear_cap(_metadata, CAP_SYS_ADMIN);
+ remove_path(file1_s4d1);
+ remove_path(file2_s4d1);
+
remove_layout1(_metadata);
cleanup_layout(_metadata);
}
-static const char bind_dir_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3";
-static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
-
/*
* layout1_bind hierarchy:
*
@@ -3230,20 +3242,25 @@ static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
* │ └── s1d2
* │ ├── f1
* │ ├── f2
- * │ └── s1d3
+ * │ └── s1d3 [disconnected by path_disconnected]
* │ ├── f1
* │ └── f2
* ├── s2d1
* │ ├── f1
- * │ └── s2d2
+ * │ └── s2d2 [bind mount from s1d2]
* │ ├── f1
* │ ├── f2
* │ └── s1d3
* │ ├── f1
* │ └── f2
- * └── s3d1
- * └── s3d2
- * └── s3d3
+ * ├── s3d1
+ * │ └── s3d2
+ * │ └── s3d3
+ * └── s4d1 [renamed from s1d3 by path_disconnected]
+ * ├── f1
+ * ├── f2
+ * └── s4d2
+ * └── f1
*/
TEST_F_FORK(layout1_bind, no_restriction)
@@ -3442,6 +3459,396 @@ TEST_F_FORK(layout1_bind, reparent_cross_mount)
ASSERT_EQ(0, rename(bind_file1_s1d3, file1_s2d2));
}
+/*
+ * Make sure access to file through a disconnected path works as expected.
+ * This test moves s1d3 to s4d1.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected)
+{
+ const struct rule layer1_allow_all[] = {
+ {
+ .path = TMP_DIR,
+ .access = ACCESS_ALL,
+ },
+ {},
+ };
+ const struct rule layer2_allow_just_f1[] = {
+ {
+ .path = file1_s1d3,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+ const struct rule layer3_only_s1d2[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+
+ /* Landlock should not deny access just because it is disconnected. */
+ int ruleset_fd_l1 =
+ create_ruleset(_metadata, ACCESS_ALL, layer1_allow_all);
+
+ /* Creates the new ruleset now before we move the dir containing the file. */
+ int ruleset_fd_l2 =
+ create_ruleset(_metadata, ACCESS_RW, layer2_allow_just_f1);
+ int ruleset_fd_l3 =
+ create_ruleset(_metadata, ACCESS_RW, layer3_only_s1d2);
+ int bind_s1d3_fd;
+
+ ASSERT_LE(0, ruleset_fd_l1);
+ ASSERT_LE(0, ruleset_fd_l2);
+ ASSERT_LE(0, ruleset_fd_l3);
+
+ enforce_ruleset(_metadata, ruleset_fd_l1);
+ EXPECT_EQ(0, close(ruleset_fd_l1));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+
+ /* Tests access is possible before we move. */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, "..", O_RDONLY | O_DIRECTORY));
+
+ /* Makes it disconnected. */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d1))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d1,
+ strerror(errno));
+ }
+
+ /* Tests that access is still possible. */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+
+ /*
+ * Tests that ".." is not possible (not because of Landlock, but just
+ * because it's disconnected).
+ */
+ EXPECT_EQ(ENOENT,
+ test_open_rel(bind_s1d3_fd, "..", O_RDONLY | O_DIRECTORY));
+
+ /* This should still work with a narrower rule. */
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY));
+ /*
+ * Accessing a file through a disconnected file descriptor can still be
+ * allowed by a rule tied to this file, even if it is no longer visible in
+ * its mount point.
+ */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+
+ enforce_ruleset(_metadata, ruleset_fd_l3);
+ EXPECT_EQ(0, close(ruleset_fd_l3));
+
+ EXPECT_EQ(EACCES, test_open(file1_s4d1, O_RDONLY));
+ /*
+ * Accessing a file through a disconnected file descriptor can still be
+ * allowed by a rule tied to the original mount point, even if it is no
+ * longer visible in its mount point.
+ */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+}
+
+/*
+ * Test that renameat with disconnected paths works under Landlock. This test
+ * moves s1d3 to s4d2, so that we can have a rule allowing refers on the move
+ * target's immediate parent.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected_rename)
+{
+ const struct rule layer1[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_DIR |
+ LANDLOCK_ACCESS_FS_REMOVE_DIR |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {
+ .path = dir_s4d1,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_DIR |
+ LANDLOCK_ACCESS_FS_REMOVE_DIR |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {}
+ };
+
+ /* This layer only handles LANDLOCK_ACCESS_FS_READ_FILE. */
+ const struct rule layer2_only_s1d2[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+ int ruleset_fd_l1, ruleset_fd_l2;
+ pid_t child_pid;
+ int bind_s1d3_fd, status;
+
+ ASSERT_EQ(0, mkdir(dir_s4d1, 0755))
+ {
+ TH_LOG("Failed to create %s: %s", dir_s4d1, strerror(errno));
+ }
+ ruleset_fd_l1 = create_ruleset(_metadata, ACCESS_ALL, layer1);
+ ruleset_fd_l2 = create_ruleset(_metadata, LANDLOCK_ACCESS_FS_READ_FILE,
+ layer2_only_s1d2);
+ ASSERT_LE(0, ruleset_fd_l1);
+ ASSERT_LE(0, ruleset_fd_l2);
+
+ enforce_ruleset(_metadata, ruleset_fd_l1);
+ EXPECT_EQ(0, close(ruleset_fd_l1));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+
+ /* Tests ENOENT priority over EACCES for disconnected directory. */
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, "..", O_DIRECTORY));
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d2))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d2,
+ strerror(errno));
+ }
+ EXPECT_EQ(ENOENT, test_open_rel(bind_s1d3_fd, "..", O_DIRECTORY));
+
+ /*
+ * The file is no longer under s1d2 but we should still be able to access it
+ * with layer 2 because its mount point is evaluated as the first valid
+ * directory because it was initially a parent. Do a fork to test this so
+ * we don't prevent ourselves from renaming it back later.
+ */
+ child_pid = fork();
+ ASSERT_LE(0, child_pid);
+ if (child_pid == 0) {
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open(file1_s4d2, O_RDONLY));
+
+ /*
+ * Tests that access widening checks indeed prevents us from renaming it
+ * back.
+ */
+ EXPECT_EQ(-1, rename(dir_s4d2, dir_s1d3));
+ EXPECT_EQ(EXDEV, errno);
+
+ /*
+ * Including through the now disconnected fd (but it should return
+ * EXDEV).
+ */
+ EXPECT_EQ(-1, renameat(bind_s1d3_fd, file1_name, AT_FDCWD,
+ file1_s2d2));
+ EXPECT_EQ(EXDEV, errno);
+ _exit(_metadata->passed ? EXIT_SUCCESS : EXIT_FAILURE);
+ return;
+ }
+
+ EXPECT_EQ(child_pid, waitpid(child_pid, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ ASSERT_EQ(0, rename(dir_s4d2, dir_s1d3))
+ {
+ TH_LOG("Failed to rename %s back to %s: %s", dir_s4d1, dir_s1d3,
+ strerror(errno));
+ }
+
+ /* Now checks that we can access it under l2. */
+ child_pid = fork();
+ ASSERT_LE(0, child_pid);
+ if (child_pid == 0) {
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d3, O_RDONLY));
+ _exit(_metadata->passed ? EXIT_SUCCESS : EXIT_FAILURE);
+ return;
+ }
+
+ EXPECT_EQ(child_pid, waitpid(child_pid, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ /*
+ * Also test that we can rename via a disconnected path. We move the
+ * dir back to the disconnected place first, then we rename file1 to
+ * file2 through our dir fd.
+ */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d2))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d2,
+ strerror(errno));
+ }
+ ASSERT_EQ(0,
+ renameat(bind_s1d3_fd, file1_name, bind_s1d3_fd, file2_name))
+ {
+ TH_LOG("Failed to rename %s to %s within disconnected %s: %s",
+ file1_name, file2_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+ ASSERT_EQ(0, renameat(bind_s1d3_fd, file2_name, AT_FDCWD, file1_s2d2))
+ {
+ TH_LOG("Failed to rename %s to %s through disconnected %s: %s",
+ file2_name, file1_s2d2, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s2d2, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d2, O_RDONLY));
+
+ /* Move it back using the disconnected path as the target. */
+ ASSERT_EQ(0, renameat(AT_FDCWD, file1_s2d2, bind_s1d3_fd, file1_name))
+ {
+ TH_LOG("Failed to rename %s to %s through disconnected %s: %s",
+ file1_s1d2, file1_name, bind_dir_s1d3, strerror(errno));
+ }
+
+ /* Now make it connected again. */
+ ASSERT_EQ(0, rename(dir_s4d2, dir_s1d3))
+ {
+ TH_LOG("Failed to rename %s back to %s: %s", dir_s4d2, dir_s1d3,
+ strerror(errno));
+ }
+
+ /* Checks again that we can access it under l2. */
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d3, O_RDONLY));
+}
+
+/*
+ * Test that linkat(2) with disconnected paths works under Landlock. This
+ * test moves s1d3 to s4d1.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected_link)
+{
+ /* Ruleset to be applied after renaming s1d3 to s4d1. */
+ const struct rule layer1[] = {
+ {
+ .path = dir_s4d1,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE,
+ },
+ {
+ .path = dir_s2d2,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE,
+ },
+ {}
+ };
+ int ruleset_fd, bind_s1d3_fd;
+
+ /* Removes unneeded files created by layout1, otherwise it will EEXIST. */
+ ASSERT_EQ(0, unlink(file1_s1d2));
+ ASSERT_EQ(0, unlink(file2_s1d3));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+
+ /* Disconnects bind_s1d3_fd. */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d1))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d1,
+ strerror(errno));
+ }
+
+ /* Need this later to test different parent link. */
+ ASSERT_EQ(0, mkdir(dir_s4d2, 0755))
+ {
+ TH_LOG("Failed to create %s: %s", dir_s4d2, strerror(errno));
+ }
+
+ ruleset_fd = create_ruleset(_metadata, ACCESS_ALL, layer1);
+ ASSERT_LE(0, ruleset_fd);
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ /* From disconnected to connected. */
+ ASSERT_EQ(0, linkat(bind_s1d3_fd, file1_name, AT_FDCWD, file1_s2d2, 0))
+ {
+ TH_LOG("Failed to link %s to %s via disconnected %s: %s",
+ file1_name, file1_s2d2, bind_dir_s1d3, strerror(errno));
+ }
+
+ /* Tests that we can access via the new link... */
+ EXPECT_EQ(0, test_open(file1_s2d2, O_RDONLY))
+ {
+ TH_LOG("Failed to open newly linked %s: %s", file1_s2d2,
+ strerror(errno));
+ }
+
+ /* ...as well as the old one. */
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY))
+ {
+ TH_LOG("Failed to open original %s: %s", file1_s4d1,
+ strerror(errno));
+ }
+
+ /* From connected to disconnected. */
+ ASSERT_EQ(0, unlink(file1_s4d1));
+ ASSERT_EQ(0, linkat(AT_FDCWD, file1_s2d2, bind_s1d3_fd, file2_name, 0))
+ {
+ TH_LOG("Failed to link %s to %s via disconnected %s: %s",
+ file1_s2d2, file2_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file2_s4d1, O_RDONLY));
+ ASSERT_EQ(0, unlink(file1_s2d2));
+
+ /* From disconnected to disconnected (same parent). */
+ ASSERT_EQ(0,
+ linkat(bind_s1d3_fd, file2_name, bind_s1d3_fd, file1_name, 0))
+ {
+ TH_LOG("Failed to link %s to %s within disconnected %s: %s",
+ file2_name, file1_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY))
+ {
+ TH_LOG("Failed to open newly linked %s: %s", file1_s4d1,
+ strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY))
+ {
+ TH_LOG("Failed to open %s through newly created link under disconnected path: %s",
+ file1_name, strerror(errno));
+ }
+ ASSERT_EQ(0, unlink(file2_s4d1));
+
+ /* From disconnected to disconnected (different parent). */
+ ASSERT_EQ(0,
+ linkat(bind_s1d3_fd, file1_name, bind_s1d3_fd, "s4d2/f1", 0))
+ {
+ TH_LOG("Failed to link %s to %s within disconnected %s: %s",
+ file1_name, "s4d2/f1", bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s4d2, O_RDONLY))
+ {
+ TH_LOG("Failed to open %s after link: %s", file1_s4d2,
+ strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, "s4d2/f1", O_RDONLY))
+ {
+ TH_LOG("Failed to open %s through disconnected path after link: %s",
+ "s4d2/f1", strerror(errno));
+ }
+}
+
#define LOWER_BASE TMP_DIR "/lower"
#define LOWER_DATA LOWER_BASE "/data"
static const char lower_fl1[] = LOWER_DATA "/fl1";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 578/982] selftests/landlock: Add disconnected leafs and branch test suites
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (576 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 577/982] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 579/982] Revert "alpha: dont leak hardware-fabricated FP exception bits to user space" Greg Kroah-Hartman
` (410 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Song Liu,
Tingmao Wang, Mickaël Salaün, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit 54f9baf537b0a091adad860ec92e3e18e0a0754c ]
Test disconnected directories with two test suites
(layout4_disconnected_leafs and layout5_disconnected_branch) and 43
variants to cover the main corner cases.
These tests are complementary to the previous commit.
Add test_renameat() and test_exchangeat() helpers.
Test coverage for security/landlock is 92.1% of 1927 lines according to
LLVM 20.
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Cc: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-5-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: skip empty rules, use the older fixture teardown, and
explicitly detach nested mounts]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 1064 ++++++++++++++++++++
1 file changed, 1064 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 4c855292113fc..2a11c4a26d71c 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -229,6 +229,16 @@ static void cleanup_layout(struct __test_metadata *const _metadata)
EXPECT_EQ(0, remove_path(TMP_DIR));
}
+static void
+cleanup_layout_with_nested_mounts(struct __test_metadata *const _metadata)
+{
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ /* Also detaches disconnected bind mounts nested below TMP_DIR. */
+ EXPECT_EQ(0, umount2(TMP_DIR, MNT_DETACH));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+ EXPECT_EQ(0, remove_path(TMP_DIR));
+}
+
static void create_layout1(struct __test_metadata *const _metadata)
{
create_file(_metadata, file1_s1d1);
@@ -587,6 +597,9 @@ static int create_ruleset(struct __test_metadata *const _metadata,
}
for (i = 0; rules[i].path; i++) {
+ if (!rules[i].access)
+ continue;
+
add_path_beneath(_metadata, ruleset_fd, rules[i].access,
rules[i].path);
}
@@ -1881,6 +1894,22 @@ static int test_exchange(const char *const oldpath, const char *const newpath)
return 0;
}
+static int test_renameat(int olddirfd, const char *oldpath, int newdirfd,
+ const char *newpath)
+{
+ if (renameat2(olddirfd, oldpath, newdirfd, newpath, 0))
+ return errno;
+ return 0;
+}
+
+static int test_exchangeat(int olddirfd, const char *oldpath, int newdirfd,
+ const char *newpath)
+{
+ if (renameat2(olddirfd, oldpath, newdirfd, newpath, RENAME_EXCHANGE))
+ return errno;
+ return 0;
+}
+
TEST_F_FORK(layout1, rename_file)
{
const struct rule rules[] = {
@@ -3849,6 +3878,1041 @@ TEST_F_FORK(layout1_bind, path_disconnected_link)
}
}
+/*
+ * layout4_disconnected_leafs with bind mount and renames:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the bind mount]
+ * │ ├── s1d31
+ * │ │ └── s1d41 [now renamed beneath s3d1]
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d32
+ * │ └── s1d42 [now renamed beneath s4d1]
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [bind mount of s1d2]
+ * │ ├── s1d31
+ * │ │ └── s1d41 [opened FD, now renamed beneath s3d1]
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d32
+ * │ └── s1d42 [opened FD, now renamed beneath s4d1]
+ * │ ├── f3
+ * │ └── f4
+ * ├── s3d1
+ * │ └── s1d41 [renamed here]
+ * │ ├── f1
+ * │ └── f2
+ * └── s4d1
+ * └── s1d42 [renamed here]
+ * ├── f3
+ * └── f4
+ */
+/* clang-format off */
+FIXTURE(layout4_disconnected_leafs) {
+ int s2d2_fd;
+};
+/* clang-format on */
+
+FIXTURE_SETUP(layout4_disconnected_leafs)
+{
+ prepare_layout(_metadata);
+
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f1");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f2");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f3");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f4");
+ create_directory(_metadata, TMP_DIR "/s2d1/s2d2");
+ create_directory(_metadata, TMP_DIR "/s3d1");
+ create_directory(_metadata, TMP_DIR "/s4d1");
+
+ self->s2d2_fd =
+ open(TMP_DIR "/s2d1/s2d2", O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s2d2_fd);
+
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_EQ(0, mount(TMP_DIR "/s1d1/s1d2", TMP_DIR "/s2d1/s2d2", NULL,
+ MS_BIND, NULL));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+}
+
+FIXTURE_TEARDOWN(layout4_disconnected_leafs)
+{
+ /* Teardown runs before this mount namespace exits. */
+
+ /* Removes files after renames. */
+ remove_path(TMP_DIR "/s3d1/s1d41/f1");
+ remove_path(TMP_DIR "/s3d1/s1d41/f2");
+ remove_path(TMP_DIR "/s4d1/s1d42/f1");
+ remove_path(TMP_DIR "/s4d1/s1d42/f3");
+ remove_path(TMP_DIR "/s4d1/s1d42/f4");
+ remove_path(TMP_DIR "/s4d1/s1d42/f5");
+
+ cleanup_layout_with_nested_mounts(_metadata);
+}
+
+FIXTURE_VARIANT(layout4_disconnected_leafs)
+{
+ /*
+ * Parent of the bind mount source. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d1;
+ /*
+ * Source of bind mount (to s2d2). It should always be enforced when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d2;
+ /*
+ * Original parent of s1d41. It should always be ignored when testing
+ * against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s1d31;
+ /*
+ * Original parent of s1d42. It should always be ignored when testing
+ * against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s1d32;
+ /*
+ * Opened and disconnected source directory. It should always be enforced
+ * when testing against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s1d41;
+ /*
+ * Opened and disconnected source directory. It should always be enforced
+ * when testing against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s1d42;
+ /*
+ * File in the s1d41 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_f1;
+ /*
+ * File in the s1d41 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_f2;
+ /*
+ * File in the s1d42 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_f3;
+ /*
+ * Parent of the bind mount destination. It should always be enforced when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s2d1;
+ /*
+ * Directory covered by the bind mount. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s2d2;
+ /*
+ * New parent of the renamed s1d41. It should always be ignored when
+ * testing against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s3d1;
+ /*
+ * New parent of the renamed s1d42. It should always be ignored when
+ * testing against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s4d1;
+
+ /* Expected result of the call to open([fd:s1d41]/f1, O_RDONLY). */
+ const int expected_read_result;
+ /* Expected result of the call to renameat([fd:s1d41]/f1, [fd:s1d42]/f1). */
+ const int expected_rename_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d41]/f2, [fd:s1d42]/f3,
+ * RENAME_EXCHANGE).
+ */
+ const int expected_exchange_result;
+ /* Expected result of the call to renameat([fd:s1d42]/f4, [fd:s1d42]/f5). */
+ const int expected_same_dir_rename_result;
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d1_mount_src_parent) {
+ /* clang-format on */
+ .allowed_s1d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_refer) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_create) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_rename) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d31_s1d32_old_parent) {
+ /* clang-format on */
+ .allowed_s1d31 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d32 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_refer) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_create) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_even) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* The destination directory has more access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_more) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access denied. */
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* The destination directory has less access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_less) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access allowed. */
+ .expected_rename_result = 0,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_mini) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d2_covered_by_mount) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* Tests collect_domain_accesses(). */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_new_parent_refer) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_new_parent_create) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs,
+ s3d1_s4d1_disconnected_rename_even){
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* The destination directory has more access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_disconnected_rename_more) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access denied. */
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* The destination directory has less access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_disconnected_rename_less) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access allowed. */
+ .expected_rename_result = 0,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, f1_f2_f3) {
+ /* clang-format on */
+ .allowed_f1 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_f2 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_f3 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+TEST_F_FORK(layout4_disconnected_leafs, read_rename_exchange)
+{
+ const __u64 handled_access =
+ LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE | LANDLOCK_ACCESS_FS_MAKE_REG;
+ const struct rule rules[] = {
+ {
+ .path = TMP_DIR "/s1d1",
+ .access = variant->allowed_s1d1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2",
+ .access = variant->allowed_s1d2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31",
+ .access = variant->allowed_s1d31,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32",
+ .access = variant->allowed_s1d32,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41",
+ .access = variant->allowed_s1d41,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32/s1d42",
+ .access = variant->allowed_s1d42,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f1",
+ .access = variant->allowed_f1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f2",
+ .access = variant->allowed_f2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f3",
+ .access = variant->allowed_f3,
+ },
+ {
+ .path = TMP_DIR "/s2d1",
+ .access = variant->allowed_s2d1,
+ },
+ /* s2d2_fd */
+ {
+ .path = TMP_DIR "/s3d1",
+ .access = variant->allowed_s3d1,
+ },
+ {
+ .path = TMP_DIR "/s4d1",
+ .access = variant->allowed_s4d1,
+ },
+ {},
+ };
+ int ruleset_fd, s1d41_bind_fd, s1d42_bind_fd;
+
+ ruleset_fd = create_ruleset(_metadata, handled_access, rules);
+ ASSERT_LE(0, ruleset_fd);
+
+ /* Adds rule for the covered directory. */
+ if (variant->allowed_s2d2) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s2d2_fd,
+ .allowed_access =
+ variant->allowed_s2d2,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s2d2_fd));
+
+ s1d41_bind_fd = open(TMP_DIR "/s2d1/s2d2/s1d31/s1d41",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d41_bind_fd);
+ s1d42_bind_fd = open(TMP_DIR "/s2d1/s2d2/s1d32/s1d42",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d42_bind_fd);
+
+ /* Disconnects and checks source and destination directories. */
+ EXPECT_EQ(0, test_open_rel(s1d41_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(0, test_open_rel(s1d42_bind_fd, "..", O_DIRECTORY));
+ /* Renames to make it accessible through s3d1/s1d41 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s1d1/s1d2/s1d31/s1d41",
+ AT_FDCWD, TMP_DIR "/s3d1/s1d41"));
+ /* Renames to make it accessible through s4d1/s1d42 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s1d1/s1d2/s1d32/s1d42",
+ AT_FDCWD, TMP_DIR "/s4d1/s1d42"));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d41_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d42_bind_fd, "..", O_DIRECTORY));
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ EXPECT_EQ(variant->expected_read_result,
+ test_open_rel(s1d41_bind_fd, "f1", O_RDONLY));
+
+ EXPECT_EQ(variant->expected_rename_result,
+ test_renameat(s1d41_bind_fd, "f1", s1d42_bind_fd, "f1"));
+ EXPECT_EQ(variant->expected_exchange_result,
+ test_exchangeat(s1d41_bind_fd, "f2", s1d42_bind_fd, "f3"));
+
+ EXPECT_EQ(variant->expected_same_dir_rename_result,
+ test_renameat(s1d42_bind_fd, "f4", s1d42_bind_fd, "f5"));
+}
+
+/*
+ * layout5_disconnected_branch before rename:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the first bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [source of the second bind mount]
+ * │ └── s2d3
+ * │ └── s2d4 [first s1d2 bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s3d1
+ * │ └── s3d2 [second s2d2 bind mount]
+ * │ └── s2d3
+ * │ └── s2d4 [first s1d2 bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * └── s4d1
+ *
+ * After rename:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the first bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [source of the second bind mount]
+ * ├── s3d1
+ * │ └── s3d2 [second s2d2 bind mount]
+ * └── s4d1
+ * └── s2d3 [renamed here]
+ * └── s2d4 [first s1d2 bind mount]
+ * └── s1d3
+ * ├── s1d41
+ * │ ├── f1
+ * │ └── f2
+ * └── s1d42
+ * ├── f3
+ * └── f4
+ *
+ * Decision path for access from the s3d1/s3d2/s2d3/s2d4/s1d3 file descriptor:
+ * 1. first bind mount: s1d3 -> s1d2
+ * 2. second bind mount: s2d3
+ * 3. tmp mount: s4d1 -> tmp [disconnected branch]
+ * 4. second bind mount: s2d2
+ * 5. tmp mount: s3d1 -> tmp
+ * 6. parent mounts: [...] -> /
+ *
+ * The s4d1 directory is evaluated even if it is not in the s2d2 mount.
+ */
+
+/* clang-format off */
+FIXTURE(layout5_disconnected_branch) {
+ int s2d4_fd, s3d2_fd;
+};
+/* clang-format on */
+
+FIXTURE_SETUP(layout5_disconnected_branch)
+{
+ prepare_layout(_metadata);
+
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f1");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f2");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f3");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f4");
+ create_directory(_metadata, TMP_DIR "/s2d1/s2d2/s2d3/s2d4");
+ create_directory(_metadata, TMP_DIR "/s3d1/s3d2");
+ create_directory(_metadata, TMP_DIR "/s4d1");
+
+ self->s2d4_fd = open(TMP_DIR "/s2d1/s2d2/s2d3/s2d4",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s2d4_fd);
+
+ self->s3d2_fd =
+ open(TMP_DIR "/s3d1/s3d2", O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s3d2_fd);
+
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_EQ(0, mount(TMP_DIR "/s1d1/s1d2", TMP_DIR "/s2d1/s2d2/s2d3/s2d4",
+ NULL, MS_BIND, NULL));
+ ASSERT_EQ(0, mount(TMP_DIR "/s2d1/s2d2", TMP_DIR "/s3d1/s3d2", NULL,
+ MS_BIND | MS_REC, NULL));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+}
+
+FIXTURE_TEARDOWN(layout5_disconnected_branch)
+{
+ /* Teardown runs before this mount namespace exits. */
+
+ /* Removes files after renames. */
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f1");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f2");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f1");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f3");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f4");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f5");
+
+ cleanup_layout_with_nested_mounts(_metadata);
+}
+
+FIXTURE_VARIANT(layout5_disconnected_branch)
+{
+ /*
+ * Parent of all files. It should always be enforced when testing against
+ * files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_base;
+ /*
+ * Parent of the first bind mount source. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d1;
+ const __u64 allowed_s1d2;
+ const __u64 allowed_s1d3;
+ const __u64 allowed_s2d1;
+ const __u64 allowed_s2d2;
+ const __u64 allowed_s2d3;
+ const __u64 allowed_s2d4;
+ const __u64 allowed_s3d1;
+ const __u64 allowed_s3d2;
+ const __u64 allowed_s4d1;
+
+ /* Expected result of the call to open([fd:s1d3]/s1d41/f1, O_RDONLY). */
+ const int expected_read_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d41/f1,
+ * [fd:s1d3]/s1d42/f1).
+ */
+ const int expected_rename_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d41/f2,
+ * [fd:s1d3]/s1d42/f3, RENAME_EXCHANGE).
+ */
+ const int expected_exchange_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d42/f4,
+ * [fd:s1d3]/s1d42/f5).
+ */
+ const int expected_same_dir_rename_result;
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d1_mount1_src_parent) {
+ /* clang-format on */
+ .allowed_s1d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_refer) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_create) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_rename) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_refer) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_create) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_rename) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_full) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d1_mount2_src_parent) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_refer) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_create) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_rename) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_rename) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d4_mount1_dst) {
+ /* clang-format on */
+ .allowed_s2d4 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_rename) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d2_mount1_dst) {
+ /* clang-format on */
+ .allowed_s3d2 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_refer) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_create) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_rename) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+TEST_F_FORK(layout5_disconnected_branch, read_rename_exchange)
+{
+ const __u64 handled_access =
+ LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE | LANDLOCK_ACCESS_FS_MAKE_REG;
+ const struct rule rules[] = {
+ {
+ .path = TMP_DIR "/s1d1",
+ .access = variant->allowed_s1d1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2",
+ .access = variant->allowed_s1d2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d3",
+ .access = variant->allowed_s1d3,
+ },
+ {
+ .path = TMP_DIR "/s2d1",
+ .access = variant->allowed_s2d1,
+ },
+ {
+ .path = TMP_DIR "/s2d1/s2d2",
+ .access = variant->allowed_s2d2,
+ },
+ {
+ .path = TMP_DIR "/s2d1/s2d2/s2d3",
+ .access = variant->allowed_s2d3,
+ },
+ /* s2d4_fd */
+ {
+ .path = TMP_DIR "/s3d1",
+ .access = variant->allowed_s3d1,
+ },
+ /* s3d2_fd */
+ {
+ .path = TMP_DIR "/s4d1",
+ .access = variant->allowed_s4d1,
+ },
+ {},
+ };
+ int ruleset_fd, s1d3_bind_fd;
+
+ ruleset_fd = create_ruleset(_metadata, handled_access, rules);
+ ASSERT_LE(0, ruleset_fd);
+
+ /* Adds rules for the covered directories. */
+ if (variant->allowed_s2d4) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s2d4_fd,
+ .allowed_access =
+ variant->allowed_s2d4,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s2d4_fd));
+
+ if (variant->allowed_s3d2) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s3d2_fd,
+ .allowed_access =
+ variant->allowed_s3d2,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s3d2_fd));
+
+ s1d3_bind_fd = open(TMP_DIR "/s3d1/s3d2/s2d3/s2d4/s1d3",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d3_bind_fd);
+
+ /* Disconnects and checks source and destination directories. */
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "../..", O_DIRECTORY));
+ /* Renames to make it accessible through s3d1/s1d41 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s2d1/s2d2/s2d3",
+ AT_FDCWD, TMP_DIR "/s4d1/s2d3"));
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d3_bind_fd, "../..", O_DIRECTORY));
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ EXPECT_EQ(variant->expected_read_result,
+ test_open_rel(s1d3_bind_fd, "s1d41/f1", O_RDONLY));
+
+ EXPECT_EQ(variant->expected_rename_result,
+ test_renameat(s1d3_bind_fd, "s1d41/f1", s1d3_bind_fd,
+ "s1d42/f1"));
+ EXPECT_EQ(variant->expected_exchange_result,
+ test_exchangeat(s1d3_bind_fd, "s1d41/f2", s1d3_bind_fd,
+ "s1d42/f3"));
+
+ EXPECT_EQ(variant->expected_same_dir_rename_result,
+ test_renameat(s1d3_bind_fd, "s1d42/f4", s1d3_bind_fd,
+ "s1d42/f5"));
+}
+
#define LOWER_BASE TMP_DIR "/lower"
#define LOWER_DATA LOWER_BASE "/data"
static const char lower_fl1[] = LOWER_DATA "/fl1";
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 579/982] Revert "alpha: dont leak hardware-fabricated FP exception bits to user space"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (577 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 578/982] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 580/982] Revert "alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally" Greg Kroah-Hartman
` (409 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 096eeed5c31bcfcc04fda3faeb87fafad3890ba8.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/alpha/kernel/traps.c | 6 +--
arch/alpha/math-emu/math.c | 88 +++++---------------------------------
2 files changed, 14 insertions(+), 80 deletions(-)
diff --git a/arch/alpha/kernel/traps.c b/arch/alpha/kernel/traps.c
index 175be96f5644f..de72bd837c5af 100644
--- a/arch/alpha/kernel/traps.c
+++ b/arch/alpha/kernel/traps.c
@@ -198,12 +198,12 @@ static long dummy_emul(void) { return 0; }
long (*alpha_fp_emul_imprecise)(struct pt_regs *regs, unsigned long writemask)
= (void *)dummy_emul;
EXPORT_SYMBOL_GPL(alpha_fp_emul_imprecise);
-long (*alpha_fp_emul) (unsigned long pc, unsigned long summary)
+long (*alpha_fp_emul) (unsigned long pc)
= (void *)dummy_emul;
EXPORT_SYMBOL_GPL(alpha_fp_emul);
#else
long alpha_fp_emul_imprecise(struct pt_regs *regs, unsigned long writemask);
-long alpha_fp_emul (unsigned long pc, unsigned long summary);
+long alpha_fp_emul (unsigned long pc);
#endif
asmlinkage void
@@ -217,7 +217,7 @@ do_entArith(unsigned long summary, unsigned long write_mask,
emulate the instruction. If the processor supports
precise exceptions, we don't have to search. */
if (!amask(AMASK_PRECISE_TRAP))
- si_code = alpha_fp_emul(regs->pc - 4, summary);
+ si_code = alpha_fp_emul(regs->pc - 4);
else
si_code = alpha_fp_emul_imprecise(regs, write_mask);
if (si_code == 0)
diff --git a/arch/alpha/math-emu/math.c b/arch/alpha/math-emu/math.c
index 14b0bc325914d..4212258f3cfdc 100644
--- a/arch/alpha/math-emu/math.c
+++ b/arch/alpha/math-emu/math.c
@@ -57,13 +57,13 @@ MODULE_DESCRIPTION("FP Software completion module");
MODULE_LICENSE("GPL v2");
extern long (*alpha_fp_emul_imprecise)(struct pt_regs *, unsigned long);
-extern long (*alpha_fp_emul) (unsigned long pc, unsigned long summary);
+extern long (*alpha_fp_emul) (unsigned long pc);
static long (*save_emul_imprecise)(struct pt_regs *, unsigned long);
-static long (*save_emul) (unsigned long pc, unsigned long summary);
+static long (*save_emul) (unsigned long pc);
long do_alpha_fp_emul_imprecise(struct pt_regs *, unsigned long);
-long do_alpha_fp_emul(unsigned long, unsigned long);
+long do_alpha_fp_emul(unsigned long);
static int alpha_fp_emul_init_module(void)
{
@@ -91,22 +91,7 @@ module_exit(alpha_fp_emul_cleanup_module);
/*
- * Exception bits of the exception summary register (EXC_SUM). Bit 0 is the
- * software completion bit; bits 1 through 5 report the exceptions the
- * hardware attributed to the trapping instruction, and lie at the same
- * positions as the corresponding IEEE_TRAP_ENABLE_* bits.
- */
-#define EXC_SUM_INV (1UL << 1)
-#define EXC_SUM_DZE (1UL << 2)
-#define EXC_SUM_OVF (1UL << 3)
-#define EXC_SUM_UNF (1UL << 4)
-#define EXC_SUM_INE (1UL << 5)
-#define EXC_SUM_MASK (EXC_SUM_INV | EXC_SUM_DZE | EXC_SUM_OVF \
- | EXC_SUM_UNF | EXC_SUM_INE)
-
-/*
- * Emulate the floating point instruction at address PC. SUMMARY is the
- * exception summary register the trap was delivered with. Returns -1 if the
+ * Emulate the floating point instruction at address PC. Returns -1 if the
* instruction to be emulated is illegal (such as with the opDEC trap), else
* the SI_CODE for a SIGFPE signal, else 0 if everything's ok.
*
@@ -115,7 +100,7 @@ module_exit(alpha_fp_emul_cleanup_module);
* stick the result of the operation into the appropriate register.
*/
long
-alpha_fp_emul (unsigned long pc, unsigned long summary)
+alpha_fp_emul (unsigned long pc)
{
FP_DECL_EX;
FP_DECL_S(SA); FP_DECL_S(SB); FP_DECL_S(SR);
@@ -320,56 +305,12 @@ alpha_fp_emul (unsigned long pc, unsigned long summary)
swcr |= (_fex << IEEE_STATUS_TO_EXCSUM_SHIFT);
current_thread_info()->ieee_state
|= (_fex << IEEE_STATUS_TO_EXCSUM_SHIFT);
- }
- /*
- * EV6 records exception status bits in the FPCR before delivering the
- * software completion trap, and swcr_update_status() above merged them
- * into SWCR. Some can be wrong for the instruction we just emulated:
- * a CVTTS of a value exactly representable as a subnormal sets FPCR_UNF
- * even though the result is exact. Clear the exceptions the trap
- * reported but that soft-fp did not raise.
- */
- if (implver() == IMPLVER_EV6) {
- unsigned long spurious = summary & EXC_SUM_MASK;
-
- if (spurious & (EXC_SUM_UNF | EXC_SUM_OVF)) {
- /*
- * EXC_SUM reports only the underflow or overflow,
- * but the hardware sets INE alongside it in the FPCR.
- */
- spurious |= EXC_SUM_INE;
- } else if (!spurious) {
- /*
- * No exception reported, so this was a denormal
- * operand trap, for which INE and UNF can be
- * fabricated as well.
- */
- spurious = EXC_SUM_INE | EXC_SUM_UNF;
- }
+ /* Update hardware control register. */
+ fpcr &= (~FPCR_MASK | FPCR_DYN_MASK);
+ fpcr |= ieee_swcr_to_fpcr(swcr);
+ wrfpcr(fpcr);
- /*
- * Never clear an exception software has confirmed. Every
- * instruction that genuinely raises one traps for software
- * completion and is recorded in ieee_state above, so a bit
- * found there -- including one just set from _fex -- belongs
- * to this or an earlier instruction and must survive.
- */
- spurious &= ~(current_thread_info()->ieee_state
- >> IEEE_STATUS_TO_EXCSUM_SHIFT);
-
- swcr &= ~(spurious << IEEE_STATUS_TO_EXCSUM_SHIFT);
- }
-
- /*
- * Update hardware control register. This has to happen even when
- * soft-fp raised nothing, to clear any fabricated bits.
- */
- fpcr &= (~FPCR_MASK | FPCR_DYN_MASK);
- fpcr |= ieee_swcr_to_fpcr(swcr);
- wrfpcr(fpcr);
-
- if (_fex) {
/* Do we generate a signal? */
_fex = _fex & swcr & IEEE_TRAP_ENABLE_MASK;
si_code = 0;
@@ -451,16 +392,9 @@ alpha_fp_emul_imprecise (struct pt_regs *regs, unsigned long write_mask)
break;
}
if (!write_mask) {
- /*
- * Re-execute insns in the trap-shadow. Pass no
- * exception summary: it describes the trap, which
- * was taken anywhere in the shadow, and so is not
- * attribution for this instruction. Nothing is
- * lost, since only EV6 -- which traps precisely and
- * never comes this way -- needs it.
- */
+ /* Re-execute insns in the trap-shadow. */
regs->pc = trigger_pc + 4;
- si_code = alpha_fp_emul(trigger_pc, 0);
+ si_code = alpha_fp_emul(trigger_pc);
goto egress;
}
trigger_pc -= 4;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 580/982] Revert "alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (578 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 579/982] Revert "alpha: dont leak hardware-fabricated FP exception bits to user space" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 581/982] net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg Greg Kroah-Hartman
` (408 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit a51363d8b28e3d05a2a63ea0c9167bc1494bf5af.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/alpha/include/uapi/asm/fpu.h | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
diff --git a/arch/alpha/include/uapi/asm/fpu.h b/arch/alpha/include/uapi/asm/fpu.h
index d28dc36786e27..cea9eafa056fc 100644
--- a/arch/alpha/include/uapi/asm/fpu.h
+++ b/arch/alpha/include/uapi/asm/fpu.h
@@ -101,12 +101,7 @@ ieee_swcr_to_fpcr(unsigned long sw)
| IEEE_TRAP_ENABLE_OVF)) << 48;
fp |= (~sw & (IEEE_TRAP_ENABLE_UNF | IEEE_TRAP_ENABLE_INE)) << 57;
fp |= (sw & IEEE_MAP_UMZ ? FPCR_UNDZ | FPCR_UNFD : 0);
- /*
- * Disable denormal operand traps only when denormal inputs are to be
- * flushed to zero. Otherwise they must keep trapping, so that /S
- * instructions reach the kernel emulation handler.
- */
- fp |= (sw & IEEE_MAP_DMZ ? FPCR_DNOD : 0);
+ fp |= (~sw & IEEE_TRAP_ENABLE_DNO) << 41;
return fp;
}
@@ -121,6 +116,7 @@ ieee_fpcr_to_swcr(unsigned long fp)
| IEEE_TRAP_ENABLE_OVF);
sw |= (~fp >> 57) & (IEEE_TRAP_ENABLE_UNF | IEEE_TRAP_ENABLE_INE);
sw |= (fp >> 47) & IEEE_MAP_UMZ;
+ sw |= (~fp >> 41) & IEEE_TRAP_ENABLE_DNO;
return sw;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 581/982] net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (579 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 580/982] Revert "alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally" Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 582/982] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
` (407 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangguan Wang, Wen Gu, D. Wythe,
David S. Miller, Junjie Cao, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangguan Wang <guangguan.wang@linux.alibaba.com>
commit 7863c9f3d24ba49dbead7e03dfbe40deb5888fdf upstream.
When receiving proposal msg in server, the fields v2_ext_offset/
eid_cnt/ism_gid_cnt in proposal msg are from the remote client
and can not be fully trusted. Especially the field v2_ext_offset,
once exceed the max value, there has the chance to access wrong
address, and crash may happen.
This patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt
before using them.
Fixes: 8c3dca341aea ("net/smc: build and send V2 CLC proposal")
Signed-off-by: Guangguan Wang <guangguan.wang@linux.alibaba.com>
Reviewed-by: Wen Gu <guwen@linux.alibaba.com>
Reviewed-by: D. Wythe <alibuda@linux.alibaba.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ jcao: SMCD_CLC_MAX_V2_GID_ENTRIES does not exist in 6.1;
SMC_MAX_ISM_DEVS is the same limit (8) under its pre-b40584d14570 name ]
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/smc/af_smc.c | 3 ++-
net/smc/smc_clc.c | 8 +++++++-
net/smc/smc_clc.h | 8 +++++++-
3 files changed, 16 insertions(+), 3 deletions(-)
diff --git a/net/smc/af_smc.c b/net/smc/af_smc.c
index 6713296fffd99..89fa7295275ca 100644
--- a/net/smc/af_smc.c
+++ b/net/smc/af_smc.c
@@ -2225,7 +2225,8 @@ static void smc_find_rdma_v2_device_serv(struct smc_sock *new_smc,
goto not_found;
smc_v2_ext = smc_get_clc_v2_ext(pclc);
- if (!smc_clc_match_eid(ini->negotiated_eid, smc_v2_ext, NULL, NULL))
+ if (!smc_v2_ext ||
+ !smc_clc_match_eid(ini->negotiated_eid, smc_v2_ext, NULL, NULL))
goto not_found;
/* prepare RDMA check */
diff --git a/net/smc/smc_clc.c b/net/smc/smc_clc.c
index ad1120a43dbd9..762e50354e11f 100644
--- a/net/smc/smc_clc.c
+++ b/net/smc/smc_clc.c
@@ -352,7 +352,6 @@ static bool smc_clc_msg_prop_valid(struct smc_clc_msg_proposal *pclc)
struct smc_clc_msg_hdr *hdr = &pclc->hdr;
struct smc_clc_v2_extension *v2_ext;
- v2_ext = smc_get_clc_v2_ext(pclc);
pclc_prfx = smc_clc_proposal_get_prefix(pclc);
if (!pclc_prfx ||
pclc_prfx->ipv6_prefixes_cnt > SMC_CLC_MAX_V6_PREFIX)
@@ -369,6 +368,13 @@ static bool smc_clc_msg_prop_valid(struct smc_clc_msg_proposal *pclc)
sizeof(struct smc_clc_msg_trail))
return false;
} else {
+ v2_ext = smc_get_clc_v2_ext(pclc);
+ if ((hdr->typev2 != SMC_TYPE_N &&
+ (!v2_ext || v2_ext->hdr.eid_cnt > SMC_CLC_MAX_UEID)) ||
+ (smcd_indicated(hdr->typev2) &&
+ v2_ext->hdr.ism_gid_cnt > SMC_MAX_ISM_DEVS))
+ return false;
+
if (ntohs(hdr->length) !=
sizeof(*pclc) +
sizeof(struct smc_clc_msg_smcd) +
diff --git a/net/smc/smc_clc.h b/net/smc/smc_clc.h
index 0f6102cd5de17..cdba392b6ec9c 100644
--- a/net/smc/smc_clc.h
+++ b/net/smc/smc_clc.h
@@ -347,8 +347,14 @@ static inline struct smc_clc_v2_extension *
smc_get_clc_v2_ext(struct smc_clc_msg_proposal *prop)
{
struct smc_clc_msg_smcd *prop_smcd = smc_get_clc_msg_smcd(prop);
+ u16 max_offset;
- if (!prop_smcd || !ntohs(prop_smcd->v2_ext_offset))
+ max_offset = offsetof(struct smc_clc_msg_proposal_area, pclc_v2_ext) -
+ offsetof(struct smc_clc_msg_proposal_area, pclc_smcd) -
+ offsetofend(struct smc_clc_msg_smcd, v2_ext_offset);
+
+ if (!prop_smcd || !ntohs(prop_smcd->v2_ext_offset) ||
+ ntohs(prop_smcd->v2_ext_offset) > max_offset)
return NULL;
return (struct smc_clc_v2_extension *)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 582/982] selftests/landlock: Add tests for whiteout object creation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (580 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 581/982] net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 6.1 583/982] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
` (406 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit ee890889b30b22f9a21636061def7a04e4f89380 ]
Add tests to check that whiteout object creation is guarded by
LANDLOCK_ACCESS_FS_MAKE_REG, in the cases where these are created from
userspace:
* Conventional creation with mknod()
* Linking or renaming an existing whiteout object
* renameat2() with RENAME_WHITEOUT,
which creates a new whiteout object in the source location
* renameat2() with RENAME_EXCHANGE,
with one of the renamed objects being a whiteout object
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-4-gnoack@google.com
[mic: Update commit message as requested]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the tests to the older filesystem fixture and
ruleset helper]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 209 ++++++++++++++++++++-
1 file changed, 207 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 2a11c4a26d71..6885b5728e41 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -36,6 +36,10 @@ int renameat2(int olddirfd, const char *oldpath, int newdirfd,
#define RENAME_EXCHANGE (1 << 1)
#endif
+#ifndef RENAME_WHITEOUT
+#define RENAME_WHITEOUT (1 << 2)
+#endif
+
#define TMP_DIR "tmp"
#define BINARY_PATH "./true"
@@ -62,6 +66,8 @@ static const char dir_s3d1[] = TMP_DIR "/s3d1";
/* dir_s3d2 is a mount point. */
static const char dir_s3d2[] = TMP_DIR "/s3d1/s3d2";
static const char dir_s3d3[] = TMP_DIR "/s3d1/s3d2/s3d3";
+static const char file1_s3d3[] = TMP_DIR "/s3d1/s3d2/s3d3/f1";
+static const char file1_s3d4[] = TMP_DIR "/s3d1/s3d2/s3d4/f1";
/*
* layout1 hierarchy:
@@ -258,7 +264,8 @@ static void create_layout1(struct __test_metadata *const _metadata)
ASSERT_EQ(0, mount("tmp", dir_s3d2, "tmpfs", 0, "size=4m,mode=700"));
clear_cap(_metadata, CAP_SYS_ADMIN);
- ASSERT_EQ(0, mkdir(dir_s3d3, 0700));
+ create_file(_metadata, file1_s3d3);
+ create_file(_metadata, file1_s3d4);
}
static void remove_layout1(struct __test_metadata *const _metadata)
@@ -275,7 +282,8 @@ static void remove_layout1(struct __test_metadata *const _metadata)
EXPECT_EQ(0, remove_path(file1_s2d2));
EXPECT_EQ(0, remove_path(file1_s2d1));
- EXPECT_EQ(0, remove_path(dir_s3d3));
+ EXPECT_EQ(0, remove_path(file1_s3d3));
+ EXPECT_EQ(0, remove_path(file1_s3d4));
set_cap(_metadata, CAP_SYS_ADMIN);
umount(dir_s3d2);
clear_cap(_metadata, CAP_SYS_ADMIN);
@@ -616,6 +624,27 @@ static void enforce_ruleset(struct __test_metadata *const _metadata,
}
}
+static void enforce_fs(struct __test_metadata *const _metadata,
+ const __u64 access_fs, const struct rule rules[])
+{
+ int ruleset_fd;
+
+ if (rules) {
+ ruleset_fd = create_ruleset(_metadata, access_fs, rules);
+ } else {
+ const struct landlock_ruleset_attr ruleset_attr = {
+ .handled_access_fs = access_fs,
+ };
+
+ ruleset_fd = landlock_create_ruleset(&ruleset_attr,
+ sizeof(ruleset_attr), 0);
+ ASSERT_LE(0, ruleset_fd);
+ }
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+}
+
TEST_F_FORK(layout1, proc_nsfs)
{
const struct rule rules[] = {
@@ -1992,6 +2021,170 @@ TEST_F_FORK(layout1, rename_file)
RENAME_EXCHANGE));
}
+TEST_F_FORK(layout1, rename_whiteout_denied)
+{
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Deny MAKE_REG, but allow MAKE_FIFO. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, NULL);
+
+ /*
+ * Try to rename a file with RENAME_WHITEOUT.
+ * file1_s3d3 is in dir_s3d2 (tmpfs), so it supports RENAME_WHITEOUT.
+ * Denied, because whiteout creation is guarded with MAKE_REG.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+}
+
+static bool is_whiteout(const char *const path)
+{
+ struct stat st;
+
+ if (stat(path, &st) == -1)
+ return false;
+
+ return S_ISCHR(st.st_mode) && st.st_rdev == makedev(0, 0);
+}
+
+static bool is_fifo(const char *const path)
+{
+ struct stat st;
+
+ return stat(path, &st) == 0 && S_ISFIFO(st.st_mode);
+}
+
+TEST_F_FORK(layout1, rename_whiteout_allowed)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Allow MAKE_REG below dir_s3d3. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, rules);
+
+ /*
+ * Rename a file with RENAME_WHITEOUT within the same directory.
+ * Allowed, because MAKE_REG is granted for the whiteout object which
+ * gets created in the source location.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d3/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_reparenting)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The moved files are FIFOs. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * The whiteout object is created in the source directory: Moving the
+ * FIFO out of dir_s3d4 is denied because MAKE_REG is not granted
+ * there, even though it is granted in the destination directory
+ * dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Moving the FIFO out of dir_s3d3 is allowed, because MAKE_REG is
+ * granted there for the created whiteout object.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d4/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d4/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_exchange)
+{
+ const char *const whiteout_s3d3 = TMP_DIR "/s3d1/s3d2/s3d3/f2";
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The exchanged files are FIFOs and an existing whiteout object. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, mknod(whiteout_s3d3, S_IFCHR | 0600, makedev(0, 0)));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * With RENAME_EXCHANGE, the whiteout object moves into the source
+ * directory of the rename: Exchanging the FIFO in dir_s3d4 with the
+ * whiteout object is denied because MAKE_REG is not granted in
+ * dir_s3d4, even though it is granted in the whiteout object's own
+ * directory dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Exchanging the FIFO in dir_s3d3 with the whiteout object is
+ * allowed, because MAKE_REG is granted in the directory into which
+ * the whiteout object moves.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+
+ /* The FIFO and the whiteout object swapped places. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(whiteout_s3d3));
+}
+
TEST_F_FORK(layout1, rename_dir)
{
const struct rule rules[] = {
@@ -3008,6 +3201,18 @@ TEST_F_FORK(layout1, make_char)
makedev(1, 3));
}
+TEST_F_FORK(layout1, make_whiteout)
+{
+ /*
+ * Creates a whiteout object (creation guarded by MAKE_REG).
+ *
+ * Contrary to the other character devices, this does not require
+ * CAP_MKNOD, cf. vfs_mknod().
+ */
+ test_make_file(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, S_IFCHR,
+ makedev(0, 0));
+}
+
TEST_F_FORK(layout1, make_block)
{
/* Creates a /dev/loop0 device. */
--
2.51.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 583/982] sunvdc: fix -EIO issue due to lack of retries
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (581 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 582/982] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 584/982] Revert "perf cs-etm: Avoid truncating AUX buffer sizes to int" Greg Kroah-Hartman
` (405 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Stian Halseth, Jens Axboe, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
[ Upstream commit 5067d4ba713961d8ccea1e06cd4c453793f3121e ]
John reports that since commit:
a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN")
users of Linux inside Solaris ldom see occasional -EIO errors because
the request send loop now times out. The current loop does 10 retries,
and inside vio_ldc_send() a further 1000 1usec retries are done as well.
Even with 10.5 msec of busy loop retries that's apparently not enough to
always succeed.
Rather than introduce continued busy looping, requeue the request and
have the delayed queue kicking retry the request after another 10ms.
This obviously isn't ideal, but there's seemingly no way to wait for
this type of event. And if 10ms of busy looping was not enough to make
progress, then presumably this is an edge condition and we just need to
guarantee to make forward progress at some later point in time. That's
more suitably done through letting the CPU tend to other work, rather
than sitting in a tight loop retrying.
[stian: rebased on top of the cookie-unmap fix, without which every
requeued attempt leaks LDC map table entries; tested on an
UltraSPARC T4 LDOM where the vdc_tx_trigger failure condition was
reproduced and absorbed by the requeue with no I/O error]
Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://lore.kernel.org/all/20251006100226.4246-2-glaubitz@physik.fu-berlin.de/
Link: https://lore.kernel.org/all/418310b3-2b77-4534-b2fd-27dcc11e333c@kernel.dk/
Signed-off-by: Stian Halseth <stian@itx.no>
Link: https://patch.msgid.link/20260901173947.3292110-3-stian@itx.no
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/sunvdc.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/block/sunvdc.c b/drivers/block/sunvdc.c
index f03bf77da8c4d..11bdbf5b2f963 100644
--- a/drivers/block/sunvdc.c
+++ b/drivers/block/sunvdc.c
@@ -557,6 +557,7 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
struct vdc_port *port = hctx->queue->queuedata;
struct vio_dring_state *dr;
unsigned long flags;
+ int ret;
dr = &port->vio.drings[VIO_DRIVER_TX_RING];
@@ -578,7 +579,13 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
return BLK_STS_DEV_RESOURCE;
}
- if (__send_request(bd->rq) < 0) {
+ ret = __send_request(bd->rq);
+ if (ret == -EAGAIN) {
+ spin_unlock_irqrestore(&port->vio.lock, flags);
+ /* already spun for 10msec, defer 10msec and retry */
+ blk_mq_delay_kick_requeue_list(hctx->queue, 10);
+ return BLK_STS_DEV_RESOURCE;
+ } else if (ret < 0) {
spin_unlock_irqrestore(&port->vio.lock, flags);
return BLK_STS_IOERR;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 584/982] Revert "perf cs-etm: Avoid truncating AUX buffer sizes to int"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (582 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 6.1 583/982] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 585/982] Revert "perf cs-etm: Flush thread stacks after decoder reset" Greg Kroah-Hartman
` (404 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 9ccb4d7bd325012505d2d5d2456cad199417be57.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/cs-etm.c | 46 +++++++++++++++++-----------------------
1 file changed, 20 insertions(+), 26 deletions(-)
diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 10e9657ee58c1..361b75b0882c4 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -1087,7 +1087,8 @@ cs_etm__get_trace(struct cs_etm_queue *etmq)
etmq->buf_used = 0;
etmq->buf_len = aux_buffer->size;
etmq->buf = aux_buffer->data;
- return 0;
+
+ return etmq->buf_len;
}
static void cs_etm__set_pid_tid_cpu(struct cs_etm_auxtrace *etm,
@@ -1684,33 +1685,26 @@ static int cs_etm__get_data_block(struct cs_etm_queue *etmq)
{
int ret;
- /* The current block is not finished */
- if (etmq->buf_len)
- return 1;
-
- ret = cs_etm__get_trace(etmq);
- if (ret < 0)
- return ret;
-
- /* No more buffer to read */
- if (!etmq->buf_len)
- return 0;
-
- /*
- * We cannot assume consecutive blocks in the data file
- * are contiguous, reset the decoder to force re-sync.
- */
- ret = cs_etm_decoder__reset(etmq->decoder);
- if (ret)
- return ret;
+ if (!etmq->buf_len) {
+ ret = cs_etm__get_trace(etmq);
+ if (ret <= 0)
+ return ret;
+ /*
+ * We cannot assume consecutive blocks in the data file
+ * are contiguous, reset the decoder to force re-sync.
+ */
+ ret = cs_etm_decoder__reset(etmq->decoder);
+ if (ret)
+ return ret;
- /*
- * Since the decoder is reset, this causes a global trace
- * discontinuity. Flush all thread stacks.
- */
- cs_etm__flush_all_stack(etmq);
+ /*
+ * Since the decoder is reset, this causes a global trace
+ * discontinuity. Flush all thread stacks.
+ */
+ cs_etm__flush_all_stack(etmq);
+ }
- return 1;
+ return etmq->buf_len;
}
static bool cs_etm__is_svc_instr(struct cs_etm_queue *etmq, u8 trace_chan_id,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 585/982] Revert "perf cs-etm: Flush thread stacks after decoder reset"
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (583 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 584/982] Revert "perf cs-etm: Avoid truncating AUX buffer sizes to int" Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 586/982] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
` (403 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 097df36140476ce86b23bfaa2fb9104a9c095752.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/cs-etm.c | 45 ----------------------------------------
1 file changed, 45 deletions(-)
diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 361b75b0882c4..3b54baf79bd4a 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -1635,45 +1635,6 @@ static int cs_etm__end_block(struct cs_etm_queue *etmq,
return 0;
}
-
-static int cs_etm__flush_stack_cb(struct thread *thread,
- void *data __maybe_unused)
-{
- thread_stack__flush(thread);
- return 0;
-}
-
-static void cs_etm__flush_machine_stack(struct cs_etm_queue *etmq, pid_t pid)
-{
- struct machine *machine;
-
- machine = machines__find(&etmq->etm->session->machines, pid);
- if (machine)
- machine__for_each_thread(machine, cs_etm__flush_stack_cb, NULL);
-}
-
-static void cs_etm__flush_all_stack(struct cs_etm_queue *etmq)
-{
- enum cs_etm_pid_fmt pid_fmt = cs_etm__get_pid_fmt(etmq);
-
- if (!etmq->etm->synth_opts.last_branch)
- return;
-
- switch (pid_fmt) {
- case CS_ETM_PIDFMT_CTXTID2:
- /* Clear the guest stack if virtualization is supported */
- cs_etm__flush_machine_stack(etmq, DEFAULT_GUEST_KERNEL_ID);
- fallthrough;
- case CS_ETM_PIDFMT_CTXTID:
- cs_etm__flush_machine_stack(etmq, HOST_KERNEL_ID);
- break;
- case CS_ETM_PIDFMT_NONE:
- default:
- break;
-
- }
-}
-
/*
* cs_etm__get_data_block: Fetch a block from the auxtrace_buffer queue
* if need be.
@@ -1696,12 +1657,6 @@ static int cs_etm__get_data_block(struct cs_etm_queue *etmq)
ret = cs_etm_decoder__reset(etmq->decoder);
if (ret)
return ret;
-
- /*
- * Since the decoder is reset, this causes a global trace
- * discontinuity. Flush all thread stacks.
- */
- cs_etm__flush_all_stack(etmq);
}
return etmq->buf_len;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 586/982] media: video-i2c: fix buffer queue ordering
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (584 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 585/982] Revert "perf cs-etm: Flush thread stacks after decoder reset" Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 587/982] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
` (402 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Arash Golgol, Hans Verkuil,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arash Golgol <arash.golgol@gmail.com>
[ Upstream commit bc4574c265ed738849e46d942617100580fcedd2 ]
Queued buffers are added to the tail of vid_cap_active in
buffer_queue(), but the capture kthread also retrieves buffers from
the tail of the list.
This makes the queue behave as LIFO instead of FIFO when multiple
buffers are queued.
Fix this by retrieving buffers from the head of the list.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/i2c/video-i2c.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/media/i2c/video-i2c.c b/drivers/media/i2c/video-i2c.c
index 83a4fc95252fa..d6aecf07040b1 100644
--- a/drivers/media/i2c/video-i2c.c
+++ b/drivers/media/i2c/video-i2c.c
@@ -464,8 +464,9 @@ static int video_i2c_thread_vid_cap(void *priv)
spin_lock(&data->slock);
if (!list_empty(&data->vid_cap_active)) {
- vid_cap_buf = list_last_entry(&data->vid_cap_active,
- struct video_i2c_buffer, list);
+ vid_cap_buf = list_first_entry(&data->vid_cap_active,
+ struct video_i2c_buffer,
+ list);
list_del(&vid_cap_buf->list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 587/982] ipv6: Select best matching nexthop object in fib6_table_lookup()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (585 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 586/982] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 588/982] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
` (401 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, David Ahern,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit 484bb9d164df397a53e0f533b262b27b1590efcb ]
Currently, when using multipath routes without nexthop objects,
fib6_table_lookup() selects the nexthop with the highest score. This
means that when both a source address and an oif are specified, the
nexthop that is chosen is the one that matches in terms of oif:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip address add 2001:db8:2::1/64 dev lo
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
When using nexthop objects, fib6_table_lookup() selects the first
matching nexthop and not necessarily the one with the highest score:
# ip nexthop add id 1 via fe80::1 dev dummy1
# ip nexthop add id 2 via fe80::2 dev dummy2
# ip nexthop add id 3 group 1/2
# ip route add 2001:db8:20::/64 nhid 3
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
This is not very significant right now because the nexthop is later
overwritten during path selection in fib6_select_path(). However, the
next patch is going to skip path selection when we have an oif match
during output route lookup.
As a preparation for this change, align the nexthop object behavior with
the legacy one and make sure that fib6_table_lookup() always selects the
best matching nexthop. Do that by always returning 0 from
rt6_nh_find_match() in order not to terminate the loop in
nexthop_for_each_fib6_nh() and storing in arg->nh the best matching
nexthop so far.
Behavior after the change:
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260611154605.992528-2-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/route.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index b1de7c6f895a2..be3e36162d059 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -823,9 +823,11 @@ static int rt6_nh_find_match(struct fib6_nh *nh, void *_arg)
{
struct fib6_nh_frl_arg *arg = _arg;
- arg->nh = nh;
- return find_match(nh, arg->flags, arg->oif, arg->strict,
- arg->mpri, arg->do_rr);
+ if (find_match(nh, arg->flags, arg->oif, arg->strict, arg->mpri,
+ arg->do_rr))
+ arg->nh = nh;
+
+ return 0;
}
static void __find_rr_leaf(struct fib6_info *f6i_start,
@@ -865,11 +867,10 @@ static void __find_rr_leaf(struct fib6_info *f6i_start,
res->nh = nexthop_fib6_nh(f6i->nh);
return;
}
- if (nexthop_for_each_fib6_nh(f6i->nh, rt6_nh_find_match,
- &arg)) {
- matched = true;
- nh = arg.nh;
- }
+ nexthop_for_each_fib6_nh(f6i->nh, rt6_nh_find_match,
+ &arg);
+ matched = !!arg.nh;
+ nh = arg.nh;
} else {
nh = f6i->fib6_nh;
if (find_match(nh, f6i->fib6_flags, oif, strict,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 588/982] ipv6: Honor oif when choosing nexthop for locally generated traffic
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (586 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 587/982] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 589/982] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
` (400 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Ahern, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit d25e7e9d8a6c1e2afb854613e417c6aa1a28ce6f ]
Commit 741a11d9e410 ("net: ipv6: Add RT6_LOOKUP_F_IFACE flag if oif is
set") made the kernel honor the oif parameter when specified as part of
output route lookup:
# ip route add 2001:db8:1::/64 dev dummy1
# ip route add ::/0 dev dummy2
# ip route get 2001:db8:1::1 oif dummy2 fibmatch
default dev dummy2 metric 1024 pref medium
Due to regression reports, the behavior was partially reverted in commit
d46a9d678e4c ("net: ipv6: Dont add RT6_LOOKUP_F_IFACE flag if saddr
set") to only honor the oif if source address is not specified:
# ip route get 2001:db8:1::1 from 2001:db8:2::1 oif dummy2 fibmatch
2001:db8:1::/64 dev dummy1 metric 1024 pref medium
That is, when source address is specified, the kernel will choose the
most specific route even if its nexthop device does not match the
specified oif.
This creates a problem for multipath routes. After looking up a route,
when source address is not specified, the kernel will choose a nexthop
whose nexthop device matches the specified oif:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# for i in {1..100}; do ip route get 2001:db8:10::${i} oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
But will disregard the oif when source address is specified despite the
fact that a matching nexthop exists:
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
53 dummy1
47 dummy2
This behavior differs from IPv4:
# ip address add 192.0.2.1/32 dev lo
# ip route add 198.51.100.0/24 nexthop via inet6 fe80::1 dev dummy1 nexthop via inet6 fe80::2 dev dummy2
# for i in {1..100}; do ip route get 198.51.100.${i} from 192.0.2.1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
What happens is that fib6_table_lookup() returns a route with a matching
nexthop device (assuming it exists):
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
But it is later overwritten during path selection in fib6_select_path()
which instead chooses a nexthop according to the calculated hash.
Solve this by telling fib6_select_path() to skip path selection if we
have an oif match during output route lookup (iif being
LOOPBACK_IFINDEX).
Behavior after the change:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
Note that enabling forwarding is only needed because we did not add
neighbor entries for the gateway addresses. When forwarding is disabled
and CONFIG_IPV6_ROUTER_PREF is not enabled in kernel config, the kernel
will treat non-existing neighbor entries as errors and perform
round-robin between the nexthops:
# sysctl -wq net.ipv6.conf.all.forwarding=0
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
50 dummy1
50 dummy2
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260611154605.992528-3-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/route.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index be3e36162d059..0a819dbd8e58d 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -2249,6 +2249,7 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
{
struct fib6_result res = {};
struct rt6_info *rt = NULL;
+ bool have_oif_match;
int strict = 0;
WARN_ON_ONCE((flags & RT6_LOOKUP_F_DST_NOREF) &&
@@ -2265,7 +2266,9 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
if (res.f6i == net->ipv6.fib6_null_entry)
goto out;
- fib6_select_path(net, &res, fl6, oif, false, skb, strict);
+ have_oif_match = fl6->flowi6_iif == LOOPBACK_IFINDEX &&
+ oif == res.nh->fib_nh_dev->ifindex;
+ fib6_select_path(net, &res, fl6, oif, have_oif_match, skb, strict);
/*Search through exception table */
rt = rt6_find_cached_rt(&res, &fl6->daddr, &fl6->saddr);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 589/982] xfrm: avoid RCU warnings around the per-netns netlink socket
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (587 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 588/982] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 590/982] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
` (399 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sabrina Dubroca, Simon Horman,
Steffen Klassert, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sabrina Dubroca <sd@queasysnail.net>
[ Upstream commit d87f8bc47fbf012a7f115e311d0603d97e47c34c ]
net->xfrm.nlsk is used in 2 types of contexts:
- fully under RCU, with rcu_read_lock + rcu_dereference and a NULL check
- in the netlink handlers, with requests coming from a userspace socket
In the 2nd case, net->xfrm.nlsk is guaranteed to stay non-NULL and the
object is alive, since we can't enter the netns destruction path while
the user socket holds a reference on the netns.
After adding the __rcu annotation to netns_xfrm.nlsk (which silences
sparse warnings in the RCU users and __net_init code), we need to tell
sparse that the 2nd case is safe. Add a helper for that.
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Stable-dep-of: d1ebd9081879 ("xfrm: fix compat ALLOCSPI request use-after-free")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/netns/xfrm.h | 2 +-
net/xfrm/xfrm_user.c | 25 +++++++++++++++++--------
2 files changed, 18 insertions(+), 9 deletions(-)
diff --git a/include/net/netns/xfrm.h b/include/net/netns/xfrm.h
index 423b52eca908d..7922ec72eaa68 100644
--- a/include/net/netns/xfrm.h
+++ b/include/net/netns/xfrm.h
@@ -59,7 +59,7 @@ struct netns_xfrm {
struct list_head inexact_bins;
- struct sock *nlsk;
+ struct sock __rcu *nlsk;
struct sock *nlsk_stash;
u32 sysctl_aevent_etime;
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 5f91a09350757..66c73b71ad653 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -35,6 +35,15 @@
#endif
#include <asm/unaligned.h>
+static struct sock *xfrm_net_nlsk(const struct net *net, const struct sk_buff *skb)
+{
+ /* get the source of this request, see netlink_unicast_kernel */
+ const struct sock *sk = NETLINK_CB(skb).sk;
+
+ /* sk is refcounted, the netns stays alive and nlsk with it */
+ return rcu_dereference_protected(net->xfrm.nlsk, sk->sk_net_refcnt);
+}
+
static int verify_one_alg(struct nlattr **attrs, enum xfrm_attr_type_t type,
struct netlink_ext_ack *extack)
{
@@ -1460,7 +1469,7 @@ static int xfrm_get_spdinfo(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_spdinfo(r_skb, net, sportid, seq, *flags);
BUG_ON(err < 0);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, sportid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, sportid);
}
static inline unsigned int xfrm_sadinfo_msgsize(void)
@@ -1520,7 +1529,7 @@ static int xfrm_get_sadinfo(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_sadinfo(r_skb, net, sportid, seq, *flags);
BUG_ON(err < 0);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, sportid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, sportid);
}
static int xfrm_get_sa(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -1540,7 +1549,7 @@ static int xfrm_get_sa(struct sk_buff *skb, struct nlmsghdr *nlh,
if (IS_ERR(resp_skb)) {
err = PTR_ERR(resp_skb);
} else {
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
}
xfrm_state_put(x);
out_noput:
@@ -1616,7 +1625,7 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
}
}
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
xfrm_state_put(x);
@@ -2246,7 +2255,7 @@ static int xfrm_get_default(struct sk_buff *skb, struct nlmsghdr *nlh,
r_up->out = READ_ONCE(net->xfrm.policy_default[XFRM_POLICY_OUT]);
nlmsg_end(r_skb, r_nlh);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, portid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, portid);
}
static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -2312,7 +2321,7 @@ static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
if (IS_ERR(resp_skb)) {
err = PTR_ERR(resp_skb);
} else {
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb,
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb,
NETLINK_CB(skb).portid);
}
} else {
@@ -2472,7 +2481,7 @@ static int xfrm_get_ae(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_aevent(r_skb, x, &c);
BUG_ON(err < 0);
- err = nlmsg_unicast(net->xfrm.nlsk, r_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, NETLINK_CB(skb).portid);
spin_unlock_bh(&x->lock);
xfrm_state_put(x);
return err;
@@ -3098,7 +3107,7 @@ static int xfrm_user_rcv_msg(struct sk_buff *skb, struct nlmsghdr *nlh,
goto err;
}
- err = netlink_dump_start(net->xfrm.nlsk, skb, nlh, &c);
+ err = netlink_dump_start(xfrm_net_nlsk(net, skb), skb, nlh, &c);
goto err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 590/982] xfrm: fix compat ALLOCSPI request use-after-free
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (588 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 589/982] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 591/982] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
` (398 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, David Lee,
Steffen Klassert, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
[ Upstream commit d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 ]
xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.
xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.
A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator")
Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Co-developed-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_user.c | 12 ------------
1 file changed, 12 deletions(-)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 66c73b71ad653..6fb79def144c8 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -1563,7 +1563,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
struct net *net = sock_net(skb->sk);
struct xfrm_state *x;
struct xfrm_userspi_info *p;
- struct xfrm_translator *xtr;
struct sk_buff *resp_skb;
xfrm_address_t *daddr;
int family;
@@ -1614,17 +1613,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
goto out;
}
- xtr = xfrm_get_translator();
- if (xtr) {
- err = xtr->alloc_compat(skb, nlmsg_hdr(skb));
-
- xfrm_put_translator(xtr);
- if (err) {
- kfree_skb(resp_skb);
- goto out;
- }
- }
-
err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 591/982] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (589 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 590/982] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 592/982] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
` (397 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot, Eric Dumazet,
Steffen Klassert, Liu Jian, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit d2f5082f9e84653fa1a9e8aebaaff23e688f5e19 ]
syzbot reported a suspicious RCU usage warning in ip6_pkt_drop():
WARNING: suspicious RCU usage in ip6_pkt_drop
include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!
Call Trace:
__in6_dev_get_safely include/net/addrconf.h:389 [inline]
ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620
ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651
xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486
When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through
workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue,
the reinjection loop ceased running in softirq context. Workqueue workers
run in process context where local_bh_disable() does not enter an RCU
read-side critical section under CONFIG_PREEMPT_RCU.
Because finish callbacks (such as ip6_rcv_finish) expect to run under an
RCU read lock (performing route lookups, l3mdev lookups, and accessing
RCU-protected data structures), invoking them in workqueue context without
rcu_read_lock() triggers RCU lockdep warnings.
Furthermore, packets queued to the workqueue via xfrm_trans_queue_net()
may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).
Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev
with blackhole_netdev, so dst entries do not keep skb->dev alive while
queued in the workqueue.
Fix these issues by:
1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the
caller's RCU section to ensure dst is reference-counted before queuing.
2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue
deferral so skb->dev remains valid during finish() callback processing.
3. Acquiring rcu_read_lock() around the finish callback invocation loop in
xfrm_trans_reinject().
Fixes: 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Cc: Liu Jian <liujian56@huawei.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_input.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/net/xfrm/xfrm_input.c b/net/xfrm/xfrm_input.c
index c3c909d9c8fab..de2e8b16b217a 100644
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -757,12 +757,17 @@ static void xfrm_trans_reinject(struct work_struct *work)
spin_unlock_bh(&trans->queue_lock);
local_bh_disable();
+ rcu_read_lock();
while ((skb = __skb_dequeue(&queue))) {
struct net *net = XFRM_TRANS_SKB_CB(skb)->net;
+ struct net_device *dev = skb->dev;
XFRM_TRANS_SKB_CB(skb)->finish(net, NULL, skb);
+ if (dev)
+ dev_put(dev);
put_net(net);
}
+ rcu_read_unlock();
local_bh_enable();
}
@@ -778,12 +783,18 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
if (skb_queue_len(&trans->queue) >= READ_ONCE(netdev_max_backlog))
return -ENOBUFS;
+ if (skb_dst(skb) && !skb_dst_force(skb))
+ return -EHOSTUNREACH;
+
BUILD_BUG_ON(sizeof(struct xfrm_trans_cb) > sizeof(skb->cb));
hold_net = maybe_get_net(net);
if (!hold_net)
return -ENODEV;
+ if (skb->dev)
+ dev_hold(skb->dev);
+
XFRM_TRANS_SKB_CB(skb)->finish = finish;
XFRM_TRANS_SKB_CB(skb)->net = hold_net;
spin_lock_bh(&trans->queue_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 592/982] esp: downgrade zerocopy managed frags before mutating skb frags
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (590 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 591/982] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 593/982] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
` (396 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maher Azzouzi, Steffen Klassert,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maher Azzouzi <maherazz04@gmail.com>
[ Upstream commit f89416eb3db151170a6f3c6dfc5239d26cdce4d2 ]
On the out-of-place output path (esp->inplace == false) ESP rewrites the
skb frag array: esp_output_head() appends a trailer frag and
esp_output_tail() replaces the frags with a destination page, both
referenced with get_page().
When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the
payload frags are owned by the ubuf and must not be referenced or
unreferenced individually, but ESP mutates the frag array without ever
downgrading the skb. This breaks the managed-frag invariant two ways:
- esp_ssg_unref() walks the source scatterlist and drops a page
reference for every frag, including the ubuf-owned payload frags,
pushing their refcount below the GUP pin bias while the pages are
still pinned, i.e. a use-after-free of the zerocopy pages;
- esp_output_tail() installs its destination page as frag 0 with
get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so
skb_release_data() takes the skip_unref branch and never drops that
reference, leaking the x->xfrag page at packet rate.
Fix this the way every other frag-mutating site does (__ip_append_data(),
__ip6_append_data(), tcp_sendmsg_locked()) and call
skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes
a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,
so the per-frag unref in esp_ssg_unref() and the frag release in
skb_release_data() are both balanced and no mixed-ownership frag array is
left behind.
Fixes: 753f1ca4e1e5 ("net: introduce managed frags infrastructure")
Signed-off-by: Maher Azzouzi <maherazz04@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/esp4.c | 6 ++++++
net/ipv6/esp6.c | 6 ++++++
2 files changed, 12 insertions(+)
diff --git a/net/ipv4/esp4.c b/net/ipv4/esp4.c
index aa1178f627552..09c2efa3a5b10 100644
--- a/net/ipv4/esp4.c
+++ b/net/ipv4/esp4.c
@@ -438,6 +438,12 @@ int esp_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info *
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
diff --git a/net/ipv6/esp6.c b/net/ipv6/esp6.c
index 312e4307ce0d5..d404f7bec268c 100644
--- a/net/ipv6/esp6.c
+++ b/net/ipv6/esp6.c
@@ -473,6 +473,12 @@ int esp6_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 593/982] ARM: socfpga: select the PL310 erratum 753970 workaround
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (591 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 592/982] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 594/982] RDMA/siw: Introduce siw_cep_set_free_and_put Greg Kroah-Hartman
` (395 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Dinh Nguyen,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit cfc1e9a543e3589ba200795b6e7fd8ef4314efdf ]
ARCH_INTEL_SOCFPGA selects CACHE_L2X0 and several PL310 erratum
workarounds. The 753970 workaround is still conditioned on PL310, but that
Kconfig symbol no longer exists, so this one selection is always disabled.
Select PL310_ERRATA_753970 directly, consistently with the other PL310
workarounds required by the platform.
Fixes: fbc125afdc50 ("ARM: socfpga: Turn on ARM errata for L2 cache")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-socfpga/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/mach-socfpga/Kconfig b/arch/arm/mach-socfpga/Kconfig
index eb72c240c2486..528c5c1368c37 100644
--- a/arch/arm/mach-socfpga/Kconfig
+++ b/arch/arm/mach-socfpga/Kconfig
@@ -16,7 +16,7 @@ menuconfig ARCH_INTEL_SOCFPGA
select ARM_ERRATA_775420
select PL310_ERRATA_588369
select PL310_ERRATA_727915
- select PL310_ERRATA_753970 if PL310
+ select PL310_ERRATA_753970
select PL310_ERRATA_769419
select RESET_CONTROLLER
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 594/982] RDMA/siw: Introduce siw_cep_set_free_and_put
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (592 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 593/982] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 595/982] RDMA/siw: Cleanup siw_accept Greg Kroah-Hartman
` (394 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernard Metzler, Guoqing Jiang,
Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoqing Jiang <guoqing.jiang@linux.dev>
[ Upstream commit b5c91543204c345f1b28af573854c4b7e699cc91 ]
Add the helper which can be used in some places.
Acked-by: Bernard Metzler <bmt@zurich.ibm.com>
Signed-off-by: Guoqing Jiang <guoqing.jiang@linux.dev>
Link: https://lore.kernel.org/r/20231113115726.12762-11-guoqing.jiang@linux.dev
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: 32cd87f54dd1 ("RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 31 ++++++++++++++----------------
1 file changed, 14 insertions(+), 17 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index 32cefc30d6cd6..bc2ad13f9c6b6 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -450,6 +450,12 @@ void siw_cep_put(struct siw_cep *cep)
kref_put(&cep->ref, __siw_cep_dealloc);
}
+static void siw_cep_set_free_and_put(struct siw_cep *cep)
+{
+ siw_cep_set_free(cep);
+ siw_cep_put(cep);
+}
+
void siw_cep_get(struct siw_cep *cep)
{
kref_get(&cep->ref);
@@ -1517,9 +1523,7 @@ int siw_connect(struct iw_cm_id *id, struct iw_cm_conn_param *params)
cep->state = SIW_EPSTATE_CLOSED;
- siw_cep_set_free(cep);
-
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
} else if (s) {
sock_release(s);
@@ -1567,16 +1571,14 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
if (cep->state != SIW_EPSTATE_RECVD_MPAREQ) {
siw_dbg_cep(cep, "out of state\n");
- siw_cep_set_free(cep);
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
return -ECONNRESET;
}
qp = siw_qp_id2obj(sdev, params->qpn);
if (!qp) {
WARN(1, "[QP %d] does not exist\n", params->qpn);
- siw_cep_set_free(cep);
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
return -EINVAL;
}
@@ -1719,8 +1721,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
cep->qp = NULL;
siw_qp_put(qp);
- siw_cep_set_free(cep);
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
return rv;
}
@@ -1743,8 +1744,7 @@ int siw_reject(struct iw_cm_id *id, const void *pdata, u8 pd_len)
if (cep->state != SIW_EPSTATE_RECVD_MPAREQ) {
siw_dbg_cep(cep, "out of state\n");
- siw_cep_set_free(cep);
- siw_cep_put(cep); /* put last reference */
+ siw_cep_set_free_and_put(cep); /* put last reference */
return -ECONNRESET;
}
@@ -1761,8 +1761,7 @@ int siw_reject(struct iw_cm_id *id, const void *pdata, u8 pd_len)
cep->state = SIW_EPSTATE_CLOSED;
- siw_cep_set_free(cep);
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
return 0;
}
@@ -1894,8 +1893,7 @@ int siw_create_listen(struct iw_cm_id *id, int backlog)
siw_socket_disassoc(s);
cep->state = SIW_EPSTATE_CLOSED;
- siw_cep_set_free(cep);
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
}
sock_release(s);
@@ -1926,8 +1924,7 @@ static void siw_drop_listeners(struct iw_cm_id *id)
cep->sock = NULL;
}
cep->state = SIW_EPSTATE_CLOSED;
- siw_cep_set_free(cep);
- siw_cep_put(cep);
+ siw_cep_set_free_and_put(cep);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 595/982] RDMA/siw: Cleanup siw_accept
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (593 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 594/982] RDMA/siw: Introduce siw_cep_set_free_and_put Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 596/982] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
` (393 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernard Metzler, Guoqing Jiang,
Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoqing Jiang <guoqing.jiang@linux.dev>
[ Upstream commit 77b59bd932a026b64303d313d966decb0e9225fa ]
With the initialization of rv and the two added label, we can
simplifiy code a bit.
Acked-by: Bernard Metzler <bmt@zurich.ibm.com>
Signed-off-by: Guoqing Jiang <guoqing.jiang@linux.dev>
Link: https://lore.kernel.org/r/20231113115726.12762-13-guoqing.jiang@linux.dev
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: 32cd87f54dd1 ("RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 41 ++++++++++--------------------
1 file changed, 14 insertions(+), 27 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index bc2ad13f9c6b6..629ed5e58473d 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -1554,7 +1554,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
struct siw_cep *cep = (struct siw_cep *)id->provider_data;
struct siw_qp *qp;
struct siw_qp_attrs qp_attrs;
- int rv, max_priv_data = MPA_MAX_PRIVDATA;
+ int rv = -EINVAL, max_priv_data = MPA_MAX_PRIVDATA;
bool wait_for_peer_rts = false;
siw_cep_set_inuse(cep);
@@ -1570,24 +1570,17 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
if (cep->state != SIW_EPSTATE_RECVD_MPAREQ) {
siw_dbg_cep(cep, "out of state\n");
-
- siw_cep_set_free_and_put(cep);
-
- return -ECONNRESET;
+ rv = -ECONNRESET;
+ goto free_cep;
}
qp = siw_qp_id2obj(sdev, params->qpn);
if (!qp) {
WARN(1, "[QP %d] does not exist\n", params->qpn);
- siw_cep_set_free_and_put(cep);
-
- return -EINVAL;
+ goto free_cep;
}
down_write(&qp->state_lock);
- if (qp->attrs.state > SIW_QP_STATE_RTR) {
- rv = -EINVAL;
- up_write(&qp->state_lock);
- goto error;
- }
+ if (qp->attrs.state > SIW_QP_STATE_RTR)
+ goto error_unlock;
siw_dbg_cep(cep, "[QP %d]\n", params->qpn);
if (try_gso && cep->mpa.hdr.params.bits & MPA_RR_FLAG_GSO_EXP) {
@@ -1601,9 +1594,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
"[QP %u]: ord %d (max %d), ird %d (max %d)\n",
qp_id(qp), params->ord, sdev->attrs.max_ord,
params->ird, sdev->attrs.max_ird);
- rv = -EINVAL;
- up_write(&qp->state_lock);
- goto error;
+ goto error_unlock;
}
if (cep->enhanced_rdma_conn_est)
max_priv_data -= sizeof(struct mpa_v2_data);
@@ -1613,9 +1604,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
cep,
"[QP %u]: private data length: %d (max %d)\n",
qp_id(qp), params->private_data_len, max_priv_data);
- rv = -EINVAL;
- up_write(&qp->state_lock);
- goto error;
+ goto error_unlock;
}
if (cep->enhanced_rdma_conn_est) {
if (params->ord > cep->ord) {
@@ -1624,9 +1613,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
} else {
cep->ird = params->ird;
cep->ord = params->ord;
- rv = -EINVAL;
- up_write(&qp->state_lock);
- goto error;
+ goto error_unlock;
}
}
if (params->ird < cep->ird) {
@@ -1635,8 +1622,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
params->ird = cep->ird;
else {
rv = -ENOMEM;
- up_write(&qp->state_lock);
- goto error;
+ goto error_unlock;
}
}
if (cep->mpa.v2_ctrl.ord &
@@ -1683,7 +1669,6 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
SIW_QP_ATTR_ORD | SIW_QP_ATTR_IRD |
SIW_QP_ATTR_MPA);
up_write(&qp->state_lock);
-
if (rv)
goto error;
@@ -1706,6 +1691,9 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
siw_cep_set_free(cep);
return 0;
+
+error_unlock:
+ up_write(&qp->state_lock);
error:
siw_socket_disassoc(cep->sock);
sock_release(cep->sock);
@@ -1720,9 +1708,8 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
}
cep->qp = NULL;
siw_qp_put(qp);
-
+free_cep:
siw_cep_set_free_and_put(cep);
-
return rv;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 596/982] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (594 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 595/982] RDMA/siw: Cleanup siw_accept Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 597/982] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
` (392 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Guoqing Jiang,
Bernard Metzler, Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoqing Jiang <guoqing.jiang@linux.dev>
[ Upstream commit 32cd87f54dd1070020e664ccb0312a9f0fea79b4 ]
We need to clear cep before release state_lock as siw_qp_llp_close and
siw_qp_modify->siw_qp_llp_close did.
Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock
is released before the error path cleanup. A concurrent ibv_modify_qp()
transitioning the QP to ERROR can race in this window:
siw_accept() ibv_modify_qp(ERROR)
---------------------- ----------------------
siw_qp_modify() fails
up_write(&qp->state_lock)
down_write(&qp->state_lock)
nextstate_from_idle():
if (qp->cep)
siw_cep_put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw_cep_get(),
all under the write lock held from the initial down_write(&qp->state_lock).
Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free
the cep before siw_accept() is done with it.
Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://lore.kernel.org/linux-rdma/d6fbe475-a5c2-f975-99b0-a0bd6b6d10e8@linux.dev/T/#m5876c1ff2de8686a9a1173b8f1aa0ff5363a785c
Signed-off-by: Guoqing Jiang <guoqing.jiang@linux.dev>
Link: https://patch.msgid.link/20260827125553.12831-1-guoqing.jiang@linux.dev
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index 629ed5e58473d..19932fc8856d7 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -1668,9 +1668,12 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
SIW_QP_ATTR_STATE | SIW_QP_ATTR_LLP_HANDLE |
SIW_QP_ATTR_ORD | SIW_QP_ATTR_IRD |
SIW_QP_ATTR_MPA);
+ if (rv) {
+ qp->cep = NULL;
+ siw_cep_put(cep);
+ goto error_unlock;
+ }
up_write(&qp->state_lock);
- if (rv)
- goto error;
siw_dbg_cep(cep, "[QP %u]: send mpa reply, %d byte pdata\n",
qp_id(qp), params->private_data_len);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 597/982] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (595 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 596/982] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 598/982] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
` (391 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 32471d84a487c7fd74532bc96be56f8028cf4a3f ]
scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted
any larger value from the SCP firmware. The shared-memory reply only holds
MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array
and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB).
The missing upper bound dates back to the original SCPI DVFS support.
Reject zero and out-of-range counts in one check and return -EINVAL.
Fixes: 8cb7cf56c9fe ("firmware: add support for ARM System Control and Power Interface(SCPI) protocol")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/022802f0b38f.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scpi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scpi.c b/drivers/firmware/arm_scpi.c
index 2d85e783ae267..aa27eb5278520 100644
--- a/drivers/firmware/arm_scpi.c
+++ b/drivers/firmware/arm_scpi.c
@@ -628,8 +628,8 @@ static struct scpi_dvfs_info *scpi_dvfs_get_info(u8 domain)
if (ret)
return ERR_PTR(ret);
- if (!buf.opp_count)
- return ERR_PTR(-ENOENT);
+ if (!buf.opp_count || buf.opp_count > MAX_DVFS_OPPS)
+ return ERR_PTR(-EINVAL);
info = kmalloc(sizeof(*info), GFP_KERNEL);
if (!info)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 598/982] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (596 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 597/982] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 599/982] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
` (390 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 70f4b78d560e592cbf3325b162424737d032fc1d ]
dvfs_get_idx() may return an out-of-range index if the SCP firmware is
buggy or returns a stale value. Only negative indexes were rejected, so a
large index walked past info->opps and could treat garbage as a clock rate
(KASAN OOB / wrong frequency to consumers). The missing upper bound dates
back to the original SCPI clock driver.
Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Fixes: cd52c2a4b5c4 ("clk: add support for clocks provided by SCP(System Control Processor)")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/04f9ab766e07.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-scpi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/clk-scpi.c b/drivers/clk/clk-scpi.c
index a39af7616b13c..c019b9ee4865e 100644
--- a/drivers/clk/clk-scpi.c
+++ b/drivers/clk/clk-scpi.c
@@ -86,7 +86,7 @@ static unsigned long scpi_dvfs_recalc_rate(struct clk_hw *hw,
int idx = clk->scpi_ops->dvfs_get_idx(clk->id);
const struct scpi_opp *opp;
- if (idx < 0)
+ if (idx < 0 || idx >= clk->info->count)
return 0;
opp = clk->info->opps + idx;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 599/982] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (597 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 598/982] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 600/982] net: devlink: convert devlink port type-specific pointers to union Greg Kroah-Hartman
` (389 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 1caceeb2d74bbe88223aea55eb8626b4c5f076fd ]
rxe_get_mcg() publishes a newly allocated multicast group in
rxe->mcg_tree before programming the backing Ethernet multicast address
with rxe_mcast_add(), which runs outside mcg_lock. A local userspace
RDMA client reaches this path with ATTACH_MCAST on a UD QP; if
rxe_mcast_add() then returns an error (for example -ENODEV when the
backing netdev has been removed, or a propagated dev_mc_add() error),
the unwind frees the published group without removing it from the tree.
A later lookup of the same MGID dereferences the freed struct rxe_mcg
from __rxe_lookup_mcg().
Fix this by keeping the new mcg private until rxe_mcast_add() succeeds.
Split the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()
before taking the tree reference, and free the still-private mcg on
failure. Because the group is never visible in mcg_tree until the
multicast address is programmed, no concurrent caller can look it up or
attach a QP to a group that is about to be torn down, so the error path
needs no conditional unwind. If another caller publishes the same MGID
while the address is being programmed, the post-add re-check under
mcg_lock finds the winner; this caller then drops its private object and
balances its own rxe_mcast_add() with rxe_mcast_del() before returning
the winner.
Reproduced by forcing the rxe_mcast_add() error return under KASAN:
without the change the next attach to the same MGID reports a
slab-use-after-free in __rxe_lookup_mcg(); with it the forced failure
returns cleanly. A no-injection attach/detach regression, including a
two-QP shared join/leave and re-attach, stays KASAN- and leak-clean.
Fixes: a926a903b7dc ("RDMA/rxe: Do not call dev_mc_add/del() under a spinlock")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260617022728.2770116-1-michael.bommarito@gmail.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +++++++++++++++++++--------
1 file changed, 36 insertions(+), 14 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mcast.c b/drivers/infiniband/sw/rxe/rxe_mcast.c
index 86cc2e18a7fda..55e78d4c83960 100644
--- a/drivers/infiniband/sw/rxe/rxe_mcast.c
+++ b/drivers/infiniband/sw/rxe/rxe_mcast.c
@@ -157,7 +157,9 @@ struct rxe_mcg *rxe_lookup_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
* @mgid: multicast address as a gid
* @mcg: new mcg object
*
- * Context: caller should hold rxe->mcg lock
+ * Initializes the mcg fields. The mcg is private and not yet visible in
+ * mcg_tree, so this may run without rxe->mcg_lock; __rxe_publish_mcg()
+ * makes it visible under the lock once it is ready.
*/
static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
struct rxe_mcg *mcg)
@@ -166,13 +168,22 @@ static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
memcpy(&mcg->mgid, mgid, sizeof(mcg->mgid));
INIT_LIST_HEAD(&mcg->qp_list);
mcg->rxe = rxe;
+}
- /* caller holds a ref on mcg but that will be
- * dropped when mcg goes out of scope. We need to take a ref
- * on the pointer that will be saved in the red-black tree
- * by __rxe_insert_mcg and used to lookup mcg from mgid later.
- * Inserting mcg makes it visible to outside so this should
- * be done last after the object is ready.
+/**
+ * __rxe_publish_mcg - make a fully initialized mcg visible in mcg_tree
+ * @mcg: the mcg object
+ *
+ * Context: caller must hold rxe->mcg_lock and a reference on mcg
+ */
+static void __rxe_publish_mcg(struct rxe_mcg *mcg)
+{
+ /* caller holds a ref on mcg but that will be dropped when mcg goes
+ * out of scope. We need to take a ref on the pointer that will be
+ * saved in the red-black tree by __rxe_insert_mcg and used to lookup
+ * mcg from mgid later. Inserting mcg makes it visible to outside so
+ * this is done last after the object is ready and the multicast
+ * address has been programmed.
*/
kref_get(&mcg->ref_cnt);
__rxe_insert_mcg(mcg);
@@ -210,26 +221,37 @@ static struct rxe_mcg *rxe_get_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
err = -ENOMEM;
goto err_dec;
}
+ __rxe_init_mcg(rxe, mgid, mcg);
+
+ /* program the multicast address while mcg is still private, before
+ * it is inserted into mcg_tree. dev_mc_add() may sleep so this must
+ * run outside mcg_lock. On failure mcg was never published, so a
+ * plain free is correct and the tree is untouched.
+ */
+ err = rxe_mcast_add(rxe, mgid);
+ if (err) {
+ kfree(mcg);
+ goto err_dec;
+ }
spin_lock_bh(&rxe->mcg_lock);
- /* re-check to see if someone else just added it */
+ /* re-check to see if someone else just added it while we were adding
+ * the multicast address; if so use theirs and drop ours
+ */
tmp = __rxe_lookup_mcg(rxe, mgid);
if (tmp) {
spin_unlock_bh(&rxe->mcg_lock);
+ rxe_mcast_del(rxe, mgid);
atomic_dec(&rxe->mcg_num);
kfree(mcg);
return tmp;
}
- __rxe_init_mcg(rxe, mgid, mcg);
+ __rxe_publish_mcg(mcg);
spin_unlock_bh(&rxe->mcg_lock);
- /* add mcast address outside of lock */
- err = rxe_mcast_add(rxe, mgid);
- if (!err)
- return mcg;
+ return mcg;
- kfree(mcg);
err_dec:
atomic_dec(&rxe->mcg_num);
return ERR_PTR(err);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 600/982] net: devlink: convert devlink port type-specific pointers to union
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (598 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 599/982] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 601/982] net: devlink: move port_type_warn_schedule() call to __devlink_port_type_set() Greg Kroah-Hartman
` (388 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Pirko, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Pirko <jiri@nvidia.com>
[ Upstream commit 3830c5719af66fac9849cf5fb04b03d4e4bb46ff ]
Instead of storing type_dev as a void pointer, convert it to union and
use it to store either struct net_device or struct ib_device pointer.
Signed-off-by: Jiri Pirko <jiri@nvidia.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: ef9fbe1b93f3 ("RDMA/core: Reject unregistering netdevs in ib_get_eth_speed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/devlink.h | 13 ++++++++++---
net/devlink/leftover.c | 17 +++++++++++++----
2 files changed, 23 insertions(+), 7 deletions(-)
diff --git a/include/net/devlink.h b/include/net/devlink.h
index ba6b8b0949432..6c55aabaedf19 100644
--- a/include/net/devlink.h
+++ b/include/net/devlink.h
@@ -121,12 +121,19 @@ struct devlink_port {
struct list_head region_list;
struct devlink *devlink;
unsigned int index;
- spinlock_t type_lock; /* Protects type and type_dev
- * pointer consistency.
+ spinlock_t type_lock; /* Protects type and type_eth/ib
+ * structures consistency.
*/
enum devlink_port_type type;
enum devlink_port_type desired_type;
- void *type_dev;
+ union {
+ struct {
+ struct net_device *netdev;
+ } type_eth;
+ struct {
+ struct ib_device *ibdev;
+ } type_ib;
+ };
struct devlink_port_attrs attrs;
u8 attrs_set:1,
switch_port:1,
diff --git a/net/devlink/leftover.c b/net/devlink/leftover.c
index 1ea84c5ffa9f1..d9e13f1836bb6 100644
--- a/net/devlink/leftover.c
+++ b/net/devlink/leftover.c
@@ -1283,7 +1283,7 @@ static int devlink_nl_port_fill(struct sk_buff *msg,
goto nla_put_failure_type_locked;
if (devlink_port->type == DEVLINK_PORT_TYPE_ETH) {
struct net *net = devlink_net(devlink_port->devlink);
- struct net_device *netdev = devlink_port->type_dev;
+ struct net_device *netdev = devlink_port->type_eth.netdev;
if (netdev && net_eq(net, dev_net(netdev)) &&
(nla_put_u32(msg, DEVLINK_ATTR_PORT_NETDEV_IFINDEX,
@@ -1293,7 +1293,7 @@ static int devlink_nl_port_fill(struct sk_buff *msg,
goto nla_put_failure_type_locked;
}
if (devlink_port->type == DEVLINK_PORT_TYPE_IB) {
- struct ib_device *ibdev = devlink_port->type_dev;
+ struct ib_device *ibdev = devlink_port->type_ib.ibdev;
if (ibdev &&
nla_put_string(msg, DEVLINK_ATTR_PORT_IBDEV_NAME,
@@ -9992,7 +9992,16 @@ static void __devlink_port_type_set(struct devlink_port *devlink_port,
devlink_port_type_warn_cancel(devlink_port);
spin_lock_bh(&devlink_port->type_lock);
devlink_port->type = type;
- devlink_port->type_dev = type_dev;
+ switch (type) {
+ case DEVLINK_PORT_TYPE_ETH:
+ devlink_port->type_eth.netdev = type_dev;
+ break;
+ case DEVLINK_PORT_TYPE_IB:
+ devlink_port->type_ib.ibdev = type_dev;
+ break;
+ default:
+ break;
+ }
spin_unlock_bh(&devlink_port->type_lock);
devlink_port_notify(devlink_port, DEVLINK_CMD_PORT_NEW);
}
@@ -12009,7 +12018,7 @@ devlink_trap_report_metadata_set(struct devlink_trap_metadata *metadata,
spin_lock(&in_devlink_port->type_lock);
if (in_devlink_port->type == DEVLINK_PORT_TYPE_ETH)
- metadata->input_dev = in_devlink_port->type_dev;
+ metadata->input_dev = in_devlink_port->type_eth.netdev;
spin_unlock(&in_devlink_port->type_lock);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 601/982] net: devlink: move port_type_warn_schedule() call to __devlink_port_type_set()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (599 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 600/982] net: devlink: convert devlink port type-specific pointers to union Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 602/982] net: devlink: move port_type_netdev_checks() " Greg Kroah-Hartman
` (387 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Pirko, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Pirko <jiri@nvidia.com>
[ Upstream commit 8573a04404ddacb2d966eef09bf38b2ad6dbe86f ]
As __devlink_port_type_set() is going to be called directly from netdevice
notifier event handle in one of the follow-up patches, move the
port_type_warn_schedule() call there.
Signed-off-by: Jiri Pirko <jiri@nvidia.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: ef9fbe1b93f3 ("RDMA/core: Reject unregistering netdevs in ib_get_eth_speed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/devlink/leftover.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/devlink/leftover.c b/net/devlink/leftover.c
index d9e13f1836bb6..ab9a8534904ce 100644
--- a/net/devlink/leftover.c
+++ b/net/devlink/leftover.c
@@ -9989,7 +9989,11 @@ static void __devlink_port_type_set(struct devlink_port *devlink_port,
{
ASSERT_DEVLINK_PORT_REGISTERED(devlink_port);
- devlink_port_type_warn_cancel(devlink_port);
+ if (type == DEVLINK_PORT_TYPE_NOTSET)
+ devlink_port_type_warn_schedule(devlink_port);
+ else
+ devlink_port_type_warn_cancel(devlink_port);
+
spin_lock_bh(&devlink_port->type_lock);
devlink_port->type = type;
switch (type) {
@@ -10084,7 +10088,6 @@ EXPORT_SYMBOL_GPL(devlink_port_type_ib_set);
void devlink_port_type_clear(struct devlink_port *devlink_port)
{
__devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_NOTSET, NULL);
- devlink_port_type_warn_schedule(devlink_port);
}
EXPORT_SYMBOL_GPL(devlink_port_type_clear);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 602/982] net: devlink: move port_type_netdev_checks() call to __devlink_port_type_set()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (600 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 601/982] net: devlink: move port_type_warn_schedule() call to __devlink_port_type_set() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 603/982] net: devlink: take RTNL in port_fill() function only if it is not held Greg Kroah-Hartman
` (386 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Pirko, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Pirko <jiri@nvidia.com>
[ Upstream commit 45791e0d00c445936bb19535fe847083b1edd26d ]
As __devlink_port_type_set() is going to be called directly from netdevice
notifier event handle in one of the follow-up patches, move the
port_type_netdev_checks() call there.
Signed-off-by: Jiri Pirko <jiri@nvidia.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: ef9fbe1b93f3 ("RDMA/core: Reject unregistering netdevs in ib_get_eth_speed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/devlink/leftover.c | 63 ++++++++++++++++++++++--------------------
1 file changed, 33 insertions(+), 30 deletions(-)
diff --git a/net/devlink/leftover.c b/net/devlink/leftover.c
index ab9a8534904ce..6f79af84d1a3a 100644
--- a/net/devlink/leftover.c
+++ b/net/devlink/leftover.c
@@ -9983,33 +9983,6 @@ void devlink_port_unregister(struct devlink_port *devlink_port)
}
EXPORT_SYMBOL_GPL(devlink_port_unregister);
-static void __devlink_port_type_set(struct devlink_port *devlink_port,
- enum devlink_port_type type,
- void *type_dev)
-{
- ASSERT_DEVLINK_PORT_REGISTERED(devlink_port);
-
- if (type == DEVLINK_PORT_TYPE_NOTSET)
- devlink_port_type_warn_schedule(devlink_port);
- else
- devlink_port_type_warn_cancel(devlink_port);
-
- spin_lock_bh(&devlink_port->type_lock);
- devlink_port->type = type;
- switch (type) {
- case DEVLINK_PORT_TYPE_ETH:
- devlink_port->type_eth.netdev = type_dev;
- break;
- case DEVLINK_PORT_TYPE_IB:
- devlink_port->type_ib.ibdev = type_dev;
- break;
- default:
- break;
- }
- spin_unlock_bh(&devlink_port->type_lock);
- devlink_port_notify(devlink_port, DEVLINK_CMD_PORT_NEW);
-}
-
static void devlink_port_type_netdev_checks(struct devlink_port *devlink_port,
struct net_device *netdev)
{
@@ -10047,6 +10020,38 @@ static void devlink_port_type_netdev_checks(struct devlink_port *devlink_port,
}
}
+static void __devlink_port_type_set(struct devlink_port *devlink_port,
+ enum devlink_port_type type,
+ void *type_dev)
+{
+ struct net_device *netdev = type_dev;
+
+ ASSERT_DEVLINK_PORT_REGISTERED(devlink_port);
+
+ if (type == DEVLINK_PORT_TYPE_NOTSET) {
+ devlink_port_type_warn_schedule(devlink_port);
+ } else {
+ devlink_port_type_warn_cancel(devlink_port);
+ if (type == DEVLINK_PORT_TYPE_ETH && netdev)
+ devlink_port_type_netdev_checks(devlink_port, netdev);
+ }
+
+ spin_lock_bh(&devlink_port->type_lock);
+ devlink_port->type = type;
+ switch (type) {
+ case DEVLINK_PORT_TYPE_ETH:
+ devlink_port->type_eth.netdev = netdev;
+ break;
+ case DEVLINK_PORT_TYPE_IB:
+ devlink_port->type_ib.ibdev = type_dev;
+ break;
+ default:
+ break;
+ }
+ spin_unlock_bh(&devlink_port->type_lock);
+ devlink_port_notify(devlink_port, DEVLINK_CMD_PORT_NEW);
+}
+
/**
* devlink_port_type_eth_set - Set port type to Ethernet
*
@@ -10056,9 +10061,7 @@ static void devlink_port_type_netdev_checks(struct devlink_port *devlink_port,
void devlink_port_type_eth_set(struct devlink_port *devlink_port,
struct net_device *netdev)
{
- if (netdev)
- devlink_port_type_netdev_checks(devlink_port, netdev);
- else
+ if (!netdev)
dev_warn(devlink_port->devlink->dev,
"devlink port type for port %d set to Ethernet without a software interface reference, device type not supported by the kernel?\n",
devlink_port->index);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 603/982] net: devlink: take RTNL in port_fill() function only if it is not held
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (601 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 602/982] net: devlink: move port_type_netdev_checks() " Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 604/982] net: convert dev->reg_state to u8 Greg Kroah-Hartman
` (385 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Pirko, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Pirko <jiri@nvidia.com>
[ Upstream commit d41c9dbd12745cfc1cb2946cd99016d83c2c5364 ]
Follow-up patch is going to introduce a netdevice notifier event
processing which is called with RTNL mutex held. Processing of this will
eventually lead to call to port_notity() and port_fill() which currently
takes RTNL mutex internally. So as a temporary solution, propagate a
bool indicating if the mutex is already held. This will go away in one
of the follow-up patches.
Signed-off-by: Jiri Pirko <jiri@nvidia.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: ef9fbe1b93f3 ("RDMA/core: Reject unregistering netdevs in ib_get_eth_speed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/devlink/leftover.c | 46 ++++++++++++++++++++++++++++--------------
1 file changed, 31 insertions(+), 15 deletions(-)
diff --git a/net/devlink/leftover.c b/net/devlink/leftover.c
index 6f79af84d1a3a..568e4efd8868a 100644
--- a/net/devlink/leftover.c
+++ b/net/devlink/leftover.c
@@ -1258,7 +1258,8 @@ devlink_nl_port_function_attrs_put(struct sk_buff *msg, struct devlink_port *por
static int devlink_nl_port_fill(struct sk_buff *msg,
struct devlink_port *devlink_port,
enum devlink_command cmd, u32 portid, u32 seq,
- int flags, struct netlink_ext_ack *extack)
+ int flags, struct netlink_ext_ack *extack,
+ bool rtnl_held)
{
struct devlink *devlink = devlink_port->devlink;
void *hdr;
@@ -1273,7 +1274,8 @@ static int devlink_nl_port_fill(struct sk_buff *msg,
goto nla_put_failure;
/* Hold rtnl lock while accessing port's netdev attributes. */
- rtnl_lock();
+ if (!rtnl_held)
+ rtnl_lock();
spin_lock_bh(&devlink_port->type_lock);
if (nla_put_u16(msg, DEVLINK_ATTR_PORT_TYPE, devlink_port->type))
goto nla_put_failure_type_locked;
@@ -1301,7 +1303,8 @@ static int devlink_nl_port_fill(struct sk_buff *msg,
goto nla_put_failure_type_locked;
}
spin_unlock_bh(&devlink_port->type_lock);
- rtnl_unlock();
+ if (!rtnl_held)
+ rtnl_unlock();
if (devlink_nl_port_attrs_put(msg, devlink_port))
goto nla_put_failure;
if (devlink_nl_port_function_attrs_put(msg, devlink_port, extack))
@@ -1316,14 +1319,15 @@ static int devlink_nl_port_fill(struct sk_buff *msg,
nla_put_failure_type_locked:
spin_unlock_bh(&devlink_port->type_lock);
- rtnl_unlock();
+ if (!rtnl_held)
+ rtnl_unlock();
nla_put_failure:
genlmsg_cancel(msg, hdr);
return -EMSGSIZE;
}
-static void devlink_port_notify(struct devlink_port *devlink_port,
- enum devlink_command cmd)
+static void __devlink_port_notify(struct devlink_port *devlink_port,
+ enum devlink_command cmd, bool rtnl_held)
{
struct devlink *devlink = devlink_port->devlink;
struct sk_buff *msg;
@@ -1338,7 +1342,8 @@ static void devlink_port_notify(struct devlink_port *devlink_port,
if (!msg)
return;
- err = devlink_nl_port_fill(msg, devlink_port, cmd, 0, 0, 0, NULL);
+ err = devlink_nl_port_fill(msg, devlink_port, cmd, 0, 0, 0, NULL,
+ rtnl_held);
if (err) {
nlmsg_free(msg);
return;
@@ -1348,6 +1353,12 @@ static void devlink_port_notify(struct devlink_port *devlink_port,
0, DEVLINK_MCGRP_CONFIG, GFP_KERNEL);
}
+static void devlink_port_notify(struct devlink_port *devlink_port,
+ enum devlink_command cmd)
+{
+ __devlink_port_notify(devlink_port, cmd, false);
+}
+
static void devlink_rate_notify(struct devlink_rate *devlink_rate,
enum devlink_command cmd)
{
@@ -1514,7 +1525,7 @@ static int devlink_nl_cmd_port_get_doit(struct sk_buff *skb,
err = devlink_nl_port_fill(msg, devlink_port, DEVLINK_CMD_PORT_NEW,
info->snd_portid, info->snd_seq, 0,
- info->extack);
+ info->extack, false);
if (err) {
nlmsg_free(msg);
return err;
@@ -1544,7 +1555,8 @@ static int devlink_nl_cmd_port_get_dumpit(struct sk_buff *msg,
DEVLINK_CMD_NEW,
NETLINK_CB(cb->skb).portid,
cb->nlh->nlmsg_seq,
- NLM_F_MULTI, cb->extack);
+ NLM_F_MULTI, cb->extack,
+ false);
if (err) {
devl_unlock(devlink);
devlink_put(devlink);
@@ -1756,7 +1768,8 @@ static int devlink_port_new_notify(struct devlink *devlink,
}
err = devlink_nl_port_fill(msg, devlink_port, DEVLINK_CMD_NEW,
- info->snd_portid, info->snd_seq, 0, NULL);
+ info->snd_portid, info->snd_seq, 0, NULL,
+ false);
if (err)
goto out;
@@ -10022,7 +10035,7 @@ static void devlink_port_type_netdev_checks(struct devlink_port *devlink_port,
static void __devlink_port_type_set(struct devlink_port *devlink_port,
enum devlink_port_type type,
- void *type_dev)
+ void *type_dev, bool rtnl_held)
{
struct net_device *netdev = type_dev;
@@ -10049,7 +10062,7 @@ static void __devlink_port_type_set(struct devlink_port *devlink_port,
break;
}
spin_unlock_bh(&devlink_port->type_lock);
- devlink_port_notify(devlink_port, DEVLINK_CMD_PORT_NEW);
+ __devlink_port_notify(devlink_port, DEVLINK_CMD_PORT_NEW, rtnl_held);
}
/**
@@ -10066,7 +10079,8 @@ void devlink_port_type_eth_set(struct devlink_port *devlink_port,
"devlink port type for port %d set to Ethernet without a software interface reference, device type not supported by the kernel?\n",
devlink_port->index);
- __devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_ETH, netdev);
+ __devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_ETH, netdev,
+ false);
}
EXPORT_SYMBOL_GPL(devlink_port_type_eth_set);
@@ -10079,7 +10093,8 @@ EXPORT_SYMBOL_GPL(devlink_port_type_eth_set);
void devlink_port_type_ib_set(struct devlink_port *devlink_port,
struct ib_device *ibdev)
{
- __devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_IB, ibdev);
+ __devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_IB, ibdev,
+ false);
}
EXPORT_SYMBOL_GPL(devlink_port_type_ib_set);
@@ -10090,7 +10105,8 @@ EXPORT_SYMBOL_GPL(devlink_port_type_ib_set);
*/
void devlink_port_type_clear(struct devlink_port *devlink_port)
{
- __devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_NOTSET, NULL);
+ __devlink_port_type_set(devlink_port, DEVLINK_PORT_TYPE_NOTSET, NULL,
+ false);
}
EXPORT_SYMBOL_GPL(devlink_port_type_clear);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 604/982] net: convert dev->reg_state to u8
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (602 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 603/982] net: devlink: take RTNL in port_fill() function only if it is not held Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 605/982] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
` (384 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, David S. Miller,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 4d42b37def70327b2bb19f823d42289aed2cd7c7 ]
Prepares things so that dev->reg_state reads can be lockless,
by adding WRITE_ONCE() on write side.
READ_ONCE()/WRITE_ONCE() do not support bitfields.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: ef9fbe1b93f3 ("RDMA/core: Reject unregistering netdevs in ib_get_eth_speed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/netdevice.h | 23 ++++++++++++++---------
net/core/dev.c | 8 ++++----
2 files changed, 18 insertions(+), 13 deletions(-)
diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index 37c1109bf1543..e97967ca27601 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -1756,6 +1756,15 @@ enum netdev_stat_type {
NETDEV_PCPU_STAT_DSTATS, /* struct pcpu_dstats */
};
+enum netdev_reg_state {
+ NETREG_UNINITIALIZED = 0,
+ NETREG_REGISTERED, /* completed register_netdevice */
+ NETREG_UNREGISTERING, /* called unregister_netdevice */
+ NETREG_UNREGISTERED, /* completed unregister todo */
+ NETREG_RELEASED, /* called free_netdev */
+ NETREG_DUMMY, /* dummy device for NAPI poll */
+};
+
/**
* struct net_device - The DEVICE structure.
*
@@ -2272,13 +2281,7 @@ struct net_device {
struct list_head link_watch_list;
- enum { NETREG_UNINITIALIZED=0,
- NETREG_REGISTERED, /* completed register_netdevice */
- NETREG_UNREGISTERING, /* called unregister_netdevice */
- NETREG_UNREGISTERED, /* completed unregister todo */
- NETREG_RELEASED, /* called free_netdev */
- NETREG_DUMMY, /* dummy device for NAPI poll */
- } reg_state:8;
+ u8 reg_state;
bool dismantle;
@@ -5169,7 +5172,9 @@ static inline bool netdev_unregistering(const struct net_device *dev)
static inline const char *netdev_reg_state(const struct net_device *dev)
{
- switch (dev->reg_state) {
+ u8 reg_state = READ_ONCE(dev->reg_state);
+
+ switch (reg_state) {
case NETREG_UNINITIALIZED: return " (uninitialized)";
case NETREG_REGISTERED: return "";
case NETREG_UNREGISTERING: return " (unregistering)";
@@ -5178,7 +5183,7 @@ static inline const char *netdev_reg_state(const struct net_device *dev)
case NETREG_DUMMY: return " (dummy)";
}
- WARN_ONCE(1, "%s: unknown reg_state %d\n", dev->name, dev->reg_state);
+ WARN_ONCE(1, "%s: unknown reg_state %d\n", dev->name, reg_state);
return " (unknown)";
}
diff --git a/net/core/dev.c b/net/core/dev.c
index 270689c9f351a..1f5d42c726d8b 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -10242,7 +10242,7 @@ int register_netdevice(struct net_device *dev)
ret = netdev_register_kobject(dev);
write_lock(&dev_base_lock);
- dev->reg_state = ret ? NETREG_UNREGISTERED : NETREG_REGISTERED;
+ WRITE_ONCE(dev->reg_state, ret ? NETREG_UNREGISTERED : NETREG_REGISTERED);
write_unlock(&dev_base_lock);
if (ret)
goto err_free_pcpu;
@@ -10531,7 +10531,7 @@ void netdev_run_todo(void)
}
write_lock(&dev_base_lock);
- dev->reg_state = NETREG_UNREGISTERED;
+ WRITE_ONCE(dev->reg_state, NETREG_UNREGISTERED);
write_unlock(&dev_base_lock);
linkwatch_forget_dev(dev);
}
@@ -10911,7 +10911,7 @@ void free_netdev(struct net_device *dev)
}
BUG_ON(dev->reg_state != NETREG_UNREGISTERED);
- dev->reg_state = NETREG_RELEASED;
+ WRITE_ONCE(dev->reg_state, NETREG_RELEASED);
/* will free via device release */
put_device(&dev->dev);
@@ -11000,7 +11000,7 @@ void unregister_netdevice_many_notify(struct list_head *head,
/* And unlink it from device chain. */
write_lock(&dev_base_lock);
unlist_netdevice(dev, false);
- dev->reg_state = NETREG_UNREGISTERING;
+ WRITE_ONCE(dev->reg_state, NETREG_UNREGISTERING);
write_unlock(&dev_base_lock);
}
flush_all_backlogs();
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 605/982] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (603 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 604/982] net: convert dev->reg_state to u8 Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 606/982] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
` (383 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5fe14f2ff4ccbace9a26,
Krystian Kaniewski, Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krystian Kaniewski <krystianmkaniewski@gmail.com>
[ Upstream commit ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 ]
ib_device_get_netdev() intentionally returns a referenced net_device even
when it is unregistering, so matching and cleanup callers can still find
the association. The reference keeps struct net_device allocated, but does
not guarantee that the device remains operational.
ib_get_eth_speed() uses the returned device operationally by invoking its
ethtool callback. Although that call is made under RTNL, the function does
not verify the registration state first. An asynchronous RDMA port query
can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit
have completed.
Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a
device which is being unregistered. Keeping RTNL across the check and the
ethtool operation prevents unregister from starting between them.
Keep the speed fallback and warning under RTNL as well, so the warning can
safely read netdev->name. Drop the netdev reference before releasing RTNL
once all accesses to the device are complete.
Fixes: d41861942fc5 ("IB/core: Add generic function to extract IB speed from netdev")
Reported-by: syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5fe14f2ff4ccbace9a26
Signed-off-by: Krystian Kaniewski <krystianmkaniewski@gmail.com>
Link: https://patch.msgid.link/20260812081708.32468-1-krystianmkaniewski@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index 06e11b50336b2..66abeaaaa5aa5 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -1902,11 +1902,13 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
return -ENODEV;
rtnl_lock();
- rc = __ethtool_get_link_ksettings(netdev, &lksettings);
- rtnl_unlock();
-
- dev_put(netdev);
+ if (READ_ONCE(netdev->reg_state) != NETREG_REGISTERED) {
+ dev_put(netdev);
+ rtnl_unlock();
+ return -ENODEV;
+ }
+ rc = __ethtool_get_link_ksettings(netdev, &lksettings);
if (!rc && lksettings.base.speed != (u32)SPEED_UNKNOWN) {
netdev_speed = lksettings.base.speed;
} else {
@@ -1914,6 +1916,8 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
pr_warn("%s speed is unknown, defaulting to %u\n", netdev->name,
netdev_speed);
}
+ dev_put(netdev);
+ rtnl_unlock();
if (netdev_speed <= SPEED_1000) {
*width = IB_WIDTH_1X;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 606/982] IB/iser: reject a remote invalidation of an unregistered direction
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (604 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 605/982] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 607/982] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
` (382 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Max Gurtovoy,
Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit d85f0f0a7c85756fc992c70d869706f19dac9259 ]
A write command whose data is sent entirely as immediate data is not
registered. iser_reg_mem_fastreg() takes the DMA key path and leaves
rdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has
already set dir[ISER_DIR_OUT].
iser_check_remote_inv() looks at dir[] alone and hands the descriptor to
iser_inv_desc(), which reads desc->sig_protected. A target that answers
such a command with IB_WR_SEND_WITH_INV faults the initiator.
Leaving those commands unregistered is deliberate.
The same function already terminates the connection when a target sends
a remote invalidation the initiator did not ask for. A target that
invalidates a direction that was never registered is in the same class,
so give it the same answer.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: rxe_wq do_work
RIP: 0010:iser_task_rsp+0x6d6/0xec0
Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04
RSP: 0018:ffff88811b008db8 EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848
RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020
RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0
R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800
R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0
PKRU: 55555554
Call Trace:
<IRQ>
__ib_process_cq+0xe1/0x390
ib_poll_handler+0x6e/0x200
irq_poll_softirq+0x1df/0x480
? clockevents_program_event+0x2ba/0x860
? __pfx_irq_poll_softirq+0x10/0x10
handle_softirqs+0x18e/0x590
? __pfx_handle_softirqs+0x10/0x10
? __hrtimer_rearm_deferred+0x156/0x450
do_softirq+0x3b/0x60
</IRQ>
<TASK>
__local_bh_enable_ip+0x61/0x70
__alloc_skb+0x732/0x890
? _raw_spin_lock_irqsave+0x85/0xe0
? __pfx___alloc_skb+0x10/0x10
? _raw_read_unlock_irqrestore+0x16/0x50
rxe_init_packet+0x16b/0x4f0
prepare_ack_packet+0xb8/0x830
rxe_receiver+0x499/0x9980
? __pfx_rxe_receiver+0x10/0x10
? rxe_completer+0x29e5/0x38c0
? hrtimer_start_range_ns_common+0x75f/0x1730
? hrtimer_start_range_ns+0xa6/0x2c0
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? __pfx_rxe_receiver+0x10/0x10
do_work+0x144/0x470
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
Fixes: 59caaed7a72a ("IB/iser: Support the remote invalidation exception")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260819010804.641772-1-yhlee@isslab.korea.ac.kr
Reviewed-by: Max Gurtovoy <mgurtovoy@nvidia.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/ulp/iser/iser_initiator.c b/drivers/infiniband/ulp/iser/iser_initiator.c
index 8ec470c519e82..5d2c02d479751 100644
--- a/drivers/infiniband/ulp/iser/iser_initiator.c
+++ b/drivers/infiniband/ulp/iser/iser_initiator.c
@@ -598,11 +598,8 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
iser_dbg("conn %p: remote invalidation for rkey %#x\n",
iser_conn, rkey);
- if (unlikely(!iser_conn->snd_w_inv)) {
- iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
- iser_conn);
- return -EPROTO;
- }
+ if (unlikely(!iser_conn->snd_w_inv))
+ goto bad_inv;
task = iscsi_itt_to_ctask(iser_conn->iscsi_conn, hdr->itt);
if (likely(task)) {
@@ -611,12 +608,16 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
if (iser_task->dir[ISER_DIR_IN]) {
desc = iser_task->rdma_reg[ISER_DIR_IN].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
if (iser_task->dir[ISER_DIR_OUT]) {
desc = iser_task->rdma_reg[ISER_DIR_OUT].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
@@ -627,6 +628,11 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
}
return 0;
+
+bad_inv:
+ iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
+ iser_conn);
+ return -EPROTO;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 607/982] IB/isert: wait for deferred control PDU completions before releasing the connection
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (605 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 606/982] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 608/982] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
` (381 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f ]
isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and
ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work
item then runs isert_completion_put() -> isert_put_cmd(), which reads
isert_conn->conn and takes conn->cmd_lock.
Nothing orders that work item against teardown. isert_wait_conn() queues
isert_release_work, which frees isert_conn, and iscsit_close_connection()
frees the iscsit_conn right after it returns, so the queued work can run
against freed memory.
Count the deferred control PDU completions per connection and let
isert_wait_conn() wait for them before the release work is queued.
ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs
iscsit_logout_post_handler(), which ends up waiting for
conn->conn_wait_comp, and that completion is only sent by
iscsit_close_connection() after it has called iscsit_wait_conn().
Waiting for it here would deadlock. Its wait stays the existing
isert_wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200)
injected into isert_do_control_comp() to widen the window:
BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620
Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182
CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)
Tainted: [B]=BAD_PAGE
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: isert_comp_wq isert_do_control_comp
Call Trace:
<TASK>
dump_stack_lvl+0x53/0x70
print_report+0xd0/0x630
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? _raw_spin_unlock_irqrestore+0x3e/0x70
? isert_put_cmd+0x53d/0x620
kasan_report+0xce/0x100
? isert_put_cmd+0x53d/0x620
isert_put_cmd+0x53d/0x620
? isert_completion_put+0x305/0x330
? isert_do_control_comp+0x2ef/0x310
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 48:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x158/0x370
isert_cma_handler+0x1e3/0x2ae0
cma_cm_event_handler+0x3e/0x240
cma_ib_req_handler+0x17d9/0x4490
cm_process_work+0x41/0x330
cm_work_handler+0x5727/0xc160
process_one_work+0x633/0x1030
worker_thread+0x45b/0xd10
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Freed by task 184:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kfree+0x121/0x380
iscsit_close_connection+0x7cf/0x1e60
iscsit_take_action_for_connection_exit+0x1b6/0x360
iscsi_target_tx_thread+0x472/0x690
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260821080620.1694119-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 22 ++++++++++++++++++++++
drivers/infiniband/ulp/isert/ib_isert.h | 2 ++
2 files changed, 24 insertions(+)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index 6d969931ab8ff..2e474a5d30ff5 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -21,6 +21,7 @@
#include <target/target_core_fabric.h>
#include <target/iscsi/iscsi_transport.h>
#include <linux/semaphore.h>
+#include <linux/wait_bit.h>
#include "ib_isert.h"
@@ -314,6 +315,7 @@ isert_init_conn(struct isert_conn *isert_conn)
init_completion(&isert_conn->login_req_comp);
init_waitqueue_head(&isert_conn->rem_wait);
kref_init(&isert_conn->kref);
+ atomic_set(&isert_conn->ctrl_comp_cnt, 0);
mutex_init(&isert_conn->mutex);
INIT_WORK(&isert_conn->release_work, isert_release_work);
}
@@ -1701,6 +1703,8 @@ isert_do_control_comp(struct work_struct *work)
struct isert_conn *isert_conn = isert_cmd->conn;
struct ib_device *ib_dev = isert_conn->cm_id->device;
struct iscsit_cmd *cmd = isert_cmd->iscsit_cmd;
+ /* The switch below may free isert_cmd. */
+ bool counted = isert_cmd->ctrl_counted;
isert_dbg("Cmd %p i_state %d\n", isert_cmd, cmd->i_state);
@@ -1722,6 +1726,14 @@ isert_do_control_comp(struct work_struct *work)
dump_stack();
break;
}
+
+ /*
+ * The count is what keeps isert_conn alive, so drop it last. The wait
+ * queue lives in the global hash table, not in isert_conn, so this is
+ * safe even if the waiter has already freed the connection.
+ */
+ if (counted && atomic_dec_and_test(&isert_conn->ctrl_comp_cnt))
+ wake_up_var(&isert_conn->ctrl_comp_cnt);
}
static void
@@ -1765,6 +1777,12 @@ isert_send_done(struct ib_cq *cq, struct ib_wc *wc)
case ISTATE_SEND_TEXTRSP:
isert_unmap_tx_desc(tx_desc, ib_dev);
+ /* Paired with the wait in isert_wait_conn(). */
+ isert_cmd->ctrl_counted =
+ isert_cmd->iscsit_cmd->i_state != ISTATE_SEND_LOGOUTRSP;
+ if (isert_cmd->ctrl_counted)
+ atomic_inc(&isert_conn->ctrl_comp_cnt);
+
INIT_WORK(&isert_cmd->comp_work, isert_do_control_comp);
queue_work(isert_comp_wq, &isert_cmd->comp_work);
return;
@@ -2609,6 +2627,10 @@ static void isert_wait_conn(struct iscsit_conn *conn)
isert_wait4cmds(conn);
isert_wait4logout(isert_conn);
+ /* Paired with the count taken in isert_send_done(). */
+ wait_var_event(&isert_conn->ctrl_comp_cnt,
+ !atomic_read(&isert_conn->ctrl_comp_cnt));
+
queue_work(isert_release_wq, &isert_conn->release_work);
}
diff --git a/drivers/infiniband/ulp/isert/ib_isert.h b/drivers/infiniband/ulp/isert/ib_isert.h
index 0bac5aa66c802..519b17e54bd34 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.h
+++ b/drivers/infiniband/ulp/isert/ib_isert.h
@@ -153,6 +153,7 @@ struct isert_cmd {
struct work_struct comp_work;
struct scatterlist sg;
bool ctx_init_done;
+ bool ctrl_counted;
};
static inline struct isert_cmd *tx_desc_to_cmd(struct iser_tx_desc *desc)
@@ -187,6 +188,7 @@ struct isert_conn {
struct mutex mutex;
struct kref kref;
struct work_struct release_work;
+ atomic_t ctrl_comp_cnt;
bool logout_posted;
bool snd_w_inv;
wait_queue_head_t rem_wait;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 608/982] RDMA/mad: Fix receive buffer leak when PKey enforcement fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (606 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 607/982] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 609/982] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
` (380 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Leon Romanovsky,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 3476c28c9addfa253f505e6bd87f1f5598b961d0 ]
ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs
ib_mad_enforce_security() before linking recv_buf onto that list. On
failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees
the ib_mad_private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL
right after ib_mad_complete_recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv_buf onto rmpp_list right after the list is initialized, so the
error path has something to free.
Fixes: 47a2b338fe63 ("IB/core: Enforce security on management datagrams")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Link: https://patch.msgid.link/20260826073216.2367-1-lirongqing@baidu.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/mad.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/mad.c b/drivers/infiniband/core/mad.c
index bddb1c607aff6..4347b3af13119 100644
--- a/drivers/infiniband/core/mad.c
+++ b/drivers/infiniband/core/mad.c
@@ -1805,6 +1805,8 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
int ret;
INIT_LIST_HEAD(&mad_recv_wc->rmpp_list);
+ list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
+
ret = ib_mad_enforce_security(mad_agent_priv,
mad_recv_wc->wc->pkey_index);
if (ret) {
@@ -1813,7 +1815,6 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
return;
}
- list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
if (is_kernel_rmpp_data_response(mad_agent_priv, mad_recv_wc)) {
spin_lock_irqsave(&mad_agent_priv->lock, flags);
mad_send_wr = ib_find_send_mad(mad_agent_priv, mad_recv_wc);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 609/982] RDMA/irdma: Enforce local fence for IB_WR_REG_MR
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (607 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 608/982] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 610/982] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
` (379 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit 3fb905f07ea45b31c8f67ba6e4668de46f527e65 ]
Enforce local fence for IB_WR_REG_MR to avoid spurious
FASTREG_VALID_MKEY async events during heavy invalidation
and registration activity.
Commit 69e8e429bca2 ("RDMA/irdma: Enforce local fence for LOCAL_INV WRs")
was very similar, but was not sufficient to prevent all occurrences
of these async events.
Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260901160014.2026285-1-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 56e3103aa77f9..a8856a8613f45 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -3282,7 +3282,7 @@ static int irdma_post_send(struct ib_qp *ibqp,
stag_info.total_len = iwmr->ibmr.length;
stag_info.reg_addr_pa = *palloc->level1.addr;
stag_info.first_pm_pbl_index = palloc->level1.idx;
- stag_info.local_fence = ib_wr->send_flags & IB_SEND_FENCE;
+ stag_info.local_fence = true;
if (iwmr->npages > IRDMA_MIN_PAGES_PER_FMR)
stag_info.chunk_size = 1;
err = irdma_sc_mr_fast_register(&iwqp->sc_qp, &stag_info,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 610/982] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (608 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 609/982] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 611/982] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
` (378 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+d396918a29afb8543e1c,
Quanye Yang, Jack Wang, Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
[ Upstream commit 2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda ]
The client borrows shared CQ credits in the ADDR_RESOLVED handler via
ib_cq_pool_get(), before the peer is connected. create_cm() can return
-ERESTARTSYS from wait_event_interruptible_timeout() without destroying
the CM ID. The init_conns() and stop-and-destroy paths then call
destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards
rdma_destroy_id().
CMA serializes the handler against rdma_destroy_id() with handler_mutex,
but that does not order the GET against destroy_con_cq_qp(). If
ADDR_RESOLVED has already passed the DESTROYING check, it can take
con_mutex, GET credits, and then lose the con to kfree. Device
unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup().
Set a per-connection flag under con_mutex before CQ/QP teardown so a
racing ADDR_RESOLVED cannot borrow credits after teardown has begun.
Reported-by: syzbot+d396918a29afb8543e1c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d396918a29afb8543e1c
Fixes: 3b89e92c2a95 ("RDMA/rtrs: Use new shared CQ mechanism")
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260830-rdma-rtrs-clt-cq-pool-leak-v1-1-b169434fd3df@proton.me
Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 ++++++++
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 ++
2 files changed, 10 insertions(+)
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
index 905693c686413..6dadf9f20e8e9 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
@@ -1738,6 +1738,8 @@ static void destroy_con_cq_qp(struct rtrs_clt_con *con)
/*
* Be careful here: destroy_con_cq_qp() can be called even
* create_con_cq_qp() failed, see comments there.
+ * Caller must set con->destroyed under this lock first so a
+ * racing ADDR_RESOLVED cannot ib_cq_pool_get() after we PUT/SKIP.
*/
lockdep_assert_held(&con->con_mutex);
rtrs_cq_qp_destroy(&con->c);
@@ -1772,6 +1774,10 @@ static int rtrs_rdma_addr_resolved(struct rtrs_clt_con *con)
int err;
mutex_lock(&con->con_mutex);
+ if (con->destroyed) {
+ mutex_unlock(&con->con_mutex);
+ return -ECONNABORTED;
+ }
err = create_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
if (err) {
@@ -2202,6 +2208,7 @@ static void rtrs_clt_stop_and_destroy_conns(struct rtrs_clt_path *clt_path)
break;
con = to_clt_con(clt_path->s.con[cid]);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
@@ -2368,6 +2375,7 @@ static int init_conns(struct rtrs_clt_path *clt_path)
if (con->c.cm_id) {
stop_cm(con);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.h b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
index f848c0392d982..5ba486bfc7daa 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.h
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
@@ -75,6 +75,8 @@ struct rtrs_clt_con {
unsigned int cpu;
struct mutex con_mutex;
int cm_err;
+ /* Set under con_mutex before CQ/QP teardown. */
+ bool destroyed;
};
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 611/982] dmaengine: sprd: Fix runtime PM reference leak in probe
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (609 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 610/982] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 612/982] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
` (377 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Frank Li, Baolin Wang,
Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit a7df136ec529ee49a789c5029bc37b98b0d4bedd ]
pm_runtime_get_sync() increments a device's usage counter even when it
fails. sprd_dma_probe() currently jumps directly to controller clock
cleanup on that error, bypassing both pm_runtime_put_noidle() and
pm_runtime_disable(). This can happen if the preceding unchecked
pm_runtime_set_active() fails and the following runtime-resume attempt
also returns an error.
Enter the existing runtime-PM unwind path instead. This drops the
reference without idling the partially initialized device, disables
runtime PM, and then releases the controller clocks. The success path
and propagated error code are unchanged.
This issue was found by a static analysis checker and confirmed by manual
source review.
Fixes: 9b3b8171f7f4 ("dmaengine: sprd: Add Spreadtrum DMA driver")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Link: https://patch.msgid.link/20260813153149.3953497-1-ruoyuw560@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/sprd-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/dma/sprd-dma.c b/drivers/dma/sprd-dma.c
index 474d3ba8ec9f9..cb48e4d2640cd 100644
--- a/drivers/dma/sprd-dma.c
+++ b/drivers/dma/sprd-dma.c
@@ -1206,7 +1206,7 @@ static int sprd_dma_probe(struct platform_device *pdev)
ret = pm_runtime_get_sync(&pdev->dev);
if (ret < 0)
- goto err_rpm;
+ goto err_register;
ret = dma_async_device_register(&sdev->dma_dev);
if (ret < 0) {
@@ -1228,7 +1228,6 @@ static int sprd_dma_probe(struct platform_device *pdev)
err_register:
pm_runtime_put_noidle(&pdev->dev);
pm_runtime_disable(&pdev->dev);
-err_rpm:
sprd_dma_disable(sdev);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 612/982] wifi: virt_wifi: free skb when disconnected
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (610 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 611/982] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 613/982] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
` (376 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mariano Baragiola, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mariano Baragiola <mbaragiola@linux.com>
[ Upstream commit f9edf7cf63b96d2b776fca8d258d3c5256e40c8e ]
When the simulated link is disconnected, virt_wifi_start_xmit() returns
NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this
return value as consumed, so every packet sent while disconnected leaks its
skb.
Free the skb before returning the drop status.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Signed-off-by: Mariano Baragiola <mbaragiola@linux.com>
Link: https://patch.msgid.link/20260809124947.3590270-1-mbaragiola@linux.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virt_wifi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/virt_wifi.c b/drivers/net/wireless/virt_wifi.c
index eac4838807c74..474451e8b5e16 100644
--- a/drivers/net/wireless/virt_wifi.c
+++ b/drivers/net/wireless/virt_wifi.c
@@ -430,6 +430,7 @@ static netdev_tx_t virt_wifi_start_xmit(struct sk_buff *skb,
priv->tx_packets++;
if (!priv->is_connected) {
priv->tx_failed++;
+ dev_kfree_skb_any(skb);
return NET_XMIT_DROP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 613/982] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (611 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 612/982] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 614/982] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
` (375 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Hao, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peng Hao <flyingpenghao@gmail.com>
[ Upstream commit a3d722190cdef18da4878b5efc27c3c386dda248 ]
mwifiex_pcie_request_irq() registers each MSI-X vector with a per-index
dev_id (&card->msix_ctx[i]). On a request_irq() failure the cleanup loop
"for (j = 0; j < i; j++)" frees msix_entries[j].vector but passes the
failed index's &card->msix_ctx[i] as the dev_id. free_irq() matches on
(irq, dev_id), so it fails to find the action registered with
&card->msix_ctx[j]: the already-requested IRQ j is not freed (leaked) and
free_irq() warns about freeing a non-existent IRQ. Use &card->msix_ctx[j].
Fixes: 99074fc1e67b ("mwifiex: enable pcie MSIx interrupt mode support")
Signed-off-by: Peng Hao <flyingpeng@tencent.com>
Link: https://patch.msgid.link/20260828111531.56723-1-flyingpeng@tencent.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/marvell/mwifiex/pcie.c b/drivers/net/wireless/marvell/mwifiex/pcie.c
index 6697132ecc977..86419669c11bf 100644
--- a/drivers/net/wireless/marvell/mwifiex/pcie.c
+++ b/drivers/net/wireless/marvell/mwifiex/pcie.c
@@ -3241,7 +3241,7 @@ static int mwifiex_pcie_request_irq(struct mwifiex_adapter *adapter)
ret);
for (j = 0; j < i; j++)
free_irq(card->msix_entries[j].vector,
- &card->msix_ctx[i]);
+ &card->msix_ctx[j]);
pci_disable_msix(pdev);
} else {
mwifiex_dbg(adapter, MSG, "MSIx enabled!");
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 614/982] wifi: libipw: reject too-short beacon and probe responses
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (612 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 613/982] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 615/982] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
` (374 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit 5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b ]
libipw_process_probe_response() and the libipw_network_init() call it
makes assume the frame contains the full 36-byte beacon and probe
response prefix, but the ipw2100 and ipw2200 receive paths only
establish that a management frame carries the generic 24-byte
three-address header.
libipw_network_init() then computes the information element length as
stats->len - sizeof(*beacon)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() yields
65524 for a 24-byte beacon, and the parser then walks the receive
buffer as if it held almost 64 KiB of information elements, reading
past the allocation.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: b453872c35cf ("[NET] ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-2-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 2220a9814c8a6..33f5dbe274c74 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1514,6 +1514,9 @@ static void libipw_process_probe_response(struct libipw_device
#endif
unsigned long flags;
+ if (stats->len < sizeof(*beacon))
+ return;
+
LIBIPW_DEBUG_SCAN("'%*pE' (%pM): %c%c%c%c %c%c%c%c-%c%c%c%c %c%c%c%c\n",
info_element->len, info_element->data,
beacon->header.addr3,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 615/982] wifi: libipw: reject too-short association responses
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (613 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 614/982] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 616/982] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
` (373 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit adb7118b7d2cfd7e8213c17d7d2829f353017754 ]
libipw_handle_assoc_resp() reads the capability, status and aid fields
of the 30-byte association response prefix and then computes the
information element length as
stats->len - sizeof(*frame)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() turns a
frame shorter than the fixed fields into a length near 64 KiB, and the
parser then reads past the receive buffer.
Both the ipw2100 and ipw2200 management receive paths reach this
function having established only that the frame carries the generic
24-byte three-address header.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: 9e8571affd1c ("[PATCH] ieee80211: Add QoS (WME) support to the ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-3-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 33f5dbe274c74..762ed2704bf65 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1302,6 +1302,9 @@ static int libipw_handle_assoc_resp(struct libipw_device *ieee, struct libipw_as
struct libipw_network *network = &network_resp;
struct net_device *dev = ieee->dev;
+ if (stats->len < sizeof(*frame))
+ return 1;
+
network->flags = 0;
network->qos_data.active = 0;
network->qos_data.supported = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 616/982] IB/IPoIB: Avoid restoring OPER_UP after multicast flush
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (614 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 615/982] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 617/982] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
` (372 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ben Davies, Carolina Jubran,
Cosmin Ratiu, Edward Srouji, Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carolina Jubran <cjubran@nvidia.com>
[ Upstream commit 9a141d3dc869d18b2eab35e999f4790a9b84e40f ]
ipoib_ib_dev_flush_light() temporarily clears IPOIB_FLAG_OPER_UP to
prevent multicast joins while ipoib_mcast_dev_flush() is running, and
restores the flag afterwards if it was previously set.
This restore races with ipoib_ib_dev_down(). If the interface is brought
down while the flush is in progress, ipoib_ib_dev_down() clears
IPOIB_FLAG_OPER_UP, but the flush path may set it again after the device
has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier_on_task race
aware"), ipoib_mcast_carrier_on_task() relies on IPOIB_FLAG_OPER_UP
being cleared to terminate its rtnl_trylock() retry loop. If the flag is
left set after shutdown, the workqueue retries forever, causing teardown
to deadlock when ipoib_ndo_uninit() waits in destroy_workqueue() while
holding RTNL.
Instead of overloading IPOIB_FLAG_OPER_UP to block multicast joins
during a light flush, introduce a dedicated IPOIB_FLAG_MCAST_FLUSH flag.
Use it together with IPOIB_FLAG_OPER_UP to determine whether multicast
joins are allowed, avoiding the race with device shutdown.
Fixes: 344bacca8cd8 ("IB/ipoib: Don't allow MC joins during light MC flush")
Reported-by: Ben Davies <ben.davies@gresearch.co.uk>
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260902-avoid-rest-oper-up-v1-1-04fcd4916cae@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +++++++
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +++++++-----
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 ++++++++--------
3 files changed, 22 insertions(+), 13 deletions(-)
diff --git a/drivers/infiniband/ulp/ipoib/ipoib.h b/drivers/infiniband/ulp/ipoib/ipoib.h
index 35e9c8a330e25..de76f147a9697 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib.h
+++ b/drivers/infiniband/ulp/ipoib/ipoib.h
@@ -87,6 +87,7 @@ enum {
IPOIB_FLAG_INITIALIZED = 1,
IPOIB_FLAG_ADMIN_UP = 2,
IPOIB_PKEY_ASSIGNED = 3,
+ IPOIB_FLAG_MCAST_FLUSH = 4,
IPOIB_FLAG_SUBINTERFACE = 5,
IPOIB_STOP_REAPER = 7,
IPOIB_FLAG_ADMIN_CM = 9,
@@ -417,6 +418,12 @@ struct ipoib_dev_priv {
const struct net_device_ops *rn_ops;
};
+static inline bool ipoib_mcast_allowed(struct ipoib_dev_priv *priv)
+{
+ return test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) &&
+ !test_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
+}
+
struct ipoib_ah {
struct net_device *dev;
struct ib_ah *ah;
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_ib.c b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
index ed25061fac629..28519a82800db 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_ib.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
@@ -1211,17 +1211,19 @@ static void __ipoib_ib_dev_flush(struct ipoib_dev_priv *priv,
}
if (level == IPOIB_FLUSH_LIGHT) {
- int oper_up;
ipoib_mark_paths_invalid(dev);
- /* Set IPoIB operation as down to prevent races between:
+ /* Set MCAST_FLUSH to prevent races between:
* the flush flow which leaves MCG and on the fly joins
* which can happen during that time. mcast restart task
* should deal with join requests we missed.
+ *
+ * Do not clear OPER_UP for this; restoring it races with
+ * ipoib_ib_dev_down() and can leave OPER_UP set after the
+ * device is down.
*/
- oper_up = test_and_clear_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ set_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_mcast_dev_flush(dev);
- if (oper_up)
- set_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ clear_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_reap_dead_ahs(priv);
}
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
index 319d4288eddde..9c00426227ed5 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
@@ -74,7 +74,7 @@ static void __ipoib_mcast_schedule_join_thread(struct ipoib_dev_priv *priv,
struct ipoib_mcast *mcast,
bool delay)
{
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
/*
@@ -470,7 +470,7 @@ static int ipoib_mcast_join(struct net_device *dev, struct ipoib_mcast *mcast)
int ret = 0;
if (!priv->broadcast ||
- !test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ !ipoib_mcast_allowed(priv))
return -EINVAL;
init_completion(&mcast->done);
@@ -556,7 +556,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
unsigned long delay_until = 0;
struct ipoib_mcast *mcast = NULL;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
if (ib_query_port(priv->ca, priv->port, &port_attr)) {
@@ -578,7 +578,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
netif_addr_unlock_bh(dev);
spin_lock_irq(&priv->lock);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
goto out;
if (!priv->broadcast) {
@@ -750,7 +750,7 @@ void ipoib_mcast_send(struct net_device *dev, u8 *daddr, struct sk_buff *skb)
spin_lock_irqsave(&priv->lock, flags);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) ||
+ if (!ipoib_mcast_allowed(priv) ||
!priv->broadcast ||
!test_bit(IPOIB_MCAST_FLAG_ATTACHED, &priv->broadcast->flags)) {
++dev->stats.tx_dropped;
@@ -872,7 +872,7 @@ void ipoib_mcast_restart_task(struct work_struct *work)
LIST_HEAD(remove_list);
struct ib_sa_mcmember_rec rec;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
/*
* shortcut...on shutdown flush is called next, just
* let it do all the work
@@ -966,9 +966,9 @@ void ipoib_mcast_restart_task(struct work_struct *work)
ipoib_mcast_remove_list(&remove_list);
/*
- * Double check that we are still up
+ * Double check that we are still up and not flushing
*/
- if (test_bit(IPOIB_FLAG_OPER_UP, &priv->flags)) {
+ if (ipoib_mcast_allowed(priv)) {
spin_lock_irq(&priv->lock);
__ipoib_mcast_schedule_join_thread(priv, NULL, 0);
spin_unlock_irq(&priv->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 617/982] wifi: cfg80211: check IP header size in cfg80211_classify8021d()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (615 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 616/982] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 618/982] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
` (371 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+878ddc3962f792e9af59,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 48b2c5c628b09cf36cbeca53e0432fc2a7518be7 ]
A frame that looks like IP can be transmitted, but be too short, so
the DS field is read incorrectly:
BUG: KMSAN: uninit-value in cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
ieee80211_select_queue+0x37a/0x9e0 net/mac80211/wme.c:180
__ieee80211_subif_start_xmit+0x60f/0x1d90 net/mac80211/tx.c:4304
ieee80211_subif_start_xmit+0xa8/0x6d0 net/mac80211/tx.c:4538
...
packet_sendmsg+0x9173/0xa2a0 net/packet/af_packet.c:3108
Use skb_header_pointer() like the MPLS case.
Assisted-by: LLM
Fixes: e31a16d6f64e ("wireless: move some utility functions from mac80211 to cfg80211")
Reported-by: syzbot+878ddc3962f792e9af59@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=878ddc3962f792e9af59
Link: https://patch.msgid.link/20260904165614.5e61a4c80b92.I37d68d3f406cb3b90b32e6943418d66070b65197@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 26 ++++++++++++++++++++++----
1 file changed, 22 insertions(+), 4 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index f59985e80e20d..ddcc67ca04cd1 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -985,12 +985,30 @@ unsigned int cfg80211_classify8021d(struct sk_buff *skb,
}
switch (skb->protocol) {
- case htons(ETH_P_IP):
- dscp = ipv4_get_dsfield(ip_hdr(skb)) & 0xfc;
+ case htons(ETH_P_IP): {
+ const struct iphdr *iph;
+ struct iphdr _iph;
+
+ iph = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*iph), &_iph);
+ if (!iph)
+ return 0;
+
+ dscp = ipv4_get_dsfield(iph) & 0xfc;
break;
- case htons(ETH_P_IPV6):
- dscp = ipv6_get_dsfield(ipv6_hdr(skb)) & 0xfc;
+ }
+ case htons(ETH_P_IPV6): {
+ const struct ipv6hdr *ip6h;
+ struct ipv6hdr _ip6h;
+
+ ip6h = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*ip6h), &_ip6h);
+ if (!ip6h)
+ return 0;
+
+ dscp = ipv6_get_dsfield(ip6h) & 0xfc;
break;
+ }
case htons(ETH_P_MPLS_UC):
case htons(ETH_P_MPLS_MC): {
struct mpls_label mpls_tmp, *mpls;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 618/982] soundwire: cadence_master: wait and cancel cdns->work before clock stop
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (616 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 617/982] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 619/982] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
` (370 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, David Lin, Shuming Fan,
Pierre-Louis Bossart, Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bard Liao <yung-chuan.liao@linux.intel.com>
[ Upstream commit aba7b41faeecb7692458095ce6fafc341fe0b80e ]
A peripheral event could happen during the clock stop process. We need
to wait for the event be handled before stopping the bus clock.
Otherwise, we will get the IO transfer timed out issue.
Fixes: af4cc917826f ("soundwire: cadence: mask Slave interrupt before stopping clock")
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: David Lin <david.lin@intel.com>
Reviewed-by: Shuming Fan <shumingf@realtek.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260901031019.233254-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/cadence_master.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/soundwire/cadence_master.c b/drivers/soundwire/cadence_master.c
index 5bd874e58dd6e..149b62df7eef8 100644
--- a/drivers/soundwire/cadence_master.c
+++ b/drivers/soundwire/cadence_master.c
@@ -1585,6 +1585,13 @@ int sdw_cdns_clock_stop(struct sdw_cdns *cdns, bool block_wake)
return 0;
}
+ /*
+ * wait for any in-flight peripheral event handling to complete before stopping the clock.
+ * No need to disable peripheral interrupts before canceling the work, as the peripheral
+ * interrupts are already masked before the work is scheduled.
+ */
+ cancel_work_sync(&cdns->work);
+
/*
* Before entering clock stop we mask the Slave
* interrupts. This helps avoid having to deal with e.g. a
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 619/982] MIPS: Octeon: apply USB FDT fixups also when USB is modular
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (617 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 618/982] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 620/982] dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask Greg Kroah-Hartman
` (369 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Orgad Shaneh, Thomas Bogendoerfer,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Orgad Shaneh <orgads@gmail.com>
[ Upstream commit 126f16e0a1b353c2ba5c7e2c8626cfa865934f9f ]
The uctl/usbn device-tree fixups in octeon_prune_device_tree() - which
set the board's USB reference-clock frequency and type from
__cvmx_helper_board_usb_get_clock_type() - are guarded by
"#ifdef CONFIG_USB", which is false when USB is built as a module. The
fixups then silently disappear and octeon-hcd sees whatever default the
DTS carries (12MHz crystal in octeon_3xxx.dts), leaving the PHY dead or
the bus erroring on boards with a different reference clock.
Use IS_ENABLED() so USB=m gets the same fixups as USB=y.
Fixes: 7fd57ab9d9cf ("MIPS: Octeon: Fix compile error when USB is not enabled.")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Orgad Shaneh <orgads@gmail.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/cavium-octeon/octeon-platform.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/mips/cavium-octeon/octeon-platform.c b/arch/mips/cavium-octeon/octeon-platform.c
index ce05c0dd3acd7..5faea06737145 100644
--- a/arch/mips/cavium-octeon/octeon-platform.c
+++ b/arch/mips/cavium-octeon/octeon-platform.c
@@ -15,7 +15,7 @@
#include <asm/octeon/octeon.h>
#include <asm/octeon/cvmx-helper-board.h>
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
#include <linux/usb/ehci_def.h>
#include <linux/usb/ehci_pdriver.h>
#include <linux/usb/ohci_pdriver.h>
@@ -1079,7 +1079,7 @@ int __init octeon_prune_device_tree(void)
;
}
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
/* OHCI/UHCI USB */
alias_prop = fdt_getprop(initial_boot_params, aliases,
"uctl", NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 620/982] dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (618 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 619/982] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 621/982] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
` (368 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen-Yu Tsai, Marek Szyprowski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen-Yu Tsai <wenst@chromium.org>
[ Upstream commit 89461db349cc00816c01d55507d511466b3b7151 ]
When a reserved memory region described in the device tree is attached
to a device, it is expected that the device's limitations are correctly
included in that description.
However, if the device driver failed to implement DMA address masking
or addressing beyond the default 32 bits (on arm64), then bad things
could happen because the DMA address was truncated, such as playing
back audio with no actual audio coming out, or DMA overwriting random
blocks of kernel memory.
Check against the coherent DMA mask when the memory regions are attached
to the device. Give a warning when the memory region can not be covered
by the mask.
A warning instead of a hard error was chosen, because it is possible
that existing drivers could be working fine even if they forgot to
extend the coherent DMA mask.
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Link: https://lore.kernel.org/r/20250421083930.374173-1-wenst@chromium.org
Stable-dep-of: 504981db4f69 ("dma-coherent: report a failed reserved memory assignment")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/coherent.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
index ff5683a57f771..b3a6d904c0b92 100644
--- a/kernel/dma/coherent.c
+++ b/kernel/dma/coherent.c
@@ -335,16 +335,22 @@ static struct reserved_mem *dma_reserved_default_memory __initdata;
static int rmem_dma_device_init(struct reserved_mem *rmem, struct device *dev)
{
- if (!rmem->priv) {
- struct dma_coherent_mem *mem;
+ struct dma_coherent_mem *mem = rmem->priv;
+ if (!mem) {
mem = dma_init_coherent_memory(rmem->base, rmem->base,
rmem->size, true);
if (IS_ERR(mem))
return PTR_ERR(mem);
rmem->priv = mem;
}
- dma_assign_coherent_memory(dev, rmem->priv);
+
+ /* Warn if the device potentially can't use the reserved memory */
+ if (mem->device_base + rmem->size - 1 >
+ min_not_zero(dev->coherent_dma_mask, dev->bus_dma_limit))
+ dev_warn(dev, "reserved memory is beyond device's set DMA address range\n");
+
+ dma_assign_coherent_memory(dev, mem);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 621/982] dma-coherent: report a failed reserved memory assignment
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (619 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 620/982] dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 622/982] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
` (367 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Marek Szyprowski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit 504981db4f69bdd28054fb98c96a3a67f7248dde ]
rmem_dma_device_init() drops the return value of
dma_assign_coherent_memory() and always reports success. That call fails
with -EBUSY when the device already has a coherent pool, and the file
allows only "*one* such region of memory" per device.
of_reserved_mem_device_init_by_idx() reads the zero as success. It logs
"assigned reserved memory node" for a region that was not assigned and
records the pairing, so of_reserved_mem_device_release() later runs
rmem_dma_device_release() for it. That clears dev->dma_mem without
looking at which region it was called for, dropping the pool the device
did get and leaving it on ordinary memory.
dma_declare_coherent_memory() checks the same call and releases the
memory on failure, and rmem_swiotlb_device_init() propagates its own
errors. Return the error here as well, so a device tree that assigns two
pools to one device fails the probe instead of half working.
Fixes: 7bfa5ab6fa1b ("drivers: dma-coherent: add initialization from device tree")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260905074727.108029-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/coherent.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
index b3a6d904c0b92..133d13428714d 100644
--- a/kernel/dma/coherent.c
+++ b/kernel/dma/coherent.c
@@ -350,8 +350,7 @@ static int rmem_dma_device_init(struct reserved_mem *rmem, struct device *dev)
min_not_zero(dev->coherent_dma_mask, dev->bus_dma_limit))
dev_warn(dev, "reserved memory is beyond device's set DMA address range\n");
- dma_assign_coherent_memory(dev, mem);
- return 0;
+ return dma_assign_coherent_memory(dev, mem);
}
static void rmem_dma_device_release(struct reserved_mem *rmem,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 622/982] dmaengine: Fix device kref underflow in dma_chan_put()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (620 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 621/982] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 623/982] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
` (366 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit 44dab659064eb5c10adb0306510eebe848ed592d ]
dma_chan_get() takes chan->device->ref only on the slow path:
/* no kref on fast path */
if (chan->client_count) {
__module_get(owner);
chan->client_count++;
return 0;
}
if (!try_module_get(owner))
return -ENODEV;
if (!dma_device_get(chan->device)) { // calls kref_get_unless_zero()
dma_chan_put() drops the ref unconditionally, so every fast-path
get/put pair drops one extra device reference.
The bug fires when two conditions hold together: a non-private
provider has a persistent client holding chan->client_count > 0
and another client cycles dmaengine_get()/dmaengine_put().
When the kref hits zero, the subsequent dma_find_channel() returns
NULL even though the provider module is still loaded.
Fix this by dropping device->ref only on the last put, matching the
single slow-path get.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-2-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index d89827d0927e4..294a00ea56990 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -513,7 +513,9 @@ static void dma_chan_put(struct dma_chan *chan)
chan->route_data = NULL;
}
- dma_device_put(chan->device);
+ /* This channel is not in use anymore, drop the device ref */
+ if (!chan->client_count)
+ dma_device_put(chan->device);
module_put(dma_chan_to_owner(chan));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 623/982] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (621 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 622/982] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 624/982] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
` (365 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit e873c74132f0c5f1452816cd9bb26208f0bba1e1 ]
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-3-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 294a00ea56990..1613b9a32baf4 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -493,10 +493,13 @@ static int dma_chan_get(struct dma_chan *chan)
*/
static void dma_chan_put(struct dma_chan *chan)
{
+ struct module *owner;
+
/* This channel is not in use, bail out */
if (!chan->client_count)
return;
+ owner = dma_chan_to_owner(chan);
chan->client_count--;
/* This channel is not in use anymore, free it */
@@ -516,7 +519,7 @@ static void dma_chan_put(struct dma_chan *chan)
/* This channel is not in use anymore, drop the device ref */
if (!chan->client_count)
dma_device_put(chan->device);
- module_put(dma_chan_to_owner(chan));
+ module_put(owner);
}
enum dma_status dma_sync_wait(struct dma_chan *chan, dma_cookie_t cookie)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 624/982] dmaengine: wait for RCU readers before releasing dma_device
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (622 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 623/982] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 625/982] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
` (364 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit dc750422170a563c7a81f6e49d36bb02c62ae37f ]
dma_issue_pending_all() walks the dma_device_list with
list_for_each_entry_rcu() under rcu_read_lock(). dma_device_release()
unlinks the device with list_del_rcu() and then calls
device->device_release() (which in many drivers, such as plx_dma.c,
directly calls kfree()).
Because there is no grace period between unlinking the device and
freeing it, concurrent RCU readers in dma_issue_pending_all() can
access the device after it has been freed.
The lockless walk originally relied on clients holding a dmaengine
reference to pin the provider module, and therefore the device, for as
long as they might traverse the list. Commit 8ad342a86359 ("dmaengine:
Add reference counting to dma_device struct") decoupled the dma_device
lifetime from the module reference, so the device can now be released
while a reader is still walking the list.
Add synchronize_rcu() before the device is freed, so RCU readers are
guaranteed to have finished. Keep it unconditional: providers that do
not implement device_release() free the device themselves once
dma_async_device_unregister() returns. This call will delay for a grace
period with dma_list_mutex held, which is safe and only teardown path is
delayed.
Fixes: 2ba05622b8b1 ("dmaengine: provide a common 'issue_pending_all' implementation")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260526-dmaengine-kref-fix-v2-0-3df60afac01d@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-4-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 1613b9a32baf4..53e755c03f414 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -426,6 +426,7 @@ static void dma_device_release(struct kref *ref)
list_del_rcu(&device->global_node);
dma_channel_rebalance();
+ synchronize_rcu();
if (device->device_release)
device->device_release(device);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 625/982] wifi: cfg80211: only group hidden BSSes with beacon entries
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (623 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 624/982] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 626/982] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
` (363 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1a797e1c81be78a2ace7,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 068843ed0902c552a13860c5ec6b2ca65b57a065 ]
When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.
But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there's a group without beacon elements.
If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its
WARN_ON_ONCE(bss->pub.hidden_beacon_bss)
WARN_ON_ONCE(!list_empty(&bss->hidden_list))
which are there because an entry without beacon elements is not supposed
to be part of a group yet.
Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.
Assisted-by: LLM
Fixes: 4593c4cbe1c9 ("cfg80211: fix BSS list hidden SSID lookup")
Reported-by: syzbot+1a797e1c81be78a2ace7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1a797e1c81be78a2ace7
Link: https://patch.msgid.link/20260904165614.bcfa64715745.Iad740347c86de56d4ff4f96a95f3c3afc47c42de@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 1ebe2f3f6f52a..829b78eba6b10 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -1879,6 +1879,13 @@ cfg80211_bss_update(struct cfg80211_registered_device *rdev,
if (!hidden)
hidden = rb_find_bss(rdev, tmp,
BSS_CMP_HIDE_NUL);
+ /*
+ * Only group with an entry with beacon data, otherwise
+ * beacon data can never be filled/updated.
+ */
+ if (hidden &&
+ !rcu_access_pointer(hidden->pub.beacon_ies))
+ hidden = NULL;
if (hidden) {
new->pub.hidden_beacon_bss = &hidden->pub;
list_add(&new->hidden_list,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 626/982] wifi: cfg80211: dont filter by BSS type when removing stale entries
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (624 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 625/982] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 627/982] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
` (362 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+dc6f4dce0d707900cdea,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b377e1000d963e7182a987082b4b06580bd7ac84 ]
When an assoc AP switches to a channel that already has a BSS entry,
cfg80211_update_assoc_bss_entry() removes that entry before rehashing
the real one, since the two would otherwise collide in the BSS rbtree.
The lookup for that entry also required it to match the connection's BSS
type, so an entry advertising e.g. the IBSS capability bit was left in
place, and the following cfg80211_rehash_bss() then ran into it:
WARN_ON(!cmp)
Changing the type shouldn't really happen, but can be triggered by a
rogue AP/device, so drop the check and remove any entries matching
the comparison.
Assisted-by: LLM
Fixes: 0afd425b1b64 ("cfg80211: fix duplicated scan entries after channel switch")
Reported-by: syzbot+dc6f4dce0d707900cdea@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dc6f4dce0d707900cdea
Link: https://patch.msgid.link/20260904165614.1f05dae1c546.Ib52d57b57caa912efee020f9d4a033a5160617ce@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 829b78eba6b10..ecf9021219380 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -2684,11 +2684,6 @@ void cfg80211_update_assoc_bss_entry(struct wireless_dev *wdev,
cbss->pub.channel = chan;
list_for_each_entry(bss, &rdev->bss_list, list) {
- if (!cfg80211_bss_type_match(bss->pub.capability,
- bss->pub.channel->band,
- wdev->conn_bss_type))
- continue;
-
if (bss == cbss)
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 627/982] wifi: mac80211: suppress chanctx warning for debugfs reset
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (625 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 626/982] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 628/982] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
` (361 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+56a1a45a9a2c04d425ff,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit bf29d085e0eba92388518719d044f4702a8c6644 ]
Before suspend all the channel contexts should removed, so the
warning makes sense and should be there, but during reset the
same code is called without first removing. Limit the check to
the real suspend case.
Assisted-by: LLM
Fixes: 12e7f517029d ("mac80211: cleanup generic suspend/resume procedures")
Reported-by: syzbot+56a1a45a9a2c04d425ff@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=56a1a45a9a2c04d425ff
Link: https://patch.msgid.link/20260904165722.fe46395e310b.Ic4aaa95bd9d0ceb6a3cd7d84c425afee7d7d3dd7@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 2 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/ieee80211_i.h | 2 +-
net/mac80211/pm.c | 8 +++++---
4 files changed, 8 insertions(+), 6 deletions(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 0d5ddd3d2c5fc..0b425f97977be 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -2725,7 +2725,7 @@ static int ieee80211_set_txq_params(struct wiphy *wiphy,
static int ieee80211_suspend(struct wiphy *wiphy,
struct cfg80211_wowlan *wowlan)
{
- return __ieee80211_suspend(wiphy_priv(wiphy), wowlan);
+ return __ieee80211_suspend(wiphy_priv(wiphy), wowlan, false);
}
static int ieee80211_resume(struct wiphy *wiphy)
diff --git a/net/mac80211/debugfs.c b/net/mac80211/debugfs.c
index 175669aa8e744..f345c61cfd62f 100644
--- a/net/mac80211/debugfs.c
+++ b/net/mac80211/debugfs.c
@@ -417,7 +417,7 @@ static ssize_t reset_write(struct file *file, const char __user *user_buf,
rtnl_lock();
wiphy_lock(local->hw.wiphy);
- __ieee80211_suspend(&local->hw, NULL);
+ __ieee80211_suspend(&local->hw, NULL, true);
ret = __ieee80211_resume(&local->hw);
wiphy_unlock(local->hw.wiphy);
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index e94a370da4c4b..2f437ddd8f1ed 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -2161,7 +2161,7 @@ int ieee80211_reconfig(struct ieee80211_local *local);
void ieee80211_stop_device(struct ieee80211_local *local);
int __ieee80211_suspend(struct ieee80211_hw *hw,
- struct cfg80211_wowlan *wowlan);
+ struct cfg80211_wowlan *wowlan, bool reset);
static inline int __ieee80211_resume(struct ieee80211_hw *hw)
{
diff --git a/net/mac80211/pm.c b/net/mac80211/pm.c
index 0ccb5701c7f39..65e0c7bd33b23 100644
--- a/net/mac80211/pm.c
+++ b/net/mac80211/pm.c
@@ -18,7 +18,8 @@ static void ieee80211_sched_scan_cancel(struct ieee80211_local *local)
cfg80211_sched_scan_stopped_locked(local->hw.wiphy, 0);
}
-int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
+int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan,
+ bool reset)
{
struct ieee80211_local *local = hw_to_local(hw);
struct ieee80211_sub_if_data *sdata;
@@ -167,9 +168,10 @@ int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
/*
* We disconnected on all interfaces before suspend, all channel
- * contexts should be released.
+ * contexts should be released, but on 'reset' debugfs that's
+ * not true so don't check there.
*/
- WARN_ON(!list_empty(&local->chanctx_list));
+ WARN_ON(!reset && !list_empty(&local->chanctx_list));
/* stop hardware - this must stop RX */
ieee80211_stop_device(local);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 628/982] wifi: mac80211: unlist vifs when their netdev is unregistered
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (626 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 627/982] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 629/982] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
` (360 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit eee2efd82867b623982ac51925b5a1812a74c50d ]
mac80211 only removes vifs from the local->interfaces list when
an interface is removed via ieee80211_if_remove(), before it
unregisters the netdev. However, it's possible for a netdev to
be unregistered without going through that: When the netns that
holds the wiphy is destroyed, the wiphy is supposed to move to
the init_ns, but that can run into allocation failures.
Then, mac80211 has an interface listed that doesn't exist, and
will eventually hit
BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!
...
_cfg80211_unregister_wdev+0x24/0x36a [cfg80211]
cfg80211_unregister_wdev+0x15/0x1d [cfg80211]
ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]
ieee80211_unregister_hw+0x73/0x1d1 [mac80211]
mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]
Remove the interface from the list in ->ndo_uninit if it's still
around to avoid this.
Assisted-by: LLM
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.038ad73e6c04.I990abca78483e058746b6f42b4796717c3028164@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 4224a7c244a3d..ee28c190faab3 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -861,9 +861,33 @@ static void ieee80211_teardown_sdata(struct ieee80211_sub_if_data *sdata)
ieee80211_link_stop(&sdata->deflink);
}
+/*
+ * The netdev can be unregistered without mac80211 doing it, e.g. by the netdev
+ * core when cfg80211 couldn't move it out of a network namespace that's being
+ * destroyed. Drop it from the interface list either way.
+ */
+static void ieee80211_unlist_sdata(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_local *local = sdata->local;
+ struct ieee80211_sub_if_data *iter;
+
+ ASSERT_RTNL();
+
+ list_for_each_entry(iter, &local->interfaces, list) {
+ if (iter != sdata)
+ continue;
+ guard(mutex)(&local->iflist_mtx);
+ list_del_rcu(&sdata->list);
+ return;
+ }
+}
+
static void ieee80211_uninit(struct net_device *dev)
{
- ieee80211_teardown_sdata(IEEE80211_DEV_TO_SUB_IF(dev));
+ struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
+
+ ieee80211_unlist_sdata(sdata);
+ ieee80211_teardown_sdata(sdata);
}
static u16 ieee80211_netdev_select_queue(struct net_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 629/982] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (627 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 628/982] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 630/982] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
` (359 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b4aa2b672b18f1d4dc5f,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 87840d4a3a21b1c19b867a80e16ba69dff284de2 ]
The code checks ->started for frames coming from wmediumd, but the
radio can be stopped after the check and before frame delivery,
causing mac80211 to hit the WARN_ON(!local->started).
Expand the mutex for this case and synchronise against it when the
radio is stopped to avoid being able to hit the warning with hwsim.
Drop the error print that would've complicated the error path, it
only triggers for allocation failures (already noisy) and malformed
frames anyway.
Assisted-by: LLM
Fixes: 7882513bacb1 ("mac80211_hwsim driver support userspace frame tx/rx")
Reported-by: syzbot+b4aa2b672b18f1d4dc5f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b4aa2b672b18f1d4dc5f
Link: https://patch.msgid.link/20260904170140.5f69a10d606b.I4a7921d00643f69e439c7a3b221d104f66a3dcdc@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mac80211_hwsim.c | 39 ++++++++++++++++-----------
1 file changed, 24 insertions(+), 15 deletions(-)
diff --git a/drivers/net/wireless/mac80211_hwsim.c b/drivers/net/wireless/mac80211_hwsim.c
index e71e40376ba58..8ebc76cbb0d98 100644
--- a/drivers/net/wireless/mac80211_hwsim.c
+++ b/drivers/net/wireless/mac80211_hwsim.c
@@ -1969,7 +1969,12 @@ static void mac80211_hwsim_stop(struct ieee80211_hw *hw)
struct sk_buff *skb;
int i;
- data->started = false;
+ /*
+ * Serialise against wmediumd userspace, so no more frames
+ * can be handed to mac80211 after this returns.
+ */
+ scoped_guard(mutex, &data->mutex)
+ data->started = false;
for (i = 0; i < ARRAY_SIZE(data->link_data); i++)
hrtimer_cancel(&data->link_data[i].beacon_timer);
@@ -4913,12 +4918,12 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
if (frame_data_len < sizeof(struct ieee80211_hdr_3addr) ||
frame_data_len > IEEE80211_MAX_DATA_LEN)
- goto err;
+ goto out;
/* Allocate new skb here */
skb = alloc_skb(frame_data_len, GFP_KERNEL);
if (skb == NULL)
- goto err;
+ goto out;
/* Copy the data */
skb_put_data(skb, frame_data, frame_data_len);
@@ -4943,10 +4948,17 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
goto out;
}
+ /*
+ * Serialise against mac80211_hwsim_stop() - mac80211 doesn't allow
+ * frames reported while the HW is down, hence the ->started check
+ * must be under mutex.
+ */
+ mutex_lock(&data2->mutex);
+
/* check if radio is configured properly */
if ((data2->idle && !data2->tmp_chan) || !data2->started)
- goto out;
+ goto out_unlock;
/* A frame is received from user space */
memset(&rx_status, 0, sizeof(rx_status));
@@ -4962,22 +4974,18 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
iter_data.channel = ieee80211_get_channel(data2->hw->wiphy,
rx_status.freq);
if (!iter_data.channel)
- goto out;
+ goto out_unlock;
rx_status.band = iter_data.channel->band;
- mutex_lock(&data2->mutex);
if (!hwsim_chans_compat(iter_data.channel, channel)) {
ieee80211_iterate_active_interfaces_atomic(
data2->hw, IEEE80211_IFACE_ITER_NORMAL,
mac80211_hwsim_tx_iter, &iter_data);
- if (!iter_data.receive) {
- mutex_unlock(&data2->mutex);
- goto out;
- }
+ if (!iter_data.receive)
+ goto out_unlock;
}
- mutex_unlock(&data2->mutex);
} else if (!channel) {
- goto out;
+ goto out_unlock;
} else {
rx_status.freq = channel->center_freq;
rx_status.band = channel->band;
@@ -4985,7 +4993,7 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.rate_idx = nla_get_u32(info->attrs[HWSIM_ATTR_RX_RATE]);
if (rx_status.rate_idx >= data2->hw->wiphy->bands[rx_status.band]->n_bitrates)
- goto out;
+ goto out_unlock;
rx_status.signal = nla_get_u32(info->attrs[HWSIM_ATTR_SIGNAL]);
hdr = (void *)skb->data;
@@ -4995,10 +5003,11 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.boottime_ns = ktime_get_boottime_ns();
mac80211_hwsim_rx(data2, &rx_status, skb);
+ mutex_unlock(&data2->mutex);
return 0;
-err:
- pr_debug("mac80211_hwsim: error occurred in %s\n", __func__);
+out_unlock:
+ mutex_unlock(&data2->mutex);
out:
dev_kfree_skb(skb);
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 630/982] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (628 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 629/982] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 631/982] wifi: cfg80211: trace: remove MAC_PR_{FMT,ARG} Greg Kroah-Hartman
` (358 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+de3ee5362db09487ea37,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 4504f3960dc4501c73be9f99eabda2e26e9db41e ]
On ifup, AP_VLAN interfaces get crypto_tx_tailroom_needed_cnt from
the AP interface, but it's never decremented again unless the AP is
also brought down. Thus, bringing the same AP_VLAN up again will
increment the counter again and eventually hit the sanity check:
WARN_ON_ONCE(sdata->crypto_tx_tailroom_needed_cnt !=
master->crypto_tx_tailroom_needed_cnt);
Reset it on ifdown to avoid that.
Assisted-by: LLM
Fixes: f9dca80b98ca ("mac80211: fix AP_VLAN crypto tailroom calculation")
Reported-by: syzbot+de3ee5362db09487ea37@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=de3ee5362db09487ea37
Link: https://patch.msgid.link/20260908122838.201719-14-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index ee28c190faab3..c8ee28928542c 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -623,6 +623,8 @@ static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata, bool going_do
RCU_INIT_POINTER(sdata->vif.bss_conf.chanctx_conf, NULL);
/* see comment in the default case below */
ieee80211_free_keys(sdata, true);
+ /* increased by AP value on ifup, so reset on ifdown */
+ sdata->crypto_tx_tailroom_needed_cnt = 0;
/* no need to tell driver */
break;
case NL80211_IFTYPE_MONITOR:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 631/982] wifi: cfg80211: trace: remove MAC_PR_{FMT,ARG}
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (629 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 630/982] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 632/982] wifi: cfg80211: make TDLS management link-aware Greg Kroah-Hartman
` (357 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 3d9c361713f24f3f55b9622d18d32add1910e6ba ]
With %pM, this really is no longer needed, and actually
longer to spell out. Remove it.
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 038e1d126304 ("wifi: mac80211: require a peer station for TDLS setup confirm")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/trace.h | 244 +++++++++++++++++++++----------------------
1 file changed, 120 insertions(+), 124 deletions(-)
diff --git a/net/wireless/trace.h b/net/wireless/trace.h
index f325ca28facea..da03b6ff71b2a 100644
--- a/net/wireless/trace.h
+++ b/net/wireless/trace.h
@@ -19,8 +19,6 @@
else \
eth_zero_addr(__entry->entry_mac); \
} while (0)
-#define MAC_PR_FMT "%pM"
-#define MAC_PR_ARG(entry_mac) (__entry->entry_mac)
#define MAXNAME 32
#define WIPHY_ENTRY __array(char, wiphy_name, 32)
@@ -454,10 +452,10 @@ DECLARE_EVENT_CLASS(key_handle,
__entry->pairwise = pairwise;
),
TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", link_id: %d, "
- "key_index: %u, pairwise: %s, mac addr: " MAC_PR_FMT,
+ "key_index: %u, pairwise: %s, mac addr: %pM",
WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->link_id,
__entry->key_index, BOOL_TO_STR(__entry->pairwise),
- MAC_PR_ARG(mac_addr))
+ __entry->mac_addr)
);
DEFINE_EVENT(key_handle, rdev_get_key,
@@ -496,10 +494,10 @@ TRACE_EVENT(rdev_add_key,
),
TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", link_id: %d, "
"key_index: %u, mode: %u, pairwise: %s, "
- "mac addr: " MAC_PR_FMT,
+ "mac addr: %pM",
WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->link_id,
__entry->key_index, __entry->mode,
- BOOL_TO_STR(__entry->pairwise), MAC_PR_ARG(mac_addr))
+ BOOL_TO_STR(__entry->pairwise), __entry->mac_addr)
);
TRACE_EVENT(rdev_set_default_key,
@@ -813,11 +811,11 @@ DECLARE_EVENT_CLASS(station_add_change,
__entry->opmode_notif_used =
params->link_sta_params.opmode_notif_used;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: %pM"
", station flags mask: %u, station flags set: %u, "
"station modify mask: %u, listen interval: %d, aid: %u, "
"plink action: %u, plink state: %u, uapsd queues: %u, vlan:%s",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(sta_mac),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->sta_mac,
__entry->sta_flags_mask, __entry->sta_flags_set,
__entry->sta_modify_mask, __entry->listen_interval,
__entry->aid, __entry->plink_action, __entry->plink_state,
@@ -849,8 +847,8 @@ DECLARE_EVENT_CLASS(wiphy_netdev_mac_evt,
NETDEV_ASSIGN;
MAC_ASSIGN(sta_mac, mac);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", mac: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(sta_mac))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", mac: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->sta_mac)
);
DECLARE_EVENT_CLASS(station_del,
@@ -871,9 +869,9 @@ DECLARE_EVENT_CLASS(station_del,
__entry->subtype = params->subtype;
__entry->reason_code = params->reason_code;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: %pM"
", subtype: %u, reason_code: %u",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(sta_mac),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->sta_mac,
__entry->subtype, __entry->reason_code)
);
@@ -909,8 +907,8 @@ TRACE_EVENT(rdev_dump_station,
MAC_ASSIGN(sta_mac, mac);
__entry->idx = _idx;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: " MAC_PR_FMT ", idx: %d",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(sta_mac),
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: %pM, idx: %d",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->sta_mac,
__entry->idx)
);
@@ -947,9 +945,9 @@ DECLARE_EVENT_CLASS(mpath_evt,
MAC_ASSIGN(dst, dst);
MAC_ASSIGN(next_hop, next_hop);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", destination: " MAC_PR_FMT ", next hop: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(dst),
- MAC_PR_ARG(next_hop))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", destination: %pM, next hop: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->dst,
+ __entry->next_hop)
);
DEFINE_EVENT(mpath_evt, rdev_add_mpath,
@@ -988,10 +986,9 @@ TRACE_EVENT(rdev_dump_mpath,
MAC_ASSIGN(next_hop, next_hop);
__entry->idx = _idx;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", index: %d, destination: "
- MAC_PR_FMT ", next hop: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->idx, MAC_PR_ARG(dst),
- MAC_PR_ARG(next_hop))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", index: %d, destination: %pM, next hop: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->idx, __entry->dst,
+ __entry->next_hop)
);
TRACE_EVENT(rdev_get_mpp,
@@ -1010,9 +1007,9 @@ TRACE_EVENT(rdev_get_mpp,
MAC_ASSIGN(dst, dst);
MAC_ASSIGN(mpp, mpp);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", destination: " MAC_PR_FMT
- ", mpp: " MAC_PR_FMT, WIPHY_PR_ARG, NETDEV_PR_ARG,
- MAC_PR_ARG(dst), MAC_PR_ARG(mpp))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", destination: %pM"
+ ", mpp: %pM", WIPHY_PR_ARG, NETDEV_PR_ARG,
+ __entry->dst, __entry->mpp)
);
TRACE_EVENT(rdev_dump_mpp,
@@ -1033,10 +1030,9 @@ TRACE_EVENT(rdev_dump_mpp,
MAC_ASSIGN(mpp, mpp);
__entry->idx = _idx;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", index: %d, destination: "
- MAC_PR_FMT ", mpp: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->idx, MAC_PR_ARG(dst),
- MAC_PR_ARG(mpp))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", index: %d, destination: %pM, mpp: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->idx, __entry->dst,
+ __entry->mpp)
);
TRACE_EVENT(rdev_return_int_mpath_info,
@@ -1243,9 +1239,9 @@ TRACE_EVENT(rdev_auth,
eth_zero_addr(__entry->bssid);
__entry->auth_type = req->auth_type;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", auth type: %d, bssid: " MAC_PR_FMT,
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", auth type: %d, bssid: %pM",
WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->auth_type,
- MAC_PR_ARG(bssid))
+ __entry->bssid)
);
TRACE_EVENT(rdev_assoc,
@@ -1294,10 +1290,10 @@ TRACE_EVENT(rdev_assoc,
memcpy(__get_dynamic_array(fils_nonces),
req->fils_nonces, 2 * FILS_NONCE_LEN);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT
- ", previous bssid: " MAC_PR_FMT ", use mfp: %s, flags: %u",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(bssid),
- MAC_PR_ARG(prev_bssid), BOOL_TO_STR(__entry->use_mfp),
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM"
+ ", previous bssid: %pM, use mfp: %s, flags: %u",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->bssid,
+ __entry->prev_bssid, BOOL_TO_STR(__entry->use_mfp),
__entry->flags)
);
@@ -1317,8 +1313,8 @@ TRACE_EVENT(rdev_deauth,
MAC_ASSIGN(bssid, req->bssid);
__entry->reason_code = req->reason_code;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT ", reason: %u",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(bssid),
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM, reason: %u",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->bssid,
__entry->reason_code)
);
@@ -1340,9 +1336,9 @@ TRACE_EVENT(rdev_disassoc,
__entry->reason_code = req->reason_code;
__entry->local_state_change = req->local_state_change;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM"
", reason: %u, local state change: %s",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(bssid),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->bssid,
__entry->reason_code,
BOOL_TO_STR(__entry->local_state_change))
);
@@ -1413,12 +1409,12 @@ TRACE_EVENT(rdev_connect,
__entry->flags = sme->flags;
MAC_ASSIGN(prev_bssid, sme->prev_bssid);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM"
", ssid: %s, auth type: %d, privacy: %s, wpa versions: %u, "
- "flags: %u, previous bssid: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(bssid), __entry->ssid,
+ "flags: %u, previous bssid: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->bssid, __entry->ssid,
__entry->auth_type, BOOL_TO_STR(__entry->privacy),
- __entry->wpa_versions, __entry->flags, MAC_PR_ARG(prev_bssid))
+ __entry->wpa_versions, __entry->flags, __entry->prev_bssid)
);
TRACE_EVENT(rdev_update_connect_params,
@@ -1542,8 +1538,8 @@ TRACE_EVENT(rdev_join_ibss,
memset(__entry->ssid, 0, IEEE80211_MAX_SSID_LEN + 1);
memcpy(__entry->ssid, params->ssid, params->ssid_len);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT ", ssid: %s",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(bssid), __entry->ssid)
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM, ssid: %s",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->bssid, __entry->ssid)
);
TRACE_EVENT(rdev_join_ocb,
@@ -1664,9 +1660,9 @@ TRACE_EVENT(rdev_set_bitrate_mask,
__entry->link_id = link_id;
MAC_ASSIGN(peer, peer);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", link_id: %d, peer: " MAC_PR_FMT,
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", link_id: %d, peer: %pM",
WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->link_id,
- MAC_PR_ARG(peer))
+ __entry->peer)
);
TRACE_EVENT(rdev_update_mgmt_frame_registrations,
@@ -1810,10 +1806,10 @@ TRACE_EVENT(rdev_tdls_mgmt,
__entry->initiator = initiator;
memcpy(__get_dynamic_array(buf), buf, len);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT ", action_code: %u, "
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM, action_code: %u, "
"dialog_token: %u, status_code: %u, peer_capability: %u "
"initiator: %s buf: %#.2x ",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer,
__entry->action_code, __entry->dialog_token,
__entry->status_code, __entry->peer_capability,
BOOL_TO_STR(__entry->initiator),
@@ -1893,8 +1889,8 @@ TRACE_EVENT(rdev_tdls_oper,
MAC_ASSIGN(peer, peer);
__entry->oper = oper;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT ", oper: %d",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer), __entry->oper)
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM, oper: %d",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer, __entry->oper)
);
DECLARE_EVENT_CLASS(rdev_pmksa,
@@ -1911,8 +1907,8 @@ DECLARE_EVENT_CLASS(rdev_pmksa,
NETDEV_ASSIGN;
MAC_ASSIGN(bssid, pmksa->bssid);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(bssid))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->bssid)
);
TRACE_EVENT(rdev_probe_client,
@@ -1929,8 +1925,8 @@ TRACE_EVENT(rdev_probe_client,
NETDEV_ASSIGN;
MAC_ASSIGN(peer, peer);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer)
);
DEFINE_EVENT(rdev_pmksa, rdev_set_pmksa,
@@ -2051,9 +2047,9 @@ TRACE_EVENT(rdev_tx_control_port,
__entry->unencrypted = unencrypted;
__entry->link_id = link_id;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT ","
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM,"
" proto: 0x%x, unencrypted: %s, link: %d",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(dest),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->dest,
be16_to_cpu(__entry->proto),
BOOL_TO_STR(__entry->unencrypted),
__entry->link_id)
@@ -2392,8 +2388,8 @@ TRACE_EVENT(rdev_add_tx_ts,
__entry->user_prio = user_prio;
__entry->admitted_time = admitted_time;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT ", TSID %d, UP %d, time %d",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer),
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM, TSID %d, UP %d, time %d",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer,
__entry->tsid, __entry->user_prio, __entry->admitted_time)
);
@@ -2413,8 +2409,8 @@ TRACE_EVENT(rdev_del_tx_ts,
MAC_ASSIGN(peer, peer);
__entry->tsid = tsid;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT ", TSID %d",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer), __entry->tsid)
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM, TSID %d",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer, __entry->tsid)
);
TRACE_EVENT(rdev_tdls_channel_switch,
@@ -2435,9 +2431,9 @@ TRACE_EVENT(rdev_tdls_channel_switch,
MAC_ASSIGN(addr, addr);
CHAN_DEF_ASSIGN(chandef);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM"
" oper class %d, " CHAN_DEF_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(addr),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->addr,
__entry->oper_class, CHAN_DEF_PR_ARG)
);
@@ -2455,8 +2451,8 @@ TRACE_EVENT(rdev_tdls_cancel_channel_switch,
NETDEV_ASSIGN;
MAC_ASSIGN(addr, addr);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(addr))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->addr)
);
TRACE_EVENT(rdev_set_pmk,
@@ -2488,9 +2484,9 @@ TRACE_EVENT(rdev_set_pmk,
pmk_conf->pmk_r0_name ? WLAN_PMK_NAME_LEN : 0);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM"
"pmk_len=%u, pmk: %s pmk_r0_name: %s", WIPHY_PR_ARG,
- NETDEV_PR_ARG, MAC_PR_ARG(aa), __entry->pmk_len,
+ NETDEV_PR_ARG, __entry->aa, __entry->pmk_len,
__print_array(__get_dynamic_array(pmk),
__get_dynamic_array_len(pmk), 1),
__entry->pmk_r0_name_len ?
@@ -2515,8 +2511,8 @@ TRACE_EVENT(rdev_del_pmk,
MAC_ASSIGN(aa, aa);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(aa))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->aa)
);
TRACE_EVENT(rdev_external_auth,
@@ -2537,7 +2533,7 @@ TRACE_EVENT(rdev_external_auth,
params->ssid.ssid_len);
__entry->status = params->status;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", bssid: %pM"
", ssid: %s, status: %u", WIPHY_PR_ARG, NETDEV_PR_ARG,
__entry->bssid, __entry->ssid, __entry->status)
);
@@ -2720,8 +2716,8 @@ TRACE_EVENT(rdev_update_owe_info,
__entry->status = owe_info->status;
memcpy(__get_dynamic_array(ie),
owe_info->ie, owe_info->ie_len);),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: " MAC_PR_FMT
- " status %d", WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer),
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: %pM"
+ " status %d", WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer,
__entry->status)
);
@@ -2739,8 +2735,8 @@ TRACE_EVENT(rdev_probe_mesh_link,
NETDEV_ASSIGN;
MAC_ASSIGN(dest, dest);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(dest))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->dest)
);
TRACE_EVENT(rdev_set_tid_config,
@@ -2757,8 +2753,8 @@ TRACE_EVENT(rdev_set_tid_config,
NETDEV_ASSIGN;
MAC_ASSIGN(peer, tid_conf->peer);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer)
);
TRACE_EVENT(rdev_reset_tid_config,
@@ -2777,8 +2773,8 @@ TRACE_EVENT(rdev_reset_tid_config,
MAC_ASSIGN(peer, peer);
__entry->tids = tids;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: " MAC_PR_FMT ", tids: 0x%x",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer), __entry->tids)
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: %pM, tids: 0x%x",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer, __entry->tids)
);
TRACE_EVENT(rdev_set_sar_specs,
@@ -2881,8 +2877,8 @@ DECLARE_EVENT_CLASS(cfg80211_netdev_mac_evt,
NETDEV_ASSIGN;
MAC_ASSIGN(macaddr, macaddr);
),
- TP_printk(NETDEV_PR_FMT ", mac: " MAC_PR_FMT,
- NETDEV_PR_ARG, MAC_PR_ARG(macaddr))
+ TP_printk(NETDEV_PR_FMT ", mac: %pM",
+ NETDEV_PR_ARG, __entry->macaddr)
);
DEFINE_EVENT(cfg80211_netdev_mac_evt, cfg80211_notify_new_peer_candidate,
@@ -2920,8 +2916,8 @@ TRACE_EVENT(cfg80211_send_rx_assoc,
MAC_ASSIGN(ap_addr,
data->ap_mld_addr ?: data->links[0].bss->bssid);
),
- TP_printk(NETDEV_PR_FMT ", " MAC_PR_FMT,
- NETDEV_PR_ARG, MAC_PR_ARG(ap_addr))
+ TP_printk(NETDEV_PR_FMT ", %pM",
+ NETDEV_PR_ARG, __entry->ap_addr)
);
DECLARE_EVENT_CLASS(netdev_frame_event,
@@ -2981,8 +2977,8 @@ DECLARE_EVENT_CLASS(netdev_mac_evt,
NETDEV_ASSIGN;
MAC_ASSIGN(mac, mac)
),
- TP_printk(NETDEV_PR_FMT ", mac: " MAC_PR_FMT,
- NETDEV_PR_ARG, MAC_PR_ARG(mac))
+ TP_printk(NETDEV_PR_FMT ", mac: %pM",
+ NETDEV_PR_ARG, __entry->mac)
);
DEFINE_EVENT(netdev_mac_evt, cfg80211_send_auth_timeout,
@@ -3004,8 +3000,8 @@ TRACE_EVENT(cfg80211_send_assoc_failure,
MAC_ASSIGN(ap_addr, data->ap_mld_addr ?: data->bss[0]->bssid);
__entry->timeout = data->timeout;
),
- TP_printk(NETDEV_PR_FMT ", mac: " MAC_PR_FMT ", timeout: %d",
- NETDEV_PR_ARG, MAC_PR_ARG(ap_addr), __entry->timeout)
+ TP_printk(NETDEV_PR_FMT ", mac: %pM, timeout: %d",
+ NETDEV_PR_ARG, __entry->ap_addr, __entry->timeout)
);
TRACE_EVENT(cfg80211_michael_mic_failure,
@@ -3027,8 +3023,8 @@ TRACE_EVENT(cfg80211_michael_mic_failure,
if (tsc)
memcpy(__entry->tsc, tsc, 6);
),
- TP_printk(NETDEV_PR_FMT ", " MAC_PR_FMT ", key type: %d, key id: %d, tsc: %pm",
- NETDEV_PR_ARG, MAC_PR_ARG(addr), __entry->key_type,
+ TP_printk(NETDEV_PR_FMT ", %pM, key type: %d, key id: %d, tsc: %pm",
+ NETDEV_PR_ARG, __entry->addr, __entry->key_type,
__entry->key_id, __entry->tsc)
);
@@ -3104,8 +3100,8 @@ TRACE_EVENT(cfg80211_new_sta,
MAC_ASSIGN(mac_addr, mac_addr);
SINFO_ASSIGN;
),
- TP_printk(NETDEV_PR_FMT ", " MAC_PR_FMT,
- NETDEV_PR_ARG, MAC_PR_ARG(mac_addr))
+ TP_printk(NETDEV_PR_FMT ", %pM",
+ NETDEV_PR_ARG, __entry->mac_addr)
);
DEFINE_EVENT(cfg80211_netdev_mac_evt, cfg80211_del_sta,
@@ -3182,8 +3178,8 @@ TRACE_EVENT(cfg80211_rx_control_port,
__entry->proto = be16_to_cpu(skb->protocol);
__entry->unencrypted = unencrypted;
),
- TP_printk(NETDEV_PR_FMT ", len=%d, " MAC_PR_FMT ", proto: 0x%x, unencrypted: %s",
- NETDEV_PR_ARG, __entry->len, MAC_PR_ARG(from),
+ TP_printk(NETDEV_PR_FMT ", len=%d, %pM, proto: 0x%x, unencrypted: %s",
+ NETDEV_PR_ARG, __entry->len, __entry->from,
__entry->proto, BOOL_TO_STR(__entry->unencrypted))
);
@@ -3324,7 +3320,7 @@ DECLARE_EVENT_CLASS(cfg80211_rx_evt,
NETDEV_ASSIGN;
MAC_ASSIGN(addr, addr);
),
- TP_printk(NETDEV_PR_FMT ", " MAC_PR_FMT, NETDEV_PR_ARG, MAC_PR_ARG(addr))
+ TP_printk(NETDEV_PR_FMT ", %pM", NETDEV_PR_ARG, __entry->addr)
);
DEFINE_EVENT(cfg80211_rx_evt, cfg80211_rx_spurious_frame,
@@ -3351,8 +3347,8 @@ TRACE_EVENT(cfg80211_ibss_joined,
MAC_ASSIGN(bssid, bssid);
CHAN_ASSIGN(channel);
),
- TP_printk(NETDEV_PR_FMT ", bssid: " MAC_PR_FMT ", " CHAN_PR_FMT,
- NETDEV_PR_ARG, MAC_PR_ARG(bssid), CHAN_PR_ARG)
+ TP_printk(NETDEV_PR_FMT ", bssid: %pM, " CHAN_PR_FMT,
+ NETDEV_PR_ARG, __entry->bssid, CHAN_PR_ARG)
);
TRACE_EVENT(cfg80211_probe_status,
@@ -3371,8 +3367,8 @@ TRACE_EVENT(cfg80211_probe_status,
__entry->cookie = cookie;
__entry->acked = acked;
),
- TP_printk(NETDEV_PR_FMT " addr:" MAC_PR_FMT ", cookie: %llu, acked: %s",
- NETDEV_PR_ARG, MAC_PR_ARG(addr), __entry->cookie,
+ TP_printk(NETDEV_PR_FMT " addr:%pM, cookie: %llu, acked: %s",
+ NETDEV_PR_ARG, __entry->addr, __entry->cookie,
BOOL_TO_STR(__entry->acked))
);
@@ -3389,8 +3385,8 @@ TRACE_EVENT(cfg80211_cqm_pktloss_notify,
MAC_ASSIGN(peer, peer);
__entry->num_packets = num_packets;
),
- TP_printk(NETDEV_PR_FMT ", peer: " MAC_PR_FMT ", num of lost packets: %u",
- NETDEV_PR_ARG, MAC_PR_ARG(peer), __entry->num_packets)
+ TP_printk(NETDEV_PR_FMT ", peer: %pM, num of lost packets: %u",
+ NETDEV_PR_ARG, __entry->peer, __entry->num_packets)
);
DEFINE_EVENT(cfg80211_netdev_mac_evt, cfg80211_gtk_rekey_notify,
@@ -3414,8 +3410,8 @@ TRACE_EVENT(cfg80211_pmksa_candidate_notify,
MAC_ASSIGN(bssid, bssid);
__entry->preauth = preauth;
),
- TP_printk(NETDEV_PR_FMT ", index:%d, bssid: " MAC_PR_FMT ", pre auth: %s",
- NETDEV_PR_ARG, __entry->index, MAC_PR_ARG(bssid),
+ TP_printk(NETDEV_PR_FMT ", index:%d, bssid: %pM, pre auth: %s",
+ NETDEV_PR_ARG, __entry->index, __entry->bssid,
BOOL_TO_STR(__entry->preauth))
);
@@ -3455,8 +3451,8 @@ TRACE_EVENT(cfg80211_tdls_oper_request,
__entry->oper = oper;
__entry->reason_code = reason_code;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: " MAC_PR_FMT ", oper: %d, reason_code %u",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer), __entry->oper,
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: %pM, oper: %d, reason_code %u",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer, __entry->oper,
__entry->reason_code)
);
@@ -3494,10 +3490,10 @@ TRACE_EVENT(cfg80211_scan_done,
MAC_ASSIGN(tsf_bssid, info->tsf_bssid);
}
),
- TP_printk("aborted: %s, scan start (TSF): %llu, tsf_bssid: " MAC_PR_FMT,
+ TP_printk("aborted: %s, scan start (TSF): %llu, tsf_bssid: %pM",
BOOL_TO_STR(__entry->aborted),
(unsigned long long)__entry->scan_start_tsf,
- MAC_PR_ARG(tsf_bssid))
+ __entry->tsf_bssid)
);
DECLARE_EVENT_CLASS(wiphy_id_evt,
@@ -3546,9 +3542,9 @@ TRACE_EVENT(cfg80211_get_bss,
__entry->bss_type = bss_type;
__entry->privacy = privacy;
),
- TP_printk(WIPHY_PR_FMT ", " CHAN_PR_FMT ", " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " CHAN_PR_FMT ", %pM"
", buf: %#.2x, bss_type: %d, privacy: %d",
- WIPHY_PR_ARG, CHAN_PR_ARG, MAC_PR_ARG(bssid),
+ WIPHY_PR_ARG, CHAN_PR_ARG, __entry->bssid,
((u8 *)__get_dynamic_array(ssid))[0], __entry->bss_type,
__entry->privacy)
);
@@ -3579,11 +3575,11 @@ TRACE_EVENT(cfg80211_inform_bss_frame,
MAC_ASSIGN(parent_bssid, data->parent_bssid);
),
TP_printk(WIPHY_PR_FMT ", " CHAN_PR_FMT
- "(scan_width: %d) signal: %d, tsb:%llu, detect_tsf:%llu, tsf_bssid: "
- MAC_PR_FMT, WIPHY_PR_ARG, CHAN_PR_ARG, __entry->scan_width,
+ "(scan_width: %d) signal: %d, tsb:%llu, detect_tsf:%llu, tsf_bssid: %pM",
+ WIPHY_PR_ARG, CHAN_PR_ARG, __entry->scan_width,
__entry->signal, (unsigned long long)__entry->ts_boottime,
(unsigned long long)__entry->parent_tsf,
- MAC_PR_ARG(parent_bssid))
+ __entry->parent_bssid)
);
DECLARE_EVENT_CLASS(cfg80211_bss_evt,
@@ -3597,7 +3593,7 @@ DECLARE_EVENT_CLASS(cfg80211_bss_evt,
MAC_ASSIGN(bssid, pub->bssid);
CHAN_ASSIGN(pub->channel);
),
- TP_printk(MAC_PR_FMT ", " CHAN_PR_FMT, MAC_PR_ARG(bssid), CHAN_PR_ARG)
+ TP_printk("%pM, " CHAN_PR_FMT, __entry->bssid, CHAN_PR_ARG)
);
DEFINE_EVENT(cfg80211_bss_evt, cfg80211_return_bss,
@@ -3689,8 +3685,8 @@ TRACE_EVENT(cfg80211_ft_event,
memcpy(__get_dynamic_array(ric_ies), ft_event->ric_ies,
ft_event->ric_ies_len);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", target_ap: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(target_ap))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", target_ap: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->target_ap)
);
TRACE_EVENT(cfg80211_stop_iface,
@@ -3724,10 +3720,10 @@ TRACE_EVENT(cfg80211_pmsr_report,
__entry->cookie = cookie;
MAC_ASSIGN(addr, addr);
),
- TP_printk(WIPHY_PR_FMT ", " WDEV_PR_FMT ", cookie:%lld, " MAC_PR_FMT,
+ TP_printk(WIPHY_PR_FMT ", " WDEV_PR_FMT ", cookie:%lld, %pM",
WIPHY_PR_ARG, WDEV_PR_ARG,
(unsigned long long)__entry->cookie,
- MAC_PR_ARG(addr))
+ __entry->addr)
);
TRACE_EVENT(cfg80211_pmsr_complete,
@@ -3761,8 +3757,8 @@ TRACE_EVENT(cfg80211_update_owe_info_event,
MAC_ASSIGN(peer, owe_info->peer);
memcpy(__get_dynamic_array(ie), owe_info->ie,
owe_info->ie_len);),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: " MAC_PR_FMT,
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(peer))
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", peer: %pM",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer)
);
TRACE_EVENT(cfg80211_bss_color_notify,
@@ -3800,8 +3796,8 @@ TRACE_EVENT(cfg80211_assoc_comeback,
MAC_ASSIGN(ap_addr, ap_addr);
__entry->timeout = timeout;
),
- TP_printk(WDEV_PR_FMT ", " MAC_PR_FMT ", timeout: %u TUs",
- WDEV_PR_ARG, MAC_PR_ARG(ap_addr), __entry->timeout)
+ TP_printk(WDEV_PR_FMT ", %pM, timeout: %u TUs",
+ WDEV_PR_ARG, __entry->ap_addr, __entry->timeout)
);
DECLARE_EVENT_CLASS(link_station_add_mod,
@@ -3859,10 +3855,10 @@ DECLARE_EVENT_CLASS(link_station_add_mod,
memcpy(__get_dynamic_array(eht_capa), params->eht_capa,
params->eht_capa_len);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: " MAC_PR_FMT
- ", link mac: " MAC_PR_FMT ", link id: %u",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(mld_mac),
- MAC_PR_ARG(link_mac), __entry->link_id)
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: %pM"
+ ", link mac: %pM, link id: %u",
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->mld_mac,
+ __entry->link_mac, __entry->link_id)
);
DEFINE_EVENT(link_station_add_mod, rdev_add_link_station,
@@ -3895,9 +3891,9 @@ TRACE_EVENT(rdev_del_link_station,
memcpy(__entry->mld_mac, params->mld_mac, 6);
__entry->link_id = params->link_id;
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: " MAC_PR_FMT
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", station mac: %pM"
", link id: %u",
- WIPHY_PR_ARG, NETDEV_PR_ARG, MAC_PR_ARG(mld_mac),
+ WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->mld_mac,
__entry->link_id)
);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 632/982] wifi: cfg80211: make TDLS management link-aware
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (630 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 631/982] wifi: cfg80211: trace: remove MAC_PR_{FMT,ARG} Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 633/982] wifi: mac80211: handle TDLS negotiation with MLO Greg Kroah-Hartman
` (356 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mukesh Sisodiya, Gregory Greenman,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Sisodiya <mukesh.sisodiya@intel.com>
[ Upstream commit c6112046b1a9c130c455ab0bbe74c3f41138693c ]
For multi-link operation(MLO) TDLS management
frames need to be transmitted on a specific link.
The TDLS setup request will add BSSID along with
peer address and userspace will pass the link-id
based on BSSID value to the driver(or mac80211).
Signed-off-by: Mukesh Sisodiya <mukesh.sisodiya@intel.com>
Signed-off-by: Gregory Greenman <gregory.greenman@intel.com>
Link: https://lore.kernel.org/r/20230616094948.cb3d87c22812.Ia3d15ac4a9a182145bf2d418bcb3ddf4539cd0a7@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 038e1d126304 ("wifi: mac80211: require a peer station for TDLS setup confirm")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/mwifiex/cfg80211.c | 8 ++++----
include/net/cfg80211.h | 7 ++++---
net/mac80211/ieee80211_i.h | 8 ++++----
net/mac80211/tdls.c | 10 +++++-----
net/wireless/nl80211.c | 7 +++++--
net/wireless/rdev-ops.h | 15 ++++++++-------
net/wireless/trace.h | 13 ++++++++-----
7 files changed, 38 insertions(+), 30 deletions(-)
diff --git a/drivers/net/wireless/marvell/mwifiex/cfg80211.c b/drivers/net/wireless/marvell/mwifiex/cfg80211.c
index 3b9b75eb4cdb8..8744a9a3eb6b5 100644
--- a/drivers/net/wireless/marvell/mwifiex/cfg80211.c
+++ b/drivers/net/wireless/marvell/mwifiex/cfg80211.c
@@ -3756,10 +3756,10 @@ static int mwifiex_cfg80211_set_coalesce(struct wiphy *wiphy,
*/
static int
mwifiex_cfg80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
- u16 status_code, u32 peer_capability,
- bool initiator, const u8 *extra_ies,
- size_t extra_ies_len)
+ const u8 *peer, int link_id, u8 action_code,
+ u8 dialog_token, u16 status_code,
+ u32 peer_capability, bool initiator,
+ const u8 *extra_ies, size_t extra_ies_len)
{
struct mwifiex_private *priv = mwifiex_netdev_get_priv(dev);
int ret;
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index 90aad35cccc10..297a88a4e14e6 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -4544,9 +4544,10 @@ struct cfg80211_ops {
struct cfg80211_gtk_rekey_data *data);
int (*tdls_mgmt)(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
- u16 status_code, u32 peer_capability,
- bool initiator, const u8 *buf, size_t len);
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token, u16 status_code,
+ u32 peer_capability, bool initiator,
+ const u8 *buf, size_t len);
int (*tdls_oper)(struct wiphy *wiphy, struct net_device *dev,
const u8 *peer, enum nl80211_tdls_operation oper);
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index 2f437ddd8f1ed..5c3993f611625 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -2519,10 +2519,10 @@ void ieee80211_recalc_chanctx_chantype(struct ieee80211_local *local,
/* TDLS */
int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
- u16 status_code, u32 peer_capability,
- bool initiator, const u8 *extra_ies,
- size_t extra_ies_len);
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token, u16 status_code,
+ u32 peer_capability, bool initiator,
+ const u8 *extra_ies, size_t extra_ies_len);
int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
const u8 *peer, enum nl80211_tdls_operation oper);
void ieee80211_tdls_peer_del_work(struct wiphy *wiphy, struct wiphy_work *wk);
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index 57bd4fc8d2375..e54442471c45a 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -6,7 +6,7 @@
* Copyright 2014, Intel Corporation
* Copyright 2014 Intel Mobile Communications GmbH
* Copyright 2015 - 2016 Intel Deutschland GmbH
- * Copyright (C) 2019, 2021-2022 Intel Corporation
+ * Copyright (C) 2019, 2021-2023 Intel Corporation
*/
#include <linux/ieee80211.h>
@@ -1186,10 +1186,10 @@ ieee80211_tdls_mgmt_teardown(struct wiphy *wiphy, struct net_device *dev,
}
int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
- u16 status_code, u32 peer_capability,
- bool initiator, const u8 *extra_ies,
- size_t extra_ies_len)
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token, u16 status_code,
+ u32 peer_capability, bool initiator,
+ const u8 *extra_ies, size_t extra_ies_len)
{
struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
int ret;
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index aa85e2e063bbc..d749fa91f399b 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -12221,6 +12221,7 @@ static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
u32 peer_capability = 0;
u16 status_code;
u8 *peer;
+ int link_id;
bool initiator;
if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
@@ -12242,8 +12243,9 @@ static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
peer_capability =
nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
+ link_id = nl80211_link_id_or_invalid(info->attrs);
- return rdev_tdls_mgmt(rdev, dev, peer, action_code,
+ return rdev_tdls_mgmt(rdev, dev, peer, link_id, action_code,
dialog_token, status_code, peer_capability,
initiator,
nla_data(info->attrs[NL80211_ATTR_IE]),
@@ -17118,7 +17120,8 @@ static const struct genl_small_ops nl80211_small_ops[] = {
.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
.doit = nl80211_tdls_mgmt,
.flags = GENL_UNS_ADMIN_PERM,
- .internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
+ .internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
+ NL80211_FLAG_MLO_VALID_LINK_ID),
},
{
.cmd = NL80211_CMD_TDLS_OPER,
diff --git a/net/wireless/rdev-ops.h b/net/wireless/rdev-ops.h
index df7f88ca0db38..db6d91c905603 100644
--- a/net/wireless/rdev-ops.h
+++ b/net/wireless/rdev-ops.h
@@ -903,17 +903,18 @@ static inline int rdev_set_rekey_data(struct cfg80211_registered_device *rdev,
static inline int rdev_tdls_mgmt(struct cfg80211_registered_device *rdev,
struct net_device *dev, u8 *peer,
- u8 action_code, u8 dialog_token,
- u16 status_code, u32 peer_capability,
- bool initiator, const u8 *buf, size_t len)
+ int link_id, u8 action_code,
+ u8 dialog_token, u16 status_code,
+ u32 peer_capability, bool initiator,
+ const u8 *buf, size_t len)
{
int ret;
- trace_rdev_tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
+ trace_rdev_tdls_mgmt(&rdev->wiphy, dev, peer, link_id, action_code,
dialog_token, status_code, peer_capability,
initiator, buf, len);
- ret = rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
- dialog_token, status_code, peer_capability,
- initiator, buf, len);
+ ret = rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, link_id,
+ action_code, dialog_token, status_code,
+ peer_capability, initiator, buf, len);
trace_rdev_return_int(&rdev->wiphy, ret);
return ret;
}
diff --git a/net/wireless/trace.h b/net/wireless/trace.h
index da03b6ff71b2a..73e388cd32fee 100644
--- a/net/wireless/trace.h
+++ b/net/wireless/trace.h
@@ -1779,15 +1779,16 @@ DEFINE_EVENT(wiphy_netdev_id_evt, rdev_sched_scan_stop,
TRACE_EVENT(rdev_tdls_mgmt,
TP_PROTO(struct wiphy *wiphy, struct net_device *netdev,
- u8 *peer, u8 action_code, u8 dialog_token,
+ u8 *peer, int link_id, u8 action_code, u8 dialog_token,
u16 status_code, u32 peer_capability,
bool initiator, const u8 *buf, size_t len),
- TP_ARGS(wiphy, netdev, peer, action_code, dialog_token, status_code,
- peer_capability, initiator, buf, len),
+ TP_ARGS(wiphy, netdev, peer, link_id, action_code, dialog_token,
+ status_code, peer_capability, initiator, buf, len),
TP_STRUCT__entry(
WIPHY_ENTRY
NETDEV_ENTRY
MAC_ENTRY(peer)
+ __field(int, link_id)
__field(u8, action_code)
__field(u8, dialog_token)
__field(u16, status_code)
@@ -1799,6 +1800,7 @@ TRACE_EVENT(rdev_tdls_mgmt,
WIPHY_ASSIGN;
NETDEV_ASSIGN;
MAC_ASSIGN(peer, peer);
+ __entry->link_id = link_id;
__entry->action_code = action_code;
__entry->dialog_token = dialog_token;
__entry->status_code = status_code;
@@ -1806,11 +1808,12 @@ TRACE_EVENT(rdev_tdls_mgmt,
__entry->initiator = initiator;
memcpy(__get_dynamic_array(buf), buf, len);
),
- TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM, action_code: %u, "
+ TP_printk(WIPHY_PR_FMT ", " NETDEV_PR_FMT ", %pM"
+ ", link_id: %d, action_code: %u "
"dialog_token: %u, status_code: %u, peer_capability: %u "
"initiator: %s buf: %#.2x ",
WIPHY_PR_ARG, NETDEV_PR_ARG, __entry->peer,
- __entry->action_code, __entry->dialog_token,
+ __entry->link_id, __entry->action_code, __entry->dialog_token,
__entry->status_code, __entry->peer_capability,
BOOL_TO_STR(__entry->initiator),
((u8 *)__get_dynamic_array(buf))[0])
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 633/982] wifi: mac80211: handle TDLS negotiation with MLO
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (631 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 632/982] wifi: cfg80211: make TDLS management link-aware Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 634/982] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
` (355 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mukesh Sisodiya, Gregory Greenman,
Benjamin Berg, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Sisodiya <mukesh.sisodiya@intel.com>
[ Upstream commit 78a7ea370d5f0eb6f3e774e7f6afece1c3a6860f ]
Userspace can now select the link to use for TDLS management
frames (indicating e.g. which BSSID should be used), use the
link_id received from cfg80211 to build the frames.
Signed-off-by: Mukesh Sisodiya <mukesh.sisodiya@intel.com>
Signed-off-by: Gregory Greenman <gregory.greenman@intel.com>
Link: https://lore.kernel.org/r/20230616094948.ce1fc230b505.Ie773c5679805001f5a52680d68d9ce0232c57648@changeid
[Benjamin fixed some locking]
Co-developed-by: Benjamin Berg <benjamin.berg@intel.com>
Signed-off-by: Benjamin Berg <benjamin.berg@intel.com>
[fix sta mutex locking too]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 038e1d126304 ("wifi: mac80211: require a peer station for TDLS setup confirm")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tdls.c | 163 +++++++++++++++++++++++++-------------------
1 file changed, 91 insertions(+), 72 deletions(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index e54442471c45a..708e7fb1b218a 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -39,9 +39,10 @@ void ieee80211_tdls_peer_del_work(struct wiphy *wiphy, struct wiphy_work *wk)
mutex_unlock(&local->mtx);
}
-static void ieee80211_tdls_add_ext_capab(struct ieee80211_sub_if_data *sdata,
+static void ieee80211_tdls_add_ext_capab(struct ieee80211_link_data *link,
struct sk_buff *skb)
{
+ struct ieee80211_sub_if_data *sdata = link->sdata;
struct ieee80211_local *local = sdata->local;
struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
bool chan_switch = local->hw.wiphy->features &
@@ -50,7 +51,7 @@ static void ieee80211_tdls_add_ext_capab(struct ieee80211_sub_if_data *sdata,
!ifmgd->tdls_wider_bw_prohibited;
bool buffer_sta = ieee80211_hw_check(&local->hw,
SUPPORTS_TDLS_BUFFER_STA);
- struct ieee80211_supported_band *sband = ieee80211_get_sband(sdata);
+ struct ieee80211_supported_band *sband = ieee80211_get_link_sband(link);
bool vht = sband && sband->vht_cap.vht_supported;
u8 *pos = skb_put(skb, 10);
@@ -152,13 +153,13 @@ ieee80211_tdls_add_supp_channels(struct ieee80211_sub_if_data *sdata,
*pos = 2 * subband_cnt;
}
-static void ieee80211_tdls_add_oper_classes(struct ieee80211_sub_if_data *sdata,
+static void ieee80211_tdls_add_oper_classes(struct ieee80211_link_data *link,
struct sk_buff *skb)
{
u8 *pos;
u8 op_class;
- if (!ieee80211_chandef_to_operating_class(&sdata->vif.bss_conf.chandef,
+ if (!ieee80211_chandef_to_operating_class(&link->conf->chandef,
&op_class))
return;
@@ -180,7 +181,7 @@ static void ieee80211_tdls_add_bss_coex_ie(struct sk_buff *skb)
*pos++ = WLAN_BSS_COEX_INFORMATION_REQUEST;
}
-static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_sub_if_data *sdata,
+static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_link_data *link,
u16 status_code)
{
struct ieee80211_supported_band *sband;
@@ -189,7 +190,8 @@ static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_sub_if_data *sdata,
if (status_code != 0)
return 0;
- sband = ieee80211_get_sband(sdata);
+ sband = ieee80211_get_link_sband(link);
+
if (sband && sband->band == NL80211_BAND_2GHZ) {
return WLAN_CAPABILITY_SHORT_SLOT_TIME |
WLAN_CAPABILITY_SHORT_PREAMBLE;
@@ -198,10 +200,11 @@ static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_sub_if_data *sdata,
return 0;
}
-static void ieee80211_tdls_add_link_ie(struct ieee80211_sub_if_data *sdata,
+static void ieee80211_tdls_add_link_ie(struct ieee80211_link_data *link,
struct sk_buff *skb, const u8 *peer,
bool initiator)
{
+ struct ieee80211_sub_if_data *sdata = link->sdata;
struct ieee80211_tdls_lnkie *lnkid;
const u8 *init_addr, *rsp_addr;
@@ -218,7 +221,7 @@ static void ieee80211_tdls_add_link_ie(struct ieee80211_sub_if_data *sdata,
lnkid->ie_type = WLAN_EID_LINK_ID;
lnkid->ie_len = sizeof(struct ieee80211_tdls_lnkie) - 2;
- memcpy(lnkid->bssid, sdata->deflink.u.mgd.bssid, ETH_ALEN);
+ memcpy(lnkid->bssid, link->u.mgd.bssid, ETH_ALEN);
memcpy(lnkid->init_sta, init_addr, ETH_ALEN);
memcpy(lnkid->resp_sta, rsp_addr, ETH_ALEN);
}
@@ -359,11 +362,12 @@ ieee80211_tdls_chandef_vht_upgrade(struct ieee80211_sub_if_data *sdata,
}
static void
-ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
+ieee80211_tdls_add_setup_start_ies(struct ieee80211_link_data *link,
struct sk_buff *skb, const u8 *peer,
u8 action_code, bool initiator,
const u8 *extra_ies, size_t extra_ies_len)
{
+ struct ieee80211_sub_if_data *sdata = link->sdata;
struct ieee80211_supported_band *sband;
struct ieee80211_local *local = sdata->local;
struct ieee80211_sta_ht_cap ht_cap;
@@ -372,8 +376,8 @@ ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
size_t offset = 0, noffset;
u8 *pos;
- sband = ieee80211_get_sband(sdata);
- if (!sband)
+ sband = ieee80211_get_link_sband(link);
+ if (WARN_ON_ONCE(!sband))
return;
ieee80211_add_srates_ie(sdata, skb, false, sband->band);
@@ -397,7 +401,7 @@ ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
offset = noffset;
}
- ieee80211_tdls_add_ext_capab(sdata, skb);
+ ieee80211_tdls_add_ext_capab(link, skb);
/* add the QoS element if we support it */
if (local->hw.queues >= IEEE80211_NUM_ACS &&
@@ -426,20 +430,16 @@ ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
offset = noffset;
}
- mutex_lock(&local->sta_mtx);
-
/* we should have the peer STA if we're already responding */
if (action_code == WLAN_TDLS_SETUP_RESPONSE) {
sta = sta_info_get(sdata, peer);
- if (WARN_ON_ONCE(!sta)) {
- mutex_unlock(&local->sta_mtx);
+ if (WARN_ON_ONCE(!sta))
return;
- }
- sta->tdls_chandef = sdata->vif.bss_conf.chandef;
+ sta->tdls_chandef = link->conf->chandef;
}
- ieee80211_tdls_add_oper_classes(sdata, skb);
+ ieee80211_tdls_add_oper_classes(link, skb);
/*
* with TDLS we can switch channels, and HT-caps are not necessarily
@@ -472,7 +472,7 @@ ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
(ht_cap.cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40))
ieee80211_tdls_add_bss_coex_ie(skb);
- ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
+ ieee80211_tdls_add_link_ie(link, skb, peer, initiator);
/* add any custom IEs that go before VHT capabilities */
if (extra_ies_len) {
@@ -529,8 +529,6 @@ ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
}
- mutex_unlock(&local->sta_mtx);
-
/* add any remaining IEs */
if (extra_ies_len) {
noffset = extra_ies_len;
@@ -540,31 +538,29 @@ ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
}
static void
-ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
+ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_link_data *link,
struct sk_buff *skb, const u8 *peer,
bool initiator, const u8 *extra_ies,
size_t extra_ies_len)
{
+ struct ieee80211_sub_if_data *sdata = link->sdata;
struct ieee80211_local *local = sdata->local;
size_t offset = 0, noffset;
struct sta_info *sta, *ap_sta;
struct ieee80211_supported_band *sband;
u8 *pos;
- sband = ieee80211_get_sband(sdata);
- if (!sband)
+ sband = ieee80211_get_link_sband(link);
+ if (WARN_ON_ONCE(!sband))
return;
- mutex_lock(&local->sta_mtx);
-
sta = sta_info_get(sdata, peer);
- ap_sta = sta_info_get(sdata, sdata->deflink.u.mgd.bssid);
- if (WARN_ON_ONCE(!sta || !ap_sta)) {
- mutex_unlock(&local->sta_mtx);
+ ap_sta = sta_info_get(sdata, sdata->vif.cfg.ap_addr);
+
+ if (WARN_ON_ONCE(!sta || !ap_sta))
return;
- }
- sta->tdls_chandef = sdata->vif.bss_conf.chandef;
+ sta->tdls_chandef = link->conf->chandef;
/* add any custom IEs that go before the QoS IE */
if (extra_ies_len) {
@@ -610,11 +606,11 @@ ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
pos = skb_put(skb, 2 + sizeof(struct ieee80211_ht_operation));
ieee80211_ie_build_ht_oper(pos, &sta->sta.deflink.ht_cap,
- &sdata->vif.bss_conf.chandef, prot,
+ &link->conf->chandef, prot,
true);
}
- ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
+ ieee80211_tdls_add_link_ie(link, skb, peer, initiator);
/* only include VHT-operation if not on the 2.4GHz band */
if (sband->band != NL80211_BAND_2GHZ &&
@@ -631,8 +627,6 @@ ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
&sta->tdls_chandef);
}
- mutex_unlock(&local->sta_mtx);
-
/* add any remaining IEs */
if (extra_ies_len) {
noffset = extra_ies_len;
@@ -641,7 +635,7 @@ ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
}
static void
-ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_sub_if_data *sdata,
+ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_link_data *link,
struct sk_buff *skb, const u8 *peer,
bool initiator, const u8 *extra_ies,
size_t extra_ies_len, u8 oper_class,
@@ -670,7 +664,7 @@ ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_sub_if_data *sdata,
offset = noffset;
}
- ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
+ ieee80211_tdls_add_link_ie(link, skb, peer, initiator);
/* add any remaining IEs */
if (extra_ies_len) {
@@ -680,20 +674,20 @@ ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_sub_if_data *sdata,
}
static void
-ieee80211_tdls_add_chan_switch_resp_ies(struct ieee80211_sub_if_data *sdata,
+ieee80211_tdls_add_chan_switch_resp_ies(struct ieee80211_link_data *link,
struct sk_buff *skb, const u8 *peer,
u16 status_code, bool initiator,
const u8 *extra_ies,
size_t extra_ies_len)
{
if (status_code == 0)
- ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
+ ieee80211_tdls_add_link_ie(link, skb, peer, initiator);
if (extra_ies_len)
skb_put_data(skb, extra_ies, extra_ies_len);
}
-static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
+static void ieee80211_tdls_add_ies(struct ieee80211_link_data *link,
struct sk_buff *skb, const u8 *peer,
u8 action_code, u16 status_code,
bool initiator, const u8 *extra_ies,
@@ -705,7 +699,8 @@ static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
case WLAN_TDLS_SETUP_RESPONSE:
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
if (status_code == 0)
- ieee80211_tdls_add_setup_start_ies(sdata, skb, peer,
+ ieee80211_tdls_add_setup_start_ies(link,
+ skb, peer,
action_code,
initiator,
extra_ies,
@@ -713,7 +708,7 @@ static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
break;
case WLAN_TDLS_SETUP_CONFIRM:
if (status_code == 0)
- ieee80211_tdls_add_setup_cfm_ies(sdata, skb, peer,
+ ieee80211_tdls_add_setup_cfm_ies(link, skb, peer,
initiator, extra_ies,
extra_ies_len);
break;
@@ -722,16 +717,17 @@ static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
if (extra_ies_len)
skb_put_data(skb, extra_ies, extra_ies_len);
if (status_code == 0 || action_code == WLAN_TDLS_TEARDOWN)
- ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
+ ieee80211_tdls_add_link_ie(link, skb,
+ peer, initiator);
break;
case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
- ieee80211_tdls_add_chan_switch_req_ies(sdata, skb, peer,
+ ieee80211_tdls_add_chan_switch_req_ies(link, skb, peer,
initiator, extra_ies,
extra_ies_len,
oper_class, chandef);
break;
case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
- ieee80211_tdls_add_chan_switch_resp_ies(sdata, skb, peer,
+ ieee80211_tdls_add_chan_switch_resp_ies(link, skb, peer,
status_code,
initiator, extra_ies,
extra_ies_len);
@@ -742,6 +738,7 @@ static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
static int
ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
+ struct ieee80211_link_data *link,
const u8 *peer, u8 action_code, u8 dialog_token,
u16 status_code, struct sk_buff *skb)
{
@@ -766,7 +763,7 @@ ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
skb_put(skb, sizeof(tf->u.setup_req));
tf->u.setup_req.dialog_token = dialog_token;
tf->u.setup_req.capability =
- cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
+ cpu_to_le16(ieee80211_get_tdls_sta_capab(link,
status_code));
break;
case WLAN_TDLS_SETUP_RESPONSE:
@@ -777,7 +774,7 @@ ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
tf->u.setup_resp.status_code = cpu_to_le16(status_code);
tf->u.setup_resp.dialog_token = dialog_token;
tf->u.setup_resp.capability =
- cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
+ cpu_to_le16(ieee80211_get_tdls_sta_capab(link,
status_code));
break;
case WLAN_TDLS_SETUP_CONFIRM:
@@ -824,7 +821,8 @@ ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
static int
ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
+ const u8 *peer, struct ieee80211_link_data *link,
+ u8 action_code, u8 dialog_token,
u16 status_code, struct sk_buff *skb)
{
struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
@@ -833,8 +831,7 @@ ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
mgmt = skb_put_zero(skb, 24);
memcpy(mgmt->da, peer, ETH_ALEN);
memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
- memcpy(mgmt->bssid, sdata->deflink.u.mgd.bssid, ETH_ALEN);
-
+ memcpy(mgmt->bssid, link->u.mgd.bssid, ETH_ALEN);
mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
IEEE80211_STYPE_ACTION);
@@ -847,7 +844,7 @@ ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
mgmt->u.action.u.tdls_discover_resp.dialog_token =
dialog_token;
mgmt->u.action.u.tdls_discover_resp.capability =
- cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
+ cpu_to_le16(ieee80211_get_tdls_sta_capab(link,
status_code));
break;
default:
@@ -859,15 +856,23 @@ ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
static struct sk_buff *
ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
- const u8 *peer, u8 action_code,
- u8 dialog_token, u16 status_code,
- bool initiator, const u8 *extra_ies,
- size_t extra_ies_len, u8 oper_class,
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token,
+ u16 status_code, bool initiator,
+ const u8 *extra_ies, size_t extra_ies_len,
+ u8 oper_class,
struct cfg80211_chan_def *chandef)
{
struct ieee80211_local *local = sdata->local;
struct sk_buff *skb;
int ret;
+ struct ieee80211_link_data *link;
+
+ link_id = link_id >= 0 ? link_id : 0;
+ rcu_read_lock();
+ link = rcu_dereference(sdata->link[link_id]);
+ if (WARN_ON(!link))
+ goto unlock;
skb = netdev_alloc_skb(sdata->dev,
local->hw.extra_tx_headroom +
@@ -887,7 +892,7 @@ ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
extra_ies_len +
sizeof(struct ieee80211_tdls_lnkie));
if (!skb)
- return NULL;
+ goto unlock;
skb_reserve(skb, local->hw.extra_tx_headroom);
@@ -900,13 +905,13 @@ ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
ret = ieee80211_prep_tdls_encap_data(local->hw.wiphy,
- sdata->dev, peer,
+ sdata->dev, link, peer,
action_code, dialog_token,
status_code, skb);
break;
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
ret = ieee80211_prep_tdls_direct(local->hw.wiphy, sdata->dev,
- peer, action_code,
+ peer, link, action_code,
dialog_token, status_code,
skb);
break;
@@ -918,19 +923,23 @@ ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
if (ret < 0)
goto fail;
- ieee80211_tdls_add_ies(sdata, skb, peer, action_code, status_code,
+ ieee80211_tdls_add_ies(link, skb, peer, action_code, status_code,
initiator, extra_ies, extra_ies_len, oper_class,
chandef);
+ rcu_read_unlock();
return skb;
fail:
dev_kfree_skb(skb);
+unlock:
+ rcu_read_unlock();
return NULL;
}
static int
ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token,
u16 status_code, u32 peer_capability,
bool initiator, const u8 *extra_ies,
size_t extra_ies_len, u8 oper_class,
@@ -988,7 +997,8 @@ ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
if (ret < 0)
goto fail;
- skb = ieee80211_tdls_build_mgmt_packet_data(sdata, peer, action_code,
+ skb = ieee80211_tdls_build_mgmt_packet_data(sdata, peer,
+ link_id, action_code,
dialog_token, status_code,
initiator, extra_ies,
extra_ies_len, oper_class,
@@ -999,7 +1009,7 @@ ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
}
if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
- ieee80211_tx_skb(sdata, skb);
+ ieee80211_tx_skb_tid(sdata, skb, 7, link_id);
return 0;
}
@@ -1067,7 +1077,8 @@ ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
static int
ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token,
u16 status_code, u32 peer_capability, bool initiator,
const u8 *extra_ies, size_t extra_ies_len)
{
@@ -1116,7 +1127,8 @@ ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
mutex_unlock(&local->mtx);
/* we cannot take the mutex while preparing the setup packet */
- ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
+ ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
+ link_id, action_code,
dialog_token, status_code,
peer_capability, initiator,
extra_ies, extra_ies_len, 0,
@@ -1140,7 +1152,8 @@ ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
static int
ieee80211_tdls_mgmt_teardown(struct wiphy *wiphy, struct net_device *dev,
- const u8 *peer, u8 action_code, u8 dialog_token,
+ const u8 *peer, int link_id,
+ u8 action_code, u8 dialog_token,
u16 status_code, u32 peer_capability,
bool initiator, const u8 *extra_ies,
size_t extra_ies_len)
@@ -1160,7 +1173,8 @@ ieee80211_tdls_mgmt_teardown(struct wiphy *wiphy, struct net_device *dev,
IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
ieee80211_flush_queues(local, sdata, false);
- ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
+ ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
+ link_id, action_code,
dialog_token, status_code,
peer_capability, initiator,
extra_ies, extra_ies_len, 0,
@@ -1205,13 +1219,14 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
switch (action_code) {
case WLAN_TDLS_SETUP_REQUEST:
case WLAN_TDLS_SETUP_RESPONSE:
- ret = ieee80211_tdls_mgmt_setup(wiphy, dev, peer, action_code,
+ ret = ieee80211_tdls_mgmt_setup(wiphy, dev, peer,
+ link_id, action_code,
dialog_token, status_code,
peer_capability, initiator,
extra_ies, extra_ies_len);
break;
case WLAN_TDLS_TEARDOWN:
- ret = ieee80211_tdls_mgmt_teardown(wiphy, dev, peer,
+ ret = ieee80211_tdls_mgmt_teardown(wiphy, dev, peer, link_id,
action_code, dialog_token,
status_code,
peer_capability, initiator,
@@ -1229,7 +1244,7 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
/* no special handling */
ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
- action_code,
+ link_id, action_code,
dialog_token,
status_code,
peer_capability,
@@ -1241,8 +1256,8 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
break;
}
- tdls_dbg(sdata, "TDLS mgmt action %d peer %pM status %d\n",
- action_code, peer, ret);
+ tdls_dbg(sdata, "TDLS mgmt action %d peer %pM link_id %d status %d\n",
+ action_code, peer, link_id, ret);
return ret;
}
@@ -1499,6 +1514,7 @@ ieee80211_tdls_ch_sw_tmpl_get(struct sta_info *sta, u8 oper_class,
int extra_ies_len = 2 + sizeof(struct ieee80211_ch_switch_timing);
u8 *pos = extra_ies;
struct sk_buff *skb;
+ int link_id = sta->sta.valid_links ? ffs(sta->sta.valid_links) - 1 : 0;
/*
* if chandef points to a wide channel add a Secondary-Channel
@@ -1526,6 +1542,7 @@ ieee80211_tdls_ch_sw_tmpl_get(struct sta_info *sta, u8 oper_class,
iee80211_tdls_add_ch_switch_timing(pos, 0, 0);
skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
+ link_id,
WLAN_TDLS_CHANNEL_SWITCH_REQUEST,
0, 0, !sta->sta.tdls_initiator,
extra_ies, extra_ies_len,
@@ -1646,11 +1663,13 @@ ieee80211_tdls_ch_sw_resp_tmpl_get(struct sta_info *sta,
struct ieee80211_sub_if_data *sdata = sta->sdata;
struct sk_buff *skb;
u8 extra_ies[2 + sizeof(struct ieee80211_ch_switch_timing)];
+ int link_id = sta->sta.valid_links ? ffs(sta->sta.valid_links) - 1 : 0;
/* initial timing are always zero in the template */
iee80211_tdls_add_ch_switch_timing(extra_ies, 0, 0);
skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
+ link_id,
WLAN_TDLS_CHANNEL_SWITCH_RESPONSE,
0, 0, !sta->sta.tdls_initiator,
extra_ies, sizeof(extra_ies), 0, NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 634/982] wifi: mac80211: require a peer station for TDLS setup confirm
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (632 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 633/982] wifi: mac80211: handle TDLS negotiation with MLO Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 635/982] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
` (354 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+e55106f8389651870be0,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 038e1d126304fd25d507fd4e671232df57bd1799 ]
It's nonsense for the setup confirm to go to station that
doesn't even exist, and it hits a warning when building
the frame:
WARN_ON_ONCE(!sta || !ap_sta)
Only accept WLAN_TDLS_SETUP_CONFIRM when the station is
already there as a TDLS station. Need to copy the call
to ieee80211_tdls_prep_mgmt_packet() since the existing
WLAN_TDLS_DISCOVERY_REQUEST already falls through to it.
Assisted-by: LLM
Fixes: 6f7eaa47e1de ("mac80211: add TDLS QoS param IE on setup-confirm")
Reported-by: syzbot+e55106f8389651870be0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e55106f8389651870be0
Link: https://patch.msgid.link/20260908122838.201719-15-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tdls.c | 19 ++++++++++++++++++-
1 file changed, 18 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index 708e7fb1b218a..b25aed68dc8a8 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -1232,6 +1232,24 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
peer_capability, initiator,
extra_ies, extra_ies_len);
break;
+ case WLAN_TDLS_SETUP_CONFIRM: {
+ struct sta_info *sta;
+
+ sta = sta_info_get(sdata, peer);
+ if (!sta || !sta->sta.tdls) {
+ ret = -ENOLINK;
+ break;
+ }
+
+ ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
+ link_id, action_code,
+ dialog_token,
+ status_code,
+ peer_capability,
+ initiator, extra_ies,
+ extra_ies_len, 0, NULL);
+ break;
+ }
case WLAN_TDLS_DISCOVERY_REQUEST:
/*
* Protect the discovery so we can hear the TDLS discovery
@@ -1240,7 +1258,6 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
*/
drv_mgd_protect_tdls_discover(sdata->local, sdata);
fallthrough;
- case WLAN_TDLS_SETUP_CONFIRM:
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
/* no special handling */
ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 635/982] wifi: mac80211: dont allow link changes when iface is down
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (633 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 634/982] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 636/982] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
` (353 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+582469b3a9ef5f13606b,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 370872d30349d81dec519e15ea2949fd63511cf7 ]
ieee80211_set_active_links() only checks that the interface is running in
the inner __ieee80211_set_active_links(), after drv_can_activate_links()
was already called, so using active_links on an interface that's down
triggers the check-sdata-in-driver warning.
Add the missing check in the debugfs file.
Assisted-by: LLM
Fixes: 3d9011029227 ("wifi: mac80211: implement link switching")
Reported-by: syzbot+582469b3a9ef5f13606b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=582469b3a9ef5f13606b
Link: https://patch.msgid.link/20260908122838.201719-16-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index f8416965c2198..6b4b5e0a19570 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -591,6 +591,9 @@ static ssize_t ieee80211_if_parse_active_links(struct ieee80211_sub_if_data *sda
if (kstrtou16(buf, 0, &active_links) || !active_links)
return -EINVAL;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
return ieee80211_set_active_links(&sdata->vif, active_links) ?: buflen;
}
IEEE80211_IF_FILE_RW(active_links);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 636/982] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (634 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 635/982] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 637/982] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
` (352 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b59873f5699e941717ca,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b481e64e4498e2c053d5954f546ee02338f6ab63 ]
In the error path of ieee80211_mesh_csa_beacon() the settings that were
just assigned are read back with rcu_dereference(), which lockdep then
complains about.
There's no need to read the pointer at all, tmp_csa_settings still is
the right value anyway.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+b59873f5699e941717ca@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b59873f5699e941717ca
Link: https://patch.msgid.link/20260908122838.201719-17-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index 1b928cd4545aa..79569c6fbbd05 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1417,7 +1417,6 @@ int ieee80211_mesh_csa_beacon(struct ieee80211_sub_if_data *sdata,
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret) {
- tmp_csa_settings = rcu_dereference(ifmsh->csa);
RCU_INIT_POINTER(ifmsh->csa, NULL);
kfree_rcu(tmp_csa_settings, rcu_head);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 637/982] wifi: mac80211: dont access the TSF of a down interface
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (635 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 636/982] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 638/982] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
` (351 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1c8c45017f784e646b47,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 0b1de9feeb8651f7a3bb53ed7c9006e3b5298c01 ]
The tsf debugfs files call the driver even if the interface
isn't up, tgriggering check-sdata-in-driver warnings.
Reject the access in that case.
Assisted-by: LLM
Fixes: 37a41b4affa3 ("mac80211: add ieee80211_vif param to tsf functions")
Reported-by: syzbot+1c8c45017f784e646b47@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1c8c45017f784e646b47
Link: https://patch.msgid.link/20260908122838.201719-18-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index 6b4b5e0a19570..cb82b7966d374 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -519,6 +519,9 @@ static ssize_t ieee80211_if_fmt_tsf(
struct ieee80211_local *local = sdata->local;
u64 tsf;
+ if (!ieee80211_sdata_running((struct ieee80211_sub_if_data *)sdata))
+ return -ENETDOWN;
+
tsf = drv_get_tsf(local, (struct ieee80211_sub_if_data *)sdata);
return scnprintf(buf, buflen, "0x%016llx\n", (unsigned long long) tsf);
@@ -532,6 +535,9 @@ static ssize_t ieee80211_if_parse_tsf(
int ret;
int tsf_is_delta = 0;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
if (strncmp(buf, "reset", 5) == 0) {
if (local->ops->reset_tsf) {
drv_reset_tsf(local, sdata);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 638/982] wifi: mac80211: add HE 6 GHz capability in the scan elems len
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (636 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 637/982] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 639/982] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
` (350 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f961b9f94edbc266f1f8,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit cd54bf333f5631d3630bab0a832e9ae648f73515 ]
The HE 6 GHz Band Capability element is in the probe request for
every band if 6 GHz is supported, so add the size to scan_ies_len.
Otherwise, building probe request elements can fail, triggering the
WARN_ON in __ieee80211_start_scan().
Assisted-by: LLM
Fixes: 2ad2274c58ee ("mac80211: Add HE 6GHz capabilities element to probe request")
Reported-by: syzbot+f961b9f94edbc266f1f8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f961b9f94edbc266f1f8
Link: https://patch.msgid.link/20260908122838.201719-19-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/main.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/main.c b/net/mac80211/main.c
index 033f407559b68..b695c0b6728ed 100644
--- a/net/mac80211/main.c
+++ b/net/mac80211/main.c
@@ -1232,6 +1232,10 @@ int ieee80211_register_hw(struct ieee80211_hw *hw)
sizeof(struct ieee80211_he_mcs_nss_supp) +
IEEE80211_HE_PPE_THRES_MAX_LEN;
+ if (local->hw.wiphy->bands[NL80211_BAND_6GHZ])
+ local->scan_ies_len +=
+ 3 + sizeof(struct ieee80211_he_6ghz_capa);
+
if (supp_eht)
local->scan_ies_len +=
3 + sizeof(struct ieee80211_eht_cap_elem) +
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 639/982] wifi: mac80211: mesh: release the channel if start fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (637 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 638/982] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 640/982] wifi: mac80211: rework ack_frame_id handling a bit Greg Kroah-Hartman
` (349 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+63a84ea9c0f57d6133fa,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ae97fff6495a8764bc0ef281cfe5444f701e527f ]
ieee80211_join_mesh() acquires a channel context and then calls
ieee80211_start_mesh(), which can fail. In that case, the chanctx
isn't released then interface removal will attempt to unassign it
after it's removed from the driver, hitting:
wlan0: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx
ieee80211_assign_link_chanctx
__ieee80211_link_release_channel
ieee80211_link_release_channel
ieee80211_teardown_sdata
unregister_netdevice_many_notify
_cfg80211_unregister_wdev
ieee80211_remove_interfaces
ieee80211_unregister_hw
mac80211_hwsim_del_radio
hwsim_exit_net
Correctly release the channel on start failures.
Assisted-by: LLM
Reported-by: syzbot+63a84ea9c0f57d6133fa@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=63a84ea9c0f57d6133fa
Fixes: 2b5e19677592 ("mac80211: cache mesh beacon")
Link: https://patch.msgid.link/20260908122838.201719-21-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 0b425f97977be..b1c9d869305f9 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -2571,7 +2571,11 @@ static int ieee80211_join_mesh(struct wiphy *wiphy, struct net_device *dev,
if (err)
return err;
- return ieee80211_start_mesh(sdata);
+ err = ieee80211_start_mesh(sdata);
+ if (err)
+ ieee80211_link_release_channel(&sdata->deflink);
+
+ return err;
}
static int ieee80211_leave_mesh(struct wiphy *wiphy, struct net_device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 640/982] wifi: mac80211: rework ack_frame_id handling a bit
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (638 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 639/982] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 641/982] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
` (348 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Berg, Ilan Peer,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit f498f6ab7adb461a68e13ea6d4443cb3636f2d93 ]
Take one more free bit to indicate it's IDR vs. internal
usage, to be able to carve out some bits here for other
internal usage, other than IDR handling with a full ACK
SKB, that is.
Reviewed-by: Benjamin Berg <benjamin.berg@intel.com>
Reviewed-by: Ilan Peer <ilan.peer@intel.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 50d3d79dc074 ("wifi: mac80211: set up the TX info early to fix failure paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/mac80211.h | 9 ++++++---
net/mac80211/cfg.c | 3 ++-
net/mac80211/ieee80211_i.h | 5 +++++
net/mac80211/status.c | 4 ++--
net/mac80211/tx.c | 14 ++++++++++----
5 files changed, 25 insertions(+), 10 deletions(-)
diff --git a/include/net/mac80211.h b/include/net/mac80211.h
index 1769d03e6b1d4..c68df4da7a367 100644
--- a/include/net/mac80211.h
+++ b/include/net/mac80211.h
@@ -1071,7 +1071,9 @@ ieee80211_rate_get_vht_nss(const struct ieee80211_tx_rate *rate)
* not valid if the interface is an MLD since we won't know which
* link the frame will be transmitted on
* @hw_queue: HW queue to put the frame on, skb_get_queue_mapping() gives the AC
- * @ack_frame_id: internal frame ID for TX status, used internally
+ * @status_data: internal data for TX status handling, assigned privately,
+ * see also &enum ieee80211_status_data for the internal documentation
+ * @status_data_idr: indicates status data is IDR allocated ID for ack frame
* @tx_time_est: TX time estimate in units of 4us, used internally
* @control: union part for control data
* @control.rates: TX rates array to try
@@ -1111,10 +1113,11 @@ struct ieee80211_tx_info {
/* common information */
u32 flags;
u32 band:3,
- ack_frame_id:13,
+ status_data_idr:1,
+ status_data:13,
hw_queue:4,
tx_time_est:10;
- /* 2 free bits */
+ /* 1 free bit */
union {
struct {
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index b1c9d869305f9..82c62fc4f0578 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -3955,7 +3955,8 @@ int ieee80211_attach_ack_skb(struct ieee80211_local *local, struct sk_buff *skb,
return -ENOMEM;
}
- IEEE80211_SKB_CB(skb)->ack_frame_id = id;
+ IEEE80211_SKB_CB(skb)->status_data_idr = 1;
+ IEEE80211_SKB_CB(skb)->status_data = id;
*cookie = ieee80211_mgmt_tx_cookie(local);
IEEE80211_SKB_CB(ack_skb)->ack.cookie = *cookie;
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index 5c3993f611625..9e1c1c859cf65 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -83,6 +83,11 @@ extern const u8 ieee80211_ac_to_qos_mask[IEEE80211_NUM_ACS];
#define IEEE80211_MAX_NAN_INSTANCE_ID 255
+enum ieee80211_status_data {
+ IEEE80211_STATUS_TYPE_MASK = 0x00f,
+ IEEE80211_STATUS_TYPE_INVALID = 0,
+ IEEE80211_STATUS_SUBDATA_MASK = 0xff0,
+};
/*
* Keep a station's queues on the active list for deficit accounting purposes
diff --git a/net/mac80211/status.c b/net/mac80211/status.c
index 9a8fca897d9f9..48870656e6c0d 100644
--- a/net/mac80211/status.c
+++ b/net/mac80211/status.c
@@ -633,7 +633,7 @@ static void ieee80211_report_ack_skb(struct ieee80211_local *local,
unsigned long flags;
spin_lock_irqsave(&local->ack_status_lock, flags);
- skb = idr_remove(&local->ack_status_frames, info->ack_frame_id);
+ skb = idr_remove(&local->ack_status_frames, info->status_data);
spin_unlock_irqrestore(&local->ack_status_lock, flags);
if (!skb)
@@ -759,7 +759,7 @@ static void ieee80211_report_used_skb(struct ieee80211_local *local,
}
rcu_read_unlock();
- } else if (info->ack_frame_id) {
+ } else if (info->status_data_idr) {
ieee80211_report_ack_skb(local, skb, acked, dropped,
ack_hwtstamp);
}
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index 0cd02bd3fae30..d1e0510d1086f 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2982,7 +2982,10 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
memset(info, 0, sizeof(*info));
info->flags = info_flags;
- info->ack_frame_id = info_id;
+ if (info_id) {
+ info->status_data = info_id;
+ info->status_data_idr = 1;
+ }
info->band = band;
if (likely(!cookie)) {
@@ -4579,9 +4582,12 @@ static void ieee80211_8023_xmit(struct ieee80211_sub_if_data *sdata,
}
if (unlikely(skb->sk &&
- skb_shinfo(skb)->tx_flags & SKBTX_WIFI_STATUS))
- info->ack_frame_id = ieee80211_store_ack_skb(local, skb,
- &info->flags, NULL);
+ skb_shinfo(skb)->tx_flags & SKBTX_WIFI_STATUS)) {
+ info->status_data = ieee80211_store_ack_skb(local, skb,
+ &info->flags, NULL);
+ if (info->status_data)
+ info->status_data_idr = 1;
+ }
info->hw_queue = sdata->vif.hw_queue[skb_get_queue_mapping(skb)];
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 641/982] wifi: mac80211: set up the TX info early to fix failure paths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (639 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 640/982] wifi: mac80211: rework ack_frame_id handling a bit Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 642/982] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
` (347 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 50d3d79dc0743b616afb00d01a626c76758721f7 ]
The previous commit 2c51457d930f ("wifi: mac80211: free ack status
frame on TX header build failure") cleaned up the leak, but still
left the code a bit messy and the failed SKB didn't get reported
to userspace.
Fix this up by initialising skb->cb[] earlier, which allows using
ieee80211_free_txskb() and therefore reports it for the failure
in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize()
failure path with it.
Assisted-by: LLM
Fixes: c3e7724b6bc2 ("mac80211: use ieee80211_free_txskb to fix possible skb leaks")
Link: https://patch.msgid.link/20260908122838.201719-22-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 38 ++++++++++++++++++++------------------
1 file changed, 20 insertions(+), 18 deletions(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index d1e0510d1086f..00e8eda67f130 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2906,10 +2906,23 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
*/
skb = skb_share_check(skb, GFP_ATOMIC);
if (unlikely(!skb)) {
- ret = -ENOMEM;
- goto free;
+ /* skb_share_check() already freed the skb */
+ if (info_id)
+ ieee80211_remove_ack_skb(local, info_id);
+ return ERR_PTR(-ENOMEM);
}
+ /* set this up so failure paths can clean up ack skb */
+ info = IEEE80211_SKB_CB(skb);
+ memset(info, 0, sizeof(*info));
+
+ info->flags = info_flags;
+ if (info_id) {
+ info->status_data = info_id;
+ info->status_data_idr = 1;
+ }
+ info->band = band;
+
hdr.frame_control = fc;
hdr.duration_id = 0;
hdr.seq_ctrl = 0;
@@ -2948,10 +2961,8 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
head_need += local->tx_headroom;
head_need = max_t(int, 0, head_need);
if (ieee80211_skb_resize(sdata, skb, head_need, ENCRYPT_DATA)) {
- ieee80211_free_txskb(&local->hw, skb);
- skb = NULL;
ret = -ENOMEM;
- goto free;
+ goto free_txskb;
}
}
@@ -2978,16 +2989,6 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
skb_reset_mac_header(skb);
- info = IEEE80211_SKB_CB(skb);
- memset(info, 0, sizeof(*info));
-
- info->flags = info_flags;
- if (info_id) {
- info->status_data = info_id;
- info->status_data_idr = 1;
- }
- info->band = band;
-
if (likely(!cookie)) {
ctrl_flags |= u32_encode_bits(link_id,
IEEE80211_TX_CTRL_MLO_LINK);
@@ -3011,16 +3012,17 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
pre_conf_link_id, link_id);
#endif
ret = -EINVAL;
- goto free;
+ goto free_txskb;
}
}
info->control.flags = ctrl_flags;
return skb;
+ free_txskb:
+ ieee80211_free_txskb(&local->hw, skb);
+ return ERR_PTR(ret);
free:
- if (info_id)
- ieee80211_remove_ack_skb(local, info_id);
kfree_skb(skb);
return ERR_PTR(ret);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 642/982] scsi: qla2xxx: Fix the ql2xfc2target parameter description
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (640 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 641/982] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 6.1 643/982] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
` (346 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 779f202a92ef10a426efc07d0f4267918cb07ca3 ]
The module parameter is ql2xfc2target, but its MODULE_PARM_DESC() names
qla2xfc2target, so modinfo describes a parameter that does not exist and
shows no description for the real one.
Use the parameter name in the description.
Fixes: 877b03795fcf ("scsi: qla2xxx: Add option to disable FC2 Target support")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260906171009.2560-1-kmehltretter@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/qla2xxx/qla_os.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/qla2xxx/qla_os.c b/drivers/scsi/qla2xxx/qla_os.c
index 3fdb120507419..e1578808e27ee 100644
--- a/drivers/scsi/qla2xxx/qla_os.c
+++ b/drivers/scsi/qla2xxx/qla_os.c
@@ -363,7 +363,7 @@ MODULE_PARM_DESC(ql2xnvme_queues,
int ql2xfc2target = 1;
module_param(ql2xfc2target, int, 0444);
-MODULE_PARM_DESC(qla2xfc2target,
+MODULE_PARM_DESC(ql2xfc2target,
"Enables FC2 Target support. "
"0 - FC2 Target support is disabled. "
"1 - FC2 Target support is enabled (default).");
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 643/982] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (641 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 642/982] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 644/982] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
` (345 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit cee9c863ee68cb27d66745eb03f60e357f4f8ad2 ]
xilinx_dma_alloc_chan_resources() builds a static ring of hardware
buffer descriptors once and the driver uses this ring throughout the
lifetime of a channel. This requires the allocation order of hardware
buffer descriptors from chan->free_seg_list to stay in sync with the
hardware buffer descriptor ring built at channel allocation time by
returning oldest descriptors to chan->free_seg_list first.
When chan->pending_list is not empty e.g. during
xilinx_dma_terminate_all() the chan->free_seg_list and the order of the
static hardware buffer descriptor ring get out of sync. Descriptors age
in this order: pending -> active -> done. So freeing pending_list first
returns the newest buffer descriptors to the chan->free_seg_list first
and thus breaks the order required by the static hardware buffer
descriptor ring. Then when the channel is reused, after a wrap around of
the free_seg_list the DMA will find a hardware buffer descriptor with a
length field that is still zeroed and stop with something like this:
xilinx-vdma 86000000.dma: Channel 000000003a21d7b8 has errors 10, cdr 6de4c000 tdr 6de4c000
After this no more descriptors are completed and a consumer potentially
blocks and waits forever. The only way to get out of this error state is
to rebuild the static hardware buffer descriptor ring and the
free_seg_list by releasing and re-acquiring the channel.
Fix the order in which hardware buffer descriptors are returned to
free_seg_list to ensure the mentioned requirement holds.
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-reuse-v1-1-d79827a844c7@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 914399ba74935..53e791513b7e0 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -889,9 +889,9 @@ static void xilinx_dma_free_descriptors(struct xilinx_dma_chan *chan)
spin_lock_irqsave(&chan->lock, flags);
- xilinx_dma_free_desc_list(chan, &chan->pending_list);
xilinx_dma_free_desc_list(chan, &chan->done_list);
xilinx_dma_free_desc_list(chan, &chan->active_list);
+ xilinx_dma_free_desc_list(chan, &chan->pending_list);
spin_unlock_irqrestore(&chan->lock, flags);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 644/982] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (642 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 6.1 643/982] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 645/982] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
` (344 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit 7ed1e3070c9b4bbd67d5519e14711038dd53ab13 ]
Using the DMA in cyclic mode modifies the hardware buffer descriptor
chain in xilinx_dma_prep_dma_cyclic so that the last descriptor used by
the cyclic transfer points back to the first descriptor, but it never
restores the original descriptor ring. This breaks using non-cyclic mode
after cyclic mode with an error like:
xilinx-vdma 86000000.dma: Channel 00000000354d5c8d has errors 100, cdr 6de40000 tdr 6de40400
The only way to get out of this error state is to rebuild the hardware
buffer descriptor ring by releasing and re-acquiring the channel.
Fix using non-cyclic mode after cyclic mode by always restoring the
original buffer descriptor ring in the same manner as it is set up by
xilinx_dma_alloc_chan_resources().
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-after-cyclic-mode-v1-1-1fe47e701d6c@bereza.email
Link: https://patch.msgid.link/20260818-fix-hw-buf-desc-after-cyclic-mode-v2-1-530ff44c6a81@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 53e791513b7e0..5fb423261c3f0 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -725,15 +725,25 @@ xilinx_aximcdma_alloc_tx_segment(struct xilinx_dma_chan *chan)
return segment;
}
-static void xilinx_dma_clean_hw_desc(struct xilinx_axidma_desc_hw *hw)
+static void xilinx_dma_clean_hw_desc(struct xilinx_dma_chan *chan,
+ struct xilinx_axidma_tx_segment *segment)
{
- u32 next_desc = hw->next_desc;
- u32 next_desc_msb = hw->next_desc_msb;
+ dma_addr_t next;
+ u32 i;
- memset(hw, 0, sizeof(struct xilinx_axidma_desc_hw));
+ /*
+ * Restore the buffer descriptor's next descriptor pointer to the value
+ * set up in xilinx_dma_alloc_chan_resources(). Otherwise using the DMA
+ * in cyclic mode leaves the next descriptor pointer altered and
+ * prevents subsequent non-cyclic transfers.
+ */
+ i = segment - chan->seg_v;
+ next = chan->seg_p +
+ sizeof(*chan->seg_v) * ((i + 1) % XILINX_DMA_NUM_DESCS);
- hw->next_desc = next_desc;
- hw->next_desc_msb = next_desc_msb;
+ memset(&segment->hw, 0, sizeof(segment->hw));
+ segment->hw.next_desc = lower_32_bits(next);
+ segment->hw.next_desc_msb = upper_32_bits(next);
}
static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
@@ -755,7 +765,7 @@ static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
static void xilinx_dma_free_tx_segment(struct xilinx_dma_chan *chan,
struct xilinx_axidma_tx_segment *segment)
{
- xilinx_dma_clean_hw_desc(&segment->hw);
+ xilinx_dma_clean_hw_desc(chan, segment);
list_add_tail(&segment->node, &chan->free_seg_list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 645/982] RDMA/efa: Keep admin queues alive while IRQ is registered
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (643 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 644/982] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 646/982] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
` (343 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e08aca85c02ff290f785f07acae758f0daf5f49e ]
The management IRQ handler accesses both the admin completion queue and the
async event queue. The driver registered the IRQ before constructing these
queues and destroyed them before freeing the IRQ, so the handler's lifetime
was not contained by the resources it accesses.
Initialize the queues with interrupts masked, request the IRQ, and then
switch to interrupt mode. On removal, reset the device and free the IRQ
before destroying the queues. Also reset the device before destroying the
queues if IRQ registration fails, because the device already has their DMA
addresses.
Fixes: b7f5e880f377 ("RDMA/efa: Add the efa module")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-1-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 4 +---
drivers/infiniband/hw/efa/efa_main.c | 15 +++++++++------
2 files changed, 10 insertions(+), 9 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index bafd210dd43e8..d6fb2edc96891 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -743,7 +743,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
aq->dmadev = edev->dmadev;
aq->efa_dev = edev->efa_dev;
- set_bit(EFA_AQ_STATE_POLLING_BIT, &aq->state);
+ efa_com_set_admin_polling_mode(edev, true);
sema_init(&aq->avail_cmds, aq->depth);
@@ -761,8 +761,6 @@ int efa_com_admin_init(struct efa_com_dev *edev,
if (err)
goto err_destroy_sq;
- efa_com_set_admin_polling_mode(edev, false);
-
err = efa_com_admin_init_aenq(edev, aenq_handlers);
if (err)
goto err_destroy_cq;
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 924940ca9de0a..68e2d5c96c886 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -595,18 +595,21 @@ static struct efa_dev *efa_probe_device(struct pci_dev *pdev)
edev->aq.msix_vector_idx = dev->admin_msix_vector_idx;
edev->aenq.msix_vector_idx = dev->admin_msix_vector_idx;
- err = efa_set_mgmnt_irq(dev);
+ err = efa_com_admin_init(edev, &aenq_handlers);
if (err)
goto err_disable_msix;
- err = efa_com_admin_init(edev, &aenq_handlers);
+ err = efa_set_mgmnt_irq(dev);
if (err)
- goto err_free_mgmnt_irq;
+ goto err_destroy_admin;
+
+ efa_com_set_admin_polling_mode(edev, false);
return dev;
-err_free_mgmnt_irq:
- efa_free_irq(dev, &dev->admin_irq);
+err_destroy_admin:
+ efa_com_dev_reset(edev, EFA_REGS_RESET_INIT_ERR);
+ efa_com_admin_destroy(edev);
err_disable_msix:
efa_disable_msix(dev);
err_reg_read_destroy:
@@ -630,8 +633,8 @@ static void efa_remove_device(struct pci_dev *pdev,
edev = &dev->edev;
efa_com_dev_reset(edev, reset_reason);
- efa_com_admin_destroy(edev);
efa_free_irq(dev, &dev->admin_irq);
+ efa_com_admin_destroy(edev);
efa_disable_msix(dev);
efa_com_mmio_reg_read_destroy(edev);
devm_iounmap(&pdev->dev, edev->reg_bar);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 646/982] RDMA/efa: Keep EQ resources alive while IRQ is registered
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (644 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 645/982] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 647/982] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
` (342 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e22a3627b7151754f07f90ea3d1ab6e85f5d93f4 ]
The completion IRQ handler accesses the EQ state and DMA buffer. Its IRQ was
registered before that state was initialized, while teardown released the
buffer before free_irq() synchronized the handler.
Initialize the EQ without arming it, register the IRQ, and then arm it.
Reverse the resource order during teardown by freeing the IRQ before
destroying the EQ.
Fixes: 2a152512a155 ("RDMA/efa: CQ notifications")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-2-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 3 +--
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 18 ++++++++++--------
3 files changed, 12 insertions(+), 10 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index d6fb2edc96891..00e339abc2c13 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -1149,7 +1149,7 @@ static void efa_com_destroy_eq(struct efa_com_dev *edev,
err);
}
-static void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
{
u32 val = 0;
@@ -1238,7 +1238,6 @@ int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
eeq->phase = 1;
eeq->depth = params.depth;
eeq->cb = cb;
- efa_com_arm_eq(edev, eeq);
return 0;
diff --git a/drivers/infiniband/hw/efa/efa_com.h b/drivers/infiniband/hw/efa/efa_com.h
index 77282234ce686..29a9d087db5d9 100644
--- a/drivers/infiniband/hw/efa/efa_com.h
+++ b/drivers/infiniband/hw/efa/efa_com.h
@@ -157,6 +157,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
void efa_com_admin_destroy(struct efa_com_dev *edev);
int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
efa_eqe_handler cb, u16 depth, u8 msix_vec);
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq);
void efa_com_eq_destroy(struct efa_com_dev *edev, struct efa_com_eq *eeq);
int efa_com_dev_reset(struct efa_com_dev *edev,
enum efa_regs_reset_reason_types reset_reason);
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 68e2d5c96c886..83e4903ca7fd5 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -288,28 +288,30 @@ static void efa_set_host_info(struct efa_dev *dev)
static void efa_destroy_eq(struct efa_dev *dev, struct efa_eq *eq)
{
- efa_com_eq_destroy(&dev->edev, &eq->eeq);
efa_free_irq(dev, &eq->irq);
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
}
static int efa_create_eq(struct efa_dev *dev, struct efa_eq *eq, u8 msix_vec)
{
int err;
- efa_setup_comp_irq(dev, eq, msix_vec);
- err = efa_request_irq(dev, &eq->irq);
+ err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
+ dev->dev_attr.max_eq_depth, msix_vec);
if (err)
return err;
- err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
- dev->dev_attr.max_eq_depth, msix_vec);
+ efa_setup_comp_irq(dev, eq, msix_vec);
+ err = efa_request_irq(dev, &eq->irq);
if (err)
- goto err_free_comp_irq;
+ goto err_destroy_eq;
+
+ efa_com_arm_eq(&dev->edev, &eq->eeq);
return 0;
-err_free_comp_irq:
- efa_free_irq(dev, &eq->irq);
+err_destroy_eq:
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 647/982] RDMA/siw: Bound fragmented header copies by the remaining length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (645 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 646/982] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 648/982] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
` (341 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Bernard Metzler, Leon Romanovsky, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 9ff797e516dbc1ecb73701ec4c24055712d44411 ]
siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the
next copy length.
Fixes: 754209850df8 ("RDMA/siw: Always consume all skbuf data in sk_data_ready() upcall.")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Link: https://patch.msgid.link/20260908085520.1746329-1-Jeremy.Jean@oss.cyber.gouv.fr
Assisted-by: Codex:gpt-6
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/siw/siw_qp_rx.c b/drivers/infiniband/sw/siw/siw_qp_rx.c
index 743ffb3754e80..d608ecc67dd9d 100644
--- a/drivers/infiniband/sw/siw/siw_qp_rx.c
+++ b/drivers/infiniband/sw/siw/siw_qp_rx.c
@@ -1095,7 +1095,7 @@ static int siw_get_hdr(struct siw_rx_stream *srx)
if (iwarp_pktinfo[opcode].hdr_len > sizeof(struct iwarp_ctrl_tagged)) {
int hdrlen = iwarp_pktinfo[opcode].hdr_len;
- bytes = min_t(int, hdrlen - MIN_DDP_HDR, srx->skb_new);
+ bytes = min_t(int, hdrlen - srx->fpdu_part_rcvd, srx->skb_new);
skb_copy_bits(skb, srx->skb_offset,
(char *)c_hdr + srx->fpdu_part_rcvd, bytes);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 648/982] netfilter: nft_nat: fully initialise new_addr in netmap setup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (646 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 647/982] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 649/982] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
` (340 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Theodor Arsenij Larionov Trichkine,
Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
[ Upstream commit d313499df66159b4b7971d760d16729598ab7e5a ]
nft_nat_setup_netmap() builds the mapped address in an on-stack
union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip
member and the loop runs a single 32-bit iteration, but it then copies
the whole 16-byte union into range->min_addr and range->max_addr, so the
upper 12 bytes reach nf_nat_setup_info() uninitialised.
KMSAN reports an uninit-value in nf_nat_setup_info() reached from
nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.
Zero-initialise new_addr.
Fixes: 3ff7ddb1353d ("netfilter: nft_nat: add netmap support")
Signed-off-by: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_nat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nft_nat.c b/net/netfilter/nft_nat.c
index 4b855c277f5cc..e1e2e46dbea74 100644
--- a/net/netfilter/nft_nat.c
+++ b/net/netfilter/nft_nat.c
@@ -64,8 +64,8 @@ static void nft_nat_setup_netmap(struct nf_nat_range2 *range,
const struct nft_pktinfo *pkt,
const struct nft_nat *priv)
{
+ union nf_inet_addr new_addr = {};
struct sk_buff *skb = pkt->skb;
- union nf_inet_addr new_addr;
__be32 netmask;
int i, len = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 649/982] netfilter: flowtable: hold reference on ct until flow is released
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (647 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 648/982] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 650/982] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
` (339 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d ]
nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.
Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
Fixes: 0ff90b6c2034 ("netfilter: nf_flow_offload: fix use-after-free and a resource leak")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_flow_table_core.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
index be74dccfe1410..16076c66fcec7 100644
--- a/net/netfilter/nf_flow_table_core.c
+++ b/net/netfilter/nf_flow_table_core.c
@@ -202,6 +202,14 @@ static void flow_offload_route_release(struct flow_offload *flow)
nft_flow_dst_release(flow, FLOW_OFFLOAD_DIR_REPLY);
}
+static void flow_offload_free_rcu(struct rcu_head *rcu_head)
+{
+ struct flow_offload *flow = container_of(rcu_head, struct flow_offload, rcu_head);
+
+ nf_ct_put(flow->ct);
+ kfree(flow);
+}
+
void flow_offload_free(struct flow_offload *flow)
{
switch (flow->type) {
@@ -211,8 +219,7 @@ void flow_offload_free(struct flow_offload *flow)
default:
break;
}
- nf_ct_put(flow->ct);
- kfree_rcu(flow, rcu_head);
+ call_rcu(&flow->rcu_head, flow_offload_free_rcu);
}
EXPORT_SYMBOL_GPL(flow_offload_free);
@@ -677,6 +684,7 @@ static int __init nf_flow_table_module_init(void)
static void __exit nf_flow_table_module_exit(void)
{
+ rcu_barrier();
nf_flow_table_offload_exit();
unregister_pernet_subsys(&nf_flow_table_net_ops);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 650/982] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (648 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 649/982] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 651/982] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
` (338 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shouping Wang, Robin Murphy,
Will Deacon, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shouping Wang <allen.wang@hj-micro.com>
[ Upstream commit 49daa3d668b69a5454b5aba0078848a479f79f1c ]
When MXP_MULTIPLE_DTM_EN is TRUE, each DTM will monitor at most
two device ports. In this case, {wp_dev_sel2, wp_dev_sel} will
only use values 2'b00 and 2'b01 per DTM.
Previously the setting allowed values beyond the supported range
per DTM, which could cause each DTM to select invalid ports when
MXP_MULTIPLE_DTM_EN is TRUE.
Fix this by only setting CMN_DTM_WPn_CONFIG_WP_DEV_SEL2 when
!multi_dtm.
Fixes: 60d1504070c2 ("perf/arm-cmn: Support new IP features")
Signed-off-by: Shouping Wang <allen.wang@hj-micro.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/arm-cmn.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/perf/arm-cmn.c b/drivers/perf/arm-cmn.c
index dc985a0c40877..43b0afd1cfe52 100644
--- a/drivers/perf/arm-cmn.c
+++ b/drivers/perf/arm-cmn.c
@@ -1207,18 +1207,22 @@ static int arm_cmn_wp_idx(struct perf_event *event)
static u32 arm_cmn_wp_config(struct perf_event *event)
{
+ struct arm_cmn *cmn = to_cmn(event->pmu);
u32 config;
u32 dev = CMN_EVENT_WP_DEV_SEL(event);
u32 chn = CMN_EVENT_WP_CHN_SEL(event);
u32 grp = CMN_EVENT_WP_GRP(event);
u32 exc = CMN_EVENT_WP_EXCLUSIVE(event);
u32 combine = CMN_EVENT_WP_COMBINE(event);
- bool is_cmn600 = to_cmn(event->pmu)->part == PART_CMN600;
+ bool is_cmn600 = cmn->part == PART_CMN600;
config = FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL, dev) |
FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_CHN_SEL, chn) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+ FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp);
+
+ if (!cmn->multi_dtm)
+ config |= FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+
if (exc)
config |= is_cmn600 ? CMN600_WPn_CONFIG_WP_EXCLUSIVE :
CMN_DTM_WPn_CONFIG_WP_EXCLUSIVE;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 651/982] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (649 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 650/982] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 652/982] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
` (337 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Thadeu Lima de Souza Cascardo, Melissa Wen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
[ Upstream commit 9eb1a393c89a79c4210230d23e7d88d239c61d7b ]
When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not
set, a drm_pending_vblank_event will be allocated. If later, there is an
allocation failure or another failure at setup_out_fence(), that event
will not have base.fence set and it will not be released at
complete_signaling().
Release the event and set crtc_state->event to NULL just like in the
DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at
drm_event_reserve_init(). That is, prepare_signaling() releases the
event and there is nothing to be done at complete_signaling(). Use
drm_event_cancel_free() as that will also undo drm_event_reserve_init()
in case it has been called.
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260727-drm_crtc_atomic_commit_leak-v1-1-23d9948a9d7c@igalia.com?part=1
Fixes: 92c715fca907 ("drm/atomic: Fix double free in drm_atomic_state_default_clear")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Signed-off-by: Melissa Wen <mwen@igalia.com>
Link: https://patch.msgid.link/20260826-drm_pending_vblank_event_leak-v4-1-f8de8b996b9d@igalia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_atomic_uapi.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/drm_atomic_uapi.c b/drivers/gpu/drm/drm_atomic_uapi.c
index 38f94b7543a70..c2e0c6dab99db 100644
--- a/drivers/gpu/drm/drm_atomic_uapi.c
+++ b/drivers/gpu/drm/drm_atomic_uapi.c
@@ -1159,10 +1159,12 @@ static int prepare_signaling(struct drm_device *dev,
struct dma_fence *fence;
struct drm_out_fence_state *f;
+ ret = -ENOMEM;
+
f = krealloc(*fence_state, sizeof(**fence_state) *
(*num_fences + 1), GFP_KERNEL);
if (!f)
- return -ENOMEM;
+ goto err_free_event;
memset(&f[*num_fences], 0, sizeof(*f));
@@ -1171,12 +1173,12 @@ static int prepare_signaling(struct drm_device *dev,
fence = drm_crtc_create_fence(crtc);
if (!fence)
- return -ENOMEM;
+ goto err_free_event;
ret = setup_out_fence(&f[(*num_fences)++], fence);
if (ret) {
dma_fence_put(fence);
- return ret;
+ goto err_free_event;
}
crtc_state->event->base.fence = fence;
@@ -1230,6 +1232,11 @@ static int prepare_signaling(struct drm_device *dev,
return -EINVAL;
return 0;
+
+err_free_event:
+ drm_event_cancel_free(dev, &crtc_state->event->base);
+ crtc_state->event = NULL;
+ return ret;
}
static void complete_signaling(struct drm_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 652/982] keys: fix lost wakeup when reaping a dead key type
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (650 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 651/982] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 653/982] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
` (336 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Jarkko Sakkinen,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 2725ab3f5ad1c5f375c7c9fee4af02a9b138f701 ]
clear_bit() is atomic with respect to the word it modifies, but it is
an unordered operation: it implies no memory barrier on either side
(Documentation/atomic_bitops.txt).
key_garbage_collector() clears KEY_GC_REAPING_KEYTYPE with clear_bit()
and calls wake_up_bit() after reaping a dead key type. wake_up_bit()
uses a lockless waitqueue check and requires a full barrier after the
clear.
The existing smp_mb() is before clear_bit(), so nothing orders the clear
against that check. The GC can see an empty waitqueue while
unregister_key_type() still sees the bit set. The final wakeup is then
lost, leaving module unload stuck in wait_on_bit().
Use clear_and_wake_up_bit(). Its clear_bit_unlock() has RELEASE
semantics, so the completed GC work stays ordered before the clear, and
its smp_mb__after_atomic() orders the clear before the waitqueue check.
Fixes: 0c061b5707ab ("KEYS: Correctly destroy key payloads when their keytype is removed")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://lore.kernel.org/r/20260821025327.61488-1-kmehltretter@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/gc.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/security/keys/gc.c b/security/keys/gc.c
index eaddaceda14ea..285ebbf490f04 100644
--- a/security/keys/gc.c
+++ b/security/keys/gc.c
@@ -324,9 +324,7 @@ static void key_garbage_collector(struct work_struct *work)
if (unlikely(gc_state & KEY_GC_REAPING_DEAD_3)) {
kdebug("dead wake");
- smp_mb();
- clear_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
- wake_up_bit(&key_gc_flags, KEY_GC_REAPING_KEYTYPE);
+ clear_and_wake_up_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
}
if (gc_state & KEY_GC_REAP_AGAIN)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 653/982] ALSA: bcd2000: Fix race between rawmidi and disconnect
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (651 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 652/982] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 654/982] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
` (335 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 221253723dc58bb901c3f27a7659823e63fc598c ]
Although we tried to fix the potential UAF issues at USB disconnect on
bcd2000 driver, there is still an overlooked case -- namely, when a
rawmidi trigger callback has been already running at USB disconnect
handling, the in-flight function (e.g. bcd2000_midi_send()) could
still access the URB, because the previous URB NULL-check & clearance
was considered only for the URB complete callbacks, but not about the
parallel rawmidi operations.
For addressing the race, this patch introduced a new spinlock that
covers each rawmidi operation as well as the rawmidi handling in the
complete callback. The URB is cleared with the lock, so it guarantees
that the pending rawmidi task already finished or a NULL check is
effective.
Fixes: 459d3a64766f ("ALSA: bcd2000: clear the URB pointers on disconnect")
Link: https://patch.msgid.link/20260910155227.996210-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/bcd2000/bcd2000.c | 33 ++++++++++++++++++++++++++-------
1 file changed, 26 insertions(+), 7 deletions(-)
diff --git a/sound/usb/bcd2000/bcd2000.c b/sound/usb/bcd2000/bcd2000.c
index 407a50f163b08..8be080d33eb0f 100644
--- a/sound/usb/bcd2000/bcd2000.c
+++ b/sound/usb/bcd2000/bcd2000.c
@@ -43,6 +43,7 @@ struct bcd2000 {
struct usb_interface *intf;
int card_index;
+ spinlock_t midi_lock;
int midi_out_active;
struct snd_rawmidi *rmidi;
struct snd_rawmidi_substream *midi_receive_substream;
@@ -90,6 +91,8 @@ static void bcd2000_midi_input_trigger(struct snd_rawmidi_substream *substream,
int up)
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2k->midi_receive_substream = up ? substream : NULL;
}
@@ -195,6 +198,8 @@ static void bcd2000_midi_output_trigger(struct snd_rawmidi_substream *substream,
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (up) {
bcd2k->midi_out_substream = substream;
/* check if there is data userspace wants to send */
@@ -219,6 +224,7 @@ static void bcd2000_output_complete(struct urb *urb)
return;
/* check if there is more data userspace wants to send */
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2000_midi_send(bcd2k);
}
@@ -234,6 +240,8 @@ static void bcd2000_input_complete(struct urb *urb)
if (!bcd2k || urb->status == -ESHUTDOWN)
return;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (urb->actual_length > 0)
bcd2000_midi_handle_input(bcd2k, urb->transfer_buffer,
urb->actual_length);
@@ -348,16 +356,26 @@ static int bcd2000_init_midi(struct bcd2000 *bcd2k)
return 0;
}
+static void bcd2000_midi_free(struct bcd2000 *bcd2k,
+ struct urb **urb_p)
+{
+ struct urb *urb = *urb_p;
+
+ if (!urb)
+ return;
+
+ usb_poison_urb(urb);
+ scoped_guard(spinlock_irq, &bcd2k->midi_lock)
+ *urb_p = NULL;
+
+ usb_free_urb(urb);
+}
+
static void bcd2000_free_usb_related_resources(struct bcd2000 *bcd2k,
struct usb_interface *interface)
{
- usb_poison_urb(bcd2k->midi_out_urb);
- usb_poison_urb(bcd2k->midi_in_urb);
-
- usb_free_urb(bcd2k->midi_out_urb);
- usb_free_urb(bcd2k->midi_in_urb);
- bcd2k->midi_out_urb = NULL;
- bcd2k->midi_in_urb = NULL;
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_out_urb);
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_in_urb);
if (bcd2k->intf) {
usb_set_intfdata(bcd2k->intf, NULL);
@@ -397,6 +415,7 @@ static int bcd2000_probe(struct usb_interface *interface,
bcd2k->card = card;
bcd2k->card_index = card_index;
bcd2k->intf = interface;
+ spin_lock_init(&bcd2k->midi_lock);
snd_card_set_dev(card, &interface->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 654/982] ALSA: pcm: set timer->private_data before registering the PCM timer
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (652 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 653/982] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 655/982] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
` (334 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+19da64013c46df87f971,
Nguyen Ngoc Thang, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
[ Upstream commit 1e713f9bb2ac583521f06b0eb4e22440b1e3d078 ]
snd_pcm_timer_init() calls snd_device_register() to link the new
struct snd_timer into the global timer list while it still carries
hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
and only afterwards sets timer->private_data = substream.
Once the timer is on the list under register_mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c_resolution(), and
snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
All three dereference timer->private_data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private_data;
return substream->runtime ? ... // substream is NULL
Move the private_data/private_free assignment before
snd_device_register() so the timer is never visible on the list
without its private_data set. On the snd_device_register() failure
path, private_free() (snd_pcm_timer_free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Reported-by: syzbot+19da64013c46df87f971@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=19da64013c46df87f971
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Link: https://patch.msgid.link/20260913134446.114724-1-ngocthang2710.1999@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/core/pcm_timer.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/sound/core/pcm_timer.c b/sound/core/pcm_timer.c
index c43484b22b34c..725a7272cd076 100644
--- a/sound/core/pcm_timer.c
+++ b/sound/core/pcm_timer.c
@@ -112,12 +112,15 @@ void snd_pcm_timer_init(struct snd_pcm_substream *substream)
"capture" : "playback",
tid.card, tid.device, tid.subdevice);
timer->hw = snd_pcm_timer;
+ /* Set before registering: a concurrent reader can invoke our hw
+ * callbacks as soon as the timer is on the global list.
+ */
+ timer->private_data = substream;
+ timer->private_free = snd_pcm_timer_free;
if (snd_device_register(timer->card, timer) < 0) {
snd_device_free(timer->card, timer);
return;
}
- timer->private_data = substream;
- timer->private_free = snd_pcm_timer_free;
substream->timer = timer;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 655/982] Input: trackpoint - fix the inertia attribute name in the ABI document
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (653 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 654/982] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 656/982] ALSA: 6fire: Clean ups with guard() Greg Kroah-Hartman
` (333 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Dmitry Torokhov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 45b0037899704caf9078be2be4de69361ca7d933 ]
The attribute is created as "inertia" (TRACKPOINT_INT_ATTR(inertia, ...)
in drivers/input/mouse/trackpoint.c); the ABI file spells the path
"intertia". The description below it already says inertia.
Fix the spelling.
Fixes: aebb47d4e7a9 ("Input: trackpoint: document sysfs interface")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260905102038.42882-1-kmehltretter@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
index df11901a6b3df..7954434b0434a 100644
--- a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
+++ b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
@@ -5,7 +5,7 @@ Contact: linux-input@vger.kernel.org
Description:
(RW) Trackpoint sensitivity.
-What: /sys/devices/platform/i8042/.../intertia
+What: /sys/devices/platform/i8042/.../inertia
Date: Aug, 2005
KernelVersion: 2.6.14
Contact: linux-input@vger.kernel.org
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 656/982] ALSA: 6fire: Clean ups with guard()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (654 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 655/982] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 657/982] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
` (332 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 6ff0d95774f0c728f96b8f78367318e95e09ee64 ]
Simple code cleanups with the guard() for spinlock and mutex.
No functional changes.
Link: https://patch.msgid.link/20250811082231.31498-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Stable-dep-of: 1589afe2d099 ("ALSA: 6fire: fix OOB write from device-reported iso length")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/chip.c | 40 ++++++++++----------
sound/usb/6fire/midi.c | 21 +++--------
sound/usb/6fire/pcm.c | 83 ++++++++++++++++++------------------------
3 files changed, 59 insertions(+), 85 deletions(-)
diff --git a/sound/usb/6fire/chip.c b/sound/usb/6fire/chip.c
index e5916c6b75aea..30b240e06a8c8 100644
--- a/sound/usb/6fire/chip.c
+++ b/sound/usb/6fire/chip.c
@@ -83,24 +83,22 @@ static int usb6fire_chip_probe(struct usb_interface *intf,
struct snd_card *card = NULL;
/* look if we already serve this card and return if so */
- mutex_lock(®ister_mutex);
- for (i = 0; i < SNDRV_CARDS; i++) {
- if (devices[i] == device) {
- if (chips[i])
- chips[i]->intf_count++;
- usb_set_intfdata(intf, chips[i]);
- mutex_unlock(®ister_mutex);
- return 0;
- } else if (!devices[i] && regidx < 0)
- regidx = i;
- }
- if (regidx < 0) {
- mutex_unlock(®ister_mutex);
- dev_err(&intf->dev, "too many cards registered.\n");
- return -ENODEV;
+ scoped_guard(mutex, ®ister_mutex) {
+ for (i = 0; i < SNDRV_CARDS; i++) {
+ if (devices[i] == device) {
+ if (chips[i])
+ chips[i]->intf_count++;
+ usb_set_intfdata(intf, chips[i]);
+ return 0;
+ } else if (!devices[i] && regidx < 0)
+ regidx = i;
+ }
+ if (regidx < 0) {
+ dev_err(&intf->dev, "too many cards registered.\n");
+ return -ENODEV;
+ }
+ devices[regidx] = device;
}
- devices[regidx] = device;
- mutex_unlock(®ister_mutex);
/* check, if firmware is present on device, upload it if not */
ret = usb6fire_fw_init(intf);
@@ -175,10 +173,10 @@ static void usb6fire_chip_disconnect(struct usb_interface *intf)
if (chip) { /* if !chip, fw upload has been performed */
chip->intf_count--;
if (!chip->intf_count) {
- mutex_lock(®ister_mutex);
- devices[chip->regidx] = NULL;
- chips[chip->regidx] = NULL;
- mutex_unlock(®ister_mutex);
+ scoped_guard(mutex, ®ister_mutex) {
+ devices[chip->regidx] = NULL;
+ chips[chip->regidx] = NULL;
+ }
/*
* Save card pointer before teardown.
diff --git a/sound/usb/6fire/midi.c b/sound/usb/6fire/midi.c
index de2691d58de6e..6c6bccc0c410d 100644
--- a/sound/usb/6fire/midi.c
+++ b/sound/usb/6fire/midi.c
@@ -23,9 +23,8 @@ static void usb6fire_midi_out_handler(struct urb *urb)
{
struct midi_runtime *rt = urb->context;
int ret;
- unsigned long flags;
- spin_lock_irqsave(&rt->out_lock, flags);
+ guard(spinlock_irqsave)(&rt->out_lock);
if (rt->out) {
ret = snd_rawmidi_transmit(rt->out, rt->out_buffer + 4,
@@ -43,18 +42,14 @@ static void usb6fire_midi_out_handler(struct urb *urb)
} else /* no more data to transmit */
rt->out = NULL;
}
- spin_unlock_irqrestore(&rt->out_lock, flags);
}
static void usb6fire_midi_in_received(
struct midi_runtime *rt, u8 *data, int length)
{
- unsigned long flags;
-
- spin_lock_irqsave(&rt->in_lock, flags);
+ guard(spinlock_irqsave)(&rt->in_lock);
if (rt->in)
snd_rawmidi_receive(rt->in, data, length);
- spin_unlock_irqrestore(&rt->in_lock, flags);
}
static int usb6fire_midi_out_open(struct snd_rawmidi_substream *alsa_sub)
@@ -73,14 +68,11 @@ static void usb6fire_midi_out_trigger(
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
struct urb *urb = &rt->out_urb;
__s8 ret;
- unsigned long flags;
- spin_lock_irqsave(&rt->out_lock, flags);
+ guard(spinlock_irqsave)(&rt->out_lock);
if (up) { /* start transfer */
- if (rt->out) { /* we are already transmitting so just return */
- spin_unlock_irqrestore(&rt->out_lock, flags);
+ if (rt->out) /* we are already transmitting so just return */
return;
- }
ret = snd_rawmidi_transmit(alsa_sub, rt->out_buffer + 4,
MIDI_BUFSIZE - 4);
@@ -99,7 +91,6 @@ static void usb6fire_midi_out_trigger(
}
} else if (rt->out == alsa_sub)
rt->out = NULL;
- spin_unlock_irqrestore(&rt->out_lock, flags);
}
static void usb6fire_midi_out_drain(struct snd_rawmidi_substream *alsa_sub)
@@ -125,14 +116,12 @@ static void usb6fire_midi_in_trigger(
struct snd_rawmidi_substream *alsa_sub, int up)
{
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
- unsigned long flags;
- spin_lock_irqsave(&rt->in_lock, flags);
+ guard(spinlock_irqsave)(&rt->in_lock);
if (up)
rt->in = alsa_sub;
else
rt->in = NULL;
- spin_unlock_irqrestore(&rt->in_lock, flags);
}
static const struct snd_rawmidi_ops out_ops = {
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 32c39d8bd2e55..14d23e3103989 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -289,7 +289,7 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
struct pcm_urb *out_urb = in_urb->peer;
struct pcm_runtime *rt = in_urb->chip->pcm;
struct pcm_substream *sub;
- unsigned long flags;
+ bool period_elapsed;
int total_length = 0;
int frame_count;
int frame;
@@ -313,17 +313,18 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* receive our capture data */
sub = &rt->capture;
- spin_lock_irqsave(&sub->lock, flags);
- if (sub->active) {
- usb6fire_pcm_capture(sub, in_urb);
- if (sub->period_off >= sub->instance->runtime->period_size) {
- sub->period_off %= sub->instance->runtime->period_size;
- spin_unlock_irqrestore(&sub->lock, flags);
- snd_pcm_period_elapsed(sub->instance);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
+ period_elapsed = false;
+ scoped_guard(spinlock_irqsave, &sub->lock) {
+ if (sub->active) {
+ usb6fire_pcm_capture(sub, in_urb);
+ if (sub->period_off >= sub->instance->runtime->period_size) {
+ sub->period_off %= sub->instance->runtime->period_size;
+ period_elapsed = true;
+ }
+ }
+ }
+ if (period_elapsed)
+ snd_pcm_period_elapsed(sub->instance);
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
@@ -338,17 +339,18 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* now send our playback data (if a free out urb was found) */
sub = &rt->playback;
- spin_lock_irqsave(&sub->lock, flags);
- if (sub->active) {
- usb6fire_pcm_playback(sub, out_urb);
- if (sub->period_off >= sub->instance->runtime->period_size) {
- sub->period_off %= sub->instance->runtime->period_size;
- spin_unlock_irqrestore(&sub->lock, flags);
- snd_pcm_period_elapsed(sub->instance);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
+ period_elapsed = false;
+ scoped_guard(spinlock_irqsave, &sub->lock) {
+ if (sub->active) {
+ usb6fire_pcm_playback(sub, out_urb);
+ if (sub->period_off >= sub->instance->runtime->period_size) {
+ sub->period_off %= sub->instance->runtime->period_size;
+ period_elapsed = true;
+ }
+ }
+ }
+ if (period_elapsed)
+ snd_pcm_period_elapsed(sub->instance);
/* setup the 4th byte of each sample (0x40 for analog channels) */
dest = out_urb->buffer;
@@ -392,7 +394,7 @@ static int usb6fire_pcm_open(struct snd_pcm_substream *alsa_sub)
if (rt->panic)
return -EPIPE;
- mutex_lock(&rt->stream_mutex);
+ guard(mutex)(&rt->stream_mutex);
alsa_rt->hw = pcm_hw;
if (alsa_sub->stream == SNDRV_PCM_STREAM_PLAYBACK) {
@@ -408,14 +410,12 @@ static int usb6fire_pcm_open(struct snd_pcm_substream *alsa_sub)
}
if (!sub) {
- mutex_unlock(&rt->stream_mutex);
dev_err(&rt->chip->dev->dev, "invalid stream type.\n");
return -EINVAL;
}
sub->instance = alsa_sub;
sub->active = false;
- mutex_unlock(&rt->stream_mutex);
return 0;
}
@@ -423,18 +423,17 @@ static int usb6fire_pcm_close(struct snd_pcm_substream *alsa_sub)
{
struct pcm_runtime *rt = snd_pcm_substream_chip(alsa_sub);
struct pcm_substream *sub = usb6fire_pcm_get_substream(alsa_sub);
- unsigned long flags;
if (rt->panic)
return 0;
- mutex_lock(&rt->stream_mutex);
+ guard(mutex)(&rt->stream_mutex);
if (sub) {
/* deactivate substream */
- spin_lock_irqsave(&sub->lock, flags);
- sub->instance = NULL;
- sub->active = false;
- spin_unlock_irqrestore(&sub->lock, flags);
+ scoped_guard(spinlock_irqsave, &sub->lock) {
+ sub->instance = NULL;
+ sub->active = false;
+ }
/* all substreams closed? if so, stop streaming */
if (!rt->playback.instance && !rt->capture.instance) {
@@ -442,7 +441,6 @@ static int usb6fire_pcm_close(struct snd_pcm_substream *alsa_sub)
rt->rate = ARRAY_SIZE(rates);
}
}
- mutex_unlock(&rt->stream_mutex);
return 0;
}
@@ -458,7 +456,7 @@ static int usb6fire_pcm_prepare(struct snd_pcm_substream *alsa_sub)
if (!sub)
return -ENODEV;
- mutex_lock(&rt->stream_mutex);
+ guard(mutex)(&rt->stream_mutex);
sub->dma_off = 0;
sub->period_off = 0;
@@ -467,7 +465,6 @@ static int usb6fire_pcm_prepare(struct snd_pcm_substream *alsa_sub)
if (alsa_rt->rate == rates[rt->rate])
break;
if (rt->rate == ARRAY_SIZE(rates)) {
- mutex_unlock(&rt->stream_mutex);
dev_err(&rt->chip->dev->dev,
"invalid rate %d in prepare.\n",
alsa_rt->rate);
@@ -475,19 +472,15 @@ static int usb6fire_pcm_prepare(struct snd_pcm_substream *alsa_sub)
}
ret = usb6fire_pcm_set_rate(rt);
- if (ret) {
- mutex_unlock(&rt->stream_mutex);
+ if (ret)
return ret;
- }
ret = usb6fire_pcm_stream_start(rt);
if (ret) {
- mutex_unlock(&rt->stream_mutex);
dev_err(&rt->chip->dev->dev,
"could not start pcm stream.\n");
return ret;
}
}
- mutex_unlock(&rt->stream_mutex);
return 0;
}
@@ -495,26 +488,22 @@ static int usb6fire_pcm_trigger(struct snd_pcm_substream *alsa_sub, int cmd)
{
struct pcm_substream *sub = usb6fire_pcm_get_substream(alsa_sub);
struct pcm_runtime *rt = snd_pcm_substream_chip(alsa_sub);
- unsigned long flags;
if (rt->panic)
return -EPIPE;
if (!sub)
return -ENODEV;
+ guard(spinlock_irqsave)(&sub->lock);
switch (cmd) {
case SNDRV_PCM_TRIGGER_START:
case SNDRV_PCM_TRIGGER_PAUSE_RELEASE:
- spin_lock_irqsave(&sub->lock, flags);
sub->active = true;
- spin_unlock_irqrestore(&sub->lock, flags);
return 0;
case SNDRV_PCM_TRIGGER_STOP:
case SNDRV_PCM_TRIGGER_PAUSE_PUSH:
- spin_lock_irqsave(&sub->lock, flags);
sub->active = false;
- spin_unlock_irqrestore(&sub->lock, flags);
return 0;
default:
@@ -527,15 +516,13 @@ static snd_pcm_uframes_t usb6fire_pcm_pointer(
{
struct pcm_substream *sub = usb6fire_pcm_get_substream(alsa_sub);
struct pcm_runtime *rt = snd_pcm_substream_chip(alsa_sub);
- unsigned long flags;
snd_pcm_uframes_t ret;
if (rt->panic || !sub)
return SNDRV_PCM_POS_XRUN;
- spin_lock_irqsave(&sub->lock, flags);
+ guard(spinlock_irqsave)(&sub->lock);
ret = sub->dma_off;
- spin_unlock_irqrestore(&sub->lock, flags);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 657/982] ALSA: usb: 6fire: Avoid embedded URBs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (655 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 656/982] ALSA: 6fire: Clean ups with guard() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 658/982] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
` (331 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 9fe49dbc023e82dfaee7b245997d820d01742a9a ]
The USB 6fire driver uses URBs embedded in different structs for PCM,
MIDI and communication, and this is basically a buggy implementation
nowadays; since a URB is managed with a refcount, this may lead to a
UAF when the URB is released asynchronously.
For addressing the problem, this patch converts those embedded URBs to
ones that are properly allocated via usb_alloc_urb(). The
pcm_urb.packets[] is gone, as it's allocated by usb_alloc_urb(), hence
it's found in urb.iso_frame_desc[] instead.
The conversions are rather straightforward; each embedded struct urb
is changed to a pointer, and its callers are updated accordingly.
The resource for those structs are released in the common destructor
functions (usb6fire_comm_free(), etc), which are called at both the
init error path and the disconnect.
No functional changes, only compile-tested.
Link: https://lore.kernel.org/20260903130757.0668310a.michal.pecio@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260903160458.1938392-4-tiwai@suse.de
Stable-dep-of: 1589afe2d099 ("ALSA: 6fire: fix OOB write from device-reported iso length")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/comm.c | 42 +++++++++-----
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 43 +++++++++-----
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 128 ++++++++++++++++++++++++-----------------
sound/usb/6fire/pcm.h | 5 +-
6 files changed, 136 insertions(+), 86 deletions(-)
diff --git a/sound/usb/6fire/comm.c b/sound/usb/6fire/comm.c
index bcfb34db37d95..cfaaad9d24028 100644
--- a/sound/usb/6fire/comm.c
+++ b/sound/usb/6fire/comm.c
@@ -21,7 +21,6 @@ enum {
static void usb6fire_comm_init_urb(struct comm_runtime *rt, struct urb *urb,
u8 *buffer, void *context, void(*handler)(struct urb *urb))
{
- usb_init_urb(urb);
urb->transfer_buffer = buffer;
urb->pipe = usb_sndintpipe(rt->chip->dev, COMM_EP);
urb->complete = handler;
@@ -142,6 +141,19 @@ static int usb6fire_comm_write16(struct comm_runtime *rt, u8 request,
return ret;
}
+static void usb6fire_comm_free(struct comm_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->comm = NULL;
+
+ usb_free_urb(rt->receiver);
+ kfree(rt->receiver_buffer);
+ kfree(rt);
+}
+
int usb6fire_comm_init(struct sfire_chip *chip)
{
struct comm_runtime *rt = kzalloc(sizeof(struct comm_runtime),
@@ -154,14 +166,18 @@ int usb6fire_comm_init(struct sfire_chip *chip)
rt->receiver_buffer = kzalloc(COMM_RECEIVER_BUFSIZE, GFP_KERNEL);
if (!rt->receiver_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
}
- urb = &rt->receiver;
+ urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!urb) {
+ ret = -ENOMEM;
+ goto error;
+ }
+ rt->receiver = urb;
rt->serial = 1;
rt->chip = chip;
- usb_init_urb(urb);
rt->init_urb = usb6fire_comm_init_urb;
rt->write8 = usb6fire_comm_write8;
rt->write16 = usb6fire_comm_write16;
@@ -176,13 +192,15 @@ int usb6fire_comm_init(struct sfire_chip *chip)
urb->interval = 1;
ret = usb_submit_urb(urb, GFP_KERNEL);
if (ret < 0) {
- kfree(rt->receiver_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create comm data receiver.");
- return ret;
+ goto error;
}
chip->comm = rt;
return 0;
+
+ error:
+ usb6fire_comm_free(rt);
+ return ret;
}
void usb6fire_comm_abort(struct sfire_chip *chip)
@@ -190,14 +208,10 @@ void usb6fire_comm_abort(struct sfire_chip *chip)
struct comm_runtime *rt = chip->comm;
if (rt)
- usb_poison_urb(&rt->receiver);
+ usb_poison_urb(rt->receiver);
}
void usb6fire_comm_destroy(struct sfire_chip *chip)
{
- struct comm_runtime *rt = chip->comm;
-
- kfree(rt->receiver_buffer);
- kfree(rt);
- chip->comm = NULL;
+ usb6fire_comm_free(chip->comm);
}
diff --git a/sound/usb/6fire/comm.h b/sound/usb/6fire/comm.h
index 2447d7ecf1798..89976f510f6c2 100644
--- a/sound/usb/6fire/comm.h
+++ b/sound/usb/6fire/comm.h
@@ -19,7 +19,7 @@ enum /* settings for comm */
struct comm_runtime {
struct sfire_chip *chip;
- struct urb receiver;
+ struct urb *receiver;
u8 *receiver_buffer;
u8 serial; /* urb serial */
diff --git a/sound/usb/6fire/midi.c b/sound/usb/6fire/midi.c
index 6c6bccc0c410d..9a1dd5b6557c7 100644
--- a/sound/usb/6fire/midi.c
+++ b/sound/usb/6fire/midi.c
@@ -66,7 +66,7 @@ static void usb6fire_midi_out_trigger(
struct snd_rawmidi_substream *alsa_sub, int up)
{
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
- struct urb *urb = &rt->out_urb;
+ struct urb *urb = rt->out_urb;
__s8 ret;
guard(spinlock_irqsave)(&rt->out_lock);
@@ -137,6 +137,19 @@ static const struct snd_rawmidi_ops in_ops = {
.trigger = usb6fire_midi_in_trigger
};
+static void usb6fire_midi_free(struct midi_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->midi = NULL;
+
+ usb_free_urb(rt->out_urb);
+ kfree(rt->out_buffer);
+ kfree(rt);
+}
+
int usb6fire_midi_init(struct sfire_chip *chip)
{
int ret;
@@ -149,8 +162,14 @@ int usb6fire_midi_init(struct sfire_chip *chip)
rt->out_buffer = kzalloc(MIDI_BUFSIZE, GFP_KERNEL);
if (!rt->out_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
+ }
+
+ rt->out_urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!rt->out_urb) {
+ ret = -ENOMEM;
+ goto error;
}
rt->chip = chip;
@@ -161,15 +180,13 @@ int usb6fire_midi_init(struct sfire_chip *chip)
spin_lock_init(&rt->in_lock);
spin_lock_init(&rt->out_lock);
- comm_rt->init_urb(comm_rt, &rt->out_urb, rt->out_buffer, rt,
+ comm_rt->init_urb(comm_rt, rt->out_urb, rt->out_buffer, rt,
usb6fire_midi_out_handler);
ret = snd_rawmidi_new(chip->card, "6FireUSB", 0, 1, 1, &rt->instance);
if (ret < 0) {
- kfree(rt->out_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "unable to create midi.\n");
- return ret;
+ goto error;
}
rt->instance->private_data = rt;
strcpy(rt->instance->name, "DMX6FireUSB MIDI");
@@ -183,6 +200,10 @@ int usb6fire_midi_init(struct sfire_chip *chip)
chip->midi = rt;
return 0;
+
+ error:
+ usb6fire_midi_free(rt);
+ return ret;
}
void usb6fire_midi_abort(struct sfire_chip *chip)
@@ -190,14 +211,10 @@ void usb6fire_midi_abort(struct sfire_chip *chip)
struct midi_runtime *rt = chip->midi;
if (rt)
- usb_poison_urb(&rt->out_urb);
+ usb_poison_urb(rt->out_urb);
}
void usb6fire_midi_destroy(struct sfire_chip *chip)
{
- struct midi_runtime *rt = chip->midi;
-
- kfree(rt->out_buffer);
- kfree(rt);
- chip->midi = NULL;
+ usb6fire_midi_free(chip->midi);
}
diff --git a/sound/usb/6fire/midi.h b/sound/usb/6fire/midi.h
index 47640c845903b..8716ab8a863ae 100644
--- a/sound/usb/6fire/midi.h
+++ b/sound/usb/6fire/midi.h
@@ -22,7 +22,7 @@ struct midi_runtime {
spinlock_t in_lock;
spinlock_t out_lock;
struct snd_rawmidi_substream *out;
- struct urb out_urb;
+ struct urb *out_urb;
u8 out_serial; /* serial number of out packet */
u8 *out_buffer;
int buffer_offset;
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 14d23e3103989..9e8f4371e89ff 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -138,8 +138,8 @@ static void usb6fire_pcm_stream_stop(struct pcm_runtime *rt)
rt->stream_state = STREAM_STOPPING;
for (i = 0; i < PCM_N_URBS; i++) {
- usb_kill_urb(&rt->in_urbs[i].instance);
- usb_kill_urb(&rt->out_urbs[i].instance);
+ usb_kill_urb(rt->in_urbs[i].instance);
+ usb_kill_urb(rt->out_urbs[i].instance);
}
ctrl_rt->usb_streaming = false;
ctrl_rt->update_streaming(ctrl_rt);
@@ -161,13 +161,13 @@ static int usb6fire_pcm_stream_start(struct pcm_runtime *rt)
rt->stream_state = STREAM_STARTING;
for (i = 0; i < PCM_N_URBS; i++) {
for (k = 0; k < PCM_N_PACKETS_PER_URB; k++) {
- packet = &rt->in_urbs[i].packets[k];
+ packet = &rt->in_urbs[i].instance->iso_frame_desc[k];
packet->offset = k * rt->in_packet_size;
packet->length = rt->in_packet_size;
packet->actual_length = 0;
packet->status = 0;
}
- ret = usb_submit_urb(&rt->in_urbs[i].instance,
+ ret = usb_submit_urb(rt->in_urbs[i].instance,
GFP_ATOMIC);
if (ret) {
usb6fire_pcm_stream_stop(rt);
@@ -197,6 +197,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
unsigned int total_length = 0;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = NULL;
u32 *dest = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
@@ -207,8 +208,9 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].actual_length > 4)
- frame_count = (urb->packets[i].actual_length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->actual_length > 4)
+ frame_count = (isoc->actual_length - 4)
/ (rt->in_n_analog << 2);
else
frame_count = 0;
@@ -220,7 +222,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
else
return;
src++; /* skip leading 4 bytes of every packet */
- total_length += urb->packets[i].length;
+ total_length += isoc->length;
for (frame = 0; frame < frame_count; frame++) {
memcpy(dest, src, bytes_per_frame);
dest += alsa_rt->channels;
@@ -244,6 +246,7 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
int frame_count;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
u32 *src_end = (u32 *) (alsa_rt->dma_area + alsa_rt->buffer_size
@@ -263,8 +266,9 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].length > 4)
- frame_count = (urb->packets[i].length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->length > 4)
+ frame_count = (isoc->length - 4)
/ (rt->out_n_analog << 2);
else
frame_count = 0;
@@ -289,6 +293,7 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
struct pcm_urb *out_urb = in_urb->peer;
struct pcm_runtime *rt = in_urb->chip->pcm;
struct pcm_substream *sub;
+ struct usb_iso_packet_descriptor *isoc_out, *isoc_in;
bool period_elapsed;
int total_length = 0;
int frame_count;
@@ -299,11 +304,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
if (usb_urb->status || rt->panic || rt->stream_state == STREAM_STOPPING)
return;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (in_urb->packets[i].status) {
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->status) {
rt->panic = true;
return;
}
+ }
if (rt->stream_state == STREAM_DISABLED) {
dev_err(&rt->chip->dev->dev,
@@ -328,12 +335,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
- out_urb->packets[i].offset = total_length;
- out_urb->packets[i].length = (in_urb->packets[i].actual_length
- - 4) / (rt->in_n_analog << 2)
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ isoc_out->offset = total_length;
+ isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
* (rt->out_n_analog << 2) + 4;
- out_urb->packets[i].status = 0;
- total_length += out_urb->packets[i].length;
+ isoc_out->status = 0;
+ total_length += isoc_out->length;
}
memset(out_urb->buffer, 0, total_length);
@@ -354,9 +362,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup the 4th byte of each sample (0x40 for analog channels) */
dest = out_urb->buffer;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (out_urb->packets[i].length >= 4) {
- frame_count = (out_urb->packets[i].length - 4)
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ if (isoc_out->length >= 4) {
+ frame_count = (isoc_out->length - 4)
/ (rt->out_n_analog << 2);
*(dest++) = 0xaa;
*(dest++) = 0xaa;
@@ -370,8 +379,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
*(dest++) = 0x40;
}
}
- usb_submit_urb(&out_urb->instance, GFP_ATOMIC);
- usb_submit_urb(&in_urb->instance, GFP_ATOMIC);
+ }
+
+ usb_submit_urb(out_urb->instance, GFP_ATOMIC);
+ usb_submit_urb(in_urb->instance, GFP_ATOMIC);
}
static void usb6fire_pcm_out_urb_handler(struct urb *usb_urb)
@@ -534,22 +545,25 @@ static const struct snd_pcm_ops pcm_ops = {
.pointer = usb6fire_pcm_pointer,
};
-static void usb6fire_pcm_init_urb(struct pcm_urb *urb,
- struct sfire_chip *chip, bool in, int ep,
- void (*handler)(struct urb *))
+static int usb6fire_pcm_init_urb(struct pcm_urb *urb,
+ struct sfire_chip *chip, bool in, int ep,
+ void (*handler)(struct urb *))
{
urb->chip = chip;
- usb_init_urb(&urb->instance);
- urb->instance.transfer_buffer = urb->buffer;
- urb->instance.transfer_buffer_length =
+ urb->instance = usb_alloc_urb(PCM_N_PACKETS_PER_URB, GFP_KERNEL);
+ if (!urb->instance)
+ return -ENOMEM;
+ urb->instance->transfer_buffer = urb->buffer;
+ urb->instance->transfer_buffer_length =
PCM_N_PACKETS_PER_URB * PCM_MAX_PACKET_SIZE;
- urb->instance.dev = chip->dev;
- urb->instance.pipe = in ? usb_rcvisocpipe(chip->dev, ep)
+ urb->instance->dev = chip->dev;
+ urb->instance->pipe = in ? usb_rcvisocpipe(chip->dev, ep)
: usb_sndisocpipe(chip->dev, ep);
- urb->instance.interval = 1;
- urb->instance.complete = handler;
- urb->instance.context = urb;
- urb->instance.number_of_packets = PCM_N_PACKETS_PER_URB;
+ urb->instance->interval = 1;
+ urb->instance->complete = handler;
+ urb->instance->context = urb;
+ urb->instance->number_of_packets = PCM_N_PACKETS_PER_URB;
+ return 0;
}
static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
@@ -571,14 +585,23 @@ static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
return 0;
}
-static void usb6fire_pcm_buffers_destroy(struct pcm_runtime *rt)
+static void usb6fire_pcm_free(struct pcm_runtime *rt)
{
int i;
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->pcm = NULL;
+
for (i = 0; i < PCM_N_URBS; i++) {
+ usb_free_urb(rt->out_urbs[i].instance);
kfree(rt->out_urbs[i].buffer);
+ usb_free_urb(rt->in_urbs[i].instance);
kfree(rt->in_urbs[i].buffer);
}
+ kfree(rt);
}
int usb6fire_pcm_init(struct sfire_chip *chip)
@@ -593,11 +616,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
return -ENOMEM;
ret = usb6fire_pcm_buffers_init(rt);
- if (ret) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- return ret;
- }
+ if (ret)
+ goto error;
rt->chip = chip;
rt->stream_state = STREAM_DISABLED;
@@ -609,10 +629,14 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
spin_lock_init(&rt->capture.lock);
for (i = 0; i < PCM_N_URBS; i++) {
- usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
- usb6fire_pcm_in_urb_handler);
- usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
- usb6fire_pcm_out_urb_handler);
+ ret = usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
+ usb6fire_pcm_in_urb_handler);
+ if (ret < 0)
+ goto error;
+ ret = usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
+ usb6fire_pcm_out_urb_handler);
+ if (ret < 0)
+ goto error;
rt->in_urbs[i].peer = &rt->out_urbs[i];
rt->out_urbs[i].peer = &rt->in_urbs[i];
@@ -620,10 +644,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
ret = snd_pcm_new(chip->card, "DMX6FireUSB", 0, 1, 1, &pcm);
if (ret < 0) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create pcm instance.\n");
- return ret;
+ goto error;
}
pcm->private_data = rt;
@@ -636,6 +658,10 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
chip->pcm = rt;
return 0;
+
+ error:
+ usb6fire_pcm_free(rt);
+ return ret;
}
void usb6fire_pcm_abort(struct sfire_chip *chip)
@@ -653,8 +679,8 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
snd_pcm_stop_xrun(rt->capture.instance);
for (i = 0; i < PCM_N_URBS; i++) {
- usb_poison_urb(&rt->in_urbs[i].instance);
- usb_poison_urb(&rt->out_urbs[i].instance);
+ usb_poison_urb(rt->in_urbs[i].instance);
+ usb_poison_urb(rt->out_urbs[i].instance);
}
}
@@ -662,9 +688,5 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
void usb6fire_pcm_destroy(struct sfire_chip *chip)
{
- struct pcm_runtime *rt = chip->pcm;
-
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- chip->pcm = NULL;
+ usb6fire_pcm_free(chip->pcm);
}
diff --git a/sound/usb/6fire/pcm.h b/sound/usb/6fire/pcm.h
index 5a092dfd69f5a..b586fe220fd11 100644
--- a/sound/usb/6fire/pcm.h
+++ b/sound/usb/6fire/pcm.h
@@ -24,10 +24,7 @@ enum /* settings for pcm */
struct pcm_urb {
struct sfire_chip *chip;
- /* BEGIN DO NOT SEPARATE */
- struct urb instance;
- struct usb_iso_packet_descriptor packets[PCM_N_PACKETS_PER_URB];
- /* END DO NOT SEPARATE */
+ struct urb *instance;
u8 *buffer;
struct pcm_urb *peer;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 658/982] ALSA: 6fire: fix OOB write from device-reported iso length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (656 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 657/982] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 659/982] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
` (330 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+855929c2df672879, Xiang Mei,
Takashi Iwai, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 1589afe2d099d3e817873bc474676968d7080410 ]
usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as
(actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where
actual_length is the unsigned length the device reported for the matching
IN packet. A packet completed with status 0 and actual_length < 4 wraps
the subtraction to 0x7fffffec; a zero-length isochronous packet is legal
on the bus, and the preceding loop rejects only non-zero status. The sum
reaches memset() on out_urb->buffer, a 4832-byte object from
kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).
Even without the wrap the result is out of bounds: at 88.2/96 kHz the
4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight
packets span 5024 bytes of that buffer. usb_submit_urb() rejects an
over-long descriptor only after the memset() and the
usb6fire_pcm_playback() copy of user PCM data have run.
Guard the subtraction as the sibling usb6fire_pcm_capture() already does,
and limit the frame count to what fits in rt->out_packet_size, the OUT
endpoint's wMaxPacketSize. This bounds total_length by the buffer size
while keeping each packet length aligned to a whole output frame.
BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018
Call Trace:
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
__asan_memset (mm/kasan/shadow.c:84)
usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Allocated by task 10:
__kmalloc_cache_noprof (mm/slub.c:5563)
usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)
usb6fire_chip_probe (sound/usb/6fire/chip.c:133)
usb_probe_interface (drivers/usb/core/driver.c:399)
The buggy address belongs to the object at ffff88802a3d0000
which belongs to the cache kmalloc-8k of size 8192
The buggy address is located 0 bytes inside of
4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)
Kernel panic - not syncing: Fatal exception in interrupt
Fixes: c6d43ba816d1 ("ALSA: usb/6fire - Driver for TerraTec DMX 6Fire USB")
Reported-by: co+855929c2df672879@bugs.sh
Closes: https://lore.kernel.org/all/gisnub8aWGLbyZLcDCSc7zWsHonMWGcyRgt5%40bugs.sh/
Assisted-by: LLM
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260914074324.3590843-1-xmei5@asu.edu
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/pcm.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 9e8f4371e89ff..5f6a63f79990b 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -335,11 +335,19 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ unsigned int frames = 0;
+
isoc_out = &out_urb->instance->iso_frame_desc[i];
isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->actual_length > 4)
+ frames = (isoc_in->actual_length - 4)
+ / (rt->in_n_analog << 2);
+ frames = min_t(unsigned int, frames,
+ (rt->out_packet_size - 4)
+ / (rt->out_n_analog << 2));
+
isoc_out->offset = total_length;
- isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
- * (rt->out_n_analog << 2) + 4;
+ isoc_out->length = frames * (rt->out_n_analog << 2) + 4;
isoc_out->status = 0;
total_length += isoc_out->length;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 659/982] wifi: virt_wifi: dont transfer operstate before register
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (657 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 658/982] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 660/982] drm/atomic-helper: Add atomic_enable plane-helper callback Greg Kroah-Hartman
` (329 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
[ Upstream commit e5c8d7acd31b27057ea42cd405d0b3ece097bc89 ]
virt_wifi_newlink() calls netif_stacked_transfer_operstate() before
register_netdevice(). If the lower device is dormant, that queues the
new netdev on lweventlist while it is still uninitialized. If
registration fails after that, for example because of an invalid name
such as "bad/name", free_netdev() immediately frees the object. A
later linkwatch_fire_event() then use-after-frees the list entry.
Move the transfer to after netdev_upper_dev_link(), as macvlan and
ipvlan already do.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Link: https://patch.msgid.link/f5a832fb0ab228ce6e2b5a91fba4ca8b79198a2f.1788948455.git.zihanx@nebusec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virt_wifi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/virt_wifi.c b/drivers/net/wireless/virt_wifi.c
index 474451e8b5e16..dd2a74f7d06e6 100644
--- a/drivers/net/wireless/virt_wifi.c
+++ b/drivers/net/wireless/virt_wifi.c
@@ -552,7 +552,6 @@ static int virt_wifi_newlink(struct net *src_net, struct net_device *dev,
}
eth_hw_addr_inherit(dev, priv->lowerdev);
- netif_stacked_transfer_operstate(priv->lowerdev, dev);
dev->ieee80211_ptr = kzalloc(sizeof(*dev->ieee80211_ptr), GFP_KERNEL);
@@ -578,6 +577,8 @@ static int virt_wifi_newlink(struct net *src_net, struct net_device *dev,
goto unregister_netdev;
}
+ netif_stacked_transfer_operstate(priv->lowerdev, dev);
+
dev->priv_destructor = virt_wifi_net_device_destructor;
priv->being_deleted = false;
priv->is_connected = false;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 660/982] drm/atomic-helper: Add atomic_enable plane-helper callback
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (658 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 659/982] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 661/982] drm/ast: Remove little-endianism from I/O helpers Greg Kroah-Hartman
` (328 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann,
Javier Martinez Canillas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Zimmermann <tzimmermann@suse.de>
[ Upstream commit 169b9182f192e8725c8de5d7d77f00f6ae6c7fd4 ]
Add atomic_enable to struct drm_plane_helper_funcs. It enables a
plane independently from updating the plane's content. As such, it is
the inverse of the atomic_disable plane helper. Useful for hardware
where plane enable state is independent from plane content.
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20230209154107.30680-2-tzimmermann@suse.de
Stable-dep-of: 073a30d75f30 ("drm/vc4: Use managed KMS polling to fix UAF on unbind")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_atomic_helper.c | 20 ++++++++++++----
include/drm/drm_atomic_helper.h | 26 +++++++++++++++++++++
include/drm/drm_modeset_helper_vtables.h | 29 +++++++++++++++++++++++-
3 files changed, 70 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/drm_atomic_helper.c b/drivers/gpu/drm/drm_atomic_helper.c
index e737e45a3a702..9199695d42ddd 100644
--- a/drivers/gpu/drm/drm_atomic_helper.c
+++ b/drivers/gpu/drm/drm_atomic_helper.c
@@ -2743,6 +2743,11 @@ void drm_atomic_helper_commit_planes(struct drm_device *dev,
funcs->atomic_disable(plane, old_state);
} else if (new_plane_state->crtc || disabling) {
funcs->atomic_update(plane, old_state);
+
+ if (!disabling && funcs->atomic_enable) {
+ if (drm_atomic_plane_enabling(old_plane_state, new_plane_state))
+ funcs->atomic_enable(plane, old_state);
+ }
}
}
@@ -2803,6 +2808,7 @@ drm_atomic_helper_commit_planes_on_crtc(struct drm_crtc_state *old_crtc_state)
struct drm_plane_state *new_plane_state =
drm_atomic_get_new_plane_state(old_state, plane);
const struct drm_plane_helper_funcs *plane_funcs;
+ bool disabling;
plane_funcs = plane->helper_private;
@@ -2812,12 +2818,18 @@ drm_atomic_helper_commit_planes_on_crtc(struct drm_crtc_state *old_crtc_state)
WARN_ON(new_plane_state->crtc &&
new_plane_state->crtc != crtc);
- if (drm_atomic_plane_disabling(old_plane_state, new_plane_state) &&
- plane_funcs->atomic_disable)
+ disabling = drm_atomic_plane_disabling(old_plane_state, new_plane_state);
+
+ if (disabling && plane_funcs->atomic_disable) {
plane_funcs->atomic_disable(plane, old_state);
- else if (new_plane_state->crtc ||
- drm_atomic_plane_disabling(old_plane_state, new_plane_state))
+ } else if (new_plane_state->crtc || disabling) {
plane_funcs->atomic_update(plane, old_state);
+
+ if (!disabling && plane_funcs->atomic_enable) {
+ if (drm_atomic_plane_enabling(old_plane_state, new_plane_state))
+ plane_funcs->atomic_enable(plane, old_state);
+ }
+ }
}
if (crtc_funcs && crtc_funcs->atomic_flush)
diff --git a/include/drm/drm_atomic_helper.h b/include/drm/drm_atomic_helper.h
index 06d8902a80972..8fc53d249c690 100644
--- a/include/drm/drm_atomic_helper.h
+++ b/include/drm/drm_atomic_helper.h
@@ -210,6 +210,32 @@ int drm_atomic_helper_page_flip_target(
__drm_atomic_get_current_plane_state((crtc_state)->state, \
plane)))
+/**
+ * drm_atomic_plane_enabling - check whether a plane is being enabled
+ * @old_plane_state: old atomic plane state
+ * @new_plane_state: new atomic plane state
+ *
+ * Checks the atomic state of a plane to determine whether it's being enabled
+ * or not. This also WARNs if it detects an invalid state (both CRTC and FB
+ * need to either both be NULL or both be non-NULL).
+ *
+ * RETURNS:
+ * True if the plane is being enabled, false otherwise.
+ */
+static inline bool drm_atomic_plane_enabling(struct drm_plane_state *old_plane_state,
+ struct drm_plane_state *new_plane_state)
+{
+ /*
+ * When enabling a plane, CRTC and FB should always be set together.
+ * Anything else should be considered a bug in the atomic core, so we
+ * gently warn about it.
+ */
+ WARN_ON((!new_plane_state->crtc && new_plane_state->fb) ||
+ (new_plane_state->crtc && !new_plane_state->fb));
+
+ return !old_plane_state->crtc && new_plane_state->crtc;
+}
+
/**
* drm_atomic_plane_disabling - check whether a plane is being disabled
* @old_plane_state: old atomic plane state
diff --git a/include/drm/drm_modeset_helper_vtables.h b/include/drm/drm_modeset_helper_vtables.h
index 6f19cf5c210e5..f74745435894b 100644
--- a/include/drm/drm_modeset_helper_vtables.h
+++ b/include/drm/drm_modeset_helper_vtables.h
@@ -1267,6 +1267,32 @@ struct drm_plane_helper_funcs {
*/
void (*atomic_update)(struct drm_plane *plane,
struct drm_atomic_state *state);
+
+ /**
+ * @atomic_enable:
+ *
+ * Drivers should use this function to unconditionally enable a plane.
+ * This hook is called in-between the &drm_crtc_helper_funcs.atomic_begin
+ * and drm_crtc_helper_funcs.atomic_flush callbacks. It is called after
+ * @atomic_update, which will be called for all enabled planes. Drivers
+ * that use @atomic_enable should set up a plane in @atomic_update and
+ * afterwards enable the plane in @atomic_enable. If a plane needs to be
+ * enabled before installing the scanout buffer, drivers can still do
+ * so in @atomic_update.
+ *
+ * Note that the power state of the display pipe when this function is
+ * called depends upon the exact helpers and calling sequence the driver
+ * has picked. See drm_atomic_helper_commit_planes() for a discussion of
+ * the tradeoffs and variants of plane commit helpers.
+ *
+ * This callback is used by the atomic modeset helpers, but it is
+ * optional. If implemented, @atomic_enable should be the inverse of
+ * @atomic_disable. Drivers that don't want to use either can still
+ * implement the complete plane update in @atomic_update.
+ */
+ void (*atomic_enable)(struct drm_plane *plane,
+ struct drm_atomic_state *state);
+
/**
* @atomic_disable:
*
@@ -1287,7 +1313,8 @@ struct drm_plane_helper_funcs {
* the tradeoffs and variants of plane commit helpers.
*
* This callback is used by the atomic modeset helpers and by the
- * transitional plane helpers, but it is optional.
+ * transitional plane helpers, but it is optional. It's intended to
+ * reverse the effects of @atomic_enable.
*/
void (*atomic_disable)(struct drm_plane *plane,
struct drm_atomic_state *state);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 661/982] drm/ast: Remove little-endianism from I/O helpers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (659 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 660/982] drm/atomic-helper: Add atomic_enable plane-helper callback Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 662/982] drm/ast: Rework definition of I/O read and write helpers Greg Kroah-Hartman
` (327 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann,
Javier Martinez Canillas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Zimmermann <tzimmermann@suse.de>
[ Upstream commit a38410860628909712ea6a2becd42bab56c70e9a ]
Replace one call to ast_io_write16() with two calls to ast_io_write8()
in ast_set_index_reg(). The combined 16-bit-wide write of an index
register and the corresponding data register only works on little-
endian systems. Write both registers independent from each other.
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20230221155745.27484-2-tzimmermann@suse.de
Stable-dep-of: 073a30d75f30 ("drm/vc4: Use managed KMS polling to fix UAF on unbind")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/ast/ast_drv.h | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/ast/ast_drv.h b/drivers/gpu/drm/ast/ast_drv.h
index 2e44b971c3a6b..22328693fcf33 100644
--- a/drivers/gpu/drm/ast/ast_drv.h
+++ b/drivers/gpu/drm/ast/ast_drv.h
@@ -281,7 +281,9 @@ static inline void ast_set_index_reg(struct ast_private *ast,
uint32_t base, uint8_t index,
uint8_t val)
{
- ast_io_write16(ast, base, ((u16)val << 8) | index);
+ ast_io_write8(ast, base, index);
+ ++base;
+ ast_io_write8(ast, base, val);
}
void ast_set_index_reg_mask(struct ast_private *ast,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 662/982] drm/ast: Rework definition of I/O read and write helpers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (660 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 661/982] drm/ast: Remove little-endianism from I/O helpers Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 663/982] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
` (326 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann,
Javier Martinez Canillas, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Zimmermann <tzimmermann@suse.de>
[ Upstream commit faf67f640fa6c036d19727e294a2915e3fe5bf7c ]
Ast defines a number of I/O helpers for accessing hardware. Only 4 of
the many generated functions are actually used. Replace the respective
generator macros with those 4 functions. No functional changes.
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20230221155745.27484-3-tzimmermann@suse.de
Stable-dep-of: 073a30d75f30 ("drm/vc4: Use managed KMS polling to fix UAF on unbind")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/ast/ast_drv.h | 48 ++++++++++-------------------------
1 file changed, 14 insertions(+), 34 deletions(-)
diff --git a/drivers/gpu/drm/ast/ast_drv.h b/drivers/gpu/drm/ast/ast_drv.h
index 22328693fcf33..58fcad3ba0dfb 100644
--- a/drivers/gpu/drm/ast/ast_drv.h
+++ b/drivers/gpu/drm/ast/ast_drv.h
@@ -237,45 +237,25 @@ struct ast_private *ast_device_create(const struct drm_driver *drv,
#define AST_IO_VGACRCB_HWC_ENABLED BIT(1)
#define AST_IO_VGACRCB_HWC_16BPP BIT(0) /* set: ARGB4444, cleared: 2bpp palette */
-#define __ast_read(x) \
-static inline u##x ast_read##x(struct ast_private *ast, u32 reg) { \
-u##x val = 0;\
-val = ioread##x(ast->regs + reg); \
-return val;\
+static inline u32 ast_read32(struct ast_private *ast, u32 reg)
+{
+ return ioread32(ast->regs + reg);
}
-__ast_read(8);
-__ast_read(16);
-__ast_read(32)
-
-#define __ast_io_read(x) \
-static inline u##x ast_io_read##x(struct ast_private *ast, u32 reg) { \
-u##x val = 0;\
-val = ioread##x(ast->ioregs + reg); \
-return val;\
+static inline void ast_write32(struct ast_private *ast, u32 reg, u32 val)
+{
+ iowrite32(val, ast->regs + reg);
}
-__ast_io_read(8);
-__ast_io_read(16);
-__ast_io_read(32);
-
-#define __ast_write(x) \
-static inline void ast_write##x(struct ast_private *ast, u32 reg, u##x val) {\
- iowrite##x(val, ast->regs + reg);\
- }
-
-__ast_write(8);
-__ast_write(16);
-__ast_write(32);
-
-#define __ast_io_write(x) \
-static inline void ast_io_write##x(struct ast_private *ast, u32 reg, u##x val) {\
- iowrite##x(val, ast->ioregs + reg);\
- }
+static inline u8 ast_io_read8(struct ast_private *ast, u32 reg)
+{
+ return ioread8(ast->ioregs + reg);
+}
-__ast_io_write(8);
-__ast_io_write(16);
-#undef __ast_io_write
+static inline void ast_io_write8(struct ast_private *ast, u32 reg, u8 val)
+{
+ iowrite8(val, ast->ioregs + reg);
+}
static inline void ast_set_index_reg(struct ast_private *ast,
uint32_t base, uint8_t index,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 663/982] ALSA: hda: trace PCM open only after assigning a stream
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (661 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 662/982] drm/ast: Rework definition of I/O read and write helpers Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 664/982] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
` (325 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Slavin Liu, Takashi Iwai,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slavin Liu <bolin.liu@seu.edu.cn>
[ Upstream commit c9e6e5f38bf75276605f1952b22285f5f3abcaff ]
Stream assignment can fail when hardware streams are exhausted.
Move the tracepoint after the NULL check because its payload accesses
the assigned stream tag.
Detected by static analysis and reviewed with AI-assisted source auditing.
Fixes: 184865085b88 ("ALSA: hda - rename hda_intel_trace.h to hda_controller_trace.h")
Assisted-by: LLM
Signed-off-by: Slavin Liu <bolin.liu@seu.edu.cn>
Link: https://patch.msgid.link/20260913125154.109944-1-bolin.liu@seu.edu.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/hda_controller.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/pci/hda/hda_controller.c b/sound/pci/hda/hda_controller.c
index 16ff8e510996b..8fc363a6fe96c 100644
--- a/sound/pci/hda/hda_controller.c
+++ b/sound/pci/hda/hda_controller.c
@@ -587,11 +587,11 @@ static int azx_pcm_open(struct snd_pcm_substream *substream)
snd_hda_codec_pcm_get(apcm->info);
mutex_lock(&chip->open_mutex);
azx_dev = azx_assign_device(chip, substream);
- trace_azx_pcm_open(chip, azx_dev);
if (azx_dev == NULL) {
err = -EBUSY;
goto unlock;
}
+ trace_azx_pcm_open(chip, azx_dev);
runtime->private_data = azx_dev;
runtime->hw = azx_pcm_hw;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 664/982] btrfs: tree-checker: print dev extent offset in error message
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (662 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 663/982] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 665/982] drm/msm/dsi: correct byte intf clock rate for 14nm DSI PHY Greg Kroah-Hartman
` (324 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit a1167d9420474ab9ed9efca99d86aeb6217c0265 ]
If a dev extent's offset is not sector size aligned, the error message is
printing the dev extent's objectid instead of the offset. This is a copy
paste error, as before this check we check the objectid field.
Fixes: 008e2512dc56 ("btrfs: tree-checker: add dev extent item checks")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/tree-checker.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/btrfs/tree-checker.c b/fs/btrfs/tree-checker.c
index 8e9139dc4bbe2..b55eb223b58bd 100644
--- a/fs/btrfs/tree-checker.c
+++ b/fs/btrfs/tree-checker.c
@@ -1729,7 +1729,7 @@ static int check_dev_extent_item(const struct extent_buffer *leaf,
sectorsize))) {
generic_err(leaf, slot,
"invalid dev extent chunk offset, has %llu not aligned to %u",
- btrfs_dev_extent_chunk_objectid(leaf, de),
+ btrfs_dev_extent_chunk_offset(leaf, de),
sectorsize);
return -EUCLEAN;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 665/982] drm/msm/dsi: correct byte intf clock rate for 14nm DSI PHY
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (663 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 664/982] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 666/982] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
` (323 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Dmitry Baryshkov,
Konrad Dybcio, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
[ Upstream commit 1d5e01dfa3410bc94476e3050485852d6bba3fe0 ]
According to the vendor kernel, byte intf clock rate should be a half of
the byte clock only when DSI PHY version is above 2.0 (in other words,
10nm PHYs and later) and only if PHY is used in D-PHY mode. Currently
MSM DSI code handles only the second part of the clause (C-PHY vs
D-PHY), skipping DSI PHY version check, which causes issues on some of
14nm DSI PHY platforms (e.g. qcm2290).
Move divisor selection to DSI PHY code, pass selected divisor through
shared timings and set byte intf clock rate accordingly.
Cc: Loic Poulain <loic.poulain@linaro.org>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Tested-by: Konrad Dybcio <konrad.dybcio@linaro.org> # SM6115P J606F
Reviewed-by: Konrad Dybcio <konrad.dybcio@linaro.org>
Patchwork: https://patchwork.freedesktop.org/patch/519006/
Link: https://lore.kernel.org/r/20230118130027.2345719-1-dmitry.baryshkov@linaro.org
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Stable-dep-of: 2028280686f4 ("drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/dsi.h | 1 +
drivers/gpu/drm/msm/dsi/dsi_host.c | 14 ++++++--------
drivers/gpu/drm/msm/dsi/phy/dsi_phy.c | 4 ++++
3 files changed, 11 insertions(+), 8 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/dsi.h b/drivers/gpu/drm/msm/dsi/dsi.h
index 6b239f77fca94..1e7dd46cece21 100644
--- a/drivers/gpu/drm/msm/dsi/dsi.h
+++ b/drivers/gpu/drm/msm/dsi/dsi.h
@@ -140,6 +140,7 @@ struct msm_dsi_phy_shared_timings {
u32 clk_post;
u32 clk_pre;
bool clk_pre_inc_by_2;
+ bool byte_intf_clk_div_2;
};
struct msm_dsi_phy_clk_request {
diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
index 335c15e430b73..6ff5cd8482004 100644
--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -122,6 +122,7 @@ struct msm_dsi_host {
struct clk *byte_intf_clk;
unsigned long byte_clk_rate;
+ unsigned long byte_intf_clk_rate;
unsigned long pixel_clk_rate;
unsigned long esc_clk_rate;
@@ -399,7 +400,6 @@ int msm_dsi_runtime_resume(struct device *dev)
int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
{
- unsigned long byte_intf_rate;
int ret;
DBG("Set clk rates: pclk=%lu, byteclk=%lu",
@@ -419,13 +419,7 @@ int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
}
if (msm_host->byte_intf_clk) {
- /* For CPHY, byte_intf_clk is same as byte_clk */
- if (msm_host->cphy_mode)
- byte_intf_rate = msm_host->byte_clk_rate;
- else
- byte_intf_rate = msm_host->byte_clk_rate / 2;
-
- ret = clk_set_rate(msm_host->byte_intf_clk, byte_intf_rate);
+ ret = clk_set_rate(msm_host->byte_intf_clk, msm_host->byte_intf_clk_rate);
if (ret) {
pr_err("%s: Failed to set rate byte intf clk, %d\n",
__func__, ret);
@@ -2428,6 +2422,10 @@ int msm_dsi_host_power_on(struct mipi_dsi_host *host,
goto unlock_ret;
}
+ msm_host->byte_intf_clk_rate = msm_host->byte_clk_rate;
+ if (phy_shared_timings->byte_intf_clk_div_2)
+ msm_host->byte_intf_clk_rate /= 2;
+
msm_dsi_sfpb_config(msm_host, true);
ret = regulator_bulk_enable(msm_host->cfg_hnd->cfg->num_regulators,
diff --git a/drivers/gpu/drm/msm/dsi/phy/dsi_phy.c b/drivers/gpu/drm/msm/dsi/phy/dsi_phy.c
index c0bcf020ef662..905bc25dc30bb 100644
--- a/drivers/gpu/drm/msm/dsi/phy/dsi_phy.c
+++ b/drivers/gpu/drm/msm/dsi/phy/dsi_phy.c
@@ -350,6 +350,8 @@ int msm_dsi_dphy_timing_calc_v3(struct msm_dsi_dphy_timing *timing,
timing->shared_timings.clk_pre_inc_by_2 = 0;
}
+ timing->shared_timings.byte_intf_clk_div_2 = true;
+
timing->ta_go = 3;
timing->ta_sure = 0;
timing->ta_get = 4;
@@ -454,6 +456,8 @@ int msm_dsi_dphy_timing_calc_v4(struct msm_dsi_dphy_timing *timing,
tmax = 255;
timing->shared_timings.clk_pre = DIV_ROUND_UP((tmax - tmin) * 125, 10000) + tmin;
+ timing->shared_timings.byte_intf_clk_div_2 = true;
+
DBG("%d, %d, %d, %d, %d, %d, %d, %d, %d, %d",
timing->shared_timings.clk_pre, timing->shared_timings.clk_post,
timing->clk_zero, timing->clk_trail, timing->clk_prepare, timing->hs_exit,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 666/982] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (664 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 665/982] drm/msm/dsi: correct byte intf clock rate for 14nm DSI PHY Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 667/982] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
` (322 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abel Vesa, Krzysztof Kozlowski,
Dmitry Baryshkov, Konrad Dybcio, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 2028280686f4fa78e2f1f6dede4b6c1fd782b9e3 ]
DSI 6G v2.9 hosts (SM8650, SM8750, Kaanapali, etc.) reparent the byte and
pixel RCGs to the DSI PHY PLL at runtime from
dsi_link_clk_set_rate_6g_v2_9(), after the PHY has been enabled. However
dsi_calc_clk_rate_6g() runs earlier, in order to compute the bit clock
request for the PHY. At that point the byte RCG still has its reset
parent (XO), so clk_round_rate() returns a bogus rate, which then ends up
in the PHY bit clock request and the PLL gets programmed to a wrong
frequency, breaking the panel.
Move the rounding to dsi_link_clk_set_rate_6g(), which is called after
the RCGs have been reparented to the PLL. Storing the rounded rate at
this point still makes later link_clk_set_rate() calls no-ops in the
CCF. Derive the byte interface clock rate from the rounded byte clock
rate, otherwise it would keep requesting the idealized rate and
retrigger the PLL on every transfer.
Reported-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reported-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Fixes: 6cd33b6f4155 ("drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value")
Assisted-by: LLM
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> # SM6115P J606F
Tested-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/750496/
Link: https://lore.kernel.org/r/20260903-fix-eliza-dsi-v1-1-3474a6c9f2e0@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 ++++++++++++++++--------------
1 file changed, 19 insertions(+), 17 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
index 6ff5cd8482004..634e42630dbf2 100644
--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -122,7 +122,7 @@ struct msm_dsi_host {
struct clk *byte_intf_clk;
unsigned long byte_clk_rate;
- unsigned long byte_intf_clk_rate;
+ bool byte_intf_clk_div_2;
unsigned long pixel_clk_rate;
unsigned long esc_clk_rate;
@@ -400,8 +400,20 @@ int msm_dsi_runtime_resume(struct device *dev)
int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
{
+ unsigned long byte_intf_clk_rate;
+ long rounded_byte_clk_rate;
int ret;
+ rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
+ msm_host->byte_clk_rate);
+ if (rounded_byte_clk_rate < 0) {
+ pr_err("%s: failed to round byte clock rate, %ld\n",
+ __func__, rounded_byte_clk_rate);
+ return rounded_byte_clk_rate;
+ }
+
+ msm_host->byte_clk_rate = rounded_byte_clk_rate;
+
DBG("Set clk rates: pclk=%lu, byteclk=%lu",
msm_host->pixel_clk_rate, msm_host->byte_clk_rate);
@@ -419,7 +431,11 @@ int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
}
if (msm_host->byte_intf_clk) {
- ret = clk_set_rate(msm_host->byte_intf_clk, msm_host->byte_intf_clk_rate);
+ byte_intf_clk_rate = msm_host->byte_clk_rate;
+ if (msm_host->byte_intf_clk_div_2)
+ byte_intf_clk_rate /= 2;
+
+ ret = clk_set_rate(msm_host->byte_intf_clk, byte_intf_clk_rate);
if (ret) {
pr_err("%s: Failed to set rate byte intf clk, %d\n",
__func__, ret);
@@ -610,24 +626,12 @@ static void dsi_calc_pclk(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
int dsi_calc_clk_rate_6g(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
{
- long rounded_byte_clk_rate;
-
if (!msm_host->mode) {
pr_err("%s: mode not set\n", __func__);
return -EINVAL;
}
dsi_calc_pclk(msm_host, is_bonded_dsi);
-
- rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
- msm_host->byte_clk_rate);
- if (rounded_byte_clk_rate < 0) {
- pr_err("%s: failed to round byte clock rate, %ld\n",
- __func__, rounded_byte_clk_rate);
- return rounded_byte_clk_rate;
- }
-
- msm_host->byte_clk_rate = rounded_byte_clk_rate;
msm_host->esc_clk_rate = clk_get_rate(msm_host->esc_clk);
return 0;
}
@@ -2422,9 +2426,7 @@ int msm_dsi_host_power_on(struct mipi_dsi_host *host,
goto unlock_ret;
}
- msm_host->byte_intf_clk_rate = msm_host->byte_clk_rate;
- if (phy_shared_timings->byte_intf_clk_div_2)
- msm_host->byte_intf_clk_rate /= 2;
+ msm_host->byte_intf_clk_div_2 = phy_shared_timings->byte_intf_clk_div_2;
msm_dsi_sfpb_config(msm_host, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 667/982] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (665 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 666/982] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 668/982] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
` (321 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Mayer, David Ahern,
Hangbin Liu, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Mayer <andrea.mayer@uniroma2.it>
[ Upstream commit 7616242a2b37883f7322aaa1d2bd6cd0fed28315 ]
When an SRv6 packet arrives on an interface enslaved to a VRF,
vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate()
has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the
common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of
a reassembled outer packet could even set it, with no VRF involved.
Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP
decapsulation") then made the unreliable bit reliably clear.
The effect of the missing flag is visible with End.DX4 when a
delivery to a local address of the node reaches the socket lookup.
For example, a UDP socket bound to the enslaved ingress interface
does not receive any of the decapsulated packets, while an unbound
socket outside the VRF does.
This contradicts Documentation/networking/vrf.rst: by default the
scope of an unbound UDP or TCP socket is limited to the default VRF.
Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does
the same for IPv6. The socket lookup then matches the decapsulated
packet like any other packet received on that enslaved interface. Such
a packet matches an unbound UDP or TCP socket only when
udp_l3mdev_accept or tcp_l3mdev_accept is set.
Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions")
Signed-off-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260913194421.31-1-andrea.mayer@uniroma2.it
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/seg6_local.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c
index b7d3563572f0d..b73c7ee3acd90 100644
--- a/net/ipv6/seg6_local.c
+++ b/net/ipv6/seg6_local.c
@@ -246,10 +246,13 @@ static bool decap_and_validate(struct sk_buff *skb, int proto)
return false;
if (proto == IPPROTO_IPIP) {
+ bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
IPCB(skb)->iif = iif;
+ if (l3slave)
+ IPCB(skb)->flags |= IPSKB_L3SLAVE;
} else if (proto == IPPROTO_IPV6) {
bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 668/982] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (666 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 667/982] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 669/982] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
` (320 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Jiayuan Chen,
Dong Chenchen, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dong Chenchen <dongchenchen2@huawei.com>
[ Upstream commit 2998147b59c9df0a51477c7a6b3d1f0ba3127dd4 ]
When the forward output route cannot be used in icmp_route_lookup(),
it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr,
the original packet's source address.
ip_route_input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip_rt_bug(). The existing check only rejects
RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN_ON_ONCE()
in ip_rt_bug() as bellow:
------------[ cut here ]------------
WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20
RIP: 0010:ip_rt_bug+0x14/0x20
Call Trace:
ip_push_pending_frames+0xfa/0x100
__icmp_send+0x905/0xf10
ip_options_compile+0xc0/0xd0
ip_rcv_finish_core+0x321/0xae0
ip_rcv+0x1de/0x260
__netif_receive_skb_one_core+0x11a/0x130
netif_receive_skb+0x7b/0x260
tun_get_user+0x11bf/0x1c10
------------[ cut here ]------------
Reject input route that is RTN_UNREACHABLE to fix it. The net warning
is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of
a race condition.
Fixes: 8b7817f3a959 ("[IPSEC]: Add ICMP host relookup support")
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Dong Chenchen <dongchenchen2@huawei.com>
Link: https://patch.msgid.link/20260910140042.1880242-1-dongchenchen2@huawei.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/icmp.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
index 5c38af80bc14e..28f0a10034e73 100644
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -571,16 +571,19 @@ static struct rtable *icmp_route_lookup(struct net *net, struct flowi4 *fl4,
skb_dstref_restore(skb_in, orefdst);
/*
- * At this point, fl4_dec.daddr should NOT be local (we
- * checked fl4_dec.saddr above). However, a race condition
- * may occur if the address is added to the interface
- * concurrently. In that case, ip_route_input() returns a
- * LOCAL route with dst.output=ip_rt_bug, which must not
- * be used for output.
+ * fl4_dec.daddr is not expected to be local here, but it can be
+ * added to an interface concurrently, in which case
+ * ip_route_input() returns a LOCAL route. It can also fail to
+ * build a forwarding route towards fl4_dec.daddr, for example,
+ * when forwarding is disabled, and return an UNREACHABLE route.
+ * Both cases will result in a route with dst.output=ip_rt_bug,
+ * which must not be used for output.
*/
- if (!err && rt2 && rt2->rt_type == RTN_LOCAL) {
+ if (!err && rt2 && rt2->rt_type == RTN_LOCAL)
net_warn_ratelimited("detected local route for %pI4 during ICMP sending, src %pI4\n",
&fl4_dec.daddr, &fl4_dec.saddr);
+ if (!err && rt2 &&
+ (rt2->rt_type == RTN_LOCAL || rt2->rt_type == RTN_UNREACHABLE)) {
dst_release(&rt2->dst);
err = -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 669/982] net: fddi: skfp: fix NULL deref when setting the MAC address while down
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (667 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 668/982] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 670/982] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
` (319 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hohyun Sim, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hohyun Sim <tlaghgus0425@korea.ac.kr>
[ Upstream commit 7c8810c2e69c3d9ca6df870b40ae9218e50b4fb1 ]
skfp_ctl_set_mac_address() calls ResetAdapter() unconditionally, without
checking netif_running(). ResetAdapter() first calls card_stop(), which
sets smc->hw.hw_state to STOPPED, and then mac_drv_clear_tx_queue(),
which walks the two transmit queues:
for (i = QUEUE_S; i <= QUEUE_A0; i++) {
queue = smc->hw.fp.tx[i] ;
...
t = queue->tx_curr_get ;
smc->hw.fp.tx[] is only populated by init_tx(), which is reached from
skfp_open() through init_smt() -> init_fddi_driver() -> init_fplus() ->
init_mac() -> init_tx(). The private area is allocated and zeroed by
alloc_fddidev(), so on an interface that has never been brought up both
queue pointers are still NULL. The hw_state test at the top of
mac_drv_clear_tx_queue() does not catch this, because card_stop() has
just set STOPPED; the function proceeds into the loop and dereferences
NULL. ResetAdapter() does call init_smt() itself, but only after the
queues have been cleared.
Setting the MAC address on a down interface therefore oopses:
ip link set dev fddi0 address 02:00:00:00:00:01
BUG: KASAN: null-ptr-deref in mac_drv_clear_tx_queue+0x68/0x2c0 [skfp]
Read of size 8 at addr 0000000000000010 by task ip/302
Call Trace:
<TASK>
mac_drv_clear_tx_queue+0x68/0x2c0 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
ResetAdapter+0x29/0x100 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
skfp_ctl_set_mac_address+0x57/0x80 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
netif_set_mac_address+0x1e4/0x2c0
do_setlink+0x684/0x2680
</TASK>
Address 0x10 is the offset of tx_curr_get, the third pointer in
struct s_smt_tx_queue, on 64-bit. mac_drv_clear_rx_queue(), which
ResetAdapter() calls immediately afterwards, dereferences
smc->hw.fp.rx[QUEUE_R1] in the same way behind the same ineffective
hw_state test; the transmit queue merely crashes first. Both are
covered by the guard below.
Skip the adapter reset when the interface is down. dev_addr_set() is
left unconditional, so the new address is still recorded in
dev->dev_addr. Nothing is lost by not resetting the adapter here:
skfp_open() deliberately re-reads the factory address on every open,
read_address(smc, NULL);
eth_hw_addr_set(dev, smc->hw.fddi_canon_addr.a);
and the comment above it states this is done to discard exactly such an
address override across a close/open cycle. An address set while the
interface is down could not have survived the following open even
before this change, so the guard removes no working behaviour. Guarding
the hardware side of ndo_set_mac_address() with netif_running() is
established practice; skge_set_mac_address() has done so since commit
2eb3e621c4e0 ("skge: set mac address bonding fix").
Guarding the reset as a whole, rather than NULL-checking the queues, is
also what the rest of the driver expects. After a previous open/close
the queue pointers are stale but non-NULL, so there is no crash, yet
ResetAdapter() goes on to call smt_online() and STI_FBI() ("Enable
Board Interrupts") while skfp_close() has already called free_irq() -
the adapter would be brought back online with no handler installed. The
only other ResetAdapter() caller is skfp_interrupt(), which by
construction runs only while the device is open.
Found by automated driver testing against an emulated SysKonnect FDDI
adapter under a KASAN-enabled 7.0.0 kernel. Triggering it requires
CAP_NET_ADMIN.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: LLM KASAN
Signed-off-by: Hohyun Sim <tlaghgus0425@korea.ac.kr>
Link: https://patch.msgid.link/20260910063743.110747-1-tlaghgus0425@korea.ac.kr
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/fddi/skfp/skfddi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/fddi/skfp/skfddi.c b/drivers/net/fddi/skfp/skfddi.c
index 2b6a607ac0b78..9264a5f112d4e 100644
--- a/drivers/net/fddi/skfp/skfddi.c
+++ b/drivers/net/fddi/skfp/skfddi.c
@@ -927,7 +927,8 @@ static int skfp_ctl_set_mac_address(struct net_device *dev, void *addr)
dev_addr_set(dev, p_sockaddr->sa_data);
spin_lock_irqsave(&bp->DriverLock, Flags);
- ResetAdapter(smc);
+ if (netif_running(dev))
+ ResetAdapter(smc);
spin_unlock_irqrestore(&bp->DriverLock, Flags);
return 0; /* always return zero */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 670/982] wifi: brcmfmac: fix lost 802.1x TX completion wakeup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (668 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 669/982] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 671/982] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
` (318 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Arend van Spriel,
Johannes Berg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 621d90169cef6c8da5b6134db5c0c4e23cdd09ce ]
brcmf_txfinalize() decrements pend_8021x_cnt before a lockless
waitqueue_active() check. atomic_dec() does not order the decrement
against the check.
The waiter can therefore observe a nonzero count while the waker observes
an empty queue, losing the final wakeup and delaying key installation
until the 950 ms timeout.
Add smp_mb__after_atomic() to order the decrement before the queue
check. wait_event_timeout() provides the matching barrier. LKMM confirms
that this forbids the lost-wakeup outcome.
Fixes: 21fff75d2fb6 ("brcmfmac: use wait_event_timeout for 8021x pending count")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260811082702.44521-1-kmehltretter@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
index 7b8104d171c51..dfb00d4548310 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
@@ -549,6 +549,8 @@ void brcmf_txfinalize(struct brcmf_if *ifp, struct sk_buff *txp, bool success)
if (type == ETH_P_PAE) {
atomic_dec(&ifp->pend_8021x_cnt);
+ /* Order the decrement before waitqueue_active() */
+ smp_mb__after_atomic();
if (waitqueue_active(&ifp->pend_8021x_wait))
wake_up(&ifp->pend_8021x_wait);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 671/982] net: bridge: mst: move switchdev call outside rcu
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (669 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 670/982] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 672/982] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
` (317 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Aleksandrov, Ido Schimmel,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikolay Aleksandrov <razor@blackwall.org>
[ Upstream commit 18a6fe05fb6e18de29fa90d388bb34044114b3d8 ]
This is a follow-up of one of sashiko's pre-existing bug reports.
br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
while holding rcu_read_lock() which invokes the blocking switchdev
notifier chain and may sleep. Nonzero MSTI changes come from netlink
with rtnl held. Move the switchdev call before entering the rcu section and
assert that rtnl is held.
The call cannot be deferred because netlink needs its error and extack.
Also DSA reads the old bridge MST state during the callback and checks it.
A deferred callback will be late and will see the updated state.
Fixes: 3a7c1661ae13 ("net: bridge: mst: fix vlan use-after-free")
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260911105021.1385934-1-razor@blackwall.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_mst.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/net/bridge/br_mst.c b/net/bridge/br_mst.c
index 43a300ae6bfaf..1654efd3045b0 100644
--- a/net/bridge/br_mst.c
+++ b/net/bridge/br_mst.c
@@ -107,21 +107,24 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
struct net_bridge_vlan *v;
int err = 0;
- rcu_read_lock();
- vg = nbp_vlan_group_rcu(p);
- if (!vg)
- goto out;
-
/* MSTI 0 (CST) state changes are notified via the regular
- * SWITCHDEV_ATTR_ID_PORT_STP_STATE.
+ * SWITCHDEV_ATTR_ID_PORT_STP_STATE. All other MSTIs are handled via
+ * netlink with RTNL held
*/
if (msti) {
+ ASSERT_RTNL();
+
err = switchdev_port_attr_set(p->dev, &attr, extack);
if (err && err != -EOPNOTSUPP)
goto out;
+ err = 0;
}
- err = 0;
+ rcu_read_lock();
+ vg = nbp_vlan_group_rcu(p);
+ if (!vg)
+ goto out_rcu_unlock;
+
list_for_each_entry_rcu(v, &vg->vlan_list, vlist) {
if (v->brvlan->msti != msti)
continue;
@@ -129,8 +132,9 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
br_mst_vlan_set_state(vg, v, state);
}
-out:
+out_rcu_unlock:
rcu_read_unlock();
+out:
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 672/982] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (670 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 671/982] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 673/982] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
` (316 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taras Madan, Kuniyuki Iwashima,
Xuanqiang Luo, Eric Dumazet, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 8e759cd1f6444a946bd1fd2b2b29eea582eea1d5 ]
tcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for
TCP_LISTEN since commit 073d89808c06 ("net: fix data-races around
sk->sk_forward_alloc").
However, there is still a small race window between tcp_v6_rcv()
and tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN
to TCP_CLOSE, causing skb_clone_and_charge_r() to be called
locklessly and resulting in the splat below. [0]
Let's avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well.
This is fine for non-listeners because tcp_rcv_state_process()
drops skb for TCP_CLOSE and opt_skb was freed immediately anyway.
[0]:
sk->sk_forward_alloc
WARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28
Modules linked in:
CPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
RIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162
Code: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 <0f> 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff
RSP: 0018:ffffc90000677bb8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41
RDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005
RBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000
R10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000
R13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003
FS: 0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__sk_destruct+0x82/0xae0 net/core/sock.c:2356
rcu_do_batch kernel/rcu/tree.c:2645 [inline]
rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897
handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622
run_ksoftirqd kernel/softirq.c:1076 [inline]
run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068
smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160
kthread+0x396/0x4a0 kernel/kthread.c:436
ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Fixes: e994b2f0fb92 ("tcp: do not lock listener to process SYN packets")
Reported-by: Taras Madan <tarasmadan@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914011420.115556-1-kuniyu@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/tcp_ipv6.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index d3952b058453f..ec668c19cb976 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1449,7 +1449,8 @@ int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb)
by tcp. Feel free to propose better solution.
--ANK (980728)
*/
- if (np->rxopt.all && sk->sk_state != TCP_LISTEN)
+ if (np->rxopt.all &&
+ !((1 << sk->sk_state) & (TCPF_LISTEN | TCPF_CLOSE)))
opt_skb = skb_clone_and_charge_r(skb, sk);
reason = SKB_DROP_REASON_NOT_SPECIFIED;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 673/982] tcp: do not let tcp_rmem be set below 4096
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (671 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 672/982] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 674/982] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
` (315 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 83a945a529d6e002dd7339c532288a931f463dba ]
We can hit a division by zero crash in tcp_rcvbuf_grow()
and tcp_rcv_space_adjust():
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
The division uses oldval = tp->rcvq_space.space as divisor.
When tp->rcvq_space.space is zero, this leads to a divide-by-zero
exception.
tp->rcvq_space.space is initialized in tcp_init_buffer_space():
tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
(u32)TCP_INIT_CWND * tp->advmss);
If tcp_rmem[1] is configured to very small values (such as 1),
sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which
computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.
This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and
tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,
tcp_rcvbuf_grow() divides by oldval == 0.
Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF
and RCVBUF for min length") ensured that net.core.rmem_default and
net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,
SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).
However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing
arbitrarily small values.
Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline
alignment, its value varies across architectures and configuration options.
Using a fixed constant of 4096 ensures a predictable, architecture-
independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere
and matches the documented 4K default.
Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912144848.3448026-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/networking/ip-sysctl.rst | 2 ++
net/ipv4/sysctl_net_ipv4.c | 4 +++-
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst
index b47b3d0ce5596..0a5ae93b44617 100644
--- a/Documentation/networking/ip-sysctl.rst
+++ b/Documentation/networking/ip-sysctl.rst
@@ -717,6 +717,8 @@ tcp_rmem - vector of 3 INTEGERs: min, default, max
case this value is ignored.
Default: between 131072 and 6MB, depending on RAM size.
+ Each of the three values cannot be set below 4096.
+
tcp_sack - BOOLEAN
Enable select acknowledgments (SACKS).
diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c
index 5d6ded54e237a..49c94650712ee 100644
--- a/net/ipv4/sysctl_net_ipv4.c
+++ b/net/ipv4/sysctl_net_ipv4.c
@@ -42,6 +42,8 @@ static u32 fib_multipath_hash_fields_all_mask __maybe_unused =
FIB_MULTIPATH_HASH_FIELD_ALL_MASK;
static unsigned int tcp_child_ehash_entries_max = 16 * 1024 * 1024;
+static int tcp_min_rcvbuf = 4096;
+
/* obsolete */
static int sysctl_tcp_low_latency __read_mostly;
@@ -1317,7 +1319,7 @@ static struct ctl_table ipv4_net_table[] = {
.maxlen = sizeof(init_net.ipv4.sysctl_tcp_rmem),
.mode = 0644,
.proc_handler = proc_dointvec_minmax,
- .extra1 = SYSCTL_ONE,
+ .extra1 = &tcp_min_rcvbuf,
},
{
.procname = "tcp_comp_sack_delay_ns",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 674/982] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (672 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 673/982] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 675/982] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
` (314 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baineng Shou, Frank Li, Vinod Koul,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baineng Shou <shoubaineng@gmail.com>
[ Upstream commit 075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47 ]
In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist
putting each entry into 'sg', but the entry length is read from 'sgl'
(the list head) instead of 'sg' (the current entry):
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
avail = sg_dma_len(sgl); /* should be 'sg' */
Consequently 'avail' is always the length of the first entry. For
multi-sg lists this causes out-of-bounds reads when a later entry is
shorter than the first, and silent data loss when it is longer.
Single-sg or uniformly-sized lists happen to mask the issue.
Fixes: c8acd6aa6bed3 ("dmaengine: mmp-pdma support")
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260910021652.1296640-1-shoubaineng@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/mmp_pdma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/mmp_pdma.c b/drivers/dma/mmp_pdma.c
index bac4905c47db7..c51a296e3c1c1 100644
--- a/drivers/dma/mmp_pdma.c
+++ b/drivers/dma/mmp_pdma.c
@@ -542,7 +542,7 @@ mmp_pdma_prep_slave_sg(struct dma_chan *dchan, struct scatterlist *sgl,
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
- avail = sg_dma_len(sgl);
+ avail = sg_dma_len(sg);
do {
len = min_t(size_t, avail, PDMA_MAX_DESC_BYTES);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 675/982] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (673 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 674/982] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 676/982] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
` (313 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 7b60ee5f46f2ee329de661f7c68b6818d8136220 ]
In btmtksdio_shutdown(), pm_runtime_get_sync() is called at the
beginning of the function. However, if sending the WMT function
control command fails later, the driver returns early.
It bypasses the corresponding pm_runtime_put_noidle() and
pm_runtime_disable() calls, leaking the PM usage counter and leaving PM
runtime enabled indefinitely.
Fall through to execute the PM runtime cleanup block even if WMT errors.
Fixes: 7f3c563c575e ("Bluetooth: btmtksdio: Add runtime PM support to SDIO based Bluetooth")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtksdio.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/bluetooth/btmtksdio.c b/drivers/bluetooth/btmtksdio.c
index 0432ae9bc6601..0fe86fd809512 100644
--- a/drivers/bluetooth/btmtksdio.c
+++ b/drivers/bluetooth/btmtksdio.c
@@ -1216,10 +1216,8 @@ static int btmtksdio_shutdown(struct hci_dev *hdev)
wmt_params.status = NULL;
err = mtk_hci_wmt_sync(hdev, &wmt_params);
- if (err < 0) {
+ if (err < 0)
bt_dev_err(hdev, "Failed to send wmt func ctrl (%d)", err);
- return err;
- }
ignore_wmt_cmd:
pm_runtime_put_noidle(bdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 676/982] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (674 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 675/982] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 677/982] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
` (312 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0cece8fa7d83523f47a3,
Juan Perdomo, Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Juan Perdomo <jcperdomo100@gmail.com>
[ Upstream commit 801fb950cae7048eb7d83b18857d1ca37b8cd5a4 ]
rfcomm_sock_cleanup_listen() closes unaccepted child sockets through
rfcomm_sock_close(), which takes the child socket lock before
rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these
locks in reverse order while handling connections and DLC state changes,
so lockdep reports a possible deadlock.
Close dequeued children without taking their socket lock. The accept queue
owns a reference to each child, and bt_accept_dequeue() locks the child
while unlinking it and clearing its parent pointer.
Dropping the child lock makes it important to prevent a concurrent
rfcomm_connect_ind() from enqueueing a new child after cleanup observes an
empty queue. Set a listening socket to BT_CLOSED while its lock is still
held, before dropping the lock and draining the queue. The state check in
rfcomm_connect_ind() then rejects new children once cleanup starts.
Reported-by: syzbot+0cece8fa7d83523f47a3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0cece8fa7d83523f47a3
Fixes: b7ce436a5d79 ("Bluetooth: switch to lock_sock in RFCOMM")
Signed-off-by: Juan Perdomo <jcperdomo100@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/sock.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/rfcomm/sock.c b/net/bluetooth/rfcomm/sock.c
index d72cdcd2e2bb1..729c70c992cfa 100644
--- a/net/bluetooth/rfcomm/sock.c
+++ b/net/bluetooth/rfcomm/sock.c
@@ -243,9 +243,7 @@ static void __rfcomm_sock_close(struct sock *sk)
*/
static void rfcomm_sock_close(struct sock *sk)
{
- lock_sock(sk);
__rfcomm_sock_close(sk);
- release_sock(sk);
}
static void rfcomm_sock_init(struct sock *sk, struct sock *parent)
@@ -903,6 +901,7 @@ static int rfcomm_sock_compat_ioctl(struct socket *sock, unsigned int cmd, unsig
static int rfcomm_sock_shutdown(struct socket *sock, int how)
{
struct sock *sk = sock->sk;
+ bool cleanup_listen = false;
int err = 0;
BT_DBG("sock %p, sk %p", sock, sk);
@@ -913,9 +912,17 @@ static int rfcomm_sock_shutdown(struct socket *sock, int how)
lock_sock(sk);
if (!sk->sk_shutdown) {
sk->sk_shutdown = SHUTDOWN_MASK;
+ if (sk->sk_state == BT_LISTEN) {
+ /* Block new children before cleaning up without sk lock. */
+ sk->sk_state = BT_CLOSED;
+ cleanup_listen = true;
+ }
release_sock(sk);
- __rfcomm_sock_close(sk);
+ if (cleanup_listen)
+ rfcomm_sock_cleanup_listen(sk);
+ else
+ __rfcomm_sock_close(sk);
lock_sock(sk);
if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime &&
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 677/982] pppoatm: ensure a writable skb header and linear data
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (675 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 676/982] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 678/982] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
` (311 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ecc7253683a3c55caa868ce0ee530fcb0044bd3c ]
In pppoatm_send(), LLC encapsulation checks whether there is sufficient
headroom for the 4-byte LLC header, but does not ensure that the skb header
is writable.
Normal transmit packets passing through ppp_start_xmit() have their header
unshared via skb_cow_head(). However, packets can also reach pppoatm_send()
via PPP channel bridging (PPPIOCBRIDGECHAN) without going through
ppp_start_xmit().
Use skb_cow_head() to ensure both sufficient headroom and a writable
header before pushing the LLC header.
While at it:
- Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent
out-of-bounds reads on zero-length or non-linear frames (e.g. from
bridging).
- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()
succeeds. This eliminates the temporary skb allocation on admission failure
and completely removes the fragile "undo" heuristic at the nospace label,
avoiding any risk of reading uninitialized headroom or performing an
unbalanced skb_push().
Fixes: 4cf476ced45d ("ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912233048.3977192-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/atm/pppoatm.c | 42 +++++++++++++++++-------------------------
1 file changed, 17 insertions(+), 25 deletions(-)
diff --git a/net/atm/pppoatm.c b/net/atm/pppoatm.c
index 3e4f17d335feb..b668a30b67a8d 100644
--- a/net/atm/pppoatm.c
+++ b/net/atm/pppoatm.c
@@ -292,10 +292,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
struct atm_vcc *vcc;
int ret;
+ if (!pskb_may_pull(skb, 1)) {
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+
ATM_SKB(skb)->vcc = pvcc->atmvcc;
pr_debug("(skb=0x%p, vcc=0x%p)\n", skb, pvcc->atmvcc);
- if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
- (void) skb_pull(skb, 1);
vcc = ATM_SKB(skb)->vcc;
bh_lock_sock(sk_atm(vcc));
@@ -318,23 +321,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
switch (pvcc->encaps) { /* LLC encapsulation needed */
case e_llc:
- if (skb_headroom(skb) < LLC_LEN) {
- struct sk_buff *n;
- n = skb_realloc_headroom(skb, LLC_LEN);
- if (n != NULL &&
- !pppoatm_may_send(pvcc, n->truesize)) {
- kfree_skb(n);
- goto nospace;
- }
- consume_skb(skb);
- skb = n;
- if (skb == NULL) {
- bh_unlock_sock(sk_atm(vcc));
- return DROP_PACKET;
- }
- } else if (!pppoatm_may_send(pvcc, skb->truesize))
+ if (skb_cow_head(skb, LLC_LEN)) {
+ bh_unlock_sock(sk_atm(vcc));
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+ if (!pppoatm_may_send(pvcc, skb->truesize))
goto nospace;
- memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
break;
case e_vc:
if (!pppoatm_may_send(pvcc, skb->truesize))
@@ -347,6 +340,12 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return 1;
}
+ if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
+ skb_pull(skb, 1);
+
+ if (pvcc->encaps == e_llc)
+ memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
+
atm_account_tx(vcc, skb);
pr_debug("atm_skb(%p)->vcc(%p)->dev(%p)\n",
skb, ATM_SKB(skb)->vcc, ATM_SKB(skb)->vcc->dev);
@@ -356,13 +355,6 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return ret;
nospace:
bh_unlock_sock(sk_atm(vcc));
- /*
- * We don't have space to send this SKB now, but we might have
- * already applied SC_COMP_PROT compression, so may need to undo
- */
- if ((pvcc->flags & SC_COMP_PROT) && skb_headroom(skb) > 0 &&
- skb->data[-1] == '\0')
- (void) skb_push(skb, 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 678/982] drop_monitor: synchronize tracepoint unregistration on error path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (676 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 677/982] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 679/982] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
` (310 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 6a038ef2b57922b6d9ca98ddac0df0681849b704 ]
If register_trace_napi_poll() fails in net_dm_trace_on_set(),
unregister_trace_kfree_skb() is called to roll back the kfree_skb
tracepoint registration.
However, tracepoint_synchronize_unregister() is omitted before calling
cancel_work_sync() and module_put(). An in-flight probe executing
concurrently on another CPU could call schedule_work() after
cancel_work_sync() has already returned, leaving a pending work item
scheduled after the module reference is dropped. If the module is then
unloaded, executing the work item triggers a kernel panic.
Add tracepoint_synchronize_unregister() after unregister_trace_kfree_skb()
in the error path, matching net_dm_trace_off_set() and
net_dm_hw_probe_unregister().
Fixes: 7c747838a558 ("drop_monitor: Split tracing enable / disable to different functions")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 78c248b9b6860..513b2f460aaa5 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -1156,6 +1156,7 @@ static int net_dm_trace_on_set(struct netlink_ext_ack *extack)
err_unregister_trace:
unregister_trace_kfree_skb(ops->kfree_skb_probe, NULL);
+ tracepoint_synchronize_unregister();
err_module_put:
for_each_possible_cpu(cpu) {
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 679/982] drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (677 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 678/982] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 680/982] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
` (309 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 439f392084f8f7f59ab9d47a9579185accefe1d8 ]
In reset_per_cpu_data(), al is computed as:
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
al += sizeof(struct nlattr);
skb = genlmsg_new(al, GFP_KERNEL);
...
nla = nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg));
...
msg = nla_data(nla);
memset(msg, 0, al);
Because al includes sizeof(struct nlattr) (the 4-byte attribute header),
genlmsg_new() allocates al bytes of tailroom starting at nla.
However, msg points to nla_data(nla), which is located
sizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al)
therefore writes al bytes starting from msg, exceeding the allocated
buffer by sizeof(struct nlattr) (4 bytes) and corrupting
skb_shared_info.
Fix this by letting al represent only the payload length, allocating
the skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing
al bytes from msg.
Fixes: 683703a26e46 ("drop_monitor: Update netlink protocol to include netlink attribute header in alert message")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 513b2f460aaa5..eebdd54726f89 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -138,9 +138,8 @@ static struct sk_buff *reset_per_cpu_data(struct per_cpu_dm_data *data)
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
- al += sizeof(struct nlattr);
- skb = genlmsg_new(al, GFP_KERNEL);
+ skb = genlmsg_new(nla_total_size(al), GFP_KERNEL);
if (!skb)
goto err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 680/982] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (678 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 679/982] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 681/982] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
` (308 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 51938dfa8a51a4f85328413fca9b6e21f9d2d088 ]
kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops
mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a
reference on the kvm_nested_guest pointer obtained from the IDR. A
concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race
through kvmhv_flush_nested() -> kvmhv_remove_nested() -> idr_remove /
--refcnt -> kvmhv_release_nested() -> kfree(gp) in that window, leaving
the iterating vCPU with a dangling pointer. The subsequent
mutex_lock(&gp->tlb_lock) and accesses to gp->shadow_pgtable,
gp->shadow_lpid and gp->l1_host all touch freed memory. The free path
is fully L1-controlled.
Fix this by incrementing gp->refcnt inside the loop before dropping
mmu_lock, mirroring what kvmhv_get_nested() does, and releasing the
reference with kvmhv_put_nested() after the per-guest work completes.
This is the same get/put discipline already used at every other
call site that drops mmu_lock while holding a nested-guest pointer.
Fixes: e3b6b4661527 ("KVM: PPC: Book3S HV: Implement H_TLB_INVALIDATE hcall")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_nested.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/powerpc/kvm/book3s_hv_nested.c b/arch/powerpc/kvm/book3s_hv_nested.c
index bc71a90c7cc76..5839b3d4cc77e 100644
--- a/arch/powerpc/kvm/book3s_hv_nested.c
+++ b/arch/powerpc/kvm/book3s_hv_nested.c
@@ -1172,8 +1172,10 @@ static void kvmhv_emulate_tlbie_all_lpid(struct kvm_vcpu *vcpu, int ric)
spin_lock(&kvm->mmu_lock);
idr_for_each_entry(&kvm->arch.kvm_nested_guest_idr, gp, lpid) {
+ ++gp->refcnt;
spin_unlock(&kvm->mmu_lock);
kvmhv_emulate_tlbie_lpid(vcpu, gp, ric);
+ kvmhv_put_nested(gp);
spin_lock(&kvm->mmu_lock);
}
spin_unlock(&kvm->mmu_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 681/982] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (679 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 680/982] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 682/982] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
` (307 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 0a416ee20bcccddf91ca5b63696a23b9d11d73aa ]
In kvmppc_svm_page_in(), if uv_page_in() fails after
kvmppc_uvmem_get_page() has succeeded, the secure device page is never
released. kvmppc_uvmem_get_page() sets a bit in kvmppc_uvmem_bitmap,
allocates a kvmppc_uvmem_page_pvt struct, marks the GFN as
KVMPPC_GFN_UVMEM_PFN, and calls zone_device_page_init() which sets
refcount=1 and locks the page. The subsequent goto out_finalize skips
the *mig.dst assignment, so migrate_vma_finalize() is a no-op for the
page, and none of those resources are ever reclaimed.
Each occurrence permanently consumes one entry from the firmware-bounded
secure memory pool (kvmppc_uvmem_bitmap), leaks pvt, and leaves the GFN
marked as secure — making it unusable for the lifetime of the VM.
The twin __kvmppc_svm_page_out() already handles the analogous uv_page_out()
failure correctly with unlock_page(dpage); __free_page(dpage). Apply
the same pattern here: unlock_page() followed by put_page(), which
chains through free_zone_device_folio() into kvmppc_uvmem_folio_free()
to clear the bitmap bit, free pvt, and reset the GFN state.
Reachable whenever uv_page_in() returns an error (e.g. UV pool
exhaustion) on any POWER9/10 + Ultravisor/PEF system.
Fixes: ca9f4942670c ("KVM: PPC: Book3S HV: Support for running secure guests")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kvm/book3s_hv_uvmem.c b/arch/powerpc/kvm/book3s_hv_uvmem.c
index e2f11f9c3f2aa..2bc67f8ef82c5 100644
--- a/arch/powerpc/kvm/book3s_hv_uvmem.c
+++ b/arch/powerpc/kvm/book3s_hv_uvmem.c
@@ -774,8 +774,11 @@ static int kvmppc_svm_page_in(struct vm_area_struct *vma,
if (spage) {
ret = uv_page_in(kvm->arch.lpid, pfn << page_shift,
gpa, 0, page_shift);
- if (ret)
+ if (ret) {
+ unlock_page(dpage);
+ put_page(dpage);
goto out_finalize;
+ }
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 682/982] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (680 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 681/982] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 683/982] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
` (306 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Shivaprasad G Bhat, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivaprasad G Bhat <sbhat@linux.ibm.com>
[ Upstream commit 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 ]
The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.
Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.
Fixes: b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Shivaprasad G Bhat <sbhat@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/iommu.c b/arch/powerpc/kernel/iommu.c
index a612abe4bfd57..81bd60c8094c1 100644
--- a/arch/powerpc/kernel/iommu.c
+++ b/arch/powerpc/kernel/iommu.c
@@ -1055,7 +1055,7 @@ int iommu_tce_check_ioba(unsigned long page_shift,
if (ioba < offset)
return -EINVAL;
- if ((ioba + 1) > (offset + size))
+ if ((ioba + npages < ioba) || (ioba - offset + npages > size))
return -EINVAL;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 683/982] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (681 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 682/982] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 684/982] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
` (305 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Sasha Levin,
Linus Walleij, Mark Brown
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
[ Upstream commit 11fc0048a6930f4fca44fe3bd16a0023e78846a2 ]
arm allmodconfig fails to build with gcc:
In file included from sound/soc/ux500/ux500_msp_i2s.c:20:
sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses
around arithmetic in operand of '^' [-Werror=parentheses]
sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro
'MSP_TX_CLKPOL_BIT'
cc1: all warnings being treated as errors
The macros never parenthesized their argument:
#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
That went unnoticed while every caller passed a plain variable, but
configure_protocol() now passes an XOR expression, which binds as
"a ^ (b & MASK)" rather than "(a ^ b) & MASK", and gcc rightly
complains.
No functional change: tx_clk_pol and rx_clk_pol only ever hold
MSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a
bool, so masking before or after the XOR gives the same 0/1 result.
Parenthesize the argument anyway - it fixes the build and stops the
macros from silently mis-evaluating a future composite argument.
Fixes: 9ccbacf5a012 ("ASoC: ux500: Validate MSP DAI configuration")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609051547.G9SJp8UQ-lkp@intel.com/
Assisted-by: LLM
Signed-off-by: Sasha Levin <sashal@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260913173132.1172003-1-sashal@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_i2s.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 2bf2699bdc49f..c66ef455e1380 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -147,8 +147,8 @@ enum msp_direction {
#define RCKPOL_MASK BIT(0)
#define TCKPOL_MASK BIT(0)
#define SPICKM_MASK (BIT(1) | BIT(0))
-#define MSP_RX_CLKPOL_BIT(n) ((n & RCKPOL_MASK) << RCKPOL_SHIFT)
-#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
+#define MSP_RX_CLKPOL_BIT(n) (((n) & RCKPOL_MASK) << RCKPOL_SHIFT)
+#define MSP_TX_CLKPOL_BIT(n) (((n) & TCKPOL_MASK) << TCKPOL_SHIFT)
#define P1ELEN_SHIFT 0
#define P1FLEN_SHIFT 3
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 684/982] ASoC: hdmi-codec: Report a change when the channel status moves
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (682 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 683/982] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 685/982] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
` (304 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit c17ae8c26eac16ad244daef44044d714f68a2ddc ]
The put() callback of "IEC958 Playback Default" stores all 24 channel
status bytes and then returns 0. The core notifies userspace only on a
positive return, so a write that changes what the get() callback hands
back is never announced, and a mixer holding the control open keeps
showing the old value.
Compare the stored bytes and return 1 when they move, the way
snd_hda_spdif_default_put() does.
The same shape is in img-spdif-out and uniperif_player.
No board with this codec was to hand. The change is a comparison of
driver state with no hardware behaviour in it, and mixer-test counts the
missing notification as event_missing.
Fixes: 7a8e1d44211e ("ASoC: hdmi-codec: Add iec958 controls")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Assisted-by: Claude:claude-opus-5
Link: https://patch.msgid.link/20260915092515.2638542-1-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/hdmi-codec.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/sound/soc/codecs/hdmi-codec.c b/sound/soc/codecs/hdmi-codec.c
index cb664d3d02dd0..cbb03da04a947 100644
--- a/sound/soc/codecs/hdmi-codec.c
+++ b/sound/soc/codecs/hdmi-codec.c
@@ -422,10 +422,14 @@ static int hdmi_codec_iec958_default_put(struct snd_kcontrol *kcontrol,
struct snd_soc_component *component = snd_kcontrol_chip(kcontrol);
struct hdmi_codec_priv *hcp = snd_soc_component_get_drvdata(component);
+ if (!memcmp(hcp->iec_status, ucontrol->value.iec958.status,
+ sizeof(hcp->iec_status)))
+ return 0;
+
memcpy(hcp->iec_status, ucontrol->value.iec958.status,
sizeof(hcp->iec_status));
- return 0;
+ return 1;
}
static int hdmi_codec_iec958_mask_get(struct snd_kcontrol *kcontrol,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 685/982] net: netsec: fix device_node reference leak on phy_np
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (683 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 684/982] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 686/982] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
` (303 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yige Jiang, Simon Horman,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yige Jiang <yigejiang86@gmail.com>
[ Upstream commit 5ae916fabca141b79b32e2e57f3c915c0f1e1b2e ]
netsec_of_probe() takes a reference on the PHY device_node with
of_parse_phandle() and stores it in priv->phy_np, but the driver never
drops it. One device_node reference is leaked per probe, on the success
path as well as on every error path reached after netsec_of_probe().
Neither consumer takes ownership. of_mdio_parse_addr() is a static
inline taking a const struct device_node * that only reads the "reg"
property. of_phy_connect() borrows as well: of_phy_get_and_connect() in
drivers/net/mdio/of_mdio.c brackets its own call with of_node_get() at
:364 and of_node_put() at :373, which would be a double put if
of_phy_connect() consumed the reference.
The node is still in use at netsec_netdev_open() time, where it is
passed to of_phy_connect(), so it has device lifetime. Release it at
the probe error label, which every failure path after the acquire
funnels through, and in netsec_remove(). Both releases precede
free_netdev(), since priv is netdev_priv(ndev). The ACPI probe path
leaves priv->phy_np NULL and of_node_put(NULL) is a no-op.
There is no end-user visible symptom on currently supported platforms:
a device_node is only freed once OF_DYNAMIC is enabled and the node has
been detached, so on a static device tree the imbalance is inert. It is
observable as a refcount that grows across bind/unbind cycles, and would
matter under device tree overlays.
Found by static analysis of reference acquire/release pairing rather
than from a runtime report. No reproducer was produced and the change
has not been runtime tested; it is compile-tested only (arm64,
CONFIG_SNI_NETSEC=m via COMPILE_TEST).
Fixes: 533dd11a12f6 ("net: socionext: Add Synquacer NetSec driver")
Signed-off-by: Yige Jiang <yigejiang86@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260913064102.37452-1-yigejiang86@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/socionext/netsec.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/socionext/netsec.c b/drivers/net/ethernet/socionext/netsec.c
index b130e978366c1..bffb5728ef714 100644
--- a/drivers/net/ethernet/socionext/netsec.c
+++ b/drivers/net/ethernet/socionext/netsec.c
@@ -2141,6 +2141,7 @@ static int netsec_probe(struct platform_device *pdev)
pm_runtime_put_sync(&pdev->dev);
pm_runtime_disable(&pdev->dev);
free_ndev:
+ of_node_put(priv->phy_np);
free_netdev(ndev);
dev_err(&pdev->dev, "init failed\n");
@@ -2158,6 +2159,7 @@ static int netsec_remove(struct platform_device *pdev)
netif_napi_del(&priv->napi);
pm_runtime_disable(&pdev->dev);
+ of_node_put(priv->phy_np);
free_netdev(priv->ndev);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 686/982] net: lock the socket in sock_gettstamp()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (684 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 685/982] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 687/982] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
` (302 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jungwoo Lee, Wongi Lee, Eric Dumazet,
Simon Horman, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 9ed55f3dbef4f4adfe65eb03b0c35c53229a8490 ]
sk->sk_flags must only be changed while holding the socket lock,
because sock_set_flag() and sock_reset_flag() use non atomic
operations (__set_bit() and __clear_bit()).
sock_gettstamp() is one of the last places where a bit of sk->sk_flags
is changed from a syscall without owning the socket lock, through
sock_enable_timestamp(sk, SOCK_TIMESTAMP).
sk_set_memalloc() and sk_clear_memalloc() also change sk->sk_flags
without the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp,
sunrpc, wireguard) need a careful audit, this will be addressed in a
separate patch.
Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free
caused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind()
can cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set,
because both threads perform a read-modify-write on the same word.
CPU 0 (bind) CPU 1 (SIOCGSTAMPNS_NEW)
-------------------------------- ----------------------------
read sk_flags = F read sk_flags = F
compute F | BIT(SOCK_RCU_FREE) compute F | BIT(SOCK_TIMESTAMP)
store F | BIT(SOCK_RCU_FREE)
sk_add_node_rcu(sk, ...)
store F | BIT(SOCK_TIMESTAMP)
After the lost update, SOCK_RCU_FREE is clear while the socket is
visible to lockless UDP receive lookups. sk_destruct() then frees
the socket immediately instead of waiting for a RCU grace period,
while the receive path still holds a reference-less pointer to it:
BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410
Read of size 8 at addr ffff888008806610 by task exploit/207
CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1
ipv4_pktinfo_prepare+0x30/0x410
udp_queue_rcv_one_skb+0x51c/0x1180
udp_unicast_rcv_skb+0x109/0x350
ip_protocol_deliver_rcu+0x14b/0x310
ip_local_deliver_finish+0x29d/0x390
ip_local_deliver+0x24d/0x2a0
Only grab the socket lock when SOCK_TIMESTAMP has to be set,
to keep the common case lockless.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Jungwoo Lee <jwlee2217@gmail.com>
Reported-by: Wongi Lee <qw3rtyp0@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915043055.3441600-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/sock.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/net/core/sock.c b/net/core/sock.c
index 64f9d77bfaec7..899ddf069940f 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -3569,7 +3569,14 @@ int sock_gettstamp(struct socket *sock, void __user *userstamp,
struct sock *sk = sock->sk;
struct timespec64 ts;
- sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ /* sk->sk_flags must only be changed under the socket lock,
+ * because sock_set_flag() uses non atomic operations.
+ */
+ if (!sock_flag(sk, SOCK_TIMESTAMP)) {
+ lock_sock(sk);
+ sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ release_sock(sk);
+ }
ts = ktime_to_timespec64(sock_read_timestamp(sk));
if (ts.tv_sec == -1)
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 687/982] net: ethernet: cortina: Ack RX overrun interrupt correctly
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (685 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 686/982] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 688/982] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
` (301 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linus Walleij, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 1dd85662fee6e2ac580b1c4f9a0c0a7ae6e31f0e ]
The RX overrun interrupt is reported in interrupt status register 4, but
gmac_irq() acknowledges it using the RX descriptor error bit from status
register 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1
the shift leaves no bit in the 32-bit register.
Acknowledge the same per-port RX overrun bit that was detected.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914-b4-gemini-ethernet-fixes-2-v2-1-5ab39a047b90@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index fcc6018067226..58189d46b9fb1 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1803,7 +1803,7 @@ static irqreturn_t gmac_irq(int irq, void *data)
if (val & (GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8))) {
spin_lock(&geth->irq_lock);
- writel(GMAC0_RXDERR_INT_BIT << (netdev->dev_id * 8),
+ writel(GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8),
geth->base + GLOBAL_INTERRUPT_STATUS_4_REG);
u64_stats_update_begin(&port->ir_stats_syncp);
++port->stats.rx_fifo_errors;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 688/982] net: macb: fix ordering around PTP timestamp read
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (686 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 687/982] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 689/982] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
` (300 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Théo Lebrun,
James Clark, Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <jjc@jclark.com>
[ Upstream commit 9ca4ba24259183ce15665be86b2956cd896c4687 ]
PTP_SYS_OFFSET_EXTENDED returns system timestamps that do not correctly
bracket the PHC register read on MACB/GEM. On a Raspberry Pi 5, the
returned interval can be as short as 37 ns, while an ordered register
read takes approximately 1 us. This biases the midpoint used by phc2sys,
causing CLOCK_REALTIME to run approximately 0.5 us ahead when synchronized
to the PHC.
gem_tsu_get_time() reads the nanoseconds register using the driver's
relaxed MMIO accessor. On weakly ordered systems, the subsequent system
timestamp can be taken before the register read completes. The internal
smp_rmb() in the pre-timestamp path also does not guarantee ordering
against the subsequent MMIO read.
Add rmb() before and after the bracketed nanoseconds read in both the
normal and seconds rollover paths so the system timestamps bracket the
PHC read. Adding the post-read barrier increases the minimum interval on
the same Raspberry Pi 5 to approximately 1 us.
Fixes: e51bb5c2784c ("net: macb: ptp: Switch to gettimex64() interface")
Tested-by: Nicolai Buchwitz <nb@tipi-net.de> # Raspberry Pi CM5, min bracket 37 ns -> 981 ns
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Théo Lebrun <theo.lebrun@bootlin.com>
Assisted-by: LLM
Signed-off-by: James Clark <jjc@jclark.com>
Link: https://patch.msgid.link/20260915045823.76100-1-jjc@jclark.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb_ptp.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/net/ethernet/cadence/macb_ptp.c b/drivers/net/ethernet/cadence/macb_ptp.c
index b1b02b8faa8bd..84ba09bfdd303 100644
--- a/drivers/net/ethernet/cadence/macb_ptp.c
+++ b/drivers/net/ethernet/cadence/macb_ptp.c
@@ -48,7 +48,12 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
spin_lock_irqsave(&bp->tsu_clk_lock, flags);
ptp_read_system_prets(sts);
+ /* explicit barriers are needed because gem_readl() is relaxed */
+ if (sts)
+ rmb();
first = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
@@ -60,7 +65,11 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
* (assume all done within 1s)
*/
ptp_read_system_prets(sts);
+ if (sts)
+ rmb();
ts->tv_nsec = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 689/982] net: mvpp2: prevent buffer overflow in page_pool allocation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (687 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 688/982] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 690/982] accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release() Greg Kroah-Hartman
` (299 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitriy Okunev, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Okunev <dokunevdmitriy@gmail.com>
[ Upstream commit 14cb1e7702e5cb3c58888f6aed498381a73927d2 ]
The per‑processor buffering scheme is supported only if the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).
This is already checked in mvpp2_probe() during the initial
activation of percpu_pools.
However, mvpp2_change_mtu() may later call
mvpp2_bm_switch_buffers(priv, true) without this check, which can
lead to an out-of-bounds access in the priv->page_pool array in
mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ
entries, and mvpp2_get_nrxqs() may return exactly that value. The
per-CPU scheme then doubles it to nrxqs * 2, exceeding the array
bounds.
Check that the hardware version is MVPP22 or newer and that the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS
before switching to per-CPU mode.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7d04b0b13b11 ("mvpp2: percpu buffers")
Signed-off-by: Dmitriy Okunev <dokunevdmitriy@gmail.com>
Link: https://patch.msgid.link/20260914091557.71769-1-dokunevdmitriy@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
index 675616142c4f4..d896d63682076 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
@@ -5075,7 +5075,8 @@ static int mvpp2_change_mtu(struct net_device *dev, int mtu)
netdev_warn(dev, "mtu %d too high, switching to shared buffers", mtu);
mvpp2_bm_switch_buffers(priv, false);
}
- } else {
+ } else if (priv->hw_version >= MVPP22 &&
+ mvpp2_get_nrxqs(priv) * 2 <= MVPP2_BM_MAX_POOLS) {
bool jumbo = false;
int i;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 690/982] accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (688 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 689/982] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 691/982] sched/fair: Move is_core_idle() out of CONFIG_NUMA Greg Kroah-Hartman
` (298 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tomer Tayar, Oded Gabbay,
Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tomer Tayar <ttayar@habana.ai>
[ Upstream commit 2e8e9a895c4589f124a37fc84d123b5114406e94 ]
The memory manager IDR is currently destroyed when user releases the
file descriptor.
However, at this point the user context might be still held, and memory
buffers might be still in use.
Later on, calls to release those buffers will fail due to not finding
their handles in the IDR, leading to a memory leak.
To avoid this leak, split the IDR destruction from the memory manager
fini, and postpone it to hpriv_release() when there is no user context
and no buffers are used.
Signed-off-by: Tomer Tayar <ttayar@habana.ai>
Reviewed-by: Oded Gabbay <ogabbay@kernel.org>
Signed-off-by: Oded Gabbay <ogabbay@kernel.org>
[ Backport to 6.1.y: this tree keeps Habanalabs under drivers/misc
rather than drivers/accel; the source change is otherwise unchanged. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/habanalabs/common/device.c | 9 +++++++++
drivers/misc/habanalabs/common/habanalabs.h | 1 +
drivers/misc/habanalabs/common/habanalabs_drv.c | 1 +
drivers/misc/habanalabs/common/memory_mgr.c | 13 ++++++++++++-
4 files changed, 23 insertions(+), 1 deletion(-)
diff --git a/drivers/misc/habanalabs/common/device.c b/drivers/misc/habanalabs/common/device.c
index 9ee1b6abd8a05..60a9fc65845bf 100644
--- a/drivers/misc/habanalabs/common/device.c
+++ b/drivers/misc/habanalabs/common/device.c
@@ -375,6 +375,9 @@ static void hpriv_release(struct kref *ref)
mutex_destroy(&hpriv->ctx_lock);
mutex_destroy(&hpriv->restore_phase_mutex);
+ /* There should be no memory buffers at this point and handles IDR can be destroyed */
+ hl_mem_mgr_idr_destroy(&hpriv->mem_mgr);
+
if ((!hdev->pldm) && (hdev->pdev) &&
(!hdev->asic_funcs->is_device_idle(hdev,
idle_mask,
@@ -464,6 +467,10 @@ static int hl_device_release(struct inode *inode, struct file *filp)
hl_release_pending_user_interrupts(hpriv->hdev);
hl_ctx_mgr_fini(hdev, &hpriv->ctx_mgr);
+
+ /* Memory buffers might be still in use at this point and thus the handles IDR destruction
+ * is postponed to hpriv_release().
+ */
hl_mem_mgr_fini(&hpriv->mem_mgr);
hdev->compute_ctx_in_release = 1;
@@ -808,6 +815,7 @@ static int device_early_init(struct hl_device *hdev)
free_cb_mgr:
hl_mem_mgr_fini(&hdev->kernel_mem_mgr);
+ hl_mem_mgr_idr_destroy(&hdev->kernel_mem_mgr);
free_chip_info:
kfree(hdev->hl_chip_info);
free_pf_wq:
@@ -851,6 +859,7 @@ static void device_early_fini(struct hl_device *hdev)
mutex_destroy(&hdev->clk_throttling.lock);
hl_mem_mgr_fini(&hdev->kernel_mem_mgr);
+ hl_mem_mgr_idr_destroy(&hdev->kernel_mem_mgr);
kfree(hdev->hl_chip_info);
diff --git a/drivers/misc/habanalabs/common/habanalabs.h b/drivers/misc/habanalabs/common/habanalabs.h
index 257b94cec6248..e6eabcdda1c5c 100644
--- a/drivers/misc/habanalabs/common/habanalabs.h
+++ b/drivers/misc/habanalabs/common/habanalabs.h
@@ -3789,6 +3789,7 @@ const char *hl_sync_engine_to_string(enum hl_sync_engine_type engine_type);
void hl_mem_mgr_init(struct device *dev, struct hl_mem_mgr *mmg);
void hl_mem_mgr_fini(struct hl_mem_mgr *mmg);
+void hl_mem_mgr_idr_destroy(struct hl_mem_mgr *mmg);
int hl_mem_mgr_mmap(struct hl_mem_mgr *mmg, struct vm_area_struct *vma,
void *args);
struct hl_mmap_mem_buf *hl_mmap_mem_buf_get(struct hl_mem_mgr *mmg,
diff --git a/drivers/misc/habanalabs/common/habanalabs_drv.c b/drivers/misc/habanalabs/common/habanalabs_drv.c
index ae3cab3f4aa55..3d4eaa7327e31 100644
--- a/drivers/misc/habanalabs/common/habanalabs_drv.c
+++ b/drivers/misc/habanalabs/common/habanalabs_drv.c
@@ -222,6 +222,7 @@ int hl_device_open(struct inode *inode, struct file *filp)
out_err:
mutex_unlock(&hdev->fpriv_list_lock);
hl_mem_mgr_fini(&hpriv->mem_mgr);
+ hl_mem_mgr_idr_destroy(&hpriv->mem_mgr);
hl_ctx_mgr_fini(hpriv->hdev, &hpriv->ctx_mgr);
filp->private_data = NULL;
mutex_destroy(&hpriv->ctx_lock);
diff --git a/drivers/misc/habanalabs/common/memory_mgr.c b/drivers/misc/habanalabs/common/memory_mgr.c
index 1936d653699ed..93a2b9faf419f 100644
--- a/drivers/misc/habanalabs/common/memory_mgr.c
+++ b/drivers/misc/habanalabs/common/memory_mgr.c
@@ -342,8 +342,19 @@ void hl_mem_mgr_fini(struct hl_mem_mgr *mmg)
"%s: Buff handle %u for CTX is still alive\n",
topic, id);
}
+}
- /* TODO: can it happen that some buffer is still in use at this point? */
+/**
+ * hl_mem_mgr_idr_destroy() - destroy memory manager IDR.
+ * @mmg: parent unified memory manager
+ *
+ * Destroy the memory manager IDR.
+ * Shall be called when IDR is empty and no memory buffers are in use.
+ */
+void hl_mem_mgr_idr_destroy(struct hl_mem_mgr *mmg)
+{
+ if (!idr_is_empty(&mmg->handles))
+ dev_crit(mmg->dev, "memory manager IDR is destroyed while it is not empty!\n");
idr_destroy(&mmg->handles);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 691/982] sched/fair: Move is_core_idle() out of CONFIG_NUMA
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (689 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 690/982] accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 692/982] sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity Greg Kroah-Hartman
` (297 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ricardo Neri, Peter Zijlstra (Intel),
Zhang Rui, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
[ Upstream commit 8b36d07f1d63de102d464f44a89704bc62d00811 ]
asym_packing needs this function to determine whether an SMT core is a
suitable destination for load balancing.
Signed-off-by: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Zhang Rui <rui.zhang@intel.com>
Link: https://lore.kernel.org/r/20230406203148.19182-2-ricardo.neri-calderon@linux.intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/fair.c | 34 +++++++++++++++++-----------------
1 file changed, 17 insertions(+), 17 deletions(-)
diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index a329bd89f1e3d..879843e807fc6 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -1049,6 +1049,23 @@ update_stats_curr_start(struct cfs_rq *cfs_rq, struct sched_entity *se)
* Scheduling class queueing methods:
*/
+static inline bool is_core_idle(int cpu)
+{
+#ifdef CONFIG_SCHED_SMT
+ int sibling;
+
+ for_each_cpu(sibling, cpu_smt_mask(cpu)) {
+ if (cpu == sibling)
+ continue;
+
+ if (!idle_cpu(sibling))
+ return false;
+ }
+#endif
+
+ return true;
+}
+
#ifdef CONFIG_NUMA
#define NUMA_IMBALANCE_MIN 2
@@ -1688,23 +1705,6 @@ struct numa_stats {
int idle_cpu;
};
-static inline bool is_core_idle(int cpu)
-{
-#ifdef CONFIG_SCHED_SMT
- int sibling;
-
- for_each_cpu(sibling, cpu_smt_mask(cpu)) {
- if (cpu == sibling)
- continue;
-
- if (!idle_cpu(sibling))
- return false;
- }
-#endif
-
- return true;
-}
-
struct task_numa_env {
struct task_struct *p;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 692/982] sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (690 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 691/982] sched/fair: Move is_core_idle() out of CONFIG_NUMA Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 693/982] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
` (296 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Felix Abecassis, Andrea Righi,
Peter Zijlstra (Intel), Vincent Guittot, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Righi <arighi@nvidia.com>
[ Upstream commit bf6aa722198d3c06e4236e8c5a480f30a64e1513 ]
When SD_ASYM_CPUCAPACITY load balancing considers pulling a misfit task,
capacity_of(dst_cpu) can overstate available compute if the SMT sibling is
busy: the core does not deliver its full nominal capacity.
If SMT is active and dst_cpu is not on a fully idle core, skip this
destination so we do not migrate a misfit expecting a capacity upgrade we
cannot actually provide.
Reported-by: Felix Abecassis <fabecassis@nvidia.com>
Signed-off-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Vincent Guittot <vincent.guittot@linaro.org>
Link: https://patch.msgid.link/20260509180955.1840064-5-arighi@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/fair.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index 879843e807fc6..325e7542fbb4b 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -8181,6 +8181,7 @@ struct lb_env {
int dst_cpu;
struct rq *dst_rq;
+ bool dst_core_idle;
struct cpumask *dst_grpmask;
int new_dst_cpu;
@@ -9361,10 +9362,16 @@ static bool update_sd_pick_busiest(struct lb_env *env,
* We can use max_capacity here as reduction in capacity on some
* CPUs in the group should either be possible to resolve
* internally or be covered by avg_load imbalance (eventually).
+ *
+ * When SMT is active, only pull a misfit to dst_cpu if it is on a
+ * fully idle core; otherwise the effective capacity of the core is
+ * reduced and we may not actually provide more capacity than the
+ * source.
*/
if ((env->sd->flags & SD_ASYM_CPUCAPACITY) &&
(sgs->group_type == group_misfit_task) &&
- (!capacity_greater(capacity_of(env->dst_cpu), sg->sgc->max_capacity) ||
+ (!env->dst_core_idle ||
+ !capacity_greater(capacity_of(env->dst_cpu), sg->sgc->max_capacity) ||
sds->local_stat.group_type != group_has_spare))
return false;
@@ -9902,6 +9909,8 @@ static inline void update_sd_lb_stats(struct lb_env *env, struct sd_lb_stats *sd
unsigned long sum_util = 0;
int sg_status = 0;
+ env->dst_core_idle = !sched_smt_active() || is_core_idle(env->dst_cpu);
+
do {
struct sg_lb_stats *sgs = &tmp_sgs;
int local_group;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 693/982] Input: xpad - add support for Victrix Pro BFG Controller
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (691 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 692/982] sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 694/982] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
` (295 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Erich Sartison, Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Erich Sartison <byt.es@mailbox.org>
commit 971fa7ea8621e123feb9c8d7dc61be1c656bd945 upstream.
The controller doesn't currently work via USB-cable.
Signed-off-by: Erich Sartison <byt.es@mailbox.org>
Link: https://patch.msgid.link/20260903103137.630170-1-byt.es@mailbox.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -240,6 +240,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0213, "Afterglow Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x021f, "Rock Candy Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x0246, "Rock Candy Gamepad for Xbox One 2015", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x024c, "PDP Victrix Pro BFG Wired Controller for Xbox", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a0, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a1, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a2, "PDP Wired Controller for Xbox One - Crimson Red", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 694/982] Input: xpad - add support for Azeron devices
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (692 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 693/982] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 695/982] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
` (294 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Roberts Kursitis, Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roberts Kursitis <roberts.kursitis@azeron.eu>
commit cba76c0f47af1a389d718c5bb69e75cbd67bba98 upstream.
Azeron controllers (Cyro, Cyborg, Classic/Compact, Cyro Lefty,
Cyborg II and Keyzen) present a standard Xbox 360 controller
interface, so they work with the existing xpad driver once their
USB IDs are added.
The 0x16d0 vendor ID is a shared block, but this is safe because
xpad only binds interfaces that match the Xbox 360 signature.
Tested with an Azeron Keyzen.
Signed-off-by: Roberts Kursitis <roberts.kursitis@azeron.eu>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260906143040.162418-1-roberts.kursitis@azeron.eu
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -299,6 +299,12 @@ static const struct xpad_device {
{ 0x1689, 0xfd00, "Razer Onza Tournament Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfd01, "Razer Onza Classic Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfe00, "Razer Sabertooth", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1103, "Azeron Cyro", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x113c, "Azeron Cyborg", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1192, "Azeron Classic/Compact", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1212, "Azeron Cyro Lefty", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x12f7, "Azeron Cyborg II", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x13ea, "Azeron Keyzen", 0, XTYPE_XBOX360 },
{ 0x17ef, 0x6182, "Lenovo Legion Controller for Windows", 0, XTYPE_XBOX360 },
{ 0x1949, 0x041a, "Amazon Game Controller", 0, XTYPE_XBOX360 },
{ 0x1bad, 0x0002, "Harmonix Rock Band Guitar", 0, XTYPE_XBOX360 },
@@ -497,6 +503,7 @@ static const struct usb_device_id xpad_t
XPAD_XBOX360_VENDOR(0x15e4), /* Numark X-Box 360 controllers */
XPAD_XBOX360_VENDOR(0x162e), /* Joytech X-Box 360 controllers */
XPAD_XBOX360_VENDOR(0x1689), /* Razer Onza */
+ XPAD_XBOX360_VENDOR(0x16d0), /* Azeron controllers */
XPAD_XBOX360_VENDOR(0x17ef), /* Lenovo */
XPAD_XBOX360_VENDOR(0x1949), /* Amazon controllers */
XPAD_XBOX360_VENDOR(0x1bad), /* Harminix Rock Band Guitar and Drums */
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 695/982] Input: xpad - fix PDP Marvel Xbox 360 controller
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (693 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 694/982] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 696/982] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
` (293 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jeremy Nyberg, Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeremy Nyberg <slickstretch3.0@gmail.com>
commit 7bc369cb3d3f3656eb77285628ee264264d28ad4 upstream.
The PDP Marvel Xbox 360 controller with USB ID 0e6f:0147 is
incorrectly classified as an Xbox One controller.
With the current XTYPE_XBOXONE classification, the controller is
detected but produces no input, while its four player LEDs continue
blinking indefinitely.
Classify USB ID 0e6f:0147 as an Xbox 360 controller instead.
Tested on a PDP Marvel Xbox 360 controller with USB ID 0e6f:0147.
All inputs register correctly and the player LED indicates the
current player.
Fixes: c225370e01b8 ("Input: xpad - sync supported devices with 360Controller")
Cc: stable@vger.kernel.org
Signed-off-by: Jeremy Nyberg <SlickStretch3.0@gmail.com>
Link: https://patch.msgid.link/20260910071627.236014-1-SlickStretch3.0@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -229,7 +229,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0139, "Afterglow Prismatic Wired Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x013a, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0146, "Rock Candy Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
- { 0x0e6f, 0x0147, "PDP Marvel Xbox One Controller", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x0147, "PDP Marvel Xbox 360 Controller", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x015c, "PDP Xbox One Arcade Stick", MAP_TRIGGERS_TO_BUTTONS, XTYPE_XBOXONE },
{ 0x0e6f, 0x0161, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0162, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 696/982] ALSA: virtio: reset device before deleting virtqueues
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (694 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 695/982] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 697/982] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
` (292 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Takashi Iwai
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <oss.patchbox@gmail.com>
commit 6c05d00af307560e6a9f1631d6270d3df5aa2272 upstream.
virtsnd_remove() and virtsnd_freeze() delete the virtqueues before
resetting the device. del_vqs() frees the vring backing, but does not
provide a generic device quiesce operation. In particular, modern
virtio-pci keeps enabled queues active until the device is reset.
Reset the device before deleting the virtqueues so it can no longer
access the vring memory when that memory is released. This also covers
probe failures after DRIVER_OK, which unwind through virtsnd_remove().
Fixes: de3a9980d8c3 ("ALSA: virtio: add virtio sound driver")
Fixes: 575483e90a32 ("ALSA: virtio: introduce device suspend/resume support")
Cc: stable@vger.kernel.org
Signed-off-by: Yuho Choi <oss.patchbox@gmail.com>
Link: https://patch.msgid.link/20260911031121.1542502-1-oss.patchbox@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/virtio/virtio_card.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/sound/virtio/virtio_card.c
+++ b/sound/virtio/virtio_card.c
@@ -349,8 +349,8 @@ static void virtsnd_remove(struct virtio
if (snd->card)
snd_card_free(snd->card);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; snd->substreams && i < snd->nsubstreams; ++i) {
struct virtio_pcm_substream *vss = &snd->substreams[i];
@@ -378,8 +378,8 @@ static int virtsnd_freeze(struct virtio_
virtsnd_disable_event_vq(snd);
virtsnd_ctl_msg_cancel_all(snd);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; i < snd->nsubstreams; ++i)
cancel_work_sync(&snd->substreams[i].elapsed_period);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 697/982] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (695 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 696/982] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 698/982] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
` (291 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Roland Waltersson, Damien Le Moal,
Niklas Cassel
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Cassel <cassel@kernel.org>
commit 82e47533221d4746947b74d2e79a478c36c6433a upstream.
A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for
JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board.
The failure is seen as soon as the ahci driver is probed, and booting with
iommu=off does not solve the problem.
Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0'
for HBAs that do not support 64-bit addressing.
For HBAs that do support 64-bit addressing, the registers are read write,
with a reset value that is Implementation Specific.
When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit
addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64.
Thus, in this case, we need to explicitly clear the registers to 0.
Fixes: 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585")
Fixes: c7a42156d99b ("ahci: disable 64bit dma on sb600")
Cc: stable@vger.kernel.org
Reported-by: Roland Waltersson <roland.waltersson@netinsight.net>
Closes: https://lore.kernel.org/linux-ide/IA0PR17MB668730A4ECCD65F7A1DC3EDC9EB62@IA0PR17MB6687.namprd17.prod.outlook.com/
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260904134310.1465051-2-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
--- a/drivers/ata/libahci.c
+++ b/drivers/ata/libahci.c
@@ -745,15 +745,28 @@ void ahci_start_fis_rx(struct ata_port *
struct ahci_port_priv *pp = ap->private_data;
u32 tmp;
- /* set FIS registers */
+ /*
+ * On HBAs that only support 32-bit addressing PxCLBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxCLBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->cmd_slot_dma >> 16) >> 16,
port_mmio + PORT_LST_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_LST_ADDR_HI);
writel(pp->cmd_slot_dma & 0xffffffff, port_mmio + PORT_LST_ADDR);
+ /*
+ * On HBAs that only support 32-bit addressing PxFBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxFBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->rx_fis_dma >> 16) >> 16,
port_mmio + PORT_FIS_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_FIS_ADDR_HI);
writel(pp->rx_fis_dma & 0xffffffff, port_mmio + PORT_FIS_ADDR);
/* enable FIS reception */
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 698/982] rds: ib: use rds_conn_drop() on protocol version mismatch
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (696 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 697/982] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 699/982] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
` (290 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI,
Allison Henderson, Aohan Mei, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit f97d8c7bab7843631206a114986c9059da03efeb upstream.
rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with
conn->c_cm_lock held. When the peer negotiates a protocol version
older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls
rds_conn_destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush_work()es the
shutdown work cp_down_w.
That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR,
DISCONNECTED) use rds_conn_drop(), which marks the connection
RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use
it here as well.
Fixes: f147dd9ecabf ("RDS/IB: Disallow connections less than RDS 3.1")
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Reviewed-by: Allison Henderson <achender@kernel.org>
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Link: https://patch.msgid.link/20260911073436.3542080-1-ljp1205831794@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/rds/ib_cm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/rds/ib_cm.c
+++ b/net/rds/ib_cm.c
@@ -115,7 +115,7 @@ void rds_ib_cm_connect_complete(struct r
&conn->c_laddr, &conn->c_faddr,
RDS_PROTOCOL_MAJOR(conn->c_version),
RDS_PROTOCOL_MINOR(conn->c_version));
- rds_conn_destroy(conn);
+ rds_conn_drop(conn);
return;
}
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 699/982] tcp: exclude old ACKs from tcp fast path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (697 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 698/982] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 700/982] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
` (289 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Amit Klein, Tamir Shahar,
Inbal Schussheim, Eric Dumazet, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
commit f81e6c3fb06327bc49cdd6e559845293ba06a704 upstream.
Exclude old ACKs before SND.UNA from the tcp fast path
as well as ACKs after SND.NXT.
Such ACKs will fall through to the slow path, where tcp_ack()
performs the appropriate validation and challenge ACK handling
according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not
accept ACK of bytes we never sent").
This prevents old ACKs from being accepted
or modifying connection state as part of the fast path before
appropriate ACK validation is applied.
In particular, this prevents payload carried by a segment with
an excessively old ACK from advancing RCV.NXT before the ACK
is rejected.
Fixes: 31770e34e43d ("tcp: Revert "tcp: remove header prediction"")
Reported-by: Amit Klein <amit.klein@mail.huji.ac.il>
Reported-by: Tamir Shahar <tamir.shahar1@mail.huji.ac.il>
Reported-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Suggested-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914090408.1435080-2-inbal.lipshtat@mail.huji.ac.il
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/tcp_input.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -5933,6 +5933,7 @@ reset:
* or pure receivers (this means either the sequence number or the ack
* value must stay constant)
* - Unexpected TCP option.
+ * - ACK sequence number is outside [SND.UNA, SND.NXT].
*
* When these conditions are not satisfied it drops into a standard
* receive procedure patterned after RFC793 to handle all cases.
@@ -5981,7 +5982,7 @@ void tcp_rcv_established(struct sock *sk
if ((tcp_flag_word(th) & TCP_HP_BITS) == tp->pred_flags &&
TCP_SKB_CB(skb)->seq == tp->rcv_nxt &&
- !after(TCP_SKB_CB(skb)->ack_seq, tp->snd_nxt)) {
+ between(TCP_SKB_CB(skb)->ack_seq, tp->snd_una, tp->snd_nxt)) {
int tcp_header_len = tp->tcp_header_len;
/* Timestamp header prediction: tcp_header_len
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 700/982] RDMA/ucma: Serialize join and leave on copy_to_user failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (698 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 699/982] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 701/982] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
` (288 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+a6ffe86390c8a6afc818,
Quanye Yang, Leon Romanovsky
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
commit 662ade4de9ff5eceb0820a9f8e9fac70ba6a815b upstream.
rdma_join_multicast() queues RoCE work that later reads the ucma_multicast
through event->param.ud.private_data, then list_add()s the CMA multicast
at the head of id_priv->mc_list. rdma_leave_multicast() matches only by
sockaddr and destroys the first hit.
ucma_process_join() used to drop ctx->mutex after a successful join and
retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls
with the same address can therefore insert a second CMA entry before the
first thread's leave. leave then cancels the newer work and the older
worker still dereferences the ucma_multicast that the first thread frees.
Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and,
on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join.
Do not leave if join itself failed: that path never published this address
on mc_list, and a leave-by-addr would destroy an earlier successful join.
Reported-by: syzbot+a6ffe86390c8a6afc818@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a6ffe86390c8a6afc818
Fixes: fe454dc31e84 ("RDMA/ucma: Fix use-after-free bug in ucma_create_uevent")
Cc: stable@vger.kernel.org
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260831-rdma-ucma-mc-uaf-v1-1-b8eeb7046aff@proton.me
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/ucma.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/drivers/infiniband/core/ucma.c
+++ b/drivers/infiniband/core/ucma.c
@@ -1488,9 +1488,10 @@ static ssize_t ucma_process_join(struct
mutex_lock(&ctx->mutex);
ret = rdma_join_multicast(ctx->cm_id, (struct sockaddr *)&mc->addr,
join_state, mc);
- mutex_unlock(&ctx->mutex);
- if (ret)
+ if (ret) {
+ mutex_unlock(&ctx->mutex);
goto err_xa_erase;
+ }
resp.id = mc->id;
if (copy_to_user(u64_to_user_ptr(cmd->response),
@@ -1498,6 +1499,7 @@ static ssize_t ucma_process_join(struct
ret = -EFAULT;
goto err_leave_multicast;
}
+ mutex_unlock(&ctx->mutex);
xa_store(&multicast_table, mc->id, mc, 0);
@@ -1505,7 +1507,6 @@ static ssize_t ucma_process_join(struct
return 0;
err_leave_multicast:
- mutex_lock(&ctx->mutex);
rdma_leave_multicast(ctx->cm_id, (struct sockaddr *) &mc->addr);
mutex_unlock(&ctx->mutex);
ucma_cleanup_mc_events(mc);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 701/982] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (699 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 700/982] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 702/982] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
` (287 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+bd317784d628820741b5,
Jeffin Philip, Leon Romanovsky
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeffin Philip <jeffinphilip14@gmail.com>
commit 33fb59da49c4c3f5c2ec9f9d4447a56857a02c02 upstream.
iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
making it accessible to global list where another CPU can kref_get()
on nlmsg_request causing a refcount "addition on 0" bug. Fix this
by initializing kref _before_ list_add_tail() so refcount for
nlmsg_request can be incremented/decremented normally. In addition,
also initialize every field before list_add_tail().
Reported-by: syzbot+bd317784d628820741b5@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=bd317784d628820741b5
Fixes: 30dc5e63d6a5 ("RDMA/core: Add support for iWARP Port Mapper user space service")
Cc: stable@vger.kernel.org
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Link: https://patch.msgid.link/20260904131437.12917-1-jeffinphilip14@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/iwpm_util.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/drivers/infiniband/core/iwpm_util.c
+++ b/drivers/infiniband/core/iwpm_util.c
@@ -314,10 +314,6 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
if (!nlmsg_request)
return NULL;
- spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
- list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
- spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
-
kref_init(&nlmsg_request->kref);
kref_get(&nlmsg_request->kref);
nlmsg_request->nlmsg_seq = nlmsg_seq;
@@ -326,6 +322,11 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
nlmsg_request->err_code = 0;
sema_init(&nlmsg_request->sem, 1);
down(&nlmsg_request->sem);
+
+ spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
+ list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
+ spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
+
return nlmsg_request;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 702/982] openvswitch: avoid reallocating confirmed conntrack labels
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (700 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 701/982] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 6.1 703/982] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
` (286 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Ilya Maximets,
Aaron Conole, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 3f118c8217c109fd13ca61caa301d72c483897ef upstream.
ovs_ct_get_conn_labels() adds the labels extension when a conntrack
entry does not have one. Confirmed conntracks can be read locklessly,
so adding an extension may reallocate and free the extension block
while another CPU accesses it.
Only add the extension for unconfirmed conntracks. A confirmed
conntrack without labels now fails the caller's label operation instead
of reallocating its extension storage.
Fixes: c2ac66735870 ("openvswitch: Allow matching on conntrack label")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/conntrack.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -359,7 +359,7 @@ static struct nf_conn_labels *ovs_ct_get
struct nf_conn_labels *cl;
cl = nf_ct_labels_find(ct);
- if (!cl) {
+ if (!cl && !nf_ct_is_confirmed(ct)) {
nf_ct_labels_ext_add(ct);
cl = nf_ct_labels_find(ct);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 703/982] net: xfrm: reject unrepresentable espintcp transport headers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (701 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 702/982] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 704/982] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
` (285 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Wyatt Feng, Ren Wei,
Steffen Klassert
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wyatt Feng <wf.kernel.dev@gmail.com>
commit 96f01b53c2d05e003b040892256de54a586e8529 upstream.
ESP-in-TCP can hand xfrm packets whose transport header offset no longer
fits after the stream parser trims the TCP envelope. The plain transport
header reset truncates that offset and triggers the skb warning path.
Use the careful transport-header helper and drop the skb through the
existing XFRM error path when the offset cannot be represented.
Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:GPT-5.4
Signed-off-by: Wyatt Feng <wf.kernel.dev@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/espintcp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/net/xfrm/espintcp.c
+++ b/net/xfrm/espintcp.c
@@ -31,7 +31,11 @@ static void handle_esp(struct sk_buff *s
{
struct tcp_skb_cb *tcp_cb = (struct tcp_skb_cb *)skb->cb;
- skb_reset_transport_header(skb);
+ if (!skb_reset_transport_header_careful(skb)) {
+ XFRM_INC_STATS(sock_net(sk), LINUX_MIB_XFRMINERROR);
+ kfree_skb(skb);
+ return;
+ }
/* restore IP CB, we need at least IP6CB->nhoff */
memmove(skb->cb, &tcp_cb->header, sizeof(tcp_cb->header));
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 704/982] kselftest/arm64: Fix size of thread_data values for pthread_join()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (702 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 6.1 703/982] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 705/982] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
` (284 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thomas Huth, Will Deacon
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Huth <thuth@redhat.com>
commit 3d1ba5cbfb622025690c218d8f20da92a9ecb383 upstream.
pthread_join() stores the thread's return value (a "void *", i.e.
8 bytes on 64 bit computers) into the address that is passed as second
parameter. However, the entries of thread_data are only normal "int"s,
i.e. only 4 bytes. The additional 4 bytes of the return value clobber
whatever is adjacent on the stack, i.e. other members of the thread_data
array (which will be re-written in the next iteration of the for-loop,
so that nobody noticed this problem), or another other local variable
on the stack for the last iteration. Use "intptr_t" to declare the
thread_data array entries with the correct size.
Fixes: 29f080881601c ("kselftest/arm64: check GCR_EL1 after context switch")
Cc: stable@vger.kernel.org
Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
+++ b/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
@@ -69,7 +69,7 @@ fail:
int execute_test(pid_t pid)
{
pthread_t thread_id[MAX_THREADS];
- int thread_data[MAX_THREADS];
+ intptr_t thread_data[MAX_THREADS];
for (int i = 0; i < MAX_THREADS; i++)
pthread_create(&thread_id[i], NULL,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 705/982] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (703 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 704/982] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 706/982] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
` (283 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bradley Morgan, Vladimir Murzin,
Mark Rutland, Will Deacon
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bradley Morgan <include@grrlz.net>
commit 955d86e5f3b95b731991fdb84966c50b16314629 upstream.
swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub
vectors with an hvc, but never passes the arguments. x0 is not set to
HVC_SET_VECTORS and x1 is not set to the vector address, so the stub
dispatch falls through and returns without writing vbar_el2. EL2 is
left pointing at the trans_pgd copy of the vectors, a page that
swsusp_free() releases right after resume.
Set the arguments up the same way __hyp_set_vectors() does.
Without this fix, Vladimir was able to trigger a hang when resuming from
hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.
Fixes: 788bfdd97434 ("arm64: trans_pgd: hibernate: Add trans_pgd_copy_el2_vectors")
Cc: stable@vger.kernel.org
Signed-off-by: Bradley Morgan <include@grrlz.net>
Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com>
Tested-by: Vladimir Murzin <vladimir.murzin@arm.com>
Acked-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kernel/hibernate-asm.S | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm64/kernel/hibernate-asm.S b/arch/arm64/kernel/hibernate-asm.S
index 0e1d9c3c6a93..2baefe7a82d3 100644
--- a/arch/arm64/kernel/hibernate-asm.S
+++ b/arch/arm64/kernel/hibernate-asm.S
@@ -89,6 +89,8 @@ alternative_insn "dc cvau, x4", "dc civac, x4", ARM64_WORKAROUND_CLEAN_CACHE
isb
cbz x24, 3f /* Do we need to re-initialise EL2? */
+ mov x1, x24
+ mov x0, #HVC_SET_VECTORS
hvc #0
3: ret
SYM_CODE_END(swsusp_arch_suspend_exit)
--
2.55.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 706/982] arm64: dts: renesas: r8a779f0: Set UFS lane count
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (704 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 705/982] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 707/982] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
` (282 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Koichiro Den, Geert Uytterhoeven
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
commit 8dc2615d5702059b2b71fca6f93c0d7d10ae54cb upstream.
Since commit e72323f3b09f ("scsi: ufs: core: Configure only active lanes
during link"), the following error is observed on R-Car S4:
ufshcd-renesas e6860000.ufs: Tx lane mismatch [config,reported] [2,1]
ufshcd-renesas e6860000.ufs: link startup failed -67
ufshcd-renesas e6860000.ufs: error -ENOLINK: Initialization failed with error -67
ufshcd-renesas e6860000.ufs: probe with driver ufshcd-renesas failed with error -67
R-Car S4 has one UFS lane per direction, as described in section 152.1
of its hardware manual. Without lanes-per-direction, the UFS platform
driver defaults to two lanes.
Previously, the core used PA_CONNECTEDRXDATALANES and
PA_CONNECTEDTXDATALANES to configure the link without checking them
against lanes-per-direction, so the missing property did not prevent
initialization.
Explicitly set lanes-per-direction to 1, now that the validation is in
place.
Fixes: 5235d551779d ("arm64: dts: renesas: r8a779f0: Add UFS node")
Cc: stable@vger.kernel.org # 7.2+
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260911073058.253000-1-den@valinux.co.jp
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
1 file changed, 1 insertion(+)
--- a/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
+++ b/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
@@ -646,6 +646,7 @@
clocks = <&cpg CPG_MOD 1514>, <&ufs30_clk>;
clock-names = "fck", "ref_clk";
freq-table-hz = <200000000 200000000>, <38400000 38400000>;
+ lanes-per-direction = <1>;
power-domains = <&sysc R8A779F0_PD_ALWAYS_ON>;
resets = <&cpg 1514>;
status = "disabled";
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 707/982] arm64: percpu: Fix this_cpu_write() casting
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (705 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 706/982] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 708/982] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
` (281 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Laight, Mark Rutland,
Jinjie Ruan, Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi, Lorenzo Stoakes (ARM)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 885bff055a0f251a51a0d4fd4f0a7b525582a3de upstream.
The arm64 implementation of this_cpu_write() casts 'val' to unsigned
long. This is necessary to handle cases where 'val' is a pointer type,
and to avoid spurious compiler warnings for the (unreachable!) cases
where the pointer type would be cast to a smaller integer type.
Unfortunately, the cast is applied to 'val' rather than '(val)', which
won't always generate the expected value when 'val' is an expression.
For example, for this_cpu_write(pcp, zero - 1), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* 'zero - 1' ===> (u32) 0xffffffff
* '(unsigned long)zero - 1' ===> (u64) 0xffffffffffffffff
* '(unsigned long)(zero - 1)' ===> (u64) 0x00000000ffffffff
Fix this by adding brackets around 'val'.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Reported-by: David Laight <david.laight.linux@gmail.com>
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: David Laight <david.laight.linux@gmail.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -178,13 +178,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_read_64, pcp)
#define this_cpu_write_1(pcp, val) \
- _pcp_protect(__percpu_write_8, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_8, pcp, (unsigned long)(val))
#define this_cpu_write_2(pcp, val) \
- _pcp_protect(__percpu_write_16, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_16, pcp, (unsigned long)(val))
#define this_cpu_write_4(pcp, val) \
- _pcp_protect(__percpu_write_32, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_32, pcp, (unsigned long)(val))
#define this_cpu_write_8(pcp, val) \
- _pcp_protect(__percpu_write_64, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_64, pcp, (unsigned long)(val))
#define this_cpu_add_1(pcp, val) \
_pcp_protect(__percpu_add_case_8, pcp, val)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 708/982] arm64: percpu: Fix this_cpu_and() mask generation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (706 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 707/982] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 709/982] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
` (280 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Jinjie Ruan,
Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 44274c657256b4911de82f8104e9e22f054cf742 upstream.
The arm64 implementation of this_cpu_and(pcp, val) is built in terms of
ANDNOT operations, which requires the 'val' argument to be bitwise
negated. The bitwise negation is not implemented correctly, with two
bugs described below.
(1) The bitwise negation is performed as '~val' rather than '~(val)'.
This won't always generate the expected value when 'val' is an
expression.
For example, for this_cpu_and(pcp, 1 - 1):
* 'val' is '1 - 1' ===> (int) 0x00000000
* '~val' is '~1 - 1' ===> (int) 0xfffffffd
* '~(val)' is '~(1 - 1)' ===> (int) 0xffffffff
... and thus bit[1] of 'pcp' would be preserved unexpectedly by the
ANDNOT operation.
(2) The bitwise negation is performed on 'val' before it has been cast
to (at least) the width of 'pcp'. This won't always generate the
expected value for the upper bits.
For example, for this_cpu_and(pcp, zero), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* '~(zero)' ===> (u32) 0xffffffff
* '(u64)~(zero)' ===> (u64) 0x00000000ffffffff
* '~((u64)(zero))' ===> (u64) 0xffffffffffffffff
... and thus bits[63:32] of 'pcp' would be preserved unexpectedly by
the ANDNOT operation.
Fix these issues by adding brackets around 'val', and by casting 'val'
to an appropriately-sized type before bitwise negation.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -205,13 +205,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_add_return_case_64, pcp, val)
#define this_cpu_and_1(pcp, val) \
- _pcp_protect(__percpu_andnot_case_8, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_8, pcp, ~(u8)(val))
#define this_cpu_and_2(pcp, val) \
- _pcp_protect(__percpu_andnot_case_16, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_16, pcp, ~(u16)(val))
#define this_cpu_and_4(pcp, val) \
- _pcp_protect(__percpu_andnot_case_32, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_32, pcp, ~(u32)(val))
#define this_cpu_and_8(pcp, val) \
- _pcp_protect(__percpu_andnot_case_64, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_64, pcp, ~(u64)(val))
#define this_cpu_or_1(pcp, val) \
_pcp_protect(__percpu_or_case_8, pcp, val)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 709/982] Bluetooth: btusb: fix NXP IW610 composite device handling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (707 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 708/982] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 710/982] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
` (279 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolas Thibert,
Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Thibert <nithibert@gmail.com>
commit 2b50adefed9808a56d84d1de803cad882cc787fa upstream.
The NXP IW610 module exposes itself as a composite USB device
(0471:0215) with three interfaces: two real Bluetooth HCI interfaces
(class 0xe0) and one vendor-specific WiFi interface (class 0xff) used
by mwifiex-nxp.
The composite device's whole USB descriptor reports class 0xe0/01/01
(Bluetooth), so btusb_table's generic USB_DEVICE_INFO(0xe0, 0x01, 0x01)
entry matches every interface, not just the two real HCI ones -- btusb
ends up binding the WiFi interface too, and mwifiex-nxp never gets it.
Fix:
1. In btusb_table (the table the USB core actually matches against),
explicitly ignore the WiFi interface via BTUSB_IGNORE, ahead of the
generic entry.
2. In quirks_table, scope the existing BTUSB_MARVELL entry to the BT
interface class instead of matching the whole device by VID/PID
(harmless either way since quirks_table isn't consulted for initial
binding, but keep it correct).
Not upstream anywhere: checked NXP's own i.MX kernel fork
(nxp-imx/linux-imx), no IW610 references in btusb.c on any branch --
their reference designs wire this chip differently (WiFi over SDIO
per their release notes), so they never hit this.
Signed-off-by: Nicolas Thibert <nithibert@gmail.com>
Cc: stable@vger.kernel.org
Assisted-by: LLM (Claude Sonnet 5, Anthropic)
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/btusb.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -67,6 +67,15 @@ static struct usb_driver btusb_driver;
#define BTUSB_BARROT BIT(28)
static const struct usb_device_id btusb_table[] = {
+ /*
+ * NXP IW610 (0471:0215): the composite device reports Bluetooth
+ * class at the whole-device level, so the generic entry below
+ * would also match this WiFi vendor interface. Ignore it here
+ * first so mwifiex-nxp can bind it instead.
+ */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x0471, 0x0215, 0xff, 0xff, 0xff),
+ .driver_info = BTUSB_IGNORE },
+
/* Generic Bluetooth USB device */
{ USB_DEVICE_INFO(0xe0, 0x01, 0x01) },
@@ -469,6 +478,14 @@ static const struct usb_device_id blackl
{ USB_DEVICE(0x1286, 0x2046), .driver_info = BTUSB_MARVELL },
{ USB_DEVICE(0x1286, 0x204e), .driver_info = BTUSB_MARVELL },
+ /*
+ * NXP IW610 BT interfaces (Marvell-lineage silicon, same quirk as
+ * the 0x1286 entries above). Scoped to the BT interface class,
+ * not just VID/PID -- see the btusb_table entry above.
+ */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x0471, 0x0215, 0xe0, 0x01, 0x01),
+ .driver_info = BTUSB_MARVELL },
+
/* Intel Bluetooth devices */
{ USB_DEVICE(0x8087, 0x0025), .driver_info = BTUSB_INTEL_COMBINED },
{ USB_DEVICE(0x8087, 0x0026), .driver_info = BTUSB_INTEL_COMBINED },
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 710/982] Bluetooth: eir: validate service data length before reading UUID
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (708 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 709/982] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 711/982] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
` (278 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
commit e8241766794cf551d787fa3a77c0d54bbea6f6aa upstream.
eir_get_service_data() reads a 16-bit UUID from the service data using
get_unaligned_le16() without first checking that the data is long enough
to hold a UUID16 (2 bytes). If a malformed EIR entry has a service data
field with only 1 byte of payload (field_len=2), eir_get_data() returns
dlen=1. The subsequent get_unaligned_le16() then reads 1 byte past the
field boundary.
Additionally, if the corrupted UUID happens to match, the length
calculation "dlen - 2" underflows to SIZE_MAX since dlen is size_t.
Current callers either pass NULL for the length parameter or bounds-check
the returned length, but future callers may not.
Add a check that dlen >= sizeof(u16) and skip fields that are too short
to contain a valid UUID16.
Fixes: 8f9ae5b3ae80 ("Bluetooth: eir: Add helpers for managing service data")
Cc: stable@vger.kernel.org
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/eir.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
--- a/net/bluetooth/eir.c
+++ b/net/bluetooth/eir.c
@@ -373,7 +373,15 @@ void *eir_get_service_data(u8 *eir, size
size_t dlen;
while ((eir = eir_get_data(eir, eir_len, EIR_SERVICE_DATA, &dlen))) {
- u16 value = get_unaligned_le16(eir);
+ u16 value;
+
+ if (dlen < sizeof(value)) {
+ eir += dlen;
+ eir_len = eir_end - eir;
+ continue;
+ }
+
+ value = get_unaligned_le16(eir);
if (uuid == value) {
if (len)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 711/982] Bluetooth: hci_codec: validate vendor codec count length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (709 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 710/982] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 712/982] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
` (277 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz,
Laxman Acharya Padhya, Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
commit d0795cfd6f655f4de84868a4f4bb41a03f037b3d upstream.
The Read Local Supported Codecs parsers consume the variable-sized
standard codec array before parsing the vendor codec count. Although the
initial reply-size check includes a vendor count byte in the fixed layout,
it does not guarantee that the byte remains after the standard codec array.
If a controller reply ends immediately after that array, calculating the
vendor codec array size reads vnd_codecs->num beyond the skb data. Use
skb_pull_data() to validate and consume each codec header before using its
count in both command variants.
Fixes: 8961987f3f5f ("Bluetooth: Enumerate local supported codec and cache details")
Fixes: 9ae664028a9e ("Bluetooth: Add support for Read Local Supported Codecs V2")
Cc: stable@vger.kernel.org
Suggested-by: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_codec.c | 36 ++++++++++++++++++------------------
1 file changed, 18 insertions(+), 18 deletions(-)
--- a/net/bluetooth/hci_codec.c
+++ b/net/bluetooth/hci_codec.c
@@ -145,11 +145,12 @@ void hci_read_supported_codecs(struct hc
skb_pull(skb, sizeof(rp->status));
- std_codecs = (void *)skb->data;
+ std_codecs = skb_pull_data(skb, sizeof(*std_codecs));
+ if (!std_codecs)
+ goto error;
/* validate codecs length before accessing */
- if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num))
+ if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num))
goto error;
/* enumerate codec capabilities of standard codecs */
@@ -161,15 +162,14 @@ void hci_read_supported_codecs(struct hc
LOCAL_CODEC_ACL_MASK | LOCAL_CODEC_SCO_MASK, &caps);
}
- skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num));
+ skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num));
- vnd_codecs = (void *)skb->data;
+ vnd_codecs = skb_pull_data(skb, sizeof(*vnd_codecs));
+ if (!vnd_codecs)
+ goto error;
/* validate vendor codecs length before accessing */
- if (skb->len <
- flex_array_size(vnd_codecs, codec, vnd_codecs->num)
- + sizeof(vnd_codecs->num))
+ if (skb->len < flex_array_size(vnd_codecs, codec, vnd_codecs->num))
goto error;
/* enumerate vendor codec capabilities */
@@ -214,11 +214,12 @@ void hci_read_supported_codecs_v2(struct
skb_pull(skb, sizeof(rp->status));
- std_codecs = (void *)skb->data;
+ std_codecs = skb_pull_data(skb, sizeof(*std_codecs));
+ if (!std_codecs)
+ goto error;
/* check for payload data length before accessing */
- if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num))
+ if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num))
goto error;
memset(&caps, 0, sizeof(caps));
@@ -229,15 +230,14 @@ void hci_read_supported_codecs_v2(struct
&caps);
}
- skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num));
+ skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num));
- vnd_codecs = (void *)skb->data;
+ vnd_codecs = skb_pull_data(skb, sizeof(*vnd_codecs));
+ if (!vnd_codecs)
+ goto error;
/* check for payload data length before accessing */
- if (skb->len <
- flex_array_size(vnd_codecs, codec, vnd_codecs->num)
- + sizeof(vnd_codecs->num))
+ if (skb->len < flex_array_size(vnd_codecs, codec, vnd_codecs->num))
goto error;
for (i = 0; i < vnd_codecs->num; i++) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 712/982] Bluetooth: hci_sync: Serialize local codec list cleanup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (710 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 711/982] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 713/982] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
` (276 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 9a10987a2f160a44a638c9a35994ca6e3089696e upstream.
hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock.
Codec list additions and both traversals in sco_sock_getsockopt() use that
lock, but the close path does not. A close and BT_CODEC query can therefore
interleave as follows:
hci_dev_close_sync() sco_sock_getsockopt()
hci_dev_lock()
fetch codec entry
hci_codec_list_clear()
kfree(entry)
read entry->id
The reader then accesses an entry which the close path has freed. KASAN
reported:
BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0
Read of size 1 at addr ffff8881001c3450
Call Trace:
sco_sock_getsockopt+0xfa0/0xfe0
do_sock_getsockopt+0x537/0x7b0
__sys_getsockopt+0xf2/0x170
Allocated by task 92:
hci_codec_list_add.isra.0+0x2c/0x440
hci_read_codec_capabilities+0x224/0x590
hci_read_supported_codecs+0x2c2/0x640
Freed by task 92:
kfree+0x131/0x3c0
hci_codec_list_clear+0xd8/0x160
hci_dev_close_sync+0x92a/0xfa0
Take hdev->lock around the clear operation at its existing point in the
close path. This makes the clear wait for active readers and prevents a new
traversal until the list is empty without changing teardown ordering.
Fixes: b938790e7054 ("Bluetooth: hci_codec: Fix leaking content of local_codecs")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sync.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -5362,7 +5362,9 @@ int hci_dev_close_sync(struct hci_dev *h
memset(hdev->eir, 0, sizeof(hdev->eir));
memset(hdev->dev_class, 0, sizeof(hdev->dev_class));
bacpy(&hdev->random_addr, BDADDR_ANY);
+ hci_dev_lock(hdev);
hci_codec_list_clear(&hdev->local_codecs);
+ hci_dev_unlock(hdev);
hci_dev_put(hdev);
return err;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 713/982] dmaengine: sun6i: fix non-atomic read of DMA position registers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (711 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 712/982] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 714/982] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
` (275 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lugnberg, Frank Li,
Vinod Koul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lugnberg <christian.lugnberg@soundtrack.io>
commit c90b6973daa37f4c283342dff881ae001dea4fe6 upstream.
sun6i_get_chan_size() reads DMA_CHAN_LLI_ADDR and DMA_CHAN_CUR_CNT in two
separate readl() calls with no synchronisation between them:
pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
DMA_CHAN_LLI_ADDR holds the physical address of the *next* descriptor the
engine will load once the current one completes. DMA_CHAN_CUR_CNT holds the
remaining byte count for the *current* descriptor. If the DMA engine
advances to the next LLI entry between the two reads, pos becomes stale: it
still points to what was the next descriptor at the time of the first read,
but that descriptor is now the current one and CUR_CNT reflects its initial
(full) byte count. The subsequent virtual-chain walk starts one entry too
early and accumulates an extra full period's worth of bytes into the
residue estimate.
Fix this by re-reading DMA_CHAN_LLI_ADDR after DMA_CHAN_CUR_CNT and
retrying if the value changed. This double-read pattern guarantees that
both registers were sampled during the same descriptor interval. The cost
is at most one extra readl() pair per call in the racy case, which occurs
only at descriptor boundaries (~every 2 ms) and is negligible.
Fixes: a90e173f3faf ("dmaengine: sun6i: Add cyclic capability")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Christian Lugnberg <christian.lugnberg@soundtrack.io>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260817135723.12807-2-christian.lugnberg@soundtrack.io
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/sun6i-dma.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -352,8 +352,10 @@ static size_t sun6i_get_chan_size(struct
size_t bytes;
dma_addr_t pos;
- pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
- bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
+ do {
+ pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
+ bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
+ } while (pos != readl(pchan->base + DMA_CHAN_LLI_ADDR));
if (pos == LLI_LAST_ITEM)
return bytes;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 714/982] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (712 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 713/982] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 715/982] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
` (274 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lugnberg, Frank Li,
Vinod Koul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lugnberg <christian.lugnberg@soundtrack.io>
commit 9096bdc8d930147f7c39a493a859acbd3a8485d8 upstream.
sun6i_dma_tx_status() calls vchan_find_desc() to look up the virtual
descriptor for a given cookie, before checking whether the pointer
vd is NULL:
vd = vchan_find_desc(&vchan->vc, cookie);
txd = to_sun6i_desc(&vd->tx); /* vd may be NULL here */
if (vd) {
for (lli = txd->v_lli; ...)
vchan_find_desc() returns NULL when the descriptor has already been
completed or is in-flight on a physical channel and no longer present
in the virtual channel's descriptor list. When vd is NULL,
to_sun6i_desc() is called unconditionally on &vd->tx before the NULL
check, which is undefined behaviour. Move the call inside the if (vd)
guard to ensure it is only reached with a valid pointer.
vd = vchan_find_desc(&vchan->vc, cookie);
if (vd) {
struct sun6i_desc *txd = to_sun6i_desc(&vd->tx);
for (lli = txd->v_lli; ...)
Fixes: 555859308723 ("dmaengine: sun6i: Add driver for the Allwinner A31 DMA controller")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Christian Lugnberg <christian.lugnberg@soundtrack.io>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260817135723.12807-3-christian.lugnberg@soundtrack.io
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/sun6i-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -969,7 +969,6 @@ static enum dma_status sun6i_dma_tx_stat
struct sun6i_pchan *pchan = vchan->phy;
struct sun6i_dma_lli *lli;
struct virt_dma_desc *vd;
- struct sun6i_desc *txd;
enum dma_status ret;
unsigned long flags;
size_t bytes = 0;
@@ -981,9 +980,9 @@ static enum dma_status sun6i_dma_tx_stat
spin_lock_irqsave(&vchan->vc.lock, flags);
vd = vchan_find_desc(&vchan->vc, cookie);
- txd = to_sun6i_desc(&vd->tx);
if (vd) {
+ struct sun6i_desc *txd = to_sun6i_desc(&vd->tx);
for (lli = txd->v_lli; lli != NULL; lli = lli->v_lli_next)
bytes += lli->len;
} else if (!pchan || !pchan->desc) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 715/982] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (713 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 714/982] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 716/982] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
` (273 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pavel Zhigulin, Alexander Chesnokov,
Frank Li, Vinod Koul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
commit 0294b6dd515256c03ea2dbf508ddd3826d788579 upstream.
If devm_kcalloc() for rx_chn->flows fails in a channel request function,
the error path calls k3_udma_glue_release_rx_chn(), which dereferences
the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
Skip the flow release loop in k3_udma_glue_release_rx_chn() when
rx_chn->flows is not allocated.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: d70241913413 ("dmaengine: ti: k3-udma: Add glue layer for non DMAengine users")
Cc: stable@vger.kernel.org
Reported-by: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
Signed-off-by: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260812053426.3521589-1-Alexander.Chesnokov@kaspersky.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/ti/k3-udma-glue.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/dma/ti/k3-udma-glue.c
+++ b/drivers/dma/ti/k3-udma-glue.c
@@ -1103,8 +1103,9 @@ void k3_udma_glue_release_rx_chn(struct
rx_chn->psil_paired = false;
}
- for (i = 0; i < rx_chn->flow_num; i++)
- k3_udma_glue_release_rx_flow(rx_chn, i);
+ if (rx_chn->flows)
+ for (i = 0; i < rx_chn->flow_num; i++)
+ k3_udma_glue_release_rx_flow(rx_chn, i);
if (xudma_rflow_is_gp(rx_chn->common.udmax, rx_chn->flow_id_base))
xudma_free_gp_rflow_range(rx_chn->common.udmax,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 716/982] ipv6: xfrm: use full sockets in local error paths
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (714 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 715/982] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 717/982] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
` (272 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Steffen Klassert
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 6973a21ee73c5567f883813c8ef414774b45892f upstream.
xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it
always pointed at a full IPv6 socket.
That is not guaranteed. TCP SYN-ACK skbs can be owned by a
TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the
full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower
MTU, the local PMTU/error handling path can reach these callbacks with that
mini-socket still attached to the skb.
The callbacks then miscast the request socket as a full inet/IPv6 socket and
can read beyond the request_sock allocation when they access inet_sock or
ipv6_pinfo state.
Resolve the owner with skb_to_full_sk() in both callbacks and bail out when
no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error
logic, which already reasons about full sockets with skb_to_full_sk().
Fixes: dd767856a36e ("xfrm6: Don't call icmpv6_send on local error")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/xfrm6_output.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/net/ipv6/xfrm6_output.c
+++ b/net/ipv6/xfrm6_output.c
@@ -19,7 +19,10 @@
void xfrm6_local_rxpmtu(struct sk_buff *skb, u32 mtu)
{
struct flowi6 fl6;
- struct sock *sk = skb->sk;
+ struct sock *sk = skb_to_full_sk(skb);
+
+ if (!sk)
+ return;
fl6.flowi6_oif = sk->sk_bound_dev_if;
fl6.daddr = ipv6_hdr(skb)->daddr;
@@ -31,7 +34,10 @@ void xfrm6_local_error(struct sk_buff *s
{
struct flowi6 fl6;
const struct ipv6hdr *hdr;
- struct sock *sk = skb->sk;
+ struct sock *sk = skb_to_full_sk(skb);
+
+ if (!sk)
+ return;
hdr = skb->encapsulation ? inner_ipv6_hdr(skb) : ipv6_hdr(skb);
fl6.fl6_dport = inet_sk(sk)->inet_dport;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 717/982] net: lan743x: fix RX checksum use-after-free
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (715 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 716/982] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 718/982] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
` (271 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Chenguang Zhao,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit a9ce4053dc945c5372dedba5017ee675b30dc0c5 upstream.
lan743x_rx_process_buffer() adds each non-first receive buffer to the
head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb()
linearizes the head and frees the fragment skb metadata.
The checksum-success path then writes ip_summed through the local skb
pointer, which still points to the final fragment. This causes a
use-after-free write when a packet spans more than one receive buffer.
Set ip_summed on the surviving head skb instead. Multi-buffer receive
can occur after a live MTU increase because existing ring entries keep
their old buffer size until they are replenished.
A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer
packet produced a one-byte KASAN use-after-free write before this change.
The same test passed after the change. The driver object also builds
with W=1. This was not tested on physical LAN743x hardware.
Fixes: cd6910501cfd ("net: lan743x: Add support for Rx IP & TCP checksum offload")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Link: https://patch.msgid.link/20260913-b4-send-lan743x-uaf-v1-1-73d563d08ba9@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/microchip/lan743x_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/ethernet/microchip/lan743x_main.c
+++ b/drivers/net/ethernet/microchip/lan743x_main.c
@@ -2720,7 +2720,7 @@ process_extension:
rx->adapter->netdev);
if (rx->adapter->netdev->features & NETIF_F_RXCSUM) {
if (!is_ice && !is_tce && !is_icsm)
- skb->ip_summed = CHECKSUM_UNNECESSARY;
+ rx->skb_head->ip_summed = CHECKSUM_UNNECESSARY;
}
netdev_dbg(netdev, "sending %d byte frame to OS",
rx->skb_head->len);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 718/982] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (716 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 717/982] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 719/982] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
` (270 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guanglei Zhu,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit 5d063822ac5184939c1ed377a339a01d8ae814e8 upstream.
The NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is
zero. Nothing requires the offsets to advance, so a modem that
points an NDP at itself, or at an earlier NDP, keeps the loop
spinning forever on one CPU.
Break out when the next NDP offset is not larger than the current
one.
Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver")
Cc: stable@vger.kernel.org
Suggested-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector feeding the driver's
receive callback an NTB whose single NDP points at itself: the
unpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100%
and the thread never returns. With this check the loop terminates
within one iteration.
Changes in v2: move the non-increasing check to the wNextNdpIndex
retrieval site, as suggested by Loic Poulain, instead of tracking
the previous offset in a separate variable.
Link: https://patch.msgid.link/20260911021734.1396599-1-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/mhi_wwan_mbim.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -338,9 +338,13 @@ static void mhi_mbim_rx(struct mhi_mbim_
unlock:
rcu_read_unlock();
next_ndp:
- /* Other NDP to process? */
- ndpoffset = (int)le16_to_cpu(ndp16.wNextNdpIndex);
- if (!ndpoffset)
+ /* Other NDP to process? The offsets must advance, or a
+ * self-referencing NDP keeps the loop spinning forever.
+ */
+ n = (int)le16_to_cpu(ndp16.wNextNdpIndex);
+ if (n > ndpoffset)
+ ndpoffset = n;
+ else
break;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 719/982] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (717 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 718/982] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 720/982] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
` (269 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guanglei Zhu,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit 31550d585589fde1ae95bf7f7a8188b2d2fdf1c7 upstream.
mhi_mbim_rx() ignores the return value of skb_copy_bits() when it
copies each datagram out of the NTB. The datagram offset and length
come from the DPE, which is only checked to lie within the NTB
itself, so a modem can point a datagram outside the received skb.
The copy then fails and the freshly allocated skbn is passed to
netif_rx() with its uninitialized contents still in place, leaking
kernel heap memory into the network stack.
Free the skb and account an error when the copy fails.
Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver")
Cc: stable@vger.kernel.org
Suggested-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector pointing a DPE
outside the received NTB: the copy fails, and the unpatched driver
hands the uninitialized skbn to the network stack (observed as
"unknown protocol" on bytes that were never written). With this
check the failed datagram is dropped and counted as an rx error.
Changes in v2: factor the free-and-count sequence out into
mhi_mbim_rx_drop(), shared with the unknown-protocol path, as
suggested by Loic Poulain.
Link: https://patch.msgid.link/20260911021734.1396599-2-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/mhi_wwan_mbim.c | 18 +++++++++++++-----
1 file changed, 13 insertions(+), 5 deletions(-)
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -240,6 +240,14 @@ static int mbim_rx_verify_ndp16(struct s
return ret;
}
+static void mhi_mbim_rx_drop(struct mhi_mbim_link *link, struct sk_buff *skb)
+{
+ dev_kfree_skb_any(skb);
+ u64_stats_update_begin(&link->rx_syncp);
+ u64_stats_inc(&link->rx_errors);
+ u64_stats_update_end(&link->rx_syncp);
+}
+
static void mhi_mbim_rx(struct mhi_mbim_context *mbim, struct sk_buff *skb)
{
int ndpoffset;
@@ -309,7 +317,10 @@ static void mhi_mbim_rx(struct mhi_mbim_
continue;
skb_put(skbn, dgram_len);
- skb_copy_bits(skb, dgram_offset, skbn->data, dgram_len);
+ if (skb_copy_bits(skb, dgram_offset, skbn->data, dgram_len)) {
+ mhi_mbim_rx_drop(link, skbn);
+ continue;
+ }
switch (skbn->data[0] & 0xf0) {
case 0x40:
@@ -321,10 +332,7 @@ static void mhi_mbim_rx(struct mhi_mbim_
default:
net_err_ratelimited("%s: unknown protocol\n",
link->ndev->name);
- dev_kfree_skb_any(skbn);
- u64_stats_update_begin(&link->rx_syncp);
- u64_stats_inc(&link->rx_errors);
- u64_stats_update_end(&link->rx_syncp);
+ mhi_mbim_rx_drop(link, skbn);
continue;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 720/982] net/sched: hhf: cap hh_flows_limit at change time
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (718 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 719/982] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 721/982] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
` (268 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini), Victor Nogueira,
hybris, Jamal Hadi Salim, Simon Horman, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
commit 2cef2588c995722a901368def30befeef9ae55c6 upstream.
hhf_change() stores TCA_HHF_HH_FLOWS_LIMIT with no upper bound. A huge
hh_flows_limit lets each new heavy-hitter flow pass the
hh_flows_current_cnt check in alloc_new_hh() and forces a fixed-size
kzalloc(GFP_ATOMIC) per flow under spoofed traffic, for unbounded memory
growth.
Bound the attribute with NLA_POLICY_MAX() at 2*HH_FLOWS_CNT (the
hhf_init() default) and report the rejected value via extack. The
deprecated nested parse is kept: legacy tc does not set NLA_F_NESTED on
TCA_OPTIONS. Configs relying on hh_limit above the default were relying
on unbounded, unsafe behaviour and are not supported going forward.
hhf_init() also ran hhf_change() before setting the default
hh_flows_limit, so a user-supplied hh_limit at add time was clobbered
back to 2048. Set the default before hhf_change() so the configured
value sticks.
This is a follow-up to commit eb56a495f59b ("net/sched: hhf: clamp
quantum in change and init paths"), which bounded the quantum of the
same qdisc; the hh_flows_limit bound is the remaining unbounded knob of
that series' scope.
Conditions to recreate the bug: CAP_NET_ADMIN in a user namespace;
tc qdisc change dev X root hhf hh_limit 4294967295 succeeds and the
value is echoed by tc qdisc show, unbounding heavy-hitter flow
allocations; also tc qdisc add dev X root hhf hh_limit 500 stores 2048
instead of 500.
Fixes: 10239edf86f1 ("net-qdisc-hhf: Heavy-Hitter Filter (HHF) qdisc")
Cc: stable@vger.kernel.org
Reported-by: Sashiko (gemini) <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260822195509.112717-1-jhs@mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/QDISC-B855.v1.20260911153152@mojatatu.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/sch_hhf.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/net/sched/sch_hhf.c
+++ b/net/sched/sch_hhf.c
@@ -526,7 +526,7 @@ static void hhf_destroy(struct Qdisc *sc
static const struct nla_policy hhf_policy[TCA_HHF_MAX + 1] = {
[TCA_HHF_BACKLOG_LIMIT] = { .type = NLA_U32 },
[TCA_HHF_QUANTUM] = { .type = NLA_U32 },
- [TCA_HHF_HH_FLOWS_LIMIT] = { .type = NLA_U32 },
+ [TCA_HHF_HH_FLOWS_LIMIT] = NLA_POLICY_MAX(NLA_U32, 2 * HH_FLOWS_CNT),
[TCA_HHF_RESET_TIMEOUT] = { .type = NLA_U32 },
[TCA_HHF_ADMIT_BYTES] = { .type = NLA_U32 },
[TCA_HHF_EVICT_TIMEOUT] = { .type = NLA_U32 },
@@ -545,7 +545,7 @@ static int hhf_change(struct Qdisc *sch,
u32 new_hhf_non_hh_weight = q->hhf_non_hh_weight;
err = nla_parse_nested_deprecated(tb, TCA_HHF_MAX, opt, hhf_policy,
- NULL);
+ extack);
if (err < 0)
return err;
@@ -617,6 +617,9 @@ static int hhf_init(struct Qdisc *sch, s
q->hhf_evict_timeout = HZ; /* 1 sec */
q->hhf_non_hh_weight = 2;
+ /* Cap max active HHs at twice len of hh_flows table. */
+ q->hh_flows_limit = 2 * HH_FLOWS_CNT;
+
if (opt) {
int err = hhf_change(sch, opt, extack);
@@ -633,8 +636,6 @@ static int hhf_init(struct Qdisc *sch, s
for (i = 0; i < HH_FLOWS_CNT; i++)
INIT_LIST_HEAD(&q->hh_flows[i]);
- /* Cap max active HHs at twice len of hh_flows table. */
- q->hh_flows_limit = 2 * HH_FLOWS_CNT;
q->hh_flows_overlimit = 0;
q->hh_flows_total_cnt = 0;
q->hh_flows_current_cnt = 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 721/982] net/packet: clear RX owner on VNET header error
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (719 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 720/982] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 722/982] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
` (267 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Willem de Bruijn,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit 33ff111d7ba3beb86e28938d6382bb5beabd865a upstream.
Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race
condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2
ring slot before converting the virtio-net header. If the conversion
fails, the drop path leaves the slot claimed.
With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves
the only slot unavailable, so the ring also drops the next valid packet.
Clear the ownership bit on this error path. TPACKET_V3 already clears
its block state here.
Fixes: 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260913-b4-send-packet-vnet-v1-1-5545ffb528ae@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/af_packet.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -2440,7 +2440,9 @@ static int tpacket_rcv(struct sk_buff *s
virtio_net_hdr_from_skb(skb, h.raw + macoff -
sizeof(struct virtio_net_hdr),
vio_le(), true, 0)) {
- if (po->tp_version == TPACKET_V3)
+ if (po->tp_version <= TPACKET_V2)
+ __clear_bit(slot_id, po->rx_ring.rx_owner_map);
+ else
prb_clear_blk_fill_status(&po->rx_ring);
goto drop_n_account;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 722/982] net/packet: avoid truncating TPACKET_V3 private size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (720 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 721/982] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 723/982] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
` (266 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Willem de Bruijn,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit 37213e61120297920ae4c937fcb326a360da5084 upstream.
tpacket_req3.tp_sizeof_priv is an unsigned int, and packet_set_ring()
validates the full value against the block size. init_prb_bdqc() then
stores it in the unsigned short blk_sizeof_priv field.
Commit 2b6867c2ce76 ("net/packet: fix overflow in check for priv area
size") fixed the validation arithmetic, but an accepted value above
USHRT_MAX still narrows when it is stored.
For a 131072-byte block, tp_sizeof_priv=65536 is valid. The narrowing
makes offset_to_first_pkt 48 instead of 65584, so packet records can be
placed in the private area that userspace asked the kernel to preserve.
blk_sizeof_priv is internal state, so widen it to hold the validated
UAPI value.
Fixes: f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer implementation.")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260913-b4-send-packet-private-v1-1-925eab2cd388@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/internal.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/packet/internal.h
+++ b/net/packet/internal.h
@@ -21,7 +21,7 @@ struct tpacket_kbdq_core {
unsigned char reset_pending_on_curr_blk;
unsigned char delete_blk_timer;
unsigned short kactive_blk_num;
- unsigned short blk_sizeof_priv;
+ unsigned int blk_sizeof_priv;
/* last_kactive_blk_num:
* trick to see if user-space has caught up
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 723/982] memstick: ms_block: destroy io_queue workqueue on removal
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (721 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 722/982] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 724/982] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
` (265 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yifei Gao, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yifei Gao <gyf161023@gmail.com>
commit 90af7fde083e1b22c349c3a8b1626728e44e474c upstream.
msb_init_disk() creates the per-card ordered workqueue msb->io_queue with
alloc_ordered_workqueue(). It is torn down with destroy_workqueue() only
on the init error path; msb_remove() never destroys it. msb_stop() merely
flushes the queue, and neither msb_data_clear() nor put_disk() free it. As
a result every card insert/remove cycle leaks the workqueue and its
kworker, exhausting kernel memory over repeated cycles.
Destroy the workqueue in msb_remove() after the disk has been removed and
the queue drained.
Fixes: 0ab30494bc4f ("memstick: add support for legacy memorysticks")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Yifei Gao <gyf161023@gmail.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/memstick/core/ms_block.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/memstick/core/ms_block.c
+++ b/drivers/memstick/core/ms_block.c
@@ -2206,6 +2206,8 @@ static void msb_remove(struct memstick_d
msb_data_clear(msb);
mutex_unlock(&msb_disk_lock);
+ destroy_workqueue(msb->io_queue);
+
put_disk(msb->disk);
memstick_set_drvdata(card, NULL);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 724/982] keys: translate request_key_auth pid for the reading procfs instance
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (722 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 723/982] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 725/982] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
` (264 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Jarkko Sakkinen
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
commit 0d6a4268b06084baafd8ee5d66955c7e1c2e053b upstream.
request_key_auth_describe() prints rka->pid into /proc/keys as a raw
pid_t in the initial pid namespace. A reader can open /proc/keys through
a mount in another pid namespace. That reader sees a number with no
meaning there. The number can even name an unrelated task. The line
needs VIEW on the key. So the reader either shares the key owner's uid
or possesses the key.
The fix keeps a struct pid. Commit 4f82f45730c6 ("net ip6 flowlabel:
Make owner a union of struct pid * and kuid_t") gave
/proc/net/ip6_flowlabel the same storage. The print goes through
pid_nr_ns(). It renders against the pid namespace of the procfs instance
the line is read through. Commit ad08978ab41c ("ipv6/flowlabel: simplify
pid namespace lookup") moved that print to the same anchor. Output
through an initial namespace /proc does not change. The line shows 0 for
a requestor with no number in that namespace.
Translating at read time was the alternative. find_pid_ns() can resolve
a recycled number. The line would then name a live task with no
connection to the key. A stored struct pid gives 0 instead when the
requestor has no number there.
Link: https://lore.kernel.org/keyrings/20260809110202.2180410-1-maoyixie.tju@gmail.com/
Fixes: 78b7280cce23 ("KEYS: Improve /proc/keys")
Cc: stable@vger.kernel.org # v5.10+
Assisted-by: Claude:claude-opus-5 codeql
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://lore.kernel.org/r/20260821095935.1864998-1-maoyixie.tju@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/keys/request_key_auth-type.h | 2 +-
security/keys/request_key_auth.c | 12 +++++++++---
2 files changed, 10 insertions(+), 4 deletions(-)
--- a/include/keys/request_key_auth-type.h
+++ b/include/keys/request_key_auth-type.h
@@ -22,7 +22,7 @@ struct request_key_auth {
const struct cred *cred;
void *callout_info;
size_t callout_len;
- pid_t pid;
+ struct pid *pid;
char op[8];
} __randomize_layout;
--- a/security/keys/request_key_auth.c
+++ b/security/keys/request_key_auth.c
@@ -9,6 +9,8 @@
#include <linux/sched.h>
#include <linux/err.h>
+#include <linux/pid.h>
+#include <linux/proc_fs.h>
#include <linux/seq_file.h>
#include <linux/slab.h>
#include <linux/uaccess.h>
@@ -73,7 +75,10 @@ static void request_key_auth_describe(co
seq_puts(m, "key:");
seq_puts(m, key->description);
if (key_is_positive(key))
- seq_printf(m, " pid:%d ci:%zu", rka->pid, rka->callout_len);
+ seq_printf(m, " pid:%d ci:%zu",
+ pid_nr_ns(rka->pid,
+ proc_pid_ns(file_inode(m->file)->i_sb)),
+ rka->callout_len);
}
/*
@@ -113,6 +118,7 @@ static void free_request_key_auth(struct
if (rka->cred)
put_cred(rka->cred);
kfree(rka->callout_info);
+ put_pid(rka->pid);
kfree(rka);
}
@@ -226,14 +232,14 @@ struct key *request_key_auth_new(struct
irka = cred->request_key_auth->payload.data[0];
rka->cred = get_cred(irka->cred);
- rka->pid = irka->pid;
+ rka->pid = get_pid(irka->pid);
up_read(&cred->request_key_auth->sem);
}
else {
/* it isn't - use this process as the context */
rka->cred = get_cred(cred);
- rka->pid = current->pid;
+ rka->pid = get_pid(task_pid(current));
}
rka->target_key = key_get(target);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 725/982] KEYS: trusted: Fix tpm2_load_cmd() boundary check
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (723 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 724/982] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 726/982] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
` (263 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+6a581c4284f721d4,
Stefano Garzarella, Srish Srinivasan, Jarkko Sakkinen
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jarkko Sakkinen <jarkko@kernel.org>
commit 114f00d738f15dd8c7318369edcdc53dd6d08763 upstream.
tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
payload->blob_len. Address this by passing the decoded blob size to
tpm2_load_cmd(), and use it for the boundary checks.
Cc: stable@vger.kernel.org # v5.13+
Fixes: f2219745250f ("security: keys: trusted: use ASN.1 TPM2 key format for the blobs")
Reported-by: co+6a581c4284f721d4@bugs.sh
Closes: https://bugs.sh/b/6a581c4284f721d4/
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Tested-by: Srish Srinivasan <ssrish@linux.ibm.com>
Link: https://lore.kernel.org/r/20260901205809.2028454-1-jarkko@kernel.org
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/keys/trusted-keys/trusted_tpm2.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/security/keys/trusted-keys/trusted_tpm2.c
+++ b/security/keys/trusted-keys/trusted_tpm2.c
@@ -108,7 +108,7 @@ struct tpm2_key_context {
static int tpm2_key_decode(struct trusted_key_payload *payload,
struct trusted_key_options *options,
- u8 **buf)
+ u8 **buf, unsigned int *blob_len)
{
int ret;
struct tpm2_key_context ctx;
@@ -129,6 +129,7 @@ static int tpm2_key_decode(struct truste
return -ENOMEM;
*buf = blob;
+ *blob_len = ctx.priv_len + ctx.pub_len;
options->keyhandle = ctx.parent;
memcpy(blob, ctx.priv, ctx.priv_len);
@@ -384,10 +385,11 @@ static int tpm2_load_cmd(struct tpm_chip
int rc;
u32 attrs;
- rc = tpm2_key_decode(payload, options, &blob);
+ rc = tpm2_key_decode(payload, options, &blob, &blob_len);
if (rc) {
/* old form */
blob = payload->blob;
+ blob_len = payload->blob_len;
payload->old_format = 1;
} else {
/* Bind for cleanup: */
@@ -399,17 +401,17 @@ static int tpm2_load_cmd(struct tpm_chip
return -EINVAL;
/* must be big enough for at least the two be16 size counts */
- if (payload->blob_len < 4)
+ if (blob_len < 4)
return -EINVAL;
private_len = get_unaligned_be16(blob);
/* must be big enough for following public_len */
- if (private_len + 2 + 2 > (payload->blob_len))
+ if (private_len + 2 + 2 > blob_len)
return -E2BIG;
public_len = get_unaligned_be16(blob + 2 + private_len);
- if (private_len + 2 + public_len + 2 > payload->blob_len)
+ if (private_len + 2 + public_len + 2 > blob_len)
return -E2BIG;
pub = blob + 2 + private_len + 2;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 726/982] i2c: at91: release DMA channels on remove and probe error
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (724 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 725/982] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 727/982] i2c: imx: release DMA channels on " Greg Kroah-Hartman
` (262 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Mukesh Kumar Savaliya,
Andi Shyti
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit f7eeb1af8537b05953fb1c88ab8b59d94059a381 upstream.
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.
Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().
Fixes: 60937b2cdbf9 ("i2c: at91: add dma support")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.8+
Acked-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-1-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-at91-core.c | 3 +++
drivers/i2c/busses/i2c-at91-master.c | 12 +++++++++++-
drivers/i2c/busses/i2c-at91.h | 1 +
3 files changed, 15 insertions(+), 1 deletion(-)
--- a/drivers/i2c/busses/i2c-at91-core.c
+++ b/drivers/i2c/busses/i2c-at91-core.c
@@ -264,6 +264,7 @@ static int at91_twi_probe(struct platfor
pm_runtime_disable(dev->dev);
pm_runtime_set_suspended(dev->dev);
+ at91_twi_dma_release(dev);
return rc;
}
@@ -280,6 +281,8 @@ static int at91_twi_remove(struct platfo
i2c_del_adapter(&dev->adapter);
clk_disable_unprepare(dev->clk);
+ at91_twi_dma_release(dev);
+
pm_runtime_disable(dev->dev);
pm_runtime_set_suspended(dev->dev);
--- a/drivers/i2c/busses/i2c-at91-master.c
+++ b/drivers/i2c/busses/i2c-at91-master.c
@@ -819,11 +819,21 @@ static int at91_twi_configure_dma(struct
error:
if (ret != -EPROBE_DEFER)
dev_info(dev->dev, "can't get DMA channel, continue without DMA support\n");
+ at91_twi_dma_release(dev);
+ return ret;
+}
+
+void at91_twi_dma_release(struct at91_twi_dev *dev)
+{
+ struct at91_twi_dma *dma = &dev->dma;
+
if (dma->chan_rx)
dma_release_channel(dma->chan_rx);
if (dma->chan_tx)
dma_release_channel(dma->chan_tx);
- return ret;
+ dma->chan_rx = NULL;
+ dma->chan_tx = NULL;
+ dev->use_dma = false;
}
static int at91_init_twi_recovery_gpio(struct platform_device *pdev,
--- a/drivers/i2c/busses/i2c-at91.h
+++ b/drivers/i2c/busses/i2c-at91.h
@@ -172,6 +172,7 @@ void at91_twi_irq_restore(struct at91_tw
void at91_init_twi_bus(struct at91_twi_dev *dev);
void at91_init_twi_bus_master(struct at91_twi_dev *dev);
+void at91_twi_dma_release(struct at91_twi_dev *dev);
int at91_twi_probe_master(struct platform_device *pdev, u32 phy_addr,
struct at91_twi_dev *dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 727/982] i2c: imx: release DMA channels on probe error
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (725 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 726/982] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 728/982] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
` (261 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Frank Li, Andi Shyti
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit e9f03b9625e2eeaca357b065c92d5b14064a1583 upstream.
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.
Release the channels on the probe error path, mirroring
i2c_imx_remove().
Fixes: ce1a78840ff7 ("i2c: imx: add DMA support for freescale i2c driver")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.19+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-2-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -1614,6 +1614,8 @@ static int i2c_imx_probe(struct platform
clk_notifier_unregister:
clk_notifier_unregister(i2c_imx->clk, &i2c_imx->clk_change_nb);
+ if (i2c_imx->dma)
+ i2c_imx_dma_free(i2c_imx);
free_irq(irq, i2c_imx);
rpm_disable:
pm_runtime_put_noidle(&pdev->dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 728/982] IB/mlx4: Fix use-after-free on pkey sysfs registration failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (726 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 727/982] i2c: imx: release DMA channels on " Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 729/982] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
` (260 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Leon Romanovsky
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
commit 1af874e9f4ce22ccf8b10ab5462f32c70d3be21a upstream.
register_pkey_tree() ignores errors from register_one_pkey_tree() and
continues registering the remaining slaves. The per-slave error path has
already released the pkey parent kobjects, but their pointers remain
stored in the device. A later device cleanup therefore passes the stale
pointers to kobject_put(), causing a use-after-free.
Clear the parent pointers after releasing a failed slave tree and skip
unregistered trees during device cleanup. This preserves the existing
best-effort registration behavior while preventing a second cleanup of
the failed tree.
Fixes: c1e7e466120b ("IB/mlx4: Add iov directory in sysfs under the ib device")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://patch.msgid.link/20260816044510.3848996-1-shuangpeng.kernel@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/mlx4/sysfs.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/infiniband/hw/mlx4/sysfs.c
+++ b/drivers/infiniband/hw/mlx4/sysfs.c
@@ -753,11 +753,13 @@ err_add:
kobject_put(p);
}
kobject_put(dev->dev_ports_parent[slave]);
+ dev->dev_ports_parent[slave] = NULL;
err_ports:
kobject_put(dev->pkeys.device_parent[slave]);
/* extra put for the device_parent create_and_add */
kobject_put(dev->pkeys.device_parent[slave]);
+ dev->pkeys.device_parent[slave] = NULL;
fail_dev:
kobject_put(dev->iov_parent);
@@ -787,6 +789,8 @@ static void unregister_pkey_tree(struct
return;
for (slave = device->dev->persist->num_vfs; slave >= 0; --slave) {
+ if (!device->pkeys.device_parent[slave])
+ continue;
list_for_each_entry_safe(p, t,
&device->pkeys.pkey_port_list[slave],
entry) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 729/982] selinux: always fill AVC decision in avc_has_perm_noaudit()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (727 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 728/982] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 730/982] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
` (259 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Göttsche,
Stephen Smalley, Paul Moore
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Göttsche <cgzones@googlemail.com>
commit 8861db305103107199b1426f25fde1fb6d465583 upstream.
avc_has_perm_noaudit() is documented to return a copy of the access
decision in @avd, but its early return for an empty requested permission
set leaves the buffer untouched. All callers pass an uninitialized
stack variable and afterwards feed it to avc_audit(), and the inode hook
even stores it in the per-task decision cache.
Fill in a deny-all, audit-all decision, similar to avd_init(), so every
caller receives a defined value at no cost on the hot path.
Cc: stable@vger.kernel.org
Fixes: e6f2f381e4015386 ("selinux: replace BUG_ONs with WARN_ONs in avc.c")
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/avc.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -1144,8 +1144,11 @@ inline int avc_has_perm_noaudit(struct s
int rc = 0;
u32 denied;
- if (WARN_ON(!requested))
+ if (WARN_ON(!requested)) {
+ /* Provide a deny-all, audit-all decision to the caller. */
+ *avd = (struct av_decision){ .auditdeny = 0xffffffff };
return -EACCES;
+ }
rcu_read_lock();
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 730/982] mmc: core: Cancel SDIO IRQ work before freeing host
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (728 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 729/982] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 731/982] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
` (258 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 6feadbecdae60a6324c967f3b1493741083793a3 upstream.
A host controller that uses sdio_signal_irq() schedules host->sdio_irq_work
from its interrupt handler. That work is only cancelled on the suspend
path (mmc_sdio_suspend()), not on the remove/free path, so a worker armed
just before the controller freed its IRQ can run after
mmc_host_classdev_release() has freed the host and dereference it through
container_of().
Cancel host->sdio_irq_work in mmc_free_host(), like the existing
host->detect drain added by commit 1036f69e2513 ("mmc: core: Cancel
delayed work before releasing host").
This issue was found by an in-house static analysis tool.
Fixes: 682696605c70 ("mmc: sdio: Add API to manage SDIO IRQs from a workqueue")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/host.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/mmc/core/host.c
+++ b/drivers/mmc/core/host.c
@@ -670,6 +670,7 @@ EXPORT_SYMBOL(mmc_remove_host);
void mmc_free_host(struct mmc_host *host)
{
cancel_delayed_work_sync(&host->detect);
+ cancel_work_sync(&host->sdio_irq_work);
mmc_pwrseq_free(host);
put_device(&host->class_dev);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 731/982] mmc: core: Fix OF node reference leak on card add failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (729 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 730/982] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 732/982] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
` (257 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhu Ling, Shawn Lin, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhu Ling <zhuling0805@qq.com>
commit 08b54e16d547d5c1aa61bf7a3595bb1620975eeb upstream.
mmc_of_find_child_device() returns a device node with its reference count
incremented. mmc_add_card() stores the reference before calling
device_add(), while the card is marked present only after device_add()
succeeds.
If device_add() fails, the callers release the card through
mmc_remove_card(). However, mmc_remove_card() only drops the OF node
reference for a present card, leaking the reference on this error path.
Move of_node_put() outside the present-card conditional so the reference
is released for both registered cards and card-add failures.
Fixes: 25185f3f31c9 ("mmc: Add SDIO function devicetree subnode parsing")
Cc: stable@vger.kernel.org
Signed-off-by: Zhu Ling <zhuling0805@qq.com>
Reviewed-by: Shawn Lin <shawn.lin@linux.dev>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/bus.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/mmc/core/bus.c
+++ b/drivers/mmc/core/bus.c
@@ -398,8 +398,8 @@ void mmc_remove_card(struct mmc_card *ca
mmc_hostname(card->host), card->rca);
}
device_del(&card->dev);
- of_node_put(card->dev.of_node);
}
+ of_node_put(card->dev.of_node);
if (host->cqe_enabled) {
host->cqe_ops->cqe_disable(host);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 732/982] mmc: mxcmmc: cancel data work and watchdog on remove
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (730 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 731/982] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 733/982] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
` (256 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit d3a421c82412344022982d5b91ba23194a0a6f29 upstream.
mxcmci_remove() frees the host through the devm tail, but neither it nor
mmc_remove_host() drains the driver's own asynchronous state.
host->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(),
is deleted only by the DMA- and IRQ-complete paths, which the remove path
does not explicitly drain; it can therefore fire after the host is freed
and dereference it in mxcmci_watchdog(). host->datawork, armed from the
IRQ handler on the PIO path, is not cancelled by the remove path either.
Free the devm-registered IRQ, then cancel datawork and delete the watchdog
in mxcmci_remove(), before dma_release_channel(). Freeing the IRQ first
keeps a trailing handler from re-arming datawork between the cancel and
the host free. Both callbacks are non-self-rearming.
This issue was found by an in-house static analysis tool.
Fixes: f6ad0a481342 ("mmc: mxcmmc: fix bug that may block a data transfer forever")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mxcmmc.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/mmc/host/mxcmmc.c
+++ b/drivers/mmc/host/mxcmmc.c
@@ -1171,6 +1171,10 @@ static int mxcmci_remove(struct platform
mmc_remove_host(mmc);
+ devm_free_irq(&pdev->dev, platform_get_irq(pdev, 0), host);
+ cancel_work_sync(&host->datawork);
+ timer_delete_sync(&host->watchdog);
+
if (host->pdata && host->pdata->exit)
host->pdata->exit(&pdev->dev, mmc);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 733/982] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (731 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 732/982] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 734/982] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
` (255 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Florian Maillard, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Maillard <florian.maillard@mailoo.org>
commit 9c182bc5d7817437a7d04ab96133f9191846d93d upstream.
The Realtek RTS522A card reader in the Lenovo ThinkPad X260
(subsystem 17aa:504a) incorrectly reports inserted SD cards as
write-protected.
This causes the MMC core to expose the card as read-only:
mmcblk0: mmc0:aaaa SN256 238 GiB (ro)
and /sys/block/mmcblk0/ro reports 1.
Setting MMC_CAP2_NO_WRITE_PROTECT makes the card writable again.
Limit the quirk to the affected Lenovo subsystem.
Assisted-by: ChatGPT:GPT-5.6 Sol
Signed-off-by: Florian Maillard <florian.maillard@mailoo.org>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/rtsx_pci_sdmmc.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/mmc/host/rtsx_pci_sdmmc.c
+++ b/drivers/mmc/host/rtsx_pci_sdmmc.c
@@ -1488,6 +1488,11 @@ static void realtek_init_host(struct rea
mmc->caps = mmc->caps | MMC_CAP_AGGRESSIVE_PM;
mmc->caps2 = MMC_CAP2_NO_PRESCAN_POWERUP | MMC_CAP2_FULL_PWR_CYCLE |
MMC_CAP2_NO_SDIO;
+
+ if (pcr->pci->device == 0x522a &&
+ pcr->pci->subsystem_vendor == PCI_VENDOR_ID_LENOVO &&
+ pcr->pci->subsystem_device == 0x504a)
+ mmc->caps2 |= MMC_CAP2_NO_WRITE_PROTECT;
mmc->max_current_330 = 400;
mmc->max_current_180 = 800;
mmc->ops = &realtek_pci_sdmmc_ops;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 734/982] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (732 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 733/982] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 735/982] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
` (254 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 4396d70bb7fec531bcf934fed016b2f3300c670b upstream.
Probe failure and removal leave SDHCI child devices registered after the
parent clock and managed resources are released.
Unregister the OF children in reverse order before disabling the parent
clock on both paths. Use of_platform_device_destroy() because manual
child creation does not set the flag required by of_platform_depopulate().
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: bb7b8ec62dfb ("mmc: sdhci-of-aspeed: Add support for the ASPEED SD controller")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Assisted-by: OpenAI:GPT-5.6
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci-of-aspeed.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/mmc/host/sdhci-of-aspeed.c
+++ b/drivers/mmc/host/sdhci-of-aspeed.c
@@ -565,12 +565,14 @@ static int aspeed_sdc_probe(struct platf
if (!cpdev) {
of_node_put(child);
ret = -ENODEV;
- goto err_clk;
+ goto err_children;
}
}
return 0;
+err_children:
+ device_for_each_child_reverse(&pdev->dev, NULL, of_platform_device_destroy);
err_clk:
clk_disable_unprepare(sdc->clk);
return ret;
@@ -580,6 +582,7 @@ static int aspeed_sdc_remove(struct plat
{
struct aspeed_sdc *sdc = dev_get_drvdata(&pdev->dev);
+ device_for_each_child_reverse(&pdev->dev, NULL, of_platform_device_destroy);
clk_disable_unprepare(sdc->clk);
return 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 735/982] mmc: sdio_uart: fix xmit_fifo leak when the port table is full
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (733 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 734/982] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 736/982] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
` (253 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Gu <ustc.gu@gmail.com>
commit 53823e25793a97d07e6e98e0904bbf74cac8bc76 upstream.
sdio_uart_add_port() allocates the transmit fifo before claiming a
slot in sdio_uart_table[]. When all UART_NR slots are taken, it
returns -EBUSY with the fifo still allocated, but the probe error
path only kfree()s the port, leaking the transmit fifo.
Free the fifo in the failure path of sdio_uart_add_port() itself so
the function retains nothing on error.
Fixes: 8b197a5ce7a7 ("sdio_uart: Use kfifo instead of the messy circ stuff")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/sdio_uart.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/mmc/core/sdio_uart.c
+++ b/drivers/mmc/core/sdio_uart.c
@@ -104,6 +104,9 @@ static int sdio_uart_add_port(struct sdi
}
spin_unlock(&sdio_uart_table_lock);
+ if (ret)
+ kfifo_free(&port->xmit_fifo);
+
return ret;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 736/982] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (734 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 735/982] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 737/982] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
` (252 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit d5ea0d226e8f0801d78702142a124d78c317d822 upstream.
The threaded IRQ handler can run before devm_request_threaded_irq()
returns, but thread_lock was initialized afterwards. Initialize it before
requesting either interrupt.
Fixes: 8047310ee984 ("mmc: sh_mmcif: fix a race, causing an Oops on SMP")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sh_mmcif.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/mmc/host/sh_mmcif.c
+++ b/drivers/mmc/host/sh_mmcif.c
@@ -1424,6 +1424,7 @@ static int sh_mmcif_probe(struct platfor
host->pd = pdev;
spin_lock_init(&host->lock);
+ mutex_init(&host->thread_lock);
mmc->ops = &sh_mmcif_ops;
sh_mmcif_init_ocr(host);
@@ -1484,8 +1485,6 @@ static int sh_mmcif_probe(struct platfor
}
}
- mutex_init(&host->thread_lock);
-
ret = mmc_add_host(mmc);
if (ret < 0)
goto err_clk;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 737/982] mmc: spi: reset bytes_xfered before retrying CRC failures
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (735 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 736/982] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 738/982] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
` (251 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Rao <raoxu@uniontech.com>
commit 8b0cc8707f65e0f51912e764e1b309b2559db1ec upstream.
mmc_spi_data_do() updates data->bytes_xfered after each block has been
transferred successfully. If a later block in the same data request
fails with a CRC error, data->bytes_xfered may therefore contain the
number of bytes completed before the failing block.
mmc_spi_request() has a private recovery path for such CRC failures. It
sends STOP_TRANSMISSION, clears data->error and jumps back to
crc_recover to issue the same command and data request again. However,
it does not clear data->bytes_xfered before the retry.
If the retry succeeds, the request is completed with the bytes from the
failed attempt still included in data->bytes_xfered. For a multi-block
request this can make the completed request report more bytes than were
transferred by the successful retry, and can even exceed the request size
when most blocks completed before the CRC error.
This is most likely to be observed on MMC-over-SPI systems where long
multi-block transfers occasionally hit a data CRC error but the
mmc_spi-internal retry succeeds. The data itself is retried, but the
completion accounting is not.
Clear data->bytes_xfered together with data->error before repeating the
request so the final completion reports only the bytes transferred by the
successful attempt.
Fixes: 061c6c847eeb ("mmc_spi: Recover from CRC errors for r/w operation over SPI.")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmc_spi.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/mmc/host/mmc_spi.c
+++ b/drivers/mmc/host/mmc_spi.c
@@ -954,6 +954,7 @@ crc_recover:
status = mmc_spi_command_send(host, mrq, &stop, 0);
crc_retry--;
mrq->data->error = 0;
+ mrq->data->bytes_xfered = 0;
goto crc_recover;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 738/982] mmc: sdhci_am654: Reset command and data lines on failed tuning
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (736 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 737/982] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 739/982] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
` (250 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit 7197d9107d9545730153b82ea5a411c5208b443f upstream.
The CMD/DATA reset after tuning should be performed regardless of
whether tuning succeeded or failed, since tuning data may remain in
the buffer in either case. Move the error return after the reset so
that the controller is always cleaned up.
Fixes: de31f6ab68a3 ("mmc: sdhci_am654: Reset Command and Data line after tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -415,15 +415,13 @@ static int sdhci_am654_execute_tuning(st
struct sdhci_host *host = mmc_priv(mmc);
int err = sdhci_execute_tuning(mmc, opcode);
- if (err)
- return err;
/*
* Tuning data remains in the buffer after tuning.
* Do a command and data reset to get rid of it
*/
sdhci_reset(host, SDHCI_RESET_CMD | SDHCI_RESET_DATA);
- return 0;
+ return err;
}
static u32 sdhci_am654_cqhci_irq(struct sdhci_host *host, u32 intmask)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 739/982] Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (737 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 738/982] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 740/982] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
` (249 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alvin Šipraga, Nuno Sá,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alvin Šipraga <alvin.sipraga@analog.com>
commit 21efadc62272cabee9bec27777ae75d84a9ca8a8 upstream.
So as not to clobber any pre-programmed GPIO state in the execution
of its gpiochip ops, the driver caches things during probe time.
However, since those ops can be called both during and immediately after
the call to devm_gpiochip_add_data(), it is imperative that things are
cached before that. That's not the case right now, so reorder the two
steps to prevent any clobbering.
In the concrete example which motivated this change, a bootloader was
preconfiguring an important GPIO output to HIGH before booting the
kernel. Linux would then inadvertently set that output to LOW while
configuring a GPIO hog on a discrete GPIO line within the same 8-bit
bank (because the cached value was 0=LOW).
Fixes: ba9f507a1bea ("Input: adp5588-keys - export unused GPIO pins")
Signed-off-by: Alvin Šipraga <alvin.sipraga@analog.com>
Reviewed-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260818-adp5588-gpio-cache-v1-1-650a2674fc0d@analog.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/keyboard/adp5588-keys.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/drivers/input/keyboard/adp5588-keys.c
+++ b/drivers/input/keyboard/adp5588-keys.c
@@ -453,12 +453,6 @@ static int adp5588_gpio_add(struct adp55
mutex_init(&kpad->gpio_lock);
- error = devm_gpiochip_add_data(dev, &kpad->gc, kpad);
- if (error) {
- dev_err(dev, "gpiochip_add failed: %d\n", error);
- return error;
- }
-
for (i = 0; i <= ADP5588_BANK(ADP5588_MAXGPIO); i++) {
kpad->dat_out[i] = adp5588_read(kpad->client,
GPIO_DAT_OUT1 + i);
@@ -466,6 +460,12 @@ static int adp5588_gpio_add(struct adp55
kpad->pull_dis[i] = adp5588_read(kpad->client, GPIO_PULL1 + i);
}
+ error = devm_gpiochip_add_data(dev, &kpad->gc, kpad);
+ if (error) {
+ dev_err(dev, "gpiochip_add failed: %d\n", error);
+ return error;
+ }
+
return 0;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 740/982] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (738 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 739/982] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 741/982] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
` (248 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alexei Turtanov, Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexei Turtanov <9alexei9@gmail.com>
commit aefbda23eeba234c3ff0f135dc5be6e294bd25a6 upstream.
The internal keyboard of the Xiaomi Redmi Book Pro 16 2026 (board TM2425)
does not work: atkbd_probe() succeeds and every command is ACKed, but no
scancodes ever arrive afterwards.
Testing on the hardware through serio_raw shows that ATKBD_CMD_RESET_DIS
(0xF5) is the culprit. After 0xF5 the embedded controller keeps ACKing
commands but stops delivering scancodes, and neither ATKBD_CMD_ENABLE
(0xF4) nor ATKBD_CMD_RESET_BAT (0xFF) bring them back. Only re-enabling
the keyboard interface at the controller level (i8042 command 0xAE, or
rewriting the command byte as i8042_port_close() does) revives it.
Running the init sequence without 0xF5 (0xED 0x00, 0xF3 0x00, 0xF4)
keeps the keyboard working.
'i8042.dumbkbd=1' also works around this, but then the driver never
writes to the keyboard and the LEDs cannot be controlled. Use the
existing atkbd_deactivate_fixup quirk instead, as done for the sibling
TM2424 by commit 3a046db33bb9 ("Input: atkbd - skip deactivate for
Xiaomi Book Pro 14's internal keyboard"). Tested on v7.2: keyboard,
Caps Lock LED and s2idle suspend/resume all work.
DMI: XIAOMI REDMI Book Pro 16 2026/TM2425, BIOS RMAPT6B0P0909 05/22/2026
Fixes: 9cf6e24c9fbf ("Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID")
Cc: stable@vger.kernel.org
Signed-off-by: Alexei Turtanov <9alexei9@gmail.com>
Link: https://patch.msgid.link/20260828112239.18081-1-9alexei9@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/keyboard/atkbd.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/input/keyboard/atkbd.c
+++ b/drivers/input/keyboard/atkbd.c
@@ -1962,6 +1962,14 @@ static const struct dmi_system_id atkbd_
},
.callback = atkbd_deactivate_fixup,
},
+ {
+ /* Xiaomi Redmi Book Pro 16 2026 (TM2425) */
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "XIAOMI"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "REDMI Book Pro 16 2026"),
+ },
+ .callback = atkbd_deactivate_fixup,
+ },
{ }
};
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 741/982] Input: evdev - zero absinfo before partial copy in EVIOCSABS
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (739 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 740/982] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 742/982] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
` (247 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit 8b852965b8eaf910c314dc346967ed82c8d4f235 upstream.
The EVIOCSABS handler copies at most the user supplied ioctl size into
an uninitialized on-stack struct input_absinfo:
if (copy_from_user(&abs, p, min_t(size_t,
size, sizeof(struct input_absinfo))))
The size comes from _IOC_SIZE() of the ioctl command and is therefore
fully controlled by userspace. A short size leaves the trailing part of
the structure holding whatever was on the kernel stack, and the whole
structure is then stored into the device:
dev->absinfo[t] = abs;
EVIOCGABS hands that back to userspace, disclosing the stale stack
bytes. Only the resolution field is currently cleared, which covers the
legacy struct layout but not an arbitrarily short size.
Zero the structure before the copy so any part not supplied by the
caller reads back as zero. The existing resolution fixup is kept, since
it also handles a size that partially overlaps that field.
Fixes: 448cd1664a57 ("Input: evdev - rearrange ioctl handling")
Cc: stable@vger.kernel.org
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Link: https://patch.msgid.link/20260901130629.24078-2-ivanrwcm25@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/evdev.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/input/evdev.c
+++ b/drivers/input/evdev.c
@@ -1231,6 +1231,8 @@ static long evdev_do_ioctl(struct file *
t = _IOC_NR(cmd) & ABS_MAX;
+ memset(&abs, 0, sizeof(abs));
+
if (copy_from_user(&abs, p, min_t(size_t,
size, sizeof(struct input_absinfo))))
return -EFAULT;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 742/982] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (740 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 741/982] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 743/982] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
` (246 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chris Sommers, Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Sommers <chris.sommers@icloud.com>
commit 25e424eb4ae1a662d9c3573218d06ac32f797fc5 upstream.
On the Acer Aspire Go 15 (AG15-42P), the internal keyboard drops out
~5 seconds after boot on both Linux and Linux-LTS kernels. Keystrokes on
the built-in keyboard stop registering while the trackpad and external
keyboards remain functional.
Testing confirms that booting with the i8042.reset kernel parameter
resolves the issue and keeps the internal keyboard responsive.
Add SERIO_QUIRK_RESET_ALWAYS to i8042_dmi_quirk_table for the Acer
Aspire AG15-42P to automatically apply this quirk on boot.
Signed-off-by: Chris Sommers <chris.sommers@icloud.com>
Link: https://patch.msgid.link/20260907182723.2709981-1-chris.sommers@icloud.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/serio/i8042-acpipnpio.h | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/serio/i8042-acpipnpio.h
+++ b/drivers/input/serio/i8042-acpipnpio.h
@@ -261,6 +261,13 @@ static const struct dmi_system_id i8042_
{
.matches = {
DMI_MATCH(DMI_SYS_VENDOR, "Acer"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "Aspire AG15-42P"),
+ },
+ .driver_data = (void *)(SERIO_QUIRK_RESET_ALWAYS)
+ },
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "Acer"),
DMI_MATCH(DMI_PRODUCT_NAME, "Aspire ES1-132"),
},
.driver_data = (void *)(SERIO_QUIRK_RESET_ALWAYS)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 743/982] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (741 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 742/982] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 744/982] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
` (245 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
commit 51cfe54f815ae175c7d1126b983d4d7c89715004 upstream.
When chunking writes into SMBus blocks in rmi_smb_write_block(), the
loop calculates block_len using the original total length (len) instead
of the remaining length (cur_len).
If len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32
for every iteration, even on the final partial chunk where fewer than 32
bytes remain. This causes smb_block_write() to read 32 bytes from the
advanced data buffer pointer, reading past the end of the input buffer.
Fix this by calculating block_len using cur_len and advancing the buffer
and address pointers by block_len.
Fixes: 82264d0cf7ae ("Input: synaptics-rmi4 - add SMBus support")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot@kernel.org
Assisted-by: LLM
Link: https://patch.msgid.link/anLFSMKSoKyyZ272@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/rmi4/rmi_smbus.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/input/rmi4/rmi_smbus.c
+++ b/drivers/input/rmi4/rmi_smbus.c
@@ -140,7 +140,7 @@ static int rmi_smb_write_block(struct rm
u8 commandcode;
struct rmi_smb_xport *rmi_smb =
container_of(xport, struct rmi_smb_xport, xport);
- int cur_len = (int)len;
+ size_t cur_len = len;
mutex_lock(&rmi_smb->page_mutex);
@@ -148,7 +148,7 @@ static int rmi_smb_write_block(struct rm
/*
* break into 32 bytes chunks to write get command code
*/
- int block_len = min_t(int, len, SMB_MAX_COUNT);
+ int block_len = min_t(size_t, cur_len, SMB_MAX_COUNT);
retval = rmi_smb_get_command_code(xport, rmiaddr, block_len,
false, &commandcode);
@@ -161,9 +161,9 @@ static int rmi_smb_write_block(struct rm
goto exit;
/* prepare to write next block of bytes */
- cur_len -= SMB_MAX_COUNT;
- databuff += SMB_MAX_COUNT;
- rmiaddr += SMB_MAX_COUNT;
+ cur_len -= block_len;
+ databuff += block_len;
+ rmiaddr += block_len;
}
exit:
mutex_unlock(&rmi_smb->page_mutex);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 744/982] Input: soc_button_array - fix MS Surface Pro 11 probe failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (742 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 743/982] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 745/982] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
` (244 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sergey Lebedev, Hans de Goede,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <johannes.goede@oss.qualcomm.com>
commit ed22ad5fdbdbf9b4cb4ad3003f60314b5a5eb89d upstream.
On the MS Surface Pro 11 soc_button_array probing races with the GPIO
driver probing. If soc_button_array wins the race then gpiod_get() returns
EPROBE_DEFER, which should normally take care of retrying later, but
the soc_button_array code deliberately ignores EPROBE_DEFER causing it
to fail its probe() which causes the volume and power buttons to now work.
The ignoring of EPROBE_DEFER is there to deal with a problem specific to
older Bay Trail (BYT) and Cherry Trail (CHT) tablets which often use this
driver. Modify the error handling to only ignore EPROBE_DEFER on BYT and
CHT platforms and propagate EPROBE_DEFER normally on other platforms.
Fixes: bcf059578980 ("Input: soc_button_array - partial revert of support for newer surface devices")
Cc: stable@vger.kernel.org
Reported-by: Sergey Lebedev <lsa.uz@pm.me>
Closes: https://lore.kernel.org/lkml/20260830141355.55898-1-lsa.uz@pm.me/
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Tested-by: Sergey Lebedev <lsa.uz@pm.me>
Link: https://patch.msgid.link/20260909093934.29411-1-johannes.goede@oss.qualcomm.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/misc/soc_button_array.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
--- a/drivers/input/misc/soc_button_array.c
+++ b/drivers/input/misc/soc_button_array.c
@@ -16,6 +16,7 @@
#include <linux/gpio/consumer.h>
#include <linux/gpio_keys.h>
#include <linux/gpio.h>
+#include <linux/platform_data/x86/soc.h>
#include <linux/platform_device.h>
static bool use_low_level_irq;
@@ -160,7 +161,7 @@ soc_button_device_create(struct platform
struct gpio_keys_platform_data *gpio_keys_pdata;
const struct dmi_system_id *dmi_id;
int invalid_acpi_index = -1;
- int error, gpio, irq;
+ int error, gpio, irq = 0;
int n_buttons = 0;
for (info = button_info; info->name; info++)
@@ -191,8 +192,9 @@ soc_button_device_create(struct platform
error = soc_button_lookup_gpio(&pdev->dev, info->acpi_index, &gpio, &irq);
if (error || irq < 0) {
/*
- * Skip GPIO if not present. Note we deliberately
- * ignore -EPROBE_DEFER errors here. On some devices
+ * Propagate -EPROBE_DEFER, skip button on other errors.
+ *
+ * -EPROBE_DEFER is ignored on Bay & Cherry Trail. Here
* Intel is using so called virtual GPIOs which are not
* GPIOs at all but some way for AML code to check some
* random status bits without need a custom opregion.
@@ -201,6 +203,12 @@ soc_button_device_create(struct platform
* we do not have a driver for these so they will never
* show up, therefore we ignore -EPROBE_DEFER.
*/
+ if ((error == -EPROBE_DEFER || irq == -EPROBE_DEFER) &&
+ !(soc_intel_is_byt() || soc_intel_is_cht())) {
+ error = -EPROBE_DEFER;
+ goto err_free_mem;
+ }
+
continue;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 745/982] Input: soc_button_array - check btns_desc->package.count
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (743 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 744/982] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 746/982] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
` (243 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shashiko, Hans de Goede,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <johannes.goede@oss.qualcomm.com>
commit fb5022278b6ea7f1838e3ef78028d5d5e3375f65 upstream.
Check that btns_desc->package.count is not 0 before accessing
btns_desc->package.elements[0].
Fixes: 4c3362f44980 ("Input: soc_button_array - add support for ACPI 6.0 Generic Button Device")
Cc: stable@vger.kernel.org
Reported-by: Shashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-input/20260909091440.3384C1F00A3A@smtp.kernel.org/
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Link: https://patch.msgid.link/20260909093934.29411-2-johannes.goede@oss.qualcomm.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/misc/soc_button_array.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/misc/soc_button_array.c
+++ b/drivers/input/misc/soc_button_array.c
@@ -377,7 +377,7 @@ static struct soc_button_info *soc_butto
}
}
- if (!btns_desc) {
+ if (!btns_desc || !btns_desc->package.count) {
dev_err(dev, "ACPI Button Descriptors not found\n");
button_info = ERR_PTR(-ENODEV);
goto out;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 746/982] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (744 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 745/982] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 747/982] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
` (242 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Raphaël Larocque,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raphaël Larocque <rlarocque@disroot.org>
commit 26eb3d92c7a4d7adb1ae1740ca6e8e100b11d1ec upstream.
The Lenovo ThinkPad T440p (PNP ID LEN0036, board id 2722) has a
Synaptics touchpad whose SMBus companion is not ready at boot and
takes roughly 200 seconds to appear. During this window the touchpad
and TrackPoint are completely unresponsive on approximately 50% of
boots, making the machine unusable until the companion finally
registers.
The device is in the topbuttonpad_pnp_ids[] SMBus allowlist, so the
kernel attempts to use SMBus/RMI4 mode by default. When the companion
is not ready, psmouse_smbus_init() leaves breadcrumbs and returns
-EAGAIN, the PS/2 fallback path is taken, but the device does not
function properly until the companion appears and RMI4 takes over.
Disable SMBus InterTouch for board id 2722 so the touchpad and
TrackPoint work immediately via PS/2 from boot. Users can still force
SMBus with psmouse.synaptics_intertouch=1 if needed.
Tested-by: Raphaël Larocque <rlarocque@disroot.org>
Signed-off-by: Raphaël Larocque <rlarocque@disroot.org>
Link: https://patch.msgid.link/20260910164425.12832-1-rlarocque@disroot.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/mouse/synaptics.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/input/mouse/synaptics.c
+++ b/drivers/input/mouse/synaptics.c
@@ -1809,6 +1809,14 @@ static int synaptics_setup_intertouch(st
return -ENXIO;
}
+
+ /* Disable intertouch on known-broken board revisions */
+ if (info->board_id == 2722) {
+ psmouse_info(psmouse,
+ "Disabling intertouch for board id %u\n",
+ info->board_id);
+ return -ENXIO;
+ }
}
psmouse_info(psmouse, "Trying to set up SMBus access\n");
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 747/982] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (745 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 746/982] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 748/982] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
` (241 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+09103639e39c989e3ed3,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
commit fe10579b6dc3f0dac61e51e1797cacbba5039ac2 upstream.
Transport drivers (such as rmi_i2c and rmi_spi) invoke
rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev
device during system power management events. However, transport drivers
are fully registered and operational even if the physical RMI driver
failed to bind or probe the rmi_dev device.
When rmi_driver_suspend() or rmi_driver_resume() is called on an unbound
rmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or
rmi_enable_irq() without driver data attached causes a NULL pointer
dereference and General Protection Fault when attempting to lock
data->enabled_mutex.
Fix this by checking if driver data is attached to rmi_dev in
rmi_driver_suspend() and rmi_driver_resume(), exiting early if
no driver data is present.
Fixes: 2b6a321da9a2 ("Input: synaptics-rmi4 - add support for Synaptics RMI4 devices")
Reported-by: syzbot+09103639e39c989e3ed3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=09103639e39c989e3ed3
Cc: stable@vger.kernel.org
Assisted-by: LLM
Link: https://patch.msgid.link/anQe8UiyUR4x0flD@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/rmi4/rmi_driver.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
--- a/drivers/input/rmi4/rmi_driver.c
+++ b/drivers/input/rmi4/rmi_driver.c
@@ -946,6 +946,15 @@ int rmi_driver_suspend(struct rmi_device
{
int retval;
+ /*
+ * Transport driver will try to suspend RMI device even if physical
+ * driver did not bind to the RMI device, because transport device
+ * (I2C, SPI) is fully registered and operational. Exit early if
+ * there is no driver data attached to the RMI device.
+ */
+ if (!dev_get_drvdata(&rmi_dev->dev))
+ return 0;
+
retval = rmi_suspend_functions(rmi_dev);
if (retval)
dev_warn(&rmi_dev->dev, "Failed to suspend functions: %d\n",
@@ -960,6 +969,10 @@ int rmi_driver_resume(struct rmi_device
{
int retval;
+ /* Skip if not fully bound to RMI driver */
+ if (!dev_get_drvdata(&rmi_dev->dev))
+ return 0;
+
rmi_enable_irq(rmi_dev, clear_wake);
retval = rmi_resume_functions(rmi_dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 748/982] Input: zero ff_effect before compat copy in input_ff_effect_from_user
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (746 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 747/982] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 749/982] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
` (240 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Dmitry Torokhov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit f84819ef8d66931ee3998fee3c4f03230f4cb6cc upstream.
In the compat path input_ff_effect_from_user() aliases the caller's
native struct ff_effect with the smaller struct ff_effect_compat and
copies only the compat sized prefix:
compat_effect = (struct ff_effect_compat *)effect;
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
The tail of the native structure is never written. Callers pass an
uninitialized on-stack object, for example evdev_do_ioctl() for
EVIOCSFF, so those bytes keep their previous stack contents.
input_ff_upload() then stores the full native structure in
ff->effects[id], from where a uinput based force feedback daemon can
read it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to
userspace.
Zero the effect before the compat copy.
Fixes: 2d56f3a32c0e ("Input: refactor evdev 32bit compat to be shareable with uinput")
Cc: stable@vger.kernel.org
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Link: https://patch.msgid.link/20260901130629.24078-3-ivanrwcm25@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/input-compat.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/input/input-compat.c
+++ b/drivers/input/input-compat.c
@@ -75,6 +75,8 @@ int input_ff_effect_from_user(const char
*/
compat_effect = (struct ff_effect_compat *)effect;
+ memset(effect, 0, sizeof(*effect));
+
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
return -EFAULT;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 749/982] hwmon: (pmbus/core) increase number of phases and add new mask
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (747 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 748/982] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 750/982] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
` (239 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nuno Sá, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nuno Sá <nuno.sa@analog.com>
commit 06bd6794b5fd2163880ac3bfe973d4cc61f359f3 upstream.
Increase the number of phases to 16 as a new upcoming device supports
such a number.
While at it, add a new mask for controlling the source of the output
voltage.
Note (groeck):
This patch was meant to prepare for support of MAX20826 and compatible
devices, which support more than 10 phases per page. However, Sashiko
reports that the mp2975 driver already supports up to 14 phases, and the
mp2856 driver supports up to 12 phases. This already has the potential for
out-of-bounds writes when probing the affected chips, making this patch a
bug fix.
Fixes: 2c6fcbb21149 ("hwmon: (pmbus) Add support for MPS Multi-phase mp2975 controller")
Fixes: f9e5f289b686 ("hwmon: (pmbus) Add support for MPS Multi-phase mp2856/mp2857 controller")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260911-hwmon-max20826-support-v2-1-5e30cbd97d84@analog.com
Cc: stable@vger.kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/pmbus.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/pmbus.h
+++ b/drivers/hwmon/pmbus/pmbus.h
@@ -241,6 +241,7 @@ enum pmbus_regs {
/*
* OPERATION
*/
+#define PB_OPERATION_CONTROL_V_SRC GENMASK(5, 4)
#define PB_OPERATION_CONTROL_ON BIT(7)
/*
@@ -376,7 +377,7 @@ enum pmbus_sensor_classes {
};
#define PMBUS_PAGES 32 /* Per PMBus specification */
-#define PMBUS_PHASES 10 /* Maximum number of phases per page */
+#define PMBUS_PHASES 16 /* Maximum number of phases per page */
/* Functionality bit mask */
#define PMBUS_HAVE_VIN BIT(0)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 750/982] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (748 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 749/982] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 751/982] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
` (238 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sanman Pradhan, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanman Pradhan <psanman@juniper.net>
commit 1d12fb94ac0975566545871dda100df34df5f845 upstream.
tps53676_identify() reads the USER_DATA_03 phase configuration to count
the phases assigned to each channel and derive the number of PMBus pages.
In each 16-bit phase descriptor the channel (PAGE) is encoded in bit 4 and
the firing order in bits 3:0, but the code tested bit 3 (0x08), which is
part of the firing-order field.
TPS53676 supports up to seven phases, so firing-order bit 3 is never set.
As a result the existing test classifies every enabled phase as channel A.
On a dual-channel configuration the phases assigned to channel B are
therefore miscounted as channel A and page 1 is not exposed.
Test the PAGE field (bit 4) instead.
Fixes: cb3d37b59012 ("hwmon: (pmbus/tps53679) Add support for TI TPS53676")
Cc: stable@vger.kernel.org
Signed-off-by: Sanman Pradhan <psanman@juniper.net>
Link: https://patch.msgid.link/20260915164823.160977-2-sanman.pradhan@hpe.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/tps53679.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/tps53679.c
+++ b/drivers/hwmon/pmbus/tps53679.c
@@ -168,7 +168,7 @@ static int tps53676_identify(struct i2c_
return -EIO;
for (i = 0; i < 2 * TPS53676_MAX_PHASES; i += 2) {
if (buf[i + 1] & 0x80) {
- if (buf[i] & 0x08)
+ if (buf[i] & BIT(4))
phases_b++;
else
phases_a++;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 751/982] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (749 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 750/982] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 752/982] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
` (237 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sanman Pradhan, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanman Pradhan <psanman@juniper.net>
commit 089070b51ccbac411462a30a454690274c6e4270 upstream.
tps53676_identify() derives the number of PMBus pages but does not
ensure that page 0 is selected for single-page configurations.
pmbus_set_page() does not update the PAGE register when info->pages is
1, so if boot firmware leaves PAGE set to another value subsequent
register accesses may target the wrong page.
For single-page devices, select page 0 explicitly.
Fixes: cb3d37b59012 ("hwmon: (pmbus/tps53679) Add support for TI TPS53676")
Cc: stable@vger.kernel.org
Signed-off-by: Sanman Pradhan <psanman@juniper.net>
Link: https://patch.msgid.link/20260916235406.681131-2-sanman.pradhan@hpe.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/tps53679.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/hwmon/pmbus/tps53679.c
+++ b/drivers/hwmon/pmbus/tps53679.c
@@ -181,6 +181,15 @@ static int tps53676_identify(struct i2c_
if (phases_b > 0) {
info->pages = 2;
info->phases[1] = phases_b;
+ } else {
+ /*
+ * pmbus_set_page() does not update the PAGE register on
+ * single-page devices, so select page 0 explicitly in case
+ * the boot firmware left the device on another page.
+ */
+ ret = i2c_smbus_write_byte_data(client, PMBUS_PAGE, 0);
+ if (ret < 0)
+ return ret;
}
return 0;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 752/982] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (750 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 751/982] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 753/982] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
` (236 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8 upstream.
When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe()
creates the w83791d_group_fanpwm45 sysfs group on the I2C client
device.
The probe error path removes this group when a later initialization
step fails, but the normal remove path only removes w83791d_group.
As a result, the optional fan/pwm 4-5 sysfs files can remain after the
driver is unbound.
The callbacks associated with these files access the driver data,
which is devm allocated and released after driver unbind. Leaving the
sysfs files behind can therefore result in accesses to stale driver
data.
Remove w83791d_group_fanpwm45 during normal teardown as well.
This issue was found by manual code inspection.
Fixes: 6e1ecd9b8f13 ("hwmon: (w83791d) fan 4/5 pins can also be used for gpio")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260914062809.1650538-1-lgs201920130244@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/w83791d.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/hwmon/w83791d.c
+++ b/drivers/hwmon/w83791d.c
@@ -1415,6 +1415,7 @@ static void w83791d_remove(struct i2c_cl
struct w83791d_data *data = i2c_get_clientdata(client);
hwmon_device_unregister(data->hwmon_dev);
+ sysfs_remove_group(&client->dev.kobj, &w83791d_group_fanpwm45);
sysfs_remove_group(&client->dev.kobj, &w83791d_group);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 753/982] hwmon: (w83793) release probe data through kref
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (751 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 752/982] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 754/982] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
` (235 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit c702a5f18b780e477eccbbab558e590e9673e4cb upstream.
w83793_probe() initializes data->kref to manage the lifetime of the
driver data. The normal remove path drops the driver-owned reference
with kref_put(), while watchdog users take and release additional
references through the same kref.
However, the probe error path still frees data directly with kfree().
This bypasses the kref-managed lifetime and discards the initial
reference without a matching kref_put(), leaving the reference
accounting unbalanced.
Drop the probe-owned reference with kref_put() instead and let
w83793_release_resources() perform the final free, matching the normal
remove path.
This issue was found by manual code inspection.
Fixes: 5852f9609d21 ("hwmon: (w83793) Add watchdog functionality")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260914073638.1662500-1-lgs201920130244@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/w83793.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/w83793.c
+++ b/drivers/hwmon/w83793.c
@@ -1929,7 +1929,9 @@ exit_remove:
for (i = 0; i < ARRAY_SIZE(w83793_temp); i++)
device_remove_file(dev, &w83793_temp[i].dev_attr);
free_mem:
- kfree(data);
+ mutex_lock(&watchdog_data_mutex);
+ kref_put(&data->kref, w83793_release_resources);
+ mutex_unlock(&watchdog_data_mutex);
exit:
return err;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 754/982] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (752 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 753/982] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 755/982] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
` (234 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Li Jun, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Jun <lijun01@kylinos.cn>
commit 7cb575b71ab98194d2e040bded3a7281e089c5ed upstream.
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.
Fixes: a7ceca4398bc8 ("watchdog: da9063: optionally disable watchdog during suspend")
Cc: stable@vger.kernel.org
Signed-off-by: Li Jun <lijun01@kylinos.cn>
Link: https://patch.msgid.link/20260917013710.2754679-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/da9063_wdt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/watchdog/da9063_wdt.c
+++ b/drivers/watchdog/da9063_wdt.c
@@ -262,7 +262,7 @@ static int __maybe_unused da9063_wdt_sus
if (!use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9063_wdt_stop(wdd);
return 0;
@@ -275,7 +275,7 @@ static int __maybe_unused da9063_wdt_res
if (!use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9063_wdt_start(wdd);
return 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 755/982] watchdog: digicolor: Avoid division by zero
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (753 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 754/982] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 756/982] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
` (233 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Baruch Siach,
Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 400cb663ca019bae6eb878f06f1094ddf7c0b0df upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Since get_timeleft() cannot propagate errors, check the clock rate early
in probe() and cache the rate in the driver data as it is unlikely to
change at runtime.
Fixes: 336694a01dae ("watchdog: digicolor: driver for Conexant Digicolor CX92755 SoC")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Acked-by: Baruch Siach <baruch@tkos.co.il>
Link: https://patch.msgid.link/20260913064851.8239-2-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/digicolor_wdt.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/drivers/watchdog/digicolor_wdt.c
+++ b/drivers/watchdog/digicolor_wdt.c
@@ -25,6 +25,7 @@ struct dc_wdt {
void __iomem *base;
struct clk *clk;
spinlock_t lock;
+ unsigned long rate;
};
static unsigned timeout;
@@ -61,7 +62,7 @@ static int dc_wdt_start(struct watchdog_
{
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
- dc_wdt_set(wdt, wdog->timeout * clk_get_rate(wdt->clk));
+ dc_wdt_set(wdt, wdog->timeout * wdt->rate);
return 0;
}
@@ -79,7 +80,7 @@ static int dc_wdt_set_timeout(struct wat
{
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
- dc_wdt_set(wdt, t * clk_get_rate(wdt->clk));
+ dc_wdt_set(wdt, t * wdt->rate);
wdog->timeout = t;
return 0;
@@ -90,7 +91,7 @@ static unsigned int dc_wdt_get_timeleft(
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
uint32_t count = readl_relaxed(wdt->base + TIMER_A_COUNT);
- return count / clk_get_rate(wdt->clk);
+ return count / wdt->rate;
}
static const struct watchdog_ops dc_wdt_ops = {
@@ -130,7 +131,11 @@ static int dc_wdt_probe(struct platform_
wdt->clk = devm_clk_get(dev, NULL);
if (IS_ERR(wdt->clk))
return PTR_ERR(wdt->clk);
- dc_wdt_wdd.max_timeout = U32_MAX / clk_get_rate(wdt->clk);
+
+ wdt->rate = clk_get_rate(wdt->clk);
+ if (!wdt->rate)
+ return -EINVAL;
+ dc_wdt_wdd.max_timeout = U32_MAX / wdt->rate;
dc_wdt_wdd.timeout = dc_wdt_wdd.max_timeout;
dc_wdt_wdd.parent = dev;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 756/982] watchdog: msc313e: Fix premature reset during timeout update
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (754 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 755/982] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 757/982] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
` (232 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 22737cfced627ffcb4b5c36d63bb3d4476f63213 upstream.
Updating the 32-bit hardware timeout requires writing to two 16-bit
registers sequentially. If the watchdog is actively running, this
non-atomic update might trigger a premature system reset.
Clear the watchdog counter before updating the registers to prevent the
timer from timing out prematurely against an intermediate threshold.
Fixes: e9800b799464 ("watchdog: Add Mstar MSC313e WDT driver")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913065126.8350-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/msc313e_wdt.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -47,6 +47,9 @@ static void msc313e_wdt_set_hw_timeout(s
{
u32 t = timeout * clk_get_rate(priv->clk);
+ /* Clear before to prevent premature reset during non-atomic updates. */
+ writew(1, priv->base + REG_WDT_CLR);
+
writew(t & 0xffff, priv->base + REG_WDT_MAX_PRD_L);
writew((t >> 16) & 0xffff, priv->base + REG_WDT_MAX_PRD_H);
writew(1, priv->base + REG_WDT_CLR);
@@ -77,6 +80,9 @@ static int msc313e_wdt_stop(struct watch
{
struct msc313e_wdt_priv *priv = watchdog_get_drvdata(wdev);
+ /* Clear before to prevent premature reset during non-atomic updates. */
+ writew(1, priv->base + REG_WDT_CLR);
+
writew(0, priv->base + REG_WDT_MAX_PRD_L);
writew(0, priv->base + REG_WDT_MAX_PRD_H);
writew(0, priv->base + REG_WDT_CLR);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 757/982] watchdog: msc313e: Propagate error code in resume()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (755 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 756/982] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 758/982] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
` (231 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 1d9763f34a85680db1e8233d654fdb85e5f897cc upstream.
If msc313e_wdt_start() fails during system resume, the error is
currently ignored. Consequently, the watchdog isn't running without the
user's knowledge.
Propagate the error code and print a message if msc313e_wdt_start()
fails.
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Fixes: e9800b7994642 ("watchdog: Add Mstar MSC313e WDT driver")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260912163334.28636-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/msc313e_wdt.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -198,11 +198,15 @@ static int __maybe_unused msc313e_wdt_su
static int __maybe_unused msc313e_wdt_resume(struct device *dev)
{
struct msc313e_wdt_priv *priv = dev_get_drvdata(dev);
+ int ret = 0;
- if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev))
- msc313e_wdt_start(&priv->wdev);
+ if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev)) {
+ ret = msc313e_wdt_start(&priv->wdev);
+ if (ret)
+ dev_err(dev, "Failed to restart watchdog (err=%d)\n", ret);
+ }
- return 0;
+ return ret;
}
static SIMPLE_DEV_PM_OPS(msc313e_wdt_pm_ops, msc313e_wdt_suspend, msc313e_wdt_resume);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 758/982] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (756 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 757/982] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 759/982] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
` (230 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Guenter Roeck
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 88f113634028ca90a857031837d8061d1a9e1a7b upstream.
sp5100_tco_init() stores the PCI device matched by for_each_pci_dev()
in the global sp5100_tco_pci and keeps its reference for the lifetime
of the driver, but neither sp5100_tco_exit() nor the error paths of
sp5100_tco_init() call pci_dev_put(), leaking the reference on driver
registration failure and on every module load/unload cycle.
Drop the reference when the platform driver or device registration
fails and when the module is unloaded.
Fixes: 15e28bf13008 ("watchdog: Add support for sp5100 chipset TCO")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260916170511.2086199-1-vulab@iscas.ac.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/sp5100_tco.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/sp5100_tco.c
+++ b/drivers/watchdog/sp5100_tco.c
@@ -605,8 +605,10 @@ static int __init sp5100_tco_init(void)
pr_info("SP5100/SB800 TCO WatchDog Timer Driver\n");
err = platform_driver_register(&sp5100_tco_driver);
- if (err)
+ if (err) {
+ pci_dev_put(sp5100_tco_pci);
return err;
+ }
sp5100_tco_platform_device =
platform_device_register_simple(TCO_DRIVER_NAME, -1, NULL, 0);
@@ -619,6 +621,7 @@ static int __init sp5100_tco_init(void)
unreg_platform_driver:
platform_driver_unregister(&sp5100_tco_driver);
+ pci_dev_put(sp5100_tco_pci);
return err;
}
@@ -626,6 +629,7 @@ static void __exit sp5100_tco_exit(void)
{
platform_device_unregister(sp5100_tco_platform_device);
platform_driver_unregister(&sp5100_tco_driver);
+ pci_dev_put(sp5100_tco_pci);
}
module_init(sp5100_tco_init);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 759/982] wifi: brcmsmac: fix UAF in brcms_free_timer()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (757 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 758/982] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 760/982] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
` (229 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Arend van Spriel,
Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit 1eeca1d5e0920fbdad6449768fd2d4364e714180 upstream.
brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
cancel_delayed_work() to cancel the timer's underlying delayed work. If
the work callback (_brcms_timer) is already running, cancel_delayed_work()
returns false without waiting, and brcms_free_timer() proceeds to kfree(t)
while the callback still accesses t through container_of().
Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.
Fixes: 5b435de0d786 ("net: wireless: add brcm80211 drivers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260815121043.938414-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c
@@ -1568,6 +1568,10 @@ void brcms_free_timer(struct brcms_timer
/* delete the timer in case it is active */
brcms_del_timer(t);
+ /* Ensure the callback has finished before freeing the timer
+ * structure, since brcms_del_timer() uses non-synchronous cancel.
+ */
+ cancel_delayed_work_sync(&t->dly_wrk);
if (wl->timers == t) {
wl->timers = wl->timers->next;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 760/982] wifi: iwlegacy: fix broadcast stations deallocation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (758 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 759/982] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 761/982] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
` (228 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislaw Gruszka, Johannes Berg,
Martin-Éric Racine
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <stf_xl@wp.pl>
commit b5526b780f8b297a76030410b96ba29153afb98f upstream.
On the error path of __il4965_up(), il_dealloc_bcast_stations() clears
only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the
same broadcast stations to be deallocated again by __il4965_down().
This can occur when RF_KILL is toggled during driver startup.
To fix clear the entire 'used' field, since we will not do any
other operations on the station.
Reported-and-tested-by: Martin-Éric Racine <martin-eric.racine+kernel-bugzilla@iki.fi>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221733
Fixes: c2fd34469d16 ("iwl4965: Fix a memory leak in error handling code of __il4965_up")
Cc: <stable@vger.kernel.org> # 7.1.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Cc: <stable@vger.kernel.org> # 6.x.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Cc: <stable@vger.kernel.org> # 5.x.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Signed-off-by: Stanislaw Gruszka <stf_xl@wp.pl>
Link: https://patch.msgid.link/20260820093059.18779-1-stf_xl@wp.pl
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/iwlegacy/common.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/intel/iwlegacy/common.c
+++ b/drivers/net/wireless/intel/iwlegacy/common.c
@@ -2324,7 +2324,7 @@ il_dealloc_bcast_stations(struct il_priv
if (!(il->stations[i].used & IL_STA_BCAST))
continue;
- il->stations[i].used &= ~IL_STA_UCODE_ACTIVE;
+ il->stations[i].used = 0;
il->num_stations--;
BUG_ON(il->num_stations < 0);
kfree(il->stations[i].lq);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 761/982] wifi: libertas_tf: fix UAF in lbtf_free_adapter()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (759 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 760/982] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 762/982] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
` (227 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit bbb9a0ab96d44a64529aafc7a16de460a1712f6a upstream.
lbtf_free_adapter() calls lbtf_free_cmd_buffer() to free the command
buffers before calling timer_delete_sync() to wait for the command
timer callback. If the timer callback (command_timer_fn) is already
running when lbtf_free_cmd_buffer() frees the command array, the
callback dereferences priv->cur_cmd->cmdbuf which points to freed
memory.
Swap the order so that timer_delete_sync() runs first, ensuring any
in-flight callback has completed before the command buffers are freed.
Fixes: 06b16ae53192 ("libertas_tf: main.c, data paths and mac80211 handlers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Link: https://patch.msgid.link/20260815115724.920628-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/libertas_tf/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/marvell/libertas_tf/main.c
+++ b/drivers/net/wireless/marvell/libertas_tf/main.c
@@ -173,8 +173,8 @@ static int lbtf_init_adapter(struct lbtf
static void lbtf_free_adapter(struct lbtf_private *priv)
{
lbtf_deb_enter(LBTF_DEB_MAIN);
- lbtf_free_cmd_buffer(priv);
timer_delete_sync(&priv->command_timer);
+ lbtf_free_cmd_buffer(priv);
lbtf_deb_leave(LBTF_DEB_MAIN);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 762/982] wifi: rsi: fix heap OOB write on key removal
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (760 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 761/982] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.1 763/982] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
` (226 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit e6c5ed7a98d7bc8b0f7918246f1c90ddb3f79dfa upstream.
When a key is removed (data == NULL), rsi_hal_load_key() runs:
memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
set_key is a struct rsi_set_key *, so the subscript is scaled by
sizeof(struct rsi_set_key) (160 bytes): &set_key[FRAME_DESC_SZ] is
skb->data + 2560, and the memset writes 144 zero bytes starting
2.4KB past the end of the 160-byte skb data buffer, corrupting
unrelated heap objects. The intended byte offset would have been
(u8 *)set_key + FRAME_DESC_SZ.
The write fires on every DISABLE_KEY callback, so plain disconnects,
roams and interface teardowns trigger it on real networks.
The memset is redundant: the whole buffer is zeroed right after
allocation, so the frame sent to the device is byte-identical
without it. Drop the else branch; normal operation is unaffected.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: dad0d04fa7ba ("rsi: Add RS9113 wireless driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/90bb2b07007942064c04aa3729cedd9eb1e930b1@linux.dev
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 --
1 file changed, 2 deletions(-)
--- a/drivers/net/wireless/rsi/rsi_91x_mgmt.c
+++ b/drivers/net/wireless/rsi/rsi_91x_mgmt.c
@@ -852,8 +852,6 @@ int rsi_hal_load_key(struct rsi_common *
memcpy(set_key->tx_mic_key, &data[16], 8);
memcpy(set_key->rx_mic_key, &data[24], 8);
}
- } else {
- memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
}
skb_put(skb, frame_len);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 763/982] wifi: wlcore: release runtime PM ref on regdomain config failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (761 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 762/982] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 764/982] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
` (225 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 8a1f3cf89ddcc700e25afe42cfad333059adcc94 upstream.
wlcore_regdomain_config() gets a runtime PM reference before sending
the regulatory-domain command. When
wlcore_cmd_regdomain_config_locked() fails, the function queues recovery
and returns without dropping that reference.
Release the reference after handling the command result so both success
and failure paths balance the preceding
pm_runtime_resume_and_get(). The recovery worker takes a separate
runtime PM reference and cannot release the reference held here.
Fixes: fa2648a34e73 ("wlcore: Add support for runtime PM")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260820125126.12757-1-runyu.xiao@seu.edu.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/ti/wlcore/main.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/drivers/net/wireless/ti/wlcore/main.c
+++ b/drivers/net/wireless/ti/wlcore/main.c
@@ -3635,10 +3635,8 @@ void wlcore_regdomain_config(struct wl12
goto out;
ret = wlcore_cmd_regdomain_config_locked(wl);
- if (ret < 0) {
+ if (ret < 0)
wl12xx_queue_recovery_work(wl);
- goto out;
- }
pm_runtime_mark_last_busy(wl->dev);
pm_runtime_put_autosuspend(wl->dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 764/982] wifi: wilc1000: fix out-of-bounds read in P2P public action frames
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (762 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 6.1 763/982] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 765/982] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
` (224 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ali Ahmet Memis, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Ahmet Memis <ali@iusegentoo.com>
commit ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14 upstream.
wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
ieee80211_is_public_action() returns true. That helper only verifies the
frame is long enough for the action category field, that is
offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both
functions then read the P2P public action header up to oui_subtype at
offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where
ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.
A public action frame of 25 to 31 bytes passes the check but is shorter
than that 32 byte header, so oui_subtype can be read out of bounds, and
because the length is unsigned, "size - ie_offset" underflows to a value
close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length,
so even the size_t subtraction in mgmt_tx() is truncated to the same
value. It then walks far past the buffer searching for a vendor element
until it reaches unmapped memory.
In the receive path the frame arrives over the air and needs no
association, so a nearby unauthenticated device can crash the host while
it is in P2P listen. Reject frames shorter than the P2P public action
header in both paths before dereferencing it.
Fixes: 4fb8b5aa2a11 ("staging: wilc1000: refactor p2p action frames handling API's")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Link: https://patch.msgid.link/20260807115230.136767-1-ali@iusegentoo.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/microchip/wilc1000/cfg80211.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
--- a/drivers/net/wireless/microchip/wilc1000/cfg80211.c
+++ b/drivers/net/wireless/microchip/wilc1000/cfg80211.c
@@ -1069,6 +1069,13 @@ void wilc_wfi_p2p_rx(struct wilc_vif *vi
if (!ieee80211_is_public_action((struct ieee80211_hdr *)buff, size))
goto out_rx_mgmt;
+ /* ieee80211_is_public_action() only validates up to the category
+ * byte, so reject frames too short for the P2P public action header
+ * before dereferencing it or computing size - ie_offset.
+ */
+ if (size < ie_offset)
+ goto out_rx_mgmt;
+
d = (struct wilc_p2p_pub_act_frame *)(&mgmt->u.action);
if (d->oui_subtype != GO_NEG_REQ && d->oui_subtype != GO_NEG_RSP &&
d->oui_subtype != P2P_INV_REQ && d->oui_subtype != P2P_INV_RSP)
@@ -1219,6 +1226,13 @@ static int mgmt_tx(struct wiphy *wiphy,
goto out_set_timeout;
}
+ /* ieee80211_is_public_action() only validates up to the category
+ * byte, so reject frames too short for the P2P public action header
+ * before dereferencing it or computing len - ie_offset.
+ */
+ if (len < ie_offset)
+ goto out_set_timeout;
+
d = (struct wilc_p2p_pub_act_frame *)(&mgmt->u.action);
if (d->oui_type != WLAN_OUI_TYPE_WFA_P2P ||
d->oui_subtype != GO_NEG_CONF) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 765/982] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (763 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 764/982] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 766/982] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
` (223 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit c1ba7f7f18465e259cf1b4d9c73fc73853d7f790 upstream.
wilc_wlan_handle_isr_ext() takes the RX transfer size from the
device-reported interrupt status register (a 15-bit field shifted left by 2,
up to 131068 bytes) and reads that many bytes from the device into
rx_buffer, which is only WILC_RX_BUFF_SIZE (96K) large. The wrap
check only handles the current offset; the size itself is never
compared against the buffer, so a bogus SDIO device can make the driver
OOB-write rx_buffer by up to ~32K with data it controls.
The oversized transfer also leaves rx_buffer_offset past the end of
the buffer, after which the unsigned wrap check stops working and
the overflow can repeat.
Drop any transfer whose size exceeds the RX buffer, acknowledging
the data interrupt and re-arming the RX engine so the bogus frame is
discarded and reception can continue. This also restores the
rx_buffer_offset <= WILC_RX_BUFF_SIZE invariant the wrap check
relies on.
This is not expected to change driver behavior in most cases:
without this check, an oversized transfer would most likely
corrupt neighboring kernel memory instead of completing anyway, and
the drop path performs the same interrupt acknowledgment and RX
engine re-arming as the normal path, so subsequent transfers are
received unaffected.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: c5c77ba18ea6 ("staging: wilc1000: Add SDIO/SPI 802.11 driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/7c971924c6bdccf6c2f75704a5a746e9303aaf64@linux.dev
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/microchip/wilc1000/wlan.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/net/wireless/microchip/wilc1000/wlan.c
+++ b/drivers/net/wireless/microchip/wilc1000/wlan.c
@@ -1040,6 +1040,15 @@ static void wilc_wlan_handle_isr_ext(str
if (size <= 0)
return;
+ /* A size exceeding the RX buffer is bogus; drop the transfer
+ * instead of overflowing the buffer.
+ */
+ if (size > WILC_RX_BUFF_SIZE) {
+ wilc->hif_func->hif_clear_int_ext(wilc,
+ DATA_INT_CLR | ENABLE_RX_VMM);
+ return;
+ }
+
if (WILC_RX_BUFF_SIZE - offset < size)
offset = 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 766/982] wifi: p54: validate curve data length in the calibration curve converters
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (764 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 765/982] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 767/982] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
` (222 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit ce858fa6b8a214dee5adb82358885fa024cdd887 upstream.
p54_convert_rev0() and p54_convert_rev1() read calibration curve
data from the device-supplied EEPROM entry using channel and
points-per-channel counts taken verbatim from that same entry, so
an entry that declares more data than it carries drives an
out-of-bounds read past the EEPROM buffer (verified with a KASAN
reproducer of the conversion loop). The sibling converters
p54_convert_output_limits() and p54_convert_db() already validate
their counts against the entry length; this path was missed.
Reject the entry when the counts do not fit in the entry data.
Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-1-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intersil/p54/eeprom.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
--- a/drivers/net/wireless/intersil/p54/eeprom.c
+++ b/drivers/net/wireless/intersil/p54/eeprom.c
@@ -418,17 +418,22 @@ free:
}
static int p54_convert_rev0(struct ieee80211_hw *dev,
- struct pda_pa_curve_data *curve_data)
+ struct pda_pa_curve_data *curve_data, size_t len)
{
struct p54_common *priv = dev->priv;
struct p54_pa_curve_data_sample *dst;
struct pda_pa_curve_data_sample_rev0 *src;
+ size_t needed = curve_data->channels *
+ (sizeof(*src) * curve_data->points_per_channel + 2);
size_t cd_len = sizeof(*curve_data) +
(curve_data->points_per_channel*sizeof(*dst) + 2) *
curve_data->channels;
unsigned int i, j;
void *source, *target;
+ if (len < sizeof(*curve_data) + needed)
+ return -EINVAL;
+
priv->curve_data = kmalloc(sizeof(*priv->curve_data) + cd_len,
GFP_KERNEL);
if (!priv->curve_data)
@@ -470,17 +475,22 @@ static int p54_convert_rev0(struct ieee8
}
static int p54_convert_rev1(struct ieee80211_hw *dev,
- struct pda_pa_curve_data *curve_data)
+ struct pda_pa_curve_data *curve_data, size_t len)
{
struct p54_common *priv = dev->priv;
struct p54_pa_curve_data_sample *dst;
struct pda_pa_curve_data_sample_rev1 *src;
+ size_t needed = curve_data->channels *
+ (sizeof(*src) * curve_data->points_per_channel + 3);
size_t cd_len = sizeof(*curve_data) +
(curve_data->points_per_channel*sizeof(*dst) + 2) *
curve_data->channels;
unsigned int i, j;
void *source, *target;
+ if (len < sizeof(*curve_data) + needed)
+ return -EINVAL;
+
priv->curve_data = kzalloc(cd_len + sizeof(*priv->curve_data),
GFP_KERNEL);
if (!priv->curve_data)
@@ -767,6 +777,7 @@ int p54_parse_eeprom(struct ieee80211_hw
case PDR_PRISM_PA_CAL_CURVE_DATA: {
struct pda_pa_curve_data *curve_data =
(struct pda_pa_curve_data *)entry->data;
+
if (data_len < sizeof(*curve_data)) {
err = -EINVAL;
goto err;
@@ -774,10 +785,10 @@ int p54_parse_eeprom(struct ieee80211_hw
switch (curve_data->cal_method_rev) {
case 0:
- err = p54_convert_rev0(dev, curve_data);
+ err = p54_convert_rev0(dev, curve_data, data_len);
break;
case 1:
- err = p54_convert_rev1(dev, curve_data);
+ err = p54_convert_rev1(dev, curve_data, data_len);
break;
default:
wiphy_err(dev->wiphy,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 767/982] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (765 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 766/982] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 768/982] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
` (221 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lamparter, Shengzhuo Wei,
Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit d8efd84f49379ed28624098821f80e992657d935 upstream.
The PDR_INTERFACE_LIST loop only checks that the record start is within
the entry before reading an entire struct exp_if from it. A truncated
trailing record makes the if_id/variant reads cross the entry boundary
into the heap beyond the EEPROM buffer (verified with a KASAN
reproducer of the loop). The variant also feeds the synth front-end
selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Acked-by: Christian Lamparter <chunkeey@gmail.com>
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-2-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intersil/p54/eeprom.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/net/wireless/intersil/p54/eeprom.c
+++ b/drivers/net/wireless/intersil/p54/eeprom.c
@@ -816,7 +816,8 @@ int p54_parse_eeprom(struct ieee80211_hw
break;
case PDR_INTERFACE_LIST:
tmp = entry->data;
- while ((u8 *)tmp < entry->data + data_len) {
+ while ((u8 *)tmp + sizeof(struct exp_if) <=
+ entry->data + data_len) {
struct exp_if *exp_if = tmp;
if (exp_if->if_id == cpu_to_le16(IF_ID_ISL39000))
synth = le16_to_cpu(exp_if->variant);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 768/982] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (766 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 767/982] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 769/982] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
` (220 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Doruk Tan Ozturk, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doruk Tan Ozturk <doruk@0sec.ai>
commit e667aee1c192d67d27c803007bfa9c6e0873e959 upstream.
mwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a
beacon/probe-response RSN or WPA information element and then walks that
many 4-byte OUIs, comparing each with memcmp(). The count comes straight
from the (attacker-supplied) IE and is never checked against the
element's own length, and the callers admit the element on element_id
alone (has_ieee_hdr() / has_vendor_hdr(), no length check). A crafted
RSN/WPA IE with a large pairwise count therefore makes the walk read up
to 255 * 4 bytes past the element -- an out-of-bounds read of the
kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe
response is processed during scan-result parsing.
Pass the number of IE bytes available at the OUI list and bound the walk
to the element. Keep the length signed and reject a negative value
before any unsigned arithmetic, so a small or zero IE length cannot
underflow to a large size_t and defeat the bound.
Found by 0sec automated security-research tooling (https://0sec.ai).
Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:multi-model
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Link: https://patch.msgid.link/20260814134704.85902-1-doruk@0sec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/scan.c | 25 ++++++++++++++++++++++---
1 file changed, 22 insertions(+), 3 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/scan.c
+++ b/drivers/net/wireless/marvell/mwifiex/scan.c
@@ -104,12 +104,24 @@ has_vendor_hdr(struct ieee_types_vendor_
* a given oui in PTK.
*/
static u8
-mwifiex_search_oui_in_ie(struct ie_body *iebody, u8 *oui)
+mwifiex_search_oui_in_ie(struct ie_body *iebody, u8 *oui, int ie_len)
{
+ const size_t ptk_body_offset = offsetof(struct ie_body, ptk_body);
u8 count;
+ /* ie_len is the number of bytes available at iebody. Keep it signed
+ * and reject a negative (underflowed) length before the unsigned
+ * comparisons below, so a small or zero IE length cannot wrap.
+ */
+ if (ie_len < 0 || (size_t)ie_len < ptk_body_offset)
+ return MWIFIEX_OUI_NOT_PRESENT;
+
count = iebody->ptk_cnt[0];
+ /* Reject an OUI count whose list would run past the element. */
+ if (ptk_body_offset + count * sizeof(iebody->ptk_body) > (size_t)ie_len)
+ return MWIFIEX_OUI_NOT_PRESENT;
+
/* There could be multiple OUIs for PTK hence
1) Take the length.
2) Check all the OUIs for AES.
@@ -143,11 +155,14 @@ mwifiex_is_rsn_oui_present(struct mwifie
u8 ret = MWIFIEX_OUI_NOT_PRESENT;
if (has_ieee_hdr(bss_desc->bcn_rsn_ie, WLAN_EID_RSN)) {
+ int ie_len = (int)bss_desc->bcn_rsn_ie->ieee_hdr.len -
+ RSN_GTK_OUI_OFFSET;
+
iebody = (struct ie_body *)
(((u8 *) bss_desc->bcn_rsn_ie->data) +
RSN_GTK_OUI_OFFSET);
oui = &mwifiex_rsn_oui[cipher][0];
- ret = mwifiex_search_oui_in_ie(iebody, oui);
+ ret = mwifiex_search_oui_in_ie(iebody, oui, ie_len);
if (ret)
return ret;
}
@@ -169,10 +184,14 @@ mwifiex_is_wpa_oui_present(struct mwifie
u8 ret = MWIFIEX_OUI_NOT_PRESENT;
if (has_vendor_hdr(bss_desc->bcn_wpa_ie, WLAN_EID_VENDOR_SPECIFIC)) {
+ int ie_len = (int)bss_desc->bcn_wpa_ie->vend_hdr.len -
+ (int)sizeof(bss_desc->bcn_wpa_ie->vend_hdr.oui) -
+ WPA_GTK_OUI_OFFSET;
+
iebody = (struct ie_body *)((u8 *)bss_desc->bcn_wpa_ie->data +
WPA_GTK_OUI_OFFSET);
oui = &mwifiex_wpa_oui[cipher][0];
- ret = mwifiex_search_oui_in_ie(iebody, oui);
+ ret = mwifiex_search_oui_in_ie(iebody, oui, ie_len);
if (ret)
return ret;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 769/982] wifi: mwifiex: validate scan response extents
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (767 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 768/982] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 770/982] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
` (219 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 3687d7d48070838cc2953431b3a27717cab0aaf6 upstream.
mwifiex_ret_802_11_scan() subtracts the fixed response fields and the
firmware-provided BSS length from resp->size without first proving that
either extent fits. A short response or oversized BSS length can
therefore underflow tlv_buf_size and make the TLV parser walk beyond the
command response.
Compute the fixed extent from the selected normal or background scan
response. Validate that the fixed fields and BSS data fit before deriving
the TLV extent and entering the parser.
Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260815135227.50392-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/scan.c | 29 ++++++++++++++++++----------
1 file changed, 19 insertions(+), 10 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/scan.c
+++ b/drivers/net/wireless/marvell/mwifiex/scan.c
@@ -2130,6 +2130,7 @@ int mwifiex_ret_802_11_scan(struct mwifi
u32 bytes_left;
u32 idx;
u32 tlv_buf_size;
+ size_t fixed_size;
struct mwifiex_ie_types_chan_band_list_param_set *chan_band_tlv;
struct chan_band_param_set *chan_band;
u8 is_bgscan_resp;
@@ -2145,6 +2146,14 @@ int mwifiex_ret_802_11_scan(struct mwifi
else
scan_rsp = &resp->params.scan_resp;
+ scan_resp_size = le16_to_cpu(resp->size);
+ fixed_size = scan_rsp->bss_desc_and_tlv_buffer - (u8 *)resp;
+ if (scan_resp_size < fixed_size) {
+ mwifiex_dbg(adapter, ERROR,
+ "SCAN_RESP: response is too short\n");
+ ret = -1;
+ goto check_next_scan;
+ }
if (scan_rsp->number_of_sets > MWIFIEX_MAX_AP) {
mwifiex_dbg(adapter, ERROR,
@@ -2162,8 +2171,6 @@ int mwifiex_ret_802_11_scan(struct mwifi
"info: SCAN_RESP: bss_descript_size %d\n",
bytes_left);
- scan_resp_size = le16_to_cpu(resp->size);
-
mwifiex_dbg(adapter, INFO,
"info: SCAN_RESP: returned %d APs before parsing\n",
scan_rsp->number_of_sets);
@@ -2171,15 +2178,17 @@ int mwifiex_ret_802_11_scan(struct mwifi
bss_info = scan_rsp->bss_desc_and_tlv_buffer;
/*
- * The size of the TLV buffer is equal to the entire command response
- * size (scan_resp_size) minus the fixed fields (sizeof()'s), the
- * BSS Descriptions (bss_descript_size as bytesLef) and the command
- * response header (S_DS_GEN)
+ * The TLV buffer follows the command-specific fixed fields and the BSS
+ * descriptions. Background-scan responses have an additional fixed
+ * field before scan_rsp, which is included in fixed_size.
*/
- tlv_buf_size = scan_resp_size - (bytes_left
- + sizeof(scan_rsp->bss_descript_size)
- + sizeof(scan_rsp->number_of_sets)
- + S_DS_GEN);
+ if (bytes_left > scan_resp_size - fixed_size) {
+ mwifiex_dbg(adapter, ERROR,
+ "SCAN_RESP: BSS data exceeds response\n");
+ ret = -1;
+ goto check_next_scan;
+ }
+ tlv_buf_size = scan_resp_size - fixed_size - bytes_left;
tlv_data = (struct mwifiex_ie_types_data *) (scan_rsp->
bss_desc_and_tlv_buffer +
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 770/982] wifi: mwifiex: validate action frame fixed fields
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (768 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 769/982] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 771/982] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
` (218 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Berg, Brian Norris, Zhao Li,
Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
commit 1c25bfad93e69ce13f744a2fb919f02ea396a985 upstream.
mwifiex_process_mgmt_packet() accepts an rx_pkt_length as small as a
four-address struct ieee80211_hdr plus the two-byte firmware length prefix.
After stripping the prefix, mwifiex_parse_mgmt_packet() can receive a
frame equal to sizeof(struct ieee80211_hdr).
For action frames, the parser reads the category byte immediately after
that header and, for a public action frame, reads the following action
code byte without verifying that either field is present. A truncated frame
can therefore make the parser consume up to two bytes past the
firmware-declared frame length. If those bytes look like a TDLS discovery
response, the malformed frame can spuriously update peer signal state.
Require the category and public action-code fields before reading them.
Use sizeof(*ieee_hdr) so the checks and field accesses directly match the
firmware four-address layout being parsed before address4 is removed.
Suggested-by: Johannes Berg <johannes@sipsolutions.net>
Suggested-by: Brian Norris <briannorris@chromium.org>
Fixes: 72e5aa8d2a6d ("mwifiex: support for parsing TDLS discovery frames")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/66f148d83eb9f0970b9abbccc85d1b61244e54ad.camel@sipsolutions.net/
Link: https://lore.kernel.org/all/20260708195911.84365-8-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/20260723011013.76968-1-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/20260723202257.688-1-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/anuWyiPQja6_5vly@google.com/
Assisted-by: Codex:gpt-5
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260825112523.95774-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/util.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/util.c
+++ b/drivers/net/wireless/marvell/mwifiex/util.c
@@ -335,10 +335,16 @@ mwifiex_parse_mgmt_packet(struct mwifiex
switch (stype) {
case IEEE80211_STYPE_ACTION:
- category = *(payload + sizeof(struct ieee80211_hdr));
+ if (len < sizeof(*ieee_hdr) + 1)
+ return -1;
+
+ category = *(payload + sizeof(*ieee_hdr));
switch (category) {
case WLAN_CATEGORY_PUBLIC:
- action_code = *(payload + sizeof(struct ieee80211_hdr)
+ if (len < sizeof(*ieee_hdr) + 2)
+ return -1;
+
+ action_code = *(payload + sizeof(*ieee_hdr)
+ 1);
if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
addr2 = ieee_hdr->addr2;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 771/982] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (769 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 770/982] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 772/982] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
` (217 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+af177aa139efdd13a9da,
Rik van Riel, syzbot+dcaca020ca8377e7ced0, Johannes Berg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rik van Riel <riel@surriel.com>
commit da2ca406f45a6e21760243152ed8d2e8e72915c2 upstream.
ieee80211_set_bitrate_mask() checks if the interface is running via
ieee80211_sdata_running(), but it does not check if the interface is
still present in the driver.
When sdata is running but IEEE80211_SDATA_IN_DRIVER is not set, the
call reaches drv_set_bitrate_mask() in driver-ops.h which hits
wlan1: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.h:884 at drv_set_bitrate_mask
Syzkaller triggers this via wext SIOCSIWRATE ioctl. The Call Trace shows
wext_ioctl_dispatch() in wext-core.c dispatching the ioctl, calling
ioctl_standard_call() for SIOCSIWRATE, which calls cfg80211_wext_siwrate()
in wext-compat.c. That builds a bitrate mask and calls
rdev_set_bitrate_mask() which ends up in ieee80211_set_bitrate_mask() in
cfg.c. The interface is marked running via SDATA_STATE_RUNNING but
flags is 0, so check_sdata_in_driver() fails.
When the interface is being torn down, or when wext ioctl is issued
during interface bringup before drv_add_interface() sets IN_DRIVER, the
running check passes while IN_DRIVER is clear.
Check IEEE80211_SDATA_IN_DRIVER in ieee80211_set_bitrate_mask() before
calling the driver, returning -ENETDOWN. This avoids the WARN_ONCE in
driver-ops.h and matches other cfg.c operations that bail early when not
in driver.
This change should be safe because wiphy mutex is held in
cfg80211_wext_siwrate() via guard(wiphy), and IN_DRIVER is set/cleared
under RTNL and wiphy paths in drv_add_interface() and
drv_remove_interface() in driver-ops.c, so the check is race-free
against driver add/remove. Returning -ENETDOWN is the same error other
not-running paths use and does not introduce new locking.
Reported-by: syzbot+af177aa139efdd13a9da@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=af177aa139efdd13a9da
Link: https://lore.kernel.org/all/6a75205c.59b6c763.2bba34.00c3.GAE@google.com/
Fixes: 554a43d5e77e ("mac80211: check sdata_running on ieee80211_set_bitrate_mask")
Cc: stable@vger.kernel.org
Assisted-by: Hermes:muse-spark-1.2 syzkaller
Signed-off-by: Rik van Riel <riel@surriel.com>
Link: https://patch.msgid.link/20260808104755.319c686e@fangorn
Reported-by: syzbot+dcaca020ca8377e7ced0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dcaca020ca8377e7ced0
[also add second syzbot report]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/cfg.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -3266,6 +3266,9 @@ static int ieee80211_set_bitrate_mask(st
if (!ieee80211_sdata_running(sdata))
return -ENETDOWN;
+ if (!(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
+ return -ENETDOWN;
+
/*
* If active validate the setting and reject it if it doesn't leave
* at least one basic rate usable, since we really have to be able
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 772/982] drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (770 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 771/982] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 773/982] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
` (216 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sajal Gupta, Ruben Wauters
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sajal Gupta <sajal2005gupta@gmail.com>
commit 59ced288fcba9e91bd38e61a972ad782c4edb7d0 upstream.
The plane property loop uses req->properties[num_properties + i] as write
index while simultaneously incrementing `num_properties` inside the loop.
At iteration i, num_properties has also incremented by i, so the write
is done at `initial_num_properties + 2*i`, skipping every other index and
advancing by 2 per iteration.
With just 2 connector and 32 plane properties the last write happens at
index 64, one slot past the end of the 64-slot (indices 0–63)
allocation. A USB device can trigger OOB by advertising the maximum
number of properties.
Fix by dropping the redundant `+ i`; num_properties is already the correct
running index, as gud_connector_fill_properties() fills the preceding
slots.
Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260821071812.16500-1-sajal2005gupta%40gmail.com?part=1
Signed-off-by: Sajal Gupta <sajal2005gupta@gmail.com>
Cc: <stable@vger.kernel.org>
Acked-by: Ruben Wauters <rubenru09@aol.com>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260902123254.36987-1-sajal2005gupta@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/gud/gud_pipe.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/gud/gud_pipe.c
+++ b/drivers/gpu/drm/gud/gud_pipe.c
@@ -547,8 +547,8 @@ int gud_pipe_check(struct drm_simple_dis
goto out;
}
- req->properties[num_properties + i].prop = cpu_to_le16(prop);
- req->properties[num_properties + i].val = cpu_to_le64(val);
+ req->properties[num_properties].prop = cpu_to_le16(prop);
+ req->properties[num_properties].val = cpu_to_le64(val);
num_properties++;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 773/982] drm/msm/adreno: fix autosuspend cleanup during teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (771 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 772/982] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 774/982] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
` (215 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Dmitry Baryshkov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 6fbbf1e152f34ad3913e4a6476680aba672c5068 upstream.
adreno_gpu_init() calls pm_runtime_use_autosuspend(), but
adreno_gpu_cleanup() does not call the matching
pm_runtime_dont_use_autosuspend() during teardown.
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped and usage_count remains
unbalanced.
The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().
Add the missing pm_runtime_dont_use_autosuspend() call to
adreno_gpu_cleanup().
This issue was found by manual code inspection.
Fixes: eeb754746b14 ("drm/msm/gpu: use pm-runtime")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/745110/
Link: https://lore.kernel.org/r/20260808131624.2854412-1-lgs201920130244@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/msm/adreno/adreno_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
@@ -1088,6 +1088,8 @@ void adreno_gpu_cleanup(struct adreno_gp
for (i = 0; i < ARRAY_SIZE(adreno_gpu->info->fw); i++)
release_firmware(adreno_gpu->fw[i]);
+ pm_runtime_dont_use_autosuspend(&gpu->pdev->dev);
+
if (priv && pm_runtime_enabled(&priv->gpu_pdev->dev))
pm_runtime_disable(&priv->gpu_pdev->dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 774/982] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (772 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 773/982] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 775/982] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
` (214 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Krzysztof Kozlowski,
Dmitry Baryshkov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit f4fae975db08a9aeec0b15e145c7d4d0fe02a0ec upstream.
msm_hdmi_phy_probe() enables runtime PM before enabling the PHY
resources and initializing the PLL, but failures from either operation
return without calling the matching pm_runtime_disable().
The remove path disables runtime PM, but it is not called when probe
fails. As a result, runtime PM remains enabled after an unsuccessful
probe.
Route failures after pm_runtime_enable() through a common error path
and disable runtime PM before returning.
This issue was found by manual code inspection.
Fixes: 15b4a4523859 ("drm/msm/hdmi: Create a separate HDMI PHY driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/753043/
Link: https://lore.kernel.org/r/20260913085814.1509352-1-lgs201920130244@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/hdmi/hdmi_phy.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/msm/hdmi/hdmi_phy.c
+++ b/drivers/gpu/drm/msm/hdmi/hdmi_phy.c
@@ -160,13 +160,13 @@ static int msm_hdmi_phy_probe(struct pla
ret = msm_hdmi_phy_resource_enable(phy);
if (ret)
- return ret;
+ goto err_pm_disable;
ret = msm_hdmi_phy_pll_init(pdev, phy->cfg->type);
if (ret) {
DRM_DEV_ERROR(dev, "couldn't init PLL\n");
msm_hdmi_phy_resource_disable(phy);
- return ret;
+ goto err_pm_disable;
}
msm_hdmi_phy_resource_disable(phy);
@@ -174,6 +174,10 @@ static int msm_hdmi_phy_probe(struct pla
platform_set_drvdata(pdev, phy);
return 0;
+
+err_pm_disable:
+ pm_runtime_disable(dev);
+ return ret;
}
static int msm_hdmi_phy_remove(struct platform_device *pdev)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 775/982] smb: client: reject short Next offsets in parse_server_interfaces()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (773 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 774/982] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 776/982] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
` (213 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 1b3221bb121079ad79a1f3c3aa360ba649832e7a upstream.
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -736,9 +736,9 @@ next_iface:
break;
}
/* Validate that Next doesn't point beyond the buffer */
- if (next > bytes_left) {
- cifs_dbg(VFS, "%s: invalid Next pointer %zu > %zd\n",
- __func__, next, bytes_left);
+ if (next < sizeof(*p) || next > bytes_left) {
+ cifs_dbg(VFS, "%s: invalid Next pointer %zu out of range [%zu, %zd]\n",
+ __func__, next, sizeof(*p), bytes_left);
rc = -EINVAL;
goto out;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 776/982] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (774 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 775/982] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 777/982] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
` (212 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
Tom Talpey, Stefan Metzmacher, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit e75c96157d45e498970158c8f7373d90102e33b9 upstream.
When an RDMA connection is successfully established via
smbd_get_connection() but cifs_get_tcp_session() later fails (e.g.
kthread_create() returns an error), the error path frees tcp_ses
without first destroying the smbd_connection.
Fix this by calling smbd_destroy() in the out_err cleanup path before
kfree(tcp_ses). smbd_destroy() safely handles the case where
smbd_conn is NULL, so it can be called unconditionally.
Closes: https://sashiko.dev/#/patchset/20260912165503.521597-1-pc%40manguebit.org
Fixes: 2f8946464b11 ("CIFS: SMBD: Upper layer connects to SMBDirect session")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Tom Talpey <tom@talpey.com>
Cc: Stefan Metzmacher <metze@samba.org>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -1894,6 +1894,7 @@ out_err:
kfree(tcp_ses->hostname);
if (tcp_ses->ssocket)
sock_release(tcp_ses->ssocket);
+ smbd_destroy(tcp_ses);
kfree(tcp_ses);
}
return ERR_PTR(rc);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 777/982] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (775 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 776/982] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 778/982] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
` (211 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream.
Fix several related bounds checking and pointer lifecycle issues in
receive_encrypted_standard()'s handling of compound encrypted frames:
- Clear next_buffer after assigning it to server->bigbuf. A stale
next_buffer pointer can lead to a use-after-free on subsequent
error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
the pre-decryption length allows NextCommand to point into stale
ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
trailing slice is large enough for a header.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5205,6 +5205,7 @@ receive_encrypted_standard(struct TCP_Se
length = decrypt_raw_data(server, buf, buf_size, NULL, 0, 0, false);
if (length)
return length;
+ pdu_length = buf_size;
next_is_large = server->large_buf;
one_more:
@@ -5217,8 +5218,15 @@ one_more:
}
if (next_cmd) {
- if (WARN_ON_ONCE(next_cmd > pdu_length))
+ if (next_cmd < MID_HEADER_SIZE(server) ||
+ next_cmd > pdu_length ||
+ pdu_length - next_cmd < MID_HEADER_SIZE(server)) {
+ unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ?
+ pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0;
+ cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n",
+ next_cmd, MID_HEADER_SIZE(server), max_next);
return -1;
+ }
if (next_is_large)
next_buffer = (char *)cifs_buf_get();
else
@@ -5254,6 +5262,7 @@ one_more:
server->bigbuf = buf = next_buffer;
else
server->smallbuf = buf = next_buffer;
+ next_buffer = NULL;
goto one_more;
} else if (ret != 0) {
/*
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 778/982] smb: client: fix potential OOB read in smb3_enum_snapshots()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (776 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 777/982] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 779/982] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
` (210 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 4775c3b7a597907e0b97556c7986fda238a377ae upstream.
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
Fixes: e02789a53d71 ("smb3: enumerating snapshots was leaving part of the data off end")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -2148,8 +2148,14 @@ smb3_enum_snapshots(const unsigned int x
* and retry the ioctl again with larger array size sufficient
* to hold all of the snapshot GMT tokens on the second try.
*/
- if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE)
+ if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE) {
+ if (ret_data_len < sizeof(struct smb_snapshot_array)) {
+ rc = -EIO;
+ kfree(retbuf);
+ return rc;
+ }
ret_data_len = sizeof(struct smb_snapshot_array);
+ }
/*
* We return struct SRV_SNAPSHOT_ARRAY, followed by
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 779/982] smb: client: fix server->total_read for compound encrypted PDUs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (777 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 778/982] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 780/982] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
` (209 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit f73726b83e4756fdaa099e1bc1143293bd57ad79 upstream.
In receive_encrypted_standard(), server->total_read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs_handle_standard() passes this full size
to smb2_check_message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2_get_data_area_len().
Fix this by setting server->total_read to the true length of the
current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining
pdu_length for the last one.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5217,6 +5217,7 @@ receive_encrypted_standard(struct TCP_Se
one_more:
shdr = (struct smb2_hdr *)buf;
next_cmd = le32_to_cpu(shdr->NextCommand);
+ server->total_read = next_cmd ? next_cmd : pdu_length;
if (*num_mids >= MAX_COMPOUND) {
cifs_server_dbg(VFS, "too many PDUs in compound\n");
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 780/982] smb: client: fix missing lower-bound check on DFS referral string offsets
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (778 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 779/982] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 781/982] ASoC: SOF: avoid a NULL dereference with unsupported widgets Greg Kroah-Hartman
` (208 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit e83330c55edc0c3ac08aa6c95e49e4694c65523b upstream.
parse_dfs_referrals() checks that DfsPathOffset and NetworkAddressOffset
do not exceed the buffer end, but fails to check that they don't point
inside the referral header itself.
If a server provides an offset smaller than
sizeof(struct dfs_referral_level_3), the derived string pointer overlaps
with the struct fields, causing cifs_strndup_from_utf16() to interpret
header data as UTF-16 strings.
Fix this by enforcing that string offsets are at least sizeof(*ref).
Fixes: 4ecce920e13a ("CIFS: move DFS response parsing out of SMB1 code")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/misc.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
--- a/fs/smb/client/misc.c
+++ b/fs/smb/client/misc.c
@@ -1005,7 +1005,11 @@ parse_dfs_referrals(struct get_dfs_refer
node->ref_flag = le16_to_cpu(ref->ReferralEntryFlags);
/* copy DfsPath */
- if (le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->DfsPathOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: DfsPathOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->DfsPathOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
@@ -1019,7 +1023,11 @@ parse_dfs_referrals(struct get_dfs_refer
}
/* copy link target UNC */
- if (le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->NetworkAddressOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: NetworkAddressOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->NetworkAddressOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 781/982] ASoC: SOF: avoid a NULL dereference with unsupported widgets
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (779 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 780/982] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 782/982] ASoC: SOF: ipc4-topology: Clarify bind failure caused by missing fw_module Greg Kroah-Hartman
` (207 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guennadi Liakhovetski,
Peter Ujfalusi, Mark Brown, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guennadi Liakhovetski <guennadi.liakhovetski@linux.intel.com>
[ Upstream commit e3720f92e0237921da537e47a0b24e27899203f8 ]
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
Cc: stable@vger.kernel.org # 6.2
Signed-off-by: Guennadi Liakhovetski <guennadi.liakhovetski@linux.intel.com>
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://lore.kernel.org/r/20230329113828.28562-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
[ Backport to 6.1.y: although the upstream stable tag names 6.2, the
same module_info dereference is present here; the source change is
otherwise unchanged. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sof/ipc4-topology.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/sound/soc/sof/ipc4-topology.c b/sound/soc/sof/ipc4-topology.c
index 49289932ba7e6..9540ba6ef659e 100644
--- a/sound/soc/sof/ipc4-topology.c
+++ b/sound/soc/sof/ipc4-topology.c
@@ -1600,6 +1600,14 @@ static int sof_ipc4_route_setup(struct snd_sof_dev *sdev, struct snd_sof_route *
int dst_queue = 0;
int ret;
+ if (!src_fw_module || !sink_fw_module) {
+ /* The NULL module will print as "(efault)" */
+ dev_err(sdev->dev, "source %s or sink %s widget weren't set up properly\n",
+ src_fw_module->man4_module_entry.name,
+ sink_fw_module->man4_module_entry.name);
+ return -ENODEV;
+ }
+
dev_dbg(sdev->dev, "bind %s -> %s\n",
src_widget->widget->name, sink_widget->widget->name);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 782/982] ASoC: SOF: ipc4-topology: Clarify bind failure caused by missing fw_module
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (780 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 781/982] ASoC: SOF: avoid a NULL dereference with unsupported widgets Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 783/982] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
` (206 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Peter Ujfalusi,
Mark Brown, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
[ Upstream commit de6aa72b265b72bca2b1897d5000c8f0147d3157 ]
The original patch uses a feature in lib/vsprintf.c to handle the invalid
address when tring to print *_fw_module->man4_module_entry.name when the
*rc_fw_module is NULL.
This case is handled by check_pointer_msg() internally and turns the
invalid pointer to '(efault)' for printing but it is hiding useful
information about the circumstances. Change the print to emmit the name
of the widget and a note on which side's fw_module is missing.
Fixes: e3720f92e023 ("ASoC: SOF: avoid a NULL dereference with unsupported widgets")
Reported-by: Dan Carpenter <error27@gmail.com>
Link: https://lore.kernel.org/alsa-devel/4826f662-42f0-4a82-ba32-8bf5f8a03256@kili.mountain/
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Rule: 'Cc: stable@vger.kernel.org' or 'commit <sha1> upstream.'
Link: https://lore.kernel.org/r/20230403090909.18233-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
[ Backport to 6.1.y follow-up to e3720f92e023: replace its (efault)
pointer formatting with source/sink diagnostics; only hunk locations
differ. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/sof/ipc4-topology.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/sound/soc/sof/ipc4-topology.c b/sound/soc/sof/ipc4-topology.c
index 9540ba6ef659e..ee6f6edec970c 100644
--- a/sound/soc/sof/ipc4-topology.c
+++ b/sound/soc/sof/ipc4-topology.c
@@ -1601,10 +1601,12 @@ static int sof_ipc4_route_setup(struct snd_sof_dev *sdev, struct snd_sof_route *
int ret;
if (!src_fw_module || !sink_fw_module) {
- /* The NULL module will print as "(efault)" */
- dev_err(sdev->dev, "source %s or sink %s widget weren't set up properly\n",
- src_fw_module->man4_module_entry.name,
- sink_fw_module->man4_module_entry.name);
+ dev_err(sdev->dev,
+ "cannot bind %s -> %s, no firmware module for: %s%s\n",
+ src_widget->widget->name, sink_widget->widget->name,
+ src_fw_module ? "" : " source",
+ sink_fw_module ? "" : " sink");
+
return -ENODEV;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 783/982] HID: logitech-hidpp: fix race condition when accessing stale stack pointer
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (781 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 782/982] ASoC: SOF: ipc4-topology: Clarify bind failure caused by missing fw_module Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 784/982] blk-mq: fix tags leak when shrink nr_hw_queues Greg Kroah-Hartman
` (205 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benoît Sevens, Jiri Kosina,
Lee Jones, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benoît Sevens <bsevens@google.com>
commit e2aaf2d3ad92ac4a8afa6b69ad4c38e7747d3d6e upstream.
The driver uses hidpp->send_receive_buf to point to a stack-allocated
buffer in the synchronous command path (__do_hidpp_send_message_sync).
However, this pointer is not cleared when the function returns.
If an event is processed (e.g. by a different thread) while the
send_mutex is held by a new command, but before that command has
updated send_receive_buf, the handler (hidpp_raw_hidpp_event) will
observe that the mutex is locked and dereference the stale pointer.
This results in an out-of-bounds access on a different thread's kernel
stack (or a NULL pointer dereference on the very first command).
Fix this by:
1. Clearing hidpp->send_receive_buf to NULL before releasing the mutex
in the synchronous command path.
2. Moving the assignment of the local 'question' and 'answer' pointers
inside the mutex_is_locked() block in the handler, and adding
a NULL check before dereferencing.
Fixes: 2f31c5252910 ("HID: Introduce hidpp, a module to handle Logitech hid++ devices")
Cc: stable@vger.kernel.org
Signed-off-by: Benoît Sevens <bsevens@google.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
[Lee: Clear hidpp->send_receive_buf at exit label in hidpp_send_message_sync()
as __do_hidpp_send_message_sync() was split out later in 60165ab774cb]
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-logitech-hidpp.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/hid/hid-logitech-hidpp.c b/drivers/hid/hid-logitech-hidpp.c
index 1d4df88f690c0..37fe852dd2da9 100644
--- a/drivers/hid/hid-logitech-hidpp.c
+++ b/drivers/hid/hid-logitech-hidpp.c
@@ -315,6 +315,7 @@ static int hidpp_send_message_sync(struct hidpp_device *hidpp,
}
exit:
+ hidpp->send_receive_buf = NULL;
mutex_unlock(&hidpp->send_mutex);
return ret;
@@ -3620,8 +3621,7 @@ static int hidpp_input_configured(struct hid_device *hdev,
static int hidpp_raw_hidpp_event(struct hidpp_device *hidpp, u8 *data,
int size)
{
- struct hidpp_report *question = hidpp->send_receive_buf;
- struct hidpp_report *answer = hidpp->send_receive_buf;
+ struct hidpp_report *question, *answer;
struct hidpp_report *report = (struct hidpp_report *)data;
int ret;
@@ -3630,6 +3630,12 @@ static int hidpp_raw_hidpp_event(struct hidpp_device *hidpp, u8 *data,
* previously sent command.
*/
if (unlikely(mutex_is_locked(&hidpp->send_mutex))) {
+ question = hidpp->send_receive_buf;
+ answer = hidpp->send_receive_buf;
+
+ if (!question)
+ return 0;
+
/*
* Check for a correct hidpp20 answer or the corresponding
* error
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 784/982] blk-mq: fix tags leak when shrink nr_hw_queues
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (782 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 783/982] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 785/982] blk-mq: fix tags UAF when shrinking q->nr_hw_queues Greg Kroah-Hartman
` (204 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chengming Zhou, Ming Lei, Jens Axboe,
Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengming Zhou <zhouchengming@bytedance.com>
[ Upstream commit e1dd7bc93029024af5688253b0c05181d6e01f8e ]
Although we don't need to realloc set->tags[] when shrink nr_hw_queues,
we need to free them. Or these tags will be leaked.
How to reproduce:
1. mount -t configfs configfs /mnt
2. modprobe null_blk nr_devices=0 submit_queues=8
3. mkdir /mnt/nullb/nullb0
4. echo 1 > /mnt/nullb/nullb0/power
5. echo 4 > /mnt/nullb/nullb0/submit_queues
6. rmdir /mnt/nullb/nullb0
In step 4, will alloc 9 tags (8 submit queues and 1 poll queue), then
in step 5, new_nr_hw_queues = 5 (4 submit queues and 1 poll queue).
At last in step 6, only these 5 tags are freed, the other 4 tags leaked.
Signed-off-by: Chengming Zhou <zhouchengming@bytedance.com>
Reviewed-by: Ming Lei <ming.lei@redhat.com>
Link: https://lore.kernel.org/r/20230821095602.70742-1-chengming.zhou@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
[ Backport to 6.1.y: use this tree's cur_nr_hw_queues snapshot when
freeing excess tag sets. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-mq.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/block/blk-mq.c b/block/blk-mq.c
index 8a9d9e3db1668..b6215bee3d3c4 100644
--- a/block/blk-mq.c
+++ b/block/blk-mq.c
@@ -4509,9 +4509,13 @@ static int blk_mq_realloc_tag_set_tags(struct blk_mq_tag_set *set,
int cur_nr_hw_queues, int new_nr_hw_queues)
{
struct blk_mq_tags **new_tags;
+ int i;
- if (cur_nr_hw_queues >= new_nr_hw_queues)
+ if (cur_nr_hw_queues >= new_nr_hw_queues) {
+ for (i = new_nr_hw_queues; i < cur_nr_hw_queues; i++)
+ __blk_mq_free_map_and_rqs(set, i);
return 0;
+ }
new_tags = kcalloc_node(new_nr_hw_queues, sizeof(struct blk_mq_tags *),
GFP_KERNEL, set->numa_node);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 785/982] blk-mq: fix tags UAF when shrinking q->nr_hw_queues
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (783 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 784/982] blk-mq: fix tags leak when shrink nr_hw_queues Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 786/982] Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync Greg Kroah-Hartman
` (203 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yi Zhang, Ming Lei, Chengming Zhou,
Hannes Reinecke, Jens Axboe, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengming Zhou <zhouchengming@bytedance.com>
[ Upstream commit 6be6d112419713334ddd9c01f219ca16adaa4c76 ]
When nr_hw_queues shrink, we free the excess tags before realloc'ing
hw_ctxs for each queue. During that resize, we may need to access those
tags, like blk_mq_tag_idle(hctx) will access queue shared tags.
This can cause a slab use-after-free, as reported by KASAN. Fix it by
moving the releasing of excess tags to the end.
Fixes: e1dd7bc93029 ("blk-mq: fix tags leak when shrink nr_hw_queues")
Reported-by: Yi Zhang <yi.zhang@redhat.com>
Closes: https://lore.kernel.org/all/CAHj4cs_CK63uoDpGBGZ6DN4OCTpzkR3UaVgK=LX8Owr8ej2ieQ@mail.gmail.com/
Cc: Ming Lei <ming.lei@redhat.com>
Signed-off-by: Chengming Zhou <zhouchengming@bytedance.com>
Reviewed-by: Hannes Reinecke <hare@suse.de>
Link: https://lore.kernel.org/r/20230908005702.2183908-1-chengming.zhou@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
[ Backport to 6.1.y follow-up to e1dd7bc93029: move those frees after
hctx resizing using cur_nr_hw_queues, preventing its tag UAF. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-mq.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/block/blk-mq.c b/block/blk-mq.c
index b6215bee3d3c4..bf69079f6bd51 100644
--- a/block/blk-mq.c
+++ b/block/blk-mq.c
@@ -4509,13 +4509,9 @@ static int blk_mq_realloc_tag_set_tags(struct blk_mq_tag_set *set,
int cur_nr_hw_queues, int new_nr_hw_queues)
{
struct blk_mq_tags **new_tags;
- int i;
- if (cur_nr_hw_queues >= new_nr_hw_queues) {
- for (i = new_nr_hw_queues; i < cur_nr_hw_queues; i++)
- __blk_mq_free_map_and_rqs(set, i);
+ if (cur_nr_hw_queues >= new_nr_hw_queues)
return 0;
- }
new_tags = kcalloc_node(new_nr_hw_queues, sizeof(struct blk_mq_tags *),
GFP_KERNEL, set->numa_node);
@@ -4804,7 +4800,8 @@ static void __blk_mq_update_nr_hw_queues(struct blk_mq_tag_set *set,
{
struct request_queue *q;
LIST_HEAD(head);
- int prev_nr_hw_queues;
+ int prev_nr_hw_queues = set->nr_hw_queues;
+ int i;
lockdep_assert_held(&set->tag_list_lock);
@@ -4831,7 +4828,6 @@ static void __blk_mq_update_nr_hw_queues(struct blk_mq_tag_set *set,
blk_mq_sysfs_unregister_hctxs(q);
}
- prev_nr_hw_queues = set->nr_hw_queues;
if (blk_mq_realloc_tag_set_tags(set, set->nr_hw_queues, nr_hw_queues) <
0)
goto reregister;
@@ -4869,6 +4865,10 @@ static void __blk_mq_update_nr_hw_queues(struct blk_mq_tag_set *set,
list_for_each_entry(q, &set->tag_list, tag_set_list)
blk_mq_unfreeze_queue(q);
+
+ /* Free the excess tags when nr_hw_queues shrink. */
+ for (i = set->nr_hw_queues; i < prev_nr_hw_queues; i++)
+ __blk_mq_free_map_and_rqs(set, i);
}
void blk_mq_update_nr_hw_queues(struct blk_mq_tag_set *set, int nr_hw_queues)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 786/982] Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (784 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 785/982] blk-mq: fix tags UAF when shrinking q->nr_hw_queues Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 787/982] Bluetooth: hci_sync: always check if connection is alive before deleting Greg Kroah-Hartman
` (202 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit 94d9ba9f9888b748d4abd2aa1547af56ae85f772 ]
Use-after-free can occur in hci_disconnect_all_sync if a connection is
deleted by concurrent processing of a controller event.
To prevent this the code now tries to iterate over the list backwards
to ensure the links are cleanup before its parents, also it no longer
relies on a cursor, instead it always uses the last element since
hci_abort_conn_sync is guaranteed to call hci_conn_del.
UAF crash log:
==================================================================
BUG: KASAN: slab-use-after-free in hci_set_powered_sync
(net/bluetooth/hci_sync.c:5424) [bluetooth]
Read of size 8 at addr ffff888009d9c000 by task kworker/u9:0/124
CPU: 0 PID: 124 Comm: kworker/u9:0 Tainted: G W
6.5.0-rc1+ #10
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS
1.16.2-1.fc38 04/01/2014
Workqueue: hci0 hci_cmd_sync_work [bluetooth]
Call Trace:
<TASK>
dump_stack_lvl+0x5b/0x90
print_report+0xcf/0x670
? __virt_addr_valid+0xdd/0x160
? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]
kasan_report+0xa6/0xe0
? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]
? __pfx_set_powered_sync+0x10/0x10 [bluetooth]
hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]
? __pfx_hci_set_powered_sync+0x10/0x10 [bluetooth]
? __pfx_lock_release+0x10/0x10
? __pfx_set_powered_sync+0x10/0x10 [bluetooth]
hci_cmd_sync_work+0x137/0x220 [bluetooth]
process_one_work+0x526/0x9d0
? __pfx_process_one_work+0x10/0x10
? __pfx_do_raw_spin_lock+0x10/0x10
? mark_held_locks+0x1a/0x90
worker_thread+0x92/0x630
? __pfx_worker_thread+0x10/0x10
kthread+0x196/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x2c/0x50
</TASK>
Allocated by task 1782:
kasan_save_stack+0x33/0x60
kasan_set_track+0x25/0x30
__kasan_kmalloc+0x8f/0xa0
hci_conn_add+0xa5/0xa80 [bluetooth]
hci_bind_cis+0x881/0x9b0 [bluetooth]
iso_connect_cis+0x121/0x520 [bluetooth]
iso_sock_connect+0x3f6/0x790 [bluetooth]
__sys_connect+0x109/0x130
__x64_sys_connect+0x40/0x50
do_syscall_64+0x60/0x90
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
Freed by task 695:
kasan_save_stack+0x33/0x60
kasan_set_track+0x25/0x30
kasan_save_free_info+0x2b/0x50
__kasan_slab_free+0x10a/0x180
__kmem_cache_free+0x14d/0x2e0
device_release+0x5d/0xf0
kobject_put+0xdf/0x270
hci_disconn_complete_evt+0x274/0x3a0 [bluetooth]
hci_event_packet+0x579/0x7e0 [bluetooth]
hci_rx_work+0x287/0xaa0 [bluetooth]
process_one_work+0x526/0x9d0
worker_thread+0x92/0x630
kthread+0x196/0x1e0
ret_from_fork+0x2c/0x50
==================================================================
Fixes: 182ee45da083 ("Bluetooth: hci_sync: Rework hci_suspend_notifier")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Backport to 6.1.y: the source change is unchanged; only hunk locations
in hci_sync.c differ. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 55 +++++++++++++++++++++++++---------------
1 file changed, 35 insertions(+), 20 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index c5adc87b4992b..84d98bc3efa3f 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -5589,6 +5589,7 @@ int hci_abort_conn_sync(struct hci_dev *hdev, struct hci_conn *conn, u8 reason)
{
int err = 0;
u16 handle = conn->handle;
+ struct hci_conn *c;
switch (conn->state) {
case BT_CONNECTED:
@@ -5602,43 +5603,57 @@ int hci_abort_conn_sync(struct hci_dev *hdev, struct hci_conn *conn, u8 reason)
err = hci_reject_conn_sync(hdev, conn, reason);
break;
default:
+ hci_dev_lock(hdev);
conn->state = BT_CLOSED;
+ hci_disconn_cfm(conn, reason);
+ hci_conn_del(conn);
+ hci_dev_unlock(hdev);
return 0;
}
+ hci_dev_lock(hdev);
+
+ /* Check if the connection hasn't been cleanup while waiting
+ * commands to complete.
+ */
+ c = hci_conn_hash_lookup_handle(hdev, handle);
+ if (!c || c != conn) {
+ err = 0;
+ goto unlock;
+ }
+
/* Cleanup hci_conn object if it cannot be cancelled as it
* likelly means the controller and host stack are out of sync
* or in case of LE it was still scanning so it can be cleanup
* safely.
*/
- if (err) {
- struct hci_conn *c;
-
- /* Check if the connection hasn't been cleanup while waiting
- * commands to complete.
- */
- c = hci_conn_hash_lookup_handle(hdev, handle);
- if (!c || c != conn)
- return 0;
-
- hci_dev_lock(hdev);
- hci_conn_failed(conn, err);
- hci_dev_unlock(hdev);
- }
+ hci_conn_failed(conn, reason);
+unlock:
+ hci_dev_unlock(hdev);
return err;
}
static int hci_disconnect_all_sync(struct hci_dev *hdev, u8 reason)
{
- struct hci_conn *conn, *tmp;
- int err;
+ struct list_head *head = &hdev->conn_hash.list;
+ struct hci_conn *conn;
- list_for_each_entry_safe(conn, tmp, &hdev->conn_hash.list, list) {
- err = hci_abort_conn_sync(hdev, conn, reason);
- if (err)
- return err;
+ rcu_read_lock();
+ while ((conn = list_first_or_null_rcu(head, struct hci_conn, list))) {
+ /* Make sure the connection is not freed while unlocking */
+ conn = hci_conn_get(conn);
+ rcu_read_unlock();
+ /* Disregard possible errors since hci_conn_del shall have been
+ * called even in case of errors had occurred since it would
+ * then cause hci_conn_failed to be called which calls
+ * hci_conn_del internally.
+ */
+ hci_abort_conn_sync(hdev, conn, reason);
+ hci_conn_put(conn);
+ rcu_read_lock();
}
+ rcu_read_unlock();
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 787/982] Bluetooth: hci_sync: always check if connection is alive before deleting
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (785 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 786/982] Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 788/982] btrfs: dont check PageError in __extent_writepage Greg Kroah-Hartman
` (201 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pauli Virtanen,
Luiz Augusto von Dentz, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pauli Virtanen <pav@iki.fi>
[ Upstream commit a239110ee8e0b0aafa265f0d54f7a16744855e70 ]
In hci_abort_conn_sync it is possible that conn is deleted concurrently
by something else, also e.g. when waiting for hdev->lock. This causes
double deletion of the conn, so UAF or conn_hash.list corruption.
Fix by having all code paths check that the connection is still in
conn_hash before deleting it, while holding hdev->lock which prevents
any races.
Log (when powering off while BAP streaming, occurs rarely):
=======================================================================
kernel BUG at lib/list_debug.c:56!
...
? __list_del_entry_valid (lib/list_debug.c:56)
hci_conn_del (net/bluetooth/hci_conn.c:154) bluetooth
hci_abort_conn_sync (net/bluetooth/hci_sync.c:5415) bluetooth
? __pfx_hci_abort_conn_sync+0x10/0x10 [bluetooth]
? lock_release+0x1d5/0x3c0
? hci_disconnect_all_sync.constprop.0+0xb2/0x230 [bluetooth]
? __pfx_lock_release+0x10/0x10
? __kmem_cache_free+0x14d/0x2e0
hci_disconnect_all_sync.constprop.0+0xda/0x230 [bluetooth]
? __pfx_hci_disconnect_all_sync.constprop.0+0x10/0x10 [bluetooth]
? hci_clear_adv_sync+0x14f/0x170 [bluetooth]
? __pfx_set_powered_sync+0x10/0x10 [bluetooth]
hci_set_powered_sync+0x293/0x450 [bluetooth]
=======================================================================
Fixes: 94d9ba9f9888 ("Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync")
Signed-off-by: Pauli Virtanen <pav@iki.fi>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Backport to 6.1.y follow-up to 94d9ba9f9888: this tree lacks the later
BT_OPEN and BT_BOUND special cases, so retain its existing state
switch and add the common liveness check. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_sync.c | 21 +++++++++++----------
1 file changed, 11 insertions(+), 10 deletions(-)
diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
index 84d98bc3efa3f..5825ab89eb22a 100644
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -5589,6 +5589,7 @@ int hci_abort_conn_sync(struct hci_dev *hdev, struct hci_conn *conn, u8 reason)
{
int err = 0;
u16 handle = conn->handle;
+ bool disconnect = false;
struct hci_conn *c;
switch (conn->state) {
@@ -5603,19 +5604,13 @@ int hci_abort_conn_sync(struct hci_dev *hdev, struct hci_conn *conn, u8 reason)
err = hci_reject_conn_sync(hdev, conn, reason);
break;
default:
- hci_dev_lock(hdev);
- conn->state = BT_CLOSED;
- hci_disconn_cfm(conn, reason);
- hci_conn_del(conn);
- hci_dev_unlock(hdev);
- return 0;
+ disconnect = true;
+ break;
}
hci_dev_lock(hdev);
- /* Check if the connection hasn't been cleanup while waiting
- * commands to complete.
- */
+ /* Check if the connection has been cleaned up concurrently */
c = hci_conn_hash_lookup_handle(hdev, handle);
if (!c || c != conn) {
err = 0;
@@ -5627,7 +5622,13 @@ int hci_abort_conn_sync(struct hci_dev *hdev, struct hci_conn *conn, u8 reason)
* or in case of LE it was still scanning so it can be cleanup
* safely.
*/
- hci_conn_failed(conn, reason);
+ if (disconnect) {
+ conn->state = BT_CLOSED;
+ hci_disconn_cfm(conn, reason);
+ hci_conn_del(conn);
+ } else {
+ hci_conn_failed(conn, reason);
+ }
unlock:
hci_dev_unlock(hdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 788/982] btrfs: dont check PageError in __extent_writepage
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (786 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 787/982] Bluetooth: hci_sync: always check if connection is alive before deleting Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 789/982] io_uring/io-wq: Fix memory leak in io_wq_create() on success path Greg Kroah-Hartman
` (200 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Josef Bacik, Christoph Hellwig,
David Sterba, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 3e92499e3b004baffb479d61e191b41b604ece9a ]
__extent_writepage currenly sets PageError whenever any error happens,
and the also checks for PageError to decide if to call error handling.
This leads to very unclear responsibility for cleaning up on errors.
In the VM and generic writeback helpers the basic idea is that once
I/O is fired off all error handling responsibility is delegated to the
end I/O handler. But if that end I/O handler sets the PageError bit,
and the submitter checks it, the bit could in some cases leak into the
submission context for fast enough I/O.
Fix this by simply not checking PageError and just using the local
ret variable to check for submission errors. This also fundamentally
solves the long problem documented in a comment in __extent_writepage
by never leaking the error bit into the submission context.
Reviewed-by: Josef Bacik <josef@toxicpanda.com>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
[ Backport to 6.1.y: apply the PageError-to-ret change in this tree's
pre-btrfs_bio_ctrl __extent_writepage(). ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/extent_io.c | 33 +--------------------------------
1 file changed, 1 insertion(+), 32 deletions(-)
diff --git a/fs/btrfs/extent_io.c b/fs/btrfs/extent_io.c
index 28dbac0bfab2f..aeea8930b973f 100644
--- a/fs/btrfs/extent_io.c
+++ b/fs/btrfs/extent_io.c
@@ -2299,38 +2299,7 @@ static int __extent_writepage(struct page *page, struct writeback_control *wbc,
set_page_writeback(page);
end_page_writeback(page);
}
- /*
- * Here we used to have a check for PageError() and then set @ret and
- * call end_extent_writepage().
- *
- * But in fact setting @ret here will cause different error paths
- * between subpage and regular sectorsize.
- *
- * For regular page size, we never submit current page, but only add
- * current page to current bio.
- * The bio submission can only happen in next page.
- * Thus if we hit the PageError() branch, @ret is already set to
- * non-zero value and will not get updated for regular sectorsize.
- *
- * But for subpage case, it's possible we submit part of current page,
- * thus can get PageError() set by submitted bio of the same page,
- * while our @ret is still 0.
- *
- * So here we unify the behavior and don't set @ret.
- * Error can still be properly passed to higher layer as page will
- * be set error, here we just don't handle the IO failure.
- *
- * NOTE: This is just a hotfix for subpage.
- * The root fix will be properly ending ordered extent when we hit
- * an error during writeback.
- *
- * But that needs a bigger refactoring, as we not only need to grab the
- * submitted OE, but also need to know exactly at which bytenr we hit
- * the error.
- * Currently the full page based __extent_writepage_io() is not
- * capable of that.
- */
- if (PageError(page))
+ if (ret)
end_extent_writepage(page, ret, page_start, page_end);
if (epd->extent_locked) {
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 789/982] io_uring/io-wq: Fix memory leak in io_wq_create() on success path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (787 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 788/982] btrfs: dont check PageError in __extent_writepage Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 790/982] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
` (199 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Xiaokun, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Xiaokun <shinnkka1@gmail.com>
[ This is a stable-only patch for 6.1.y ]
Commit 657ca82526d0 ("io_uring/io-wq: inherit cpuset of cgroup in io
worker") was backported from upstream commit 84eacf177faa to 6.1.y.
In linux-6.1.y, this backport introduced a temporary allowed_mask
variable in io_wq_create(). It is correctly freed on the error path,
but is not freed on the success path. As a result, every successful
call to io_wq_create() leaks cpumask_size() bytes of memory.
This is a 6.1-specific backport issue caused by the differences in the
io-wq implementation, so the fix only applies to 6.1.y.
Fixes: 657ca82526d0 ("io_uring/io-wq: inherit cpuset of cgroup in io worker")
Signed-off-by: Chen Xiaokun <shinnkka1@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
io_uring/io-wq.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
index 0c3de2fead81c..f1bc212309c81 100644
--- a/io_uring/io-wq.c
+++ b/io_uring/io-wq.c
@@ -1221,6 +1221,7 @@ struct io_wq *io_wq_create(unsigned bounded, struct io_wq_data *data)
wq->task = get_task_struct(data->task);
atomic_set(&wq->worker_refs, 1);
init_completion(&wq->worker_done);
+ free_cpumask_var(allowed_mask);
return wq;
err:
io_wq_put_hash(data->hash);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 790/982] spi: spi-zynqmp-gqspi: stop the controller on shutdown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (788 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 789/982] io_uring/io-wq: Fix memory leak in io_wq_create() on success path Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 791/982] bpf: bpf_sk_storage: Fix invalid wait context lockdep report Greg Kroah-Hartman
` (198 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Itai Handler, Mark Brown,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Itai Handler <itai.handler@gmail.com>
commit e922bad8b2d5028c51a096d083fea41cd0987154 upstream.
The driver has no ->shutdown, and platform_drv_shutdown() has no
fallback of its own. Unlike pci_device_shutdown(), which clears bus
mastering when kexec_in_progress, nothing on the platform bus disarms a
device that can still write to memory. The normal kexec path never
calls ->suspend either, so the quiesce in zynqmp_qspi_suspend() is not
reached.
A controller that is still executing a DMA read may therefore keep
writing to memory across a kexec. QSPIDMA_DST_ADDR still points at
memory owned by the kernel that called kexec, DST_SIZE is non-zero and
the flash is still clocked, so data can keep landing in RAM while the
new kernel is being relocated, and after it has started executing.
That destination is a physical address which means nothing to the new
kernel, so the writes can corrupt whatever now occupies it: kernel text
or data, page tables, or the initrd. Nothing reports an error and the
resulting behaviour is undefined.
This can be observed by reading GQSPI_EN (offset 0x114) and
QSPIDMA_DST_ADDR/SIZE/STS/CTRL (offsets 0x800 to 0x80c) early in the new
kernel, before the driver probes: without this patch GQSPI_EN reads 1
and QSPIDMA_DST_ADDR still points into the previous kernel's memory.
Add a ->shutdown that stops the controller the way zynqmp_qspi_suspend()
already does. spi_controller_suspend() stops the queue, waits for a
message that is already executing and makes any later transfer fail with
-ESHUTDOWN, so nothing can be cut short by the register write that
follows. It may sleep, which is fine here: device_shutdown() runs in
process context. Unlike ->suspend this cannot abort on error, because a
controller left mastering the bus is worse than a truncated transfer, so
a failure to drain is only logged.
GQSPI_EN_OFST is then cleared, as zynqmp_qspi_remove() and
zynqmp_qspi_suspend() already do. Skip that write only when
pm_runtime_get_if_in_use() returns 0, i.e. runtime suspended: the clocks
are gated, so the registers are unreachable and the controller cannot be
mastering the bus. A negative return is not the same thing - it is what
the CONFIG_PM=n stub always returns, and there probe() has enabled pclk
and refclk for good, so the controller is running and must be stopped.
Fixes: dfe11a11d523 ("spi: Add support for Zynq Ultrascale+ MPSoC GQSPI controller")
Cc: stable@vger.kernel.org
Signed-off-by: Itai Handler <itai.handler@gmail.com>
Link: https://patch.msgid.link/20260910174832.873352-1-itai.handler@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
[ itai: context only - zynqmp_qspi_of_match[] still sits between
zynqmp_qspi_remove() and MODULE_DEVICE_TABLE() in this tree, hoisted to
the top of the file upstream by commit 29f4d95b97bc ("spi:
spi-zynqmp-gqspi: Add tap delay support for GQSPI controller on Versal
platform"), so zynqmp_qspi_shutdown() is placed above it ]
Signed-off-by: Itai Handler <itai.handler@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-zynqmp-gqspi.c | 34 ++++++++++++++++++++++++++++++++++
1 file changed, 34 insertions(+)
diff --git a/drivers/spi/spi-zynqmp-gqspi.c b/drivers/spi/spi-zynqmp-gqspi.c
index 204e5d03a6c53..ab62100f0b987 100644
--- a/drivers/spi/spi-zynqmp-gqspi.c
+++ b/drivers/spi/spi-zynqmp-gqspi.c
@@ -1257,6 +1257,39 @@ static int zynqmp_qspi_remove(struct platform_device *pdev)
return 0;
}
+static void zynqmp_qspi_shutdown(struct platform_device *pdev)
+{
+ struct zynqmp_qspi *xqspi = platform_get_drvdata(pdev);
+ int ret;
+
+ /*
+ * Stop the queue and reject any later transfer first, so the write
+ * below cannot cut into a message that is still being executed.
+ * Unlike ->suspend this cannot abort on error: a controller left
+ * mastering the bus is worse than a truncated transfer.
+ */
+ ret = spi_controller_suspend(xqspi->ctlr);
+ if (ret)
+ dev_warn(&pdev->dev, "could not stop the queue: %d\n", ret);
+
+ /*
+ * Only a runtime suspended controller can be left alone: its clocks
+ * are gated, so it cannot be mastering the bus, and its registers
+ * must not be accessed either. Any other answer means it may be
+ * running and has to be stopped. In particular, on a kernel built
+ * without runtime PM this returns -EINVAL, and there the clocks
+ * enabled in probe() are never gated at all.
+ */
+ ret = pm_runtime_get_if_in_use(&pdev->dev);
+ if (!ret)
+ return;
+
+ zynqmp_gqspi_write(xqspi, GQSPI_EN_OFST, 0x0);
+
+ if (ret > 0)
+ pm_runtime_put_noidle(&pdev->dev);
+}
+
static const struct of_device_id zynqmp_qspi_of_match[] = {
{ .compatible = "xlnx,zynqmp-qspi-1.0", },
{ /* End of table */ }
@@ -1267,6 +1300,7 @@ MODULE_DEVICE_TABLE(of, zynqmp_qspi_of_match);
static struct platform_driver zynqmp_qspi_driver = {
.probe = zynqmp_qspi_probe,
.remove = zynqmp_qspi_remove,
+ .shutdown = zynqmp_qspi_shutdown,
.driver = {
.name = "zynqmp-qspi",
.of_match_table = zynqmp_qspi_of_match,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 791/982] bpf: bpf_sk_storage: Fix invalid wait context lockdep report
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (789 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 790/982] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 792/982] drm/msm/dp: Drop aux devices together with DP controller Greg Kroah-Hartman
` (197 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Martin KaFai Lau, Daniel Borkmann,
Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Martin KaFai Lau <martin.lau@kernel.org>
[ Upstream commit a96a44aba556c42b432929d37d60158aca21ad4c ]
'./test_progs -t test_local_storage' reported a splat:
[ 27.137569] =============================
[ 27.138122] [ BUG: Invalid wait context ]
[ 27.138650] 6.5.0-03980-gd11ae1b16b0a #247 Tainted: G O
[ 27.139542] -----------------------------
[ 27.140106] test_progs/1729 is trying to lock:
[ 27.140713] ffff8883ef047b88 (stock_lock){-.-.}-{3:3}, at: local_lock_acquire+0x9/0x130
[ 27.141834] other info that might help us debug this:
[ 27.142437] context-{5:5}
[ 27.142856] 2 locks held by test_progs/1729:
[ 27.143352] #0: ffffffff84bcd9c0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x4/0x40
[ 27.144492] #1: ffff888107deb2c0 (&storage->lock){..-.}-{2:2}, at: bpf_local_storage_update+0x39e/0x8e0
[ 27.145855] stack backtrace:
[ 27.146274] CPU: 0 PID: 1729 Comm: test_progs Tainted: G O 6.5.0-03980-gd11ae1b16b0a #247
[ 27.147550] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014
[ 27.149127] Call Trace:
[ 27.149490] <TASK>
[ 27.149867] dump_stack_lvl+0x130/0x1d0
[ 27.152609] dump_stack+0x14/0x20
[ 27.153131] __lock_acquire+0x1657/0x2220
[ 27.153677] lock_acquire+0x1b8/0x510
[ 27.157908] local_lock_acquire+0x29/0x130
[ 27.159048] obj_cgroup_charge+0xf4/0x3c0
[ 27.160794] slab_pre_alloc_hook+0x28e/0x2b0
[ 27.161931] __kmem_cache_alloc_node+0x51/0x210
[ 27.163557] __kmalloc+0xaa/0x210
[ 27.164593] bpf_map_kzalloc+0xbc/0x170
[ 27.165147] bpf_selem_alloc+0x130/0x510
[ 27.166295] bpf_local_storage_update+0x5aa/0x8e0
[ 27.167042] bpf_fd_sk_storage_update_elem+0xdb/0x1a0
[ 27.169199] bpf_map_update_value+0x415/0x4f0
[ 27.169871] map_update_elem+0x413/0x550
[ 27.170330] __sys_bpf+0x5e9/0x640
[ 27.174065] __x64_sys_bpf+0x80/0x90
[ 27.174568] do_syscall_64+0x48/0xa0
[ 27.175201] entry_SYSCALL_64_after_hwframe+0x6e/0xd8
[ 27.175932] RIP: 0033:0x7effb40e41ad
[ 27.176357] Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d8
[ 27.179028] RSP: 002b:00007ffe64c21fc8 EFLAGS: 00000202 ORIG_RAX: 0000000000000141
[ 27.180088] RAX: ffffffffffffffda RBX: 00007ffe64c22768 RCX: 00007effb40e41ad
[ 27.181082] RDX: 0000000000000020 RSI: 00007ffe64c22008 RDI: 0000000000000002
[ 27.182030] RBP: 00007ffe64c21ff0 R08: 0000000000000000 R09: 00007ffe64c22788
[ 27.183038] R10: 0000000000000064 R11: 0000000000000202 R12: 0000000000000000
[ 27.184006] R13: 00007ffe64c22788 R14: 00007effb42a1000 R15: 0000000000000000
[ 27.184958] </TASK>
It complains about acquiring a local_lock while holding a raw_spin_lock.
It means it should not allocate memory while holding a raw_spin_lock
since it is not safe for RT.
raw_spin_lock is needed because bpf_local_storage supports tracing
context. In particular for task local storage, it is easy to
get a "current" task PTR_TO_BTF_ID in tracing bpf prog.
However, task (and cgroup) local storage has already been moved to
bpf mem allocator which can be used after raw_spin_lock.
The splat is for the sk storage. For sk (and inode) storage,
it has not been moved to bpf mem allocator. Using raw_spin_lock or not,
kzalloc(GFP_ATOMIC) could theoretically be unsafe in tracing context.
However, the local storage helper requires a verifier accepted
sk pointer (PTR_TO_BTF_ID), it is hypothetical if that (mean running
a bpf prog in a kzalloc unsafe context and also able to hold a verifier
accepted sk pointer) could happen.
This patch avoids kzalloc after raw_spin_lock to silent the splat.
There is an existing kzalloc before the raw_spin_lock. At that point,
a kzalloc is very likely required because a lookup has just been done
before. Thus, this patch always does the kzalloc before acquiring
the raw_spin_lock and remove the later kzalloc usage after the
raw_spin_lock. After this change, it will have a charge and then
uncharge during the syscall bpf_map_update_elem() code path.
This patch opts for simplicity and not continue the old
optimization to save one charge and uncharge.
This issue is dated back to the very first commit of bpf_sk_storage
which had been refactored multiple times to create task, inode, and
cgroup storage. This patch uses a Fixes tag with a more recent
commit that should be easier to do backport.
Fixes: b00fa38a9c1c ("bpf: Enable non-atomic allocations in local storage")
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20230901231129.578493-2-martin.lau@linux.dev
[ Backport to 6.1.y: retain the pre-reuse_now unlink/free API while
moving the charged element allocation outside local_storage->lock. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/bpf_local_storage.c | 47 ++++++++++------------------------
1 file changed, 14 insertions(+), 33 deletions(-)
diff --git a/kernel/bpf/bpf_local_storage.c b/kernel/bpf/bpf_local_storage.c
index 51a9f024c1829..23cbd7b1b810d 100644
--- a/kernel/bpf/bpf_local_storage.c
+++ b/kernel/bpf/bpf_local_storage.c
@@ -373,7 +373,7 @@ bpf_local_storage_update(void *owner, struct bpf_local_storage_map *smap,
void *value, u64 map_flags, gfp_t gfp_flags)
{
struct bpf_local_storage_data *old_sdata = NULL;
- struct bpf_local_storage_elem *selem = NULL;
+ struct bpf_local_storage_elem *alloc_selem, *selem = NULL;
struct bpf_local_storage *local_storage;
unsigned long flags;
int err;
@@ -427,11 +427,12 @@ bpf_local_storage_update(void *owner, struct bpf_local_storage_map *smap,
}
}
- if (gfp_flags == GFP_KERNEL) {
- selem = bpf_selem_alloc(smap, owner, value, true, gfp_flags);
- if (!selem)
- return ERR_PTR(-ENOMEM);
- }
+ /* A lookup has just been done before and concluded a new selem is
+ * needed. The chance of an unnecessary alloc is unlikely.
+ */
+ alloc_selem = selem = bpf_selem_alloc(smap, owner, value, true, gfp_flags);
+ if (!alloc_selem)
+ return ERR_PTR(-ENOMEM);
raw_spin_lock_irqsave(&local_storage->lock, flags);
@@ -443,13 +444,13 @@ bpf_local_storage_update(void *owner, struct bpf_local_storage_map *smap,
* simple.
*/
err = -EAGAIN;
- goto unlock_err;
+ goto unlock;
}
old_sdata = bpf_local_storage_lookup(local_storage, smap, false);
err = check_flags(old_sdata, map_flags);
if (err)
- goto unlock_err;
+ goto unlock;
if (old_sdata && (map_flags & BPF_F_LOCK)) {
copy_map_value_locked(&smap->map, old_sdata->data, value,
@@ -458,23 +459,7 @@ bpf_local_storage_update(void *owner, struct bpf_local_storage_map *smap,
goto unlock;
}
- if (gfp_flags != GFP_KERNEL) {
- /* local_storage->lock is held. Hence, we are sure
- * we can unlink and uncharge the old_sdata successfully
- * later. Hence, instead of charging the new selem now
- * and then uncharge the old selem later (which may cause
- * a potential but unnecessary charge failure), avoid taking
- * a charge at all here (the "!old_sdata" check) and the
- * old_sdata will not be uncharged later during
- * bpf_selem_unlink_storage_nolock().
- */
- selem = bpf_selem_alloc(smap, owner, value, !old_sdata, gfp_flags);
- if (!selem) {
- err = -ENOMEM;
- goto unlock_err;
- }
- }
-
+ alloc_selem = NULL;
/* First, link the new selem to the map */
bpf_selem_link_map(smap, selem);
@@ -485,20 +470,16 @@ bpf_local_storage_update(void *owner, struct bpf_local_storage_map *smap,
if (old_sdata) {
bpf_selem_unlink_map(SELEM(old_sdata));
bpf_selem_unlink_storage_nolock(local_storage, SELEM(old_sdata),
- false, true);
+ true, true);
}
unlock:
raw_spin_unlock_irqrestore(&local_storage->lock, flags);
- return SDATA(selem);
-
-unlock_err:
- raw_spin_unlock_irqrestore(&local_storage->lock, flags);
- if (selem) {
+ if (alloc_selem) {
mem_uncharge(smap, owner, smap->elem_size);
- kfree(selem);
+ kfree(alloc_selem);
}
- return ERR_PTR(err);
+ return err ? ERR_PTR(err) : SDATA(selem);
}
static u16 bpf_local_storage_cache_idx_get(struct bpf_local_storage_cache *cache)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 792/982] drm/msm/dp: Drop aux devices together with DP controller
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (790 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 791/982] bpf: bpf_sk_storage: Fix invalid wait context lockdep report Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 793/982] erofs: Fix detection of atomic context Greg Kroah-Hartman
` (196 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjorn Andersson, Dmitry Baryshkov,
Douglas Anderson, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjorn Andersson <quic_bjorande@quicinc.com>
[ Upstream commit a7bfb2ad2184a1fba78be35209b6019aa8cc8d4d ]
Using devres to depopulate the aux bus made sure that upon a probe
deferral the EDP panel device would be destroyed and recreated upon next
attempt.
But the struct device which the devres is tied to is the DPUs
(drm_dev->dev), which may be happen after the DP controller is torn
down.
Indications of this can be seen in the commonly seen EDID-hexdump full
of zeros in the log, or the occasional/rare KASAN fault where the
panel's attempt to read the EDID information causes a use after free on
DP resources.
It's tempting to move the devres to the DP controller's struct device,
but the resources used by the device(s) on the aux bus are explicitly
torn down in the error path. The KASAN-reported use-after-free also
remains, as the DP aux "module" explicitly frees its devres-allocated
memory in this code path.
As such, explicitly depopulate the aux bus in the error path, and in the
component unbind path, to avoid these issues.
Fixes: 2b57f726611e ("drm/msm/dp: fix aux-bus EP lifetime")
Signed-off-by: Bjorn Andersson <quic_bjorande@quicinc.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Patchwork: https://patchwork.freedesktop.org/patch/542163/
Link: https://lore.kernel.org/r/20230612220106.1884039-1-quic_bjorande@quicinc.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
[ Backport to 6.1.y: the source change is unchanged; refresh context
around the older DP bridge layout. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_display.c | 14 +++-----------
1 file changed, 3 insertions(+), 11 deletions(-)
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index 5beb727f8437f..ddd0279bc8963 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -322,6 +322,8 @@ static void dp_display_unbind(struct device *dev, struct device *master,
kthread_stop(dp->ev_tsk);
+ of_dp_aux_depopulate_bus(dp->aux);
+
dp_power_client_deinit(dp->power);
dp_unregister_audio_driver(dev, dp->audio);
dp_aux_unregister(dp->aux);
@@ -1535,11 +1537,6 @@ void msm_dp_debugfs_init(struct msm_dp *dp_display, struct drm_minor *minor)
}
}
-static void of_dp_aux_depopulate_bus_void(void *data)
-{
- of_dp_aux_depopulate_bus(data);
-}
-
static int dp_display_get_next_bridge(struct msm_dp *dp)
{
int rc;
@@ -1568,12 +1565,6 @@ static int dp_display_get_next_bridge(struct msm_dp *dp)
of_node_put(aux_bus);
if (rc)
goto error;
-
- rc = devm_add_action_or_reset(dp->drm_dev->dev,
- of_dp_aux_depopulate_bus_void,
- dp_priv->aux);
- if (rc)
- goto error;
} else if (dp->is_edp) {
DRM_ERROR("eDP aux_bus not found\n");
return -ENODEV;
@@ -1597,6 +1588,7 @@ static int dp_display_get_next_bridge(struct msm_dp *dp)
error:
if (dp->is_edp) {
+ of_dp_aux_depopulate_bus(dp_priv->aux);
disable_irq(dp_priv->irq);
dp_display_host_phy_exit(dp_priv);
dp_display_host_deinit(dp_priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 793/982] erofs: Fix detection of atomic context
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (791 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 792/982] drm/msm/dp: Drop aux devices together with DP controller Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 794/982] selftests/landlock: Add layout1.refer_mount_root Greg Kroah-Hartman
` (195 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Will Shiu, Gao Xiang,
Sandeep Dhavale, Gao Xiang, Alexandre Mergnat, Artem Dinaburg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sandeep Dhavale <dhavale@google.com>
[ Upstream commit 12d0a24afd9ea58e581ea64d64e066f2027b28d9 ]
Current check for atomic context is not sufficient as
z_erofs_decompressqueue_endio can be called under rcu lock
from blk_mq_flush_plug_list(). See the stacktrace [1]
In such case we should hand off the decompression work for async
processing rather than trying to do sync decompression in current
context. Patch fixes the detection by checking for
rcu_read_lock_any_held() and while at it use more appropriate
!in_task() check than in_atomic().
Background: Historically erofs would always schedule a kworker for
decompression which would incur the scheduling cost regardless of
the context. But z_erofs_decompressqueue_endio() may not always
be in atomic context and we could actually benefit from doing the
decompression in z_erofs_decompressqueue_endio() if we are in
thread context, for example when running with dm-verity.
This optimization was later added in patch [2] which has shown
improvement in performance benchmarks.
==============================================
[1] Problem stacktrace
[name:core&]BUG: sleeping function called from invalid context at kernel/locking/mutex.c:291
[name:core&]in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 1615, name: CpuMonitorServi
[name:core&]preempt_count: 0, expected: 0
[name:core&]RCU nest depth: 1, expected: 0
CPU: 7 PID: 1615 Comm: CpuMonitorServi Tainted: G S W OE 6.1.25-android14-5-maybe-dirty-mainline #1
Hardware name: MT6897 (DT)
Call trace:
dump_backtrace+0x108/0x15c
show_stack+0x20/0x30
dump_stack_lvl+0x6c/0x8c
dump_stack+0x20/0x48
__might_resched+0x1fc/0x308
__might_sleep+0x50/0x88
mutex_lock+0x2c/0x110
z_erofs_decompress_queue+0x11c/0xc10
z_erofs_decompress_kickoff+0x110/0x1a4
z_erofs_decompressqueue_endio+0x154/0x180
bio_endio+0x1b0/0x1d8
__dm_io_complete+0x22c/0x280
clone_endio+0xe4/0x280
bio_endio+0x1b0/0x1d8
blk_update_request+0x138/0x3a4
blk_mq_plug_issue_direct+0xd4/0x19c
blk_mq_flush_plug_list+0x2b0/0x354
__blk_flush_plug+0x110/0x160
blk_finish_plug+0x30/0x4c
read_pages+0x2fc/0x370
page_cache_ra_unbounded+0xa4/0x23c
page_cache_ra_order+0x290/0x320
do_sync_mmap_readahead+0x108/0x2c0
filemap_fault+0x19c/0x52c
__do_fault+0xc4/0x114
handle_mm_fault+0x5b4/0x1168
do_page_fault+0x338/0x4b4
do_translation_fault+0x40/0x60
do_mem_abort+0x60/0xc8
el0_da+0x4c/0xe0
el0t_64_sync_handler+0xd4/0xfc
el0t_64_sync+0x1a0/0x1a4
[2] Link: https://lore.kernel.org/all/20210317035448.13921-1-huangjianan@oppo.com/
Reported-by: Will Shiu <Will.Shiu@mediatek.com>
Suggested-by: Gao Xiang <xiang@kernel.org>
Signed-off-by: Sandeep Dhavale <dhavale@google.com>
Reviewed-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Reviewed-by: Alexandre Mergnat <amergnat@baylibre.com>
Link: https://lore.kernel.org/r/20230621220848.3379029-1-dhavale@google.com
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
[ Backport to 6.1.y: the source change is unchanged; only its location
in z_erofs_decompress_kickoff() differs. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/erofs/zdata.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/erofs/zdata.c b/fs/erofs/zdata.c
index 66c323cbdd73e..49b7c77488415 100644
--- a/fs/erofs/zdata.c
+++ b/fs/erofs/zdata.c
@@ -1271,7 +1271,7 @@ static void z_erofs_decompress_kickoff(struct z_erofs_decompressqueue *io,
if (atomic_add_return(bios, &io->pending_bios))
return;
/* Use workqueue and sync decompression for atomic contexts only */
- if (in_atomic() || irqs_disabled()) {
+ if (!in_task() || irqs_disabled() || rcu_read_lock_any_held()) {
queue_work(z_erofs_workqueue, &io->u.work);
/* enable sync decompression for readahead */
if (sbi->opt.sync_decompress == EROFS_SYNC_DECOMPRESS_AUTO)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 794/982] selftests/landlock: Add layout1.refer_mount_root
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (792 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 793/982] erofs: Fix detection of atomic context Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 795/982] erofs: fix atomic context detection when !CONFIG_DEBUG_LOCK_ALLOC Greg Kroah-Hartman
` (194 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Paul Moore,
Mickaël Salaün, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit 0055f53aac80fd938bf7cdfad7ad414ca6c0e198 ]
Add tests to check error codes when linking or renaming a mount root
directory. This previously triggered a kernel warning, but it is fixed
with the previous commit.
Cc: Günther Noack <gnoack@google.com>
Cc: Paul Moore <paul@paul-moore.com>
Link: https://lore.kernel.org/r/20240516181935.1645983-3-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt to the older selftest header layout]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 50 +++++++++++++++++++++++++++++
1 file changed, 50 insertions(+)
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -21,6 +21,12 @@
#include <sys/sysmacros.h>
#include <unistd.h>
+/*
+ * Intentionally included last to work around header conflict.
+ * See https://sourceware.org/glibc/wiki/Synchronizing_Headers.
+ */
+#include <linux/mount.h>
+
#include "common.h"
#ifndef renameat2
@@ -32,6 +38,13 @@ int renameat2(int olddirfd, const char *
}
#endif
+#ifndef open_tree
+int open_tree(int dfd, const char *filename, unsigned int flags)
+{
+ return syscall(__NR_open_tree, dfd, filename, flags);
+}
+#endif
+
#ifndef RENAME_EXCHANGE
#define RENAME_EXCHANGE (1 << 1)
#endif
@@ -2400,6 +2413,43 @@ TEST_F_FORK(layout1, refer_denied_by_def
layer_dir_s1d1_refer);
}
+/*
+ * Tests walking through a denied root mount.
+ */
+TEST_F_FORK(layout1, refer_mount_root_deny)
+{
+ const struct landlock_ruleset_attr ruleset_attr = {
+ .handled_access_fs = LANDLOCK_ACCESS_FS_MAKE_DIR,
+ };
+ int root_fd, ruleset_fd;
+
+ /* Creates a mount object from a non-mount point. */
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ root_fd =
+ open_tree(AT_FDCWD, dir_s1d1,
+ AT_EMPTY_PATH | OPEN_TREE_CLONE | OPEN_TREE_CLOEXEC);
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_LE(0, root_fd);
+
+ ruleset_fd =
+ landlock_create_ruleset(&ruleset_attr, sizeof(ruleset_attr), 0);
+ ASSERT_LE(0, ruleset_fd);
+
+ ASSERT_EQ(0, prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0));
+ ASSERT_EQ(0, landlock_restrict_self(ruleset_fd, 0));
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ /* Link denied by Landlock: EACCES. */
+ EXPECT_EQ(-1, linkat(root_fd, ".", root_fd, "does_not_exist", 0));
+ EXPECT_EQ(EACCES, errno);
+
+ /* renameat2() always returns EBUSY. */
+ EXPECT_EQ(-1, renameat2(root_fd, ".", root_fd, "does_not_exist", 0));
+ EXPECT_EQ(EBUSY, errno);
+
+ EXPECT_EQ(0, close(root_fd));
+}
+
TEST_F_FORK(layout1, reparent_link)
{
const struct rule layer1[] = {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 795/982] erofs: fix atomic context detection when !CONFIG_DEBUG_LOCK_ALLOC
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (793 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 794/982] selftests/landlock: Add layout1.refer_mount_root Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 796/982] spi: zynqmp-gqspi: Use devm_spi_alloc_host() Greg Kroah-Hartman
` (193 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Junli Liu, Gao Xiang, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junli Liu <liujunli@lixiang.com>
[ Upstream commit c99fab6e80b76422741d34aafc2f930a482afbdd ]
Since EROFS handles decompression in non-atomic contexts due to
uncontrollable decompression latencies and vmap() usage, it tries
to detect atomic contexts and only kicks off a kworker on demand
in order to reduce unnecessary scheduling overhead.
However, the current approach is insufficient and can lead to
sleeping function calls in invalid contexts, causing kernel
warnings and potential system instability. See the stacktrace [1]
and previous discussion [2].
The current implementation only checks rcu_read_lock_any_held(),
which behaves inconsistently across different kernel configurations:
- When CONFIG_DEBUG_LOCK_ALLOC is enabled: correctly detects
RCU critical sections by checking rcu_lock_map
- When CONFIG_DEBUG_LOCK_ALLOC is disabled: compiles to
"!preemptible()", which only checks preempt_count and misses
RCU critical sections
This patch introduces z_erofs_in_atomic() to provide comprehensive
atomic context detection:
1. Check RCU preemption depth when CONFIG_PREEMPTION is enabled,
as RCU critical sections may not affect preempt_count but still
require atomic handling
2. Always use async processing when CONFIG_PREEMPT_COUNT is disabled,
as preemption state cannot be reliably determined
3. Fall back to standard preemptible() check for remaining cases
The function replaces the previous complex condition check and ensures
that z_erofs always uses (kthread_)work in atomic contexts to minimize
scheduling overhead and prevent sleeping in invalid contexts.
[1] Problem stacktrace
[ 61.266692] BUG: sleeping function called from invalid context at kernel/locking/rtmutex_api.c:510
[ 61.266702] in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 107, name: irq/54-ufshcd
[ 61.266704] preempt_count: 0, expected: 0
[ 61.266705] RCU nest depth: 2, expected: 0
[ 61.266710] CPU: 0 UID: 0 PID: 107 Comm: irq/54-ufshcd Tainted: G W O 6.12.17 #1
[ 61.266714] Tainted: [W]=WARN, [O]=OOT_MODULE
[ 61.266715] Hardware name: schumacher (DT)
[ 61.266717] Call trace:
[ 61.266718] dump_backtrace+0x9c/0x100
[ 61.266727] show_stack+0x20/0x38
[ 61.266728] dump_stack_lvl+0x78/0x90
[ 61.266734] dump_stack+0x18/0x28
[ 61.266736] __might_resched+0x11c/0x180
[ 61.266743] __might_sleep+0x64/0xc8
[ 61.266745] mutex_lock+0x2c/0xc0
[ 61.266748] z_erofs_decompress_queue+0xe8/0x978
[ 61.266753] z_erofs_decompress_kickoff+0xa8/0x190
[ 61.266756] z_erofs_endio+0x168/0x288
[ 61.266758] bio_endio+0x160/0x218
[ 61.266762] blk_update_request+0x244/0x458
[ 61.266766] scsi_end_request+0x38/0x278
[ 61.266770] scsi_io_completion+0x4c/0x600
[ 61.266772] scsi_finish_command+0xc8/0xe8
[ 61.266775] scsi_complete+0x88/0x148
[ 61.266777] blk_mq_complete_request+0x3c/0x58
[ 61.266780] scsi_done_internal+0xcc/0x158
[ 61.266782] scsi_done+0x1c/0x30
[ 61.266783] ufshcd_compl_one_cqe+0x12c/0x438
[ 61.266786] __ufshcd_transfer_req_compl+0x2c/0x78
[ 61.266788] ufshcd_poll+0xf4/0x210
[ 61.266789] ufshcd_transfer_req_compl+0x50/0x88
[ 61.266791] ufshcd_intr+0x21c/0x7c8
[ 61.266792] irq_forced_thread_fn+0x44/0xd8
[ 61.266796] irq_thread+0x1a4/0x358
[ 61.266799] kthread+0x12c/0x138
[ 61.266802] ret_from_fork+0x10/0x20
[2] https://lore.kernel.org/r/58b661d0-0ebb-4b45-a10d-c5927fb791cd@paulmck-laptop
Signed-off-by: Junli Liu <liujunli@lixiang.com>
Reviewed-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Link: https://lore.kernel.org/r/20250805011957.911186-1-liujunli@lixiang.com
[ Gao Xiang: Use the original trace in v1. ]
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/erofs/zdata.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/fs/erofs/zdata.c b/fs/erofs/zdata.c
index 49b7c77488415..27cfc9aa30722 100644
--- a/fs/erofs/zdata.c
+++ b/fs/erofs/zdata.c
@@ -1255,6 +1255,16 @@ static void z_erofs_decompressqueue_work(struct work_struct *work)
kvfree(bgq);
}
+/* Use workqueue and sync decompression for atomic contexts only */
+static inline bool z_erofs_in_atomic(void)
+{
+ if (IS_ENABLED(CONFIG_PREEMPTION) && rcu_preempt_depth())
+ return true;
+ if (!IS_ENABLED(CONFIG_PREEMPT_COUNT))
+ return true;
+ return !preemptible();
+}
+
static void z_erofs_decompress_kickoff(struct z_erofs_decompressqueue *io,
int bios)
{
@@ -1270,8 +1280,7 @@ static void z_erofs_decompress_kickoff(struct z_erofs_decompressqueue *io,
if (atomic_add_return(bios, &io->pending_bios))
return;
- /* Use workqueue and sync decompression for atomic contexts only */
- if (!in_task() || irqs_disabled() || rcu_read_lock_any_held()) {
+ if (z_erofs_in_atomic()) {
queue_work(z_erofs_workqueue, &io->u.work);
/* enable sync decompression for readahead */
if (sbi->opt.sync_decompress == EROFS_SYNC_DECOMPRESS_AUTO)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 796/982] spi: zynqmp-gqspi: Use devm_spi_alloc_host()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (794 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 795/982] erofs: fix atomic context detection when !CONFIG_DEBUG_LOCK_ALLOC Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 797/982] bpf: bpf_sk_storage: Fix the missing uncharge in sk_omem_alloc Greg Kroah-Hartman
` (192 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jinjie Ruan, Michal Simek,
Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jinjie Ruan <ruanjinjie@huawei.com>
[ Upstream commit 64640f6c972e80f52196416a8d4dc3c0ffcbc82d ]
Use devm_spi_alloc_host() so that there's no need to call
spi_controller_put() in the error path.
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Acked-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20240826121421.3384792-2-ruanjinjie@huawei.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-zynqmp-gqspi.c | 18 ++++++------------
1 file changed, 6 insertions(+), 12 deletions(-)
diff --git a/drivers/spi/spi-zynqmp-gqspi.c b/drivers/spi/spi-zynqmp-gqspi.c
index ab62100f0b987..edcf8d24ad494 100644
--- a/drivers/spi/spi-zynqmp-gqspi.c
+++ b/drivers/spi/spi-zynqmp-gqspi.c
@@ -1104,7 +1104,7 @@ static int zynqmp_qspi_probe(struct platform_device *pdev)
struct device_node *np = dev->of_node;
u32 num_cs;
- ctlr = spi_alloc_master(&pdev->dev, sizeof(*xqspi));
+ ctlr = devm_spi_alloc_host(&pdev->dev, sizeof(*xqspi));
if (!ctlr)
return -ENOMEM;
@@ -1114,29 +1114,25 @@ static int zynqmp_qspi_probe(struct platform_device *pdev)
platform_set_drvdata(pdev, xqspi);
xqspi->regs = devm_platform_ioremap_resource(pdev, 0);
- if (IS_ERR(xqspi->regs)) {
- ret = PTR_ERR(xqspi->regs);
- goto remove_master;
- }
+ if (IS_ERR(xqspi->regs))
+ return PTR_ERR(xqspi->regs);
xqspi->pclk = devm_clk_get(&pdev->dev, "pclk");
if (IS_ERR(xqspi->pclk)) {
dev_err(dev, "pclk clock not found.\n");
- ret = PTR_ERR(xqspi->pclk);
- goto remove_master;
+ return PTR_ERR(xqspi->pclk);
}
xqspi->refclk = devm_clk_get(&pdev->dev, "ref_clk");
if (IS_ERR(xqspi->refclk)) {
dev_err(dev, "ref_clk clock not found.\n");
- ret = PTR_ERR(xqspi->refclk);
- goto remove_master;
+ return PTR_ERR(xqspi->refclk);
}
ret = clk_prepare_enable(xqspi->pclk);
if (ret) {
dev_err(dev, "Unable to enable APB clock.\n");
- goto remove_master;
+ return ret;
}
ret = clk_prepare_enable(xqspi->refclk);
@@ -1221,8 +1217,6 @@ static int zynqmp_qspi_probe(struct platform_device *pdev)
clk_disable_unprepare(xqspi->refclk);
clk_dis_pclk:
clk_disable_unprepare(xqspi->pclk);
-remove_master:
- spi_controller_put(ctlr);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 797/982] bpf: bpf_sk_storage: Fix the missing uncharge in sk_omem_alloc
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (795 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 796/982] spi: zynqmp-gqspi: Use devm_spi_alloc_host() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 798/982] HID: hyperv: streamline driver probe to avoid devres issues Greg Kroah-Hartman
` (191 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Martin KaFai Lau, Daniel Borkmann,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Martin KaFai Lau <martin.lau@kernel.org>
[ Upstream commit 55d49f750b1cb1f177fb1b00ae02cba4613bcfb7 ]
The commit c83597fa5dc6 ("bpf: Refactor some inode/task/sk storage functions
for reuse"), refactored the bpf_{sk,task,inode}_storage_free() into
bpf_local_storage_unlink_nolock() which then later renamed to
bpf_local_storage_destroy(). The commit accidentally passed the
"bool uncharge_mem = false" argument to bpf_selem_unlink_storage_nolock()
which then stopped the uncharge from happening to the sk->sk_omem_alloc.
This missing uncharge only happens when the sk is going away (during
__sk_destruct).
This patch fixes it by always passing "uncharge_mem = true". It is a
noop to the task/inode/cgroup storage because they do not have the
map_local_storage_(un)charge enabled in the map_ops. A followup patch
will be done in bpf-next to remove the uncharge_mem argument.
A selftest is added in the next patch.
Fixes: c83597fa5dc6 ("bpf: Refactor some inode/task/sk storage functions for reuse")
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20230901231129.578493-3-martin.lau@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/bpf_local_storage.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/bpf_local_storage.c b/kernel/bpf/bpf_local_storage.c
index 23cbd7b1b810d..9d7dfbb376ea3 100644
--- a/kernel/bpf/bpf_local_storage.c
+++ b/kernel/bpf/bpf_local_storage.c
@@ -577,7 +577,7 @@ bool bpf_local_storage_unlink_nolock(struct bpf_local_storage *local_storage)
* of the loop will set the free_cgroup_storage to true.
*/
free_storage = bpf_selem_unlink_storage_nolock(
- local_storage, selem, false, false);
+ local_storage, selem, true, false);
}
return free_storage;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 798/982] HID: hyperv: streamline driver probe to avoid devres issues
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (796 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 797/982] bpf: bpf_sk_storage: Fix the missing uncharge in sk_omem_alloc Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 799/982] start_kernel: Add __no_stack_protector function attribute Greg Kroah-Hartman
` (190 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Kelley, Vitaly Kuznetsov,
Saurabh Sengar, Jiri Kosina, Suraj Jitindar Singh, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vitaly Kuznetsov <vkuznets@redhat.com>
commit 66ef47faa90d838cda131fe1f7776456cc3b59f2 upstream
It was found that unloading 'hid_hyperv' module results in a devres
complaint:
...
hv_vmbus: unregistering driver hid_hyperv
------------[ cut here ]------------
WARNING: CPU: 2 PID: 3983 at drivers/base/devres.c:691 devres_release_group+0x1f2/0x2c0
...
Call Trace:
<TASK>
? devres_release_group+0x1f2/0x2c0
? __warn+0xd1/0x1c0
? devres_release_group+0x1f2/0x2c0
? report_bug+0x32a/0x3c0
? handle_bug+0x53/0xa0
? exc_invalid_op+0x18/0x50
? asm_exc_invalid_op+0x1a/0x20
? devres_release_group+0x1f2/0x2c0
? devres_release_group+0x90/0x2c0
? rcu_is_watching+0x15/0xb0
? __pfx_devres_release_group+0x10/0x10
hid_device_remove+0xf5/0x220
device_release_driver_internal+0x371/0x540
? klist_put+0xf3/0x170
bus_remove_device+0x1f1/0x3f0
device_del+0x33f/0x8c0
? __pfx_device_del+0x10/0x10
? cleanup_srcu_struct+0x337/0x500
hid_destroy_device+0xc8/0x130
mousevsc_remove+0xd2/0x1d0 [hid_hyperv]
device_release_driver_internal+0x371/0x540
driver_detach+0xc5/0x180
bus_remove_driver+0x11e/0x2a0
? __mutex_unlock_slowpath+0x160/0x5e0
vmbus_driver_unregister+0x62/0x2b0 [hv_vmbus]
...
And the issue seems to be that the corresponding devres group is not
allocated. Normally, devres_open_group() is called from
__hid_device_probe() but Hyper-V HID driver overrides 'hid_dev->driver'
with 'mousevsc_hid_driver' stub and basically re-implements
__hid_device_probe() by calling hid_parse() and hid_hw_start() but not
devres_open_group(). hid_device_probe() does not call __hid_device_probe()
for it. Later, when the driver is removed, hid_device_remove() calls
devres_release_group() as it doesn't check whether hdev->driver was
initially overridden or not.
The issue seems to be related to the commit 62c68e7cee33 ("HID: ensure
timely release of driver-allocated resources") but the commit itself seems
to be correct.
Fix the issue by dropping the 'hid_dev->driver' override and using
hid_register_driver()/hid_unregister_driver() instead. Alternatively, it
would have been possible to rely on the default handling but
HID_CONNECT_DEFAULT implies HID_CONNECT_HIDRAW and it doesn't seem to work
for mousevsc as-is.
Fixes: 62c68e7cee33 ("HID: ensure timely release of driver-allocated resources")
Suggested-by: Michael Kelley <mhklinux@outlook.com>
Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Reviewed-by: Michael Kelley <mhklinux@outlook.com>
Tested-by: Saurabh Sengar <ssengar@linux.microsoft.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
[ 6.1: context adjusted only - mousevsc_ll_driver is non-const in 6.1
because the hid_ll_driver constification (for-6.12/constify-rdesc,
e.g. 054e0bd34577) is not present; the applied diff is identical to
the upstream commit, no functional change ]
Signed-off-by: Suraj Jitindar Singh <surajjs@amazon.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-hyperv.c | 58 ++++++++++++++++++++++++++++------------
1 file changed, 41 insertions(+), 17 deletions(-)
diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c
index b9f64e3744885..3fdea2a59ce2f 100644
--- a/drivers/hid/hid-hyperv.c
+++ b/drivers/hid/hid-hyperv.c
@@ -456,6 +456,25 @@ static int mousevsc_hid_raw_request(struct hid_device *hid,
return 0;
}
+static int mousevsc_hid_probe(struct hid_device *hid_dev, const struct hid_device_id *id)
+{
+ int ret;
+
+ ret = hid_parse(hid_dev);
+ if (ret) {
+ hid_err(hid_dev, "parse failed\n");
+ return ret;
+ }
+
+ ret = hid_hw_start(hid_dev, HID_CONNECT_HIDINPUT | HID_CONNECT_HIDDEV);
+ if (ret) {
+ hid_err(hid_dev, "hw start failed\n");
+ return ret;
+ }
+
+ return 0;
+}
+
static struct hid_ll_driver mousevsc_ll_driver = {
.parse = mousevsc_hid_parse,
.open = mousevsc_hid_open,
@@ -465,7 +484,16 @@ static struct hid_ll_driver mousevsc_ll_driver = {
.raw_request = mousevsc_hid_raw_request,
};
-static struct hid_driver mousevsc_hid_driver;
+static const struct hid_device_id mousevsc_devices[] = {
+ { HID_DEVICE(BUS_VIRTUAL, HID_GROUP_ANY, 0x045E, 0x0621) },
+ { }
+};
+
+static struct hid_driver mousevsc_hid_driver = {
+ .name = "hid-hyperv",
+ .id_table = mousevsc_devices,
+ .probe = mousevsc_hid_probe,
+};
static int mousevsc_probe(struct hv_device *device,
const struct hv_vmbus_device_id *dev_id)
@@ -507,7 +535,6 @@ static int mousevsc_probe(struct hv_device *device,
}
hid_dev->ll_driver = &mousevsc_ll_driver;
- hid_dev->driver = &mousevsc_hid_driver;
hid_dev->bus = BUS_VIRTUAL;
hid_dev->vendor = input_dev->hid_dev_info.vendor;
hid_dev->product = input_dev->hid_dev_info.product;
@@ -522,20 +549,6 @@ static int mousevsc_probe(struct hv_device *device,
if (ret)
goto probe_err2;
-
- ret = hid_parse(hid_dev);
- if (ret) {
- hid_err(hid_dev, "parse failed\n");
- goto probe_err2;
- }
-
- ret = hid_hw_start(hid_dev, HID_CONNECT_HIDINPUT | HID_CONNECT_HIDDEV);
-
- if (ret) {
- hid_err(hid_dev, "hw start failed\n");
- goto probe_err2;
- }
-
device_init_wakeup(&device->device, true);
input_dev->connected = true;
@@ -615,12 +628,23 @@ static struct hv_driver mousevsc_drv = {
static int __init mousevsc_init(void)
{
- return vmbus_driver_register(&mousevsc_drv);
+ int ret;
+
+ ret = hid_register_driver(&mousevsc_hid_driver);
+ if (ret)
+ return ret;
+
+ ret = vmbus_driver_register(&mousevsc_drv);
+ if (ret)
+ hid_unregister_driver(&mousevsc_hid_driver);
+
+ return ret;
}
static void __exit mousevsc_exit(void)
{
vmbus_driver_unregister(&mousevsc_drv);
+ hid_unregister_driver(&mousevsc_hid_driver);
}
MODULE_LICENSE("GPL");
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 799/982] start_kernel: Add __no_stack_protector function attribute
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (797 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 798/982] HID: hyperv: streamline driver probe to avoid devres issues Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 800/982] media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings Greg Kroah-Hartman
` (189 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nathan Chancellor, Miguel Ojeda,
Peter Zijlstra (Intel), Nick Desaulniers, Josh Poimboeuf,
Artem Dinaburg, Sasha Levin, Michael Ellerman
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: ndesaulniers@google.com <ndesaulniers@google.com>
[ Upstream commit 514ca14ed5444b911de59ed3381dfd195d99fe4b ]
Back during the discussion of
commit a9a3ed1eff36 ("x86: Fix early boot crash on gcc-10, third try")
we discussed the need for a function attribute to control the omission
of stack protectors on a per-function basis; at the time Clang had
support for no_stack_protector but GCC did not. This was fixed in
gcc-11. Now that the function attribute is available, let's start using
it.
Callers of boot_init_stack_canary need to use this function attribute
unless they're compiled with -fno-stack-protector, otherwise the canary
stored in the stack slot of the caller will differ upon the call to
boot_init_stack_canary. This will lead to a call to __stack_chk_fail()
then panic.
Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=94722
Link: https://lore.kernel.org/all/20200316130414.GC12561@hirez.programming.kicks-ass.net/
Tested-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Michael Ellerman <mpe@ellerman.id.au> (powerpc)
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Nick Desaulniers <ndesaulniers@google.com>
Link: https://lore.kernel.org/r/20230412-no_stackp-v2-1-116f9fe4bbe7@google.com
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: ndesaulniers@google.com <ndesaulniers@google.com>
[ Backport to 6.1.y: retain this tree's start_kernel() signature, which
predates its upstream __noreturn annotation, and add
__no_stack_protector. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/smp.c | 1 +
include/linux/compiler_attributes.h | 12 ++++++++++++
init/main.c | 3 ++-
3 files changed, 15 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/smp.c b/arch/powerpc/kernel/smp.c
index 980f2bc832d98..fa17fdcc55a3d 100644
--- a/arch/powerpc/kernel/smp.c
+++ b/arch/powerpc/kernel/smp.c
@@ -1608,6 +1608,7 @@ static void add_cpu_to_masks(int cpu)
}
/* Activate a secondary processor. */
+__no_stack_protector
void start_secondary(void *unused)
{
unsigned int cpu = raw_smp_processor_id();
diff --git a/include/linux/compiler_attributes.h b/include/linux/compiler_attributes.h
index ab1fe28162b5e..b9778e13b0a08 100644
--- a/include/linux/compiler_attributes.h
+++ b/include/linux/compiler_attributes.h
@@ -277,6 +277,18 @@
*/
#define __noreturn __attribute__((__noreturn__))
+/*
+ * Optional: only supported since GCC >= 11.1, clang >= 7.0.
+ *
+ * gcc: https://gcc.gnu.org/onlinedocs/gcc/Common-Function-Attributes.html#index-no_005fstack_005fprotector-function-attribute
+ * clang: https://clang.llvm.org/docs/AttributeReference.html#no-stack-protector-safebuffers
+ */
+#if __has_attribute(__no_stack_protector__)
+# define __no_stack_protector __attribute__((__no_stack_protector__))
+#else
+# define __no_stack_protector
+#endif
+
/*
* Optional: not supported by gcc.
* Optional: not supported by icc.
diff --git a/init/main.c b/init/main.c
index 50b84f1f9ff38..6acfd5a78bd7a 100644
--- a/init/main.c
+++ b/init/main.c
@@ -908,7 +908,8 @@ static void __init print_unknown_bootoptions(void)
memblock_free(unknown_options, len);
}
-asmlinkage __visible void __init __no_sanitize_address start_kernel(void)
+asmlinkage __visible __init __no_sanitize_address __no_stack_protector
+void start_kernel(void)
{
char *command_line;
char *after_dashes;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 800/982] media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (798 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 799/982] start_kernel: Add __no_stack_protector function attribute Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 801/982] net/mlx5e: TC, Fix internal port memory leak Greg Kroah-Hartman
` (188 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fabian Wüthrich, Hans de Goede,
Daniel Scally, Sakari Ailus, Mauro Carvalho Chehab,
Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
[ Upstream commit 284be5693163343e1cf17c03917eecd1d6681bcf ]
When ipu_bridge_parse_rotation() and ipu_bridge_parse_orientation() run
sensor->adev is not set yet.
So if either of the dev_warn() calls about unknown values are hit this
will lead to a NULL pointer deref.
Set sensor->adev earlier, with a borrowed ref to avoid making unrolling
on errors harder, to fix this.
Fixes: 485aa3df0dff ("media: ipu3-cio2: Parse sensor orientation and rotation")
Cc: Fabian Wüthrich <me@fabwu.ch>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Reviewed-by: Daniel Scally <dan.scally@ideasonboard.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org>
[ Backport to 6.1.y: apply the sensor adev assignment in this tree's
older ipu3/cio2-bridge.c and cio2_bridge_connect_sensor(). ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/pci/intel/ipu3/cio2-bridge.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/media/pci/intel/ipu3/cio2-bridge.c b/drivers/media/pci/intel/ipu3/cio2-bridge.c
index df6c94da2f6ad..e68b735a150a9 100644
--- a/drivers/media/pci/intel/ipu3/cio2-bridge.c
+++ b/drivers/media/pci/intel/ipu3/cio2-bridge.c
@@ -280,6 +280,11 @@ static int cio2_bridge_connect_sensor(const struct cio2_sensor_config *cfg,
}
sensor = &bridge->sensors[bridge->n_sensors];
+ /*
+ * Borrow our adev ref to the sensor for now, on success
+ * acpi_dev_get(adev) is done further below.
+ */
+ sensor->adev = adev;
strscpy(sensor->name, cfg->hid, sizeof(sensor->name));
ret = cio2_bridge_read_acpi_buffer(adev, "SSDB",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 801/982] net/mlx5e: TC, Fix internal port memory leak
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (799 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 800/982] media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 802/982] sh: push-switch: Reorder cleanup operations to avoid use-after-free bug Greg Kroah-Hartman
` (187 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jianbo Liu, Vlad Buslov,
Saeed Mahameed, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jianbo Liu <jianbol@nvidia.com>
[ Upstream commit ac5da544a3c2047cbfd715acd9cec8380d7fe5c6 ]
The flow rule can be splited, and the extra post_act rules are added
to post_act table. It's possible to trigger memleak when the rule
forwards packets from internal port and over tunnel, in the case that,
for example, CT 'new' state offload is allowed. As int_port object is
assigned to the flow attribute of post_act rule, and its refcnt is
incremented by mlx5e_tc_int_port_get(), but mlx5e_tc_int_port_put() is
not called, the refcnt is never decremented, then int_port is never
freed.
The kmemleak reports the following error:
unreferenced object 0xffff888128204b80 (size 64):
comm "handler20", pid 50121, jiffies 4296973009 (age 642.932s)
hex dump (first 32 bytes):
01 00 00 00 19 00 00 00 03 f0 00 00 04 00 00 00 ................
98 77 67 41 81 88 ff ff 98 77 67 41 81 88 ff ff .wgA.....wgA....
backtrace:
[<00000000e992680d>] kmalloc_trace+0x27/0x120
[<000000009e945a98>] mlx5e_tc_int_port_get+0x3f3/0xe20 [mlx5_core]
[<0000000035a537f0>] mlx5e_tc_add_fdb_flow+0x473/0xcf0 [mlx5_core]
[<0000000070c2cec6>] __mlx5e_add_fdb_flow+0x7cf/0xe90 [mlx5_core]
[<000000005cc84048>] mlx5e_configure_flower+0xd40/0x4c40 [mlx5_core]
[<000000004f8a2031>] mlx5e_rep_indr_offload.isra.0+0x10e/0x1c0 [mlx5_core]
[<000000007df797dc>] mlx5e_rep_indr_setup_tc_cb+0x90/0x130 [mlx5_core]
[<0000000016c15cc3>] tc_setup_cb_add+0x1cf/0x410
[<00000000a63305b4>] fl_hw_replace_filter+0x38f/0x670 [cls_flower]
[<000000008bc9e77c>] fl_change+0x1fd5/0x4430 [cls_flower]
[<00000000e7f766e4>] tc_new_tfilter+0x867/0x2010
[<00000000e101c0ef>] rtnetlink_rcv_msg+0x6fc/0x9f0
[<00000000e1111d44>] netlink_rcv_skb+0x12c/0x360
[<0000000082dd6c8b>] netlink_unicast+0x438/0x710
[<00000000fc568f70>] netlink_sendmsg+0x794/0xc50
[<0000000016e92590>] sock_sendmsg+0xc5/0x190
So fix this by moving int_port cleanup code to the flow attribute
free helper, which is used by all the attribute free cases.
Fixes: 8300f225268b ("net/mlx5e: Create new flow attr for multi table actions")
Signed-off-by: Jianbo Liu <jianbol@nvidia.com>
Reviewed-by: Vlad Buslov <vladbu@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
[ Backport to 6.1.y: this tree already releases the primary flow-attribute
references in mlx5e_tc_del_fdb_flow() and lacks
mlx5_free_flow_attr_actions(); release only cloned post-action attribute
references from the corresponding free_flow_post_acts() cleanup. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_tc.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_tc.c b/drivers/net/ethernet/mellanox/mlx5/core/en_tc.c
index 05888942ef276..d2f226a09a0c7 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_tc.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_tc.c
@@ -3692,6 +3692,7 @@ free_flow_post_acts(struct mlx5e_tc_flow *flow)
{
struct mlx5_core_dev *counter_dev = get_flow_counter_dev(flow);
struct mlx5e_post_act *post_act = get_post_action(flow->priv);
+ struct mlx5_esw_flow_attr *esw_attr;
struct mlx5_flow_attr *attr, *tmp;
bool vf_tun;
@@ -3713,6 +3714,16 @@ free_flow_post_acts(struct mlx5e_tc_flow *flow)
mlx5_modify_header_dealloc(flow->priv->mdev, attr->modify_hdr);
}
+ if (mlx5e_is_eswitch_flow(flow)) {
+ esw_attr = attr->esw_attr;
+ if (esw_attr->int_port)
+ mlx5e_tc_int_port_put(mlx5e_get_int_port_priv(flow->priv),
+ esw_attr->int_port);
+ if (esw_attr->dest_int_port)
+ mlx5e_tc_int_port_put(mlx5e_get_int_port_priv(flow->priv),
+ esw_attr->dest_int_port);
+ }
+
list_del(&attr->list);
kvfree(attr->parse_attr);
kfree(attr);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 802/982] sh: push-switch: Reorder cleanup operations to avoid use-after-free bug
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (800 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 801/982] net/mlx5e: TC, Fix internal port memory leak Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 803/982] wifi: rtw88: delete timer and free skb queue when unloading Greg Kroah-Hartman
` (186 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Duoming Zhou, Geert Uytterhoeven,
John Paul Adrian Glaubitz, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Duoming Zhou <duoming@zju.edu.cn>
[ Upstream commit 246f80a0b17f8f582b2c0996db02998239057c65 ]
The original code puts flush_work() before timer_shutdown_sync()
in switch_drv_remove(). Although we use flush_work() to stop
the worker, it could be rescheduled in switch_timer(). As a result,
a use-after-free bug can occur. The details are shown below:
(cpu 0) | (cpu 1)
switch_drv_remove() |
flush_work() |
... | switch_timer // timer
| schedule_work(&psw->work)
timer_shutdown_sync() |
... | switch_work_handler // worker
kfree(psw) // free |
| psw->state = 0 // use
This patch puts timer_shutdown_sync() before flush_work() to
mitigate the bugs. As a result, the worker and timer will be
stopped safely before the deallocate operations.
Fixes: 9f5e8eee5cfe ("sh: generic push-switch framework.")
Signed-off-by: Duoming Zhou <duoming@zju.edu.cn>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://lore.kernel.org/r/20230802033737.9738-1-duoming@zju.edu.cn
Signed-off-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
[ Backport to 6.1.y: use timer_shutdown_sync(), already available here,
so the timer cannot rearm before the queued work is flushed. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/sh/drivers/push-switch.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/sh/drivers/push-switch.c b/arch/sh/drivers/push-switch.c
index 2813140fd92bb..6ecba5f521eb6 100644
--- a/arch/sh/drivers/push-switch.c
+++ b/arch/sh/drivers/push-switch.c
@@ -101,8 +101,8 @@ static int switch_drv_remove(struct platform_device *pdev)
device_remove_file(&pdev->dev, &dev_attr_switch);
platform_set_drvdata(pdev, NULL);
+ timer_shutdown_sync(&psw->debounce);
flush_work(&psw->work);
- del_timer_sync(&psw->debounce);
free_irq(irq, pdev);
kfree(psw);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 803/982] wifi: rtw88: delete timer and free skb queue when unloading
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (801 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 802/982] sh: push-switch: Reorder cleanup operations to avoid use-after-free bug Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 804/982] btrfs: insert tree mod log move in push_node_left Greg Kroah-Hartman
` (185 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Dmitry Antipov,
Kalle Valo, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Antipov <dmantipov@yandex.ru>
[ Upstream commit 634fcbcaa4062db39aeb5ac6ed1bc1feb8dd5216 ]
Fix possible crash and memory leak on driver unload by deleting
TX purge timer and freeing C2H queue in 'rtw_core_deinit()',
shrink critical section in the latter by freeing COEX queue
out of TX report lock scope.
Reviewed-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Signed-off-by: Kalle Valo <kvalo@kernel.org>
Link: https://lore.kernel.org/r/20230628072327.167196-1-dmantipov@yandex.ru
[ Backport to 6.1.y: the source change is unchanged; only hunk locations
in rtw_core_deinit() differ. The target-only Fixes trailer names the
initial rtw88 driver commit, which introduced this lifetime. ]
Fixes: e3037485c68e ("rtw88: new Realtek 802.11ac driver")
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw88/main.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw88/main.c b/drivers/net/wireless/realtek/rtw88/main.c
index 8f486152fbd9f..53c61758d57a0 100644
--- a/drivers/net/wireless/realtek/rtw88/main.c
+++ b/drivers/net/wireless/realtek/rtw88/main.c
@@ -2135,10 +2135,12 @@ void rtw_core_deinit(struct rtw_dev *rtwdev)
release_firmware(wow_fw->firmware);
destroy_workqueue(rtwdev->tx_wq);
+ timer_delete_sync(&rtwdev->tx_report.purge_timer);
spin_lock_irqsave(&rtwdev->tx_report.q_lock, flags);
ieee80211_purge_tx_queue(rtwdev->hw, &rtwdev->tx_report.queue);
- skb_queue_purge(&rtwdev->coex.queue);
spin_unlock_irqrestore(&rtwdev->tx_report.q_lock, flags);
+ skb_queue_purge(&rtwdev->coex.queue);
+ skb_queue_purge(&rtwdev->c2h_queue);
list_for_each_entry_safe(rsvd_pkt, tmp, &rtwdev->rsvd_page_list,
build_list) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 804/982] btrfs: insert tree mod log move in push_node_left
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (802 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 803/982] wifi: rtw88: delete timer and free skb queue when unloading Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 805/982] scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list Greg Kroah-Hartman
` (184 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Filipe Manana, Boris Burkov,
David Sterba, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Boris Burkov <boris@bur.io>
[ Upstream commit 5cead5422a0e3d13b0bcee986c0f5c4ebb94100b ]
There is a fairly unlikely race condition in tree mod log rewind that
can result in a kernel panic which has the following trace:
[530.569] BTRFS critical (device sda3): unable to find logical 0 length 4096
[530.585] BTRFS critical (device sda3): unable to find logical 0 length 4096
[530.602] BUG: kernel NULL pointer dereference, address: 0000000000000002
[530.618] #PF: supervisor read access in kernel mode
[530.629] #PF: error_code(0x0000) - not-present page
[530.641] PGD 0 P4D 0
[530.647] Oops: 0000 [#1] SMP
[530.654] CPU: 30 PID: 398973 Comm: below Kdump: loaded Tainted: G S O K 5.12.0-0_fbk13_clang_7455_gb24de3bdb045 #1
[530.680] Hardware name: Quanta Mono Lake-M.2 SATA 1HY9U9Z001G/Mono Lake-M.2 SATA, BIOS F20_3A15 08/16/2017
[530.703] RIP: 0010:__btrfs_map_block+0xaa/0xd00
[530.755] RSP: 0018:ffffc9002c2f7600 EFLAGS: 00010246
[530.767] RAX: ffffffffffffffea RBX: ffff888292e41000 RCX: f2702d8b8be15100
[530.784] RDX: ffff88885fda6fb8 RSI: ffff88885fd973c8 RDI: ffff88885fd973c8
[530.800] RBP: ffff888292e410d0 R08: ffffffff82fd7fd0 R09: 00000000fffeffff
[530.816] R10: ffffffff82e57fd0 R11: ffffffff82e57d70 R12: 0000000000000000
[530.832] R13: 0000000000001000 R14: 0000000000001000 R15: ffffc9002c2f76f0
[530.848] FS: 00007f38d64af000(0000) GS:ffff88885fd80000(0000) knlGS:0000000000000000
[530.866] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[530.880] CR2: 0000000000000002 CR3: 00000002b6770004 CR4: 00000000003706e0
[530.896] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[530.912] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[530.928] Call Trace:
[530.934] ? btrfs_printk+0x13b/0x18c
[530.943] ? btrfs_bio_counter_inc_blocked+0x3d/0x130
[530.955] btrfs_map_bio+0x75/0x330
[530.963] ? kmem_cache_alloc+0x12a/0x2d0
[530.973] ? btrfs_submit_metadata_bio+0x63/0x100
[530.984] btrfs_submit_metadata_bio+0xa4/0x100
[530.995] submit_extent_page+0x30f/0x360
[531.004] read_extent_buffer_pages+0x49e/0x6d0
[531.015] ? submit_extent_page+0x360/0x360
[531.025] btree_read_extent_buffer_pages+0x5f/0x150
[531.037] read_tree_block+0x37/0x60
[531.046] read_block_for_search+0x18b/0x410
[531.056] btrfs_search_old_slot+0x198/0x2f0
[531.066] resolve_indirect_ref+0xfe/0x6f0
[531.076] ? ulist_alloc+0x31/0x60
[531.084] ? kmem_cache_alloc_trace+0x12e/0x2b0
[531.095] find_parent_nodes+0x720/0x1830
[531.105] ? ulist_alloc+0x10/0x60
[531.113] iterate_extent_inodes+0xea/0x370
[531.123] ? btrfs_previous_extent_item+0x8f/0x110
[531.134] ? btrfs_search_path_in_tree+0x240/0x240
[531.146] iterate_inodes_from_logical+0x98/0xd0
[531.157] ? btrfs_search_path_in_tree+0x240/0x240
[531.168] btrfs_ioctl_logical_to_ino+0xd9/0x180
[531.179] btrfs_ioctl+0xe2/0x2eb0
This occurs when logical inode resolution takes a tree mod log sequence
number, and then while backref walking hits a rewind on a busy node
which has the following sequence of tree mod log operations (numbers
filled in from a specific example, but they are somewhat arbitrary)
REMOVE_WHILE_FREEING slot 532
REMOVE_WHILE_FREEING slot 531
REMOVE_WHILE_FREEING slot 530
...
REMOVE_WHILE_FREEING slot 0
REMOVE slot 455
REMOVE slot 454
REMOVE slot 453
...
REMOVE slot 0
ADD slot 455
ADD slot 454
ADD slot 453
...
ADD slot 0
MOVE src slot 0 -> dst slot 456 nritems 533
REMOVE slot 455
REMOVE slot 454
REMOVE slot 453
...
REMOVE slot 0
When this sequence gets applied via btrfs_tree_mod_log_rewind, it
allocates a fresh rewind eb, and first inserts the correct key info for
the 533 elements, then overwrites the first 456 of them, then decrements
the count by 456 via the add ops, then rewinds the move by doing a
memmove from 456:988->0:532. We have never written anything past 532, so
that memmove writes garbage into the 0:532 range. In practice, this
results in a lot of fully 0 keys. The rewind then puts valid keys into
slots 0:455 with the last removes, but 456:532 are still invalid.
When search_old_slot uses this eb, if it uses one of those invalid
slots, it can then read the extent buffer and issue a bio for offset 0
which ultimately panics looking up extent mappings.
This bad tree mod log sequence gets generated when the node balancing
code happens to do a balance_node_right followed by a push_node_left
while logging in the tree mod log. Illustrated for ebs L and R (left and
right):
L R
start:
[XXX|YYY|...] [ZZZ|...|...]
balance_node_right:
[XXX|YYY|...] [...|ZZZ|...] move Z to make room for Y
[XXX|...|...] [YYY|ZZZ|...] copy Y from L to R
push_node_left:
[XXX|YYY|...] [...|ZZZ|...] copy Y from R to L
[XXX|YYY|...] [ZZZ|...|...] move Z into emptied space (NOT LOGGED!)
This is because balance_node_right logs a move, but push_node_left
explicitly doesn't. That is because logging the move would remove the
overwritten src < dst range in the right eb, which was already logged
when we called btrfs_tree_mod_log_eb_copy. The correct sequence would
include a move from 456:988 to 0:532 after remove 0:455 and before
removing 0:532. Reversing that sequence would entail creating keys for
0:532, then moving those keys out to 456:988, then creating more keys
for 0:455.
i.e.,
REMOVE_WHILE_FREEING slot 532
REMOVE_WHILE_FREEING slot 531
REMOVE_WHILE_FREEING slot 530
...
REMOVE_WHILE_FREEING slot 0
MOVE src slot 456 -> dst slot 0 nritems 533
REMOVE slot 455
REMOVE slot 454
REMOVE slot 453
...
REMOVE slot 0
ADD slot 455
ADD slot 454
ADD slot 453
...
ADD slot 0
MOVE src slot 0 -> dst slot 456 nritems 533
REMOVE slot 455
REMOVE slot 454
REMOVE slot 453
...
REMOVE slot 0
Fix this to log the move but avoid the double remove by putting all the
logging logic in btrfs_tree_mod_log_eb_copy which has enough information
to detect these cases and properly log moves, removes, and adds. Leave
btrfs_tree_mod_log_insert_move to handle insert_ptr and delete_ptr's
tree mod logging.
(Un)fortunately, this is quite difficult to reproduce, and I was only
able to reproduce it by adding sleeps in btrfs_search_old_slot that
would encourage more log rewinding during ino_to_logical ioctls. I was
able to hit the warning in the previous patch in the series without the
fix quite quickly, but not after this patch.
CC: stable@vger.kernel.org # 5.15+
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Boris Burkov <boris@bur.io>
Signed-off-by: David Sterba <dsterba@suse.com>
[ Backport to 6.1.y: retain the older btrfs_node_key_ptr_offset() call
signature and pass GFP_NOFS to alloc_tree_mod_elem(). The tree-mod-log
ordering change is otherwise identical to upstream. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/ctree.c | 10 +++---
fs/btrfs/tree-mod-log.c | 73 ++++++++++++++++++++++++++++++++++++-----
2 files changed, 70 insertions(+), 13 deletions(-)
diff --git a/fs/btrfs/ctree.c b/fs/btrfs/ctree.c
index 9620bf289f78a..36f54f0f21d83 100644
--- a/fs/btrfs/ctree.c
+++ b/fs/btrfs/ctree.c
@@ -2653,8 +2653,8 @@ static int push_node_left(struct btrfs_trans_handle *trans,
if (push_items < src_nritems) {
/*
- * Don't call btrfs_tree_mod_log_insert_move() here, key removal
- * was already fully logged by btrfs_tree_mod_log_eb_copy() above.
+ * btrfs_tree_mod_log_eb_copy handles logging the move, so we
+ * don't need to do an explicit tree mod log operation for it.
*/
memmove_extent_buffer(src, btrfs_node_key_ptr_offset(0),
btrfs_node_key_ptr_offset(push_items),
@@ -2715,8 +2715,10 @@ static int balance_node_right(struct btrfs_trans_handle *trans,
btrfs_abort_transaction(trans, ret);
return ret;
}
- ret = btrfs_tree_mod_log_insert_move(dst, push_items, 0, dst_nritems);
- BUG_ON(ret < 0);
+ /*
+ * btrfs_tree_mod_log_eb_copy handles logging the move, so we don't
+ * need to do an explicit tree mod log operation for it.
+ */
memmove_extent_buffer(dst, btrfs_node_key_ptr_offset(push_items),
btrfs_node_key_ptr_offset(0),
(dst_nritems) *
diff --git a/fs/btrfs/tree-mod-log.c b/fs/btrfs/tree-mod-log.c
index 8a3a14686d3e7..2c190dcff5161 100644
--- a/fs/btrfs/tree-mod-log.c
+++ b/fs/btrfs/tree-mod-log.c
@@ -245,6 +245,26 @@ int btrfs_tree_mod_log_insert_key(struct extent_buffer *eb, int slot,
return ret;
}
+static struct tree_mod_elem *tree_mod_log_alloc_move(struct extent_buffer *eb,
+ int dst_slot, int src_slot,
+ int nr_items)
+{
+ struct tree_mod_elem *tm;
+
+ tm = kzalloc(sizeof(*tm), GFP_NOFS);
+ if (!tm)
+ return ERR_PTR(-ENOMEM);
+
+ tm->logical = eb->start;
+ tm->slot = src_slot;
+ tm->move.dst_slot = dst_slot;
+ tm->move.nr_items = nr_items;
+ tm->op = BTRFS_MOD_LOG_MOVE_KEYS;
+ RB_CLEAR_NODE(&tm->node);
+
+ return tm;
+}
+
int btrfs_tree_mod_log_insert_move(struct extent_buffer *eb,
int dst_slot, int src_slot,
int nr_items)
@@ -262,18 +282,13 @@ int btrfs_tree_mod_log_insert_move(struct extent_buffer *eb,
if (!tm_list)
return -ENOMEM;
- tm = kzalloc(sizeof(*tm), GFP_NOFS);
- if (!tm) {
- ret = -ENOMEM;
+ tm = tree_mod_log_alloc_move(eb, dst_slot, src_slot, nr_items);
+ if (IS_ERR(tm)) {
+ ret = PTR_ERR(tm);
+ tm = NULL;
goto free_tms;
}
- tm->logical = eb->start;
- tm->slot = src_slot;
- tm->move.dst_slot = dst_slot;
- tm->move.nr_items = nr_items;
- tm->op = BTRFS_MOD_LOG_MOVE_KEYS;
-
for (i = 0; i + dst_slot < src_slot && i < nr_items; i++) {
tm_list[i] = alloc_tree_mod_elem(eb, i + dst_slot,
BTRFS_MOD_LOG_KEY_REMOVE_WHILE_MOVING, GFP_NOFS);
@@ -486,6 +501,10 @@ int btrfs_tree_mod_log_eb_copy(struct extent_buffer *dst,
struct tree_mod_elem **tm_list_add, **tm_list_rem;
int i;
bool locked = false;
+ struct tree_mod_elem *dst_move_tm = NULL;
+ struct tree_mod_elem *src_move_tm = NULL;
+ u32 dst_move_nr_items = btrfs_header_nritems(dst) - dst_offset;
+ u32 src_move_nr_items = btrfs_header_nritems(src) - (src_offset + nr_items);
if (!tree_mod_need_log(fs_info, NULL))
return 0;
@@ -498,6 +517,26 @@ int btrfs_tree_mod_log_eb_copy(struct extent_buffer *dst,
if (!tm_list)
return -ENOMEM;
+ if (dst_move_nr_items) {
+ dst_move_tm = tree_mod_log_alloc_move(dst, dst_offset + nr_items,
+ dst_offset, dst_move_nr_items);
+ if (IS_ERR(dst_move_tm)) {
+ ret = PTR_ERR(dst_move_tm);
+ dst_move_tm = NULL;
+ goto free_tms;
+ }
+ }
+ if (src_move_nr_items) {
+ src_move_tm = tree_mod_log_alloc_move(src, src_offset,
+ src_offset + nr_items,
+ src_move_nr_items);
+ if (IS_ERR(src_move_tm)) {
+ ret = PTR_ERR(src_move_tm);
+ src_move_tm = NULL;
+ goto free_tms;
+ }
+ }
+
tm_list_add = tm_list;
tm_list_rem = tm_list + nr_items;
for (i = 0; i < nr_items; i++) {
@@ -520,6 +559,11 @@ int btrfs_tree_mod_log_eb_copy(struct extent_buffer *dst,
goto free_tms;
locked = true;
+ if (dst_move_tm) {
+ ret = tree_mod_log_insert(fs_info, dst_move_tm);
+ if (ret)
+ goto free_tms;
+ }
for (i = 0; i < nr_items; i++) {
ret = tree_mod_log_insert(fs_info, tm_list_rem[i]);
if (ret)
@@ -528,6 +572,11 @@ int btrfs_tree_mod_log_eb_copy(struct extent_buffer *dst,
if (ret)
goto free_tms;
}
+ if (src_move_tm) {
+ ret = tree_mod_log_insert(fs_info, src_move_tm);
+ if (ret)
+ goto free_tms;
+ }
write_unlock(&fs_info->tree_mod_log_lock);
kfree(tm_list);
@@ -535,6 +584,12 @@ int btrfs_tree_mod_log_eb_copy(struct extent_buffer *dst,
return 0;
free_tms:
+ if (dst_move_tm && !RB_EMPTY_NODE(&dst_move_tm->node))
+ rb_erase(&dst_move_tm->node, &fs_info->tree_mod_log);
+ kfree(dst_move_tm);
+ if (src_move_tm && !RB_EMPTY_NODE(&src_move_tm->node))
+ rb_erase(&src_move_tm->node, &fs_info->tree_mod_log);
+ kfree(src_move_tm);
for (i = 0; i < nr_items * 2; i++) {
if (tm_list[i] && !RB_EMPTY_NODE(&tm_list[i]->node))
rb_erase(&tm_list[i]->node, &fs_info->tree_mod_log);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 805/982] scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (803 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 804/982] btrfs: insert tree mod log move in push_node_left Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 806/982] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status Greg Kroah-Hartman
` (183 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xingui Yang, Xiang Chen,
Martin K. Petersen, Artem Dinaburg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xingui Yang <yangxingui@huawei.com>
[ Upstream commit 71fb36b5ff113a7674710b9d6063241eada84ff7 ]
When freeing slots in function slot_complete_v3_hw(), it is possible that
sas_dev.list is being traversed elsewhere, and it may trigger a NULL
pointer exception, such as follows:
==>cq thread ==>scsi_eh_6
==>scsi_error_handler()
==>sas_eh_handle_sas_errors()
==>sas_scsi_find_task()
==>lldd_abort_task()
==>slot_complete_v3_hw() ==>hisi_sas_abort_task()
==>hisi_sas_slot_task_free() ==>dereg_device_v3_hw()
==>list_del_init() ==>list_for_each_entry_safe()
[ 7165.434918] sas: Enter sas_scsi_recover_host busy: 32 failed: 32
[ 7165.434926] sas: trying to find task 0x00000000769b5ba5
[ 7165.434927] sas: sas_scsi_find_task: aborting task 0x00000000769b5ba5
[ 7165.434940] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000769b5ba5) aborted
[ 7165.434964] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000c9f7aa07) ignored
[ 7165.434965] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000e2a1cf01) ignored
[ 7165.434968] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
[ 7165.434972] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000022d52d93) ignored
[ 7165.434975] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000066a7516c) ignored
[ 7165.434976] Mem abort info:
[ 7165.434982] ESR = 0x96000004
[ 7165.434991] Exception class = DABT (current EL), IL = 32 bits
[ 7165.434992] SET = 0, FnV = 0
[ 7165.434993] EA = 0, S1PTW = 0
[ 7165.434994] Data abort info:
[ 7165.434994] ISV = 0, ISS = 0x00000004
[ 7165.434995] CM = 0, WnR = 0
[ 7165.434997] user pgtable: 4k pages, 48-bit VAs, pgdp = 00000000f29543f2
[ 7165.434998] [0000000000000000] pgd=0000000000000000
[ 7165.435003] Internal error: Oops: 96000004 [#1] SMP
[ 7165.439863] Process scsi_eh_6 (pid: 4109, stack limit = 0x00000000c43818d5)
[ 7165.468862] pstate: 00c00009 (nzcv daif +PAN +UAO)
[ 7165.473637] pc : dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw]
[ 7165.479443] lr : dereg_device_v3_hw+0x2c/0xa8 [hisi_sas_v3_hw]
[ 7165.485247] sp : ffff00001d623bc0
[ 7165.488546] x29: ffff00001d623bc0 x28: ffffa027d03b9508
[ 7165.493835] x27: ffff80278ed50af0 x26: ffffa027dd31e0a8
[ 7165.499123] x25: ffffa027d9b27f88 x24: ffffa027d9b209f8
[ 7165.504411] x23: ffffa027c45b0d60 x22: ffff80278ec07c00
[ 7165.509700] x21: 0000000000000008 x20: ffffa027d9b209f8
[ 7165.514988] x19: ffffa027d9b27f88 x18: ffffffffffffffff
[ 7165.520276] x17: 0000000000000000 x16: 0000000000000000
[ 7165.525564] x15: ffff0000091d9708 x14: ffff0000093b7dc8
[ 7165.530852] x13: ffff0000093b7a23 x12: 6e7265746e692067
[ 7165.536140] x11: 0000000000000000 x10: 0000000000000bb0
[ 7165.541429] x9 : ffff00001d6238f0 x8 : ffffa027d877af00
[ 7165.546718] x7 : ffffa027d6329600 x6 : ffff7e809f58ca00
[ 7165.552006] x5 : 0000000000001f8a x4 : 000000000000088e
[ 7165.557295] x3 : ffffa027d9b27fa8 x2 : 0000000000000000
[ 7165.562583] x1 : 0000000000000000 x0 : 000000003000188e
[ 7165.567872] Call trace:
[ 7165.570309] dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw]
[ 7165.575775] hisi_sas_abort_task+0x248/0x358 [hisi_sas_main]
[ 7165.581415] sas_eh_handle_sas_errors+0x258/0x8e0 [libsas]
[ 7165.586876] sas_scsi_recover_host+0x134/0x458 [libsas]
[ 7165.592082] scsi_error_handler+0xb4/0x488
[ 7165.596163] kthread+0x134/0x138
[ 7165.599380] ret_from_fork+0x10/0x18
[ 7165.602940] Code: d5033e9f b9000040 aa0103e2 eb03003f (f9400021)
[ 7165.609004] kernel fault(0x1) notification starting on CPU 75
[ 7165.700728] ---[ end trace fc042cbbea224efc ]---
[ 7165.705326] Kernel panic - not syncing: Fatal exception
To fix the issue, grab sas_dev lock when traversing the members of
sas_dev.list in dereg_device_v3_hw() and hisi_sas_release_tasks() to avoid
concurrency of adding and deleting member. When function
hisi_sas_release_tasks() calls hisi_sas_do_release_task() to free slot, the
lock cannot be grabbed again in hisi_sas_slot_task_free(), then a bool
parameter need_lock is added.
Signed-off-by: Xingui Yang <yangxingui@huawei.com>
Signed-off-by: Xiang Chen <chenxiang66@hisilicon.com>
Link: https://lore.kernel.org/r/1679283265-115066-2-git-send-email-chenxiang66@hisilicon.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
[ Backport to 6.1.y: omit the SATA NCQ-error call-site update because that
path does not call hisi_sas_do_release_task() in 6.1.y. The list locking
change is otherwise identical to upstream. ]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/hisi_sas/hisi_sas.h | 3 ++-
drivers/scsi/hisi_sas/hisi_sas_main.c | 23 +++++++++++++++--------
drivers/scsi/hisi_sas/hisi_sas_v1_hw.c | 2 +-
drivers/scsi/hisi_sas/hisi_sas_v2_hw.c | 2 +-
drivers/scsi/hisi_sas/hisi_sas_v3_hw.c | 4 +++-
5 files changed, 22 insertions(+), 12 deletions(-)
diff --git a/drivers/scsi/hisi_sas/hisi_sas.h b/drivers/scsi/hisi_sas/hisi_sas.h
index 9aebf4a26b132..2ecf97f7ae525 100644
--- a/drivers/scsi/hisi_sas/hisi_sas.h
+++ b/drivers/scsi/hisi_sas/hisi_sas.h
@@ -652,7 +652,8 @@ extern void hisi_sas_phy_down(struct hisi_hba *hisi_hba, int phy_no, int rdy,
extern void hisi_sas_phy_bcast(struct hisi_sas_phy *phy);
extern void hisi_sas_slot_task_free(struct hisi_hba *hisi_hba,
struct sas_task *task,
- struct hisi_sas_slot *slot);
+ struct hisi_sas_slot *slot,
+ bool need_lock);
extern void hisi_sas_init_mem(struct hisi_hba *hisi_hba);
extern void hisi_sas_rst_work_handler(struct work_struct *work);
extern void hisi_sas_sync_rst_work_handler(struct work_struct *work);
diff --git a/drivers/scsi/hisi_sas/hisi_sas_main.c b/drivers/scsi/hisi_sas/hisi_sas_main.c
index 10ea1d434c48d..290c9915fb9b2 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_main.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_main.c
@@ -205,7 +205,7 @@ static int hisi_sas_slot_index_alloc(struct hisi_hba *hisi_hba,
}
void hisi_sas_slot_task_free(struct hisi_hba *hisi_hba, struct sas_task *task,
- struct hisi_sas_slot *slot)
+ struct hisi_sas_slot *slot, bool need_lock)
{
int device_id = slot->device_id;
struct hisi_sas_device *sas_dev = &hisi_hba->devices[device_id];
@@ -239,9 +239,13 @@ void hisi_sas_slot_task_free(struct hisi_hba *hisi_hba, struct sas_task *task,
}
}
- spin_lock(&sas_dev->lock);
- list_del_init(&slot->entry);
- spin_unlock(&sas_dev->lock);
+ if (need_lock) {
+ spin_lock(&sas_dev->lock);
+ list_del_init(&slot->entry);
+ spin_unlock(&sas_dev->lock);
+ } else {
+ list_del_init(&slot->entry);
+ }
memset(slot, 0, offsetof(struct hisi_sas_slot, buf));
@@ -1059,7 +1063,7 @@ static void hisi_sas_port_notify_formed(struct asd_sas_phy *sas_phy)
}
static void hisi_sas_do_release_task(struct hisi_hba *hisi_hba, struct sas_task *task,
- struct hisi_sas_slot *slot)
+ struct hisi_sas_slot *slot, bool need_lock)
{
if (task) {
unsigned long flags;
@@ -1076,7 +1080,7 @@ static void hisi_sas_do_release_task(struct hisi_hba *hisi_hba, struct sas_task
spin_unlock_irqrestore(&task->task_state_lock, flags);
}
- hisi_sas_slot_task_free(hisi_hba, task, slot);
+ hisi_sas_slot_task_free(hisi_hba, task, slot, need_lock);
}
static void hisi_sas_release_task(struct hisi_hba *hisi_hba,
@@ -1085,8 +1089,11 @@ static void hisi_sas_release_task(struct hisi_hba *hisi_hba,
struct hisi_sas_slot *slot, *slot2;
struct hisi_sas_device *sas_dev = device->lldd_dev;
+ spin_lock(&sas_dev->lock);
list_for_each_entry_safe(slot, slot2, &sas_dev->list, entry)
- hisi_sas_do_release_task(hisi_hba, slot->task, slot);
+ hisi_sas_do_release_task(hisi_hba, slot->task, slot, false);
+
+ spin_unlock(&sas_dev->lock);
}
void hisi_sas_release_tasks(struct hisi_hba *hisi_hba)
@@ -1620,7 +1627,7 @@ static int hisi_sas_abort_task(struct sas_task *task)
*/
if (rc == TMF_RESP_FUNC_COMPLETE && rc2 != TMF_RESP_FUNC_SUCC) {
if (task->lldd_task)
- hisi_sas_do_release_task(hisi_hba, task, slot);
+ hisi_sas_do_release_task(hisi_hba, task, slot, true);
}
} else if (task->task_proto & SAS_PROTOCOL_SATA ||
task->task_proto & SAS_PROTOCOL_STP) {
diff --git a/drivers/scsi/hisi_sas/hisi_sas_v1_hw.c b/drivers/scsi/hisi_sas/hisi_sas_v1_hw.c
index 70c24377c6a19..76176b1fc035d 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_v1_hw.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_v1_hw.c
@@ -1310,7 +1310,7 @@ static void slot_complete_v1_hw(struct hisi_hba *hisi_hba,
}
out:
- hisi_sas_slot_task_free(hisi_hba, task, slot);
+ hisi_sas_slot_task_free(hisi_hba, task, slot, true);
if (task->task_done)
task->task_done(task);
diff --git a/drivers/scsi/hisi_sas/hisi_sas_v2_hw.c b/drivers/scsi/hisi_sas/hisi_sas_v2_hw.c
index ae39f6b5dc9a8..1470d6bf3052b 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_v2_hw.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_v2_hw.c
@@ -2473,7 +2473,7 @@ static void slot_complete_v2_hw(struct hisi_hba *hisi_hba,
}
task->task_state_flags |= SAS_TASK_STATE_DONE;
spin_unlock_irqrestore(&task->task_state_lock, flags);
- hisi_sas_slot_task_free(hisi_hba, task, slot);
+ hisi_sas_slot_task_free(hisi_hba, task, slot, true);
if (!is_internal && (task->task_proto != SAS_PROTOCOL_SMP)) {
spin_lock_irqsave(&device->done_lock, flags);
diff --git a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
index ccd52fc7d34a2..3db206c743831 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
@@ -873,6 +873,7 @@ static void dereg_device_v3_hw(struct hisi_hba *hisi_hba,
cfg_abt_set_query_iptt = hisi_sas_read32(hisi_hba,
CFG_ABT_SET_QUERY_IPTT);
+ spin_lock(&sas_dev->lock);
list_for_each_entry_safe(slot, slot2, &sas_dev->list, entry) {
cfg_abt_set_query_iptt &= ~CFG_SET_ABORTED_IPTT_MSK;
cfg_abt_set_query_iptt |= (1 << CFG_SET_ABORTED_EN_OFF) |
@@ -880,6 +881,7 @@ static void dereg_device_v3_hw(struct hisi_hba *hisi_hba,
hisi_sas_write32(hisi_hba, CFG_ABT_SET_QUERY_IPTT,
cfg_abt_set_query_iptt);
}
+ spin_unlock(&sas_dev->lock);
cfg_abt_set_query_iptt &= ~(1 << CFG_SET_ABORTED_EN_OFF);
hisi_sas_write32(hisi_hba, CFG_ABT_SET_QUERY_IPTT,
cfg_abt_set_query_iptt);
@@ -2364,7 +2366,7 @@ static void slot_complete_v3_hw(struct hisi_hba *hisi_hba,
}
task->task_state_flags |= SAS_TASK_STATE_DONE;
spin_unlock_irqrestore(&task->task_state_lock, flags);
- hisi_sas_slot_task_free(hisi_hba, task, slot);
+ hisi_sas_slot_task_free(hisi_hba, task, slot, true);
if (!is_internal && (task->task_proto != SAS_PROTOCOL_SMP)) {
spin_lock_irqsave(&device->done_lock, flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 806/982] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (804 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 805/982] scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 807/982] bpf: Fix bpf_skb_change_tail wrt csum partial skbs Greg Kroah-Hartman
` (182 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit d343407b728a80b74be3c24b59f15e60289ea527 ]
When __inject_sigp_stop() is called for a Stop and Store Status
operation, if the vCPU is running, the interrupt is marked as pending
and the status is stored by the thread performing the KVM_RUN IOCTL.
If the vCPU is already stopped, the status is stored immediately.
Storing the status means writing into userspace, which might fault, and
__inject_sigp_stop() is called from do_inject_vcpu() which in turn is
always called holding a spinlock, which is obviously an issue.
Fix this by returning -EWOULDBLOCK from __inject_sigp_stop(), and
adding a bool flag to indicate whether a store status is needed. The
callers of do_inject_vcpu() are modified to pass the pointer to the
bool flag; whenever a Store Status operation is needed, the callers can
now perform it outside the spinlock.
Opportunistically refactor kvm_s390_set_irq_state() to use
scoped_guard() and __free().
Fixes: 6cddd432e3da ("KVM: s390: handle stop irqs without action_bits")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Added Fixes tag while picking -- Claudio ]
Message-ID: <20260812104436.109741-7-imbrenda@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/interrupt.c | 70 +++++++++++++++++++++------------------
1 file changed, 38 insertions(+), 32 deletions(-)
diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c
index 6be9c79383dd5..9e76d26e02121 100644
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -1582,23 +1582,21 @@ static int __inject_set_prefix(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
}
#define KVM_S390_STOP_SUPP_FLAGS (KVM_S390_STOP_FLAG_STORE_STATUS)
-static int __inject_sigp_stop(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
+static int __inject_sigp_stop(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq, bool *storestatus)
{
struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
struct kvm_s390_stop_info *stop = &li->irq.stop;
- int rc = 0;
vcpu->stat.inject_stop_signal++;
trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_SIGP_STOP, 0, 0);
if (irq->u.stop.flags & ~KVM_S390_STOP_SUPP_FLAGS)
return -EINVAL;
-
if (is_vcpu_stopped(vcpu)) {
- if (irq->u.stop.flags & KVM_S390_STOP_FLAG_STORE_STATUS)
- rc = kvm_s390_store_status_unloaded(vcpu,
- KVM_S390_STORE_STATUS_NOADDR);
- return rc;
+ if (!(irq->u.stop.flags & KVM_S390_STOP_FLAG_STORE_STATUS))
+ return 0;
+ *storestatus = true;
+ return -EWOULDBLOCK;
}
if (test_and_set_bit(IRQ_PEND_SIGP_STOP, &li->pending_irqs))
@@ -2138,7 +2136,7 @@ void kvm_s390_clear_stop_irq(struct kvm_vcpu *vcpu)
spin_unlock(&li->lock);
}
-static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
+static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq, bool *storestatus)
{
int rc;
@@ -2150,7 +2148,7 @@ static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
rc = __inject_set_prefix(vcpu, irq);
break;
case KVM_S390_SIGP_STOP:
- rc = __inject_sigp_stop(vcpu, irq);
+ rc = __inject_sigp_stop(vcpu, irq, storestatus);
break;
case KVM_S390_RESTART:
rc = __inject_sigp_restart(vcpu);
@@ -2186,11 +2184,16 @@ static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
int kvm_s390_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
{
struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
+ bool storestatus = false;
int rc;
spin_lock(&li->lock);
- rc = do_inject_vcpu(vcpu, irq);
+ rc = do_inject_vcpu(vcpu, irq, &storestatus);
spin_unlock(&li->lock);
+
+ if (rc == -EWOULDBLOCK && storestatus)
+ rc = kvm_s390_store_status_unloaded(vcpu, KVM_S390_STORE_STATUS_NOADDR);
+
if (!rc)
kvm_s390_vcpu_wakeup(vcpu);
return rc;
@@ -2926,7 +2929,8 @@ int kvm_set_msi(struct kvm_kernel_irq_routing_entry *e, struct kvm *kvm,
int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len)
{
struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
- struct kvm_s390_irq *buf;
+ struct kvm_s390_irq *buf __free(kvfree) = NULL;
+ bool tmp, storestatus = false;
int r = 0;
int n;
@@ -2934,31 +2938,33 @@ int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len
if (!buf)
return -ENOMEM;
- if (copy_from_user((void *) buf, irqstate, len)) {
- r = -EFAULT;
- goto out_free;
- }
+ if (copy_from_user((void *)buf, irqstate, len))
+ return -EFAULT;
- /*
- * Don't allow setting the interrupt state
- * when there are already interrupts pending
- */
- spin_lock(&li->lock);
- if (li->pending_irqs) {
- r = -EBUSY;
- goto out_unlock;
- }
+ scoped_guard(spinlock, &li->lock) {
+ /*
+ * Don't allow setting the interrupt state
+ * when there are already interrupts pending
+ */
+ if (li->pending_irqs)
+ return -EBUSY;
- for (n = 0; n < len / sizeof(*buf); n++) {
- r = do_inject_vcpu(vcpu, &buf[n]);
- if (r)
- break;
+ for (n = 0; n < len / sizeof(*buf); n++) {
+ tmp = false;
+ r = do_inject_vcpu(vcpu, &buf[n], &tmp);
+ if (r == -EWOULDBLOCK && tmp) {
+ storestatus = true;
+ r = 0;
+ }
+ if (r)
+ break;
+ }
}
-out_unlock:
- spin_unlock(&li->lock);
-out_free:
- vfree(buf);
+ if (storestatus) {
+ n = kvm_s390_store_status_unloaded(vcpu, KVM_S390_STORE_STATUS_NOADDR);
+ return r ? r : n;
+ }
return r;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 807/982] bpf: Fix bpf_skb_change_tail wrt csum partial skbs
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (805 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 806/982] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 808/982] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL Greg Kroah-Hartman
` (181 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tom Hadlaw, Yusuke Suzuki,
Daniel Borkmann, Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 3b55f350c68a0aceff108f47f9d31f47ebffaf7b ]
Cilium generates ICMP "frag needed" replies from BPF when a LB DSR
packet exceeds the egress MTU. The reply is built by first trimming the
packet down to target size via bpf_skb_change_tail(), and then pushing
the ICMP error headers in front of it.
The trim is rejected for skbs which carry a checksum offload, e.g. TCP
packets aggregated by GRO on ingress where tcp_gro_complete() leaves
the skb as CHECKSUM_PARTIAL. __bpf_skb_min_len() raises the minimum
length to the end of the L4 checksum field, so a trim to 42 bytes bails
out with -EINVAL given a min_len of 52 in this case, and due to that
the ICMP generator fails. This is not the case if GRO is turned off.
Fix this bpf_skb_change_tail() restriction and drop the checksum offload
when the new length no longer covers the checksum field. The BPF program
rewrites the skb into an ICMP error and computes the checksum itself
anyway.
Fixes: 5293efe62df8 ("bpf: add bpf_skb_change_tail helper")
Reported-by: Tom Hadlaw <tom.hadlaw@isovalent.com>
Reported-by: Yusuke Suzuki <yusuke.suzuki@isovalent.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260907121025.1923656-1-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 5d9f0b21d49da..fe6d963d340bf 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -3772,12 +3772,6 @@ static u32 __bpf_skb_min_len(const struct sk_buff *skb)
if (offset > 0)
min_len = offset;
}
- if (skb->ip_summed == CHECKSUM_PARTIAL) {
- offset = skb_checksum_start_offset(skb) +
- skb->csum_offset + sizeof(__sum16);
- if (offset > 0)
- min_len = offset;
- }
return min_len;
}
@@ -3794,6 +3788,11 @@ static int bpf_skb_grow_rcsum(struct sk_buff *skb, unsigned int new_len)
static int bpf_skb_trim_rcsum(struct sk_buff *skb, unsigned int new_len)
{
+ if (skb->ip_summed == CHECKSUM_PARTIAL &&
+ new_len < skb_checksum_start_offset(skb) + skb->csum_offset +
+ sizeof(__sum16))
+ skb->ip_summed = CHECKSUM_NONE;
+
return __skb_trim_rcsum(skb, new_len);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 808/982] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (806 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 807/982] bpf: Fix bpf_skb_change_tail wrt csum partial skbs Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 809/982] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc Greg Kroah-Hartman
` (180 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+adfca3e91be95776,
Alexei Starovoitov, Weiming Shi, Daniel Borkmann, Emil Tsalapatis,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit e4a62833adff6ef0fe7c0b90393204fe3c26b5c5 ]
An LWT_SEG6LOCAL program can invalidate its cached SRH with
bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter
may reallocate skb->head, leaving the per-CPU SRH pointer dangling.
Post-program SRH validation then writes through that pointer.
Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier
rejects this unsafe helper combination. Other LWT program types continue
to expose the helper through lwt_out_func_proto().
Fixes: 004d4b274e2a ("ipv6: sr: Add seg6local action End.BPF")
Reported-by: co+adfca3e91be95776@bugs.sh
Suggested-by: Alexei Starovoitov <alexei.starovoitov@gmail.com>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Closes: https://lore.kernel.org/all/GCy0KRM2IcQGoJQTjJEU9D0maBxXzEDHuQpq@bugs.sh/
Link: https://lore.kernel.org/bpf/DL9COXZQXX4V.1FN45QO2Q77ZH@gmail.com/
Link: https://lore.kernel.org/bpf/20260909040807.3885815-2-bestswngs@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/core/filter.c b/net/core/filter.c
index fe6d963d340bf..bb86d9db3731d 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -8535,6 +8535,8 @@ static const struct bpf_func_proto *
lwt_seg6local_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog)
{
switch (func_id) {
+ case BPF_FUNC_skb_pull_data:
+ return NULL;
#if IS_ENABLED(CONFIG_IPV6_SEG6_BPF)
case BPF_FUNC_lwt_seg6_store_bytes:
return &bpf_lwt_seg6_store_bytes_proto;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 809/982] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (807 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 808/982] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 810/982] bpf: support access variable length array of integer type Greg Kroah-Hartman
` (179 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sven Schnelle, Steven Rostedt,
Masami Hiramatsu (Google), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sven Schnelle <svens@linux.ibm.com>
[ Upstream commit d22c3e0088e85be8131f7a9283f759cdbb20726d ]
The current regex also matches symbols in modules, which makes the
test fail on s390 where name_show is present only once in the kernel,
but also multiple times in modules:
000001b1401cdc20 t name_show
000001b0c05e6c40 t name_show [mdev]
000001b0c0495f30 t name_show [i2c_core]
Fix this by changing the regular expression to only match the function
name.
Link: https://lore.kernel.org/all/20260909092954.2200558-1-svens@linux.ibm.com/
Fixes: 03b80ff8023a ("selftests/ftrace: Add new test case which checks non unique symbol")
Signed-off-by: Sven Schnelle <svens@linux.ibm.com>
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc b/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc
index bc9514428dbaf..07b1177c16344 100644
--- a/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc
+++ b/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc
@@ -6,7 +6,7 @@
SYMBOL='name_show'
# We skip this test on kernel where SYMBOL is unique or does not exist.
-if [ "$(grep -c -E "[[:alnum:]]+ t ${SYMBOL}" /proc/kallsyms)" -le '1' ]; then
+if [ "$(grep -c -E "[[:alnum:]]+ t ${SYMBOL}$" /proc/kallsyms)" -le '1' ]; then
exit_unsupported
fi
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 810/982] bpf: support access variable length array of integer type
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (808 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 809/982] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 811/982] bpf: Fix divide-by-zero in btf_struct_walk() Greg Kroah-Hartman
` (178 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chengming Zhou, Feng Zhou,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Feng Zhou <zhoufeng.zf@bytedance.com>
[ Upstream commit 2569c7b8726fc06d946a4f999fb1be15b68f3f3c ]
After this commit:
bpf: Support variable length array in tracing programs (9c5f8a1008a1)
Trace programs can access variable length array, but for structure
type. This patch adds support for integer type.
Example:
Hook load_balance
struct sched_domain {
...
unsigned long span[];
}
The access: sd->span[0].
Co-developed-by: Chengming Zhou <zhouchengming@bytedance.com>
Signed-off-by: Chengming Zhou <zhouchengming@bytedance.com>
Signed-off-by: Feng Zhou <zhoufeng.zf@bytedance.com>
Link: https://lore.kernel.org/r/20230420032735.27760-2-zhoufeng.zf@bytedance.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Stable-dep-of: b0b3dc665296 ("bpf: Fix divide-by-zero in btf_struct_walk()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 4fa37f58d97dd..2aa8afcebfce0 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -5626,11 +5626,13 @@ static int btf_struct_walk(struct bpf_verifier_log *log, const struct btf *btf,
if (off < moff)
goto error;
- /* Only allow structure for now, can be relaxed for
- * other types later.
- */
+ /* allow structure and integer */
t = btf_type_skip_modifiers(btf, array_elem->type,
NULL);
+
+ if (btf_type_is_int(t))
+ return WALK_SCALAR;
+
if (!btf_type_is_struct(t))
goto error;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 811/982] bpf: Fix divide-by-zero in btf_struct_walk()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (809 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 810/982] bpf: support access variable length array of integer type Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 812/982] HID: elecom: fix bus type for M-XGL20DLBK Greg Kroah-Hartman
` (177 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Eduard Zingerman,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit b0b3dc66529676228cb938cbcad66920f735c223 ]
When an access goes past the struct and the last member is a flexible
array, btf_struct_walk() folds the offset back into a single element with
(off - moff) % t->size, but never checks that the element type has a size.
BTF takes an empty struct, so this in program BTF
/* event could be empty */
struct event {
#ifdef HAVE_TIMESTAMP
__u64 ts;
#endif
};
struct batch {
int nr;
struct event events[];
};
divides by zero at prog load time. Getting there needs a PTR_TO_BTF_ID that
is not MEM_ALLOC, e.g. a plain read of a local kptr stashed in a map from a
sleepable program.
Oops: divide error: 0000 [#1] SMP KASAN PTI
RIP: 0010:btf_struct_walk+0x53f/0x1570
Call Trace:
<TASK>
btf_struct_access+0x42a/0xcd0
check_ptr_to_btf_access+0x4dc/0x1160
check_mem_access+0x3a45/0x8740
check_load_mem+0x36a/0xd10
do_check_common+0x3ef0/0xb210
bpf_check+0x6d3b/0x8580
bpf_prog_load+0xf7c/0x2720
__sys_bpf+0xa83/0x3690
__x64_sys_bpf+0xc7/0x150
x64_sys_call+0x1f3f/0x27e0
do_syscall_64+0xe5/0x610
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>
Reject a zero-sized element type. The fixed array path in the same function
already bails out on the same thing:
btf_struct_walk()
...
/* skip empty array */
if (moff == mtrue_end)
continue;
msize /= total_nelems;
Fixes: 9c5f8a1008a1 ("bpf: Support variable length array in tracing programs")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260910122316.186384-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 2aa8afcebfce0..e20b4d024a828 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -5633,7 +5633,7 @@ static int btf_struct_walk(struct bpf_verifier_log *log, const struct btf *btf,
if (btf_type_is_int(t))
return WALK_SCALAR;
- if (!btf_type_is_struct(t))
+ if (!btf_type_is_struct(t) || !t->size)
goto error;
off = (off - moff) % t->size;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 812/982] HID: elecom: fix bus type for M-XGL20DLBK
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (810 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 811/982] bpf: Fix divide-by-zero in btf_struct_walk() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 813/982] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch() Greg Kroah-Hartman
` (176 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Oscar Priego Verdugo, Jiri Kosina,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oscar Priego Verdugo <oscar.priegov@gmail.com>
[ Upstream commit 8e2a4b458ad25e13422bb059758c30a6562aa9cf ]
The M-XGL20DLBK is matched as a USB device by hid-elecom, but
its entry in hid_have_special_driver[] uses HID_BLUETOOTH_DEVICE.
This prevents the special-driver quirk entry from matching the USB
device handled by hid-elecom. Use HID_USB_DEVICE there as well.
Fixes: 55633e681afb ("HID: elecom: add support for EX-G M-XGL20DLBK wireless mouse")
Signed-off-by: Oscar Priego Verdugo <oscar.priegov@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-quirks.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hid/hid-quirks.c b/drivers/hid/hid-quirks.c
index 657f51f6b9c58..af2534ae6201a 100644
--- a/drivers/hid/hid-quirks.c
+++ b/drivers/hid/hid-quirks.c
@@ -404,7 +404,7 @@ static const struct hid_device_id hid_have_special_driver[] = {
#endif
#if IS_ENABLED(CONFIG_HID_ELECOM)
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_BM084) },
- { HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XGL20DLBK) },
+ { HID_USB_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XGL20DLBK) },
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_HT1MRBK_01AC) },
{ HID_USB_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XT3URBK_00FB) },
{ HID_USB_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XT3URBK_018F) },
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 813/982] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (811 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 812/982] HID: elecom: fix bus type for M-XGL20DLBK Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 814/982] bpf: Fix out-of-bounds read of rtt_min in sock_ops Greg Kroah-Hartman
` (175 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul E. McKenney, Rik van Riel,
Jose Fernandez (Anthropic), Josef Bacik, Alexei Starovoitov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jose Fernandez (Anthropic) <jose.fernandez@linux.dev>
[ Upstream commit 85136bf22404474a815fc0ed26ec0d1cbc1bc3f9 ]
__htab_map_lookup_and_delete_batch() has no rescheduling point. The
batch count bounds how many entries are copied out, not how many
buckets are visited, so one BPF_MAP_LOOKUP_BATCH call can walk the
map end to end. The empty-bucket fast path is worse: it stays inside
a single rcu_read_lock() / bpf_disable_instrumentation() section for
any run of consecutive empty buckets.
That holds up on small maps, but it falls apart at scale. On a
144-CPU arm64 host running a CONFIG_PREEMPT_NONE kernel, periodic
BPF_MAP_LOOKUP_BATCH calls against an LRU hash map with 16,777,216
buckets held a CPU inside the batch op for 77+ seconds and triggered
the soft lockup watchdog.
Commit 75134f16e7dd ("bpf: Add schedule points in batch ops") fixed this
same problem in the generic batch ops, but not in this htab-native path,
which every htab-based hash map variant uses for its lookup[_and_delete]
batch ops.
Complete that fix here. Leave the critical section after 64 consecutive
empty buckets, call cond_resched_tasks_rcu_qs(), and resume at the saved
bucket cursor. No locks are held at that point, and resuming from the
cursor is already the function's behavior for non-empty buckets. Add the
same call to the per-bucket loop after copy_to_user(), where every lock
has been dropped. cond_resched_rcu() is not enough here: sleeping with
bpf_prog_active elevated makes tracing programs on that CPU silently
skip their invocations.
Plain cond_resched() is not enough either. It is a no-op under PREEMPT
and PREEMPT_LAZY, the only models arm64 and x86 have offered since
commit 7dadeaa6e851 ("sched: Further restrict the preemption modes").
It is also never a Tasks RCU quiescent state, in any model: the
reschedule counts as a preemption. The walking task stays a holdout and
stalls every synchronize_rcu_tasks() caller, ftrace and BPF trampoline
teardown included, until the syscall returns [1].
cond_resched_tasks_rcu_qs() is the usual tool for that [2]. It reports
the quiescent state at each yield and still reschedules as
cond_resched() does on PREEMPT_NONE and PREEMPT_VOLUNTARY kernels.
Fixes: 057996380a42 ("bpf: Add batch ops to all htab bpf map")
Cc: "Paul E. McKenney" <paulmck@kernel.org>
Cc: Rik van Riel <riel@surriel.com>
Link: https://lore.kernel.org/bpf/20260715215314.44423f47@fangorn/ [1]
Link: https://lore.kernel.org/bpf/9d444098-7c03-4163-af12-bd0a79a51443@paulmck-laptop/ [2]
Assisted-by: LLM
Signed-off-by: Jose Fernandez (Anthropic) <jose.fernandez@linux.dev>
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
Reviewed-by: Rik van Riel <riel@surriel.com>
Link: https://lore.kernel.org/r/20260909-b4-htab-batch-resched-v2-1-0cb529d8f95a@toxicpanda.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/hashtab.c | 24 +++++++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c
index b2f207a5dd4fd..291c2befa120d 100644
--- a/kernel/bpf/hashtab.c
+++ b/kernel/bpf/hashtab.c
@@ -1653,6 +1653,12 @@ static int htab_lru_percpu_map_lookup_and_delete_elem(struct bpf_map *map,
flags);
}
+/*
+ * Max consecutive empty buckets to walk in one RCU +
+ * instrumentation-disabled section before rescheduling.
+ */
+#define HTAB_BATCH_EMPTY_RESCHED 64
+
static int
__htab_map_lookup_and_delete_batch(struct bpf_map *map,
const union bpf_attr *attr,
@@ -1674,6 +1680,7 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
unsigned long flags = 0;
bool locked = false;
struct htab_elem *l;
+ u32 empty_cnt = 0;
struct bucket *b;
int ret = 0;
@@ -1839,12 +1846,21 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
}
next_batch:
- /* If we are not copying data, we can go to next bucket and avoid
- * unlocking the rcu.
+ /*
+ * If we are not copying data, we can go to next bucket and avoid
+ * unlocking the rcu. Bound the walk though: after
+ * HTAB_BATCH_EMPTY_RESCHED consecutive empty buckets, fully exit
+ * the critical section (no locks are held here) and reschedule.
*/
if (!bucket_cnt && (batch + 1 < htab->n_buckets)) {
batch++;
- goto again_nocopy;
+ if (++empty_cnt < HTAB_BATCH_EMPTY_RESCHED)
+ goto again_nocopy;
+ empty_cnt = 0;
+ rcu_read_unlock();
+ bpf_enable_instrumentation();
+ cond_resched_tasks_rcu_qs();
+ goto again;
}
rcu_read_unlock();
@@ -1858,11 +1874,13 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
}
total += bucket_cnt;
+ empty_cnt = 0;
batch++;
if (batch >= htab->n_buckets) {
ret = -ENOENT;
goto after_loop;
}
+ cond_resched_tasks_rcu_qs();
goto again;
after_loop:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 814/982] bpf: Fix out-of-bounds read of rtt_min in sock_ops
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (812 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 813/982] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 815/982] bpf, sockmap: Fix self-redirect copied_seq double-counting Greg Kroah-Hartman
` (174 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, VEGA, Jiayuan Chen, Emil Tsalapatis,
Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 75f8cf22463d82bb1fb0239a3d485fc8f4c8ef03 ]
A sockops prog reading skops->rtt_min never checks the sk type: on the
tcp_conn_request() path sock_ops->sk is a request_sock (non-full), and the
ctx rewrite casts it to a tcp_sock (full) and reads rtt_min past the end of
the request_sock, returning dirty adjacent memory.
SEC("sockops")
int prog(struct bpf_sock_ops *skops)
{
switch (skops->op) {
case BPF_SOCK_OPS_RWND_INIT:
leak = skops->rtt_min; /* reads the request_sock OOB */
...
}
}
For instance one such read returned rtt_min=0xffff8881, the high half of a
leaked kernel pointer.
Guarding that cast is exactly what SOCK_OPS_GET_FIELD() does -- it checks
is_locked_tcp_sock and returns 0 when sock_ops->sk is not a locked full
socket. Every other tcp_sock field in sock_ops goes through it; rtt_min is
the only one open-coded, so it skips the check.
Read rtt_min through SOCK_OPS_GET_FIELD() too. rtt_min is a bit special:
it is a struct minmax and we only want the current min, so pass
rtt_min.s[0].v. That is equivalent to the old hand-computed offset
offsetof(struct tcp_sock, rtt_min) + sizeof_field(struct minmax_sample, t)
(s[0] sits at rtt_min + 0 and .v at + sizeof(.t), i.e. what minmax_get()
returns), so the loaded field is unchanged and only the full-sock guard is
added. The two BUILD_BUG_ON()s that protected the hand-computed offset
are no longer needed.
Before patch:
0: r1 = *(u64 *)(r1 +0) ; r1 = skops->sk
1: r1 = *(u32 *)(r1 +2324) ; ((tcp_sock *)sk)->rtt_min.s[0].v
After patch:
0: *(u64 *)(r1 +56) = r9
1: r9 = *(u8 *)(r1 +50) ; is_locked_tcp_sock
2: if r9 == 0 goto pc+4 ; not a locked full sock -> 0
3: r9 = *(u64 *)(r1 +56)
4: r1 = *(u64 *)(r1 +0) ; r1 = skops->sk
5: r1 = *(u32 *)(r1 +2324) ; rtt_min.s[0].v
6: goto pc+2
7: r9 = *(u64 *)(r1 +56)
8: r1 = 0
Fixes: 44f0e43037d3 ("bpf: Add support for reading sk_state and more")
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/r/20260903100921.113374-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 13 +------------
1 file changed, 1 insertion(+), 12 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index bb86d9db3731d..12caa1ac346cf 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -10593,18 +10593,7 @@ static u32 sock_ops_convert_ctx_access(enum bpf_access_type type,
break;
case offsetof(struct bpf_sock_ops, rtt_min):
- BUILD_BUG_ON(sizeof_field(struct tcp_sock, rtt_min) !=
- sizeof(struct minmax));
- BUILD_BUG_ON(sizeof(struct minmax) <
- sizeof(struct minmax_sample));
-
- *insn++ = BPF_LDX_MEM(BPF_FIELD_SIZEOF(
- struct bpf_sock_ops_kern, sk),
- si->dst_reg, si->src_reg,
- offsetof(struct bpf_sock_ops_kern, sk));
- *insn++ = BPF_LDX_MEM(BPF_W, si->dst_reg, si->dst_reg,
- offsetof(struct tcp_sock, rtt_min) +
- sizeof_field(struct minmax_sample, t));
+ SOCK_OPS_GET_FIELD(rtt_min, rtt_min.s[0].v, struct tcp_sock);
break;
case offsetof(struct bpf_sock_ops, bpf_sock_ops_cb_flags):
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 815/982] bpf, sockmap: Fix self-redirect copied_seq double-counting
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (813 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 814/982] bpf: Fix out-of-bounds read of rtt_min in sock_ops Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 816/982] pinctrl: meson: Fix typo in s4 group name Greg Kroah-Hartman
` (173 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Sitnicki, Jiayuan Chen,
Geliang Tang, Emil Tsalapatis, Alexei Starovoitov, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geliang Tang <tanggeliang@kylinos.cn>
[ Upstream commit 490a83d6386eec1d29f470c8d7331677fb46c3b7 ]
When a BPF stream_verdict program redirects an skb back to the same
socket (self-redirect with BPF_F_INGRESS), sk_psock_verdict_apply()
calls tcp_eat_skb() which advances tcp_sk->copied_seq. However, the
skb is then delivered to the socket's psock ingress queue and later
read by tcp_bpf_recvmsg_parser(), which also advances copied_seq via
the copied_from_self accounting path. This double-counting causes
copied_seq to advance by 2x the actual data length, triggering:
TCP recvmsg seq # bug 2: copied BF2E806, seq BF2E7FD, \
rcvnxt BF2E806, fl 0
WARNING: net/ipv4/tcp.c:2745 at tcp_recvmsg_locked+0x72b/0x2640
Call Trace:
tcp_recvmsg+0x10a/0x500
sock_recvmsg+0x168/0x1d0
__sys_recvfrom+0x19a/0x2a0
__x64_sys_recvfrom+0xe4/0x1f0
do_syscall_64+0xf7/0x530
entry_SYSCALL_64_after_hwframe+0x77/0x7f
cleanup rbuf bug: copied BF2E806 seq BF2E806 rcvnxt BF2E806
WARNING: net/ipv4/tcp.c:1609 at tcp_cleanup_rbuf+0xf2/0x1c0
Call Trace:
tcp_recvmsg_locked+0x8d1/0x2640
tcp_recvmsg+0x10a/0x500
sock_recvmsg+0x168/0x1d0
__sys_recvfrom+0x19a/0x2a0
__x64_sys_recvfrom+0xe4/0x1f0
do_syscall_64+0xf7/0x530
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fix this by converting self-redirect verdict to __SK_PASS at the
beginning of sk_psock_verdict_apply(). This bypasses the
__SK_REDIRECT case entirely (which calls sk_psock_eat_skb), letting
the __SK_PASS path queue the skb to the psock ingress queue. The
data is then read via tcp_bpf_recvmsg_parser(), which advances
copied_seq exactly once through copied_from_self. Cross-socket
redirects continue through __SK_REDIRECT with sk_psock_eat_skb()
unchanged.
Fixes: e5c6de5fa025 ("bpf, sockmap: Incorrectly handling copied_seq")
Suggested-by: Jakub Sitnicki <jakub@cloudflare.com>
Suggested-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Signed-off-by: Geliang Tang <tanggeliang@kylinos.cn>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/1a8e797a1b26e2f695aaac22ac644c2862f63466.1788858299.git.tanggeliang@kylinos.cn
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skmsg.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/core/skmsg.c b/net/core/skmsg.c
index 11bc309811d30..20e67399f0b6a 100644
--- a/net/core/skmsg.c
+++ b/net/core/skmsg.c
@@ -1031,6 +1031,10 @@ static int sk_psock_verdict_apply(struct sk_psock *psock, struct sk_buff *skb,
int err = 0;
u32 len, off;
+ if (verdict == __SK_REDIRECT && skb_bpf_ingress(skb) &&
+ skb_bpf_redirect_fetch(skb) == psock->sk)
+ verdict = __SK_PASS;
+
switch (verdict) {
case __SK_PASS:
err = -EIO;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 816/982] pinctrl: meson: Fix typo in s4 group name
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (814 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 815/982] bpf, sockmap: Fix self-redirect copied_seq double-counting Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 817/982] HID: amd_sfh: Validate PCI BAR size before mapping Greg Kroah-Hartman
` (172 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Anderson, Neil Armstrong,
Linus Walleij, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Anderson <sanderson@brivo.com>
[ Upstream commit 692f32609a30f75ca3401e25b504bfd06bd5662a ]
One of the i2c pin groups has some junk at the end. The name should be
i2c2_scl_h1, and indeed that's the name used by i2c2_pins3 in
meson-s4.dtsi.
Fixes: 775214d389c25 ("pinctrl: meson: add pinctrl driver support for Meson-S4 Soc")
Signed-off-by: Sean Anderson <sanderson@brivo.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/meson/pinctrl-meson-s4.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pinctrl/meson/pinctrl-meson-s4.c b/drivers/pinctrl/meson/pinctrl-meson-s4.c
index cea77864b8808..b61d562f9a9fa 100644
--- a/drivers/pinctrl/meson/pinctrl-meson-s4.c
+++ b/drivers/pinctrl/meson/pinctrl-meson-s4.c
@@ -854,7 +854,7 @@ static const char * const i2c1_groups[] = {
static const char * const i2c2_groups[] = {
"i2c2_sda_d", "i2c2_scl_d",
"i2c2_sda_h8", "i2c2_scl_h9",
- "i2c2_sda_h0", "i2c2_scl_h1l,"
+ "i2c2_sda_h0", "i2c2_scl_h1",
};
static const char * const i2c3_groups[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 817/982] HID: amd_sfh: Validate PCI BAR size before mapping
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (815 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 816/982] pinctrl: meson: Fix typo in s4 group name Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 818/982] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Greg Kroah-Hartman
` (171 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+4eadd4dfe9e66522bae8,
Slawomir Stepien, Basavaraj Natikar, Jiri Kosina, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slawomir Stepien <sst@poczta.fm>
[ Upstream commit 65bcc5f89704efe5b9d69d4ea2c1002d90c31382 ]
The amd_sfh driver maps PCI BAR 2 using pcim_iomap_regions() and
subsequently accesses MMIO registers at offsets up to 0x10958 (e.g.,
AMD_P2C_MSG3 at 0x1068C). However, the driver never validates that the BAR
size is large enough to cover these accesses. If the driver is bound to a
device with a smaller BAR 2, this leads to an out-of-bounds memory access
and a page fault during the probe function.
For example, a page fault can occur when reading from privdata->mmio +
AMD_P2C_MSG3 in mp2_select_ops():
BUG: unable to handle page fault for address: ffffc9000390368c
PGD 100000067 P4D 100000067 PUD 1012c1067 PMD 105b64067 PTE 0
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:readl arch/x86/include/asm/io.h:59 [inline]
RIP: 0010:mp2_select_ops drivers/hid/amd-sfh-hid/amd_sfh_pcie.c:282
[inline]
RIP: 0010:amd_mp2_pci_probe+0x337/0x5f0
drivers/hid/amd-sfh-hid/amd_sfh_pcie.c:487
Call Trace:
<TASK>
local_pci_probe drivers/pci/pci-driver.c:332 [inline]
pci_call_probe drivers/pci/pci-driver.c:394 [inline]
__pci_device_probe drivers/pci/pci-driver.c:455 [inline]
pci_device_probe+0x431/0xc90 drivers/pci/pci-driver.c:489
Fix this by verifying that the length of BAR 2 is at least 128KB before
attempting to map it. Since the maximum accessed offset is 0x10958, and PCI
BAR sizes are powers of 2, any legitimate hardware will have a BAR size of
at least 128KB.
Fixes: 4f567b9f8141 ("SFH: PCIe driver to add support of AMD sensor fusion hub")
Assisted-by: Gemini:gemini-3.7-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+4eadd4dfe9e66522bae8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Link: https://syzkaller.appspot.com/ai_job?id=3bc1c45c-548f-4ab5-8243-d2c8ec321d6c
Signed-off-by: Slawomir Stepien <sst@poczta.fm>
Acked-by: Basavaraj Natikar <Basavaraj.Natikar@amd.com>
Link: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/amd-sfh-hid/amd_sfh_common.h | 4 ++++
drivers/hid/amd-sfh-hid/amd_sfh_pcie.c | 10 ++++++++++
2 files changed, 14 insertions(+)
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_common.h b/drivers/hid/amd-sfh-hid/amd_sfh_common.h
index 2643bb14fee27..0aeb670ae1a4f 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_common.h
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_common.h
@@ -11,11 +11,15 @@
#define AMD_SFH_COMMON_H
#include <linux/pci.h>
+#include <linux/sizes.h>
#include "amd_sfh_hid.h"
#define PCI_DEVICE_ID_AMD_MP2 0x15E4
#define PCI_DEVICE_ID_AMD_MP2_1_1 0x164A
+/* The BAR 2 size must cover the highest register offset (0x10958) */
+#define AMD_SFH_MIN_BAR_SIZE SZ_128K
+
#define AMD_C2P_MSG(regno) (0x10500 + ((regno) * 4))
#define AMD_P2C_MSG(regno) (0x10680 + ((regno) * 4))
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
index 9c963ad27f9d1..20d898a70b8a2 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
@@ -345,6 +345,16 @@ static int amd_mp2_pci_probe(struct pci_dev *pdev, const struct pci_device_id *i
if (rc)
return rc;
+ if (!(pci_resource_flags(pdev, 2) & IORESOURCE_MEM)) {
+ dev_err(&pdev->dev, "BAR 2 is not IORESOURCE_MEM\n");
+ return -ENODEV;
+ }
+
+ if (pci_resource_len(pdev, 2) < AMD_SFH_MIN_BAR_SIZE) {
+ dev_err(&pdev->dev, "BAR 2 is too small\n");
+ return -EINVAL;
+ }
+
rc = pcim_iomap_regions(pdev, BIT(2), DRIVER_NAME);
if (rc)
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 818/982] squashfs: Add dictionary size range check to prevent shift-out-of-bounds
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (816 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 817/982] HID: amd_sfh: Validate PCI BAR size before mapping Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 819/982] Bluetooth: SMP: reject Security Request over BR/EDR Greg Kroah-Hartman
` (170 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ran Hongyun, Phillip Lougher,
Zhihao Cheng, Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ran Hongyun <ranhongyun1@huawei.com>
[ Upstream commit 1f7745fb3580152ca902ef181b605f33cabfb1d0 ]
When an abnormal SquashFS image (COMP_OPTS flag is 1 but dictionary size
is 0) is mounted, and performs shift operations using dictionarysize, the
shift exponent is -1, causing a shift-out-of-bounds.
Detail as below:
squashfs_comp_opts(msblk, buffer, length)
squashfs_xz_comp_opts()
if (comp_opts)
n = ffs(opts->dict_size) - 1;<----opts->dict_size=0, n=-1
if (opts->dict_size != (1 << n) && opts->dict_size !=
(1 << n) + (1 << (n + 1))) <----shift-out-of-bounds
Fix it by adding a dictionary size range check before the shift operation.
Fixes: ff750311d30a ("Squashfs: add compression options support to xz decompressor")
Signed-off-by: Ran Hongyun <ranhongyun1@huawei.com>
Link: https://patch.msgid.link/20260713115525.2661734-1-ranhongyun1@huawei.com
Reviewed-by: Phillip Lougher <phillip@squashfs.org.uk>
Reviewed-by: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/squashfs/xz_wrapper.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/fs/squashfs/xz_wrapper.c b/fs/squashfs/xz_wrapper.c
index 6c49481a2f8c4..7d54cd524d6d9 100644
--- a/fs/squashfs/xz_wrapper.c
+++ b/fs/squashfs/xz_wrapper.c
@@ -57,10 +57,10 @@ static void *squashfs_xz_comp_opts(struct squashfs_sb_info *msblk,
opts->dict_size = le32_to_cpu(comp_opts->dictionary_size);
- /* the dictionary size should be 2^n or 2^n+2^(n+1) */
+ /* the dictionary size should be positive and 2^n or 2^n+2^(n+1) */
n = ffs(opts->dict_size) - 1;
- if (opts->dict_size != (1 << n) && opts->dict_size != (1 << n) +
- (1 << (n + 1))) {
+ if (opts->dict_size <= 0 || (opts->dict_size != (1 << n) &&
+ opts->dict_size != (1 << n) + (1 << (n + 1)))) {
err = -EIO;
goto out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 819/982] Bluetooth: SMP: reject Security Request over BR/EDR
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (817 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 818/982] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 820/982] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel Greg Kroah-Hartman
` (169 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christiano Amora,
Luiz Augusto von Dentz, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christiano Amora <christiano.amora@gmail.com>
[ Upstream commit f033482d76a9f18080c7a40c5f9c678bd7adc8f3 ]
Bose QC Ultra Headphones (dual-mode, same public address on both
transports) occasionally send an SMP Security Request on the BR/EDR
SMP fixed channel right after the ACL link is encrypted. The kernel
handles it as if it were an LE link: smp_cmd_security_req() has no
transport check, smp_ltk_encrypt() looks up an LTK with the ACL
connection's dst_type, and hci_find_ltk() matches the peer's LE LTK
because the LE public address type is stored as ADDR_LE_DEV_PUBLIC (0),
the same value as BDADDR_BREDR. HCI_OP_LE_START_ENC is then issued on
the ACL handle, the controller rejects it with Invalid HCI Command
Parameters, and hci_cs_le_start_enc() disconnects the link with
HCI_ERROR_AUTH_FAILURE. The headphones drop within a second of
connecting, before any profile is up; a manual reconnect works.
btmon (MediaTek MT7922, kernel 7.0.12):
> HCI Event: Encryption Change (0x08) plen 4
Status: Success (0x00)
Handle: 50 Address: BC:87:FA:47:73:5E (Bose Corporation)
Encryption: Enabled with AES-CCM (0x02)
> ACL Data RX: Handle 50 flags 0x02 dlen 6
BR/EDR SMP: Security Request (0x0b) len 1
Authentication requirement: No bonding, No MITM, SC (0x08)
< HCI Command: LE Start Encryption (0x08|0x0019) plen 28
Handle: 50 Address: BC:87:FA:47:73:5E (Bose Corporation)
> HCI Event: Command Status (0x0f) plen 4
LE Start Encryption (0x08|0x0019) ncmd 1
Status: Invalid HCI Command Parameters (0x12)
< HCI Command: Disconnect (0x01|0x0006) plen 3
Handle: 50 Address: BC:87:FA:47:73:5E (Bose Corporation)
Reason: Authentication Failure (0x05)
SMP over BR/EDR is limited to cross-transport key derivation; the
Security Request procedure (Core Specification Vol 3, Part H, Section
2.4.6, PDU in Section 3.6.7) has no BR/EDR counterpart. Reply with
Pairing Failed / Command Not Supported on a non-LE link, before the PDU
is parsed, and keep the connection. The reply is sent directly rather
than through smp_failure(): rejecting a command on the wrong transport
is not an authentication failure, and MGMT_EV_AUTH_FAILED would make
bluetoothd disconnect the device.
Tested on the affected host (kernel 7.0.12, MediaTek MT7922, Bose QC
Ultra) with the patched module built out of tree: 7 days and 49
reconnects without a drop, against 2 drops in the 3 days before the
patch. Every disconnect in that week had a userspace or remote reason.
Fixes: b5ae344d4c0f ("Bluetooth: Add full SMP BR/EDR support")
Assisted-by: LLM
Signed-off-by: Christiano Amora <christiano.amora@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/smp.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/net/bluetooth/smp.c b/net/bluetooth/smp.c
index 1f8561112ec14..1700e295f14da 100644
--- a/net/bluetooth/smp.c
+++ b/net/bluetooth/smp.c
@@ -2295,6 +2295,23 @@ static u8 smp_cmd_security_req(struct l2cap_conn *conn, struct sk_buff *skb)
bt_dev_dbg(hdev, "conn %p", conn);
+ /* SMP over BR/EDR only covers cross-transport key derivation; the
+ * Security Request procedure has no BR/EDR counterpart. Reject it
+ * here, otherwise smp_ltk_encrypt() finds the peer's LE LTK
+ * (ADDR_LE_DEV_PUBLIC and BDADDR_BREDR are both 0) and issues
+ * HCI_OP_LE_START_ENC on the ACL handle, which the controller
+ * rejects and hci_cs_le_start_enc() turns into a disconnect. Reply
+ * without smp_failure(): this is not an authentication failure, and
+ * MGMT_EV_AUTH_FAILED would make bluetoothd drop the device.
+ */
+ if (hcon->type != LE_LINK) {
+ u8 reason = SMP_CMD_NOTSUPP;
+
+ smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason),
+ &reason);
+ return 0;
+ }
+
if (skb->len < sizeof(*rp))
return SMP_INVALID_PARAMS;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 820/982] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (818 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 819/982] Bluetooth: SMP: reject Security Request over BR/EDR Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 821/982] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() Greg Kroah-Hartman
` (168 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lee Jones, Luiz Augusto von Dentz,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lee Jones <lee@kernel.org>
[ Upstream commit 71af682ba4692c2ed9ace4c3d4ca462ae368c029 ]
In send_cancel(), pending mesh_tx objects are removed from the
hdev->mesh_pending list and freed via mesh_send_complete(). However, if
a mesh transmission was already queued onto hdev->cmd_sync_work_list via
mesh_next(), the queued entry retains a raw pointer to mesh_tx.
When hci_cmd_sync_work later processes the entry, it attempts to execute
mesh_send_sync and its destroy callback mesh_send_start_complete using
the already freed mesh_tx pointer, leading to a use-after-free.
Fix this by invoking hci_cmd_sync_dequeue() for mesh_send_sync on the
target mesh_tx before completing it. If the entry is found and dequeued,
its destroy callback will complete and free the object; otherwise,
mesh_send_complete() is called directly.
Additionally, ensure the transmission queue advances after cancellation
or errors. In mesh_send_start_complete(), call mesh_next() on error
unless err is -ECANCELED, because hci_cmd_sync_dequeue() holds
hdev->cmd_sync_work_lock and calling mesh_next() synchronously would
deadlock. Instead, advance the queue in send_cancel() once the lock is
released and if no transmission is in progress.
Fixes: b338d91703fa ("Bluetooth: Implement support for Mesh")
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/mgmt.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index 6a3f4afc9760a..251e0c0a062a7 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -2217,6 +2217,8 @@ static void mesh_send_start_complete(struct hci_dev *hdev, void *data, int err)
hci_dev_clear_flag(hdev, HCI_MESH_SENDING);
/* Send Complete Error Code for handle */
mesh_send_complete(hdev, mesh_tx, false);
+ if (err != -ECANCELED)
+ mesh_next(hdev, NULL, 0);
return;
}
@@ -2326,19 +2328,28 @@ static int send_cancel(struct hci_dev *hdev, void *data)
do {
mesh_tx = mgmt_mesh_next(hdev, cmd->sk);
- if (mesh_tx)
- mesh_send_complete(hdev, mesh_tx, false);
+ if (mesh_tx) {
+ if (!hci_cmd_sync_dequeue(hdev, mesh_send_sync,
+ mesh_tx, NULL))
+ mesh_send_complete(hdev, mesh_tx, false);
+ }
} while (mesh_tx);
} else {
mesh_tx = mgmt_mesh_find(hdev, cancel->handle);
- if (mesh_tx && mesh_tx->sk == cmd->sk)
- mesh_send_complete(hdev, mesh_tx, false);
+ if (mesh_tx && mesh_tx->sk == cmd->sk) {
+ if (!hci_cmd_sync_dequeue(hdev, mesh_send_sync,
+ mesh_tx, NULL))
+ mesh_send_complete(hdev, mesh_tx, false);
+ }
}
mgmt_cmd_complete(cmd->sk, hdev->id, MGMT_OP_MESH_SEND_CANCEL,
0, NULL, 0);
+ if (!hci_dev_test_flag(hdev, HCI_MESH_SENDING))
+ mesh_next(hdev, NULL, 0);
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 821/982] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (819 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 820/982] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 822/982] Documentation: s390: correct spelling Greg Kroah-Hartman
` (167 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kashyap Desai, Sumit Saxena,
Shivasharan S, Chandrakanth patil, Bart Van Assche,
Martin K. Petersen (Oracle), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
[ Upstream commit 42d1221d321e55afc7bba9109a77aaf5a817c8a3 ]
Protect the megasas_get_ctrl_info() call in megasas_resume() with
instance->reset_mutex using scoped_guard().
megasas_get_ctrl_info() may release and reacquire instance->reset_mutex.
Hence, calling this function without holding instance->reset_mutex is not
safe.
Fixes: c3b10a55abc9 ("scsi: megaraid_sas: Update controller info during resume")
Cc: Kashyap Desai <kashyap.desai@broadcom.com>
Cc: Sumit Saxena <sumit.saxena@broadcom.com>
Cc: Shivasharan S <shivasharan.srikanteshwara@broadcom.com>
Cc: Chandrakanth patil <chandrakanth.patil@broadcom.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/f06b5ee432b21cf293f0663e15b64f75a84b9fd5.1788204406.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/megaraid/megaraid_sas_base.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/megaraid/megaraid_sas_base.c b/drivers/scsi/megaraid/megaraid_sas_base.c
index 0d398029b2afe..483df636fe865 100644
--- a/drivers/scsi/megaraid/megaraid_sas_base.c
+++ b/drivers/scsi/megaraid/megaraid_sas_base.c
@@ -7872,7 +7872,9 @@ megasas_resume(struct device *dev)
goto fail_init_mfi;
}
- if (megasas_get_ctrl_info(instance) != DCMD_SUCCESS)
+ scoped_guard(mutex, &instance->reset_mutex)
+ rval = megasas_get_ctrl_info(instance);
+ if (rval != DCMD_SUCCESS)
goto fail_init_mfi;
tasklet_init(&instance->isr_tasklet, instance->instancet->tasklet,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 822/982] Documentation: s390: correct spelling
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (820 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 821/982] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.1 823/982] docs: s390/pci: Improve and update PCI documentation Greg Kroah-Hartman
` (166 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Randy Dunlap, Heiko Carstens,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Randy Dunlap <rdunlap@infradead.org>
[ Upstream commit ac56c666f80df0b1dc9c3ef53d0798b74629a116 ]
Correct spelling problems for Documentation/s390/ as reported
by codespell.
Signed-off-by: Randy Dunlap <rdunlap@infradead.org>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Link: https://lore.kernel.org/r/20230209071400.31476-16-rdunlap@infradead.org
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Stable-dep-of: 4525a9110495 ("s390/pci/docs: Fix sriov_numvfs attribute name")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/s390/pci.rst | 4 ++--
Documentation/s390/vfio-ccw.rst | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/Documentation/s390/pci.rst b/Documentation/s390/pci.rst
index 8157f0cddbc24..a1a72a47dc960 100644
--- a/Documentation/s390/pci.rst
+++ b/Documentation/s390/pci.rst
@@ -51,7 +51,7 @@ Entries specific to zPCI functions and entries that hold zPCI information.
The slot entries are set up using the function identifier (FID) of the
PCI function. The format depicted as XXXXXXXX above is 8 hexadecimal digits
- with 0 padding and lower case hexadecimal digitis.
+ with 0 padding and lower case hexadecimal digits.
- /sys/bus/pci/slots/XXXXXXXX/power
@@ -66,7 +66,7 @@ Entries specific to zPCI functions and entries that hold zPCI information.
- function_handle
Low-level identifier used for a configured PCI function.
- It might be useful for debuging.
+ It might be useful for debugging.
- pchid
Model-dependent location of the I/O adapter.
diff --git a/Documentation/s390/vfio-ccw.rst b/Documentation/s390/vfio-ccw.rst
index ea928a3806f43..945a5b57a56d5 100644
--- a/Documentation/s390/vfio-ccw.rst
+++ b/Documentation/s390/vfio-ccw.rst
@@ -176,7 +176,7 @@ The process of how these work together.
Use the 'mdev_create' sysfs file, we need to manually create one (and
only one for our case) mediated device.
3. vfio_mdev.ko drives the mediated ccw device.
- vfio_mdev is also the vfio device drvier. It will probe the mdev and
+ vfio_mdev is also the vfio device driver. It will probe the mdev and
add it to an iommu_group and a vfio_group. Then we could pass through
the mdev to a guest.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 823/982] docs: s390/pci: Improve and update PCI documentation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (821 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 822/982] Documentation: s390: correct spelling Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 824/982] s390/pci/docs: Fix sriov_numvfs attribute name Greg Kroah-Hartman
` (165 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Farhan Ali, Randy Dunlap,
Matthew Rosato, Niklas Schnelle, Gerd Bayer, Vasily Gorbik,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Schnelle <schnelle@linux.ibm.com>
[ Upstream commit 737c4f4a241ca85c597ca2ef1a6f8446bf681ab5 ]
Update the s390 specific PCI documentation to better reflect current
behavior and terms such as the handling of Isolated VFs via commit
25f39d3dcb48 ("s390/pci: Ignore RID for isolated VFs").
Add a descriptions for /sys/firmware/clp/uid_checking which was added
in commit b043a81ce3ee ("s390/pci: Expose firmware provided UID Checking
state in sysfs") but missed documentation.
Similarly add documentation for the fidparm attribute added by commit
99ad39306a62 ("s390/pci: Expose FIDPARM attribute in sysfs") and
add a list of pft values and their names.
Finally improve formatting of the different attribute descriptions by
adding a separating colon.
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Acked-by: Randy Dunlap <rdunlap@infradead.org>
Tested-by: Randy Dunlap <rdunlap@infradead.org>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Gerd Bayer <gbayer@linux.ibm.com>
Link: https://lore.kernel.org/r/20260407-uid_slot-v8-1-15ae4409d2ce@linux.ibm.com
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Stable-dep-of: 4525a9110495 ("s390/pci/docs: Fix sriov_numvfs attribute name")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/s390/pci.rst | 152 ++++++++++++++++++++++++-------------
1 file changed, 101 insertions(+), 51 deletions(-)
diff --git a/Documentation/s390/pci.rst b/Documentation/s390/pci.rst
index a1a72a47dc960..d4cafd92529f0 100644
--- a/Documentation/s390/pci.rst
+++ b/Documentation/s390/pci.rst
@@ -6,6 +6,7 @@ S/390 PCI
Authors:
- Pierre Morel
+ - Niklas Schnelle
Copyright, IBM Corp. 2020
@@ -27,14 +28,16 @@ Command line parameters
debugfs entries
---------------
-The S/390 debug feature (s390dbf) generates views to hold various debug results in sysfs directories of the form:
+The S/390 debug feature (s390dbf) generates views to hold various debug results
+in sysfs directories of the form:
* /sys/kernel/debug/s390dbf/pci_*/
For example:
- /sys/kernel/debug/s390dbf/pci_msg/sprintf
- Holds messages from the processing of PCI events, like machine check handling
+
+ holds messages from the processing of PCI events, like machine check handling
and setting of global functionality, like UID checking.
Change the level of logging to be more or less verbose by piping
@@ -47,87 +50,134 @@ Sysfs entries
Entries specific to zPCI functions and entries that hold zPCI information.
-* /sys/bus/pci/slots/XXXXXXXX
+* /sys/bus/pci/slots/XXXXXXXX:
- The slot entries are set up using the function identifier (FID) of the
- PCI function. The format depicted as XXXXXXXX above is 8 hexadecimal digits
- with 0 padding and lower case hexadecimal digits.
+ The slot entries are set up using the function identifier (FID) of the PCI
+ function as slot name. The format depicted as XXXXXXXX above is 8 hexadecimal
+ digits with 0 padding and lower case hexadecimal digits.
- /sys/bus/pci/slots/XXXXXXXX/power
A physical function that currently supports a virtual function cannot be
powered off until all virtual functions are removed with:
- echo 0 > /sys/bus/pci/devices/XXXX:XX:XX.X/sriov_numvf
+ echo 0 > /sys/bus/pci/devices/DDDD:BB:dd.f/sriov_numvf
-* /sys/bus/pci/devices/XXXX:XX:XX.X/
+* /sys/bus/pci/devices/DDDD:BB:dd.f/:
- - function_id
- A zPCI function identifier that uniquely identifies the function in the Z server.
+ - function_id:
+ The zPCI function identifier (FID) is a 32-bit hexadecimal value that
+ uniquely identifies the PCI function. Unless the hypervisor provides
+ a virtual FID e.g. on KVM this identifier is unique across the machine even
+ between different partitions.
- - function_handle
- Low-level identifier used for a configured PCI function.
- It might be useful for debugging.
+ - function_handle:
+ This 32-bit hexadecimal value is a low-level identifier used for a PCI
+ function. Note that the function handle may be changed and become invalid
+ on PCI events and when enabling/disabling the PCI function.
- - pchid
- Model-dependent location of the I/O adapter.
+ - pchid:
+ This 16-bit hexadecimal value encodes a model-dependent location for
+ the PCI function.
- - pfgid
- PCI function group ID, functions that share identical functionality
+ - pfgid:
+ PCI function group ID; functions that share identical functionality
use a common identifier.
A PCI group defines interrupts, IOMMU, IOTLB, and DMA specifics.
- - vfn
+ - vfn:
The virtual function number, from 1 to N for virtual functions,
0 for physical functions.
- - pft
- The PCI function type
-
- - port
- The port corresponds to the physical port the function is attached to.
- It also gives an indication of the physical function a virtual function
- is attached to.
-
- - uid
- The user identifier (UID) may be defined as part of the machine
- configuration or the z/VM or KVM guest configuration. If the accompanying
- uid_is_unique attribute is 1 the platform guarantees that the UID is unique
- within that instance and no devices with the same UID can be attached
- during the lifetime of the system.
-
- - uid_is_unique
- Indicates whether the user identifier (UID) is guaranteed to be and remain
- unique within this Linux instance.
-
- - pfip/segmentX
+ - pft:
+ The PCI function type is an s390-specific type attribute. It indicates
+ a more general, usage oriented, type than PCI Specification
+ class/vendor/device identifiers. That is PCI functions with the same pft
+ value may be backed by different hardware implementations. At the same time
+ apart from unclassified functions (pft is 0x00) the same pft value
+ generally implies a similar usage model. At the same time the same
+ PCI hardware device may appear with different pft values when in a
+ different usage model. For example NETD and NETH VFs may be implemented
+ by the same PCI hardware device but in NETD the parent Physical Function
+ is user managed while with NETH it is platform managed.
+
+ Currently the following PFT values are defined:
+
+ - 0x00 (UNC): Unclassified
+ - 0x02 (ROCE): RoCE Express
+ - 0x05 (ISM): Internal Shared Memory
+ - 0x0a (ROC2): RoCE Express 2
+ - 0x0b (NVMe): NVMe
+ - 0x0c (NETH): Network Express hybrid
+ - 0x0d (CNW): Cloud Network Adapter
+ - 0x0f (NETD): Network Express direct
+
+ - port:
+ The port is a decimal value corresponding to the physical port the function
+ is attached to. Virtual Functions (VFs) share the port with their parent
+ Physical Function (PF). A value of 0 indicates that the port attribute is
+ not applicable for that PCI function type.
+
+ - uid:
+ The user-defined identifier (UID) for a PCI function is a 32-bit
+ hexadecimal value. It is defined on a per instance basis as part of the
+ partition, KVM guest, or z/VM guest configuration. If UID Checking is
+ enabled the platform ensures that the UID is unique within that instance
+ and no two PCI functions with the same UID will be visible to the instance.
+
+ Independent of this guarantee and unlike the function ID (FID) the UID may
+ be the same in different partitions within the same machine. This allows to
+ create PCI configurations in multiple partitions to be identical in the
+ UID-namespace.
+
+ - uid_is_unique:
+ A 0 or 1 flag indicating whether the user-defined identifier (UID) is
+ guaranteed to be and remain unique within this Linux instance. This
+ platform feature is called UID Checking.
+
+ - pfip/segmentX:
The segments determine the isolation of a function.
They correspond to the physical path to the function.
The more the segments are different, the more the functions are isolated.
+ - fidparm:
+ Contains an 8-bit-per-PCI function parameter field in hexadecimal provided
+ by the platform. The meaning of this field is PCI function type specific.
+ For NETH VFs a value of 0x01 indicates that the function supports
+ promiscuous mode.
+
+* /sys/firmware/clp/uid_checking:
+
+ In addition to the per-device uid_is_unique attribute this presents a
+ global indication of whether UID Checking is enabled. This allows users
+ to check for UID Checking even when no PCI functions are configured.
+
Enumeration and hotplug
=======================
The PCI address consists of four parts: domain, bus, device and function,
-and is of this form: DDDD:BB:dd.f
+and is of this form: DDDD:BB:dd.f.
-* When not using multi-functions (norid is set, or the firmware does not
- support multi-functions):
+* For a PCI function for which the platform does not expose the RID, the
+ pci=norid kernel parameter is used, or a so-called isolated Virtual Function
+ which does have RID information but is used without its parent Physical
+ Function being part of the same PCI configuration:
- There is only one function per domain.
- - The domain is set from the zPCI function's UID as defined during the
- LPAR creation.
+ - The domain is set from the zPCI function's UID if UID Checking is on;
+ otherwise the domain ID is generated dynamically and is not stable
+ across reboots or hot plug.
-* When using multi-functions (norid parameter is not set),
- zPCI functions are addressed differently:
+* For a PCI function for which the platform exposes the RID and which
+ is not an Isolated Virtual Function:
- There is still only one bus per domain.
- - There can be up to 256 functions per bus.
+ - There can be up to 256 PCI functions per bus.
- - The domain part of the address of all functions for
- a multi-Function device is set from the zPCI function's UID as defined
- in the LPAR creation for the function zero.
+ - The domain part of the address of all functions within the same topology is
+ that of the configured PCI function with the lowest devfn within that
+ topology.
- - New functions will only be ready for use after the function zero
- (the function with devfn 0) has been enumerated.
+ - Virtual Functions generated by an SR-IOV capable Physical Function only
+ become visible once SR-IOV is enabled.
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 824/982] s390/pci/docs: Fix sriov_numvfs attribute name
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (822 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 6.1 823/982] docs: s390/pci: Improve and update PCI documentation Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 825/982] s390/cio: Fix cio_update_schib() to not cache invalid schib Greg Kroah-Hartman
` (164 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Randy Dunlap,
Heiko Carstens, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 4525a911049543c23885a540a788d13be318a486 ]
The attribute is sriov_numvfs (drivers/pci/iov.c); the document names it
sriov_numvf, which does not exist.
Use sriov_numvfs.
Fixes: de267a7c71ba ("s390/pci: Documentation for zPCI")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/s390/pci.rst | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/s390/pci.rst b/Documentation/s390/pci.rst
index d4cafd92529f0..c487e41d6ba28 100644
--- a/Documentation/s390/pci.rst
+++ b/Documentation/s390/pci.rst
@@ -60,7 +60,7 @@ Entries specific to zPCI functions and entries that hold zPCI information.
A physical function that currently supports a virtual function cannot be
powered off until all virtual functions are removed with:
- echo 0 > /sys/bus/pci/devices/DDDD:BB:dd.f/sriov_numvf
+ echo 0 > /sys/bus/pci/devices/DDDD:BB:dd.f/sriov_numvfs
* /sys/bus/pci/devices/DDDD:BB:dd.f/:
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 825/982] s390/cio: Fix cio_update_schib() to not cache invalid schib
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (823 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 824/982] s390/pci/docs: Fix sriov_numvfs attribute name Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 826/982] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points Greg Kroah-Hartman
` (163 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bezenah, Vineeth Vijayan,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
[ Upstream commit 29d9e5835d89223aa913dcf7b942cc1c148bdd25 ]
When pmcw.dnv is 0, the contents of all SCHIB fields are unpredictable.
Zero sch->schib in that case to prevent subsequent code from making
decisions based on unpredictable data.
Reported-by: William Bezenah <wbezenah@linux.ibm.com>
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Fixes: 8c58a229688c ("s390/cio: Do not unregister the subchannel based on DNV")
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/cio/cio.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/s390/cio/cio.c b/drivers/s390/cio/cio.c
index 54bfa9fe3031b..dc798baf4d49d 100644
--- a/drivers/s390/cio/cio.c
+++ b/drivers/s390/cio/cio.c
@@ -453,7 +453,8 @@ EXPORT_SYMBOL_GPL(cio_commit_config);
/**
* cio_update_schib - Perform stsch and update schib if subchannel is valid.
* @sch: subchannel on which to perform stsch
- * Return zero on success, -ENODEV otherwise.
+ * Return zero on success, -ENODEV if the subchannel is not operational,
+ * -EACCES if the subchannel has no valid device.
*/
int cio_update_schib(struct subchannel *sch)
{
@@ -462,10 +463,12 @@ int cio_update_schib(struct subchannel *sch)
if (stsch(sch->schid, &schib))
return -ENODEV;
- memcpy(&sch->schib, &schib, sizeof(schib));
-
- if (!css_sch_is_valid(&schib))
+ if (!css_sch_is_valid(&schib)) {
+ memset(&sch->schib, 0, sizeof(sch->schib));
return -EACCES;
+ }
+
+ memcpy(&sch->schib, &schib, sizeof(schib));
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 826/982] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (824 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 825/982] s390/cio: Fix cio_update_schib() to not cache invalid schib Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 827/982] fs: avoid repeated scans in evict_inodes() Greg Kroah-Hartman
` (162 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bezenah, Vineeth Vijayan,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
[ Upstream commit f6f2985eabdb2bfdc82ce90a1ea3ec53ba795f34 ]
The device number valid (dnv) bit in the PMCW must be checked before
acting on any other PMCW fields for IO-type subchannels. A subchannel
with dnv=0 has no valid device number associated, making it meaningless
to evaluate the enabled (ena) state or issue any I/O instruction against
it.
Reported-by: William Bezenah <wbezenah@linux.ibm.com>
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Fixes: 8c58a229688c ("s390/cio: Do not unregister the subchannel based on DNV")
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/cio/device_ops.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/drivers/s390/cio/device_ops.c b/drivers/s390/cio/device_ops.c
index a5dba3829769c..a18919a50909a 100644
--- a/drivers/s390/cio/device_ops.c
+++ b/drivers/s390/cio/device_ops.c
@@ -142,6 +142,8 @@ int ccw_device_clear(struct ccw_device *cdev, unsigned long intparm)
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -198,6 +200,8 @@ int ccw_device_start_timeout_key(struct ccw_device *cdev, struct ccw1 *cpa,
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -375,6 +379,8 @@ int ccw_device_halt(struct ccw_device *cdev, unsigned long intparm)
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -409,6 +415,8 @@ int ccw_device_resume(struct ccw_device *cdev)
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -544,6 +552,8 @@ int ccw_device_tm_start_timeout_key(struct ccw_device *cdev, struct tcw *tcw,
int rc;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_VERIFY) {
@@ -686,6 +696,8 @@ int ccw_device_tm_intrg(struct ccw_device *cdev)
{
struct subchannel *sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state != DEV_STATE_ONLINE)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 827/982] fs: avoid repeated scans in evict_inodes()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (825 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 826/982] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 828/982] xsk: Use a 32-bit compare in xsk_map_gen_lookup Greg Kroah-Hartman
` (161 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Sun, Jan Kara,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Sun <sunjunchao@bytedance.com>
[ Upstream commit 7459c021874246c196f397686e100702f059b9e7 ]
We observed hung tasks when users attempted to unmount a filesystem
after its disk had been removed while still in use. During device
removal, fs_bdev_mark_dead() calls evict_inodes() while holding s_umount.
Each time evict_inodes() drops s_inode_list_lock to reschedule, it
restarts the walk from the head of s_inodes. With many referenced inodes
at the head of the list, these restarts repeatedly scan the same inodes
without reclaiming them. This can keep s_umount held for a long time,
blocking concurrent umount attempts and triggering hung-task reports.
Keep the current inode, already marked I_FREEING, out of the disposal
batch until s_inode_list_lock is reacquired. Resume the walk from this
inode and dispose of it in a later batch or at the end of the walk.
The zero-refcount and state checks under i_lock allow this walker to
claim the inode by setting I_FREEING and removing it from the LRU.
Other reclaimers skip the inode, leaving this walker responsible for
eviction. Only evict() removes it from s_inodes, so keeping it out of
the disposal batch ensures that it remains on the list while the lock
is dropped. After reacquiring the lock, reading its current next pointer
accounts for concurrent removal of following inodes.
The existing inode lifetime rules prohibit acquiring a reference to an
inode marked I_FREEING or I_WILL_FREE. __iget() requires its caller to
hold i_lock and establish that taking a reference is valid. Inode lookup
and igrab() check these flags under i_lock when acquiring a reference
from zero. ihold() requires an existing reference, which would keep
i_count nonzero and prevent this walker from claiming the inode. These
rules already allow iput_final() and the inode shrinker to release
i_lock after setting I_FREEING and before eviction completes.
A temporary __iget() reference would also keep the inode on the list,
but its release must preserve last-reference handling. Another user can
acquire a reference, update lazy timestamps and drop its reference while
the pin is held. If the pin becomes the last reference, dropping it with
atomic_dec_and_test() and evicting directly bypasses iput()'s lazytime
handling and can lose those timestamp updates.
Releasing the pin with iput() preserves that handling, but does not
guarantee eviction. fs_bdev_mark_dead() runs with SB_ACTIVE set, so iput()
may retain the inode in cache, whereas evict_inodes() must evict eligible
zero-reference inodes. The inode may also have been freed when iput()
returns, so the walker cannot then use it to force eviction. Using
I_FREEING preserves the existing eviction behavior without introducing
an additional last-reference transition.
The xfstests auto group passed on ext4 and XFS with known unrelated
failures excluded. No new issues were observed, and the previously
reproducible hung task no longer occurs with this patch.
Fixes: ac05fbb40062 ("inode: don't softlockup when evicting inodes")
Signed-off-by: Julian Sun <sunjunchao@bytedance.com>
Link: https://patch.msgid.link/20260915044912.3183440-1-sunjunchao@bytedance.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/inode.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/fs/inode.c b/fs/inode.c
index 0036d5c68fd41..f3af99ce154d3 100644
--- a/fs/inode.c
+++ b/fs/inode.c
@@ -754,7 +754,6 @@ void evict_inodes(struct super_block *sb)
struct inode *inode, *next;
LIST_HEAD(dispose);
-again:
spin_lock(&sb->s_inode_list_lock);
list_for_each_entry_safe(inode, next, &sb->s_inodes, i_sb_list) {
if (atomic_read(&inode->i_count))
@@ -773,19 +772,19 @@ void evict_inodes(struct super_block *sb)
inode->i_state |= I_FREEING;
inode_lru_list_del(inode);
spin_unlock(&inode->i_lock);
- list_add(&inode->i_lru, &dispose);
/*
- * We can have a ton of inodes to evict at unmount time given
- * enough memory, check to see if we need to go to sleep for a
- * bit so we don't livelock.
+ * Keep this inode out of dispose so it stays on s_inodes while
+ * the list lock is dropped. I_FREEING prevents new references
+ * and leaves eviction to us, so we can resume the walk from it.
*/
if (need_resched()) {
spin_unlock(&sb->s_inode_list_lock);
cond_resched();
dispose_list(&dispose);
- goto again;
+ spin_lock(&sb->s_inode_list_lock);
}
+ list_add(&inode->i_lru, &dispose);
}
spin_unlock(&sb->s_inode_list_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 828/982] xsk: Use a 32-bit compare in xsk_map_gen_lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (826 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 827/982] fs: avoid repeated scans in evict_inodes() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 829/982] bpf: Skip unsettled links in link iterator Greg Kroah-Hartman
` (160 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou,
Alexei Starovoitov, Emil Tsalapatis, Eduard Zingerman,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
[ Upstream commit 70504de0bb627848667207bec7ccfd647deb8814 ]
xsk_map_gen_lookup() loads a u32 key and compares it with max_entries
using BPF_JMP_IMM. BPF immediates are sign-extended to 64 bits, so a
max_entries value of 0x80000000 or higher becomes a threshold larger
than every zero-extended 32-bit key. An out-of-range index then skips
the bounds check and the generated lookup reads past xsk_map[].
Compare with BPF_JMP32_IMM so the check stays in 32-bit unsigned range.
Fixes: e65650f291ee ("bpf: Implement map_gen_lookup() callback for XSKMAP")
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://patch.msgid.link/7d2cb8e8dfaa9eb8fdff85156987a60960787dc3.1789056660.git.zhilinz@nebusec.ai
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xdp/xskmap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/xdp/xskmap.c b/net/xdp/xskmap.c
index 47cb92c4d541b..d52a1a822622e 100644
--- a/net/xdp/xskmap.c
+++ b/net/xdp/xskmap.c
@@ -116,7 +116,7 @@ static int xsk_map_gen_lookup(struct bpf_map *map, struct bpf_insn *insn_buf)
struct bpf_insn *insn = insn_buf;
*insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0);
- *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 5);
+ *insn++ = BPF_JMP32_IMM(BPF_JGE, ret, map->max_entries, 5);
*insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(sizeof(struct xsk_sock *)));
*insn++ = BPF_ALU64_IMM(BPF_ADD, mp, offsetof(struct xsk_map, xsk_map));
*insn++ = BPF_ALU64_REG(BPF_ADD, ret, mp);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 829/982] bpf: Skip unsettled links in link iterator
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (827 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 828/982] xsk: Use a 32-bit compare in xsk_map_gen_lookup Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 830/982] net/sched: cls_u32: fix manual hash table handle IDR aliasing Greg Kroah-Hartman
` (159 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Andrii Nakryiko, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 50e80e2bb5e2be8515205b9c496b9640ddefa434 ]
bpf_link_prime() inserts a link into link_idr before anon_inode_getfile()
succeeds and before bpf_link_settle() publishes the ID in link->id.
bpf_link_by_id() treats such an ID-zero link as unsettled, but the link
iterator takes a reference without this check.
If anon_inode_getfile() then fails, the creator removes the ID and frees
its still-private link directly. The iterator is left with a dangling
reference and its next bpf_link_put() accesses freed memory.
Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as
bpf_link_by_id() does.
BUG: KASAN: slab-use-after-free in bpf_link_put
Write of size 8 by task exp/384
Call Trace:
bpf_link_put kernel/bpf/syscall.c:3372
bpf_link_seq_next kernel/bpf/link_iter.c:33
bpf_seq_read kernel/bpf/bpf_iter.c:158
vfs_read fs/read_write.c:572
ksys_read fs/read_write.c:716
do_syscall_64 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Fixes: 9f8836127308 ("bpf: Add bpf_link iterator")
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260914170206.170723-2-bestswngs@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/syscall.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index 19f7c9e17be14..d630d1665c6b0 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -4800,7 +4800,10 @@ struct bpf_link *bpf_link_get_curr_or_next(u32 *id)
again:
link = idr_get_next(&link_idr, id);
if (link) {
- link = bpf_link_inc_not_zero(link);
+ if (link->id)
+ link = bpf_link_inc_not_zero(link);
+ else
+ link = ERR_PTR(-EAGAIN);
if (IS_ERR(link)) {
(*id)++;
goto again;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 830/982] net/sched: cls_u32: fix manual hash table handle IDR aliasing
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (828 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 829/982] bpf: Skip unsettled links in link iterator Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 831/982] bpf: Restrict CO-RE poisoning to relocatable instructions Greg Kroah-Hartman
` (158 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini + nipa),
Victor Nogueira, hybris, Jamal Hadi Salim, Simon Horman,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 0a5f5d9e94dead312d32c366b917c64e552b72f7 ]
A u32 hash table created with an explicit handle ('tc filter add ...
handle 801: u32 divisor N') keys its IDR entry on the raw handle, while
the destroy paths free it under handle2id(handle). The two key domains
disagree for handles in the 0x800..0xFFF htid range:
handle2id() folds them back into the auto-allocated id space (1..0x7FF).
A manual table therefore leaves its raw-keyed IDR entry unreachable on
delete (a permanent leak), and its delete can drop the idr entry of an
unrelated live auto table. A later auto allocation can then hand out a
handle that aliases the live manual table; u32_lookup_ht() first-match
routes lookups and TCA_U32_LINK for that htid to the wrong table.
Key the divisor-path alloc on handle2id(handle) so allocation and
removal share one key domain. A manual handle that maps onto an id
already in use is rejected with -ENOSPC, and auto allocation skips ids
held by live manual tables.
Conditions to recreate:
ip link add test0 type dummy
tc qdisc add dev test0 clsact
tc filter add dev test0 ingress protocol ip pref 1 \
handle 801: u32 divisor 16
tc filter add dev test0 ingress protocol ip pref 2 u32 divisor 16
tc -d filter show dev test0 ingress | grep 'fh 801:'
# unpatched: two live tables with handle 0x80100000 (the pref 2 root
# hnode is auto-allocated id 1); patched: the auto hnode takes id 2.
Also tested with a poc with a live u32 table on the block, add/delete a manual
table 'handle 901: u32 divisor 1' twice; unpatched, the re-add fails with
-ENOSPC because the raw key leaked on the first delete.
Fixes: 73af53d82076 ("net: sched: cls_u32: Fix u32's systematic failure to free IDR entries for hnodes.")
Reported-by: Sashiko (gemini + nipa) <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260822222049.114526-1-jhs@mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/QDISC-LQFE.v1.20260911041746.1@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/cls_u32.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
index 0c6b6f2aeb531..276ee95f65010 100644
--- a/net/sched/cls_u32.c
+++ b/net/sched/cls_u32.c
@@ -996,8 +996,16 @@ static int u32_change(struct net *net, struct sk_buff *in_skb,
return -ENOMEM;
}
} else {
- err = idr_alloc_u32(&tp_c->handle_idr, ht, &handle,
- handle, GFP_KERNEL);
+ /* The IDR is keyed on the mapped id, and that is
+ * what the destroy paths remove. Ask for it here,
+ * so a manual handle colliding with the
+ * auto-allocated id space is rejected (-ENOSPC)
+ * instead of aliasing a future auto id.
+ */
+ u32 id = handle2id(handle);
+
+ err = idr_alloc_u32(&tp_c->handle_idr, ht, &id, id,
+ GFP_KERNEL);
if (err) {
kfree(ht);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 831/982] bpf: Restrict CO-RE poisoning to relocatable instructions
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (829 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 830/982] net/sched: cls_u32: fix manual hash table handle IDR aliasing Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 832/982] libbpf: Reject truncated ldimm64 CO-RE relocations Greg Kroah-Hartman
` (157 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini,
Kumar Kartikeya Dwivedi, Eduard Zingerman, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 394ae398337c5f87e567f6cd63b937fc2b2f6ddc ]
CO-RE relocation records can name any instruction offset. When a
relocation cannot be resolved, bpf_core_patch_insn() currently poisons its
target before checking whether that instruction is a valid relocation
target. Malformed metadata can therefore replace jumps, calls, exits,
register-source arithmetic, or non-immediate loads instead of failing at
the relocation step.
Handle poisoning only after the instruction has passed the same class and
operand-form checks used for a resolved relocation. Route invalid forms
through the existing diagnostic and return a hard error. Keep poisoning
supported instructions, including both halves of a plain ldimm64, so an
unresolved relocation in dead code remains valid.
Extend bpf_core_poison_insn() to poison both halves of ldimm64, and return
its status directly from each validated instruction case. This avoids
routing the success path through a common label and leaves the helper free
to report errors.
The shared relocation code applies this restriction to both libbpf and
in-kernel CO-RE.
Fixes: d7a252708dbc ("libbpf: Improve handling of failed CO-RE relocations")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://patch.msgid.link/20260917233222.2542500-7-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/lib/bpf/relo_core.c | 58 +++++++++++++++++++++------------------
1 file changed, 31 insertions(+), 27 deletions(-)
diff --git a/tools/lib/bpf/relo_core.c b/tools/lib/bpf/relo_core.c
index 701a4fc305b0a..5dec5f2d84652 100644
--- a/tools/lib/bpf/relo_core.c
+++ b/tools/lib/bpf/relo_core.c
@@ -965,23 +965,30 @@ static int bpf_core_calc_relo(const char *prog_name,
}
/*
- * Turn instruction for which CO_RE relocation failed into invalid one with
+ * Turn instruction for which CO-RE relocation failed into invalid one with
* distinct signature.
*/
-static void bpf_core_poison_insn(const char *prog_name, int relo_idx,
- int insn_idx, struct bpf_insn *insn)
+static int bpf_core_poison_insn(const char *prog_name, int relo_idx,
+ struct bpf_insn *insn, int insn_idx)
{
- pr_debug("prog '%s': relo #%d: substituting insn #%d w/ invalid insn\n",
- prog_name, relo_idx, insn_idx);
- insn->code = BPF_JMP | BPF_CALL;
- insn->dst_reg = 0;
- insn->src_reg = 0;
- insn->off = 0;
- /* if this instruction is reachable (not a dead code),
- * verifier will complain with the following message:
- * invalid func unknown#195896080
- */
- insn->imm = 195896080; /* => 0xbad2310 => "bad relo" */
+ int insn_cnt = is_ldimm64_insn(insn) ? 2 : 1;
+ int i;
+
+ for (i = 0; i < insn_cnt; i++) {
+ pr_debug("prog '%s': relo #%d: substituting insn #%d w/ invalid insn\n",
+ prog_name, relo_idx, insn_idx + i);
+ insn[i].code = BPF_JMP | BPF_CALL;
+ insn[i].dst_reg = 0;
+ insn[i].src_reg = 0;
+ insn[i].off = 0;
+ /*
+ * If this instruction is reachable (not dead code), the verifier
+ * will complain with "invalid func unknown#195896080".
+ */
+ insn[i].imm = 195896080; /* => 0xbad2310 => "bad relo" */
+ }
+
+ return 0;
}
static int insn_bpf_size_to_bytes(struct bpf_insn *insn)
@@ -1032,17 +1039,6 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
class = BPF_CLASS(insn->code);
- if (res->poison) {
-poison:
- /* poison second part of ldimm64 to avoid confusing error from
- * verifier about "unknown opcode 00"
- */
- if (is_ldimm64_insn(insn))
- bpf_core_poison_insn(prog_name, relo_idx, insn_idx + 1, insn + 1);
- bpf_core_poison_insn(prog_name, relo_idx, insn_idx, insn);
- return 0;
- }
-
orig_val = res->orig_val;
new_val = res->new_val;
@@ -1050,7 +1046,9 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
case BPF_ALU:
case BPF_ALU64:
if (BPF_SRC(insn->code) != BPF_K)
- return -EINVAL;
+ goto bad_insn;
+ if (res->poison)
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
if (res->validate && insn->imm != orig_val) {
pr_warn("prog '%s': relo #%d: unexpected insn #%d (ALU/ALU64) value: got %u, exp %llu -> %llu\n",
prog_name, relo_idx,
@@ -1067,6 +1065,8 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
case BPF_LDX:
case BPF_ST:
case BPF_STX:
+ if (res->poison)
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
if (res->validate && insn->off != orig_val) {
pr_warn("prog '%s': relo #%d: unexpected insn #%d (LDX/ST/STX) value: got %u, exp %llu -> %llu\n",
prog_name, relo_idx, insn_idx, insn->off, (unsigned long long)orig_val,
@@ -1082,7 +1082,7 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
pr_warn("prog '%s': relo #%d: insn #%d (LDX/ST/STX) accesses field incorrectly. "
"Make sure you are accessing pointers, unsigned integers, or fields of matching type and size.\n",
prog_name, relo_idx, insn_idx);
- goto poison;
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
}
orig_val = insn->off;
@@ -1125,6 +1125,9 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
return -EINVAL;
}
+ if (res->poison)
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
+
imm = (__u32)insn[0].imm | ((__u64)insn[1].imm << 32);
if (res->validate && imm != orig_val) {
pr_warn("prog '%s': relo #%d: unexpected insn #%d (LDIMM64) value: got %llu, exp %llu -> %llu\n",
@@ -1142,6 +1145,7 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
break;
}
default:
+bad_insn:
pr_warn("prog '%s': relo #%d: trying to relocate unrecognized insn #%d, code:0x%x, src:0x%x, dst:0x%x, off:0x%x, imm:0x%x\n",
prog_name, relo_idx, insn_idx, insn->code,
insn->src_reg, insn->dst_reg, insn->off, insn->imm);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 832/982] libbpf: Reject truncated ldimm64 CO-RE relocations
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (830 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 831/982] bpf: Restrict CO-RE poisoning to relocatable instructions Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 833/982] netfilter: flowtable: publish HW_DEAD after worker is done Greg Kroah-Hartman
` (156 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Kumar Kartikeya Dwivedi,
Eduard Zingerman, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit b4e875d397da451fb4e9c573ff4b86db53caba05 ]
CO-RE relocation of an ldimm64 instruction operates on two instruction
slots. A malformed BPF ELF can end a function after the first slot and
attach a CO-RE relocation to it. libbpf allocates the instruction array
according to the function symbol size, so the shared relocation code would
then access beyond the allocation.
Reject a terminal ldimm64 in libbpf's relocation loop, where the program
length is available, before resolving or applying the relocation. Both
resolved and unresolved relocations validate the absent second slot, and
unresolved relocation poisoning would additionally write past the array.
The in-kernel caller is protected by the verifier's early instruction-stream
check before it applies CO-RE relocations.
Fixes: eacaaed784e2 ("libbpf: Implement enum value-based CO-RE relocations")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/20260914140852.03DA21F0089B@smtp.kernel.org
Link: https://patch.msgid.link/20260917233222.2542500-11-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/lib/bpf/libbpf.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
index a4ce4258711bc..39315efbba6d2 100644
--- a/tools/lib/bpf/libbpf.c
+++ b/tools/lib/bpf/libbpf.c
@@ -5741,6 +5741,13 @@ bpf_object__relocate_core(struct bpf_object *obj, const char *targ_btf_path)
return -EINVAL;
insn = &prog->insns[insn_idx];
+ if (is_ldimm64_insn(insn) && (size_t)insn_idx + 1 >= prog->insns_cnt) {
+ pr_warn("prog '%s': relo #%d: insn #%d (LDIMM64) is truncated\n",
+ prog->name, i, insn_idx);
+ err = -EINVAL;
+ goto out;
+ }
+
err = record_relo_core(prog, rec, insn_idx);
if (err) {
pr_warn("prog '%s': relo #%d: failed to record relocation: %d\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 833/982] netfilter: flowtable: publish HW_DEAD after worker is done
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (831 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 832/982] libbpf: Reject truncated ldimm64 CO-RE relocations Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 834/982] netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation Greg Kroah-Hartman
` (155 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit d644b23afe1ef509c9961a6d84a093c2587edf02 ]
flow_offload_work_del() sets NF_FLOW_HW_DEAD before the work handler
clears NF_FLOW_HW_PENDING. Once a flow is both HW_DYING and HW_DEAD, a
concurrent garbage collection pass can remove it and schedule it for RCU
freeing.
The offload worker holds neither an RCU read lock nor a reference to the
flow. If it is preempted after publishing HW_DEAD, the RCU callback can
free the flow before the worker resumes and clears HW_PENDING, resulting
in a use-after-free.
Move HW_DEAD publication to the common worker epilogue after the pending
bit is cleared, making it the final flow access by destroy work. Order all
preceding flow accesses before publishing the bit that allows garbage
collection to free the object.
Fixes: 2c8897953f3b ("netfilter: flowtable: Add pending bit for offload work")
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_flow_table_offload.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nf_flow_table_offload.c b/net/netfilter/nf_flow_table_offload.c
index cd8bce176ae88..1747c0af75698 100644
--- a/net/netfilter/nf_flow_table_offload.c
+++ b/net/netfilter/nf_flow_table_offload.c
@@ -993,7 +993,6 @@ static void flow_offload_work_del(struct flow_offload_work *offload)
flow_offload_tuple_del(offload, FLOW_OFFLOAD_DIR_ORIGINAL);
if (test_bit(NF_FLOW_HW_BIDIRECTIONAL, &offload->flow->flags))
flow_offload_tuple_del(offload, FLOW_OFFLOAD_DIR_REPLY);
- set_bit(NF_FLOW_HW_DEAD, &offload->flow->flags);
}
static void flow_offload_tuple_stats(struct flow_offload_work *offload,
@@ -1057,6 +1056,12 @@ static void flow_offload_work_handler(struct work_struct *work)
}
clear_bit(NF_FLOW_HW_PENDING, &offload->flow->flags);
+ if (offload->cmd == FLOW_CLS_DESTROY) {
+ /* Publish after the worker's last flow access. */
+ smp_mb__before_atomic();
+ set_bit(NF_FLOW_HW_DEAD, &offload->flow->flags);
+ }
+
kfree(offload);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 834/982] netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (832 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 833/982] netfilter: flowtable: publish HW_DEAD after worker is done Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 835/982] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier Greg Kroah-Hartman
` (154 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Westphal, Scott Mitchell,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Scott Mitchell <scott.k.mitch1@gmail.com>
[ Upstream commit a4400a5b343d1bc4aa8f685608515413238e7ee2 ]
Currently, instance_create() uses GFP_ATOMIC because it's called while
holding instances_lock spinlock. This makes allocation more likely to
fail under memory pressure.
Refactor nfqnl_recv_config() to drop RCU lock after instance_lookup()
and peer_portid verification. A socket cannot simultaneously send a
message and close, so the queue owned by the sending socket cannot be
destroyed while processing its CONFIG message. This allows
instance_create() to allocate with GFP_KERNEL_ACCOUNT before taking
the spinlock.
Suggested-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Scott Mitchell <scott.k.mitch1@gmail.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Stable-dep-of: 9461613afc59 ("netfilter: nfnetlink_queue: hold nfnl mutex in event notifier")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nfnetlink_queue.c | 75 +++++++++++++++------------------
1 file changed, 34 insertions(+), 41 deletions(-)
diff --git a/net/netfilter/nfnetlink_queue.c b/net/netfilter/nfnetlink_queue.c
index cdc420c29e112..a363853442cb9 100644
--- a/net/netfilter/nfnetlink_queue.c
+++ b/net/netfilter/nfnetlink_queue.c
@@ -119,17 +119,9 @@ instance_create(struct nfnl_queue_net *q, u_int16_t queue_num, u32 portid)
unsigned int h;
int err;
- spin_lock(&q->instances_lock);
- if (instance_lookup(q, queue_num)) {
- err = -EEXIST;
- goto out_unlock;
- }
-
- inst = kzalloc(sizeof(*inst), GFP_ATOMIC);
- if (!inst) {
- err = -ENOMEM;
- goto out_unlock;
- }
+ inst = kzalloc(sizeof(*inst), GFP_KERNEL_ACCOUNT);
+ if (!inst)
+ return ERR_PTR(-ENOMEM);
inst->queue_num = queue_num;
inst->peer_portid = portid;
@@ -139,9 +131,15 @@ instance_create(struct nfnl_queue_net *q, u_int16_t queue_num, u32 portid)
spin_lock_init(&inst->lock);
INIT_LIST_HEAD(&inst->queue_list);
+ spin_lock(&q->instances_lock);
+ if (instance_lookup(q, queue_num)) {
+ err = -EEXIST;
+ goto out_unlock;
+ }
+
if (!try_module_get(THIS_MODULE)) {
err = -EAGAIN;
- goto out_free;
+ goto out_unlock;
}
h = instance_hashfn(queue_num);
@@ -151,10 +149,9 @@ instance_create(struct nfnl_queue_net *q, u_int16_t queue_num, u32 portid)
return inst;
-out_free:
- kfree(inst);
out_unlock:
spin_unlock(&q->instances_lock);
+ kfree(inst);
return ERR_PTR(err);
}
@@ -1322,7 +1319,8 @@ static int nfqnl_recv_config(struct sk_buff *skb, const struct nfnl_info *info,
struct nfqnl_msg_config_cmd *cmd = NULL;
struct nfqnl_instance *queue;
__u32 flags = 0, mask = 0;
- int ret = 0;
+
+ WARN_ON_ONCE(!lockdep_nfnl_is_held(NFNL_SUBSYS_QUEUE));
if (nfqa[NFQA_CFG_CMD]) {
cmd = nla_data(nfqa[NFQA_CFG_CMD]);
@@ -1368,47 +1366,44 @@ static int nfqnl_recv_config(struct sk_buff *skb, const struct nfnl_info *info,
}
}
+ /* Lookup queue under RCU. After peer_portid check (or for new queue
+ * in BIND case), the queue is owned by the socket sending this message.
+ * A socket cannot simultaneously send a message and close, so while
+ * processing this CONFIG message, nfqnl_rcv_nl_event() (triggered by
+ * socket close) cannot destroy this queue. Safe to use without RCU.
+ */
rcu_read_lock();
queue = instance_lookup(q, queue_num);
if (queue && queue->peer_portid != NETLINK_CB(skb).portid) {
- ret = -EPERM;
- goto err_out_unlock;
+ rcu_read_unlock();
+ return -EPERM;
}
+ rcu_read_unlock();
if (cmd != NULL) {
switch (cmd->command) {
case NFQNL_CFG_CMD_BIND:
- if (queue) {
- ret = -EBUSY;
- goto err_out_unlock;
- }
- queue = instance_create(q, queue_num,
- NETLINK_CB(skb).portid);
- if (IS_ERR(queue)) {
- ret = PTR_ERR(queue);
- goto err_out_unlock;
- }
+ if (queue)
+ return -EBUSY;
+ queue = instance_create(q, queue_num, NETLINK_CB(skb).portid);
+ if (IS_ERR(queue))
+ return PTR_ERR(queue);
break;
case NFQNL_CFG_CMD_UNBIND:
- if (!queue) {
- ret = -ENODEV;
- goto err_out_unlock;
- }
+ if (!queue)
+ return -ENODEV;
instance_destroy(q, queue);
- goto err_out_unlock;
+ return 0;
case NFQNL_CFG_CMD_PF_BIND:
case NFQNL_CFG_CMD_PF_UNBIND:
break;
default:
- ret = -ENOTSUPP;
- goto err_out_unlock;
+ return -EOPNOTSUPP;
}
}
- if (!queue) {
- ret = -ENODEV;
- goto err_out_unlock;
- }
+ if (!queue)
+ return -ENODEV;
if (nfqa[NFQA_CFG_PARAMS]) {
struct nfqnl_msg_config_params *params =
@@ -1433,9 +1428,7 @@ static int nfqnl_recv_config(struct sk_buff *skb, const struct nfnl_info *info,
spin_unlock_bh(&queue->lock);
}
-err_out_unlock:
- rcu_read_unlock();
- return ret;
+ return 0;
}
static const struct nfnl_callback nfqnl_cb[NFQNL_MSG_MAX] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 835/982] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (833 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 834/982] netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 836/982] netfilter: nft_synproxy: use the family-aware checksum helper Greg Kroah-Hartman
` (153 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Westphal, Pablo Neira Ayuso,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 9461613afc59acef44a0071b0dd5075f6e993ffe ]
We must serialize the release notifier and the config netlink function.
A concurrent thread can issue close() which can call the release function
while unrelated socket processes UNBIND request for same portid:
Oops: general protection fault, [..]
RIP: 0010:__instance_destroy+0x60/0x210 [nfnetlink_queue]
Call Trace:
nfqnl_recv_config+0x9b0/0xdc0 [nfnetlink_queue]
nfnetlink_rcv_msg+0x7c2/0xeb0
? __pfx_nfnetlink_rcv_msg+0x10/0x10
After this, parallel UNBIND and URELEASE events are impossible.
This change isn't nice, but its the shortest fix given instances
are not refcounted and the nfnetlink config callback drops the
rcu read lock early due to need for sleeping allocations.
Fixes: 7af4cc3fa158 ("[NETFILTER]: Add "nfnetlink_queue" netfilter queue handler over nfnetlink")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nfnetlink_queue.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/net/netfilter/nfnetlink_queue.c b/net/netfilter/nfnetlink_queue.c
index a363853442cb9..3d522248b45be 100644
--- a/net/netfilter/nfnetlink_queue.c
+++ b/net/netfilter/nfnetlink_queue.c
@@ -1034,6 +1034,7 @@ nfqnl_rcv_nl_event(struct notifier_block *this,
if (event == NETLINK_URELEASE && n->protocol == NETLINK_NETFILTER) {
int i;
+ nfnl_lock(NFNL_SUBSYS_QUEUE);
/* destroy all instances for this portid */
spin_lock(&q->instances_lock);
for (i = 0; i < INSTANCE_BUCKETS; i++) {
@@ -1047,6 +1048,7 @@ nfqnl_rcv_nl_event(struct notifier_block *this,
}
}
spin_unlock(&q->instances_lock);
+ nfnl_unlock(NFNL_SUBSYS_QUEUE);
}
return NOTIFY_DONE;
}
@@ -1368,9 +1370,9 @@ static int nfqnl_recv_config(struct sk_buff *skb, const struct nfnl_info *info,
/* Lookup queue under RCU. After peer_portid check (or for new queue
* in BIND case), the queue is owned by the socket sending this message.
- * A socket cannot simultaneously send a message and close, so while
- * processing this CONFIG message, nfqnl_rcv_nl_event() (triggered by
- * socket close) cannot destroy this queue. Safe to use without RCU.
+ * nfqnl_rcv_nl_event() will block on the nfnl subsys mutex that is
+ * held by the caller, so the queue cannot be destroyed in parallel,
+ * even after we drop the RCU read lock.
*/
rcu_read_lock();
queue = instance_lookup(q, queue_num);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 836/982] netfilter: nft_synproxy: use the family-aware checksum helper
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (834 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 835/982] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 837/982] ipvs: revalidate ihl before icmp_send Greg Kroah-Hartman
` (152 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Pablo Neira Ayuso,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit a311a898172743558b82f6035ef2aa8c310a4223 ]
nft_synproxy_do_eval() verifies the TCP checksum before it switches on
skb->protocol. It uses nf_ip_checksum(), which constructs an IPv4
pseudo header and relies on the IPv4 header checksum when folding the
whole skb. Neither operation is valid for an IPv6 packet.
A correctly checksummed IPv6 segment can therefore fail verification
when it reaches the hook as CHECKSUM_NONE or, at NF_INET_LOCAL_IN,
CHECKSUM_COMPLETE. nft_synproxy_do_eval() returns NF_DROP before
nft_synproxy_eval_v6() can send a SYN-ACK.
nft_synproxy_validate() deliberately admits NFPROTO_IPV6 and
NFPROTO_INET, and the xtables counterpart ip6t_SYNPROXY.c already calls
nf_ip6_checksum().
Use nf_checksum() with nft_pf() so the checksum helper dispatches to the
packet family's implementation.
Fixes: ad49d86e07a4 ("netfilter: nf_tables: Add synproxy support")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_synproxy.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nft_synproxy.c b/net/netfilter/nft_synproxy.c
index 75416f9344116..3c674137eb81a 100644
--- a/net/netfilter/nft_synproxy.c
+++ b/net/netfilter/nft_synproxy.c
@@ -117,7 +117,8 @@ static void nft_synproxy_do_eval(const struct nft_synproxy *priv,
return;
}
- if (nf_ip_checksum(skb, nft_hook(pkt), thoff, IPPROTO_TCP)) {
+ if (nf_checksum(skb, nft_hook(pkt), thoff, IPPROTO_TCP,
+ nft_pf(pkt))) {
regs->verdict.code = NF_DROP;
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 837/982] ipvs: revalidate ihl before icmp_send
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (835 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 836/982] netfilter: nft_synproxy: use the family-aware checksum helper Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 838/982] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name Greg Kroah-Hartman
` (151 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Anastasov, Pablo Neira Ayuso,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit e290145564886d6a3038810c621f738c1fe9fa51 ]
While the outer IP header is already pulled into the skb head, we must
be careful and revalidate the embedded headers after reading them from
the skb frags to prevent possible out-of-bounds access.
One such place reported by Sashiko is ip_vs_in_icmp() where local
process can change the ihl field and after pskb_may_pull() we can see
larger value. Even if icmp_send() has checks to prevent out-of-bounds
access, play safe and add check to drop the packet if the ihl field is
changed. As the outer headers are pulled, make sure the transport
header is updated too, it was used before commit 7fcc2fe39fed ("net:
icmp: avoid invalid transport header access in icmp_send tracepoint")
Fixes: f2edb9f7706d ("ipvs: implement passive PMTUD for IPIP packets")
Link: https://sashiko.dev/#/patchset/20260806105211.34622-1-ja%40ssi.bg
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/ipvs/ip_vs_core.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index e417fe52fef8f..41f09e29d221b 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -1781,6 +1781,12 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
/* Ensure the IP header is present in headroom */
if (!pskb_may_pull(skb, hlen_orig))
goto ignore_tunnel;
+ skb_set_transport_header(skb, hlen_orig);
+ /* Before now we may used ihl from skb frag, revalidate it after
+ * copying it into skb head to prevent out-of-bounds access
+ */
+ if (ip_hdr(skb)->ihl * 4 != hlen_orig)
+ goto ignore_tunnel;
IP_VS_DBG(12, "Sending ICMP for %pI4->%pI4: t=%u, c=%u, i=%u\n",
&ip_hdr(skb)->saddr, &ip_hdr(skb)->daddr,
type, code, ntohl(info));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 838/982] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (836 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 837/982] ipvs: revalidate ihl before icmp_send Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 839/982] ocfs2: make ocfs2_calc_xattr_init() return void Greg Kroah-Hartman
` (150 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+4bd730aede2791e40bdf,
Naman Gulati, Pablo Neira Ayuso, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Naman Gulati <namangulati@google.com>
[ Upstream commit 207d591c353201f3bd3e0c89bb7d44a849c8fd59 ]
expect_iter_name() is invoked by nf_ct_expect_iterate_net() under
spin_lock_bh(&nf_conntrack_expect_lock). It does not hold
rcu_read_lock().
When accessing exp->helper with rcu_dereference() in syzbot's report,
lockdep warns:
=============================
WARNING: suspicious RCU usage
syzkaller #0 Not tainted
-----------------------------
net/netfilter/nf_conntrack_netlink.c:3393 suspicious rcu_dereference_check() usage!
locks held by syz-executor381/5628: 2, last CPU#1:
#0: ffffffff9aee42a0 (nfnl_subsys_ctnetlink_exp){+.+.}-{4:4},
at: nfnetlink_rcv_msg+0xa69/0x12b0
#1: ffffffff8ea74d58 (nf_conntrack_expect_lock){+...}-{3:3},
at: nf_ct_expect_iterate_net+0x38/0x180
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150
lockdep_rcu_suspicious+0x140/0x1d0
expect_iter_name+0xfb/0x100
nf_ct_expect_iterate_net+0xf2/0x180
ctnetlink_del_expect+0x45d/0x640
nfnetlink_rcv_msg+0xcc2/0x12b0
netlink_rcv_skb+0x226/0x4a0
nfnetlink_rcv+0x2b9/0x28c0
netlink_unicast+0x7bd/0x940
netlink_sendmsg+0x813/0xb40
____sys_sendmsg+0x54e/0x850
___sys_sendmsg+0x2a5/0x360
__sys_sendmsg+0x2a5/0x360
do_syscall_64+0x166/0x520
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Use rcu_dereference_protected() with lockdep_is_held() on
nf_conntrack_expect_lock instead, similar to expect_iter_me() in
nf_conntrack_helper.c.
Fixes: f01794106042 ("netfilter: nf_conntrack_expect: use expect->helper")
Reported-by: syzbot+4bd730aede2791e40bdf@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6aa4a377.f81106d8.2ab401.0024.GAE@google.com/T/#u
Signed-off-by: Naman Gulati <namangulati@google.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_conntrack_netlink.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
index 8b9951c5624d3..963efcdfca39f 100644
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -3388,7 +3388,8 @@ static bool expect_iter_name(struct nf_conntrack_expect *exp, void *data)
struct nf_conntrack_helper *helper;
const char *name = data;
- helper = rcu_dereference(exp->helper);
+ helper = rcu_dereference_protected(exp->helper,
+ lockdep_is_held(&nf_conntrack_expect_lock));
if (!helper)
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 839/982] ocfs2: make ocfs2_calc_xattr_init() return void
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (837 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 838/982] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 840/982] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Greg Kroah-Hartman
` (149 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joseph Qi, Andrew Morton,
kernel test robot, Mark Fasheh, Joel Becker, Junxiao Bi,
Changwei Ge, Jun Piao, Heming Zhao, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joseph Qi <joseph.qi@linux.alibaba.com>
[ Upstream commit 525c0edc032b3297d0c1056cf1fa20cf1f9e6184 ]
ocfs2_calc_xattr_init() used to read the default ACL off the parent inode
itself, so it could return an error from ocfs2_xattr_get_nolock(). Commit
bd7c05fb4a47 ("ocfs2: fix circular locking dependency in
ocfs2_init_acl()") moved that lookup before the transaction starts and
deleted the error path, but left the now vestigial 'int ret = 0'
declaration and both 'return ret' statements behind, along with an
unreachable error branch in ocfs2_mknod().
Drop the leftover variable and convert the return type to void, so the
callee states that it always succeeds and the caller no longer carries a
check that can never trigger.
No functional change.
Link: https://lore.kernel.org/20260904023751.3703334-1-joseph.qi@linux.alibaba.com
Fixes: bd7c05fb4a47 ("ocfs2: fix circular locking dependency in ocfs2_init_acl()")
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609040247.8B3lmoqX-lkp@intel.com/
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ocfs2/namei.c | 9 ++-------
fs/ocfs2/xattr.c | 13 +++++--------
fs/ocfs2/xattr.h | 8 ++++----
3 files changed, 11 insertions(+), 19 deletions(-)
diff --git a/fs/ocfs2/namei.c b/fs/ocfs2/namei.c
index c97c6fdb8cec2..62f9d976c8fb3 100644
--- a/fs/ocfs2/namei.c
+++ b/fs/ocfs2/namei.c
@@ -332,13 +332,8 @@ static int ocfs2_mknod(struct user_namespace *mnt_userns,
goto leave;
/* calculate meta data/clusters for setting security and acl xattr */
- status = ocfs2_calc_xattr_init(dir, mode, &si, &want_clusters,
- &xattr_credits, &want_meta,
- &acl_state);
- if (status < 0) {
- mlog_errno(status);
- goto leave;
- }
+ ocfs2_calc_xattr_init(dir, mode, &si, &want_clusters, &xattr_credits,
+ &want_meta, &acl_state);
/* Reserve a cluster if creating an extent based directory. */
if (S_ISDIR(mode) && !ocfs2_supports_inline_data(osb)) {
diff --git a/fs/ocfs2/xattr.c b/fs/ocfs2/xattr.c
index 3f6cf0259679b..62d6d73083642 100644
--- a/fs/ocfs2/xattr.c
+++ b/fs/ocfs2/xattr.c
@@ -611,12 +611,11 @@ int ocfs2_calc_security_init(struct inode *dir,
return ret;
}
-int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
- struct ocfs2_security_xattr_info *si,
- int *want_clusters, int *xattr_credits,
- int *want_meta, struct ocfs2_acl_state *acl_state)
+void ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
+ struct ocfs2_security_xattr_info *si,
+ int *want_clusters, int *xattr_credits,
+ int *want_meta, struct ocfs2_acl_state *acl_state)
{
- int ret = 0;
struct ocfs2_super *osb = OCFS2_SB(dir->i_sb);
int s_size = 0, a_size = 0, acl_len = 0, new_clusters;
@@ -638,7 +637,7 @@ int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
}
if (!(s_size + a_size))
- return ret;
+ return;
/*
* The max space of security xattr taken inline is
@@ -704,8 +703,6 @@ int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
}
}
}
-
- return ret;
}
static int ocfs2_xattr_extend_allocation(struct inode *inode,
diff --git a/fs/ocfs2/xattr.h b/fs/ocfs2/xattr.h
index 5901f2095bc57..016374e9a147e 100644
--- a/fs/ocfs2/xattr.h
+++ b/fs/ocfs2/xattr.h
@@ -57,10 +57,10 @@ int ocfs2_calc_security_init(struct inode *,
int *, int *, struct ocfs2_alloc_context **);
struct ocfs2_acl_state;
-int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
- struct ocfs2_security_xattr_info *si,
- int *want_clusters, int *xattr_credits,
- int *want_meta, struct ocfs2_acl_state *acl_state);
+void ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
+ struct ocfs2_security_xattr_info *si,
+ int *want_clusters, int *xattr_credits,
+ int *want_meta, struct ocfs2_acl_state *acl_state);
/*
* xattrs can live inside an inode, as part of an external xattr block,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 840/982] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (838 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 839/982] ocfs2: make ocfs2_calc_xattr_init() return void Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 841/982] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan Greg Kroah-Hartman
` (148 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Francesco Magazzu,
Lyude Paul, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
[ Upstream commit aff09d9e37e02dc60bde79035ac15b136d602259 ]
If list_for_each_entry() exits without hitting a break then "pstate" is
not a valid pstate pointer. Introduce a "found" variable instead.
The check is reachable from userspace: nvkm_clk_ustate_update() takes the
pstate id straight from the 'pstate' debugfs file, so requesting an id
that is not in clk->states - or any id at all when the perf tables are
broken and the list is empty - makes the pstate->pstate != req test
dereference the list head cast to a struct nvkm_pstate, which is an
out-of-bounds read.
Fixes: 7c8565220697 ("drm/nouveau/clk: implement power state and engine clock control in core")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
[Francesco: rebased on drm-misc-next, expanded the commit message]
Signed-off-by: Francesco Magazzu <postadelmaga@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260918131620.405133-2-postadelmaga@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
index da07a2fbef062..33f073ab3c49f 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
@@ -473,6 +473,7 @@ static int
nvkm_clk_ustate_update(struct nvkm_clk *clk, int req)
{
struct nvkm_pstate *pstate;
+ bool found = false;
int i = 0;
if (!clk->allow_reclock)
@@ -480,12 +481,14 @@ nvkm_clk_ustate_update(struct nvkm_clk *clk, int req)
if (req != -1 && req != -2) {
list_for_each_entry(pstate, &clk->states, head) {
- if (pstate->pstate == req)
+ if (pstate->pstate == req) {
+ found = true;
break;
+ }
i++;
}
- if (pstate->pstate != req)
+ if (!found)
return -EINVAL;
req = i;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 841/982] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (839 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 840/982] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 842/982] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure Greg Kroah-Hartman
` (147 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Francesco Magazzu, Lyude Paul,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Francesco Magazzu <postadelmaga@gmail.com>
[ Upstream commit e5cccdafc855cd5f96f4b51d38114a0360b075d7 ]
nvkm_cstate_prog() reuses 'ret' for the voltage and fan-speed restore
calls it makes after reprogramming the clocks. Those calls almost always
succeed, so the status of the reclock itself is overwritten and the
function reports success even when clk->func->calc() or clk->func->prog()
failed. The converse is also true: a successful reclock is reported as an
error if the final restore call fails, even though that failure is only
logged and otherwise ignored.
The only consumer of the return value is the error message in
nvkm_pstate_work(), so in practice a failing reclock is simply never
reported. Nothing else changes, but a function that returns success on
failure is a trap for the next caller.
Keep the calc/prog status in 'ret' and use a separate local for the
restore calls.
Fixes: 3eca809b3c05 ("drm/nouveau/clk: cosmetic changes")
Signed-off-by: Francesco Magazzu <postadelmaga@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260918131620.405133-5-postadelmaga@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
index 33f073ab3c49f..c7a6c6ba936a8 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
@@ -199,16 +199,18 @@ nvkm_cstate_prog(struct nvkm_clk *clk, struct nvkm_pstate *pstate, int cstatei)
}
if (volt) {
- ret = nvkm_volt_set_id(volt, cstate->voltage,
- pstate->base.voltage, clk->temp, -1);
- if (ret && ret != -ENODEV)
- nvkm_error(subdev, "failed to lower voltage: %d\n", ret);
+ int err = nvkm_volt_set_id(volt, cstate->voltage,
+ pstate->base.voltage, clk->temp, -1);
+
+ if (err && err != -ENODEV)
+ nvkm_error(subdev, "failed to lower voltage: %d\n", err);
}
if (therm) {
- ret = nvkm_therm_cstate(therm, pstate->fanspeed, -1);
- if (ret && ret != -ENODEV)
- nvkm_error(subdev, "failed to lower fan speed: %d\n", ret);
+ int err = nvkm_therm_cstate(therm, pstate->fanspeed, -1);
+
+ if (err && err != -ENODEV)
+ nvkm_error(subdev, "failed to lower fan speed: %d\n", err);
}
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 842/982] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (840 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 841/982] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 843/982] net: gue: reject invalid REMCSUM offsets Greg Kroah-Hartman
` (146 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+6cc37aba98dac721c415,
Nguyen Ngoc Thang, Simon Horman, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
[ Upstream commit 47abe7a5c4eb53269aca3506446f851572a059a3 ]
flow_offload_alloc() returns NULL when the conntrack entry is dying
(e.g. raced with a conntrack flush) or when the GFP_ATOMIC allocation
fails; both are expected under load and neither is a kernel bug. This
path runs from softirq on every committed packet, so with
panic_on_warn=1 an unprivileged user can panic the box just by racing
a conntrack flush against a `tc ... action ct commit` classifier.
Reproduced with a custom repro under QEMU: a small, fixed set of UDP
flows through `tc filter ... action ct commit` on lo, raced against
threads flooding bare ctnetlink CT_DELETE (flush) requests. Hits
WARNING: net/sched/act_ct.c:437 (tcf_ct_flow_table_add(), inlined
into tcf_ct_act() in this build) within ~15s on the unpatched kernel;
same setup is clean on the patched kernel. The fix itself is
behavior-preserving: both branches already did `goto err_alloc`
before and after, only the WARN is removed.
Fixes: 64ff70b80fd4 ("net/sched: act_ct: Offload established connections to flow table")
Reported-by: syzbot+6cc37aba98dac721c415@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=6cc37aba98dac721c415
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915150816.36487-1-ngocthang2710.1999@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_ct.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c
index fd5de2ed900a5..5e23f8d932ff2 100644
--- a/net/sched/act_ct.c
+++ b/net/sched/act_ct.c
@@ -428,11 +428,10 @@ static void tcf_ct_flow_table_add(struct tcf_ct_flow_table *ct_ft,
if (test_and_set_bit(IPS_OFFLOAD_BIT, &ct->status))
return;
+ /* NULL if ct is dying (raced flush) or the atomic alloc failed. */
entry = flow_offload_alloc(ct);
- if (!entry) {
- WARN_ON_ONCE(1);
+ if (!entry)
goto err_alloc;
- }
if (tcp) {
ct->proto.tcp.seen[0].flags |= IP_CT_TCP_FLAG_BE_LIBERAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 843/982] net: gue: reject invalid REMCSUM offsets
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (841 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 842/982] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 844/982] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink() Greg Kroah-Hartman
` (145 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 2566866fc30965d915d0b52b5c3323b362619f0e ]
The REMCSUM option carries an absolute checksum start and checksum field
offset. gue_remcsum() passes them to skb_remcsum_process(), whose
partial path stores offset - start in the u16 skb->csum_offset variable.
If offset is less than start, this underflows.
A forwarded packet can retain CHECKSUM_PARTIAL and reach a NETIF_F_HW_CSUM
driver which trusts the metadata, leading skb_copy_and_csum_dev() to write
two bytes about 64 KiB beyond the destination buffer.
Reject reversed tuples in validate_gue_flags(), after the existing length
validation, so all GUE parsers enforce the ordering in one place.
Fixes: fe881ef11cf0 ("gue: Use checksum partial with remote checksum offload")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Link: https://patch.msgid.link/20260915124806.2852293-2-Jeremy.Jean@oss.cyber.gouv.fr
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/gue.h | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/include/net/gue.h b/include/net/gue.h
index caefd6da86939..d377155fd0b31 100644
--- a/include/net/gue.h
+++ b/include/net/gue.h
@@ -84,8 +84,9 @@ static inline size_t guehdr_priv_flags_len(__be32 flags)
}
/* Validate standard and private flags. Returns non-zero (meaning invalid)
- * if there is an unknown standard or private flags, or the options length for
- * the flags exceeds the options length specific in hlen of the GUE header.
+ * if there is an unknown standard or private flags, if the options length for
+ * the flags exceeds the options length specified in hlen of the GUE header, or
+ * if a private option contains invalid data.
*/
static inline int validate_gue_flags(struct guehdr *guehdr, size_t optlen)
{
@@ -103,8 +104,8 @@ static inline int validate_gue_flags(struct guehdr *guehdr, size_t optlen)
/* Private flags are last four bytes accounted in
* guehdr_flags_len
*/
- __be32 pflags = *(__be32 *)((void *)&guehdr[1] +
- len - GUE_LEN_PRIV);
+ void *data = (void *)&guehdr[1] + len;
+ __be32 pflags = *(__be32 *)(data - GUE_LEN_PRIV);
if (pflags & ~GUE_PFLAGS_ALL)
return 1;
@@ -112,6 +113,16 @@ static inline int validate_gue_flags(struct guehdr *guehdr, size_t optlen)
len += guehdr_priv_flags_len(pflags);
if (len > optlen)
return 1;
+
+ if (pflags & GUE_PFLAG_REMCSUM) {
+ __be16 *pd = data;
+
+ /* The field offset pd[1] must not be less
+ * than the start pd[0].
+ */
+ if (ntohs(pd[1]) < ntohs(pd[0]))
+ return 1;
+ }
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 844/982] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink().
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (842 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 843/982] net: gue: reject invalid REMCSUM offsets Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 845/982] sctp: avoid livelock while updating retransmit path Greg Kroah-Hartman
` (144 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Xuanqiang Luo,
Ido Schimmel, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit dd47bcf279f1083f09bf5266890b26263361022b ]
The cited commit accidentally added ip6gre_tunnel_unlink_md()
in ip6erspan_changelink().
Let's correct it to ip6erspan_tunnel_unlink_md().
Fixes: b80d0b93b991 ("net: ip6_gre: fix tunnel metadata device sharing.")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260916230927.378957-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ip6_gre.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index 86d2fbed0a363..950d5e74b094e 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -2337,7 +2337,7 @@ static int ip6erspan_changelink(struct net_device *dev, struct nlattr *tb[],
return PTR_ERR(t);
ip6erspan_set_version(data, &p);
- ip6gre_tunnel_unlink_md(ign, t);
+ ip6erspan_tunnel_unlink_md(ign, t);
ip6gre_tunnel_unlink(ign, t);
ip6erspan_tnl_change(t, &p, !tb[IFLA_MTU]);
ip6erspan_tunnel_link_md(ign, t);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 845/982] sctp: avoid livelock while updating retransmit path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (843 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 844/982] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 846/982] net: usb: catc: bound the RX packet length in catc_rx_done() Greg Kroah-Hartman
` (143 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yiqi Sun, Xin Long, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yiqi Sun <sunyiqixm@gmail.com>
[ Upstream commit d2c31b837406395e576afeb25958c98e9938f3f6 ]
sctp_assoc_update_retran_path() can loop forever when every remaining
transport, including retran_path, is SCTP_UNCONFIRMED: the state check
runs before the wraparound test, so the loop cannot observe that it has
completed a full pass.
Fix this by considering a transport only when it is not UNCONFIRMED,
then checking whether the walk has returned to retran_path. This makes
the full-pass termination independent of the transport state while
preserving the existing fallback selection semantics.
Also restore the NULL guard around the retran_path assignment. In the
all-UNCONFIRMED case there is no eligible replacement transport, and
installing NULL would leave later retransmit-path users and the debug
print with a NULL path.
Fixes: 4c47af4d5eb2 ("net: sctp: rework multihoming retransmission path selection to rfc4960")
Signed-off-by: Yiqi Sun <sunyiqixm@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260915095017.942213-1-sunyiqixm@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/associola.c | 15 ++++++++-------
1 file changed, 8 insertions(+), 7 deletions(-)
diff --git a/net/sctp/associola.c b/net/sctp/associola.c
index c141f8a1262df..a957142672cb2 100644
--- a/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -1305,18 +1305,19 @@ void sctp_assoc_update_retran_path(struct sctp_association *asoc)
/* Manually skip the head element. */
if (&trans->transports == &asoc->peer.transport_addr_list)
continue;
- if (trans->state == SCTP_UNCONFIRMED)
- continue;
- trans_next = sctp_trans_elect_best(trans, trans_next);
- /* Active is good enough for immediate return. */
- if (trans_next->state == SCTP_ACTIVE)
- break;
+ if (trans->state != SCTP_UNCONFIRMED) {
+ trans_next = sctp_trans_elect_best(trans, trans_next);
+ /* Active is good enough for immediate return. */
+ if (trans_next->state == SCTP_ACTIVE)
+ break;
+ }
/* We've reached the end, time to update path. */
if (trans == asoc->peer.retran_path)
break;
}
- asoc->peer.retran_path = trans_next;
+ if (trans_next)
+ asoc->peer.retran_path = trans_next;
pr_debug("%s: association:%p updated new path to addr:%pISpc\n",
__func__, asoc, &asoc->peer.retran_path->ipaddr.sa);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 846/982] net: usb: catc: bound the RX packet length in catc_rx_done()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (844 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 845/982] sctp: avoid livelock while updating retransmit path Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 847/982] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget Greg Kroah-Hartman
` (142 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Simon Horman,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
[ Upstream commit 9d565b6b72fe3f41fd43636e143072848105189f ]
catc_rx_done() walks a multi-packet URB, reading a two-byte length from
each packet header. Its bound, pkt_len > urb->actual_length, ignores the
header offset and compares against the whole transfer rather than the
bytes left from pkt_start, so a crafted packet header makes
skb_copy_to_linear_data() read past the buffer.
A length below ETH_HLEN is also accepted, including zero, and
eth_type_trans() then reads a MAC header from the uninitialised tailroom
of a shorter skb. The is_f5u011 branch takes its length straight from
the transfer, so a zero-length URB reaches the same path.
Track the bytes remaining from the current packet, and reject a header
that does not fit, a length past what is left, and a length below an
Ethernet header.
A transfer shorter than an Ethernet header, including a zero-length one,
previously became a runt skb passed to netif_rx() and counted as
received; it is now counted in rx_length_errors and ends the walk.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/AS8P251MB00015FD7716F38C345619B56C8BB2@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/catc.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/net/usb/catc.c b/drivers/net/usb/catc.c
index 98346cb4ece01..dd1e29add0609 100644
--- a/drivers/net/usb/catc.c
+++ b/drivers/net/usb/catc.c
@@ -239,17 +239,26 @@ static void catc_rx_done(struct urb *urb)
}
do {
- if(!catc->is_f5u011) {
- pkt_len = le16_to_cpup((__le16*)pkt_start);
- if (pkt_len > urb->actual_length) {
+ int remaining = urb->actual_length -
+ (pkt_start - (u8 *)urb->transfer_buffer);
+
+ if (!catc->is_f5u011) {
+ if (remaining < pkt_offset) {
catc->netdev->stats.rx_length_errors++;
catc->netdev->stats.rx_errors++;
break;
}
+ pkt_len = le16_to_cpup((__le16 *)pkt_start);
} else {
pkt_len = urb->actual_length;
}
+ if (pkt_len < ETH_HLEN || pkt_len + pkt_offset > remaining) {
+ catc->netdev->stats.rx_length_errors++;
+ catc->netdev->stats.rx_errors++;
+ break;
+ }
+
if (!(skb = dev_alloc_skb(pkt_len)))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 847/982] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (845 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 846/982] net: usb: catc: bound the RX packet length in catc_rx_done() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 848/982] drm/virtio: fix object leak when drm_gem_handle_create() fails Greg Kroah-Hartman
` (141 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini + nipa),
Victor Nogueira, hybris, Jamal Hadi Salim, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 8a60ade2277e1f0e0d0578d565354e52292fa46d ]
hfsc_classify() applies the "filter may only point downwards" level check
only when the filter result carries no bound class. A filter created with
a flowid gets res.class set once at bind time, so the check never runs for
it during classification. hfsc_adjust_levels() can later raise a class's
level without revalidating existing bindings, leaving two binds that were
each legal at bind time pointing at each other; the classify walk then
bounces between two interior classes forever with the qdisc lock held and
BH disabled — a soft lockup from a single packet. The stuck walk trips
the watchdog:
watchdog: BUG: soft lockup - CPU#3 stuck for 13s! [ping:444]
RIP: 0010:u32_classify+0x542/0x17f0
...
tcf_classify+0x66/0xa0
hfsc_enqueue+0x166/0xdf0
Bound the traversal with a budget of non-descending hops, the only way a
configured walk can move without descending the class tree once levels
drift after bind time. The budget is cumulative over the whole walk and
is deliberately not reset on a descending hop: a chain that alternates a
descent with a lateral hop would return the budget every lap and never
trip. Descending hops never decrement it, so legitimately deep trees are
unaffected and a terminating lateral chain still classifies normally.
Drop the packet with a rate-limited warning once the budget is exhausted,
mirroring the merged HTB fix.
This is a follow-up to commit 729c4896ab82 ("net/sched: sch_htb: limit
htb_classify inner-class filter hops"), which bounded the same classify
loop on the HTB side but left the HFSC walk unbounded.
Conditions to recreate the bug:
- CONFIG_NET_SCHED, CONFIG_NET_SCH_HFSC, CONFIG_NET_CLS_U32,
CONFIG_LOCKUP_DETECTOR.
- Build a cycle with two legal-at-bind-time flowid binds and a level
drift: class X 1:1 (child of root) with leaf child 1:10; class Y 1:2
(sibling of X) with children 1:20 and 1:200; root u32 filter flowid
1:1; filter on X flowid 1:2 (legal when Y is a leaf); after Y's level
rises to 2, filter on Y flowid 1:1 (legal then). Send one packet (ping
on the device). Unfixed kernel: classify spins with the qdisc lock
held; with softlockup_panic=1 it panics.
- Reachable from unprivileged user via unshare -Urn (CAP_NET_ADMIN).
Fixes: a2f79227138c ("net_sched: sch_hfsc: fix classification loops")
Reported-by: Sashiko (gemini + nipa) <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/netdev/QDISC-CTUU.v2.20260913192614@mojatatu.com/
Link: https://sashiko.dev/#/patchset/QDISC-CTUU.v2.20260913192614@mojatatu.com
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/QDISC-CTUU.v2.20260913192614%40mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-CTUU.v3.20260916184908@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_hfsc.c | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/net/sched/sch_hfsc.c b/net/sched/sch_hfsc.c
index 2d6baf7d7b036..eb99bc1a76f6f 100644
--- a/net/sched/sch_hfsc.c
+++ b/net/sched/sch_hfsc.c
@@ -387,6 +387,15 @@ cftree_update(struct hfsc_class *cl)
#define SM_MASK ((1ULL << SM_SHIFT) - 1)
#define ISM_MASK ((1ULL << ISM_SHIFT) - 1)
+/*
+ * Cap on the non-descending hops a classify walk may take before its
+ * filter chain is treated as misconfigured. A flowid binding that was
+ * legal at bind time can become lateral once hfsc_adjust_levels()
+ * raises a class level; a few such hops are legitimate, an unbounded
+ * run means the chain cycles.
+ */
+#define HFSC_CLASSIFY_MAX_DRIFT 8
+
static inline u64
seg_x2y(u64 x, u64 sm)
{
@@ -1131,6 +1140,7 @@ hfsc_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
struct hfsc_class *head, *cl;
struct tcf_result res;
struct tcf_proto *tcf;
+ unsigned int drift;
int result;
if (TC_H_MAJ(skb->priority ^ sch->handle) == 0 &&
@@ -1140,6 +1150,7 @@ hfsc_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
*qerr = NET_XMIT_SUCCESS | __NET_XMIT_BYPASS;
head = &q->root;
+ drift = HFSC_CLASSIFY_MAX_DRIFT;
tcf = rcu_dereference_bh(q->root.filter_list);
while (tcf && (result = tcf_classify(skb, NULL, tcf, &res, false)) >= 0) {
#ifdef CONFIG_NET_CLS_ACT
@@ -1165,6 +1176,17 @@ hfsc_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
if (cl->level == 0)
return cl; /* hit leaf class */
+ /*
+ * flowid binds skip the level check above (res.class is set
+ * at bind time and levels drift after), so a walk can follow
+ * lateral hops without descending; a bounded number of them
+ * is legal, more means the chain cycles.
+ */
+ if (cl->level >= head->level && drift-- == 0) {
+ pr_warn_ratelimited("hfsc: classify hop budget exhausted, dropping packet\n");
+ return NULL;
+ }
+
/* apply inner filter chain */
tcf = rcu_dereference_bh(cl->filter_list);
head = cl;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 848/982] drm/virtio: fix object leak when drm_gem_handle_create() fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (846 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 847/982] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 849/982] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Greg Kroah-Hartman
` (140 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Junrui Luo,
Dmitry Osipenko, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 36570ef2244cc4d7563b1f0157bc0f032498638c ]
virtio_gpu_gem_create() owns the reference taken by
virtio_gpu_object_create(). On the drm_gem_handle_create() error path it
calls drm_gem_object_release() instead of dropping that reference.
drm_gem_object_release() is the inverse of drm_gem_object_init() and does
not touch the reference count or call obj->funcs->free(), so it is only
correct as the last step of a destructor, as in
virtio_gpu_cleanup_object(). Using it here leaves the bo at refcount 1
with no remaining reference, so virtio_gpu_free_object() never runs and
the shmem pages, sg table and virtio_gpu_object are leaked. Since
virtio_gpu_object_create() has already set bo->created,
VIRTIO_GPU_CMD_RESOURCE_UNREF is not queued either, leaking the host-side
resource and the resource id.
drm_gem_handle_create_tail() drops the handle reference on all of its
internal error paths, so the caller only has to drop its own. Use
drm_gem_object_put(), matching the success path below.
Fixes: dc5698e80cf7 ("Add virtio gpu driver.")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-1-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_gem.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_gem.c b/drivers/gpu/drm/virtio/virtgpu_gem.c
index 2e75cdeb49b3d..0233a1c3181c5 100644
--- a/drivers/gpu/drm/virtio/virtgpu_gem.c
+++ b/drivers/gpu/drm/virtio/virtgpu_gem.c
@@ -45,7 +45,7 @@ static int virtio_gpu_gem_create(struct drm_file *file,
ret = drm_gem_handle_create(file, &obj->base.base, &handle);
if (ret) {
- drm_gem_object_release(&obj->base.base);
+ drm_gem_object_put(&obj->base.base);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 849/982] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (847 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 848/982] drm/virtio: fix object leak when drm_gem_handle_create() fails Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 850/982] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Greg Kroah-Hartman
` (139 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junrui Luo, Dmitry Osipenko,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 477bc3068fc3777b9d8ffd79e265b0dfdf2d3a6b ]
virtio_gpu_resource_create_ioctl() calls drm_gem_object_release() on the
drm_gem_handle_create() error path instead of dropping the reference it
owns, so obj->funcs->free() never runs and the virtio_gpu_object, its
pages and sg table, the resource id and the host-side resource are
leaked.
Use drm_gem_object_put() instead.
Fixes: 62fb7a5e1096 ("virtio-gpu: add 3d/virgl support")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-2-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
index bc8c1e9a845fd..df6edae131139 100644
--- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c
+++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
@@ -358,7 +358,7 @@ static int virtio_gpu_resource_create_ioctl(struct drm_device *dev, void *data,
ret = drm_gem_handle_create(file, obj, &handle);
if (ret) {
- drm_gem_object_release(obj);
+ drm_gem_object_put(obj);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 850/982] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (848 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 849/982] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 851/982] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Greg Kroah-Hartman
` (138 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junrui Luo, Dmitry Osipenko,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 24b6d5c7641412c9ebef0d4c8b888d49a0e6b880 ]
virtio_gpu_resource_create_blob_ioctl() calls drm_gem_object_release() on
both the virtio_gpu_resource_assign_uuid() and drm_gem_handle_create()
error paths instead of dropping the reference it owns, so
obj->funcs->free() never runs and the virtio_gpu_object, the resource id
and the host-side resource are leaked.
Use drm_gem_object_put() instead.
Fixes: 897b4d1acaf5 ("drm/virtio: implement blob resources: resource create blob ioctl")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-3-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
index df6edae131139..ef83b4f400697 100644
--- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c
+++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
@@ -724,14 +724,14 @@ static int virtio_gpu_resource_create_blob_ioctl(struct drm_device *dev,
if (params.blob_flags & VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE) {
ret = virtio_gpu_resource_assign_uuid(vgdev, bo);
if (ret) {
- drm_gem_object_release(obj);
+ drm_gem_object_put(obj);
return ret;
}
}
ret = drm_gem_handle_create(file, obj, &handle);
if (ret) {
- drm_gem_object_release(obj);
+ drm_gem_object_put(obj);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 851/982] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (849 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 850/982] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 852/982] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough Greg Kroah-Hartman
` (137 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junrui Luo, Dmitry Osipenko,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 036d28db1818af2f9d80db771f5405da84d7732d ]
virtio_gpu_vram_create() frees the object with a bare kfree(vram) on
both error paths after drm_gem_private_object_init() has run, and on the
second one after drm_gem_create_mmap_offset() has linked obj->vma_node
into the device's VMA offset manager. The freed object stays in that
interval tree, so a later lookup or insertion walks freed memory, and
the dma_resv and gpuva lock are never destroyed.
Call drm_gem_object_release() before kfree() on both paths.
Fixes: 16845c5d5409 ("drm/virtio: implement blob resources: implement vram object")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-4-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_vram.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_vram.c b/drivers/gpu/drm/virtio/virtgpu_vram.c
index 6b45b0429fef9..51a2d8252dc7d 100644
--- a/drivers/gpu/drm/virtio/virtgpu_vram.c
+++ b/drivers/gpu/drm/virtio/virtgpu_vram.c
@@ -202,16 +202,12 @@ int virtio_gpu_vram_create(struct virtio_gpu_device *vgdev,
/* Create fake offset */
ret = drm_gem_create_mmap_offset(obj);
- if (ret) {
- kfree(vram);
- return ret;
- }
+ if (ret)
+ goto err_release_obj;
ret = virtio_gpu_resource_id_get(vgdev, &vram->base.hw_res_handle);
- if (ret) {
- kfree(vram);
- return ret;
- }
+ if (ret)
+ goto err_release_obj;
virtio_gpu_cmd_resource_create_blob(vgdev, &vram->base, params, NULL,
0);
@@ -225,4 +221,9 @@ int virtio_gpu_vram_create(struct virtio_gpu_device *vgdev,
*bo_ptr = &vram->base;
return 0;
+
+err_release_obj:
+ drm_gem_object_release(obj);
+ kfree(vram);
+ return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 852/982] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (850 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 851/982] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 853/982] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() Greg Kroah-Hartman
` (136 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng, Luiz Augusto von Dentz,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
[ Upstream commit f0ca020cbb9bb7f3f4ea8ba1dfcf30a282aec91e ]
Fix multiple out-of-bounds reads in Bluetooth BNEP frame processing:
1. In bnep_rx_frame() and bnep_ctrl_frame() (net/bluetooth/bnep/core.c),
use pskb_may_pull() to verify the BNEP header, control type byte,
filter count, and extension headers exist before reading them, and
return 0 after handling BNEP_CONTROL instead of falling through to
Ethernet frame submission when no extension headers follow.
2. In bnep_net_xmit() (net/bluetooth/bnep/netdev.c), verify skb->len >=
ETH_HLEN with pskb_may_pull() before reading the 14-byte Ethernet
header to prevent an out-of-bounds heap read and infoleak on short
AF_PACKET TX frames.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/bnep/core.c | 17 ++++++++++++++++-
net/bluetooth/bnep/netdev.c | 8 +++++++-
2 files changed, 23 insertions(+), 2 deletions(-)
diff --git a/net/bluetooth/bnep/core.c b/net/bluetooth/bnep/core.c
index a691d228f66c5..d6f69b6710623 100644
--- a/net/bluetooth/bnep/core.c
+++ b/net/bluetooth/bnep/core.c
@@ -273,9 +273,14 @@ static int bnep_rx_extension(struct bnep_session *s, struct sk_buff *skb)
BT_DBG("type 0x%x len %u", h->type, h->len);
+ if (skb->len < h->len) {
+ err = -EILSEQ;
+ break;
+ }
+
switch (h->type & BNEP_TYPE_MASK) {
case BNEP_EXT_CONTROL:
- bnep_rx_control(s, skb->data, skb->len);
+ bnep_rx_control(s, skb->data, h->len);
break;
default:
@@ -376,6 +381,11 @@ static int bnep_rx_frame(struct bnep_session *s, struct sk_buff *skb)
goto badframe;
}
+ if ((type & BNEP_TYPE_MASK) == BNEP_CONTROL) {
+ kfree_skb(skb);
+ return 0;
+ }
+
/* Strip 802.1p header */
if (ntohs(s->eh.h_proto) == ETH_P_8021Q) {
if (!skb_pull(skb, 4))
@@ -454,6 +464,11 @@ static int bnep_tx_frame(struct bnep_session *s, struct sk_buff *skb)
goto send;
}
+ if (skb->len < ETH_HLEN) {
+ kfree_skb(skb);
+ return 0;
+ }
+
iv[il++] = (struct kvec) { &type, 1 };
len++;
diff --git a/net/bluetooth/bnep/netdev.c b/net/bluetooth/bnep/netdev.c
index cc1cff63194f0..5d9d851db926f 100644
--- a/net/bluetooth/bnep/netdev.c
+++ b/net/bluetooth/bnep/netdev.c
@@ -169,6 +169,12 @@ static netdev_tx_t bnep_net_xmit(struct sk_buff *skb,
BT_DBG("skb %p, dev %p", skb, dev);
+ if (!pskb_may_pull(skb, ETH_HLEN)) {
+ dev->stats.tx_dropped++;
+ kfree_skb(skb);
+ return NETDEV_TX_OK;
+ }
+
#ifdef CONFIG_BT_BNEP_MC_FILTER
if (bnep_net_mc_filter(skb, s)) {
kfree_skb(skb);
@@ -221,7 +227,7 @@ void bnep_net_setup(struct net_device *dev)
dev->addr_len = ETH_ALEN;
ether_setup(dev);
- dev->min_mtu = 0;
+ dev->min_mtu = ETH_MIN_MTU;
dev->max_mtu = ETH_MAX_MTU;
dev->priv_flags &= ~IFF_TX_SKB_SHARING;
dev->netdev_ops = &bnep_netdev_ops;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 853/982] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (851 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 852/982] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 854/982] net: usb: sr9700: include receive overhead in the length check Greg Kroah-Hartman
` (135 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng, Luiz Augusto von Dentz,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
[ Upstream commit 6d91041bb38b97e2feb625123cc0529d7b83a0e1 ]
While rfcomm_recv_frame() verifies that skb->len is at least
sizeof(*hdr) + 1 (4 bytes: 3-byte header + 1-byte FCS), an RFCOMM frame
with an extended 2-byte length field (!__test_ea(hdr->len)) has a 4-byte
header plus a 1-byte FCS (5 bytes minimum, sizeof(*hdr) + 2).
When a 4-byte RFCOMM frame with EA == 0 arrives:
1. The initial skb->len < sizeof(*hdr) + 1 check passes (4 < 4 is false).
2. Trimming the FCS byte decrements skb->len to 3.
3. If __check_fcs() succeeds, skb_pull(skb, 4) fails (4 > 3) and returns
NULL without advancing skb->data.
4. Because the return value of skb_pull() is ignored, the un-pulled
3-byte struct rfcomm_hdr remains at skb->data and is either queued as
application payload via rfcomm_recv_data() or parsed as a multiplexer
control command via rfcomm_recv_mcc() on DLCI 0.
Fix this by extending the length check in rfcomm_recv_frame() to also
require skb->len >= sizeof(*hdr) + 2 when !__test_ea(hdr->len).
Fixes: b230e5bf501c ("Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/rfcomm/core.c b/net/bluetooth/rfcomm/core.c
index 104d75908dbc9..6324e03ff0d07 100644
--- a/net/bluetooth/rfcomm/core.c
+++ b/net/bluetooth/rfcomm/core.c
@@ -1813,7 +1813,8 @@ static struct rfcomm_session *rfcomm_recv_frame(struct rfcomm_session *s,
return s;
}
- if (skb->len < sizeof(*hdr) + 1) {
+ if (skb->len < sizeof(*hdr) + 1 ||
+ (!__test_ea(hdr->len) && skb->len < sizeof(*hdr) + 2)) {
kfree_skb(skb);
return s;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 854/982] net: usb: sr9700: include receive overhead in the length check
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (852 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 853/982] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 855/982] tg3: clean up PHYLIB resources on probe failure Greg Kroah-Hartman
` (134 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ethan Nelson-Moore, Pengpeng Hou,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <hppiscas@163.com>
[ Upstream commit c06bde80ae7a7b595732f7cabcb92cf08db9d56a ]
The receive fixup subtracts the Ethernet CRC from the reported packet
length, but compares that payload length against the whole remaining
receive buffer. The following copy starts after the three-byte header,
and the cursor advance consumes both that header and the four-byte CRC.
Require the payload to fit after SR_RX_OVERHEAD before copying it or
advancing to the next packet. The loop already ensures that the
remaining buffer is larger than the overhead, so the subtraction is
safe.
The issue was found by our static-analysis tool.
Fixes: c9b37458e956 ("USB2NET : SR9700 : One chip USB 1.1 USB2NET SR9700Device Driver Support")
Reviewed-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Tested-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Signed-off-by: Pengpeng Hou <hppiscas@163.com>
Link: https://patch.msgid.link/20260920034745.18468-1-hppiscas@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/sr9700.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/usb/sr9700.c b/drivers/net/usb/sr9700.c
index e4d7bcd0d99c2..202bb55e811f4 100644
--- a/drivers/net/usb/sr9700.c
+++ b/drivers/net/usb/sr9700.c
@@ -403,7 +403,8 @@ static int sr9700_rx_fixup(struct usbnet *dev, struct sk_buff *skb)
/* ignore the CRC length */
len = (skb->data[1] | (skb->data[2] << 8)) - 4;
- if (len > ETH_FRAME_LEN || len > skb->len || len < 0)
+ if (len > ETH_FRAME_LEN || len < 0 ||
+ len > skb->len - SR_RX_OVERHEAD)
return 0;
/* the last packet of current skb */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 855/982] tg3: clean up PHYLIB resources on probe failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (853 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 854/982] net: usb: sr9700: include receive overhead in the length check Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 856/982] s390/debug: Do not register views for failed static debug areas Greg Kroah-Hartman
` (133 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Paolo Abeni,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit a92e1a412c53dc0d9ad639e7abf8b3fc70a5b6ad ]
tg3_get_invariants() can register an MDIO bus and connect a PHY for
USE_PHYLIB devices. If tg3_init_one() later fails, its common error path
releases the mappings and netdev without undoing those PHYLIB resources.
Disconnect the PHY and unregister the MDIO bus before the remaining
teardown. Guard PHY cleanup with USE_PHYLIB to match tg3_phy_init(), and
call tg3_mdio_fini() unconditionally to match tg3_mdio_init(). The existing
IS_CONNECTED and MDIOBUS_INITED flags make both helpers safe when
initialization only completed partially.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: 158d7abdae85 ("tg3: Add mdio bus registration")
Assisted-by: OpenAI:GPT-5.6
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Link: https://patch.msgid.link/20260917183336.36239-1-mhun512@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/tg3.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/ethernet/broadcom/tg3.c b/drivers/net/ethernet/broadcom/tg3.c
index 5e8c11fc5912a..65bab84f4d972 100644
--- a/drivers/net/ethernet/broadcom/tg3.c
+++ b/drivers/net/ethernet/broadcom/tg3.c
@@ -17969,6 +17969,10 @@ static int tg3_init_one(struct pci_dev *pdev,
return 0;
err_out_apeunmap:
+ if (tg3_flag(tp, USE_PHYLIB))
+ tg3_phy_fini(tp);
+ tg3_mdio_fini(tp);
+
if (tp->aperegs) {
iounmap(tp->aperegs);
tp->aperegs = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 856/982] s390/debug: Do not register views for failed static debug areas
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (854 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 855/982] tg3: clean up PHYLIB resources on probe failure Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 857/982] s390/debug: Fix NULL pointer dereference in debug_info_copy() Greg Kroah-Hartman
` (132 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikhail Zaslonko, Heiko Carstens,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikhail Zaslonko <zaslonko@linux.ibm.com>
[ Upstream commit 28e29992b034acffc9342df216c06097825ce610 ]
__REGISTER_STATIC_DEBUG_INFO() calls debug_register_view()
unconditionally, even when debug_register_static() has failed. In that
case _debug_register() was never reached and id->debugfs_root_entry is
still NULL, so debugfs_create_file() places the view file in the debugfs
root directory. For sclp_err this leaves a /sys/kernel/debug/hex_ascii
file with nothing to indicate which debug log it belongs to.
debug_register_static() is not exported and the macro is its only
caller, so let it return an error code and skip the view registration
when it fails. No debugfs files are created for such an area then.
Reproduce by booting with s390dbf=sclp_err::100000000. The sclp_err
registration fails, no s390dbf/sclp_err/ directory is created, and a
hex_ascii file appears in the debugfs root instead.
Fixes: d72541f94512 ("s390/debug: add early tracing support")
Signed-off-by: Mikhail Zaslonko <zaslonko@linux.ibm.com>
Reviewed-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/include/asm/debug.h | 8 ++++++--
arch/s390/kernel/debug.c | 12 +++++++++---
2 files changed, 15 insertions(+), 5 deletions(-)
diff --git a/arch/s390/include/asm/debug.h b/arch/s390/include/asm/debug.h
index ac665b9670c5d..0c56b1b4a171d 100644
--- a/arch/s390/include/asm/debug.h
+++ b/arch/s390/include/asm/debug.h
@@ -451,7 +451,11 @@ static int VNAME(var, active_entries)[EARLY_AREAS] __initdata
#define __REGISTER_STATIC_DEBUG_INFO(var, name, pages, areas, view) \
static int __init VNAME(var, reg)(void) \
{ \
- debug_register_static(&var, (pages), (areas)); \
+ int rc; \
+ \
+ rc = debug_register_static(&var, (pages), (areas)); \
+ if (rc) \
+ return rc; \
debug_register_view(&var, (view)); \
return 0; \
} \
@@ -483,7 +487,7 @@ static debug_info_t __refdata var = \
__DEBUG_INFO_INIT(var, (name), (buf_size)); \
__REGISTER_STATIC_DEBUG_INFO(var, name, pages, nr_areas, view)
-void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas);
+int debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas);
#endif /* MODULE */
diff --git a/arch/s390/kernel/debug.c b/arch/s390/kernel/debug.c
index 8cc747b39c84d..ea7c31b407023 100644
--- a/arch/s390/kernel/debug.c
+++ b/arch/s390/kernel/debug.c
@@ -703,8 +703,12 @@ EXPORT_SYMBOL(debug_register);
*
* Note: This function is called automatically via an initcall generated by
* DEFINE_STATIC_DEBUG_INFO.
+ *
+ * Return:
+ * - 0 on success
+ * - negative error code on failure
*/
-void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
+int debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
{
unsigned long flags;
debug_info_t *copy;
@@ -712,7 +716,7 @@ void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
if (!initialized) {
pr_err("Tried to register debug feature %s too early\n",
id->name);
- return;
+ return -EINVAL;
}
copy = debug_info_alloc("", pages_per_area, nr_areas, id->buf_size,
@@ -727,7 +731,7 @@ void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
id->active_entries = NULL;
spin_unlock_irqrestore(&id->lock, flags);
- return;
+ return -ENOMEM;
}
/* Replace static trace area with dynamic copy. */
@@ -745,6 +749,8 @@ void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
mutex_lock(&debug_mutex);
_debug_register(id);
mutex_unlock(&debug_mutex);
+
+ return 0;
}
/* Remove debugfs entries. */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 857/982] s390/debug: Fix NULL pointer dereference in debug_info_copy()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (855 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 856/982] s390/debug: Do not register views for failed static debug areas Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 858/982] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error Greg Kroah-Hartman
` (131 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikhail Zaslonko,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikhail Zaslonko <zaslonko@linux.ibm.com>
[ Upstream commit 012bfcd5a51082d5a65f096dfb9ca652b5267965 ]
When debug_register_static() fails, it clears areas, active_pages and
active_entries but leaves the area bounds unchanged. Copying such an
area, either by opening its view file or via debug_dump(), makes
debug_info_copy() dereference the NULL pointers.
Skip the copy loop when the source has no areas.
Closes: https://lore.kernel.org/r/20260903132123.12F271F00A3F@smtp.kernel.org
Fixes: d72541f94512 ("s390/debug: add early tracing support")
Signed-off-by: Mikhail Zaslonko <zaslonko@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kernel/debug.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/s390/kernel/debug.c b/arch/s390/kernel/debug.c
index ea7c31b407023..1b23ff7162e5a 100644
--- a/arch/s390/kernel/debug.c
+++ b/arch/s390/kernel/debug.c
@@ -345,7 +345,8 @@ static debug_info_t *debug_info_copy(debug_info_t *in, int mode)
debug_info_free(rc);
} while (1);
- if (mode == NO_AREAS)
+ /* debug_register_static() failure leaves areas NULL, bounds intact */
+ if (mode == NO_AREAS || !in->areas)
goto out;
for (i = 0; i < in->nr_areas; i++) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 858/982] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (856 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 857/982] s390/debug: Fix NULL pointer dereference in debug_info_copy() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 859/982] bpf: Fix bpf_sock context code generation Greg Kroah-Hartman
` (130 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, bui duc phuc, Simon Horman,
Paolo Abeni, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: bui duc phuc <phucduc.bui@gmail.com>
[ Upstream commit ac4334522e4ba4a3b6710dd5d4cc98092824b8ca ]
pm_runtime_get_sync() leaves the runtime PM usage counter incremented even
when it fails, but the error path in netcp_probe() does not call
pm_runtime_put_noidle() to balance it, leaking a reference each time
resume fails.
Use pm_runtime_resume_and_get() instead, which automatically drops the
usage counter on failure, fixing the leak.
Fixes: 84640e27f230 ("net: netcp: Add Keystone NetCP core ethernet driver")
Signed-off-by: bui duc phuc <phucduc.bui@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260918042804.13101-1-phucduc.bui@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ti/netcp_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/netcp_core.c b/drivers/net/ethernet/ti/netcp_core.c
index 6c0c9b795c8fe..21bee6a5172a0 100644
--- a/drivers/net/ethernet/ti/netcp_core.c
+++ b/drivers/net/ethernet/ti/netcp_core.c
@@ -2167,7 +2167,7 @@ static int netcp_probe(struct platform_device *pdev)
return -ENOMEM;
pm_runtime_enable(&pdev->dev);
- ret = pm_runtime_get_sync(&pdev->dev);
+ ret = pm_runtime_resume_and_get(&pdev->dev);
if (ret < 0) {
dev_err(dev, "Failed to enable NETCP power-domain\n");
pm_runtime_disable(&pdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 859/982] bpf: Fix bpf_sock context code generation
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (857 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 858/982] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 860/982] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc Greg Kroah-Hartman
` (129 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini, Emil Tsalapatis,
Alexei Starovoitov, Jiayuan Chen, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emil Tsalapatis <emil@etsalapatis.com>
[ Upstream commit 4a4852376e3a2727ea40e61143d6d7c22bb6dfad ]
Currently, the ctx access code reads the rx_queue_mapping
field with either a 4-byte or 2-byte load. The rest of the bits
in the register are marked known zero by the verifier. However,
the emitted ctx access code places in the register on certain
the special value (-1) using BPF_MOV_IMM64, which gets sign-extended
to turn on all the bits in the register. By shifting this value right,
the program ends up with a value at runtime above what the verifier
assumes is possible.
Fix this by ensuring the read value is as wide as the assumed size.
Use MOV32 instructions instead of MOV64 instructions to keep
the upper bits zero as assumed by the verifier. Also properly report
the size of the destination variable (the bpf_sock field, 4 bytes) instead
of the source (the socket field, 2 bytes).
Fixes: c3c16f2ea6d2 ("bpf: Add rx_queue_mapping to bpf_sock")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-4-emil@etsalapatis.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 12caa1ac346cf..678fd0c108c84 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -10049,11 +10049,12 @@ u32 bpf_sock_convert_ctx_access(enum bpf_access_type type,
target_size));
*insn++ = BPF_JMP_IMM(BPF_JNE, si->dst_reg, NO_QUEUE_MAPPING,
1);
- *insn++ = BPF_MOV64_IMM(si->dst_reg, -1);
+ *insn++ = BPF_MOV32_IMM(si->dst_reg, -1);
#else
- *insn++ = BPF_MOV64_IMM(si->dst_reg, -1);
- *target_size = 2;
+ *insn++ = BPF_MOV32_IMM(si->dst_reg, -1);
#endif
+ *target_size = sizeof_field(struct bpf_sock, rx_queue_mapping);
+
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 860/982] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (858 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 859/982] bpf: Fix bpf_sock context code generation Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 861/982] net/mlx5: Add mlx5_ifc definitions for bridge multicast support Greg Kroah-Hartman
` (128 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhao Gongyi, Alexei Starovoitov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
[ Upstream commit 814a81c842bd88f6bd8a4ce550d560df071a5d03 ]
sock_map_alloc() only rejects max_entries == 0 and otherwise allows any
u32 value. sock_map_free() then walks the sks[] array with a signed int
iterator:
int i;
for (i = 0; i < stab->map.max_entries; i++)
struct sock **psk = &stab->sks[i];
When a SOCKMAP is created with max_entries = 0xffffffff (UINT_MAX), the
allocation of 32 GiB can succeed on large-memory hosts. During free the
counter reaches 0x80000000, wraps to INT_MIN, is sign-extended by movslq
and turned into a ~16 GiB negative offset from stab->sks, pointing far
below the allocation.
The faulting access is an xchg() write in sock_map_free(). Without
KASAN, the same out-of-bounds write can fault on an unmapped vmalloc page
or corrupt an unrelated allocation if that vmalloc address is populated.
On a KASAN kernel with CONFIG_KASAN_VMALLOC=y, the shadow check for that
address hits an unmapped shadow page and oopses first:
BUG: unable to handle page fault for address: fffff521b59c5a00
RIP: 0010:kasan_check_range+0x107/0x190
Call Trace:
sock_map_free+0x93/0x190
map_create+0x68d/0xb30
__sys_bpf+0x21e/0x2e70
Vmcore confirmed stab->map.max_entries == 0xffffffff, stab->sks ==
0xffffc911ace2d000, and the faulting address sks + (s64)INT_MIN * 8
exactly at 0xffffc90dace2d000. The same buggy path is reached on the
normal close()/bpf_map_free_deferred() path whenever such a map is
destroyed.
sock_map_alloc() used to bound its allocation size through
bpf_map_charge_init(), but the bound was dropped when rlimit-based memory
accounting was removed. Reject max_entries > INT_MAX at creation time so
the signed iterator in sock_map_free() never sees a value that would
overflow.
Triggered by syzkaller and reproduced on both a 6.6-based KASAN kernel
and the upstream v7.3-rc2 kernel.
Fixes: 0d2c4f964050 ("bpf: Eliminate rlimit-based memory accounting for sockmap and sockhash maps")
Signed-off-by: Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260917121016.48171-1-zhaogongyi@bytedance.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/sock_map.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/core/sock_map.c b/net/core/sock_map.c
index fb10c33acc3fd..582eb60af7680 100644
--- a/net/core/sock_map.c
+++ b/net/core/sock_map.c
@@ -35,6 +35,7 @@ static struct bpf_map *sock_map_alloc(union bpf_attr *attr)
if (!capable(CAP_NET_ADMIN))
return ERR_PTR(-EPERM);
if (attr->max_entries == 0 ||
+ attr->max_entries > INT_MAX ||
attr->key_size != 4 ||
(attr->value_size != sizeof(u32) &&
attr->value_size != sizeof(u64)) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 861/982] net/mlx5: Add mlx5_ifc definitions for bridge multicast support
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (859 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 860/982] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 862/982] net/mlx5: Bridge, increase bridge tables sizes Greg Kroah-Hartman
` (127 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlad Buslov, Maor Dickman, Roi Dayan,
Saeed Mahameed, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlad Buslov <vladbu@nvidia.com>
[ Upstream commit e5688f6fb9e3d0254a8fb1c714c38e407f0baa64 ]
Add the required hardware definitions to mlx5_ifc: fdb_uplink_hairpin,
fdb_multi_path_any_table_limit_regc, fdb_multi_path_any_table.
Signed-off-by: Vlad Buslov <vladbu@nvidia.com>
Reviewed-by: Maor Dickman <maord@nvidia.com>
Reviewed-by: Roi Dayan <roid@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Stable-dep-of: 35e6f970f553 ("net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/mlx5/mlx5_ifc.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/include/linux/mlx5/mlx5_ifc.h b/include/linux/mlx5/mlx5_ifc.h
index 9610b325f2b61..5fa2e164d0d42 100644
--- a/include/linux/mlx5/mlx5_ifc.h
+++ b/include/linux/mlx5/mlx5_ifc.h
@@ -865,7 +865,12 @@ enum {
struct mlx5_ifc_flow_table_eswitch_cap_bits {
u8 fdb_to_vport_reg_c_id[0x8];
- u8 reserved_at_8[0xd];
+ u8 reserved_at_8[0x5];
+ u8 fdb_uplink_hairpin[0x1];
+ u8 fdb_multi_path_any_table_limit_regc[0x1];
+ u8 reserved_at_f[0x3];
+ u8 fdb_multi_path_any_table[0x1];
+ u8 reserved_at_13[0x2];
u8 fdb_modify_header_fwd_to_table[0x1];
u8 fdb_ipv4_ttl_modify[0x1];
u8 flow_source[0x1];
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 862/982] net/mlx5: Bridge, increase bridge tables sizes
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (860 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 861/982] net/mlx5: Add mlx5_ifc definitions for bridge multicast support Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 863/982] net/mlx5: Bridge, move additional data structures to priv header Greg Kroah-Hartman
` (126 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlad Buslov, Maor Dickman, Roi Dayan,
Saeed Mahameed, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlad Buslov <vladbu@nvidia.com>
[ Upstream commit 9071b423c302b70eff80da715d724c4e75c1c46a ]
Bridge ingress and egress tables got more flow groups recently for QinQ
support and will get more in following patches of this series. Increase the
sizes of the tables to allow offloading more flows in each mode.
Signed-off-by: Vlad Buslov <vladbu@nvidia.com>
Reviewed-by: Maor Dickman <maord@nvidia.com>
Reviewed-by: Roi Dayan <roid@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Stable-dep-of: 35e6f970f553 ("net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index d0b2676c32145..6cd7c5817922c 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -13,8 +13,8 @@
#define CREATE_TRACE_POINTS
#include "diag/bridge_tracepoint.h"
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE 12000
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE 16000
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE 131072
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE 524288
#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_FROM 0
#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO \
(MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
@@ -40,10 +40,10 @@
MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE - 1)
#define MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE \
(MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_TO + 1)
-static_assert(MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE == 64000);
+static_assert(MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE == 1048576);
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE 16000
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_SIZE (32000 - 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE 131072
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_SIZE (262144 - 1)
#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_FROM 0
#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_TO \
(MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE - 1)
@@ -63,7 +63,7 @@ static_assert(MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE == 64000);
MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_FROM
#define MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE \
(MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_TO + 1)
-static_assert(MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE == 64000);
+static_assert(MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE == 524288);
#define MLX5_ESW_BRIDGE_SKIP_TABLE_SIZE 0
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 863/982] net/mlx5: Bridge, move additional data structures to priv header
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (861 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 862/982] net/mlx5: Bridge, increase bridge tables sizes Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 864/982] net/mlx5: Bridge, extract code to lookup parent bridge of port Greg Kroah-Hartman
` (125 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlad Buslov, Maor Dickman, Roi Dayan,
Saeed Mahameed, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlad Buslov <vladbu@nvidia.com>
[ Upstream commit 6767c97d7adc3c4283c0167a9716de3953f251b1 ]
Following patches in series will require accessing flow tables and groups
sizes, table levels and struct mlx5_esw_bridge from new the new source file
dedicated to multicast code. Expose these data in bridge_priv.h to reduce
clutter in following patches that will implement the actual functionality.
Signed-off-by: Vlad Buslov <vladbu@nvidia.com>
Reviewed-by: Maor Dickman <maord@nvidia.com>
Reviewed-by: Roi Dayan <roid@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Stable-dep-of: 35e6f970f553 ("net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../ethernet/mellanox/mlx5/core/esw/bridge.c | 85 -------------------
.../mellanox/mlx5/core/esw/bridge_priv.h | 85 +++++++++++++++++++
2 files changed, 85 insertions(+), 85 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index 6cd7c5817922c..f1752852c70f3 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -13,66 +13,6 @@
#define CREATE_TRACE_POINTS
#include "diag/bridge_tracepoint.h"
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE 131072
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE 524288
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_FROM 0
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_FROM + \
- MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_FROM + \
- MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_FROM + \
- MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_FROM + \
- MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_TO + 1)
-static_assert(MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE == 1048576);
-
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE 131072
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_SIZE (262144 - 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_FROM 0
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_FROM + \
- MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_FROM + \
- MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_SIZE - 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_FROM \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_TO + 1)
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_TO \
- MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_FROM
-#define MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE \
- (MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_TO + 1)
-static_assert(MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE == 524288);
-
-#define MLX5_ESW_BRIDGE_SKIP_TABLE_SIZE 0
-
-enum {
- MLX5_ESW_BRIDGE_LEVEL_INGRESS_TABLE,
- MLX5_ESW_BRIDGE_LEVEL_EGRESS_TABLE,
- MLX5_ESW_BRIDGE_LEVEL_SKIP_TABLE,
-};
-
static const struct rhashtable_params fdb_ht_params = {
.key_offset = offsetof(struct mlx5_esw_bridge_fdb_entry, key),
.key_len = sizeof(struct mlx5_esw_bridge_fdb_key),
@@ -80,31 +20,6 @@ static const struct rhashtable_params fdb_ht_params = {
.automatic_shrinking = true,
};
-enum {
- MLX5_ESW_BRIDGE_VLAN_FILTERING_FLAG = BIT(0),
-};
-
-struct mlx5_esw_bridge {
- int ifindex;
- int refcnt;
- struct list_head list;
- struct mlx5_esw_bridge_offloads *br_offloads;
-
- struct list_head fdb_list;
- struct rhashtable fdb_ht;
-
- struct mlx5_flow_table *egress_ft;
- struct mlx5_flow_group *egress_vlan_fg;
- struct mlx5_flow_group *egress_qinq_fg;
- struct mlx5_flow_group *egress_mac_fg;
- struct mlx5_flow_group *egress_miss_fg;
- struct mlx5_pkt_reformat *egress_miss_pkt_reformat;
- struct mlx5_flow_handle *egress_miss_handle;
- unsigned long ageing_time;
- u32 flags;
- u16 vlan_proto;
-};
-
static void
mlx5_esw_bridge_fdb_offload_notify(struct net_device *dev, const unsigned char *addr, u16 vid,
unsigned long val)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h
index 878311fe950a4..b99761e73c1b6 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h
@@ -12,6 +12,70 @@
#include <linux/xarray.h>
#include "fs_core.h"
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE 131072
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE 524288
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_FROM 0
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_QINQ_FILTER_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_MAC_GRP_IDX_TO + 1)
+static_assert(MLX5_ESW_BRIDGE_INGRESS_TABLE_SIZE == 1048576);
+
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE 131072
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_SIZE (262144 - 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_FROM 0
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_EGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_QINQ_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_MAC_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_TO \
+ MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_FROM
+#define MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE \
+ (MLX5_ESW_BRIDGE_EGRESS_TABLE_MISS_GRP_IDX_TO + 1)
+static_assert(MLX5_ESW_BRIDGE_EGRESS_TABLE_SIZE == 524288);
+
+#define MLX5_ESW_BRIDGE_SKIP_TABLE_SIZE 0
+
+enum {
+ MLX5_ESW_BRIDGE_LEVEL_INGRESS_TABLE,
+ MLX5_ESW_BRIDGE_LEVEL_EGRESS_TABLE,
+ MLX5_ESW_BRIDGE_LEVEL_SKIP_TABLE,
+};
+
+enum {
+ MLX5_ESW_BRIDGE_VLAN_FILTERING_FLAG = BIT(0),
+};
+
struct mlx5_esw_bridge_fdb_key {
unsigned char addr[ETH_ALEN];
u16 vid;
@@ -60,4 +124,25 @@ struct mlx5_esw_bridge_port {
struct xarray vlans;
};
+struct mlx5_esw_bridge {
+ int ifindex;
+ int refcnt;
+ struct list_head list;
+ struct mlx5_esw_bridge_offloads *br_offloads;
+
+ struct list_head fdb_list;
+ struct rhashtable fdb_ht;
+
+ struct mlx5_flow_table *egress_ft;
+ struct mlx5_flow_group *egress_vlan_fg;
+ struct mlx5_flow_group *egress_qinq_fg;
+ struct mlx5_flow_group *egress_mac_fg;
+ struct mlx5_flow_group *egress_miss_fg;
+ struct mlx5_pkt_reformat *egress_miss_pkt_reformat;
+ struct mlx5_flow_handle *egress_miss_handle;
+ unsigned long ageing_time;
+ u32 flags;
+ u16 vlan_proto;
+};
+
#endif /* _MLX5_ESW_BRIDGE_PRIVATE_ */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 864/982] net/mlx5: Bridge, extract code to lookup parent bridge of port
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (862 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 863/982] net/mlx5: Bridge, move additional data structures to priv header Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 865/982] net/mlx5: Bridge, snoop igmp/mld packets Greg Kroah-Hartman
` (124 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlad Buslov, Maor Dickman, Roi Dayan,
Saeed Mahameed, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlad Buslov <vladbu@nvidia.com>
[ Upstream commit b99c4ef29e278ab0b91406e52df4fa9b634b117e ]
The pattern when function looks up a port by vport_num+vhca_id tuple in
order to just obtain its parent bridge is repeated multiple times in
bridge.c file. Further commits in this series use the pattern even more.
Extract the pattern to standalone mlx5_esw_bridge_from_port_lookup()
function to improve code readability.
This commits doesn't change functionality.
Signed-off-by: Vlad Buslov <vladbu@nvidia.com>
Reviewed-by: Maor Dickman <maord@nvidia.com>
Reviewed-by: Roi Dayan <roid@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Stable-dep-of: 35e6f970f553 ("net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../ethernet/mellanox/mlx5/core/esw/bridge.c | 47 ++++++++++---------
1 file changed, 26 insertions(+), 21 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index f1752852c70f3..776441b16bb85 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -933,6 +933,19 @@ static void mlx5_esw_bridge_port_erase(struct mlx5_esw_bridge_port *port,
xa_erase(&br_offloads->ports, mlx5_esw_bridge_port_key(port));
}
+static struct mlx5_esw_bridge *
+mlx5_esw_bridge_from_port_lookup(u16 vport_num, u16 esw_owner_vhca_id,
+ struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ struct mlx5_esw_bridge_port *port;
+
+ port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+ if (!port)
+ return NULL;
+
+ return port->bridge;
+}
+
static void mlx5_esw_bridge_fdb_entry_refresh(struct mlx5_esw_bridge_fdb_entry *entry)
{
trace_mlx5_esw_bridge_fdb_entry_refresh(entry);
@@ -1388,28 +1401,26 @@ mlx5_esw_bridge_fdb_entry_init(struct net_device *dev, u16 vport_num, u16 esw_ow
int mlx5_esw_bridge_ageing_time_set(u16 vport_num, u16 esw_owner_vhca_id, unsigned long ageing_time,
struct mlx5_esw_bridge_offloads *br_offloads)
{
- struct mlx5_esw_bridge_port *port;
+ struct mlx5_esw_bridge *bridge;
- port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
- if (!port)
+ bridge = mlx5_esw_bridge_from_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+ if (!bridge)
return -EINVAL;
- port->bridge->ageing_time = clock_t_to_jiffies(ageing_time);
+ bridge->ageing_time = clock_t_to_jiffies(ageing_time);
return 0;
}
int mlx5_esw_bridge_vlan_filtering_set(u16 vport_num, u16 esw_owner_vhca_id, bool enable,
struct mlx5_esw_bridge_offloads *br_offloads)
{
- struct mlx5_esw_bridge_port *port;
struct mlx5_esw_bridge *bridge;
bool filtering;
- port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
- if (!port)
+ bridge = mlx5_esw_bridge_from_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+ if (!bridge)
return -EINVAL;
- bridge = port->bridge;
filtering = bridge->flags & MLX5_ESW_BRIDGE_VLAN_FILTERING_FLAG;
if (filtering == enable)
return 0;
@@ -1426,15 +1437,13 @@ int mlx5_esw_bridge_vlan_filtering_set(u16 vport_num, u16 esw_owner_vhca_id, boo
int mlx5_esw_bridge_vlan_proto_set(u16 vport_num, u16 esw_owner_vhca_id, u16 proto,
struct mlx5_esw_bridge_offloads *br_offloads)
{
- struct mlx5_esw_bridge_port *port;
struct mlx5_esw_bridge *bridge;
- port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id,
- br_offloads);
- if (!port)
+ bridge = mlx5_esw_bridge_from_port_lookup(vport_num, esw_owner_vhca_id,
+ br_offloads);
+ if (!bridge)
return -EINVAL;
- bridge = port->bridge;
if (bridge->vlan_proto == proto)
return 0;
if (proto != ETH_P_8021Q && proto != ETH_P_8021AD) {
@@ -1626,14 +1635,12 @@ void mlx5_esw_bridge_fdb_update_used(struct net_device *dev, u16 vport_num, u16
struct switchdev_notifier_fdb_info *fdb_info)
{
struct mlx5_esw_bridge_fdb_entry *entry;
- struct mlx5_esw_bridge_port *port;
struct mlx5_esw_bridge *bridge;
- port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
- if (!port)
+ bridge = mlx5_esw_bridge_from_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+ if (!bridge)
return;
- bridge = port->bridge;
entry = mlx5_esw_bridge_fdb_lookup(bridge, fdb_info->addr, fdb_info->vid);
if (!entry) {
esw_debug(br_offloads->esw->dev,
@@ -1680,14 +1687,12 @@ void mlx5_esw_bridge_fdb_remove(struct net_device *dev, u16 vport_num, u16 esw_o
{
struct mlx5_eswitch *esw = br_offloads->esw;
struct mlx5_esw_bridge_fdb_entry *entry;
- struct mlx5_esw_bridge_port *port;
struct mlx5_esw_bridge *bridge;
- port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
- if (!port)
+ bridge = mlx5_esw_bridge_from_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+ if (!bridge)
return;
- bridge = port->bridge;
entry = mlx5_esw_bridge_fdb_lookup(bridge, fdb_info->addr, fdb_info->vid);
if (!entry) {
esw_warn(esw->dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 865/982] net/mlx5: Bridge, snoop igmp/mld packets
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (863 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 864/982] net/mlx5: Bridge, extract code to lookup parent bridge of port Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 866/982] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports Greg Kroah-Hartman
` (123 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlad Buslov, Maor Dickman, Roi Dayan,
Saeed Mahameed, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlad Buslov <vladbu@nvidia.com>
[ Upstream commit 18c2916cee12137f32669d42ac1fbb87cba343bb ]
Handle SWITCHDEV_ATTR_ID_BRIDGE_MC_DISABLED attribute notification to
dynamically toggle bridge multicast offload. Set new
MLX5_ESW_BRIDGE_MCAST_FLAG bridge flag when multicast offload is enabled.
Put multicast-specific code into new bridge_mcast.c file.
When initializing bridge multicast pipeline create a static rule for
snooping on IGMP traffic and three rules for snooping on MLD traffic (for
query, report and done message types). Note that matching MLD traffic
requires having flexparser MLX5_FLEX_PROTO_ICMPV6 capability enabled.
By default Linux bridge is created with multicast enabled which can be
modified by 'mcast_snooping' argument:
$ ip link set name my_bridge type bridge mcast_snooping 0
Signed-off-by: Vlad Buslov <vladbu@nvidia.com>
Reviewed-by: Maor Dickman <maord@nvidia.com>
Reviewed-by: Roi Dayan <roid@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Stable-dep-of: 35e6f970f553 ("net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/mellanox/mlx5/core/Makefile | 2 +-
.../mellanox/mlx5/core/en/rep/bridge.c | 4 +
.../ethernet/mellanox/mlx5/core/esw/bridge.c | 31 ++
.../ethernet/mellanox/mlx5/core/esw/bridge.h | 9 +
.../mellanox/mlx5/core/esw/bridge_mcast.c | 316 ++++++++++++++++++
.../mellanox/mlx5/core/esw/bridge_priv.h | 27 +-
6 files changed, 384 insertions(+), 5 deletions(-)
create mode 100644 drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_mcast.c
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/Makefile b/drivers/net/ethernet/mellanox/mlx5/core/Makefile
index a22c32aabf111..0eb76b78e9121 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/Makefile
+++ b/drivers/net/ethernet/mellanox/mlx5/core/Makefile
@@ -75,7 +75,7 @@ mlx5_core-$(CONFIG_MLX5_ESWITCH) += esw/acl/helper.o \
esw/acl/egress_lgcy.o esw/acl/egress_ofld.o \
esw/acl/ingress_lgcy.o esw/acl/ingress_ofld.o
-mlx5_core-$(CONFIG_MLX5_BRIDGE) += esw/bridge.o en/rep/bridge.o
+mlx5_core-$(CONFIG_MLX5_BRIDGE) += esw/bridge.o esw/bridge_mcast.o en/rep/bridge.o
mlx5_core-$(CONFIG_MLX5_MPFS) += lib/mpfs.o
mlx5_core-$(CONFIG_VXLAN) += lib/vxlan.o
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
index 6748c92941b1e..6ea546a22b31a 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
@@ -301,6 +301,10 @@ mlx5_esw_bridge_port_obj_attr_set(struct net_device *dev,
attr->u.vlan_protocol,
br_offloads);
break;
+ case SWITCHDEV_ATTR_ID_BRIDGE_MC_DISABLED:
+ err = mlx5_esw_bridge_mcast_set(vport_num, esw_owner_vhca_id,
+ !attr->u.mc_disabled, br_offloads);
+ break;
default:
err = -EOPNOTSUPP;
}
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index 776441b16bb85..94d8f42e4318d 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -868,6 +868,7 @@ static void mlx5_esw_bridge_put(struct mlx5_esw_bridge_offloads *br_offloads,
return;
mlx5_esw_bridge_egress_table_cleanup(bridge);
+ mlx5_esw_bridge_mcast_disable(bridge);
list_del(&bridge->list);
rhashtable_destroy(&bridge->fdb_ht);
kvfree(bridge);
@@ -1458,6 +1459,36 @@ int mlx5_esw_bridge_vlan_proto_set(u16 vport_num, u16 esw_owner_vhca_id, u16 pro
return 0;
}
+int mlx5_esw_bridge_mcast_set(u16 vport_num, u16 esw_owner_vhca_id, bool enable,
+ struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ struct mlx5_eswitch *esw = br_offloads->esw;
+ struct mlx5_esw_bridge *bridge;
+ int err = 0;
+ bool mcast;
+
+ if (!(MLX5_CAP_ESW_FLOWTABLE((esw)->dev, fdb_multi_path_any_table) ||
+ MLX5_CAP_ESW_FLOWTABLE((esw)->dev, fdb_multi_path_any_table_limit_regc)) ||
+ !MLX5_CAP_ESW_FLOWTABLE((esw)->dev, fdb_uplink_hairpin) ||
+ !MLX5_CAP_ESW_FLOWTABLE_FDB((esw)->dev, ignore_flow_level))
+ return -EOPNOTSUPP;
+
+ bridge = mlx5_esw_bridge_from_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+ if (!bridge)
+ return -EINVAL;
+
+ mcast = bridge->flags & MLX5_ESW_BRIDGE_MCAST_FLAG;
+ if (mcast == enable)
+ return 0;
+
+ if (enable)
+ err = mlx5_esw_bridge_mcast_enable(bridge);
+ else
+ mlx5_esw_bridge_mcast_disable(bridge);
+
+ return err;
+}
+
static int mlx5_esw_bridge_vport_init(u16 vport_num, u16 esw_owner_vhca_id, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct mlx5_esw_bridge *bridge)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
index 10851a515bca8..b18f137173d98 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
@@ -25,12 +25,19 @@ struct mlx5_esw_bridge_offloads {
struct delayed_work update_work;
struct mlx5_flow_table *ingress_ft;
+ struct mlx5_flow_group *ingress_igmp_fg;
+ struct mlx5_flow_group *ingress_mld_fg;
struct mlx5_flow_group *ingress_vlan_fg;
struct mlx5_flow_group *ingress_vlan_filter_fg;
struct mlx5_flow_group *ingress_qinq_fg;
struct mlx5_flow_group *ingress_qinq_filter_fg;
struct mlx5_flow_group *ingress_mac_fg;
+ struct mlx5_flow_handle *igmp_handle;
+ struct mlx5_flow_handle *mld_query_handle;
+ struct mlx5_flow_handle *mld_report_handle;
+ struct mlx5_flow_handle *mld_done_handle;
+
struct mlx5_flow_table *skip_ft;
};
@@ -64,6 +71,8 @@ int mlx5_esw_bridge_vlan_filtering_set(u16 vport_num, u16 esw_owner_vhca_id, boo
struct mlx5_esw_bridge_offloads *br_offloads);
int mlx5_esw_bridge_vlan_proto_set(u16 vport_num, u16 esw_owner_vhca_id, u16 proto,
struct mlx5_esw_bridge_offloads *br_offloads);
+int mlx5_esw_bridge_mcast_set(u16 vport_num, u16 esw_owner_vhca_id, bool enable,
+ struct mlx5_esw_bridge_offloads *br_offloads);
int mlx5_esw_bridge_port_vlan_add(u16 vport_num, u16 esw_owner_vhca_id, u16 vid, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_mcast.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_mcast.c
new file mode 100644
index 0000000000000..d5a89a86c9e84
--- /dev/null
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_mcast.c
@@ -0,0 +1,316 @@
+// SPDX-License-Identifier: GPL-2.0 OR Linux-OpenIB
+/* Copyright (c) 2022, NVIDIA CORPORATION & AFFILIATES. All rights reserved. */
+
+#include "bridge.h"
+#include "eswitch.h"
+#include "bridge_priv.h"
+
+static struct mlx5_flow_group *
+mlx5_esw_bridge_ingress_igmp_fg_create(struct mlx5_eswitch *esw,
+ struct mlx5_flow_table *ingress_ft)
+{
+ int inlen = MLX5_ST_SZ_BYTES(create_flow_group_in);
+ struct mlx5_flow_group *fg;
+ u32 *in, *match;
+
+ in = kvzalloc(inlen, GFP_KERNEL);
+ if (!in)
+ return ERR_PTR(-ENOMEM);
+
+ MLX5_SET(create_flow_group_in, in, match_criteria_enable, MLX5_MATCH_OUTER_HEADERS);
+ match = MLX5_ADDR_OF(create_flow_group_in, in, match_criteria);
+
+ MLX5_SET_TO_ONES(fte_match_param, match, outer_headers.ip_version);
+ MLX5_SET_TO_ONES(fte_match_param, match, outer_headers.ip_protocol);
+
+ MLX5_SET(create_flow_group_in, in, start_flow_index,
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_IDX_FROM);
+ MLX5_SET(create_flow_group_in, in, end_flow_index,
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_IDX_TO);
+
+ fg = mlx5_create_flow_group(ingress_ft, in);
+ kvfree(in);
+ if (IS_ERR(fg))
+ esw_warn(esw->dev,
+ "Failed to create IGMP flow group for bridge ingress table (err=%pe)\n",
+ fg);
+
+ return fg;
+}
+
+static struct mlx5_flow_group *
+mlx5_esw_bridge_ingress_mld_fg_create(struct mlx5_eswitch *esw,
+ struct mlx5_flow_table *ingress_ft)
+{
+ int inlen = MLX5_ST_SZ_BYTES(create_flow_group_in);
+ struct mlx5_flow_group *fg;
+ u32 *in, *match;
+
+ if (!(MLX5_CAP_GEN(esw->dev, flex_parser_protocols) & MLX5_FLEX_PROTO_ICMPV6)) {
+ esw_warn(esw->dev,
+ "Can't create MLD flow group due to missing hardware ICMPv6 parsing support\n");
+ return NULL;
+ }
+
+ in = kvzalloc(inlen, GFP_KERNEL);
+ if (!in)
+ return ERR_PTR(-ENOMEM);
+
+ MLX5_SET(create_flow_group_in, in, match_criteria_enable,
+ MLX5_MATCH_OUTER_HEADERS | MLX5_MATCH_MISC_PARAMETERS_3);
+ match = MLX5_ADDR_OF(create_flow_group_in, in, match_criteria);
+
+ MLX5_SET_TO_ONES(fte_match_param, match, outer_headers.ip_version);
+ MLX5_SET_TO_ONES(fte_match_param, match, misc_parameters_3.icmpv6_type);
+
+ MLX5_SET(create_flow_group_in, in, start_flow_index,
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_IDX_FROM);
+ MLX5_SET(create_flow_group_in, in, end_flow_index,
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_IDX_TO);
+
+ fg = mlx5_create_flow_group(ingress_ft, in);
+ kvfree(in);
+ if (IS_ERR(fg))
+ esw_warn(esw->dev,
+ "Failed to create MLD flow group for bridge ingress table (err=%pe)\n",
+ fg);
+
+ return fg;
+}
+
+static int
+mlx5_esw_bridge_ingress_mcast_fgs_init(struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ struct mlx5_flow_table *ingress_ft = br_offloads->ingress_ft;
+ struct mlx5_eswitch *esw = br_offloads->esw;
+ struct mlx5_flow_group *igmp_fg, *mld_fg;
+
+ igmp_fg = mlx5_esw_bridge_ingress_igmp_fg_create(esw, ingress_ft);
+ if (IS_ERR(igmp_fg))
+ return PTR_ERR(igmp_fg);
+
+ mld_fg = mlx5_esw_bridge_ingress_mld_fg_create(esw, ingress_ft);
+ if (IS_ERR(mld_fg)) {
+ mlx5_destroy_flow_group(igmp_fg);
+ return PTR_ERR(mld_fg);
+ }
+
+ br_offloads->ingress_igmp_fg = igmp_fg;
+ br_offloads->ingress_mld_fg = mld_fg;
+ return 0;
+}
+
+static void
+mlx5_esw_bridge_ingress_mcast_fgs_cleanup(struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ if (br_offloads->ingress_mld_fg)
+ mlx5_destroy_flow_group(br_offloads->ingress_mld_fg);
+ br_offloads->ingress_mld_fg = NULL;
+ if (br_offloads->ingress_igmp_fg)
+ mlx5_destroy_flow_group(br_offloads->ingress_igmp_fg);
+ br_offloads->ingress_igmp_fg = NULL;
+}
+
+static struct mlx5_flow_handle *
+mlx5_esw_bridge_ingress_igmp_fh_create(struct mlx5_flow_table *ingress_ft,
+ struct mlx5_flow_table *skip_ft)
+{
+ struct mlx5_flow_destination dest = {
+ .type = MLX5_FLOW_DESTINATION_TYPE_FLOW_TABLE,
+ .ft = skip_ft,
+ };
+ struct mlx5_flow_act flow_act = {
+ .action = MLX5_FLOW_CONTEXT_ACTION_FWD_DEST,
+ .flags = FLOW_ACT_NO_APPEND,
+ };
+ struct mlx5_flow_spec *rule_spec;
+ struct mlx5_flow_handle *handle;
+
+ rule_spec = kvzalloc(sizeof(*rule_spec), GFP_KERNEL);
+ if (!rule_spec)
+ return ERR_PTR(-ENOMEM);
+
+ rule_spec->match_criteria_enable = MLX5_MATCH_OUTER_HEADERS;
+
+ MLX5_SET_TO_ONES(fte_match_param, rule_spec->match_criteria, outer_headers.ip_version);
+ MLX5_SET(fte_match_param, rule_spec->match_value, outer_headers.ip_version, 4);
+ MLX5_SET_TO_ONES(fte_match_param, rule_spec->match_criteria, outer_headers.ip_protocol);
+ MLX5_SET(fte_match_param, rule_spec->match_value, outer_headers.ip_protocol, IPPROTO_IGMP);
+
+ handle = mlx5_add_flow_rules(ingress_ft, rule_spec, &flow_act, &dest, 1);
+
+ kvfree(rule_spec);
+ return handle;
+}
+
+static struct mlx5_flow_handle *
+mlx5_esw_bridge_ingress_mld_fh_create(u8 type, struct mlx5_flow_table *ingress_ft,
+ struct mlx5_flow_table *skip_ft)
+{
+ struct mlx5_flow_destination dest = {
+ .type = MLX5_FLOW_DESTINATION_TYPE_FLOW_TABLE,
+ .ft = skip_ft,
+ };
+ struct mlx5_flow_act flow_act = {
+ .action = MLX5_FLOW_CONTEXT_ACTION_FWD_DEST,
+ .flags = FLOW_ACT_NO_APPEND,
+ };
+ struct mlx5_flow_spec *rule_spec;
+ struct mlx5_flow_handle *handle;
+
+ rule_spec = kvzalloc(sizeof(*rule_spec), GFP_KERNEL);
+ if (!rule_spec)
+ return ERR_PTR(-ENOMEM);
+
+ rule_spec->match_criteria_enable = MLX5_MATCH_OUTER_HEADERS | MLX5_MATCH_MISC_PARAMETERS_3;
+
+ MLX5_SET_TO_ONES(fte_match_param, rule_spec->match_criteria, outer_headers.ip_version);
+ MLX5_SET(fte_match_param, rule_spec->match_value, outer_headers.ip_version, 6);
+ MLX5_SET_TO_ONES(fte_match_param, rule_spec->match_criteria, misc_parameters_3.icmpv6_type);
+ MLX5_SET(fte_match_param, rule_spec->match_value, misc_parameters_3.icmpv6_type, type);
+
+ handle = mlx5_add_flow_rules(ingress_ft, rule_spec, &flow_act, &dest, 1);
+
+ kvfree(rule_spec);
+ return handle;
+}
+
+static int
+mlx5_esw_bridge_ingress_mcast_fhs_create(struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ struct mlx5_flow_handle *igmp_handle, *mld_query_handle, *mld_report_handle,
+ *mld_done_handle;
+ struct mlx5_flow_table *ingress_ft = br_offloads->ingress_ft,
+ *skip_ft = br_offloads->skip_ft;
+ int err;
+
+ igmp_handle = mlx5_esw_bridge_ingress_igmp_fh_create(ingress_ft, skip_ft);
+ if (IS_ERR(igmp_handle))
+ return PTR_ERR(igmp_handle);
+
+ if (br_offloads->ingress_mld_fg) {
+ mld_query_handle = mlx5_esw_bridge_ingress_mld_fh_create(ICMPV6_MGM_QUERY,
+ ingress_ft,
+ skip_ft);
+ if (IS_ERR(mld_query_handle)) {
+ err = PTR_ERR(mld_query_handle);
+ goto err_mld_query;
+ }
+
+ mld_report_handle = mlx5_esw_bridge_ingress_mld_fh_create(ICMPV6_MGM_REPORT,
+ ingress_ft,
+ skip_ft);
+ if (IS_ERR(mld_report_handle)) {
+ err = PTR_ERR(mld_report_handle);
+ goto err_mld_report;
+ }
+
+ mld_done_handle = mlx5_esw_bridge_ingress_mld_fh_create(ICMPV6_MGM_REDUCTION,
+ ingress_ft,
+ skip_ft);
+ if (IS_ERR(mld_done_handle)) {
+ err = PTR_ERR(mld_done_handle);
+ goto err_mld_done;
+ }
+ } else {
+ mld_query_handle = NULL;
+ mld_report_handle = NULL;
+ mld_done_handle = NULL;
+ }
+
+ br_offloads->igmp_handle = igmp_handle;
+ br_offloads->mld_query_handle = mld_query_handle;
+ br_offloads->mld_report_handle = mld_report_handle;
+ br_offloads->mld_done_handle = mld_done_handle;
+
+ return 0;
+
+err_mld_done:
+ mlx5_del_flow_rules(mld_report_handle);
+err_mld_report:
+ mlx5_del_flow_rules(mld_query_handle);
+err_mld_query:
+ mlx5_del_flow_rules(igmp_handle);
+ return err;
+}
+
+static void
+mlx5_esw_bridge_ingress_mcast_fhs_cleanup(struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ if (br_offloads->mld_done_handle)
+ mlx5_del_flow_rules(br_offloads->mld_done_handle);
+ br_offloads->mld_done_handle = NULL;
+ if (br_offloads->mld_report_handle)
+ mlx5_del_flow_rules(br_offloads->mld_report_handle);
+ br_offloads->mld_report_handle = NULL;
+ if (br_offloads->mld_query_handle)
+ mlx5_del_flow_rules(br_offloads->mld_query_handle);
+ br_offloads->mld_query_handle = NULL;
+ if (br_offloads->igmp_handle)
+ mlx5_del_flow_rules(br_offloads->igmp_handle);
+ br_offloads->igmp_handle = NULL;
+}
+
+static int mlx5_esw_brige_mcast_global_enable(struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ int err;
+
+ if (br_offloads->ingress_igmp_fg)
+ return 0; /* already enabled by another bridge */
+
+ err = mlx5_esw_bridge_ingress_mcast_fgs_init(br_offloads);
+ if (err) {
+ esw_warn(br_offloads->esw->dev,
+ "Failed to create global multicast flow groups (err=%d)\n",
+ err);
+ return err;
+ }
+
+ err = mlx5_esw_bridge_ingress_mcast_fhs_create(br_offloads);
+ if (err) {
+ esw_warn(br_offloads->esw->dev,
+ "Failed to create global multicast flows (err=%d)\n",
+ err);
+ goto err_fhs;
+ }
+
+ return 0;
+
+err_fhs:
+ mlx5_esw_bridge_ingress_mcast_fgs_cleanup(br_offloads);
+ return err;
+}
+
+static void mlx5_esw_brige_mcast_global_disable(struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ struct mlx5_esw_bridge *br;
+
+ list_for_each_entry(br, &br_offloads->bridges, list) {
+ /* Ingress table is global, so only disable snooping when all
+ * bridges on esw have multicast disabled.
+ */
+ if (br->flags & MLX5_ESW_BRIDGE_MCAST_FLAG)
+ return;
+ }
+
+ mlx5_esw_bridge_ingress_mcast_fhs_cleanup(br_offloads);
+ mlx5_esw_bridge_ingress_mcast_fgs_cleanup(br_offloads);
+}
+
+int mlx5_esw_bridge_mcast_enable(struct mlx5_esw_bridge *bridge)
+{
+ int err;
+
+ err = mlx5_esw_brige_mcast_global_enable(bridge->br_offloads);
+ if (err)
+ return err;
+
+ bridge->flags |= MLX5_ESW_BRIDGE_MCAST_FLAG;
+ return 0;
+}
+
+void mlx5_esw_bridge_mcast_disable(struct mlx5_esw_bridge *bridge)
+{
+ bridge->flags &= ~MLX5_ESW_BRIDGE_MCAST_FLAG;
+ mlx5_esw_brige_mcast_global_disable(bridge->br_offloads);
+}
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h
index b99761e73c1b6..dbb935db1b3c7 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge_priv.h
@@ -12,11 +12,26 @@
#include <linux/xarray.h>
#include "fs_core.h"
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_SIZE 1
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_SIZE 3
#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE 131072
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE 524288
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_FROM 0
-#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO \
- (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_UNTAGGED_GRP_SIZE \
+ (524288 - MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_SIZE - \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_SIZE)
+
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_IDX_FROM 0
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_IGMP_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_SIZE - 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_FROM \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_MLD_GRP_IDX_TO + 1)
+#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO \
+ (MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_FROM + \
+ MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_SIZE - 1)
#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_FROM \
(MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_GRP_IDX_TO + 1)
#define MLX5_ESW_BRIDGE_INGRESS_TABLE_VLAN_FILTER_GRP_IDX_TO \
@@ -74,6 +89,7 @@ enum {
enum {
MLX5_ESW_BRIDGE_VLAN_FILTERING_FLAG = BIT(0),
+ MLX5_ESW_BRIDGE_MCAST_FLAG = BIT(1),
};
struct mlx5_esw_bridge_fdb_key {
@@ -145,4 +161,7 @@ struct mlx5_esw_bridge {
u16 vlan_proto;
};
+int mlx5_esw_bridge_mcast_enable(struct mlx5_esw_bridge *bridge);
+void mlx5_esw_bridge_mcast_disable(struct mlx5_esw_bridge *bridge);
+
#endif /* _MLX5_ESW_BRIDGE_PRIVATE_ */
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 866/982] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (864 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 865/982] net/mlx5: Bridge, snoop igmp/mld packets Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 867/982] net/mlx5: Bridge, pass net device when linking vport to bridge Greg Kroah-Hartman
` (122 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernardo Soares, Vlad Buslov,
Saeed Mahameed, Mark Bloch, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bernardo Soares <bsoares.it@gmail.com>
[ Upstream commit 35e6f970f553954d92ba20afa885139a8e7dd0d7 ]
mlx5 registers the bridge offload switchdev notifiers once per eswitch
instance, but the notifier chains are global, so every instance sees
every event and must filter out the ones that aren't its own. The
existing filter, mlx5_esw_bridge_dev_same_hw(), only checks that the
event netdevice sits on the same HCA - intentional for merged eswitch,
where one bridge can span representors of several eswitches on one
HCA - but same-HCA doesn't mean the instance actually has that port:
peer ports are only created reactively from NETDEV_CHANGEUPPER, so an
instance brought up after a sibling PF's port was already enslaved has
none. The port object and attribute handlers claim the event anyway
once same-HW passes, then fail the port lookup and return -EINVAL,
which gets reported to user space even though the owning instance
already handled it (e.g. "bridge vlan add ... RTNETLINK answers:
Invalid argument"). Fix by filtering on the tracked port instead.
The same gap exists in the generic recursive lower-device walk used by
attribute changes on a bridge with more than one representor enslaved
directly: mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get() is entered
with the bridge master netdevice, falls through to its generic
netdev_for_each_lower_dev() loop, and returns as soon as the recursion
into any one lower device yields a non-NULL rep - the underlying base
case, mlx5_esw_bridge_rep_vport_num_vhca_id_get(), only checks
mlx5_esw_bridge_dev_same_hw(), not ownership by the calling instance's
br_offloads. mlx5_esw_bridge_lag_rep_get(), used for the LAG-master
case, already filters on mlx5_esw_bridge_dev_same_esw() per candidate
and so cannot select a sibling's rep; it is not the source of this bug.
On a merged-eswitch HCA with a bridge spanning representors of more
than one eswitch instance directly, the walk can return a sibling's rep
instead of continuing to the one the calling instance actually owns, so
the attribute change fails the same way as above. Fix by checking
mlx5_esw_bridge_port_exists() at the point each rep is picked, same as
the previous fix did for the notifier filter.
Fixes: c358ea1741bc ("net/mlx5: Bridge, allow merged eswitch connectivity")
Signed-off-by: Bernardo Soares <bsoares.it@gmail.com>
Cc: Vlad Buslov <vladbu@nvidia.com>
Cc: Saeed Mahameed <saeedm@nvidia.com>
Reviewed-by: Mark Bloch <mbloch@nvidia.com>
Link: https://patch.msgid.link/20260918095931.29792-2-bsoares.it@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../mellanox/mlx5/core/en/rep/bridge.c | 45 +++++++++++++++----
.../ethernet/mellanox/mlx5/core/esw/bridge.c | 6 +++
.../ethernet/mellanox/mlx5/core/esw/bridge.h | 2 +
3 files changed, 44 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
index 6ea546a22b31a..ea7c5e907266e 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
@@ -85,9 +85,16 @@ mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(struct net_device *dev, struct m
struct net_device *lower_dev;
struct list_head *iter;
- if (netif_is_lag_master(dev) || mlx5e_eswitch_rep(dev))
- return mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, esw, vport_num,
- esw_owner_vhca_id);
+ if (netif_is_lag_master(dev) || mlx5e_eswitch_rep(dev)) {
+ struct net_device *rep;
+
+ rep = mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, esw, vport_num,
+ esw_owner_vhca_id);
+ if (rep && !mlx5_esw_bridge_port_exists(*vport_num, *esw_owner_vhca_id,
+ esw->br_offloads))
+ return NULL;
+ return rep;
+ }
netdev_for_each_lower_dev(dev, lower_dev, iter) {
struct net_device *rep;
@@ -104,6 +111,28 @@ mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(struct net_device *dev, struct m
return NULL;
}
+static bool mlx5_esw_bridge_rep_port_lookup(struct net_device *dev,
+ struct mlx5_esw_bridge_offloads *br_offloads,
+ u16 *vport_num, u16 *esw_owner_vhca_id)
+{
+ if (!mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, br_offloads->esw, vport_num,
+ esw_owner_vhca_id))
+ return false;
+
+ return mlx5_esw_bridge_port_exists(*vport_num, *esw_owner_vhca_id, br_offloads);
+}
+
+static bool mlx5_esw_bridge_lower_rep_port_lookup(struct net_device *dev,
+ struct mlx5_esw_bridge_offloads *br_offloads,
+ u16 *vport_num, u16 *esw_owner_vhca_id)
+{
+ if (!mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(dev, br_offloads->esw, vport_num,
+ esw_owner_vhca_id))
+ return false;
+
+ return mlx5_esw_bridge_port_exists(*vport_num, *esw_owner_vhca_id, br_offloads);
+}
+
static bool mlx5_esw_bridge_is_local(struct net_device *dev, struct net_device *rep,
struct mlx5_eswitch *esw)
{
@@ -218,8 +247,7 @@ mlx5_esw_bridge_port_obj_add(struct net_device *dev,
u16 vport_num, esw_owner_vhca_id;
int err;
- if (!mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, br_offloads->esw, &vport_num,
- &esw_owner_vhca_id))
+ if (!mlx5_esw_bridge_rep_port_lookup(dev, br_offloads, &vport_num, &esw_owner_vhca_id))
return 0;
port_obj_info->handled = true;
@@ -245,8 +273,7 @@ mlx5_esw_bridge_port_obj_del(struct net_device *dev,
const struct switchdev_obj_port_vlan *vlan;
u16 vport_num, esw_owner_vhca_id;
- if (!mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, br_offloads->esw, &vport_num,
- &esw_owner_vhca_id))
+ if (!mlx5_esw_bridge_rep_port_lookup(dev, br_offloads, &vport_num, &esw_owner_vhca_id))
return 0;
port_obj_info->handled = true;
@@ -272,8 +299,8 @@ mlx5_esw_bridge_port_obj_attr_set(struct net_device *dev,
u16 vport_num, esw_owner_vhca_id;
int err = 0;
- if (!mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(dev, br_offloads->esw, &vport_num,
- &esw_owner_vhca_id))
+ if (!mlx5_esw_bridge_lower_rep_port_lookup(dev, br_offloads, &vport_num,
+ &esw_owner_vhca_id))
return 0;
port_attr_info->handled = true;
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index 94d8f42e4318d..bb7698e967977 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -1618,6 +1618,12 @@ int mlx5_esw_bridge_vport_peer_unlink(int ifindex, u16 vport_num, u16 esw_owner_
extack);
}
+bool mlx5_esw_bridge_port_exists(u16 vport_num, u16 esw_owner_vhca_id,
+ struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ return mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+}
+
int mlx5_esw_bridge_port_vlan_add(u16 vport_num, u16 esw_owner_vhca_id, u16 vid, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
index b18f137173d98..bda199cdd931b 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
@@ -73,6 +73,8 @@ int mlx5_esw_bridge_vlan_proto_set(u16 vport_num, u16 esw_owner_vhca_id, u16 pro
struct mlx5_esw_bridge_offloads *br_offloads);
int mlx5_esw_bridge_mcast_set(u16 vport_num, u16 esw_owner_vhca_id, bool enable,
struct mlx5_esw_bridge_offloads *br_offloads);
+bool mlx5_esw_bridge_port_exists(u16 vport_num, u16 esw_owner_vhca_id,
+ struct mlx5_esw_bridge_offloads *br_offloads);
int mlx5_esw_bridge_port_vlan_add(u16 vport_num, u16 esw_owner_vhca_id, u16 vid, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 867/982] net/mlx5: Bridge, pass net device when linking vport to bridge
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (865 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 866/982] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 868/982] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports Greg Kroah-Hartman
` (121 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vlad Buslov, Gal Pressman,
Saeed Mahameed, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlad Buslov <vladbu@nvidia.com>
[ Upstream commit ade19f0d6a3a395e7936227811acbf897ee186fc ]
Following patch requires access to additional data in bridge net_device.
Pass the whole structure down the stack instead of adding necessary fields
as function arguments one-by-one.
Signed-off-by: Vlad Buslov <vladbu@nvidia.com>
Reviewed-by: Gal Pressman <gal@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Stable-dep-of: 2e51097c982b ("net/mlx5: Bridge, don't fail unlink of untracked/unsupported peer ports")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../mellanox/mlx5/core/en/rep/bridge.c | 9 +++--
.../ethernet/mellanox/mlx5/core/esw/bridge.c | 35 ++++++++++---------
.../ethernet/mellanox/mlx5/core/esw/bridge.h | 10 +++---
3 files changed, 29 insertions(+), 25 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
index ea7c5e907266e..effb0706a71ad 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
@@ -160,7 +160,6 @@ static int mlx5_esw_bridge_port_changeupper(struct notifier_block *nb, void *ptr
struct mlx5_eswitch *esw = br_offloads->esw;
u16 vport_num, esw_owner_vhca_id;
struct netlink_ext_ack *extack;
- int ifindex = upper->ifindex;
int err = 0;
if (!netif_is_bridge_master(upper))
@@ -174,15 +173,15 @@ static int mlx5_esw_bridge_port_changeupper(struct notifier_block *nb, void *ptr
if (mlx5_esw_bridge_is_local(dev, rep, esw))
err = info->linking ?
- mlx5_esw_bridge_vport_link(ifindex, vport_num, esw_owner_vhca_id,
+ mlx5_esw_bridge_vport_link(upper, vport_num, esw_owner_vhca_id,
br_offloads, extack) :
- mlx5_esw_bridge_vport_unlink(ifindex, vport_num, esw_owner_vhca_id,
+ mlx5_esw_bridge_vport_unlink(upper, vport_num, esw_owner_vhca_id,
br_offloads, extack);
else if (mlx5_esw_bridge_dev_same_hw(rep, esw))
err = info->linking ?
- mlx5_esw_bridge_vport_peer_link(ifindex, vport_num, esw_owner_vhca_id,
+ mlx5_esw_bridge_vport_peer_link(upper, vport_num, esw_owner_vhca_id,
br_offloads, extack) :
- mlx5_esw_bridge_vport_peer_unlink(ifindex, vport_num, esw_owner_vhca_id,
+ mlx5_esw_bridge_vport_peer_unlink(upper, vport_num, esw_owner_vhca_id,
br_offloads, extack);
return err;
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index bb7698e967977..882b87bc45d50 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -821,7 +821,7 @@ mlx5_esw_bridge_egress_miss_flow_create(struct mlx5_flow_table *egress_ft,
return handle;
}
-static struct mlx5_esw_bridge *mlx5_esw_bridge_create(int ifindex,
+static struct mlx5_esw_bridge *mlx5_esw_bridge_create(struct net_device *br_netdev,
struct mlx5_esw_bridge_offloads *br_offloads)
{
struct mlx5_esw_bridge *bridge;
@@ -841,7 +841,7 @@ static struct mlx5_esw_bridge *mlx5_esw_bridge_create(int ifindex,
goto err_fdb_ht;
INIT_LIST_HEAD(&bridge->fdb_list);
- bridge->ifindex = ifindex;
+ bridge->ifindex = br_netdev->ifindex;
bridge->refcnt = 1;
bridge->ageing_time = clock_t_to_jiffies(BR_DEFAULT_AGEING_TIME);
bridge->vlan_proto = ETH_P_8021Q;
@@ -878,14 +878,14 @@ static void mlx5_esw_bridge_put(struct mlx5_esw_bridge_offloads *br_offloads,
}
static struct mlx5_esw_bridge *
-mlx5_esw_bridge_lookup(int ifindex, struct mlx5_esw_bridge_offloads *br_offloads)
+mlx5_esw_bridge_lookup(struct net_device *br_netdev, struct mlx5_esw_bridge_offloads *br_offloads)
{
struct mlx5_esw_bridge *bridge;
ASSERT_RTNL();
list_for_each_entry(bridge, &br_offloads->bridges, list) {
- if (bridge->ifindex == ifindex) {
+ if (bridge->ifindex == br_netdev->ifindex) {
mlx5_esw_bridge_get(bridge);
return bridge;
}
@@ -898,7 +898,7 @@ mlx5_esw_bridge_lookup(int ifindex, struct mlx5_esw_bridge_offloads *br_offloads
return ERR_PTR(err);
}
- bridge = mlx5_esw_bridge_create(ifindex, br_offloads);
+ bridge = mlx5_esw_bridge_create(br_netdev, br_offloads);
if (IS_ERR(bridge) && list_empty(&br_offloads->bridges))
mlx5_esw_bridge_ingress_table_cleanup(br_offloads);
return bridge;
@@ -1541,15 +1541,15 @@ static int mlx5_esw_bridge_vport_cleanup(struct mlx5_esw_bridge_offloads *br_off
return 0;
}
-static int mlx5_esw_bridge_vport_link_with_flags(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
- u16 flags,
+static int mlx5_esw_bridge_vport_link_with_flags(struct net_device *br_netdev, u16 vport_num,
+ u16 esw_owner_vhca_id, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
struct mlx5_esw_bridge *bridge;
int err;
- bridge = mlx5_esw_bridge_lookup(ifindex, br_offloads);
+ bridge = mlx5_esw_bridge_lookup(br_netdev, br_offloads);
if (IS_ERR(bridge)) {
NL_SET_ERR_MSG_MOD(extack, "Error checking for existing bridge with same ifindex");
return PTR_ERR(bridge);
@@ -1567,15 +1567,16 @@ static int mlx5_esw_bridge_vport_link_with_flags(int ifindex, u16 vport_num, u16
return err;
}
-int mlx5_esw_bridge_vport_link(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_link(struct net_device *br_netdev, u16 vport_num, u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
- return mlx5_esw_bridge_vport_link_with_flags(ifindex, vport_num, esw_owner_vhca_id, 0,
+ return mlx5_esw_bridge_vport_link_with_flags(br_netdev, vport_num, esw_owner_vhca_id, 0,
br_offloads, extack);
}
-int mlx5_esw_bridge_vport_unlink(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_unlink(struct net_device *br_netdev, u16 vport_num,
+ u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
@@ -1587,7 +1588,7 @@ int mlx5_esw_bridge_vport_unlink(int ifindex, u16 vport_num, u16 esw_owner_vhca_
NL_SET_ERR_MSG_MOD(extack, "Port is not attached to any bridge");
return -EINVAL;
}
- if (port->bridge->ifindex != ifindex) {
+ if (port->bridge->ifindex != br_netdev->ifindex) {
NL_SET_ERR_MSG_MOD(extack, "Port is attached to another bridge");
return -EINVAL;
}
@@ -1598,23 +1599,25 @@ int mlx5_esw_bridge_vport_unlink(int ifindex, u16 vport_num, u16 esw_owner_vhca_
return err;
}
-int mlx5_esw_bridge_vport_peer_link(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_peer_link(struct net_device *br_netdev, u16 vport_num,
+ u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
if (!MLX5_CAP_ESW(br_offloads->esw->dev, merged_eswitch))
return 0;
- return mlx5_esw_bridge_vport_link_with_flags(ifindex, vport_num, esw_owner_vhca_id,
+ return mlx5_esw_bridge_vport_link_with_flags(br_netdev, vport_num, esw_owner_vhca_id,
MLX5_ESW_BRIDGE_PORT_FLAG_PEER,
br_offloads, extack);
}
-int mlx5_esw_bridge_vport_peer_unlink(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_peer_unlink(struct net_device *br_netdev, u16 vport_num,
+ u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
- return mlx5_esw_bridge_vport_unlink(ifindex, vport_num, esw_owner_vhca_id, br_offloads,
+ return mlx5_esw_bridge_vport_unlink(br_netdev, vport_num, esw_owner_vhca_id, br_offloads,
extack);
}
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
index bda199cdd931b..7bc66c877ea44 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
@@ -43,16 +43,18 @@ struct mlx5_esw_bridge_offloads {
struct mlx5_esw_bridge_offloads *mlx5_esw_bridge_init(struct mlx5_eswitch *esw);
void mlx5_esw_bridge_cleanup(struct mlx5_eswitch *esw);
-int mlx5_esw_bridge_vport_link(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_link(struct net_device *br_netdev, u16 vport_num, u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
-int mlx5_esw_bridge_vport_unlink(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_unlink(struct net_device *br_netdev, u16 vport_num, u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
-int mlx5_esw_bridge_vport_peer_link(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_peer_link(struct net_device *br_netdev, u16 vport_num,
+ u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
-int mlx5_esw_bridge_vport_peer_unlink(int ifindex, u16 vport_num, u16 esw_owner_vhca_id,
+int mlx5_esw_bridge_vport_peer_unlink(struct net_device *br_netdev, u16 vport_num,
+ u16 esw_owner_vhca_id,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
void mlx5_esw_bridge_fdb_update_used(struct net_device *dev, u16 vport_num, u16 esw_owner_vhca_id,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 868/982] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (866 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 867/982] net/mlx5: Bridge, pass net device when linking vport to bridge Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 869/982] sctp: hold asoc or transport before mod_timer() in timer handlers Greg Kroah-Hartman
` (120 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernardo Soares, Mark Bloch,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bernardo Soares <bsoares.it@gmail.com>
[ Upstream commit 2e51097c982b7b22382fda3202ba29f0ea33e8c0 ]
mlx5_esw_bridge_vport_unlink() returns -EINVAL when the port isn't
tracked by this instance's br_offloads. This is reachable on a sibling
instance that registered its notifier after the port was already
enslaved: it never saw the NETDEV_CHANGEUPPER link event, so
peer_link() never created a peer port for it, but it does see the
later unlink event and fails. Return 0 instead, and give
mlx5_esw_bridge_vport_peer_unlink() the same merged_eswitch capability
guard peer_link() already has, since without it peer_link() likewise
never creates a port to unlink.
This also matters beyond the -EINVAL itself:
mlx5_esw_bridge_switchdev_port_event() runs on the per-netns
netdev_chain, and notifier_from_errno(-EINVAL) sets NOTIFY_STOP_MASK,
which call_netdevice_notifiers_info() checks to stop calling further
listeners on that chain - so the old -EINVAL silently dropped the
event for any listener registered later on the same chain, even
though none of it was visible to user space since
__netdev_upper_dev_unlink() discards the return value.
Fixes: c358ea1741bc ("net/mlx5: Bridge, allow merged eswitch connectivity")
Signed-off-by: Bernardo Soares <bsoares.it@gmail.com>
Reviewed-by: Mark Bloch <mbloch@nvidia.com>
Link: https://patch.msgid.link/20260918095931.29792-3-bsoares.it@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index 882b87bc45d50..2dd9685867ba9 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -1584,10 +1584,8 @@ int mlx5_esw_bridge_vport_unlink(struct net_device *br_netdev, u16 vport_num,
int err;
port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
- if (!port) {
- NL_SET_ERR_MSG_MOD(extack, "Port is not attached to any bridge");
- return -EINVAL;
- }
+ if (!port)
+ return 0;
if (port->bridge->ifindex != br_netdev->ifindex) {
NL_SET_ERR_MSG_MOD(extack, "Port is attached to another bridge");
return -EINVAL;
@@ -1617,6 +1615,9 @@ int mlx5_esw_bridge_vport_peer_unlink(struct net_device *br_netdev, u16 vport_nu
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
+ if (!MLX5_CAP_ESW(br_offloads->esw->dev, merged_eswitch))
+ return 0;
+
return mlx5_esw_bridge_vport_unlink(br_netdev, vport_num, esw_owner_vhca_id, br_offloads,
extack);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 869/982] sctp: hold asoc or transport before mod_timer() in timer handlers
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (867 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 868/982] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 870/982] net: stmmac: selftests: Support running selftests on DSA conduits Greg Kroah-Hartman
` (119 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tangxin Xie, Xin Long,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xin Long <lucien.xin@gmail.com>
[ Upstream commit cae23ae3f7887a1cf8a75da38edcebeef695040f ]
Take the association or transport reference before rearming a timer in the
timer handlers.
The existing code calls mod_timer() before taking the reference needed by
the rearmed timer without holding the sock lock. This creates a race with
timer cleanup: if the timer is deleted after mod_timer() returns but before
the reference is taken, the cleanup path can drop the timer's reference and
destroy the transport or association. The timer handler then takes a
reference on the already freed object and eventually drops it, causing a
refcount underflow.
Hold the object before mod_timer() and drop the reference if mod_timer()
reports that the timer was already pending in timer handlers. Apply the
same ordering to the proto-unreachable path, which can rearm a transport
timer outside the timer handlers without holding the sock lock.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Tangxin Xie <xietangxin@h-partners.com>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/c31b5e3ee2b7274e804f5eba2f21e2412e7eef7a.1790013825.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/input.c | 7 ++++---
net/sctp/sm_sideeffect.c | 37 ++++++++++++++++++++++---------------
2 files changed, 26 insertions(+), 18 deletions(-)
diff --git a/net/sctp/input.c b/net/sctp/input.c
index 70530cbe57d0a..b208569b4bf0e 100644
--- a/net/sctp/input.c
+++ b/net/sctp/input.c
@@ -451,9 +451,10 @@ void sctp_icmp_proto_unreachable(struct sock *sk,
if (timer_pending(&t->proto_unreach_timer))
return;
else {
- if (!mod_timer(&t->proto_unreach_timer,
- jiffies + (HZ/20)))
- sctp_transport_hold(t);
+ sctp_transport_hold(t);
+ if (mod_timer(&t->proto_unreach_timer,
+ jiffies + (HZ / 20)))
+ sctp_transport_put(t);
}
} else {
struct net *net = sock_net(sk);
diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c
index 4391f070dc1e1..cfc35dadaf74a 100644
--- a/net/sctp/sm_sideeffect.c
+++ b/net/sctp/sm_sideeffect.c
@@ -244,8 +244,9 @@ void sctp_generate_t3_rtx_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->T3_rtx_timer, jiffies + (HZ/20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->T3_rtx_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -280,8 +281,9 @@ static void sctp_generate_timeout_event(struct sctp_association *asoc,
timeout_type);
/* Try again later. */
- if (!mod_timer(&asoc->timers[timeout_type], jiffies + (HZ/20)))
- sctp_association_hold(asoc);
+ sctp_association_hold(asoc);
+ if (mod_timer(&asoc->timers[timeout_type], jiffies + (HZ / 20)))
+ sctp_association_put(asoc);
goto out_unlock;
}
@@ -373,8 +375,9 @@ void sctp_generate_heartbeat_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->hb_timer, jiffies + (HZ/20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->hb_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -383,8 +386,9 @@ void sctp_generate_heartbeat_event(struct timer_list *t)
timeout = sctp_transport_timeout(transport);
if (elapsed < timeout) {
elapsed = timeout - elapsed;
- if (!mod_timer(&transport->hb_timer, jiffies + elapsed))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->hb_timer, jiffies + elapsed))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -417,9 +421,10 @@ void sctp_generate_proto_unreach_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->proto_unreach_timer,
- jiffies + (HZ/20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->proto_unreach_timer,
+ jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -453,8 +458,9 @@ void sctp_generate_reconf_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->reconf_timer, jiffies + (HZ / 20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->reconf_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -489,8 +495,9 @@ void sctp_generate_probe_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->probe_timer, jiffies + (HZ / 20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->probe_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 870/982] net: stmmac: selftests: Support running selftests on DSA conduits
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (868 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 869/982] sctp: hold asoc or transport before mod_timer() in timer handlers Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 871/982] net: stmmac: selftests: Check the dev->features for S-TAG offload testing Greg Kroah-Hartman
` (118 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit d68acbf93531abdb5b02b21994cd4c15a3c95b42 ]
Most stmmac selftests rely on dev_add_pack() to add custom handlers,
that validate the packets sent to ourselves through MAC loopback.
However, when the stmmac-driven interface is a DSA CPU conduit, all
frames that are received have ETH_P_XDSA as a protocol, even though they
don't actually contain any tag as they come from the loopback and not
the switch.
This will prevent any incoming packet to match our packet handlers.
Let's register a ETH_P_ALL packet handler when we detect that we're a
DSA conduit, and use a proxy packet handler to filter the h_proto.
As this allows external frames to be received through our .func(), the
packet handler is added after the dev->addr field is populated in our
selftest attributes.
Note that we may still receive incoming packets from the switch, but
these frames shouldn't interfere with the very specific frames used for
selftests, and stmmac selftests in general aren't safe against external
traffic interferences.
This was validated on a WPQ864 devkit for IPQ8064, that has the SoC
connected to a QCA8k switch.
The ARP offload's packet handler is left alone, this feature is just not
implemented in stmmac and due for removal.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-2-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../stmicro/stmmac/stmmac_selftests.c | 89 +++++++++++++++----
1 file changed, 71 insertions(+), 18 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index c0821d95f8e8c..9ceb9ed751c93 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -13,6 +13,7 @@
#include <linux/ip.h>
#include <linux/phy.h>
#include <linux/udp.h>
+#include <net/dsa.h>
#include <net/pkt_cls.h>
#include <net/pkt_sched.h>
#include <net/tcp.h>
@@ -238,6 +239,9 @@ struct stmmac_test_priv {
struct stmmac_packet_attrs *packet;
struct packet_type pt;
struct completion comp;
+ __be16 packet_type;
+ int (*func)(struct sk_buff *skb, struct net_device *ndev,
+ struct packet_type *pt, struct net_device *orig_ndev);
int double_vlan;
int vlan_id;
int ok;
@@ -317,6 +321,50 @@ static int stmmac_test_loopback_validate(struct sk_buff *skb,
return 0;
}
+static int stmmac_sft_filter(struct sk_buff *skb, struct net_device *ndev,
+ struct packet_type *pt,
+ struct net_device *orig_ndev)
+{
+ struct stmmac_test_priv *tpriv = pt->af_packet_priv;
+ struct ethhdr *hdr = eth_hdr(skb);
+ int ret = 0;
+
+ if (hdr->h_proto == tpriv->packet_type) {
+ struct sk_buff *nskb = skb_clone(skb, GFP_ATOMIC);
+
+ if (nskb)
+ ret = tpriv->func(nskb, ndev, pt, orig_ndev);
+ }
+
+ kfree_skb(skb);
+ return ret;
+}
+
+static void stmmac_sft_add_pack(struct packet_type *pt)
+{
+ struct stmmac_test_priv *tpriv = pt->af_packet_priv;
+
+ if (netdev_uses_dsa(tpriv->pt.dev)) {
+ tpriv->packet_type = tpriv->pt.type;
+ tpriv->func = tpriv->pt.func;
+
+ /* DSA conduit will report ETH_P_XDSA, so our packet handler
+ * won't match. Let's register a ETH_P_ALL match and filter
+ * manually in stmmac_sft_filter.
+ */
+ tpriv->pt.type = htons(ETH_P_ALL);
+ tpriv->pt.func = stmmac_sft_filter;
+ tpriv->pt.ignore_outgoing = true;
+ }
+
+ dev_add_pack(pt);
+}
+
+static void stmmac_sft_remove_pack(struct packet_type *pt)
+{
+ dev_remove_pack(pt);
+}
+
static int __stmmac_test_loopback(struct stmmac_priv *priv,
struct stmmac_packet_attrs *attr)
{
@@ -338,7 +386,7 @@ static int __stmmac_test_loopback(struct stmmac_priv *priv,
tpriv->packet = attr;
if (!attr->dont_wait)
- dev_add_pack(&tpriv->pt);
+ stmmac_sft_add_pack(&tpriv->pt);
skb = stmmac_test_get_udp_skb(priv, attr);
if (!skb) {
@@ -361,7 +409,7 @@ static int __stmmac_test_loopback(struct stmmac_priv *priv,
cleanup:
if (!attr->dont_wait)
- dev_remove_pack(&tpriv->pt);
+ stmmac_sft_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -775,7 +823,7 @@ static int stmmac_test_flowctrl(struct stmmac_priv *priv)
tpriv->pt.func = stmmac_test_flowctrl_validate;
tpriv->pt.dev = priv->dev;
tpriv->pt.af_packet_priv = tpriv;
- dev_add_pack(&tpriv->pt);
+ stmmac_sft_add_pack(&tpriv->pt);
/* Compute minimum number of packets to make FIFO full */
pkt_count = priv->plat->rx_fifo_size;
@@ -833,7 +881,7 @@ static int stmmac_test_flowctrl(struct stmmac_priv *priv)
cleanup:
dev_mc_del(priv->dev, paddr);
dev_set_promiscuity(priv->dev, -1);
- dev_remove_pack(&tpriv->pt);
+ stmmac_sft_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -938,18 +986,20 @@ static int __stmmac_test_vlanfilt(struct stmmac_priv *priv)
* HASH values.
*/
tpriv->vlan_id = 0x123;
- dev_add_pack(&tpriv->pt);
ret = vlan_vid_add(priv->dev, htons(ETH_P_8021Q), tpriv->vlan_id);
if (ret)
goto cleanup;
+ attr.vlan = 1;
+ attr.dst = priv->dev->dev_addr;
+ attr.sport = 9;
+ attr.dport = 9;
+
+ stmmac_sft_add_pack(&tpriv->pt);
+
for (i = 0; i < 4; i++) {
- attr.vlan = 1;
attr.vlan_id_out = tpriv->vlan_id + i;
- attr.dst = priv->dev->dev_addr;
- attr.sport = 9;
- attr.dport = 9;
skb = stmmac_test_get_udp_skb(priv, &attr);
if (!skb) {
@@ -976,9 +1026,9 @@ static int __stmmac_test_vlanfilt(struct stmmac_priv *priv)
}
vlan_del:
+ stmmac_sft_remove_pack(&tpriv->pt);
vlan_vid_del(priv->dev, htons(ETH_P_8021Q), tpriv->vlan_id);
cleanup:
- dev_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -1032,18 +1082,20 @@ static int __stmmac_test_dvlanfilt(struct stmmac_priv *priv)
* HASH values.
*/
tpriv->vlan_id = 0x123;
- dev_add_pack(&tpriv->pt);
ret = vlan_vid_add(priv->dev, htons(ETH_P_8021AD), tpriv->vlan_id);
if (ret)
goto cleanup;
+ attr.vlan = 2;
+ attr.dst = priv->dev->dev_addr;
+ attr.sport = 9;
+ attr.dport = 9;
+
+ stmmac_sft_add_pack(&tpriv->pt);
+
for (i = 0; i < 4; i++) {
- attr.vlan = 2;
attr.vlan_id_out = tpriv->vlan_id + i;
- attr.dst = priv->dev->dev_addr;
- attr.sport = 9;
- attr.dport = 9;
skb = stmmac_test_get_udp_skb(priv, &attr);
if (!skb) {
@@ -1070,9 +1122,9 @@ static int __stmmac_test_dvlanfilt(struct stmmac_priv *priv)
}
vlan_del:
+ stmmac_sft_remove_pack(&tpriv->pt);
vlan_vid_del(priv->dev, htons(ETH_P_8021AD), tpriv->vlan_id);
cleanup:
- dev_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -1303,7 +1355,6 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
tpriv->vlan_id = 0x123;
- dev_add_pack(&tpriv->pt);
ret = vlan_vid_add(priv->dev, htons(proto), tpriv->vlan_id);
if (ret)
@@ -1311,6 +1362,8 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
attr.dst = priv->dev->dev_addr;
+ stmmac_sft_add_pack(&tpriv->pt);
+
skb = stmmac_test_get_udp_skb(priv, &attr);
if (!skb) {
ret = -ENOMEM;
@@ -1328,9 +1381,9 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
ret = tpriv->ok ? 0 : -ETIMEDOUT;
vlan_del:
+ stmmac_sft_remove_pack(&tpriv->pt);
vlan_vid_del(priv->dev, htons(proto), tpriv->vlan_id);
cleanup:
- dev_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 871/982] net: stmmac: selftests: Check the dev->features for S-TAG offload testing
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (869 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 870/982] net: stmmac: selftests: Support running selftests on DSA conduits Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 872/982] net: stmmac: selftests: Capture all packets for vlan checks Greg Kroah-Hartman
` (117 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit ba804b23d76d278ee475b8427fa7c5623ce5e270 ]
The S-TAG offload insertion incorrectly checks the dvlan (double vlan)
DMA cap, which is different than S-TAG support. Use
NETIF_F_HW_VLAN_STAG_TX to check if the feature is supported instead.
Note that this flag isn't set in stmmac yet, but contrary to ARP
offload, this is a feature that has a chance to get there eventually so
let's leave the selftest here for now. It'll report -EOPNOTSUPP in the
meantime.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-4-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index 9ceb9ed751c93..e2fd7de10dd21 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -1395,7 +1395,7 @@ static int stmmac_test_vlanoff(struct stmmac_priv *priv)
static int stmmac_test_svlanoff(struct stmmac_priv *priv)
{
- if (!priv->dma_cap.dvlan)
+ if (!(priv->dev->features & NETIF_F_HW_VLAN_STAG_TX))
return -EOPNOTSUPP;
return stmmac_test_vlanoff_common(priv, true);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 872/982] net: stmmac: selftests: Capture all packets for vlan checks
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (870 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 871/982] net: stmmac: selftests: Check the dev->features for S-TAG offload testing Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 873/982] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K Greg Kroah-Hartman
` (116 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit 960db6f65788c21249ea04a947d5c01e38d19294 ]
While we use vlan_vid_add to trigger the tag filtering machinery
in the driver, there's no netdev associated to the VLAN. This causes the
skb to arrive with empty skb->vlan_tci fields, as the packet is marked
OTHERHOST in __netif_receive_skb_core(), and we fail our validation.
Let's use the proxy mechanism introduced for DSA, that registers a
ETH_P_ALL packet handler that runs earlier, before the vlan netdev
lookup, then filters for the correct ethertype before passing an skb
clone to our validation function.
As we may receive external frames with the right tag from the outside,
let's move the address check in the vlan validation function earlier.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-5-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../stmicro/stmmac/stmmac_selftests.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index e2fd7de10dd21..fa338b083129c 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -242,6 +242,7 @@ struct stmmac_test_priv {
__be16 packet_type;
int (*func)(struct sk_buff *skb, struct net_device *ndev,
struct packet_type *pt, struct net_device *orig_ndev);
+ bool capture_all;
int double_vlan;
int vlan_id;
int ok;
@@ -344,13 +345,15 @@ static void stmmac_sft_add_pack(struct packet_type *pt)
{
struct stmmac_test_priv *tpriv = pt->af_packet_priv;
- if (netdev_uses_dsa(tpriv->pt.dev)) {
+ if (netdev_uses_dsa(tpriv->pt.dev) || tpriv->capture_all) {
tpriv->packet_type = tpriv->pt.type;
tpriv->func = tpriv->pt.func;
/* DSA conduit will report ETH_P_XDSA, so our packet handler
* won't match. Let's register a ETH_P_ALL match and filter
- * manually in stmmac_sft_filter.
+ * manually in stmmac_sft_filter. This is also useful for
+ * VLAN tests, to capture packets otherwise marked as
+ * OTHERHOST.
*/
tpriv->pt.type = htons(ETH_P_ALL);
tpriv->pt.func = stmmac_sft_filter;
@@ -923,6 +926,11 @@ static int stmmac_test_vlan_validate(struct sk_buff *skb,
goto out;
if (skb_headlen(skb) < (STMMAC_TEST_PKT_SIZE - ETH_HLEN))
goto out;
+
+ ehdr = (struct ethhdr *)skb_mac_header(skb);
+ if (!ether_addr_equal_unaligned(ehdr->h_dest, tpriv->packet->dst))
+ goto out;
+
if (tpriv->vlan_id) {
if (skb->vlan_proto != htons(proto))
goto out;
@@ -934,10 +942,6 @@ static int stmmac_test_vlan_validate(struct sk_buff *skb,
}
}
- ehdr = (struct ethhdr *)skb_mac_header(skb);
- if (!ether_addr_equal_unaligned(ehdr->h_dest, tpriv->packet->dst))
- goto out;
-
ihdr = ip_hdr(skb);
if (tpriv->double_vlan)
ihdr = (struct iphdr *)(skb_network_header(skb) + 4);
@@ -979,6 +983,7 @@ static int __stmmac_test_vlanfilt(struct stmmac_priv *priv)
tpriv->pt.dev = priv->dev;
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
+ tpriv->capture_all = true;
/*
* As we use HASH filtering, false positives may appear. This is a
@@ -1075,6 +1080,7 @@ static int __stmmac_test_dvlanfilt(struct stmmac_priv *priv)
tpriv->pt.dev = priv->dev;
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
+ tpriv->capture_all = true;
/*
* As we use HASH filtering, false positives may appear. This is a
@@ -1355,6 +1361,7 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
tpriv->vlan_id = 0x123;
+ tpriv->capture_all = true;
ret = vlan_vid_add(priv->dev, htons(proto), tpriv->vlan_id);
if (ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 873/982] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (871 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 872/982] net: stmmac: selftests: Capture all packets for vlan checks Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 874/982] nfc: nfcmrvl: validate helper command length before pull Greg Kroah-Hartman
` (115 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Nicolai Buchwitz,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit b42e7012773a0e81e97a2dda6ef907f5147a6658 ]
DMA bufsize selection isn't made on the MTU but the actual frame length,
so including the L2 header. On DWMAC4, if the len is exactly BUF_SIZE_8KiB,
the next larger size is incorrectly selected.
Lets fix the comparison and while at it, rename the parameter from len
to mtu.
Fixes: c3efed5ad1b0 ("net: stmmac: Enable dwmac4 jumbo frame more than 8KiB").
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Link: https://patch.msgid.link/20260917215339.2022523-6-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c | 4 ++--
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
drivers/net/ethernet/stmicro/stmmac/ring_mode.c | 4 ++--
3 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c b/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c
index 89a14084c6117..db47c8f6093c6 100644
--- a/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c
+++ b/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c
@@ -477,11 +477,11 @@ static void dwmac4_set_sarc(struct dma_desc *p, u32 sarc_type)
p->des3 |= cpu_to_le32(sarc_type & TDES3_SA_INSERT_CTRL_MASK);
}
-static int set_16kib_bfsize(int mtu)
+static int set_16kib_bfsize(int len)
{
int ret = 0;
- if (unlikely(mtu >= BUF_SIZE_8KiB))
+ if (unlikely(len > BUF_SIZE_8KiB))
ret = BUF_SIZE_16KiB;
return ret;
}
diff --git a/drivers/net/ethernet/stmicro/stmmac/hwif.h b/drivers/net/ethernet/stmicro/stmmac/hwif.h
index 19424af936d2b..c4fe5c3f3de39 100644
--- a/drivers/net/ethernet/stmicro/stmmac/hwif.h
+++ b/drivers/net/ethernet/stmicro/stmmac/hwif.h
@@ -565,7 +565,7 @@ struct stmmac_mode_ops {
unsigned int (*is_jumbo_frm) (int len, int ehn_desc);
int (*jumbo_frm)(struct stmmac_tx_queue *tx_q, struct sk_buff *skb,
int csum);
- int (*set_16kib_bfsize)(int mtu);
+ int (*set_16kib_bfsize)(int len);
void (*init_desc3)(struct dma_desc *p);
void (*refill_desc3)(struct stmmac_rx_queue *rx_q, struct dma_desc *p);
void (*clean_desc3)(struct stmmac_tx_queue *tx_q, struct dma_desc *p);
diff --git a/drivers/net/ethernet/stmicro/stmmac/ring_mode.c b/drivers/net/ethernet/stmicro/stmmac/ring_mode.c
index 45c14c1bb0eaa..88a8d22812f5d 100644
--- a/drivers/net/ethernet/stmicro/stmmac/ring_mode.c
+++ b/drivers/net/ethernet/stmicro/stmmac/ring_mode.c
@@ -128,10 +128,10 @@ static void clean_desc3(struct stmmac_tx_queue *tx_q, struct dma_desc *p)
p->des3 = 0;
}
-static int set_16kib_bfsize(int mtu)
+static int set_16kib_bfsize(int len)
{
int ret = 0;
- if (unlikely(mtu > BUF_SIZE_8KiB))
+ if (unlikely(len > BUF_SIZE_8KiB))
ret = BUF_SIZE_16KiB;
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 874/982] nfc: nfcmrvl: validate helper command length before pull
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (872 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 873/982] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 875/982] nfc: st21nfca: validate received frame size Greg Kroah-Hartman
` (114 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, David Heidelberg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 686f942332b1667f13f3b8d6a2f50bcfbf42e277 ]
The firmware download receive path removes the NCI data header and
reads the helper command before validating the remaining packet length.
A short frame can therefore reach the data access before the malformed
packet is rejected.
Validate the complete helper command length before stripping the NCI
data header.
Fixes: 3194c6870158 ("NFC: nfcmrvl: add firmware download support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715084325.40276-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/nfcmrvl/fw_dnld.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/nfc/nfcmrvl/fw_dnld.c b/drivers/nfc/nfcmrvl/fw_dnld.c
index e83f65596a88a..f7191954db4f6 100644
--- a/drivers/nfc/nfcmrvl/fw_dnld.c
+++ b/drivers/nfc/nfcmrvl/fw_dnld.c
@@ -262,9 +262,14 @@ static int process_state_fw_dnld(struct nfcmrvl_private *priv,
* B8..N: payload
*/
- /* Remove NCI HDR */
- skb_pull(skb, 3);
- if (skb->data[0] != HELPER_CMD_PACKET_FORMAT || skb->len != 5) {
+ if (skb->len != NCI_DATA_HDR_SIZE + 5) {
+ nfc_err(priv->dev, "bad command");
+ return -EINVAL;
+ }
+
+ /* Remove NCI header */
+ skb_pull(skb, NCI_DATA_HDR_SIZE);
+ if (skb->data[0] != HELPER_CMD_PACKET_FORMAT) {
nfc_err(priv->dev, "bad command");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 875/982] nfc: st21nfca: validate received frame size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (873 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 874/982] nfc: nfcmrvl: validate helper command length before pull Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 876/982] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm() Greg Kroah-Hartman
` (113 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, David Heidelberg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit a653c01ce447f10c36b901646888c0330363af4f ]
st21nfca_hci_i2c_repack() trims a received frame at its EOF marker
before removing byte stuffing. It then assumes the truncated frame
contains the LLC header and two CRC bytes, and it unconditionally reads
the byte after an escape marker.
A malformed frame can place EOF immediately after the start marker or can
end its data portion with an escape marker. The former leaves too few
bytes for check_crc(), while the latter makes the unstuffing loop read past
the current skb length.
Require the minimum framing bytes both before and after unstuffing. Use
separate input and output cursors while removing byte stuffing, and reject
an escape marker without its encoded byte. This keeps malformed frames
within the received frame boundary before CRC processing.
Fixes: 3096e25a3e40 ("NFC: st21nfca: Fix incorrect byte stuffing revocation")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715084405.41546-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/st21nfca/i2c.c | 29 +++++++++++++++++++----------
1 file changed, 19 insertions(+), 10 deletions(-)
diff --git a/drivers/nfc/st21nfca/i2c.c b/drivers/nfc/st21nfca/i2c.c
index 76b55986bcf85..c1dc1ad765dde 100644
--- a/drivers/nfc/st21nfca/i2c.c
+++ b/drivers/nfc/st21nfca/i2c.c
@@ -290,27 +290,36 @@ static int check_crc(u8 *buf, int buflen)
*/
static int st21nfca_hci_i2c_repack(struct sk_buff *skb)
{
- int i, j, r, size;
+ int read, write, r, size;
- if (skb->len < 1 || (skb->len > 1 && skb->data[1] != 0))
+ if (skb->len < ST21NFCA_FRAME_HEADROOM ||
+ !IS_START_OF_FRAME(skb->data))
return -EBADMSG;
size = get_frame_size(skb->data, skb->len);
if (size > 0) {
+ if (size < ST21NFCA_FRAME_HEADROOM + 2)
+ return -EBADMSG;
+
skb_trim(skb, size);
/* remove ST21NFCA byte stuffing for upper layer */
- for (i = 1, j = 0; i < skb->len; i++) {
- if (skb->data[i + j] ==
+ for (read = 1, write = 1; read < skb->len;) {
+ if (skb->data[read] ==
(u8) ST21NFCA_ESCAPE_BYTE_STUFFING) {
- skb->data[i] = skb->data[i + j + 1]
- | ST21NFCA_BYTE_STUFFING_MASK;
- i++;
- j++;
+ if (read + 1 == skb->len)
+ return -EBADMSG;
+
+ skb->data[write++] = skb->data[read + 1]
+ | ST21NFCA_BYTE_STUFFING_MASK;
+ read += 2;
+ } else {
+ skb->data[write++] = skb->data[read++];
}
- skb->data[i] = skb->data[i + j];
}
/* remove byte stuffing useless byte */
- skb_trim(skb, i - j);
+ skb_trim(skb, write);
+ if (skb->len < ST21NFCA_FRAME_HEADROOM + 2)
+ return -EBADMSG;
/* remove ST21NFCA_SOF_EOF from head */
skb_pull(skb, 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 876/982] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (874 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 875/982] nfc: st21nfca: validate received frame size Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 877/982] selftests: nci: Correct pthread_create return value check Greg Kroah-Hartman
` (112 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
[ Upstream commit bf1460acdf8cf5a07c819f59785d40f20d113099 ]
nfc_llcp_recv_dm() handles DM(NOBOUND)/DM(REJ) for a socket that is still
linked on local->connecting_sockets: it looks the socket up with
nfc_llcp_connecting_sock_get(), sets sk->sk_state = LLCP_CLOSED and
returns, without taking the socket lock and without unlinking the socket
from the connecting_sockets list.
llcp_sock_release() selects the list to unlink from by sk_state: a socket
in LLCP_CONNECTING is unlinked from connecting_sockets, otherwise from the
sockets list. Because recv_dm left the socket physically on
connecting_sockets but in the LLCP_CLOSED state, release() takes the else
branch and calls nfc_llcp_sock_unlink(&local->sockets, sk). That runs
sk_del_node_init() while holding sockets.lock, i.e. it removes the socket
from the connecting_sockets hlist under the wrong lock. A concurrent
connect() linking another socket onto connecting_sockets under
connecting_sockets.lock then mutates the same hlist unserialized, which
corrupts the list and desyncs the sk_add_node()/sk_del_node_init()
sock_hold()/__sock_put() pairing. An unprivileged local process holding
LLCP sockets, with the DM supplied by the remote peer over an established
LLCP link, can drive this to leak kernel sockets without bound (the
mis-decrement goes through the non-freeing __sock_put() path, so the
object is never released), leading to memory exhaustion / DoS.
This is the same class of bug that was fixed in the sibling handler
nfc_llcp_recv_cc() by commit b493ea2765cc ("nfc: llcp: Fix use-after-free
race in nfc_llcp_recv_cc()"); recv_dm did not receive the equivalent fix.
Fix it the same way: take lock_sock(), re-check that the socket is still
hashed (release() may have won the race), and for the NOBOUND/REJ case
unlink it from connecting_sockets before moving it to LLCP_CLOSED. The
unlink drops the connecting_sockets membership reference via
sk_del_node_init(), leaving the socket unhashed, so the later
nfc_llcp_sock_unlink() in llcp_sock_release() becomes a no-op and no
double put occurs.
Fixes: a69f32af86e3 ("NFC: Socket linked list")
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Link: https://patch.msgid.link/20260716232657.203145-1-qwe.aldo@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_core.c | 25 +++++++++++++++++++++++++
1 file changed, 25 insertions(+)
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index 7b86faf3f4ce5..9ae9b4fde311e 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1249,6 +1249,7 @@ static void nfc_llcp_recv_dm(struct nfc_llcp_local *local,
struct nfc_llcp_sock *llcp_sock;
struct sock *sk;
u8 dsap, ssap, reason;
+ bool connecting = false;
dsap = nfc_llcp_dsap(skb);
ssap = nfc_llcp_ssap(skb);
@@ -1260,6 +1261,7 @@ static void nfc_llcp_recv_dm(struct nfc_llcp_local *local,
case LLCP_DM_NOBOUND:
case LLCP_DM_REJ:
llcp_sock = nfc_llcp_connecting_sock_get(local, dsap);
+ connecting = true;
break;
default:
@@ -1274,10 +1276,33 @@ static void nfc_llcp_recv_dm(struct nfc_llcp_local *local,
sk = &llcp_sock->sk;
+ lock_sock(sk);
+
+ /* Check if socket was destroyed whilst waiting for the lock */
+ if (!sk_hashed(sk)) {
+ release_sock(sk);
+ nfc_llcp_sock_put(llcp_sock);
+ return;
+ }
+
+ /*
+ * For DM(NOBOUND)/DM(REJ) the socket is still linked on the
+ * connecting_sockets list. Unlink it here, under the socket lock,
+ * before moving it to LLCP_CLOSED: llcp_sock_release() selects the
+ * list to unlink from by sk_state, so leaving a connecting socket
+ * in the CLOSED state would make it unlink from the wrong list and
+ * corrupt the connecting_sockets list / desync the socket refcount.
+ * This mirrors nfc_llcp_recv_cc().
+ */
+ if (connecting)
+ nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
+
sk->sk_err = ENXIO;
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
+ release_sock(sk);
+
nfc_llcp_sock_put(llcp_sock);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 877/982] selftests: nci: Correct pthread_create return value check
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (875 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 876/982] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 878/982] nfc: llcp: Fix race condition in accept_queue lifecycle Greg Kroah-Hartman
` (111 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lei Zhu, David Heidelberg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lei Zhu <zhulei@kylinos.cn>
[ Upstream commit 3d8afc5243ea2ee803d98e69eb4a01748167ac1b ]
The pthread_create() functions returns 0 on success and a positive value on
failure. Modify the return value check to correctly detect failure cases.
Fixes: 72696bd8a09d ("selftests: nci: Extract the start/stop discovery function")
Signed-off-by: Lei Zhu <zhulei@kylinos.cn>
Link: https://patch.msgid.link/20260729072426.303484-1-zhulei_szu@163.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/nci/nci_dev.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/tools/testing/selftests/nci/nci_dev.c b/tools/testing/selftests/nci/nci_dev.c
index 162c41e9bcae8..6f571e3c21c09 100644
--- a/tools/testing/selftests/nci/nci_dev.c
+++ b/tools/testing/selftests/nci/nci_dev.c
@@ -438,7 +438,7 @@ FIXTURE_SETUP(NCI)
else
rc = pthread_create(&thread_t, NULL, virtual_dev_open,
(void *)&self->virtual_nci_fd);
- ASSERT_GT(rc, -1);
+ ASSERT_EQ(rc, 0);
rc = send_cmd_with_idx(self->sd, self->fid, self->pid,
NFC_CMD_DEV_UP, self->dev_idex);
@@ -509,7 +509,7 @@ FIXTURE_TEARDOWN(NCI)
rc = pthread_create(&thread_t, NULL, virtual_deinit,
(void *)&self->virtual_nci_fd);
- ASSERT_GT(rc, -1);
+ ASSERT_EQ(rc, 0);
rc = send_cmd_with_idx(self->sd, self->fid, self->pid,
NFC_CMD_DEV_DOWN, self->dev_idex);
EXPECT_EQ(rc, 0);
@@ -590,7 +590,7 @@ int start_polling(int dev_idx, int proto, int virtual_fd, int sd, int fid, int p
rc = pthread_create(&thread_t, NULL, virtual_poll_start,
(void *)&virtual_fd);
- if (rc < 0)
+ if (rc)
return rc;
rc = send_cmd_mt_nla(sd, fid, pid, NFC_CMD_START_POLL, 2, nla_start_poll_type,
@@ -610,7 +610,7 @@ int stop_polling(int dev_idx, int virtual_fd, int sd, int fid, int pid)
rc = pthread_create(&thread_t, NULL, virtual_poll_stop,
(void *)&virtual_fd);
- if (rc < 0)
+ if (rc)
return rc;
rc = send_cmd_with_idx(sd, fid, pid,
@@ -830,6 +830,8 @@ int disconnect_tag(int nfc_sock, int virtual_fd)
status = pthread_create(&thread_t, NULL, virtual_deactivate_proc,
(void *)&virtual_fd);
+ if (status)
+ return status;
close(nfc_sock);
pthread_join(thread_t, (void **)&status);
@@ -874,7 +876,7 @@ TEST_F(NCI, deinit)
else
rc = pthread_create(&thread_t, NULL, virtual_deinit,
(void *)&self->virtual_nci_fd);
- ASSERT_GT(rc, -1);
+ ASSERT_EQ(rc, 0);
rc = send_cmd_with_idx(self->sd, self->fid, self->pid,
NFC_CMD_DEV_DOWN, self->dev_idex);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 878/982] nfc: llcp: Fix race condition in accept_queue lifecycle
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (876 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 877/982] selftests: nci: Correct pthread_create return value check Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 879/982] selftests: nci: Fix uninitialized family ID on missing attribute Greg Kroah-Hartman
` (110 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lee Jones, David Heidelberg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lee Jones <lee@kernel.org>
[ Upstream commit c3eef2f988a3db9690369d7cef9a3344dd9788d3 ]
In nfc_llcp_socket_release(), sockets and listener accept queues are
walked under the local sockets rwlock and bh_lock_sock(). However,
bh_lock_sock() does not synchronise against process-context lock_sock()
held by nfc_llcp_accept_dequeue() during accept(). Because
socket_release() does not check sock_owned_by_user(), both paths can
concurrently unlink and release the same child socket, resulting in
use-after-free or a NULL pointer dereference of child->parent in
nfc_llcp_accept_unlink().
Fix this synchronisation race by having nfc_llcp_socket_release() use
process-context lock_sock() instead of bh_lock_sock():
1. Pop sockets from the local sockets list under the write lock using
nfc_llcp_sock_list_pop() so lock_sock() can be acquired without
holding the rwlock.
2. Because lock_sock() can sleep, defer the final release of the
nfc_llcp_local structure to a workqueue (release_work). This avoids
a sleeping-in-atomic bug when the last local reference is dropped
from softirq context. Additionally, hold a single device reference
on local from registration until final destruction.
3. In nfc_llcp_local_get(), use kref_get_unless_zero() to prevent
resurrecting a local object whose teardown has been scheduled.
4. In llcp_sock_accept(), verify that the listener socket state is still
LLCP_LISTEN after waking from schedule_timeout() to prevent hangs if
the listener is closed concurrently.
5. When unlinking unaccepted child sockets during listener release,
unlink them from local->sockets, call sock_orphan(), and drop their
initial sk_alloc creation reference via sock_put().
6. Make nfc_llcp_accept_unlink() idempotent by guarding parent access with
a NULL check.
Fixes: 50b78b2a6500 ("NFC: Fix sleeping in atomic when releasing socket")
Signed-off-by: Lee Jones <lee@kernel.org>
Link: https://patch.msgid.link/20260902123033.1169067-1-lee@kernel.org
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp.h | 1 +
net/nfc/llcp_core.c | 125 +++++++++++++++++++++++++++-----------------
net/nfc/llcp_sock.c | 49 ++++++++++++-----
3 files changed, 116 insertions(+), 59 deletions(-)
diff --git a/net/nfc/llcp.h b/net/nfc/llcp.h
index d8345ed57c954..23ae7a0112d37 100644
--- a/net/nfc/llcp.h
+++ b/net/nfc/llcp.h
@@ -91,6 +91,7 @@ struct nfc_llcp_local {
struct hlist_head pending_sdreqs;
struct timer_list sdreq_timer;
struct work_struct sdreq_timeout_work;
+ struct work_struct release_work;
u8 sdreq_next_tid;
/* sockets array */
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index 9ae9b4fde311e..a4d7b2eaebd43 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -20,6 +20,8 @@ static LIST_HEAD(llcp_devices);
/* Protects llcp_devices list */
static DEFINE_SPINLOCK(llcp_devices_lock);
+static struct workqueue_struct *llcp_wq;
+
static void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb);
void nfc_llcp_sock_link(struct llcp_sock_list *l, struct sock *sk)
@@ -63,21 +65,33 @@ static void nfc_llcp_socket_purge(struct nfc_llcp_sock *sock)
}
}
+static struct sock *nfc_llcp_sock_list_pop(struct llcp_sock_list *l)
+{
+ struct sock *sk;
+
+ write_lock(&l->lock);
+ sk = sk_head(&l->head);
+ if (sk) {
+ sock_hold(sk);
+ sk_del_node_init(sk);
+ }
+ write_unlock(&l->lock);
+
+ return sk;
+}
+
static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
int err)
{
struct sock *sk;
- struct hlist_node *tmp;
struct nfc_llcp_sock *llcp_sock;
skb_queue_purge(&local->tx_queue);
- write_lock(&local->sockets.lock);
-
- sk_for_each_safe(sk, tmp, &local->sockets.head) {
+ while ((sk = nfc_llcp_sock_list_pop(&local->sockets))) {
llcp_sock = nfc_llcp_sock(sk);
- bh_lock_sock(sk);
+ lock_sock(sk);
nfc_llcp_socket_purge(llcp_sock);
@@ -91,17 +105,27 @@ static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
list_for_each_entry_safe(lsk, n,
&llcp_sock->accept_queue,
accept_queue) {
- accept_sk = &lsk->sk;
- bh_lock_sock(accept_sk);
-
- nfc_llcp_accept_unlink(accept_sk);
+ bool put_creation = false;
- if (err)
- accept_sk->sk_err = err;
- accept_sk->sk_state = LLCP_CLOSED;
- accept_sk->sk_state_change(sk);
+ accept_sk = &lsk->sk;
+ lock_sock_nested(accept_sk,
+ SINGLE_DEPTH_NESTING);
+
+ if (nfc_llcp_sock(accept_sk)->parent == sk) {
+ nfc_llcp_accept_unlink(accept_sk);
+ nfc_llcp_sock_unlink(&local->sockets, accept_sk);
+
+ if (err)
+ accept_sk->sk_err = err;
+ accept_sk->sk_state = LLCP_CLOSED;
+ accept_sk->sk_state_change(accept_sk);
+ sock_orphan(accept_sk);
+ put_creation = true;
+ }
- bh_unlock_sock(accept_sk);
+ release_sock(accept_sk);
+ if (put_creation)
+ sock_put(accept_sk); /* creation ref */
}
}
@@ -110,23 +134,18 @@ static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
- bh_unlock_sock(sk);
-
- sk_del_node_init(sk);
+ release_sock(sk);
+ sock_put(sk);
}
- write_unlock(&local->sockets.lock);
-
/* If we still have a device, we keep the RAW sockets alive */
if (device == true)
return;
- write_lock(&local->raw_sockets.lock);
-
- sk_for_each_safe(sk, tmp, &local->raw_sockets.head) {
+ while ((sk = nfc_llcp_sock_list_pop(&local->raw_sockets))) {
llcp_sock = nfc_llcp_sock(sk);
- bh_lock_sock(sk);
+ lock_sock(sk);
nfc_llcp_socket_purge(llcp_sock);
@@ -135,26 +154,20 @@ static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
- bh_unlock_sock(sk);
-
- sk_del_node_init(sk);
+ release_sock(sk);
+ sock_put(sk);
}
-
- write_unlock(&local->raw_sockets.lock);
}
static struct nfc_llcp_local *nfc_llcp_local_get(struct nfc_llcp_local *local)
{
- /* Since using nfc_llcp_local may result in usage of nfc_dev, whenever
- * we hold a reference to local, we also need to hold a reference to
- * the device to avoid UAF.
- */
- if (!nfc_get_device(local->dev->idx))
+ if (!local)
return NULL;
- kref_get(&local->ref);
+ if (kref_get_unless_zero(&local->ref))
+ return local;
- return local;
+ return NULL;
}
static void local_cleanup(struct nfc_llcp_local *local)
@@ -172,30 +185,34 @@ static void local_cleanup(struct nfc_llcp_local *local)
nfc_llcp_free_sdp_tlv_list(&local->pending_sdreqs);
}
-static void local_release(struct kref *ref)
+static void local_release_work(struct work_struct *work)
{
struct nfc_llcp_local *local;
+ struct nfc_dev *dev;
- local = container_of(ref, struct nfc_llcp_local, ref);
+ local = container_of(work, struct nfc_llcp_local, release_work);
+ dev = local->dev;
local_cleanup(local);
kfree(local);
+ nfc_put_device(dev);
}
-int nfc_llcp_local_put(struct nfc_llcp_local *local)
+static void local_release(struct kref *ref)
{
- struct nfc_dev *dev;
- int ret;
+ struct nfc_llcp_local *local;
- if (local == NULL)
- return 0;
+ local = container_of(ref, struct nfc_llcp_local, ref);
- dev = local->dev;
+ queue_work(llcp_wq, &local->release_work);
+}
- ret = kref_put(&local->ref, local_release);
- nfc_put_device(dev);
+int nfc_llcp_local_put(struct nfc_llcp_local *local)
+{
+ if (!local)
+ return 0;
- return ret;
+ return kref_put(&local->ref, local_release);
}
static struct nfc_llcp_sock *nfc_llcp_sock_get(struct nfc_llcp_local *local,
@@ -1703,6 +1720,7 @@ int nfc_llcp_register_device(struct nfc_dev *ndev)
INIT_WORK(&local->rx_work, nfc_llcp_rx_work);
INIT_WORK(&local->timeout_work, nfc_llcp_timeout_work);
+ INIT_WORK(&local->release_work, local_release_work);
rwlock_init(&local->sockets.lock);
rwlock_init(&local->connecting_sockets.lock);
@@ -1746,10 +1764,23 @@ void nfc_llcp_unregister_device(struct nfc_dev *dev)
int __init nfc_llcp_init(void)
{
- return nfc_llcp_sock_init();
+ int ret;
+
+ llcp_wq = alloc_workqueue("nfc_llcp_wq", WQ_UNBOUND, 0);
+ if (!llcp_wq)
+ return -ENOMEM;
+
+ ret = nfc_llcp_sock_init();
+ if (ret) {
+ destroy_workqueue(llcp_wq);
+ return ret;
+ }
+
+ return 0;
}
void nfc_llcp_exit(void)
{
nfc_llcp_sock_exit();
+ destroy_workqueue(llcp_wq);
}
diff --git a/net/nfc/llcp_sock.c b/net/nfc/llcp_sock.c
index 0cb1688bcbba7..8764b6d82a97d 100644
--- a/net/nfc/llcp_sock.c
+++ b/net/nfc/llcp_sock.c
@@ -392,11 +392,12 @@ void nfc_llcp_accept_unlink(struct sock *sk)
pr_debug("state %d\n", sk->sk_state);
- list_del_init(&llcp_sock->accept_queue);
- sk_acceptq_removed(llcp_sock->parent);
- llcp_sock->parent = NULL;
-
- sock_put(sk);
+ if (llcp_sock->parent) {
+ list_del_init(&llcp_sock->accept_queue);
+ sk_acceptq_removed(llcp_sock->parent);
+ llcp_sock->parent = NULL;
+ sock_put(sk);
+ }
}
void nfc_llcp_accept_enqueue(struct sock *parent, struct sock *sk)
@@ -423,12 +424,20 @@ struct sock *nfc_llcp_accept_dequeue(struct sock *parent,
list_for_each_entry_safe(lsk, n, &llcp_parent->accept_queue,
accept_queue) {
+ struct nfc_llcp_local *local;
+
sk = &lsk->sk;
- lock_sock(sk);
+ lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
if (sk->sk_state == LLCP_CLOSED) {
- release_sock(sk);
+ local = nfc_llcp_sock(sk)->local;
+
nfc_llcp_accept_unlink(sk);
+ if (local)
+ nfc_llcp_sock_unlink(&local->sockets, sk);
+ sock_orphan(sk);
+ release_sock(sk);
+ sock_put(sk);
continue;
}
@@ -464,7 +473,7 @@ static int llcp_sock_accept(struct socket *sock, struct socket *newsock,
pr_debug("parent %p\n", sk);
- lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
+ lock_sock(sk);
if (sk->sk_state != LLCP_LISTEN) {
ret = -EBADFD;
@@ -490,7 +499,12 @@ static int llcp_sock_accept(struct socket *sock, struct socket *newsock,
release_sock(sk);
timeo = schedule_timeout(timeo);
- lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
+ lock_sock(sk);
+
+ if (sk->sk_state != LLCP_LISTEN) {
+ ret = -EBADFD;
+ break;
+ }
}
__set_current_state(TASK_RUNNING);
remove_wait_queue(sk_sleep(sk), &wait);
@@ -629,13 +643,24 @@ static int llcp_sock_release(struct socket *sock)
list_for_each_entry_safe(lsk, n, &llcp_sock->accept_queue,
accept_queue) {
+ bool put_creation = false;
+
accept_sk = &lsk->sk;
- lock_sock(accept_sk);
+ lock_sock_nested(accept_sk, SINGLE_DEPTH_NESTING);
- nfc_llcp_send_disconnect(lsk);
- nfc_llcp_accept_unlink(accept_sk);
+ if (nfc_llcp_sock(accept_sk)->parent == sk) {
+ nfc_llcp_send_disconnect(lsk);
+ nfc_llcp_accept_unlink(accept_sk);
+ nfc_llcp_sock_unlink(&local->sockets, accept_sk);
+
+ accept_sk->sk_state = LLCP_CLOSED;
+ sock_orphan(accept_sk);
+ put_creation = true;
+ }
release_sock(accept_sk);
+ if (put_creation)
+ sock_put(accept_sk); /* creation ref */
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 879/982] selftests: nci: Fix uninitialized family ID on missing attribute
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (877 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 878/982] nfc: llcp: Fix race condition in accept_queue lifecycle Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 880/982] selftests/nci: Fix out-of-bounds store on thread join Greg Kroah-Hartman
` (109 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chaithanya Lagisetty, Hangbin Liu,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
[ Upstream commit eda518d2cdb6074a0bcdfa06af291616bcb5c421 ]
get_family_id() walks the generic netlink CTRL_CMD_GETFAMILY reply
looking for the CTRL_ATTR_FAMILY_ID attribute and returns the parsed
value in the local variable "id". If the reply does not carry that
attribute, the parsing loop never assigns "id" and the function returns
an indeterminate stack value, which the caller stores in self->fid and
uses for subsequent netlink requests.
Initialize "id" to 0 so a missing attribute yields a deterministic
(invalid) family ID instead of a garbage value.
Fixes: f595cf1242f3 ("selftests: Add nci suite")
Signed-off-by: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260901070618.3299012-1-nagachaithanya9911@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/nci/nci_dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/nci/nci_dev.c b/tools/testing/selftests/nci/nci_dev.c
index 6f571e3c21c09..87262f8d0c101 100644
--- a/tools/testing/selftests/nci/nci_dev.c
+++ b/tools/testing/selftests/nci/nci_dev.c
@@ -182,7 +182,7 @@ static int get_family_id(int sd, __u32 pid, __u32 *event_group)
} ans;
struct nlattr *na;
int resp_len;
- __u16 id;
+ __u16 id = 0;
int len;
int rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 880/982] selftests/nci: Fix out-of-bounds store on thread join
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (878 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 879/982] selftests: nci: Fix uninitialized family ID on missing attribute Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 881/982] nfc: virtual_ncidev: Add missing ioctl compat handler Greg Kroah-Hartman
` (108 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Gellermann, Simon Horman,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Gellermann <christian.gellermann@codasip.com>
[ Upstream commit 6be581aeffc215bfc77939cd59902b0dbc4af23e ]
The NCI test collects the exit status of its helper threads by passing
the address of an int to pthread_join():
int status;
...
pthread_join(thread_t, (void **) &status);
pthread_join() stores a void pointer to the memory location. On 64-bit
systems, a void pointer is wider than an int, so the store overruns the
4 bytes of space allocated on the stack for the integer and corrupts the
adjacent stack. On our CHERI system, this caused a fault due to a
capability bounds violation.
Fix this by introducing a helper that joins a thread through a void
pointer and converts the result back to an integer, which is what the
helper threads return.
While here, also fix the logic in disconnect_tag() if the helper thread
creation failed. Previously, it would have joined a thread that was
never created when pthread_create() failed.
Fixes: f595cf1242f3 ("selftests: Add nci suite")
Signed-off-by: Chris Gellermann <christian.gellermann@codasip.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260904095915.3372241-1-christian.gellermann@codasip.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/nci/nci_dev.c | 31 +++++++++++++++++----------
1 file changed, 20 insertions(+), 11 deletions(-)
diff --git a/tools/testing/selftests/nci/nci_dev.c b/tools/testing/selftests/nci/nci_dev.c
index 87262f8d0c101..30db9bda001e3 100644
--- a/tools/testing/selftests/nci/nci_dev.c
+++ b/tools/testing/selftests/nci/nci_dev.c
@@ -8,6 +8,7 @@
#include <stdlib.h>
#include <errno.h>
+#include <stdint.h>
#include <string.h>
#include <sys/ioctl.h>
#include <fcntl.h>
@@ -87,6 +88,16 @@ struct msgtemplate {
char buf[MAX_MSG_SIZE];
};
+static int join_thread_status(pthread_t thread)
+{
+ void *thread_ret = NULL;
+
+ if (pthread_join(thread, &thread_ret))
+ return -1;
+
+ return (int)(intptr_t)thread_ret;
+}
+
static int create_nl_socket(void)
{
int fd;
@@ -444,7 +455,7 @@ FIXTURE_SETUP(NCI)
NFC_CMD_DEV_UP, self->dev_idex);
EXPECT_EQ(rc, 0);
- pthread_join(thread_t, (void **)&status);
+ status = join_thread_status(thread_t);
ASSERT_EQ(status, 0);
self->open_state = true;
}
@@ -514,7 +525,7 @@ FIXTURE_TEARDOWN(NCI)
NFC_CMD_DEV_DOWN, self->dev_idex);
EXPECT_EQ(rc, 0);
- pthread_join(thread_t, (void **)&status);
+ status = join_thread_status(thread_t);
ASSERT_EQ(status, 0);
}
@@ -585,7 +596,6 @@ int start_polling(int dev_idx, int proto, int virtual_fd, int sd, int fid, int p
void *nla_start_poll_data[2] = {&dev_idx, &proto};
int nla_start_poll_len[2] = {4, 4};
pthread_t thread_t;
- int status;
int rc;
rc = pthread_create(&thread_t, NULL, virtual_poll_start,
@@ -598,14 +608,12 @@ int start_polling(int dev_idx, int proto, int virtual_fd, int sd, int fid, int p
if (rc != 0)
return rc;
- pthread_join(thread_t, (void **)&status);
- return status;
+ return join_thread_status(thread_t);
}
int stop_polling(int dev_idx, int virtual_fd, int sd, int fid, int pid)
{
pthread_t thread_t;
- int status;
int rc;
rc = pthread_create(&thread_t, NULL, virtual_poll_stop,
@@ -618,8 +626,7 @@ int stop_polling(int dev_idx, int virtual_fd, int sd, int fid, int pid)
if (rc != 0)
return rc;
- pthread_join(thread_t, (void **)&status);
- return status;
+ return join_thread_status(thread_t);
}
TEST_F(NCI, start_poll)
@@ -834,8 +841,10 @@ int disconnect_tag(int nfc_sock, int virtual_fd)
return status;
close(nfc_sock);
- pthread_join(thread_t, (void **)&status);
- return status;
+ if (status)
+ return -1;
+
+ return join_thread_status(thread_t);
}
TEST_F(NCI, t4t_tag_read)
@@ -882,7 +891,7 @@ TEST_F(NCI, deinit)
NFC_CMD_DEV_DOWN, self->dev_idex);
EXPECT_EQ(rc, 0);
- pthread_join(thread_t, (void **)&status);
+ status = join_thread_status(thread_t);
self->open_state = 0;
ASSERT_EQ(status, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 881/982] nfc: virtual_ncidev: Add missing ioctl compat handler
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (879 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 880/982] selftests/nci: Fix out-of-bounds store on thread join Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 882/982] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure Greg Kroah-Hartman
` (107 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Gellermann, Simon Horman,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Gellermann <christian.gellermann@codasip.com>
[ Upstream commit 51814683e28fc64eceb415962376956c3cfc75a7 ]
The compat handler for ioctls to the virtual nci device is missing. So,
nci-specific ioctls of a compat task return with -1 and errno set to
ENOTTY. Add a handler.
The handling of an ioctl() call of a compat task to get the index of
virtual nci device (IOCTL_GET_NCIDEV_IDX) lands in the default case of
the ioctl compat handler (see fs/ioctl.c):
COMPAT_SYSCALL_DEFINE3(ioctl, ...)
{
...
default:
error = do_vfs_ioctl(fd_file(f), fd, cmd, ...);
if (error != -ENOIOCTLCMD)
break;
if (fd_file(f)->f_op->compat_ioctl)
error = fd_file(f)->f_op->compat_ioctl(fd_file(f), cmd, arg);
if (error == -ENOIOCTLCMD)
error = -ENOTTY;
...
}
There, do_vfs_ioctl() returns -ENOIOCTLCMD and compat_ioctl is not
set for virtual_ncidev_fops, i.e. f_op->compat_ioctl == NULL. So, the
ioctl() syscall returns with -1 and errno set to ENOTTY to the compat
task.
To fix this, use the compat_ptr_ioctl helper for compat handling here.
It shall be used for ioctls that "either ignore the argument or pass a
pointer to a compatible data type". The driver's sole ioctl takes a user
void pointer and copies nfc_dev->idx to it, a 4-byte integer across all
ABIs.
This issue has been found by running the nci_dev kernel selftest as
rv64 binary on top of a CHERI kernel, where the ioctl() ends up in
the ioctl compat handler, similar to a 32-bit application on top of a
64-bit kernel.
Fixes: e624e6c3e777 ("nfc: Add a virtual nci device driver")
Signed-off-by: Chris Gellermann <christian.gellermann@codasip.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260904164252.18351-1-christian.gellermann@codasip.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/virtual_ncidev.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/nfc/virtual_ncidev.c b/drivers/nfc/virtual_ncidev.c
index 85c06dbb2c449..1f9b3fb04e0ae 100644
--- a/drivers/nfc/virtual_ncidev.c
+++ b/drivers/nfc/virtual_ncidev.c
@@ -196,7 +196,8 @@ static const struct file_operations virtual_ncidev_fops = {
.write = virtual_ncidev_write,
.open = virtual_ncidev_open,
.release = virtual_ncidev_close,
- .unlocked_ioctl = virtual_ncidev_ioctl
+ .unlocked_ioctl = virtual_ncidev_ioctl,
+ .compat_ioctl = compat_ptr_ioctl,
};
static int __init virtual_ncidev_init(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 882/982] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (880 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 881/982] nfc: virtual_ncidev: Add missing ioctl compat handler Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.1 883/982] nfc: st21nfca: validate ISO15693 inventory length Greg Kroah-Hartman
` (106 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Simon Horman,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit 66f4300206b82b0b143ef0d9be90cd8d29f23a47 ]
nfc_genl_llc_sdreq() builds a list of TLV nodes while walking nested
netlink attrs, but 3 error paths (nested-attr parse failure, TLV alloc
ENOMEM, nfc_llcp_send_snl_sdreq() failure) all skip freeing what was
already queued.
Route them through a new free_list label, mirroring the SDRES path in
the same file which already does this. Harmless on the success path
too -- send_snl_sdreq() drains the list as it moves nodes, so it's
already empty by the time free_list runs.
Fixes: d9b8d8e19b07 ("NFC: llcp: Service Name Lookup netlink interface")
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260914121129.2098606-1-congnt264@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/netlink.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/nfc/netlink.c b/net/nfc/netlink.c
index e9ac6a6f934e7..c59eb73c84914 100644
--- a/net/nfc/netlink.c
+++ b/net/nfc/netlink.c
@@ -1178,7 +1178,7 @@ static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
if (rc != 0) {
rc = -EINVAL;
- goto put_local;
+ goto free_list;
}
if (!sdp_attrs[NFC_SDP_ATTR_URI])
@@ -1197,7 +1197,7 @@ static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
sdreq = nfc_llcp_build_sdreq_tlv(tid, uri, uri_len);
if (sdreq == NULL) {
rc = -ENOMEM;
- goto put_local;
+ goto free_list;
}
tlvs_len += sdreq->tlv_len;
@@ -1212,6 +1212,9 @@ static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
rc = nfc_llcp_send_snl_sdreq(local, &sdreq_list, tlvs_len);
+free_list:
+ nfc_llcp_free_sdp_tlv_list(&sdreq_list);
+
put_local:
nfc_llcp_local_put(local);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 883/982] nfc: st21nfca: validate ISO15693 inventory length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (881 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 882/982] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 884/982] nfc: llcp: fix -ENOMEM on connect with zero-length service name Greg Kroah-Hartman
` (105 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, David Heidelberg,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 7f2ea5ed588c03d481f0301e6c3d4240132383fb ]
The ISO15693 inventory helper removes a two-byte prefix without checking
that it exists, then accepts a one-byte remainder before reading data[1] as
the DSFID.
Require the prefix and at least two remaining bytes before copying the UID
data and reading the DSFID.
Fixes: 7974728094d3 ("NFC: st21nfca: Add ISO15693 Reader/Writer support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260830132958.6397-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/st21nfca/core.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/nfc/st21nfca/core.c b/drivers/nfc/st21nfca/core.c
index 161caf2675cfc..7eb5e5f0686be 100644
--- a/drivers/nfc/st21nfca/core.c
+++ b/drivers/nfc/st21nfca/core.c
@@ -577,9 +577,7 @@ static int st21nfca_get_iso15693_inventory(struct nfc_hci_dev *hdev,
if (r < 0)
goto exit;
- skb_pull(inventory_skb, 2);
-
- if (inventory_skb->len == 0 ||
+ if (!skb_pull(inventory_skb, 2) || inventory_skb->len < 2 ||
inventory_skb->len > NFC_ISO15693_UID_MAXSIZE) {
r = -EPROTO;
goto exit;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 884/982] nfc: llcp: fix -ENOMEM on connect with zero-length service name
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (882 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 6.1 883/982] nfc: st21nfca: validate ISO15693 inventory length Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 885/982] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap() Greg Kroah-Hartman
` (104 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ömer Mete Kaya,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ömer Mete Kaya <omermetekaya0@gmail.com>
[ Upstream commit c04981e42d94f39c1dba965cc462a046e946a6c5 ]
When service_name_len is 0, kmemdup() returns ZERO_SIZE_PTR which
passes the NULL check, causing nfc_llcp_send_connect() to attempt
building a zero-length service name TLV and fail with -ENOMEM.
Fix by setting service_name to NULL directly when service_name_len is 0.
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260909122029.34081-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_sock.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/net/nfc/llcp_sock.c b/net/nfc/llcp_sock.c
index 8764b6d82a97d..a841d8474e2a6 100644
--- a/net/nfc/llcp_sock.c
+++ b/net/nfc/llcp_sock.c
@@ -759,12 +759,16 @@ static int llcp_sock_connect(struct socket *sock, struct sockaddr *_addr,
llcp_sock->service_name_len = min_t(unsigned int,
addr->service_name_len,
NFC_LLCP_MAX_SERVICE_NAME);
- llcp_sock->service_name = kmemdup(addr->service_name,
- llcp_sock->service_name_len,
- GFP_KERNEL);
- if (!llcp_sock->service_name) {
- ret = -ENOMEM;
- goto sock_llcp_release;
+ if (llcp_sock->service_name_len == 0) {
+ llcp_sock->service_name = NULL;
+ } else {
+ llcp_sock->service_name = kmemdup(addr->service_name,
+ llcp_sock->service_name_len,
+ GFP_KERNEL);
+ if (!llcp_sock->service_name) {
+ ret = -ENOMEM;
+ goto sock_llcp_release;
+ }
}
nfc_llcp_sock_link(&local->connecting_sockets, sk);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 885/982] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (883 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 884/982] nfc: llcp: fix -ENOMEM on connect with zero-length service name Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 886/982] nfc: llcp: fix slab-out-of-bounds reads when logging service names Greg Kroah-Hartman
` (103 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ömer Mete Kaya,
David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ömer Mete Kaya <omermetekaya0@gmail.com>
[ Upstream commit 408cff6bd60636df201274d320edfdfde9ed41db ]
nfc_llcp_wks_sap() compares only service_name_len bytes, so a short
service_name like "u" matches longer WKS strings like "urn:nfc:sn:snep".
Fix by requiring exact length match before strncmp().
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260909121437.33744-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index a4d7b2eaebd43..0b1a2755f58ac 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -367,7 +367,8 @@ static int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len)
if (wks[sap] == NULL)
continue;
- if (strncmp(wks[sap], service_name, service_name_len) == 0)
+ if (strlen(wks[sap]) == service_name_len &&
+ !strncmp(wks[sap], service_name, service_name_len))
return sap;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 886/982] nfc: llcp: fix slab-out-of-bounds reads when logging service names
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (884 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 885/982] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 887/982] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Greg Kroah-Hartman
` (102 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1e3df0852e82c21ca418,
Ömer Mete Kaya, David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ömer Mete Kaya <omermetekaya0@gmail.com>
[ Upstream commit 7dcf371a35632f035baf77bcf2c129165f772ce4 ]
nfc_llcp_wks_sap() and nfc_llcp_build_sdreq_tlv() pass non-null-
terminated strings to pr_debug() using the %s format specifier.
The buffers are allocated via kmemdup() or come from netlink
attributes and are not guaranteed to be null-terminated, causing
__dynamic_pr_debug() to read beyond the allocated region:
KASAN: slab-out-of-bounds Read in __dynamic_pr_debug
Fix both call sites by using %.*s with the explicit length to limit
the output to the actual length of the string.
Fixes: d9b8d8e19b07 ("NFC: llcp: Service Name Lookup netlink interface")
Reported-by: syzbot+1e3df0852e82c21ca418@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1e3df0852e82c21ca418
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260908161952.731468-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_commands.c | 2 +-
net/nfc/llcp_core.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/nfc/llcp_commands.c b/net/nfc/llcp_commands.c
index a93bf0b43d504..2d9e0925b1cc7 100644
--- a/net/nfc/llcp_commands.c
+++ b/net/nfc/llcp_commands.c
@@ -135,7 +135,7 @@ struct nfc_llcp_sdp_tlv *nfc_llcp_build_sdreq_tlv(u8 tid, const char *uri,
{
struct nfc_llcp_sdp_tlv *sdreq;
- pr_debug("uri: %s, len: %zu\n", uri, uri_len);
+ pr_debug("uri: %.*s, len: %zu\n", (int)uri_len, uri, uri_len);
/* sdreq->tlv_len is u8, takes uri_len, + 3 for header, + 1 for NULL */
if (WARN_ON_ONCE(uri_len > U8_MAX - 4))
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index 0b1a2755f58ac..49f7793ab0312 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -356,7 +356,7 @@ static int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len)
{
int sap, num_wks;
- pr_debug("%s\n", service_name);
+ pr_debug("%.*s\n", (int)service_name_len, service_name);
if (service_name == NULL)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 887/982] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (885 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 886/982] nfc: llcp: fix slab-out-of-bounds reads when logging service names Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 888/982] net/sched: act_gate: budget the per-entry list in get_fill_size Greg Kroah-Hartman
` (101 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1853daab1a47603d4678,
Deepanshu Kartikey, David Heidelberg, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Deepanshu Kartikey <kartikey406@gmail.com>
[ Upstream commit b61732f47316d45f27706db7812950145d3327b5 ]
frame->ccid.datalen is read directly from the USB response frame
and used, unchecked, as an index into frame->data[]. A malicious or
malfunctioning device can set this field to an arbitrary value,
causing the driver to read far outside the received buffer.
Bound ccid.datalen against the maximum possible ACR122 frame size
before using it. This replaces the existing datalen == 0 check,
since datalen < 2 already covers that case and additionally
rejects datalen == 1, which would still underflow the
"datalen - 2" offset used below.
Fixes: 9815c7cf22da ("NFC: pn533: Separate physical layer from the core implementation")
Reported-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1853daab1a47603d4678
Tested-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com
Assisted-by: LLM
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Link: https://patch.msgid.link/20260923035627.6210-1-kartikey406@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/pn533/usb.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/nfc/pn533/usb.c b/drivers/nfc/pn533/usb.c
index 0b7e3b118dfd4..986d5bae2177f 100644
--- a/drivers/nfc/pn533/usb.c
+++ b/drivers/nfc/pn533/usb.c
@@ -320,7 +320,9 @@ static bool pn533_acr122_is_rx_frame_valid(void *_frame, struct pn533 *dev)
if (frame->ccid.type != 0x83)
return false;
- if (!frame->ccid.datalen)
+ if (frame->ccid.datalen < 2 ||
+ frame->ccid.datalen > PN533_ACR122_FRAME_MAX_PAYLOAD_LEN +
+ PN533_ACR122_RX_FRAME_TAIL_LEN)
return false;
if (frame->data[frame->ccid.datalen - 2] == 0x63)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 888/982] net/sched: act_gate: budget the per-entry list in get_fill_size
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (886 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 887/982] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 889/982] veth: manage XDP program pointers during channel resize Greg Kroah-Hartman
` (100 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, hybris, Jamal Hadi Salim,
Victor Nogueira, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Victor Nogueira <victor@mojatatu.com>
[ Upstream commit cfa165cbfbed9d0f4bbc22fef4309f595a3ab187 ]
tcf_gate_get_fill_size returns only the TCA_GATE_PARMS size, but
tcf_gate_dump also emits three 64-bit timestamps, the clock id, flags,
priority and the variable-length TCA_GATE_ENTRY_LIST nest. The per-entry
nest is unbounded: parse_gate_list places no cap on the number of
sched-entries, so a gate with many entries can push the real dump well
past the skb that tca_get_fill allocates from this size.
RTM_NEWACTION then fails the add-notify with -EINVAL while the action is
already committed to the IDR, and a subsequent RTM_GETACTION on the
installed gate also returns -EINVAL because its dump no longer fits.
Fix this by accounting for the missing fields in tcf_gate_get_fill_size
along with all elements in the entries list.
Note that sizing the reply from the action lets an oversized gate
install cleanly for the first time: with the input unbounded by
parse_gate_list, the sized skb can now grow well above
NLMSG_GOODSIZE per netlink request (a transient GFP_KERNEL allocation
reachable only with namespace-local CAP_NET_ADMIN). Overload from a
malicious netns admin is hardening material, not net, per the
discussion at
https://lore.kernel.org/netdev/20260914191108.55a1a4f1@kernel.org/;
a follow-up patch for net-next will cap the sched-entry count.
Fixes: 4e76e75d6aba ("net sched actions: calculate add/delete event message size")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824153903.4143642-1-victor@mojatatu.com
Tested-by: hybris <hybris@mojatatu.ai>
Co-developed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/QDISC-3BLH.v1.20260914203033@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_gate.c | 30 +++++++++++++++++++++++++++++-
1 file changed, 29 insertions(+), 1 deletion(-)
diff --git a/net/sched/act_gate.c b/net/sched/act_gate.c
index fa0127e5a46bc..a43102a020a18 100644
--- a/net/sched/act_gate.c
+++ b/net/sched/act_gate.c
@@ -682,7 +682,35 @@ static void tcf_gate_stats_update(struct tc_action *a, u64 bytes, u64 packets,
static size_t tcf_gate_get_fill_size(const struct tc_action *act)
{
- return nla_total_size(sizeof(struct tc_gate));
+ struct tcf_gate *gact = to_gate(act);
+ const struct tcf_gate_params *p;
+ struct tcfg_gate_entry *entry;
+ size_t size = nla_total_size(sizeof(struct tc_gate)) /* TCA_GATE_PARMS */
+ + 3 * nla_total_size_64bit(sizeof(u64)) /* TCA_GATE_BASE_TIME
+ * TCA_GATE_CYCLE_TIME
+ * TCA_GATE_CYCLE_TIME_EXT
+ */
+ + nla_total_size(sizeof(s32)) /* TCA_GATE_CLOCKID */
+ + nla_total_size(sizeof(u32)) /* TCA_GATE_FLAGS */
+ + nla_total_size(sizeof(s32)) /* TCA_GATE_PRIORITY */
+ + nla_total_size(0); /* TCA_GATE_ENTRY_LIST */
+ /* TCA_GATE_TM is budgeted by tcf_action_shared_attrs_size() */
+
+ rcu_read_lock();
+ p = rcu_dereference(gact->param);
+ if (p) {
+ list_for_each_entry_rcu(entry, &p->entries, list)
+ /* TCA_GATE_ONE_ENTRY nest and its attributes */
+ size += nla_total_size(0)
+ + nla_total_size(sizeof(u32)) /* TCA_GATE_ENTRY_INDEX */
+ + nla_total_size(0) /* TCA_GATE_ENTRY_GATE */
+ + nla_total_size(sizeof(u32)) /* TCA_GATE_ENTRY_INTERVAL */
+ + nla_total_size(sizeof(s32)) /* TCA_GATE_ENTRY_MAX_OCTETS */
+ + nla_total_size(sizeof(s32)); /* TCA_GATE_ENTRY_IPV */
+ }
+ rcu_read_unlock();
+
+ return size;
}
static void tcf_gate_entry_destructor(void *priv)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 889/982] veth: manage XDP program pointers during channel resize
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (887 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 888/982] net/sched: act_gate: budget the per-entry list in get_fill_size Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 890/982] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6() Greg Kroah-Hartman
` (99 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Stanislav Fomichev,
Jiayuan Chen, Jason Xing, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 7104a370714346b667712913dc16abf14bbc97ed ]
veth_set_channels() tears down XDP resources for removed RX queues
without clearing rq->xdp_prog. If the program is then detached or
replaced, those queues keep the old pointer after bpf_prog_put().
A later channel increase can re-enable NAPI and run the freed program.
BUG: unable to handle page fault for address: ffffc90000256048
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: veth_xdp_rcv_skb (include/linux/filter.h:779
include/net/xdp.h:696 drivers/net/veth.c:820)
Call Trace:
veth_xdp_rcv (drivers/net/veth.c:941)
veth_poll (drivers/net/veth.c:986)
__napi_poll (net/core/dev.c:7787)
net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007)
handle_softirqs (kernel/softirq.c:645)
Kernel panic - not syncing: Fatal exception in interrupt
Fixes: 4752eeb3d891 ("veth: implement support for set_channel ethtool op")
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Jason Xing <kerneljasonxing@gmail.com>
Link: https://patch.msgid.link/20260921231856.1798630-1-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/veth.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/veth.c b/drivers/net/veth.c
index e7e8c277a9255..2eef96cfd279a 100644
--- a/drivers/net/veth.c
+++ b/drivers/net/veth.c
@@ -1015,6 +1015,7 @@ static int __veth_napi_enable_range(struct net_device *dev, int start, int end)
for (i = start; i < end; i++) {
struct veth_rq *rq = &priv->rq[i];
+ rcu_assign_pointer(rq->xdp_prog, priv->_xdp_prog);
napi_enable(&rq->xdp_napi);
rcu_assign_pointer(priv->rq[i].napi, &priv->rq[i].xdp_napi);
}
@@ -1043,6 +1044,7 @@ static void veth_napi_del_range(struct net_device *dev, int start, int end)
rcu_assign_pointer(priv->rq[i].napi, NULL);
napi_disable(&rq->xdp_napi);
+ rcu_assign_pointer(rq->xdp_prog, NULL);
__netif_napi_del(&rq->xdp_napi);
}
synchronize_net();
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 890/982] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (888 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 889/982] veth: manage XDP program pointers during channel resize Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 891/982] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Greg Kroah-Hartman
` (98 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Shihuang Liu,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shihuang Liu <shlomojune6@gmail.com>
[ Upstream commit 3b4e0b0c008a8c1b474730248cd5b873026c74bd ]
skb_maybe_pull_tail() subtracts skb_headlen(skb) from the unsigned max
argument and passes the result to __pskb_pull_tail() as a signed int. The
function does not ensure that max is at least skb_headlen(skb).
This can happen while parsing IPv6 extension headers when an skb already
has a linear area larger than MAX_IPV6_HDR_LEN. Once the parser needs data
beyond the linear area, max - skb_headlen(skb) wraps and is converted to a
negative delta. __pskb_pull_tail() then passes that negative length to
skb_copy_bits(), where it can become a very large copy length.
Pass the requested length itself as the pull bound at the three
extension-header call sites, so the delta can no longer go negative.
Fixes: 1431fb31ecba ("xen-netback: fix fragment detection in checksum setup")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Shihuang Liu <shlomojune6@gmail.com>
Link: https://patch.msgid.link/20260919133604.50948-1-shlomojune6@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skbuff.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 40b2fee82bf9f..a66066bc98610 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -5256,7 +5256,8 @@ static int skb_checksum_setup_ipv6(struct sk_buff *skb, bool recalculate)
err = skb_maybe_pull_tail(skb,
off +
sizeof(struct ipv6_opt_hdr),
- MAX_IPV6_HDR_LEN);
+ off +
+ sizeof(struct ipv6_opt_hdr));
if (err < 0)
goto out;
@@ -5271,7 +5272,8 @@ static int skb_checksum_setup_ipv6(struct sk_buff *skb, bool recalculate)
err = skb_maybe_pull_tail(skb,
off +
sizeof(struct ip_auth_hdr),
- MAX_IPV6_HDR_LEN);
+ off +
+ sizeof(struct ip_auth_hdr));
if (err < 0)
goto out;
@@ -5286,7 +5288,8 @@ static int skb_checksum_setup_ipv6(struct sk_buff *skb, bool recalculate)
err = skb_maybe_pull_tail(skb,
off +
sizeof(struct frag_hdr),
- MAX_IPV6_HDR_LEN);
+ off +
+ sizeof(struct frag_hdr));
if (err < 0)
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 891/982] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (889 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 890/982] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 892/982] bpf: Fix immediate JMP JEQ/JNE on MIPS32 Greg Kroah-Hartman
` (97 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefano Sasso, Ido Schimmel,
David Ahern, Eric Dumazet, Andrea Mayer, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit ab7aa05c06ae340e5c7530bb78fa8d23794e460b ]
The VRF device is an Ethernet device but it can have non-Ethernet ports
such as IP tunnels. Before the cited commit, capturing packets from such
ports on the VRF device resulted in these packets being detected as
malformed since they lack an Ethernet header.
The cited commit fixed it by pushing a dummy Ethernet header to such
packets before the capture and pulling it afterwards. In the case of
CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
the dummy Ethernet header. This is wrong as skb->csum should not include
the checksum of the Ethernet header ("checksum of the _whole_ packet as
seen by netif_rx()").
This also means that L4 protocols receive a corrupted skb->csum and
potentially drop the packet, as is the case with UDP packets whose
checksum was completed by software.
Fix by removing the unnecessary call to skb_postpush_rcsum().
Fixes: 048939088220 ("vrf: add mac header for tunneled packets when sniffer is attached")
Reported-by: Stefano Sasso <stesasso@gmail.com>
Closes: https://lore.kernel.org/netdev/CALtE316UtL3x7LL6uxfXzx8rW6AbzYPeDOb478hqJCr_-dj=Wg@mail.gmail.com/
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Link: https://patch.msgid.link/20260922131239.2509494-1-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vrf.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/vrf.c b/drivers/net/vrf.c
index 65668113f715e..807b96925fe1e 100644
--- a/drivers/net/vrf.c
+++ b/drivers/net/vrf.c
@@ -1278,8 +1278,6 @@ static int vrf_prepare_mac_header(struct sk_buff *skb,
skb->protocol = eth->h_proto;
skb->pkt_type = PACKET_HOST;
- skb_postpush_rcsum(skb, skb->data, ETH_HLEN);
-
skb_pull_inline(skb, ETH_HLEN);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 892/982] bpf: Fix immediate JMP JEQ/JNE on MIPS32
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (890 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 891/982] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 893/982] bpf: Fix BSWAP 32 and 16 on MIPS64 Greg Kroah-Hartman
` (96 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johan Almbladh, Alexei Starovoitov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Almbladh <johan.almbladh@anyfinetworks.com>
[ Upstream commit db762fd96be225bd06161c9631160c755d891693 ]
An addu instruction was emitted instead of addiu, causing the immediate
value 1 to be interpreted as register $at. This made the comparison
result invalid when the immediate operand was negative. Note that $at
is mapped to BPF_REG_AX, which is used for constant blinding.
Fix the instruction to use the immediate form.
Found with test_bpf on MIPS32r1 emulated by QEMU.
Fixes: eb63cfcd2ee8 ("mips, bpf: Add eBPF JIT for 32-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-1-johan.almbladh@anyfinetworks.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/net/bpf_jit_comp32.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/mips/net/bpf_jit_comp32.c b/arch/mips/net/bpf_jit_comp32.c
index ace5db3fbd171..78f47c7b8d60d 100644
--- a/arch/mips/net/bpf_jit_comp32.c
+++ b/arch/mips/net/bpf_jit_comp32.c
@@ -1111,7 +1111,7 @@ static void emit_jmp_i64(struct jit_context *ctx,
emit(ctx, xor, tmp, lo(dst), tmp);
}
if (imm < 0) { /* Compare sign extension */
- emit(ctx, addu, MIPS_R_T9, hi(dst), 1);
+ emit(ctx, addiu, MIPS_R_T9, hi(dst), 1);
emit(ctx, or, tmp, tmp, MIPS_R_T9);
} else { /* Compare zero extension */
emit(ctx, or, tmp, tmp, hi(dst));
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 893/982] bpf: Fix BSWAP 32 and 16 on MIPS64
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (891 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 892/982] bpf: Fix immediate JMP JEQ/JNE on MIPS32 Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 894/982] driver core: Better advertise dev_err_probe() Greg Kroah-Hartman
` (95 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johan Almbladh, Alexei Starovoitov,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Almbladh <johan.almbladh@anyfinetworks.com>
[ Upstream commit 8110ba09777873443db286b3cbb89b0e6311c554 ]
The 16/32-bit byteswap implementations for MIPS64r1 and earlier do
not have an explicit zero extension afterwards. The input is first
sign-extended to 64 bits, and the byteswap sequence can then leave
the result sign-extended depending on the value of the low bits.
Add the missing zero-extension.
Found with test_bpf on MIPS64r1 emulated by QEMU.
Fixes: fbc802de6b10 ("mips, bpf: Add new eBPF JIT for 64-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-2-johan.almbladh@anyfinetworks.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/net/bpf_jit_comp64.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/arch/mips/net/bpf_jit_comp64.c b/arch/mips/net/bpf_jit_comp64.c
index 0e7c1bdcf9148..b45c6c3bf1641 100644
--- a/arch/mips/net/bpf_jit_comp64.c
+++ b/arch/mips/net/bpf_jit_comp64.c
@@ -302,8 +302,7 @@ static void emit_bswap_r64(struct jit_context *ctx, u8 dst, u32 width)
case 16:
emit_sext(ctx, dst, dst);
emit_bswap_r(ctx, dst, width);
- if (cpu_has_mips64r2 || cpu_has_mips64r6)
- emit_zext(ctx, dst);
+ emit_zext(ctx, dst);
break;
}
clobber_reg(ctx, dst);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 894/982] driver core: Better advertise dev_err_probe()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (892 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 893/982] bpf: Fix BSWAP 32 and 16 on MIPS64 Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 895/982] driver core: Make dev_err_probe() silent for -ENOMEM Greg Kroah-Hartman
` (94 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
Uwe Kleine-König, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
[ Upstream commit 532888a59505da2a3fbb4abac6adad381cedb374 ]
Describing the usage of dev_err_probe() as being (only?) "deemed
acceptable" has a bad connotation. In fact dev_err_probe() fulfills
three tasks:
- handling of EPROBE_DEFER (even more than degrading to dev_dbg())
- symbolic output of the error code
- return err for compact error code paths
Advertise these better and claim the usage to be "fine" to get rid of
the bad connotation.
Acked-by: Rafael J. Wysocki <rafael@kernel.org>
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Link: https://lore.kernel.org/r/20231215174540.2438601-2-u.kleine-koenig@pengutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 4eb3f195ef08 ("tg3: use random MAC address when tg3_get_device_address fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/core.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/base/core.c b/drivers/base/core.c
index 81a8fe313f6a4..09114e717800b 100644
--- a/drivers/base/core.c
+++ b/drivers/base/core.c
@@ -5042,13 +5042,14 @@ define_dev_printk_level(_dev_info, KERN_INFO);
*
* return dev_err_probe(dev, err, ...);
*
- * Note that it is deemed acceptable to use this function for error
- * prints during probe even if the @err is known to never be -EPROBE_DEFER.
+ * Using this helper in your probe function is totally fine even if @err is
+ * known to never be -EPROBE_DEFER.
* The benefit compared to a normal dev_err() is the standardized format
- * of the error code and the fact that the error code is returned.
+ * of the error code, it being emitted symbolically (i.e. you get "EAGAIN"
+ * instead of "-35") and the fact that the error code is returned which allows
+ * more compact error paths.
*
* Returns @err.
- *
*/
int dev_err_probe(const struct device *dev, int err, const char *fmt, ...)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 895/982] driver core: Make dev_err_probe() silent for -ENOMEM
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (893 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 894/982] driver core: Better advertise dev_err_probe() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 896/982] driver core: Add device probe log helper dev_warn_probe() Greg Kroah-Hartman
` (93 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Uwe Kleine-König,
Geert Uytterhoeven, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
[ Upstream commit 2f3cfd2f4b7cf3026fe6b9b2a5320cc18f4c184e ]
For an out-of-memory error there should be no additional output. Adapt
dev_err_probe() to not emit the error message when err is -ENOMEM.
This simplifies handling errors that might among others be -ENOMEM.
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://lore.kernel.org/r/3d1e308d45cddf67749522ca42d83f5b4f0b9634.1718311756.git.u.kleine-koenig@baylibre.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 4eb3f195ef08 ("tg3: use random MAC address when tg3_get_device_address fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/core.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
diff --git a/drivers/base/core.c b/drivers/base/core.c
index 09114e717800b..fde08c9660a31 100644
--- a/drivers/base/core.c
+++ b/drivers/base/core.c
@@ -5060,11 +5060,22 @@ int dev_err_probe(const struct device *dev, int err, const char *fmt, ...)
vaf.fmt = fmt;
vaf.va = &args;
- if (err != -EPROBE_DEFER) {
- dev_err(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
- } else {
+ switch (err) {
+ case -EPROBE_DEFER:
device_set_deferred_probe_reason(dev, &vaf);
dev_dbg(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
+ break;
+
+ case -ENOMEM:
+ /*
+ * We don't print anything on -ENOMEM, there is already enough
+ * output.
+ */
+ break;
+
+ default:
+ dev_err(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
+ break;
}
va_end(args);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 896/982] driver core: Add device probe log helper dev_warn_probe()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (894 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 895/982] driver core: Make dev_err_probe() silent for -ENOMEM Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 897/982] tg3: use random MAC address when tg3_get_device_address fails Greg Kroah-Hartman
` (92 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dragan Simic,
Hélène Vulquin, Mark Brown, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dragan Simic <dsimic@manjaro.org>
[ Upstream commit 36e69b160705b65bf136c2fb6a1194447eeb8478 ]
Some drivers can still provide their functionality to a certain extent
even when some of their resource acquisitions eventually fail. In such
cases, emitting errors isn't the desired action, but warnings should be
emitted instead.
To solve this, introduce dev_warn_probe() as a new device probe log helper,
which behaves identically as the already existing dev_err_probe(), while it
produces warnings instead of errors. The intended use is with the resources
that are actually optional for a particular driver.
While there, copyedit the kerneldoc for dev_err_probe() a bit, to simplify
its wording a bit, and reuse it as the kerneldoc for dev_warn_probe(), with
the necessary wording adjustments, of course.
Signed-off-by: Dragan Simic <dsimic@manjaro.org>
Tested-by: Hélène Vulquin <oss@helene.moe>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/2be0a28538bb2a3d1bcc91e2ca1f2d0dc09146d9.1727601608.git.dsimic@manjaro.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 4eb3f195ef08 ("tg3: use random MAC address when tg3_get_device_address fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/core.c | 129 +++++++++++++++++++++++++++++--------
include/linux/dev_printk.h | 1 +
2 files changed, 102 insertions(+), 28 deletions(-)
diff --git a/drivers/base/core.c b/drivers/base/core.c
index fde08c9660a31..00737fc051575 100644
--- a/drivers/base/core.c
+++ b/drivers/base/core.c
@@ -5018,6 +5018,49 @@ define_dev_printk_level(_dev_info, KERN_INFO);
#endif
+static void __dev_probe_failed(const struct device *dev, int err, bool fatal,
+ const char *fmt, va_list vargsp)
+{
+ struct va_format vaf;
+ va_list vargs;
+
+ /*
+ * On x86_64 and possibly on other architectures, va_list is actually a
+ * size-1 array containing a structure. As a result, function parameter
+ * vargsp decays from T[1] to T*, and &vargsp has type T** rather than
+ * T(*)[1], which is expected by its assignment to vaf.va below.
+ *
+ * One standard way to solve this mess is by creating a copy in a local
+ * variable of type va_list and then using a pointer to that local copy
+ * instead, which is the approach employed here.
+ */
+ va_copy(vargs, vargsp);
+
+ vaf.fmt = fmt;
+ vaf.va = &vargs;
+
+ switch (err) {
+ case -EPROBE_DEFER:
+ device_set_deferred_probe_reason(dev, &vaf);
+ dev_dbg(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
+ break;
+
+ case -ENOMEM:
+ /* Don't print anything on -ENOMEM, there's already enough output */
+ break;
+
+ default:
+ /* Log fatal final failures as errors, otherwise produce warnings */
+ if (fatal)
+ dev_err(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
+ else
+ dev_warn(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
+ break;
+ }
+
+ va_end(vargs);
+}
+
/**
* dev_err_probe - probe error check and log helper
* @dev: the pointer to the struct device
@@ -5030,7 +5073,7 @@ define_dev_printk_level(_dev_info, KERN_INFO);
* -EPROBE_DEFER and propagate error upwards.
* In case of -EPROBE_DEFER it sets also defer probe reason, which can be
* checked later by reading devices_deferred debugfs attribute.
- * It replaces code sequence::
+ * It replaces the following code sequence::
*
* if (err != -EPROBE_DEFER)
* dev_err(dev, ...);
@@ -5042,47 +5085,77 @@ define_dev_printk_level(_dev_info, KERN_INFO);
*
* return dev_err_probe(dev, err, ...);
*
- * Using this helper in your probe function is totally fine even if @err is
- * known to never be -EPROBE_DEFER.
+ * Using this helper in your probe function is totally fine even if @err
+ * is known to never be -EPROBE_DEFER.
* The benefit compared to a normal dev_err() is the standardized format
- * of the error code, it being emitted symbolically (i.e. you get "EAGAIN"
- * instead of "-35") and the fact that the error code is returned which allows
- * more compact error paths.
+ * of the error code, which is emitted symbolically (i.e. you get "EAGAIN"
+ * instead of "-35"), and having the error code returned allows more
+ * compact error paths.
*
* Returns @err.
*/
int dev_err_probe(const struct device *dev, int err, const char *fmt, ...)
{
- struct va_format vaf;
- va_list args;
+ va_list vargs;
- va_start(args, fmt);
- vaf.fmt = fmt;
- vaf.va = &args;
+ va_start(vargs, fmt);
- switch (err) {
- case -EPROBE_DEFER:
- device_set_deferred_probe_reason(dev, &vaf);
- dev_dbg(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
- break;
+ /* Use dev_err() for logging when err doesn't equal -EPROBE_DEFER */
+ __dev_probe_failed(dev, err, true, fmt, vargs);
- case -ENOMEM:
- /*
- * We don't print anything on -ENOMEM, there is already enough
- * output.
- */
- break;
+ va_end(vargs);
- default:
- dev_err(dev, "error %pe: %pV", ERR_PTR(err), &vaf);
- break;
- }
+ return err;
+}
+EXPORT_SYMBOL_GPL(dev_err_probe);
- va_end(args);
+/**
+ * dev_warn_probe - probe error check and log helper
+ * @dev: the pointer to the struct device
+ * @err: error value to test
+ * @fmt: printf-style format string
+ * @...: arguments as specified in the format string
+ *
+ * This helper implements common pattern present in probe functions for error
+ * checking: print debug or warning message depending if the error value is
+ * -EPROBE_DEFER and propagate error upwards.
+ * In case of -EPROBE_DEFER it sets also defer probe reason, which can be
+ * checked later by reading devices_deferred debugfs attribute.
+ * It replaces the following code sequence::
+ *
+ * if (err != -EPROBE_DEFER)
+ * dev_warn(dev, ...);
+ * else
+ * dev_dbg(dev, ...);
+ * return err;
+ *
+ * with::
+ *
+ * return dev_warn_probe(dev, err, ...);
+ *
+ * Using this helper in your probe function is totally fine even if @err
+ * is known to never be -EPROBE_DEFER.
+ * The benefit compared to a normal dev_warn() is the standardized format
+ * of the error code, which is emitted symbolically (i.e. you get "EAGAIN"
+ * instead of "-35"), and having the error code returned allows more
+ * compact error paths.
+ *
+ * Returns @err.
+ */
+int dev_warn_probe(const struct device *dev, int err, const char *fmt, ...)
+{
+ va_list vargs;
+
+ va_start(vargs, fmt);
+
+ /* Use dev_warn() for logging when err doesn't equal -EPROBE_DEFER */
+ __dev_probe_failed(dev, err, false, fmt, vargs);
+
+ va_end(vargs);
return err;
}
-EXPORT_SYMBOL_GPL(dev_err_probe);
+EXPORT_SYMBOL_GPL(dev_warn_probe);
static inline bool fwnode_is_primary(struct fwnode_handle *fwnode)
{
diff --git a/include/linux/dev_printk.h b/include/linux/dev_printk.h
index ca32b5bb28eb5..eb2094e43050c 100644
--- a/include/linux/dev_printk.h
+++ b/include/linux/dev_printk.h
@@ -276,6 +276,7 @@ do { \
dev_driver_string(dev), dev_name(dev), ## arg)
__printf(3, 4) int dev_err_probe(const struct device *dev, int err, const char *fmt, ...);
+__printf(3, 4) int dev_warn_probe(const struct device *dev, int err, const char *fmt, ...);
/* Simple helper for dev_err_probe() when ERR_PTR() is to be returned. */
#define dev_err_ptr_probe(dev, ___err, fmt, ...) \
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 897/982] tg3: use random MAC address when tg3_get_device_address fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (895 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 896/982] driver core: Add device probe log helper dev_warn_probe() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 898/982] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems Greg Kroah-Hartman
` (91 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, Ivan Delalande,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivan Delalande <colona@arista.com>
[ Upstream commit 4eb3f195ef08c5acaed87958297e41cc49588dde ]
Some of the tg3 NICs we use (BCM57762) reset the SRAM MAC address to the
placeholder address on link flaps, tg3_chip_reset, etc. We've typically
fixed it from userspace, but since e4c00ba7274b ("tg3: replace
placeholder MAC address with device property") was merged, tg3 just
fails probe as we don't have a way to get it through the generic
device_get_mac_address infrastructure as fallback on our systems.
Make the driver assign a random address in this condition instead of
being fatal for probe. Set deferred_probe_reason through dev_warn_probe
if the address isn't yet available from the provider.
Fixes: e4c00ba7274b ("tg3: replace placeholder MAC address with device property")
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Link: https://lore.kernel.org/netdev/20260909191751.651aa5c4@kernel.org/
Signed-off-by: Ivan Delalande <colona@arista.com>
Link: https://patch.msgid.link/20260918224715.GA654128@visor
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/tg3.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/tg3.c b/drivers/net/ethernet/broadcom/tg3.c
index 65bab84f4d972..045d33ca7c675 100644
--- a/drivers/net/ethernet/broadcom/tg3.c
+++ b/drivers/net/ethernet/broadcom/tg3.c
@@ -17834,11 +17834,14 @@ static int tg3_init_one(struct pci_dev *pdev,
err = tg3_get_device_address(tp, addr);
if (err) {
- dev_err(&pdev->dev,
- "Could not obtain valid ethernet address, aborting\n");
- goto err_out_apeunmap;
+ dev_warn_probe(&pdev->dev, err,
+ "Could not obtain a valid ethernet address\n");
+ if (err == -EPROBE_DEFER)
+ goto err_out_apeunmap;
+ eth_hw_addr_random(dev);
+ } else {
+ eth_hw_addr_set(dev, addr);
}
- eth_hw_addr_set(dev, addr);
intmbx = MAILBOX_INTERRUPT_0 + TG3_64BIT_REG_LOW;
rcvmbx = MAILBOX_RCVRET_CON_IDX_0 + TG3_64BIT_REG_LOW;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 898/982] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (896 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 897/982] tg3: use random MAC address when tg3_get_device_address fails Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 899/982] net: bcmgenet: initialize u64 stats seq counter for all queues Greg Kroah-Hartman
` (90 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit 0e2bec77ea62895416600c90588f593516572bca ]
When bcmgenet was converted to 64-bit statistics, STAT_RTNL members were
switched to point into struct rtnl_link_stats64, whose fields are 64-bit
(__u64) regardless of architecture.
However, bcmgenet_get_ethtool_stats() retained a legacy check:
if (sizeof(unsigned long) != sizeof(u32) &&
s->stat_sizeof == sizeof(unsigned long))
On 32-bit systems, sizeof(unsigned long) == sizeof(u32), causing this
condition to evaluate to false. As a result, 64-bit RTNL stats fields were
read via *(u32 *)p. On 32-bit Big-Endian systems (such as MIPS BE), this
reads the high 32 bits and returns 0 until the counter exceeds 4GB; on
32-bit Little-Endian systems (such as 32-bit ARM), the value is truncated
to 32 bits.
Fix this by checking if s->stat_sizeof == sizeof(u64) so 64-bit fields are
always read as 64-bit values.
Fixes: 59aa6e3072aa ("net: bcmgenet: switch to use 64bit statistics")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-2-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index a22f569987c6f..bda534237a7a9 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -1307,9 +1307,8 @@ static void bcmgenet_get_ethtool_stats(struct net_device *dev,
p = (char *)&stats64;
p += s->stat_offset;
- if (sizeof(unsigned long) != sizeof(u32) &&
- s->stat_sizeof == sizeof(unsigned long))
- data[i] = *(unsigned long *)p;
+ if (s->stat_sizeof == sizeof(u64))
+ data[i] = *(u64 *)p;
else
data[i] = *(u32 *)p;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 899/982] net: bcmgenet: initialize u64 stats seq counter for all queues
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (897 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 898/982] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 900/982] net: bcmgenet: move bcmgenet_power_up into resume_noirq Greg Kroah-Hartman
` (89 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit 3aeaa609fda19c09d5298c9fedaaa3b6229601b5 ]
bcmgenet_gstrings_stats statically defines ethtool statistics for queues
0 through GENET_MAX_MQ_CNT (4). However, bcmgenet_probe() only initialized
the u64_stats_sync seq counter up to priv->hw_params->rx_queues and
priv->hw_params->tx_queues.
Since priv->hw_params->rx_queues is 0 across all hardware versions (and
priv->hw_params->tx_queues is 0 on GENET V1), rings 1..4 have uninitialized
u64_stats_sync structures. When ethtool -S is run on 32-bit kernels,
bcmgenet_get_ethtool_stats() reads stats from rx_rings[1..4], causing
lockdep warnings due to the uninitialized sequence counters.
Initialize the sequence counters for all GENET_MAX_MQ_CNT + 1 queues.
Fixes: ffc2c8c4a714 ("net: bcmgenet: Initialize u64 stats seq counter")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-3-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index bda534237a7a9..8107242398f18 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -4073,10 +4073,10 @@ static int bcmgenet_probe(struct platform_device *pdev)
priv->rx_rings[i].rx_max_coalesced_frames = 1;
/* Initialize u64 stats seq counter for 32bit machines */
- for (i = 0; i <= priv->hw_params->rx_queues; i++)
+ for (i = 0; i <= GENET_MAX_MQ_CNT; i++) {
u64_stats_init(&priv->rx_rings[i].stats64.syncp);
- for (i = 0; i <= priv->hw_params->tx_queues; i++)
u64_stats_init(&priv->tx_rings[i].stats64.syncp);
+ }
/* libphy will determine the link state */
netif_carrier_off(dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 900/982] net: bcmgenet: move bcmgenet_power_up into resume_noirq
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (898 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 899/982] net: bcmgenet: initialize u64 stats seq counter for all queues Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 901/982] net: bcmgenet: allow return of power up status Greg Kroah-Hartman
` (88 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Doug Berger, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doug Berger <opendmb@gmail.com>
[ Upstream commit ffce2bedd361177718dc0c3787f4adb4785a0151 ]
The bcmgenet_power_up() function is moved from the resume method
to the resume_noirq method for symmetry with the suspend_noirq
method. This allows the wol_active flag to be removed.
The UMAC_IRQ_WAKE_EVENT interrupts that can be unmasked by the
bcmgenet_wol_power_down_cfg() function are now re-masked by the
bcmgenet_wol_power_up_cfg() function at the resume_noirq level
as well.
Signed-off-by: Doug Berger <opendmb@gmail.com>
Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20250306192643.2383632-13-opendmb@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: cbbc1aee7776 ("net: bcmgenet: do not skip WoL power up on GENET V1")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/broadcom/genet/bcmgenet.c | 24 +++++++++----------
.../net/ethernet/broadcom/genet/bcmgenet.h | 1 -
.../ethernet/broadcom/genet/bcmgenet_wol.c | 8 +++----
3 files changed, 15 insertions(+), 18 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 8107242398f18..19ce77e687ddf 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -4142,8 +4142,20 @@ static int bcmgenet_resume_noirq(struct device *d)
reg = bcmgenet_intrl2_0_readl(priv, INTRL2_CPU_STAT);
if (reg & UMAC_IRQ_WAKE_EVENT)
pm_wakeup_event(&priv->pdev->dev, 0);
+
+ /* From WOL-enabled suspend, switch to regular clock */
+ bcmgenet_power_up(priv, GENET_POWER_WOL_MAGIC);
}
+ /* If this is an internal GPHY, power it back on now, before UniMAC is
+ * brought out of reset as absolutely no UniMAC activity is allowed
+ */
+ if (priv->internal_phy)
+ bcmgenet_power_up(priv, GENET_POWER_PASSIVE);
+
+ /* take MAC out of reset */
+ bcmgenet_umac_reset(priv);
+
bcmgenet_intrl2_0_writel(priv, UMAC_IRQ_WAKE_EVENT, INTRL2_CPU_CLEAR);
return 0;
@@ -4160,18 +4172,6 @@ static int bcmgenet_resume(struct device *d)
if (!netif_running(dev))
return 0;
- /* From WOL-enabled suspend, switch to regular clock */
- if (device_may_wakeup(d) && priv->wolopts)
- bcmgenet_power_up(priv, GENET_POWER_WOL_MAGIC);
-
- /* If this is an internal GPHY, power it back on now, before UniMAC is
- * brought out of reset as absolutely no UniMAC activity is allowed
- */
- if (priv->internal_phy)
- bcmgenet_power_up(priv, GENET_POWER_PASSIVE);
-
- bcmgenet_umac_reset(priv);
-
init_umac(priv);
phy_init_hw(dev->phydev);
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.h b/drivers/net/ethernet/broadcom/genet/bcmgenet.h
index 94957dfa55b6f..bbbb4f317f9e0 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.h
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.h
@@ -658,7 +658,6 @@ struct bcmgenet_priv {
struct clk *clk_wol;
u32 wolopts;
u8 sopass[SOPASS_MAX];
- bool wol_active;
struct bcmgenet_mib_counters mib;
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c b/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c
index cd5a35309ca78..2384d60937e1d 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c
@@ -177,7 +177,6 @@ int bcmgenet_wol_power_down_cfg(struct bcmgenet_priv *priv,
retries);
clk_prepare_enable(priv->clk_wol);
- priv->wol_active = 1;
if (hfb_enable) {
bcmgenet_hfb_reg_writel(priv, hfb_enable,
@@ -216,13 +215,12 @@ void bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
return;
}
- if (!priv->wol_active)
- return; /* failed to suspend so skip the rest */
-
- priv->wol_active = 0;
clk_disable_unprepare(priv->clk_wol);
priv->crc_fwd_en = 0;
+ bcmgenet_intrl2_0_writel(priv, UMAC_IRQ_WAKE_EVENT,
+ INTRL2_CPU_MASK_SET);
+
/* Disable Magic Packet Detection */
if (priv->wolopts & (WAKE_MAGIC | WAKE_MAGICSECURE)) {
reg = bcmgenet_umac_readl(priv, UMAC_MPD_CTRL);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 901/982] net: bcmgenet: allow return of power up status
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (899 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 900/982] net: bcmgenet: move bcmgenet_power_up into resume_noirq Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 902/982] net: bcmgenet: do not skip WoL power up on GENET V1 Greg Kroah-Hartman
` (87 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Doug Berger, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doug Berger <opendmb@gmail.com>
[ Upstream commit 2432b9817b7cb91aaae9e5032da0bb017cb3102d ]
It is possible for a WoL power up to fail due to the GENET being
reset while in the suspend state. Allow these failures to be
returned as error codes to allow different recovery behavior
when necessary.
Signed-off-by: Doug Berger <opendmb@gmail.com>
Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20250306192643.2383632-14-opendmb@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: cbbc1aee7776 ("net: bcmgenet: do not skip WoL power up on GENET V1")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 13 ++++++++-----
drivers/net/ethernet/broadcom/genet/bcmgenet.h | 4 ++--
drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c | 12 +++++++-----
3 files changed, 17 insertions(+), 12 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 19ce77e687ddf..ea171dd2f2a06 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -1697,13 +1697,14 @@ static int bcmgenet_power_down(struct bcmgenet_priv *priv,
return ret;
}
-static void bcmgenet_power_up(struct bcmgenet_priv *priv,
- enum bcmgenet_power_mode mode)
+static int bcmgenet_power_up(struct bcmgenet_priv *priv,
+ enum bcmgenet_power_mode mode)
{
+ int ret = 0;
u32 reg;
if (!bcmgenet_has_ext(priv))
- return;
+ return ret;
reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
@@ -1739,11 +1740,13 @@ static void bcmgenet_power_up(struct bcmgenet_priv *priv,
}
break;
case GENET_POWER_WOL_MAGIC:
- bcmgenet_wol_power_up_cfg(priv, mode);
- return;
+ ret = bcmgenet_wol_power_up_cfg(priv, mode);
+ break;
default:
break;
}
+
+ return ret;
}
static struct enet_cb *bcmgenet_get_txcb(struct bcmgenet_priv *priv,
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.h b/drivers/net/ethernet/broadcom/genet/bcmgenet.h
index bbbb4f317f9e0..5f0cf8f1f634d 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.h
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.h
@@ -741,8 +741,8 @@ void bcmgenet_get_wol(struct net_device *dev, struct ethtool_wolinfo *wol);
int bcmgenet_set_wol(struct net_device *dev, struct ethtool_wolinfo *wol);
int bcmgenet_wol_power_down_cfg(struct bcmgenet_priv *priv,
enum bcmgenet_power_mode mode);
-void bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
- enum bcmgenet_power_mode mode);
+int bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
+ enum bcmgenet_power_mode mode);
void bcmgenet_eee_enable_set(struct net_device *dev, bool enable,
bool tx_lpi_enabled);
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c b/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c
index 2384d60937e1d..f3b18050aa88c 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c
@@ -205,14 +205,14 @@ int bcmgenet_wol_power_down_cfg(struct bcmgenet_priv *priv,
return 0;
}
-void bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
- enum bcmgenet_power_mode mode)
+int bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
+ enum bcmgenet_power_mode mode)
{
u32 reg;
if (mode != GENET_POWER_WOL_MAGIC) {
netif_err(priv, wol, priv->dev, "invalid mode: %d\n", mode);
- return;
+ return -EINVAL;
}
clk_disable_unprepare(priv->clk_wol);
@@ -225,7 +225,7 @@ void bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
if (priv->wolopts & (WAKE_MAGIC | WAKE_MAGICSECURE)) {
reg = bcmgenet_umac_readl(priv, UMAC_MPD_CTRL);
if (!(reg & MPD_EN))
- return; /* already reset so skip the rest */
+ return -EPERM; /* already reset so skip the rest */
reg &= ~(MPD_EN | MPD_PW_EN);
bcmgenet_umac_writel(priv, reg, UMAC_MPD_CTRL);
}
@@ -234,7 +234,7 @@ void bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
if (priv->wolopts & WAKE_FILTER) {
reg = bcmgenet_hfb_reg_readl(priv, HFB_CTRL);
if (!(reg & RBUF_ACPI_EN))
- return; /* already reset so skip the rest */
+ return -EPERM; /* already reset so skip the rest */
reg &= ~(RBUF_HFB_EN | RBUF_ACPI_EN);
bcmgenet_hfb_reg_writel(priv, reg, HFB_CTRL);
}
@@ -245,4 +245,6 @@ void bcmgenet_wol_power_up_cfg(struct bcmgenet_priv *priv,
reg &= ~CMD_CRC_FWD;
bcmgenet_umac_writel(priv, reg, UMAC_CMD);
spin_unlock_bh(&priv->reg_lock);
+
+ return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 902/982] net: bcmgenet: do not skip WoL power up on GENET V1
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (900 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 901/982] net: bcmgenet: allow return of power up status Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 903/982] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr Greg Kroah-Hartman
` (86 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit cbbc1aee7776c7fa1d89e6cb963a23e58c495dca ]
bcmgenet_power_up() had an early check for bcmgenet_has_ext(priv) before
dispatching by power mode. GENET V1 does not have the EXT block (unlike
GENET V2+), which causes bcmgenet_power_up() to immediately return 0.
As a consequence, when waking up from GENET_POWER_WOL_MAGIC on GENET V1,
bcmgenet_wol_power_up_cfg() is never invoked to disable the WoL clock,
clear wake event masks, and restore normal PHY and MAC operations.
Move the bcmgenet_has_ext() checks to the GENET_POWER_PASSIVE and
GENET_POWER_CABLE_SENSE cases where the EXT registers are actually
accessed, allowing GENET_POWER_WOL_MAGIC cleanup to execute on all
hardware versions.
Fixes: c3ae64ae0c08 ("net: bcmgenet: handle GENET_POWER_WOL_MAGIC")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-4-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index ea171dd2f2a06..68acfac5491dc 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -1703,13 +1703,12 @@ static int bcmgenet_power_up(struct bcmgenet_priv *priv,
int ret = 0;
u32 reg;
- if (!bcmgenet_has_ext(priv))
- return ret;
-
- reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
-
switch (mode) {
case GENET_POWER_PASSIVE:
+ if (!bcmgenet_has_ext(priv))
+ break;
+
+ reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
reg &= ~(EXT_PWR_DOWN_DLL | EXT_PWR_DOWN_BIAS |
EXT_ENERGY_DET_MASK);
if (GENET_IS_V5(priv) && !bcmgenet_has_ephy_16nm(priv)) {
@@ -1733,8 +1732,12 @@ static int bcmgenet_power_up(struct bcmgenet_priv *priv,
break;
case GENET_POWER_CABLE_SENSE:
+ if (!bcmgenet_has_ext(priv))
+ break;
+
/* enable APD */
if (!GENET_IS_V5(priv)) {
+ reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
reg |= EXT_PWR_DN_EN_LD;
bcmgenet_ext_writel(priv, reg, EXT_EXT_PWR_MGMT);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 903/982] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (901 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 902/982] net: bcmgenet: do not skip WoL power up on GENET V1 Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 904/982] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT Greg Kroah-Hartman
` (85 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit 273941c85fc2632cd3e56ddff737b9245de7697d ]
bcmgenet_set_mac_addr() did not check whether the provided MAC address is a
valid Ethernet address before applying it. Userspace could configure an
invalid address (such as all zeroes or a multicast address) while the
interface is down.
Add a call to is_valid_ether_addr() and return -EADDRNOTAVAIL if the MAC
address is not valid.
Fixes: 1c1008c793fa ("net: bcmgenet: add main driver file")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-5-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 68acfac5491dc..6b6a3465c07fb 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -3566,6 +3566,9 @@ static int bcmgenet_set_mac_addr(struct net_device *dev, void *p)
if (netif_running(dev))
return -EBUSY;
+ if (!is_valid_ether_addr(addr->sa_data))
+ return -EADDRNOTAVAIL;
+
eth_hw_addr_set(dev, addr->sa_data);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 904/982] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (902 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 903/982] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 905/982] ip_gre: Reject enabling collect metadata through changelink Greg Kroah-Hartman
` (84 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit d64e277b955be4506931802837499b62c8f3968a ]
bcmgenet_get_coalesce() reads DMA_RING0_TIMEOUT to calculate
rx_coalesce_usecs without masking out bits outside DMA_TIMEOUT_MASK
(16 bits). If upper bits are non-zero or contain status/flags, the
computed value of rx_coalesce_usecs returned to userspace via ethtool
becomes corrupted.
Mask the register read with DMA_TIMEOUT_MASK before computing the
timeout in microseconds.
Fixes: 4a29645bfe6c ("net: bcmgenet: Implement RX coalescing control knobs")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-6-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 6b6a3465c07fb..c729da84a19bb 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -837,7 +837,8 @@ static int bcmgenet_get_coalesce(struct net_device *dev,
ec->rx_max_coalesced_frames =
bcmgenet_rdma_ring_readl(priv, 0, DMA_MBUF_DONE_THRESH);
ec->rx_coalesce_usecs =
- bcmgenet_rdma_readl(priv, DMA_RING0_TIMEOUT) * 8192 / 1000;
+ (bcmgenet_rdma_readl(priv, DMA_RING0_TIMEOUT) &
+ DMA_TIMEOUT_MASK) * 8192 / 1000;
for (i = 0; i <= priv->hw_params->rx_queues; i++) {
ring = &priv->rx_rings[i];
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 905/982] ip_gre: Reject enabling collect metadata through changelink
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (903 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 904/982] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 906/982] vxlan: use one headroom snapshot for neighbour replies Greg Kroah-Hartman
` (83 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Ido Schimmel,
Hangbin Liu, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
[ Upstream commit a3f315be9d30eeb6938d11fa17fd4b32d52f7c42 ]
ipgre_netlink_parms() can enable collect_md on an existing GRE, GRETAP
or ERSPAN device. Unlike newlink, changelink does not enforce metadata
tunnel uniqueness. Converting a non-metadata device can therefore
replace the metadata receive entry for another device of the same type
in the same netns. Deleting either device then clears the shared entry,
breaking metadata receive lookup for the surviving device.
If parameter validation fails after collect_md is set, deleting the
modified device can also clear an entry it never owned.
Reject enabling metadata mode in both changelink callbacks before any
encapsulation or tunnel parameters are modified. Allow requests that
repeat the metadata attribute on an existing metadata device.
Fixes: 2e15ea390e6f ("ip_gre: Add support to collect tunnel metadata.")
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260921031859.9283-1-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/ip_gre.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
index b635d2fedd2db..66c35ced1e887 100644
--- a/net/ipv4/ip_gre.c
+++ b/net/ipv4/ip_gre.c
@@ -1409,6 +1409,12 @@ static int ipgre_changelink(struct net_device *dev, struct nlattr *tb[],
if (!rtnl_dev_link_net_capable(dev, t->net))
return -EPERM;
+ if (data && data[IFLA_GRE_COLLECT_METADATA] && !t->collect_md) {
+ NL_SET_ERR_MSG(extack,
+ "Enabling collect_md on an existing device is not supported");
+ return -EOPNOTSUPP;
+ }
+
err = ipgre_newlink_encap_setup(dev, data);
if (err)
return err;
@@ -1441,6 +1447,12 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[],
if (!rtnl_dev_link_net_capable(dev, t->net))
return -EPERM;
+ if (data && data[IFLA_GRE_COLLECT_METADATA] && !t->collect_md) {
+ NL_SET_ERR_MSG(extack,
+ "Enabling collect_md on an existing device is not supported");
+ return -EOPNOTSUPP;
+ }
+
err = ipgre_newlink_encap_setup(dev, data);
if (err)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 906/982] vxlan: use one headroom snapshot for neighbour replies
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (904 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 905/982] ip_gre: Reject enabling collect metadata through changelink Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 907/982] net: xps: reject an out of range traffic class Greg Kroah-Hartman
` (82 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sanghyun Park, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanghyun Park <sanghyun.park.cnu@gmail.com>
[ Upstream commit 481506a756dcd828ef42391cb08f38d8d96d38fc ]
vxlan_na_create() samples LL_RESERVED_SPACE() to size the reply skb and then
samples it again to reserve headroom. A concurrent vxlan_changelink() can
update needed_headroom between the two reads, creating a TOCTOU race. The
second value can exceed the allocation and make the Ethernet header write out
of bounds.
The race is reproducible on the unpatched kernel. It occurred when
vxlan_na_create() generated a neighbour reply while vxlan_changelink() changed
the link headroom. KASAN caught a four-byte write two bytes beyond a 704-byte
skbuff_small_head allocation.
Snapshot the headroom once and use that value for both allocation and
reservation.
Fixes: 4b29dba9c085 ("vxlan: fix nonfunctional neigh_reduce()")
Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
Link: https://patch.msgid.link/20260918032842.502409-2-sanghyun.park.cnu@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 9327b38fb6fde..59b90864d0509 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -2000,13 +2000,15 @@ static struct sk_buff *vxlan_na_create(struct sk_buff *request,
struct ipv6hdr *pip6;
u8 *daddr;
int na_olen = 8; /* opt hdr + ETH_ALEN for target */
+ int headroom;
int ns_olen;
int i, len;
if (dev == NULL || !pskb_may_pull(request, request->len))
return NULL;
- len = LL_RESERVED_SPACE(dev) + sizeof(struct ipv6hdr) +
+ headroom = LL_RESERVED_SPACE(dev);
+ len = headroom + sizeof(struct ipv6hdr) +
sizeof(*na) + na_olen + dev->needed_tailroom;
reply = alloc_skb(len, GFP_ATOMIC);
if (reply == NULL)
@@ -2014,7 +2016,7 @@ static struct sk_buff *vxlan_na_create(struct sk_buff *request,
reply->protocol = htons(ETH_P_IPV6);
reply->dev = dev;
- skb_reserve(reply, LL_RESERVED_SPACE(request->dev));
+ skb_reserve(reply, headroom);
skb_push(reply, sizeof(struct ethhdr));
skb_reset_mac_header(reply);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 907/982] net: xps: reject an out of range traffic class
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (905 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 906/982] vxlan: use one headroom snapshot for neighbour replies Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 908/982] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() Greg Kroah-Hartman
` (81 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
[ Upstream commit 4da3b7b8b50f3e2fde54a4c18a82a8e3f6223910 ]
Only the entries below dev->num_tc are valid in dev->tc_to_txq[], and
dev->prio_tc_map[] may only name classes below it. netdev_set_num_tc()
lowers dev->num_tc without touching either array.
netdev_txq_to_tc() walks all TC_MAX_QUEUE slots and
netdev_get_prio_tc_map() returns the entry as it stands, so a leftover
entry is handed out as a traffic class >= dev->num_tc. Taking that
class from netdev_txq_to_tc(), __netif_set_xps_queue() rejects only a
negative one and indexes an XPS map sized for dev->num_tc classes:
tci = j * num_tc + tc;
RCU_INIT_POINTER(new_dev_maps->attr_map[tci], map);
attr_map[] holds nr_ids * num_tc entries and j runs over the ids named
in the mask, so a class that is not below num_tc pushes tci past the end
of the map for the last ids and the store overruns it.
Any caller that lowers num_tc leaves such entries behind, and
mqprio_destroy() tears down with netdev_set_num_tc(dev, 0) rather than
netdev_reset_tc(). After mqprio with 8 classes then 1, tc_to_txq[1..7]
still describe txq 1..7. The splat is from an XPS write to txq 2 on a
veth with 8 rx queues: attr_map[] has 8 * 1 entries, tci = j + 2, and
j == 6 stores one past the end of the 88-byte map:
BUG: KASAN: slab-out-of-bounds in __netif_set_xps_queue (net/core/dev.c:2954)
Write of size 8 at addr ffff88813016bc58 by task xps_oob/634
__netif_set_xps_queue (net/core/dev.c:2954)
xps_rxqs_store (net/core/net-sysfs.c:1880)
netdev_queue_attr_store (net/core/net-sysfs.c:1390)
Allocated by task 634:
__kmalloc_noprof (mm/slub.c:5439)
__netif_set_xps_queue (net/core/dev.c:2937)
The buggy address is located 0 bytes to the right of
allocated 88-byte region [ffff88813016bc00, ffff88813016bc58)
Reject a class the map has no room for.
Fixes: 184c449f91fe ("net: Add support for XPS with QoS via traffic classes")
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/162DD16F-54C6-444A-9E09-0B8CB3D591F2@doyensec.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 1f5d42c726d8b..3b81f1787222f 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -2630,7 +2630,7 @@ int __netif_set_xps_queue(struct net_device *dev, const unsigned long *mask,
dev = netdev_get_tx_queue(dev, index)->sb_dev ? : dev;
tc = netdev_txq_to_tc(dev, index);
- if (tc < 0)
+ if (tc < 0 || tc >= num_tc)
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 908/982] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (906 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 907/982] net: xps: reject an out of range traffic class Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 909/982] net/smc: fix UAF on lgr list traversal in smcr_port_err() Greg Kroah-Hartman
` (80 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kimi Security Team, Weiming Shi,
Yilin Zhang, Eric Dumazet, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yilin Zhang <yilinzhang@moonshot.ai>
[ Upstream commit fe99bbeee5c5dbd3abc30721a8079ced59649d97 ]
When tcp_send_synack() replaces the cloned SYN skb at the head of the
retransmit queue with a copy, it frees the original with
tcp_rtx_queue_unlink_and_free() and only repairs tp->highest_sack.
tp->retransmit_skb_hint keeps pointing at the freed
skbuff_fclone_cache object.
The dangling hint is read in tcp_verify_retransmit_hint() and used as
the root of the rbtree walk in tcp_xmit_retransmit_queue(). An
unprivileged TFO client (sendmsg(MSG_FASTOPEN)) can arm the hint with
an attacker-supplied ICMP fragmentation-needed message, after which a
simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)
Read of size 4 at addr ffff88800604d928 by task swapper/1/0
Call Trace:
tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)
tcp_simple_retransmit (net/ipv4/tcp_input.c:3158)
tcp_v4_err (net/ipv4/tcp_ipv4.c:587)
Sync the hint to the copy.
Fixes: c31b70c9968f ("tcp: Add logic to check for SYN w/ data in tcp_simple_retransmit")
Reported-by: Kimi Security Team <bug-report@moonshot.ai>
Tested-by: Weiming Shi <shiweiming@moonshot.ai>
Signed-off-by: Yilin Zhang <yilinzhang@moonshot.ai>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/8a9dff4063a2745653b7e88ceb745d75efa16e68.1790224474.git.yilinzhang@moonshot.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/tcp_output.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index 256e0a755d544..39f25b886678c 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -3551,6 +3551,7 @@ void tcp_send_active_reset(struct sock *sk, gfp_t priority)
*/
int tcp_send_synack(struct sock *sk)
{
+ struct tcp_sock *tp = tcp_sk(sk);
struct sk_buff *skb;
skb = tcp_rtx_queue_head(sk);
@@ -3568,6 +3569,8 @@ int tcp_send_synack(struct sock *sk)
if (!nskb)
return -ENOMEM;
INIT_LIST_HEAD(&nskb->tcp_tsorted_anchor);
+ if (skb == tp->retransmit_skb_hint)
+ tp->retransmit_skb_hint = nskb;
tcp_highest_sack_replace(sk, skb, nskb);
tcp_rtx_queue_unlink_and_free(skb, sk);
__skb_header_release(nskb);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 909/982] net/smc: fix UAF on lgr list traversal in smcr_port_err()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (907 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 908/982] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 910/982] tipc: Fix a data race on mon->peer_cnt in mon_timeout() Greg Kroah-Hartman
` (79 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mahanta Jambigi, Sidraya Jayagond,
Dust Li, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sidraya Jayagond <sidraya@linux.ibm.com>
[ Upstream commit 61cb282fe97b3b0ba32ca09417a693162bf4ae3f ]
smcr_port_err() traverses smc_lgr_list.list without holding
smc_lgr_list.lock, allowing a concurrent smc_lgr_terminate_sched()
to free an lgr while it is still being dereferenced.
Hold smc_lgr_list.lock across the traversal. Update
smc_ib_gid_check() to call smcr_port_err() after releasing the lock.
Fixes: 541afa10c126 ("net/smc: add smcr_port_err() and smcr_link_down() processing")
Reviewed-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Signed-off-by: Sidraya Jayagond <sidraya@linux.ibm.com>
Reviewed-by: Dust Li <dust.li@linux.alibaba.com>
Link: https://patch.msgid.link/20260922073149.474762-1-sidraya@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/smc/smc_core.c | 2 ++
net/smc/smc_ib.c | 10 ++++++++--
2 files changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/smc/smc_core.c b/net/smc/smc_core.c
index 213af93f39d3f..5d188222807a8 100644
--- a/net/smc/smc_core.c
+++ b/net/smc/smc_core.c
@@ -1737,6 +1737,7 @@ void smcr_port_err(struct smc_ib_device *smcibdev, u8 ibport)
struct smc_link_group *lgr, *n;
int i;
+ spin_lock_bh(&smc_lgr_list.lock);
list_for_each_entry_safe(lgr, n, &smc_lgr_list.list, list) {
if (strncmp(smcibdev->pnetid[ibport - 1], lgr->pnet_id,
SMC_MAX_PNETID_LEN))
@@ -1751,6 +1752,7 @@ void smcr_port_err(struct smc_ib_device *smcibdev, u8 ibport)
smcr_link_down_cond_sched(lnk);
}
}
+ spin_unlock_bh(&smc_lgr_list.lock);
}
static void smc_link_down_work(struct work_struct *work)
diff --git a/net/smc/smc_ib.c b/net/smc/smc_ib.c
index 8e41034d8d96f..c1dbcc3f667d1 100644
--- a/net/smc/smc_ib.c
+++ b/net/smc/smc_ib.c
@@ -333,6 +333,7 @@ static bool smc_ib_check_link_gid(u8 gid[SMC_GID_SIZE], bool smcrv2,
static void smc_ib_gid_check(struct smc_ib_device *smcibdev, u8 ibport)
{
struct smc_link_group *lgr;
+ bool stale_gid = false;
int i;
spin_lock_bh(&smc_lgr_list.lock);
@@ -348,11 +349,16 @@ static void smc_ib_gid_check(struct smc_ib_device *smcibdev, u8 ibport)
continue;
if (!smc_ib_check_link_gid(lgr->lnk[i].gid,
lgr->smc_version == SMC_V2,
- smcibdev, ibport))
- smcr_port_err(smcibdev, ibport);
+ smcibdev, ibport)) {
+ stale_gid = true;
+ goto out;
+ }
}
}
+out:
spin_unlock_bh(&smc_lgr_list.lock);
+ if (stale_gid)
+ smcr_port_err(smcibdev, ibport);
}
static int smc_ib_remember_port_attr(struct smc_ib_device *smcibdev, u8 ibport)
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 910/982] tipc: Fix a data race on mon->peer_cnt in mon_timeout()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (908 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 909/982] net/smc: fix UAF on lgr list traversal in smcr_port_err() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 911/982] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails Greg Kroah-Hartman
` (78 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ginger Li, Tung Nguyen,
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ginger Li <ginger.jzllee@gmail.com>
[ Upstream commit 8e1937fed6738460554ec123c64839e2445e7d53 ]
mon_timeout() evaluates dom_size(mon->peer_cnt) before it takes mon->lock,
while mon->peer_cnt is updated under that lock by tipc_mon_add_peer() and
tipc_mon_remove_peer(). The value can therefore be stale, and the decision
whether the local domain has to be recomputed can be based on an outdated
member count.
Read mon->peer_cnt inside the write_lock_bh(&mon->lock) protected region.
Fixes: 35c55c9877f8 ("tipc: add neighbor monitoring framework")
Signed-off-by: Ginger Li <ginger.jzllee@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260922080909.21123-1-ginger.jzllee@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/tipc/monitor.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/tipc/monitor.c b/net/tipc/monitor.c
index 23efd35adaa35..e96dcdaa93894 100644
--- a/net/tipc/monitor.c
+++ b/net/tipc/monitor.c
@@ -632,9 +632,10 @@ static void mon_timeout(struct timer_list *t)
{
struct tipc_monitor *mon = from_timer(mon, t, timer);
struct tipc_peer *self;
- int best_member_cnt = dom_size(mon->peer_cnt) - 1;
+ int best_member_cnt;
write_lock_bh(&mon->lock);
+ best_member_cnt = dom_size(mon->peer_cnt) - 1;
self = mon->self;
if (self && (best_member_cnt != self->applied)) {
mon_update_local_domain(mon);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 911/982] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (909 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 910/982] tipc: Fix a data race on mon->peer_cnt in mon_timeout() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 912/982] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure Greg Kroah-Hartman
` (77 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Heiko Stuebner,
Lorenzo Bianconi, Coia Prant, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Coia Prant <coiaprant@gmail.com>
[ Upstream commit 8db67bb6a1fffa4df68fbbc22e39943aeeff9178 ]
gmac_clk_enable() enables the bulk clocks first and then the optional
PHY clock. If clk_prepare_enable() on the PHY clock fails, the function
returns without rolling back the bulk clocks, and bsp_priv->clk_enabled
stays false, so the later gmac_clk_enable(bsp_priv, false) becomes a
no-op and the bulk clock references are leaked.
Add the missing clk_bulk_disable_unprepare() on that failure path.
Fixes: ea449f7fa0bf ("net: ethernet: stmmac: dwmac-rk: rework optional clock handling")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Heiko Stuebner <heiko@sntech.de>
Acked-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Signed-off-by: Coia Prant <coiaprant@gmail.com>
Link: https://patch.msgid.link/20260923123713.3137146-1-coiaprant@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c b/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
index 34198d95c68b9..3c2e1548b8c67 100644
--- a/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
+++ b/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
@@ -1553,8 +1553,11 @@ static int gmac_clk_enable(struct rk_priv_data *bsp_priv, bool enable)
return ret;
ret = clk_prepare_enable(bsp_priv->clk_phy);
- if (ret)
+ if (ret) {
+ clk_bulk_disable_unprepare(bsp_priv->num_clks,
+ bsp_priv->clks);
return ret;
+ }
if (bsp_priv->ops && bsp_priv->ops->set_clock_selection)
bsp_priv->ops->set_clock_selection(bsp_priv,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 912/982] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (910 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 911/982] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 913/982] bridge: check llc_mac_hdr_init() return value in br_send_bpdu() Greg Kroah-Hartman
` (76 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 72f9dd522f8d6c5a00be9695c7bb74631eb5069e ]
In llc_conn_ac_resend_i_xxx_x_set_0_or_send_rr(), if llc_mac_hdr_init()
fails, kfree_skb(skb) is called instead of kfree_skb(nskb). This leaks
the newly allocated nskb, reads from the freed skb via LLC_I_GET_NR(pdu),
and double-frees skb when llc_conn_state_process() drops its reference.
In llc_sap_action_send_xid_r() and llc_sap_action_send_test_r(), nskb is
leaked if llc_mac_hdr_init() returns an error.
Free nskb in all three error paths.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/llc/llc_c_ac.c | 2 +-
net/llc/llc_s_ac.c | 4 ++++
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/llc/llc_c_ac.c b/net/llc/llc_c_ac.c
index 40ca3c1e42a2e..5c8483f63ebbc 100644
--- a/net/llc/llc_c_ac.c
+++ b/net/llc/llc_c_ac.c
@@ -443,7 +443,7 @@ int llc_conn_ac_resend_i_xxx_x_set_0_or_send_rr(struct sock *sk,
if (likely(!rc))
llc_conn_send_pdu(sk, nskb);
else
- kfree_skb(skb);
+ kfree_skb(nskb);
}
if (rc) {
nr = LLC_I_GET_NR(pdu);
diff --git a/net/llc/llc_s_ac.c b/net/llc/llc_s_ac.c
index 7a0cae9a81114..cc6fb29a9510a 100644
--- a/net/llc/llc_s_ac.c
+++ b/net/llc/llc_s_ac.c
@@ -127,6 +127,8 @@ int llc_sap_action_send_xid_r(struct llc_sap *sap, struct sk_buff *skb)
rc = llc_mac_hdr_init(nskb, mac_sa, mac_da);
if (likely(!rc))
rc = dev_queue_xmit(nskb);
+ else
+ kfree_skb(nskb);
out:
return rc;
}
@@ -176,6 +178,8 @@ int llc_sap_action_send_test_r(struct llc_sap *sap, struct sk_buff *skb)
rc = llc_mac_hdr_init(nskb, mac_sa, mac_da);
if (likely(!rc))
rc = dev_queue_xmit(nskb);
+ else
+ kfree_skb(nskb);
out:
return rc;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 913/982] bridge: check llc_mac_hdr_init() return value in br_send_bpdu()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (911 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 912/982] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 914/982] net/sched: sch_teql: fix shadowed err in __teql_resolve() Greg Kroah-Hartman
` (75 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Aleksandrov, Ido Schimmel,
bridge, Eric Dumazet, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ac704ff08e511c87643799c385f55ecd69b85e03 ]
If llc_mac_hdr_init() fails (for instance if the port device type does
not support LLC or dev_hard_header() fails), br_send_bpdu() should drop
the skb instead of resetting the mac header to the LLC payload and
transmitting a malformed frame.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Nikolay Aleksandrov <razor@blackwall.org>
Cc: Ido Schimmel <idosch@nvidia.com>
Cc: bridge@lists.linux.dev
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260924082951.1599377-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_stp_bpdu.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/bridge/br_stp_bpdu.c b/net/bridge/br_stp_bpdu.c
index 0e4572f313307..1917d11411d72 100644
--- a/net/bridge/br_stp_bpdu.c
+++ b/net/bridge/br_stp_bpdu.c
@@ -52,7 +52,10 @@ static void br_send_bpdu(struct net_bridge_port *p,
LLC_SAP_BSPAN, LLC_PDU_CMD);
llc_pdu_init_as_ui_cmd(skb);
- llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr);
+ if (llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr)) {
+ kfree_skb(skb);
+ return;
+ }
skb_reset_mac_header(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 914/982] net/sched: sch_teql: fix shadowed err in __teql_resolve()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (912 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 913/982] bridge: check llc_mac_hdr_init() return value in br_send_bpdu() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 915/982] vlan: ensure sufficient headroom in vlan_dev_hard_header() Greg Kroah-Hartman
` (74 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jamal Hadi Salim, Jiri Pirko,
Eric Dumazet, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 907b978e82cb4c1c245fc2985bb27c5d5c88c8f6 ]
__teql_resolve() declares an inner 'int err;' inside the
'if (neigh_event_send(n, skb_res) == 0)' block, shadowing the outer
'int err = 0;'. As a result, a negative return from dev_hard_header()
is written to the inner variable and __teql_resolve() still returns 0.
Remove the shadowed variable and set the outer err to -EINVAL when
dev_hard_header() returns a negative error.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Jiri Pirko <jiri@resnulli.us>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-4-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_teql.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/net/sched/sch_teql.c b/net/sched/sch_teql.c
index ace524afdcf5c..a308d42c69f65 100644
--- a/net/sched/sch_teql.c
+++ b/net/sched/sch_teql.c
@@ -265,14 +265,11 @@ __teql_resolve(struct sk_buff *skb, struct sk_buff *skb_res,
}
if (neigh_event_send(n, skb_res) == 0) {
- int err;
char haddr[MAX_ADDR_LEN];
neigh_ha_snapshot(haddr, n, dev);
- err = dev_hard_header(skb, dev, ntohs(skb_protocol(skb, false)),
- haddr, NULL, skb->len);
-
- if (err < 0)
+ if (dev_hard_header(skb, dev, ntohs(skb_protocol(skb, false)),
+ haddr, NULL, skb->len) < 0)
err = -EINVAL;
} else {
err = (skb_res == NULL) ? -EAGAIN : 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 915/982] vlan: ensure sufficient headroom in vlan_dev_hard_header()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (913 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 914/982] net/sched: sch_teql: fix shadowed err in __teql_resolve() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 916/982] autofs: fix sbi->pipe file reference leak in autofs_kill_sb() Greg Kroah-Hartman
` (73 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zixuan Chai, Hangbin Liu,
Eric Dumazet, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit cd5dd68267c4238795fadaf02b3575ca3f8a6500 ]
Callers that only reserve ETH_HLEN or less (such as llc_alloc_frame()),
or skbs allocated before dynamic device/headroom changes (e.g. toggling
VLAN_FLAG_REORDER_HDR or bonding/team switching slaves), can reach
vlan_dev_hard_header() with insufficient headroom and trigger
skb_under_panic().
Use skb_cow_head() in vlan_dev_hard_header() when VLAN_FLAG_REORDER_HDR
is not set to ensure sufficient headroom for the VLAN header(s) and the
underlying device hard header.
Use READ_ONCE() to read dev->hard_header_len and dev->needed_headroom as
they can be updated concurrently under RTNL (e.g. in
vlan_transfer_features()) while vlan_dev_hard_header() runs locklessly on
the transmit path. Also avoid LL_RESERVED_SPACE(dev) here so that the
extra HH_DATA_MOD alignment padding does not trigger unnecessary
pskb_expand_head() reallocations on inner stacked VLAN devices after the
outer VLAN header has been pushed.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Zixuan Chai <petalzu987@gmail.com>
Closes: https://lore.kernel.org/netdev/cover.1789987105.git.petalzu987@gmail.com/
Link: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Hangbin Liu <liuhangbin@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/8021q/vlan_dev.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/8021q/vlan_dev.c b/net/8021q/vlan_dev.c
index c08228d488346..a703d7f09f502 100644
--- a/net/8021q/vlan_dev.c
+++ b/net/8021q/vlan_dev.c
@@ -53,6 +53,11 @@ static int vlan_dev_hard_header(struct sk_buff *skb, struct net_device *dev,
int rc;
if (!(vlan->flags & VLAN_FLAG_REORDER_HDR)) {
+ unsigned int hlen = READ_ONCE(dev->hard_header_len) +
+ READ_ONCE(dev->needed_headroom);
+
+ if (skb_cow_head(skb, hlen) < 0)
+ return -ENOMEM;
vhdr = skb_push(skb, VLAN_HLEN);
vlan_tci = vlan->vlan_id;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 916/982] autofs: fix sbi->pipe file reference leak in autofs_kill_sb()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (914 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 915/982] vlan: ensure sufficient headroom in vlan_dev_hard_header() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 917/982] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits Greg Kroah-Hartman
` (72 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng,
Christian Brauner (Amutable), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
[ Upstream commit aa5e44b29ffe4eaa08cc2237fd65bc2596bc023e ]
When autofs_fill_super() fails before clearing AUTOFS_SBI_CATATONIC (for
example, when find_get_pid() fails on an invalid pgrp mount option, or
when an fs_context is closed before mounting), deactivate_locked_super()
invokes autofs_kill_sb() -> autofs_catatonic_mode(sbi).
Because AUTOFS_SBI_CATATONIC is still set in sbi->flags,
autofs_catatonic_mode() returns early without calling fput(sbi->pipe),
permanently leaking the pipe struct file reference.
Explicitly release sbi->pipe in autofs_kill_sb() if it is still non-NULL
after autofs_catatonic_mode().
Fixes: ebc921ca9b92 ("autofs: copy autofs4 to autofs")
Signed-off-by: Hui Peng <benquike@gmail.com>
Link: https://patch.msgid.link/20260919204808.2812930-1-benquike@gmail.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/autofs/inode.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/autofs/inode.c b/fs/autofs/inode.c
index affa70360b1f8..47356259a1a68 100644
--- a/fs/autofs/inode.c
+++ b/fs/autofs/inode.c
@@ -50,6 +50,10 @@ void autofs_kill_sb(struct super_block *sb)
if (sbi) {
/* Free wait queues, close pipe */
autofs_catatonic_mode(sbi);
+ if (sbi->pipe) {
+ fput(sbi->pipe);
+ sbi->pipe = NULL;
+ }
put_pid(sbi->oz_pgrp);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 917/982] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (915 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 916/982] autofs: fix sbi->pipe file reference leak in autofs_kill_sb() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 918/982] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED Greg Kroah-Hartman
` (71 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
Peter Zijlstra (Intel), Ingo Molnar, Dapeng Mi, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit cec38d5c098a350dcf084d345025136ade7e6d1e ]
When reinstating PEBS counters into PERF_GLOBAL_CTRL for a KVM guest, mask
the value with perf's desired/original PERF_GLOBAL_CTRL value to ensure
KVM doesn't unintentionally set reserved bits in PERF_GLOBAL_CTRL. E.g.
if the guest's PEBS_ENABLE value had bit 63, "Enable Precise Store", set,
then using the raw guest PEBS value would propagate bit 63 to the guest's
PERF_GLOBAL_CTRL value (which thankfully would be a failed VM-Entry, not
a VMX Abort).
The only reason this bug isn't reachable is because KVM doesn't support
"Enable Precise Store" (which is probably a KVM bug?), i.e. bit 63 can't
be set in kvm_pmu->pebs_enable and thus not in arr[pebs_enable].guest. In
other words, this _should_ be a glorified NOP in the current code base.
Fixes: c59a1f106f5c ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-2-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index b1bc81bef4083..ac4e149af80c2 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -4190,7 +4190,7 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
arr[pebs_enable].guest &= ~kvm_pmu->host_cross_mapped_mask;
arr[global_ctrl].guest &= ~kvm_pmu->host_cross_mapped_mask;
/* Set hw GLOBAL_CTRL bits for PEBS counter when it runs for guest */
- arr[global_ctrl].guest |= arr[pebs_enable].guest;
+ arr[global_ctrl].guest |= intel_ctrl & arr[pebs_enable].guest;
}
return arr;
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 918/982] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (916 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 917/982] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 919/982] mptcp: return sk_wait_data() errors from recvmsg() Greg Kroah-Hartman
` (70 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
Peter Zijlstra (Intel), Ingo Molnar, Dapeng Mi, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 4b64dbdc5861477f148e13d1ed127e7fe7182e4f ]
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit,
*never* insert an entry for PEBS_ENABLED if the CPU properly isolates PEBS
events, in which case disabling counters via PERF_GLOBAL_CTRL is sufficient
to prevent unwanted PEBS events in the guest (or host). Because perf loads
PEBS_ENABLE with the unfiltered cpu_hw_events.pebs_enabled, i.e. with both
host and guest masks, there is no need to load different values for the
guest versus host, perf+KVM can and should simply control which counters
are enabled/disabled via PERF_GLOBAL_CTRL.
Avoiding touching PEBS_ENABLED "fixes" a bug where PEBS_ENABLED can end up
with "stuck" bits if a PEBS event is throttled between generating the list
and actually entering the guest (Intel CPUs can't arbtitrarily block NMIs).
Fixes in quotes because leaving PEBS_ENABLED as-is doesn't fix the
underlying problem of perf (via PMIs) being able to modify state after the
perf<=>KVM handoff.
But not writing PEBS_ENABLED is desirable no matter what, as stating the
obvious, leaving PEBS_ENABLED as-is avoids three MSR writes on every VMX
transition: one each on entry/exit, and one more explicit WRMSR to zero
PEBS_ENABLED before VM-Entry (KVM assumes the only reason PEBS_ENABLED is
in the load list is if the CPU lacks PEBS isolation and thus needs a
quiescent period).
Opportunistically add comments to (better) explain the rules for generating
the set of PEBS counters that will be active while the guest is running,
along with a FIXME for the suspected hack-a-fix where perf disables guest
PEBS if _any_ PEBS event is configured to count in the host (commit
854250329c02 ("KVM: x86/pmu: Disable guest PEBS temporarily in two rare
situations") doesn't explain the motivation, at all).
Fixes: c59a1f106f5c ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-3-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 55 ++++++++++++++++++++++++------------
1 file changed, 37 insertions(+), 18 deletions(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index ac4e149af80c2..4ddd967a9d3d1 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -4123,12 +4123,15 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
struct kvm_pmu *kvm_pmu = (struct kvm_pmu *)data;
u64 intel_ctrl = hybrid(cpuc->pmu, intel_ctrl);
u64 pebs_mask = cpuc->pebs_enabled & x86_pmu.pebs_capable;
- int global_ctrl, pebs_enable;
+ u64 guest_pebs_mask;
+ int global_ctrl;
/*
* In addition to obeying exclude_guest/exclude_host, remove bits being
* used for PEBS when running a guest, because PEBS writes to virtual
- * addresses (not physical addresses).
+ * addresses (not physical addresses). If the guest wants to utilize
+ * PEBS, and PEBS can be safely enabled in the guest, bits for the guest's
+ * PEBS-enabled counters will be OR'd back in as appropriate.
*/
*nr = 0;
global_ctrl = (*nr)++;
@@ -4175,24 +4178,40 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
};
}
- pebs_enable = (*nr)++;
- arr[pebs_enable] = (struct perf_guest_switch_msr){
- .msr = MSR_IA32_PEBS_ENABLE,
- .host = cpuc->pebs_enabled & ~cpuc->intel_ctrl_guest_mask,
- .guest = pebs_mask & ~cpuc->intel_ctrl_host_mask & kvm_pmu->pebs_enable,
- };
+ /*
+ * Restrict guest PEBS events to counters that (a) perf supports, (b)
+ * the guest wants to use for PEBS, (c) are not excluded from counting
+ * in the guest, and (d) _are_ excluded from counting in the host.
+ */
+ guest_pebs_mask = pebs_mask & intel_ctrl & kvm_pmu->pebs_enable &
+ ~cpuc->intel_ctrl_host_mask &
+ cpuc->intel_ctrl_guest_mask;
- if (arr[pebs_enable].host) {
- /* Disable guest PEBS if host PEBS is enabled. */
- arr[pebs_enable].guest = 0;
- } else {
- /* Disable guest PEBS thoroughly for cross-mapped PEBS counters. */
- arr[pebs_enable].guest &= ~kvm_pmu->host_cross_mapped_mask;
- arr[global_ctrl].guest &= ~kvm_pmu->host_cross_mapped_mask;
- /* Set hw GLOBAL_CTRL bits for PEBS counter when it runs for guest */
- arr[global_ctrl].guest |= intel_ctrl & arr[pebs_enable].guest;
- }
+ /*
+ * Disable counters where the guest PMC is different than the host PMC
+ * being used on behalf of the guest, as the PEBS record includes
+ * PERF_GLOBAL_STATUS, i.e. the guest will see overflow status for the
+ * wrong counter(s).
+ */
+ guest_pebs_mask &= ~kvm_pmu->host_cross_mapped_mask;
+
+ /*
+ * FIXME: Allow guest and host usage of PEBS events to co-exist instead
+ * of disabling guest PEBS entirely if the host is using PEBS.
+ * What exactly goes wrong if guest and host are using PEBS is
+ * unknown.
+ */
+ if (pebs_mask & ~cpuc->intel_ctrl_guest_mask)
+ guest_pebs_mask = 0;
+ /*
+ * Do NOT mess with PEBS_ENABLED. As above, disabling counters via
+ * PERF_GLOBAL_CTRL is sufficient, and loading a stale PEBS_ENABLED,
+ * e.g. on VM-Exit, can put the system in a bad state. Simply enable
+ * counters in PERF_GLOBAL_CTRL, as perf load PEBS_ENABLED with the
+ * full value, i.e. perf *also* relies on PERF_GLOBAL_CTRL.
+ */
+ arr[global_ctrl].guest |= guest_pebs_mask;
return arr;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 919/982] mptcp: return sk_wait_data() errors from recvmsg()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (917 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 918/982] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 920/982] rculist: add list_splice_rcu() for private lists Greg Kroah-Hartman
` (69 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Matthieu Baerts (NGI0),
Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
[ Upstream commit 60404266ef3e0a1cd8f7a164060e0c83efb72f4b ]
Commit 581302298524 ("mptcp: error out earlier on disconnect") made
mptcp_recvmsg() stop when sk_wait_data() returns an error. The error is
stored in err, but the function then jumps to a path which returns
copied. When no data was copied, recvmsg() therefore returns zero and
reports a false EOF.
Store the result in copied, which is the value returned by the function.
This also keeps the usual partial-read result when data was copied before
the error.
A recvmsg() blocked in one thread reproduces the issue when another
thread disconnects the same MPTCP socket with connect(AF_UNSPEC).
Before this change recvmsg() returns zero; afterwards it returns -EPIPE.
Fixes: 581302298524 ("mptcp: error out earlier on disconnect")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260913-b4-send-mptcp-recv-error-v1-1-4eaa3684a8b8@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mptcp/protocol.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index ca78add7670d9..10be901f8c026 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -2320,7 +2320,7 @@ static int mptcp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
mptcp_cleanup_rbuf(msk, copied);
err = sk_wait_data(sk, &timeo, NULL);
if (err < 0) {
- err = copied ? : err;
+ copied = copied ? : err;
goto out_err;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 920/982] rculist: add list_splice_rcu() for private lists
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (918 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 919/982] mptcp: return sk_wait_data() errors from recvmsg() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 921/982] netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase Greg Kroah-Hartman
` (68 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul E. McKenney, Pablo Neira Ayuso,
Benjamin Robin (Schneider Electric), Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit f902877b635551513729bdf9a8d1422c4aab7741 ]
This patch adds a helper function, list_splice_rcu(), to safely splice
a private (non-RCU-protected) list into an RCU-protected list.
The function ensures that only the pointer visible to RCU readers
(prev->next) is updated using rcu_assign_pointer(), while the rest of
the list manipulations are performed with regular assignments, as the
source list is private and not visible to concurrent RCU readers.
This is useful for moving elements from a private list into a global
RCU-protected list, ensuring safe publication for RCU readers.
Subsystems with some sort of batching mechanism from userspace can
benefit from this new function.
The function __list_splice_rcu() has been added for clarity and to
follow the same pattern as in the existing list_splice*() interfaces,
where there is a check to ensure that the list to splice is not
empty. Note that __list_splice_rcu() has no documentation for this
reason.
Reviewed-by: Paul E. McKenney <paulmck@kernel.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/rculist.h | 29 +++++++++++++++++++++++++++++
1 file changed, 29 insertions(+)
diff --git a/include/linux/rculist.h b/include/linux/rculist.h
index d29740be4833e..ad37c0584c23b 100644
--- a/include/linux/rculist.h
+++ b/include/linux/rculist.h
@@ -204,6 +204,35 @@ static inline void list_replace_rcu(struct list_head *old,
old->prev = LIST_POISON2;
}
+static inline void __list_splice_rcu(struct list_head *list,
+ struct list_head *prev,
+ struct list_head *next)
+{
+ struct list_head *first = list->next;
+ struct list_head *last = list->prev;
+
+ last->next = next;
+ first->prev = prev;
+ next->prev = last;
+ rcu_assign_pointer(list_next_rcu(prev), first);
+}
+
+/**
+ * list_splice_rcu - splice a non-RCU list into an RCU-protected list,
+ * designed for stacks.
+ * @list: the non RCU-protected list to splice
+ * @head: the place in the existing RCU-protected list to splice
+ *
+ * The list pointed to by @head can be RCU-read traversed concurrently with
+ * this function.
+ */
+static inline void list_splice_rcu(struct list_head *list,
+ struct list_head *head)
+{
+ if (!list_empty(list))
+ __list_splice_rcu(list, head, head->next);
+}
+
/**
* __list_splice_init_rcu - join an RCU-protected list into an existing list.
* @list: the RCU-protected list to splice
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 921/982] netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (919 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 920/982] rculist: add list_splice_rcu() for private lists Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 922/982] af_unix: Drop all SCM attributes for SOCKMAP Greg Kroah-Hartman
` (67 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin,
Benjamin Robin (Schneider Electric)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit a6134e62dba2ea4f760b29d5226907f447c92400 ]
Publish new hooks in the list into the basechain/flowtable using
splice_list_rcu() to ensure netlink dump list traversal via rcu is safe
while concurrent ruleset update is going on.
Fixes: 78d9f48f7f44 ("netfilter: nf_tables: add devices to existing flowtable")
Fixes: b9703ed44ffb ("netfilter: nf_tables: support for adding new devices to an existing netdev chain")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_tables_api.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index 96b0638c220a7..a373a0969e994 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -9995,8 +9995,8 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
nft_trans_flowtable(trans),
&nft_trans_flowtable_hooks(trans),
NFT_MSG_NEWFLOWTABLE);
- list_splice(&nft_trans_flowtable_hooks(trans),
- &nft_trans_flowtable(trans)->hook_list);
+ list_splice_rcu(&nft_trans_flowtable_hooks(trans),
+ &nft_trans_flowtable(trans)->hook_list);
} else {
nft_clear(net, nft_trans_flowtable(trans));
nf_tables_flowtable_notify(&trans->ctx,
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 922/982] af_unix: Drop all SCM attributes for SOCKMAP.
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (920 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 921/982] netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 923/982] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
` (66 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xingyu Jin, Kuniyuki Iwashima,
Jakub Kicinski, Lee Jones, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 965dc93481d1b80d341bdd16c27b16fe197175ee ]
SOCKMAP can hide inflight fd from AF_UNIX GC.
When a socket in SOCKMAP receives skb with inflight fd,
sk_psock_verdict_data_ready() looks up the mapped socket and
enqueue skb to its psock->ingress_skb.
Since neither the old nor the new GC can inspect the psock
queue, the hidden skb leaks the inflight sockets. Note that
this cannot be detected via kmemleak because inflight sockets
are linked to a global list.
In addition, SOCKMAP redirect breaks the Tarjan-based GC's
assumption that unix_edge.successor is always alive, which
is no longer true once skb is redirected, resulting in
use-after-free below. [0]
Moreover, SOCKMAP does not call scm_stat_del() properly,
so unix_show_fdinfo() could report an incorrect fd count.
sk_msg_recvmsg() does not support any SCM attributes in the
first place.
Let's drop all SCM attributes before passing skb to the
SOCKMAP layer.
[0]:
BUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)
Read of size 8 at addr ffff888125362670 by task kworker/56:1/496
CPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
Workqueue: events sk_psock_backlog
Call Trace:
<TASK>
dump_stack_lvl (lib/dump_stack.c:122)
print_report (mm/kasan/report.c:379)
kasan_report (mm/kasan/report.c:597)
unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)
unix_destroy_fpl (net/unix/garbage.c:317)
unix_destruct_scm (./include/net/scm.h:80 ./include/net/scm.h:86 net/unix/af_unix.c:1976)
sk_psock_backlog (./include/linux/skbuff.h:?)
process_scheduled_works (kernel/workqueue.c:?)
worker_thread (kernel/workqueue.c:?)
kthread (kernel/kthread.c:438)
ret_from_fork (arch/x86/kernel/process.c:164)
ret_from_fork_asm (arch/x86/entry/entry_64.S:258)
</TASK>
Allocated by task 955:
kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78)
__kasan_slab_alloc (mm/kasan/common.c:369)
kmem_cache_alloc_noprof (mm/slub.c:4539)
sk_prot_alloc (net/core/sock.c:2240)
sk_alloc (net/core/sock.c:2301)
unix_create1 (net/unix/af_unix.c:1099)
unix_create (net/unix/af_unix.c:1169)
__sock_create (net/socket.c:1606)
__sys_socketpair (net/socket.c:1811)
__x64_sys_socketpair (net/socket.c:1863 net/socket.c:1860 net/socket.c:1860)
do_syscall_64 (arch/x86/entry/syscall_64.c:?)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
Freed by task 496:
kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78)
kasan_save_free_info (mm/kasan/generic.c:587)
__kasan_slab_free (mm/kasan/common.c:287)
kmem_cache_free (mm/slub.c:6165)
__sk_destruct (net/core/sock.c:2282 net/core/sock.c:2384)
sk_psock_destroy (./include/net/sock.h:?)
process_scheduled_works (kernel/workqueue.c:?)
worker_thread (kernel/workqueue.c:?)
kthread (kernel/kthread.c:438)
ret_from_fork (arch/x86/kernel/process.c:164)
ret_from_fork_asm (arch/x86/entry/entry_64.S:258)
Fixes: c63829182c37 ("af_unix: Implement ->psock_update_sk_prot()")
Fixes: 77462de14a43 ("af_unix: Add read_sock for stream socket types")
Reported-by: Xingyu Jin <xingyuj@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260415184830.3988432-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[Lee: Drop skb_orphan() from unix_destruct_scm() and omit the
unix_stream_read_skb() / unix_dgram_read_skb() hunks as
69bbe2bcbe8c and d92fbaccd09a are not present]
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/unix/af_unix.c | 42 ++++++++++++++++++++++++++++++++----------
1 file changed, 32 insertions(+), 10 deletions(-)
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index a4fa3c279a465..b8824d374b52f 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1784,16 +1784,19 @@ static void unix_peek_fds(struct scm_cookie *scm, struct sk_buff *skb)
static void unix_destruct_scm(struct sk_buff *skb)
{
- struct scm_cookie scm;
+ struct scm_cookie scm = {};
+
+ swap(scm.pid, UNIXCB(skb).pid);
- memset(&scm, 0, sizeof(scm));
- scm.pid = UNIXCB(skb).pid;
if (UNIXCB(skb).fp)
unix_detach_fds(&scm, skb);
- /* Alas, it calls VFS */
- /* So fscking what? fput() had been SMP-safe since the last Summer */
scm_destroy(&scm);
+}
+
+static void unix_wfree(struct sk_buff *skb)
+{
+ unix_destruct_scm(skb);
sock_wfree(skb);
}
@@ -1809,7 +1812,7 @@ static int unix_scm_to_skb(struct scm_cookie *scm, struct sk_buff *skb, bool sen
if (scm->fp && send_fds)
err = unix_attach_fds(scm, skb);
- skb->destructor = unix_destruct_scm;
+ skb->destructor = unix_wfree;
return err;
}
@@ -1886,6 +1889,13 @@ static void scm_stat_del(struct sock *sk, struct sk_buff *skb)
}
}
+static void unix_orphan_scm(struct sock *sk, struct sk_buff *skb)
+{
+ scm_stat_del(sk, skb);
+ unix_destruct_scm(skb);
+ skb->destructor = sock_wfree;
+}
+
/*
* Send AF_UNIX data.
*/
@@ -2557,10 +2567,16 @@ static int unix_read_skb(struct sock *sk, skb_read_actor_t recv_actor)
int err;
mutex_lock(&u->iolock);
+
skb = skb_recv_datagram(sk, MSG_DONTWAIT, &err);
- mutex_unlock(&u->iolock);
- if (!skb)
+ if (!skb) {
+ mutex_unlock(&u->iolock);
return err;
+ }
+
+ unix_orphan_scm(sk, skb);
+
+ mutex_unlock(&u->iolock);
return recv_actor(sk, skb);
}
@@ -2716,10 +2732,16 @@ static int unix_stream_read_skb(struct sock *sk, skb_read_actor_t recv_actor)
return -ENOTCONN;
mutex_lock(&u->iolock);
+
skb = skb_recv_datagram(sk, MSG_DONTWAIT, &err);
- mutex_unlock(&u->iolock);
- if (!skb)
+ if (!skb) {
+ mutex_unlock(&u->iolock);
return err;
+ }
+
+ unix_orphan_scm(sk, skb);
+
+ mutex_unlock(&u->iolock);
#if IS_ENABLED(CONFIG_AF_UNIX_OOB)
if (unlikely(skb == READ_ONCE(u->oob_skb))) {
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 923/982] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (921 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 922/982] af_unix: Drop all SCM attributes for SOCKMAP Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 924/982] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 Greg Kroah-Hartman
` (65 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guanglei Zhu, Jakub Kicinski,
Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit c7ead9704249d57d4693a04697e3bbd285138fa9 upstream.
The netif index carried in the DPMAIF PIT header is five bits wide,
but ccmni_inst[] only has room for NIC_DEV_MAX (21) entries.
t7xx_ccmni_recv_skb() indexes the array without a bounds check, so
indexes 21 to 31 read past it. The out-of-bounds value lands in the
callback table that follows the array, which is never NULL, so the
existing !ccmni check does not catch it and the driver dereferences
whatever sits there as a struct t7xx_ccmni.
Drop the skb when the index is out of range.
Fixes: 05d19bf500f8 ("net: wwan: t7xx: Add WWAN network interface")
Cc: stable@vger.kernel.org
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Link: https://patch.msgid.link/20260911021734.1396599-3-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wwan/t7xx/t7xx_netdev.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/wwan/t7xx/t7xx_netdev.c b/drivers/net/wwan/t7xx/t7xx_netdev.c
index f71d3bc3b237c..2eea9997b8fda 100644
--- a/drivers/net/wwan/t7xx/t7xx_netdev.c
+++ b/drivers/net/wwan/t7xx/t7xx_netdev.c
@@ -321,6 +321,10 @@ static void t7xx_ccmni_recv_skb(struct t7xx_pci_dev *t7xx_dev, struct sk_buff *s
skb_cb = T7XX_SKB_CB(skb);
netif_id = skb_cb->netif_idx;
+ if (netif_id >= NIC_DEV_MAX) {
+ dev_kfree_skb(skb);
+ return;
+ }
ccmni = t7xx_dev->ccmni_ctlb->ccmni_inst[netif_id];
if (!ccmni) {
dev_kfree_skb(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 924/982] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (922 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 923/982] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 925/982] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow Greg Kroah-Hartman
` (64 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikael Etienne, Arthur Husband,
Alvin Lim, Mario Limonciello, Bjorn Helgaas, David Laight,
John Smith, Lennert Buytenhek, Niklas Cassel, Roland Waltersson
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
commit 4fde448225123442c5796f54b7a4400e2d3cbaf6 upstream.
Multiple users report data corruption during 64-bit DMA transfers on
systems with AMD NBIO 7.7 and 7.11 controllers.
This occurs when BIOS enables AMD "enhanced atomic operations" on PCIe Root
Ports. When enhanced atomics are enabled, any 64-bit DMA access may be
corrupted.
Disable enhanced atomics using SMN for NBIO 7.7 and 7.11 based models.
Reported-by: Mikael Etienne <mikael1022bzh@gmail.com>
Closes: https://lore.kernel.org/178789300872.392066.15963676631650361573@gmail.com/
Reported-by: Arthur Husband <artmoty@gmail.com>
Closes: https://lore.kernel.org/20260406222335.379935-1-artmoty@gmail.com/
Reported-by: Alvin Lim <alvinwylim@gmail.com>
Closes: https://lore.kernel.org/20260621100844.1224301-1-alvinwylim@gmail.com/
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
[bhelgaas: commit log, s/IOVA/DMA/ in comment]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org
Cc: David Laight <david.laight.linux@gmail.com>
Cc: John Smith <imjohnsmith4000@gmail.com>
Cc: Lennert Buytenhek <kernel@wantstofly.org>
Cc: Niklas Cassel <cassel@kernel.org>
Cc: Roland Waltersson <roland.waltersson@netinsight.net>
Link: https://patch.msgid.link/20260908190600.226485-2-mario.limonciello@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/pci/fixup.c | 99 +++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 99 insertions(+)
--- a/arch/x86/pci/fixup.c
+++ b/arch/x86/pci/fixup.c
@@ -844,4 +844,103 @@ static void quirk_clear_strap_no_soft_re
}
}
DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x15b8, quirk_clear_strap_no_soft_reset_dev2_f0);
+
+/*
+ * Enhanced atomic operations can cause corruption with 64-bit DMA
+ * on these devices.
+ */
+#define RX_ENH_ATOMIC_EN BIT(8)
+
+static const u32 nbio_7_7_pcie_smn_addrs[] = {
+ 0x111401d0,
+ 0x111411d0,
+ 0x111421d0,
+ 0x111431d0,
+ 0x111441d0,
+ 0x112401d0,
+ 0x112411d0,
+ 0x112421d0,
+ 0x112431d0,
+ 0x112441d0,
+ 0x112451d0,
+ 0x113401d0,
+ 0x114401d0,
+};
+
+static const u32 nbio_7_11_pcie_smn_addrs[] = {
+ 0x112401d0,
+ 0x112411d0,
+ 0x112421d0,
+ 0x112431d0,
+ 0x112441d0,
+ 0x112451d0,
+ 0x113401d0,
+ 0x113411d0,
+ 0x113421d0,
+ 0x113431d0,
+ 0x113441d0,
+ 0x113451d0,
+};
+
+static void quirk_amd_nbio_enhanced_atomic(struct pci_dev *host_bridge,
+ const u32 *smn_addrs,
+ size_t nr_smn_addrs)
+{
+ bool changed = false;
+ size_t i;
+ u32 data;
+ int ret;
+
+ for (i = 0; i < nr_smn_addrs; i++) {
+ ret = amd_smn_read(0, smn_addrs[i], &data);
+ if (ret)
+ continue;
+ if (!(data & RX_ENH_ATOMIC_EN))
+ continue;
+ data = data & ~RX_ENH_ATOMIC_EN;
+ ret = amd_smn_write(0, smn_addrs[i], data);
+ if (ret)
+ continue;
+ if (changed)
+ continue;
+ ret = amd_smn_read(0, smn_addrs[i], &data);
+ if (ret)
+ continue;
+ if (data & RX_ENH_ATOMIC_EN)
+ continue;
+ changed = true;
+ }
+
+ if (changed)
+ pci_info(host_bridge, "enhanced atomics disabled\n");
+}
+
+static void quirk_amd_nbio_7_7_disable_enhanced_atomic(struct pci_dev *dev)
+{
+ quirk_amd_nbio_enhanced_atomic(dev, nbio_7_7_pcie_smn_addrs,
+ ARRAY_SIZE(nbio_7_7_pcie_smn_addrs));
+}
+
+static void quirk_amd_nbio_7_11_disable_enhanced_atomic(struct pci_dev *dev)
+{
+ quirk_amd_nbio_enhanced_atomic(dev, nbio_7_11_pcie_smn_addrs,
+ ARRAY_SIZE(nbio_7_11_pcie_smn_addrs));
+}
+
+/* Phoenix, Hawk Point (NBIO 7.7) */
+DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x14E8,
+ quirk_amd_nbio_7_7_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_RESUME(PCI_VENDOR_ID_AMD, 0x14E8,
+ quirk_amd_nbio_7_7_disable_enhanced_atomic);
+
+/* Strix, Krackan, Strix Halo (NBIO 7.11) */
+DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x1507,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_RESUME(PCI_VENDOR_ID_AMD, 0x1507,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x1122,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_RESUME(PCI_VENDOR_ID_AMD, 0x1122,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+
#endif
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 925/982] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (923 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 924/982] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 926/982] sctp: discard the rest of the packet on a stale-cookie error Greg Kroah-Hartman
` (63 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Burton, Eric Dumazet,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit 99cc2a62e07a44a22254d7beca9ef1f8ad886d0d upstream.
Commit 48a5fe38772b ("tipc: fix bc_ackers underflow on duplicate
GRP_ACK_MSG") rejected duplicate/stale ACKs in tipc_group_proto_rcv()
by returning early when less_eq(acked, m->bc_acked).
However, that check remains incomplete in two ways:
1. When grp->bc_ackers is zero (e.g. on a quiet group, when replicast
ACKs were not requested, or after all expected members have already
acknowledged), an unexpected GRP_ACK_MSG with acked > m->bc_acked
passes less_eq() and unconditionally decrements grp->bc_ackers.
Because bc_ackers is a u16, this wraps to 65535, causing
tipc_group_bc_cong() to permanently report congestion and blocking
all future group broadcasts on the socket.
2. During an active broadcast round (grp->bc_ackers > 0), the sender
transmits packet S and advances grp->bc_snd_nxt to S + 1. Receivers
increment their expected counter to S + 1 upon consuming packet S,
so the only valid ACK value for the current round is strictly
acked == grp->bc_snd_nxt.
However, tipc_group_update_bc_members() initializes each member's
m->bc_acked to prev = grp->bc_snd_nxt - 1 (S - 1 before increment).
This leaves a 2-sequence gap (S - 1 to S + 1) in sequence space.
An incoming ACK is therefore neither rejected as duplicate nor
prevented from decrementing grp->bc_ackers if an unexpected or stale
value (such as S) is received. A member sending acked = S followed
by acked = S + 1 could decrement grp->bc_ackers twice in the same
round, prematurely clearing bc_ackers or underflowing it.
Fix this by:
- Dropping GRP_ACK_MSG immediately if grp->bc_ackers is zero.
- Requiring acked == grp->bc_snd_nxt and rejecting duplicates where
m->bc_acked == acked. Because replicast broadcast rounds are strictly
sequential, only grp->bc_snd_nxt can be acknowledged, and each member
can acknowledge at most once per round.
Note that a related pre-existing issue in tipc_group_delete_member()
(where grp->bc_ackers decrementing to zero upon member departure does
not restore *grp->open or trigger a socket wakeup) will be addressed
in a separate patch.
Fixes: 48a5fe38772b ("tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG")
Fixes: 2f487712b893 ("tipc: guarantee that group broadcast doesn't bypass group unicast")
Reported-by: James Burton <jamesburton@meta.com>
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260913044233.193927-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/tipc/group.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/tipc/group.c
+++ b/net/tipc/group.c
@@ -797,10 +797,10 @@ void tipc_group_proto_rcv(struct tipc_gr
tipc_group_open(m, usr_wakeup);
return;
case GRP_ACK_MSG:
- if (!m)
+ if (!m || !grp->bc_ackers)
return;
acked = msg_grp_bc_acked(hdr);
- if (less_eq(acked, m->bc_acked))
+ if (acked != grp->bc_snd_nxt || m->bc_acked == acked)
return;
m->bc_acked = acked;
if (--grp->bc_ackers)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 926/982] sctp: discard the rest of the packet on a stale-cookie error
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (924 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 925/982] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 927/982] af_packet: fix integer overflow in prb_calc_retire_blk_tmo() Greg Kroah-Hartman
` (62 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xin Long, TencentOS Corvus AI,
Aohan Mei, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit 4498467a8af06cfa3d71cb04bd7c4170dec8f449 upstream.
When an association is in COOKIE-ECHOED state and the peer sends a
bundled [ERROR(Stale Cookie)][DATA] packet from one of its non-primary
addresses, processing the ERROR chunk takes the non-fatal stale-cookie
retry path sctp_sf_do_5_2_6_stale(), which queues
SCTP_CMD_DEL_NON_PRIMARY while keeping the association alive.
sctp_cmd_del_non_primary() removes every non-primary transport -
including the very transport this packet arrived on, which is still
referenced by the receive lookup and shared by all chunks of the
packet via chunk->transport.
sctp_assoc_rm_peer() does redirect asoc->peer.last_data_from away from
the removed transport, but right afterwards the bundled DATA chunk
makes sctp_assoc_bh_rcv() re-register
asoc->peer.last_data_from = chunk->transport unconditionally, undoing
the redirection with the just-removed transport.
Once the packet is done, the receive reference is dropped and the
transport is RCU-freed, while the surviving association keeps the
dangling last_data_from. A later FWD-TSN (or the delayed SACK timer)
makes sctp_gen_sack() dereference it (->param_flags and friends), and
sctp_make_sack()/sctp_outq_select_transport() may write to the freed
object and link it into the live transport list. This is a
use-after-free triggerable by any malicious SCTP peer (or a local
unprivileged user acting as one) with no capabilities required:
BUG: KASAN: slab-use-after-free in sctp_do_sm+0x498a/0x5660
Read of size 4 at addr ffff88800e1e356c by task poc/115
Call Trace: sctp_do_sm <- sctp_assoc_bh_rcv <- sctp_inq_push <-
sctp_rcv <- ip_protocol_deliver_rcu <- ip_rcv
Allocated: sctp_transport_new <- sctp_assoc_add_peer <-
sctp_process_init (INIT-ACK processing)
Freed: kfree <- sctp_transport_destroy_rcu <- rcu_core
(call_rcu queued by sctp_transport_put at end of sctp_rcv)
The buggy address is located 364 bytes inside of freed 1024-byte
region [ffff88800e1e3400, ffff88800e1e3800), cache kmalloc-1k
Note that commit 03a9d10ecf71 ("sctp: drop a chunk if its transport
was removed") only covers the window between the receive lookup and
the chunk processing (e.g. an ASCONF DEL-IP racing the socket backlog);
here the transport is removed *while* the packet is being processed,
by an earlier chunk of the same packet, so the drop in sctp_inq_push()
does not reach this path. Verified with the bundled [ERROR(Stale
Cookie)][DATA] + FWD-TSN reproducer: the KASAN report above still
fires with that commit applied, and is gone with this patch on top.
Fix it by discarding the rest of the packet on this path, as suggested
by Xin. After the stale-cookie ERROR has sent the association back to
COOKIE-WAIT and removed the non-primary transports, the remaining
chunks of the packet can only run against the restarted handshake
while referencing the removed arrival transport through
chunk->transport: besides the last_data_from registration above,
sctp_cmd_setup_t2() and the sctp_make_*() reply builders would also
copy that pointer into association-lifetime state that
sctp_assoc_rm_peer() has already sanitized. Let the peer retransmit
them, in line with what sctp_inq_push() does for chunks whose
transport was removed before processing.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Suggested-by: Xin Long <lucien.xin@gmail.com>
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260921093707.1432184-1-ljp1205831794@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sctp/sm_statefuns.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -2625,6 +2625,8 @@ static enum sctp_disposition sctp_sf_do_
sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(reply));
+ sctp_add_cmd_sf(commands, SCTP_CMD_DISCARD_PACKET, SCTP_NULL());
+
return SCTP_DISPOSITION_CONSUME;
nomem:
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 927/982] af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (925 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 926/982] sctp: discard the rest of the packet on a stale-cookie error Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 928/982] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT Greg Kroah-Hartman
` (61 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dairui Zhang, Willem de Bruijn,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dairui Zhang <zhangdairui@gmail.com>
commit 56d82862a0a243ac14ba11b6d7b57ddc2d064b95 upstream.
prb_calc_retire_blk_tmo() computes in 32-bit int arithmetic:
mbits = (blk_size_in_bytes * 8) / (1024 * 1024);
If I'm reading the validation right, tp_block_size is user
controlled and packet_set_ring() only rejects values that are <= 0
as int or not page aligned, so a 256MiB block goes right through
(and alloc_one_pg_vec_page() even has a vzalloc fallback for it).
0x10000000 * 8 wraps to INT_MIN, and on a NIC reporting 1 Gbps
(div == 1) the function ends up returning -2047.
The condition is actually (8 * size) mod 2^32 >= 2^31 && div == 1,
so the trigger set is [256,512), [768,1024), [1280,1536) and
[1792,2048) MiB. Other sizes wrap to non-negative values and faster
links divide the unsigned value back below 2^31, which is why this
doesn't blow up for everyone.
What makes it fatal is what happens next in init_prb_bdqc():
p1->interval_ktime = ms_to_ktime(prb_calc_retire_blk_tmo(...));
hrtimer_start(&p1->retire_blk_timer, p1->interval_ktime,
HRTIMER_MODE_REL_SOFT);
A negative relative timeout expires immediately. The callback
unconditionally returns HRTIMER_RESTART, and hrtimer_forward() turns
the negative interval into hrtimer_resolution:
if (interval < hrtimer_resolution)
interval = hrtimer_resolution;
So the SOFT timer re-fires at the maximum rate forever, holding
sk_receive_queue.lock each pass. One CPU spins in softirq until the
socket is closed. Repeat with more rings and the machine is gone.
The overflow itself is ancient - it was introduced together with
TPACKET_V3 in f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer
implementation."). Its effect prior to f7460d2989fa ("net:
af_packet: Use hrtimer to do the retire operation", v6.18) was not
as clear-cut, though: the return value was stored into an unsigned
short retire_blk_tov, so a negative result was truncated, and a
0-jiffy delay loop could be programmed as well. Neither is nearly
as detrimental as the immediate maximum-rate spin the hrtimer
conversion turned it into.
(Unrelated to CVE-2019-20812 - that one was the ethtool failure path
returning 0, which now returns DEFAULT_PRB_RETIRE_TOV.)
Reproducer, needs CAP_NET_RAW (a --network host container has it by
default) and a 1 Gbps NIC (QEMU e1000 works):
int fd = socket(AF_PACKET, SOCK_RAW, htons(ETH_P_ALL));
bind(fd, ...);
int v = TPACKET_V3;
setsockopt(fd, SOL_PACKET, PACKET_VERSION, &v, sizeof(v));
struct tpacket_req3 req = {
.tp_block_size = 0x10000000,
.tp_block_nr = 1,
.tp_frame_size = 2048,
.tp_frame_nr = 0x10000000 / 2048,
.tp_retire_blk_tov = 0,
};
setsockopt(fd, SOL_PACKET, PACKET_RX_RING, &req, sizeof(req));
Compute in 64 bits instead. The operands are already bounded by the
existing validation, so nothing else changes. If you'd prefer a
different fix, just say so and I'll respin.
Fixes: f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer implementation.")
Cc: stable@vger.kernel.org
Signed-off-by: Dairui Zhang <zhangdairui@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260923050101.1510064-1-zhangdairui@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/af_packet.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -638,7 +638,7 @@ static int prb_calc_retire_blk_tmo(struc
return DEFAULT_PRB_RETIRE_TOV;
div = ecmd.base.speed / 1000;
- mbits = (blk_size_in_bytes * 8) / (1024 * 1024);
+ mbits = (u64)blk_size_in_bytes * 8 / (1024 * 1024);
if (div)
mbits /= div;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 928/982] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (926 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 927/982] af_packet: fix integer overflow in prb_calc_retire_blk_tmo() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 929/982] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes Greg Kroah-Hartman
` (60 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Peng, Hangbin Liu,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit d22609f3d13fc5baacd92c222731b03c593401db upstream.
Commit 7a9bc9e3f423 ("fou: Don't allow 0 for FOU_ATTR_IPPROTO.") added
NLA_POLICY_MIN(NLA_U8, 1) to fou_nl_policy[FOU_ATTR_IPPROTO], which
rejects an explicitly supplied FOU_ATTR_IPPROTO == 0 attribute with
-ERANGE.
However, FOU_ATTR_IPPROTO is an optional netlink attribute. When a user
sends FOU_CMD_ADD with FOU_ATTR_TYPE set to FOU_ENCAP_DIRECT and omits
FOU_ATTR_IPPROTO entirely, nla_policy validation succeeds and
parse_nl_config() leaves cfg->protocol as 0 (from memset(cfg, 0,
sizeof(*cfg))). fou_create() then creates a FOU_ENCAP_DIRECT socket with
fou->protocol == 0.
In fou_udp_recv(), returning -fou->protocol to udp_queue_rcv_one_skb()
triggers IP protocol resubmission when fou->protocol > 0, whereas
returning 0 tells the UDP tunnel layer that the skb was consumed without
freeing it. When fou->protocol == 0, every packet received on the socket
returns 0 from fou_udp_recv() and leaks the sk_buff.
Reject FOU_ENCAP_DIRECT when !cfg->protocol in fou_create() so that
creating a direct encapsulation port without FOU_ATTR_IPPROTO fails with
-EINVAL while leaving FOU_CMD_DEL and FOU_CMD_GET (which share
parse_nl_config()) unaffected.
Tested in QEMU against Linux 7.3.0-rc3 by sending a FOU_CMD_ADD Generic
Netlink request with FOU_ATTR_PORT = 5555 and FOU_ATTR_TYPE =
FOU_ENCAP_DIRECT while omitting FOU_ATTR_IPPROTO. On the unfixed kernel,
FOU_CMD_ADD succeeds (err = 0), FOU_CMD_GET reports fou->type = 1 and
fou->protocol = 0, and sending 4000 UDP packets to 127.0.0.1:5555 leaks
all 4000 sk_buffs (SUnreclaim in /proc/meminfo grows from 41456 kB to
59008 kB, +17552 kB); with this patch applied, FOU_CMD_ADD is rejected
with -EINVAL (-22).
Fixes: 23461551c006 ("fou: Support for foo-over-udp RX path")
Fixes: 7a9bc9e3f423 ("fou: Don't allow 0 for FOU_ATTR_IPPROTO.")
Cc: stable@vger.kernel.org
Signed-off-by: Hui Peng <benquike@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260921045920.1613098-1-benquike@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/fou_core.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/net/ipv4/fou_core.c
+++ b/net/ipv4/fou_core.c
@@ -607,6 +607,10 @@ static int fou_create(struct net *net, s
/* Initial for fou type */
switch (cfg->type) {
case FOU_ENCAP_DIRECT:
+ if (!cfg->protocol) {
+ err = -EINVAL;
+ goto error;
+ }
tunnel_cfg.encap_rcv = fou_udp_recv;
tunnel_cfg.gro_receive = fou_gro_receive;
tunnel_cfg.gro_complete = fou_gro_complete;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 929/982] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (927 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 928/982] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 930/982] workqueue: Fix NULL current_pwq deref in flush dependency check Greg Kroah-Hartman
` (59 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tejun Heo, Roman Gushchin,
Patrick Lu (Anthropic), Jan Kara, Christian Brauner (Amutable)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrick Lu (Anthropic) <perf.patrick.lu@gmail.com>
commit f6988c90671e83db79df1b7b9d6fdb0e5947fd84 upstream.
cleanup_offline_cgwb() prepares at most WB_MAX_INODES_PER_ISW inodes
per call and is called again until the dying wb is drained, but every
call walks wb->b_attached and then wb->b_dirty_time from the same end.
Inodes already prepared (they stay on the list with I_WB_SWITCH set
until the switch worker runs) and inodes that cannot be switched
(I_FREEING, I_WILL_FREE, !SB_ACTIVE, DAX, already on the target wb)
stay where they are, so each pass rescans a growing run of them under
wb->list_lock and a full drain is quadratic in the number of inodes on
the list. With ~17M inodes attached to one dying cgwb we saw this end
in soft lockups, with CPUs reported stuck for 21-48s.
Walk both lists from the oldest end and move every scanned inode to
the newest end, so the next pass starts where the previous one stopped
and the drain becomes linear. b_attached is unordered, so nobody sees
the reorder there. b_dirty_time is ordered by dirtied_when, but the
oldest unscanned inode stays at the end move_expired_inodes() picks
from, sync takes the whole list regardless of order, and prepared
inodes leave the list as soon as the switch work runs and get a new
dirtied_time_when on the new wb anyway, so the only inodes left out of
order are the ones that can never switch (DAX), and only on the dying
wb.
Fixes: c22d70a162d3 ("writeback, cgroup: release dying cgwbs by switching attached inodes")
Cc: stable@vger.kernel.org
Acked-by: Tejun Heo <tj@kernel.org>
Acked-by: Roman Gushchin <roman.gushchin@linux.dev>
Signed-off-by: Patrick Lu (Anthropic) <perf.patrick.lu@gmail.com>
Link: https://patch.msgid.link/20260911-wb-cgwb-rotate-v2-1-a9ab253a1295@gmail.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/fs-writeback.c | 25 ++++++++++++++++++++-----
1 file changed, 20 insertions(+), 5 deletions(-)
--- a/fs/fs-writeback.c
+++ b/fs/fs-writeback.c
@@ -667,19 +667,34 @@ static bool isw_prepare_wbs_switch(struc
struct inode_switch_wbs_context *isw,
struct list_head *list, int *nr)
{
- struct inode *inode;
+ struct inode *inode, *tmp;
+ LIST_HEAD(scanned);
+ bool full = false;
+
+ /*
+ * Walk from the oldest end and move scanned inodes to the newest
+ * end, so the next scan resumes at unscanned inodes instead of
+ * re-walking an ever-growing run of prepared and skipped ones.
+ * For b_dirty_time this keeps the oldest unscanned inode at the
+ * end move_expired_inodes() picks from; b_attached is unordered.
+ */
+ list_for_each_entry_safe_reverse(inode, tmp, list, i_io_list) {
+ list_move(&inode->i_io_list, &scanned);
- list_for_each_entry(inode, list, i_io_list) {
if (!inode_prepare_wbs_switch(inode, new_wb))
continue;
isw->inodes[*nr] = inode;
(*nr)++;
- if (*nr >= WB_MAX_INODES_PER_ISW - 1)
- return true;
+ if (*nr >= WB_MAX_INODES_PER_ISW - 1) {
+ full = true;
+ break;
+ }
}
- return false;
+ list_splice(&scanned, list);
+
+ return full;
}
/**
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 930/982] workqueue: Fix NULL current_pwq deref in flush dependency check
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (928 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 929/982] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 931/982] writeback: report a Tasks-RCU quiescent state per cgwb drain pass Greg Kroah-Hartman
` (58 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pavankumar Kondeti, Tejun Heo
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
commit db6365ced4d5855e321f772b240c0e473bcfcdd5 upstream.
check_flush_dependency() uses current_wq_worker() to determine whether
the caller is a workqueue worker and then dereferences worker->current_pwq
to test whether the current workqueue is WQ_MEM_RECLAIM.
current_wq_worker() only means that %current has PF_WQ_WORKER set. A
kworker can reach check_flush_dependency() while it is not executing a
work item. One such path is worker_thread() acting as the pool manager,
where create_worker() does GFP_KERNEL allocation and the allocation path
invokes the OOM notifier. In that state worker->current_pwq is NULL
because current_pwq is set only by process_one_work() and cleared again
after the work function returns.
[ 416.760634][ T375] Call trace:
[ 416.760638][ T375] check_flush_dependency+0x80/0x120 (P)
[ 416.760648][ T375] __flush_work+0x98/0x224
[ 416.760657][ T375] flush_work+0x30/0x44
[ 416.760665][ T375] ...
[ 416.760710][ T375] blocking_notifier_call_chain+0x58/0xa0
[ 416.760719][ T375] out_of_memory+0xb4/0x458
[ 416.760730][ T375] __alloc_pages_may_oom+0x11c/0x1a8
[ 416.760739][ T375] __alloc_pages_slowpath+0x314/0x46c
[ 416.760746][ T375] __alloc_frozen_pages_noprof+0x110/0x1a4
[ 416.760753][ T375] new_slab+0x12c/0x484
[ 416.760759][ T375] ___slab_alloc+0x7a8/0xc7c
[ 416.760765][ T375] __slab_alloc+0x74/0xd8
[ 416.760772][ T375] __kmalloc_cache_node_noprof+0x2ac/0x304
[ 416.760779][ T375] alloc_worker+0x28/0x60
[ 416.760785][ T375] create_worker+0x4c/0x20c
[ 416.760790][ T375] worker_thread+0xe8/0x2b8
[ 416.760796][ T375] kthread+0x1a8/0x200
[ 416.760805][ T375] ret_from_fork+0x10/0x20
Guard the WQ_MEM_RECLAIM-worker warning with worker->current_pwq. If the
kworker is not currently executing a work item, there is no current
workqueue to diagnose with that warning. The PF_MEMALLOC warning is left
unchanged so explicit reclaim context flushing a !WQ_MEM_RECLAIM target
is still reported.
Fixes: fca839c00a12 ("workqueue: warn if memory reclaim tries to flush !WQ_MEM_RECLAIM workqueue")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/workqueue.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -2628,7 +2628,7 @@ static void check_flush_dependency(struc
WARN_ONCE(current->flags & PF_MEMALLOC,
"workqueue: PF_MEMALLOC task %d(%s) is flushing !WQ_MEM_RECLAIM %s:%ps",
current->pid, current->comm, target_wq->name, target_func);
- WARN_ONCE(worker && ((worker->current_pwq->wq->flags &
+ WARN_ONCE(worker && worker->current_pwq && ((worker->current_pwq->wq->flags &
(WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM),
"workqueue: WQ_MEM_RECLAIM %s:%ps is flushing !WQ_MEM_RECLAIM %s:%ps",
worker->current_pwq->wq->name, worker->current_func,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 931/982] writeback: report a Tasks-RCU quiescent state per cgwb drain pass
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (929 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 930/982] workqueue: Fix NULL current_pwq deref in flush dependency check Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 932/982] fsl/fman: Fix clk reference leak in read_dts_node() Greg Kroah-Hartman
` (57 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Josef Bacik, Andrew Morton,
Tejun Heo, Roman Gushchin, Jan Kara, Lorenzo Stoakes (ARM),
David Hildenbrand, Dennis Zhou, Liam R. Howlett,
Matthew Wilcox (Oracle), Michal Hocko, Mike Rapoport,
Paul E . McKenney, Suren Baghdasaryan, Vlastimil Babka
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Josef Bacik <josef@toxicpanda.com>
commit 407a5d205179a4ab186571b0e16ec42725dc77bc upstream.
cleanup_offline_cgwbs_workfn() drains a dying cgwb by calling
cleanup_offline_cgwb() until it returns false, with a cond_resched()
between passes. On a CONFIG_PREEMPTION kernel that cond_resched() does
nothing: _cond_resched() is a plain "return 0", and under PREEMPT_DYNAMIC
the full and lazy modes disable it. Since commit 7dadeaa6e851 ("sched:
Further restrict the preemption modes") those are the only two models on
the architectures with PREEMPT_LAZY support, arm64 and x86 among them, so
the drain loop never reports a Tasks-RCU quiescent state.
A worker draining a cgwb with millions of attached inodes runs for
minutes. On a 6.18 arm64 host in lazy mode the cgwb worker drained one
dying cgroup's writeback domain for over 11 minutes. A BPF program unlink
(bpf_trampoline_unlink_prog -> bpf_trampoline_update ->
unregister_ftrace_direct -> ftrace_shutdown -> synchronize_rcu_tasks())
waited on that grace period while holding the trampoline mutex, 42 tasks
queued behind it in D state, and the hung task detector fired at 614 s and
panicked the host. Any BPF or ftrace detach during a long drain inherits
the drain's length.
Fix this by calling cond_resched_tasks_rcu_qs() so we do not stall out
anybody who calls sycnrhonize_rcu_tasks(). We put this in a do { } while
loop because if we have many small cgroups cleanup_offline_cgwb() will
return false and we will never call cond_resched_tasks_rcu_qs(), creating
the same problem.
Link: https://lore.kernel.org/20260909-cgwb-tasks-rcu-qs-v1-1-967a7754771f@toxicpanda.com
Fixes: c22d70a162d3 ("writeback, cgroup: release dying cgwbs by switching attached inodes")
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Link: https://lore.kernel.org/bpf/9d444098-7c03-4163-af12-bd0a79a51443@paulmck-laptop/
Assisted-by: LLM
Acked-by: Tejun Heo <tj@kernel.org>
Reviewed-by: Roman Gushchin <roman.gushchin@linux.dev>
Reviewed-by: Jan Kara <jack@suse.cz>
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dennis Zhou <dennis@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: "Paul E . McKenney" <paulmck@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/backing-dev.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/mm/backing-dev.c
+++ b/mm/backing-dev.c
@@ -694,8 +694,9 @@ static void cleanup_offline_cgwbs_workfn
continue;
spin_unlock_irq(&cgwb_lock);
- while (cleanup_offline_cgwb(wb))
- cond_resched();
+ do {
+ cond_resched_tasks_rcu_qs();
+ } while (cleanup_offline_cgwb(wb));
spin_lock_irq(&cgwb_lock);
wb_put(wb);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 932/982] fsl/fman: Fix clk reference leak in read_dts_node()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (930 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 931/982] writeback: report a Tasks-RCU quiescent state per cgwb drain pass Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 933/982] ipv6: do not let ipv6_find_hdr() return an offset past the packet end Greg Kroah-Hartman
` (56 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Simon Horman,
Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit a644f09b2090ad22a13fbcf9d141084f573108ef upstream.
of_clk_get() returns a clock with its reference count incremented, but
read_dts_node() only uses it to read the rate and never calls clk_put().
The clock is not stored anywhere, so the reference cannot be released
later either.
Release the clock once its rate has been read, which also covers the
error path taken when the rate is zero.
Fixes: 414fd46e7762 ("fsl/fman: Add FMan support")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260917110135.2148068-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/freescale/fman/fman.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/ethernet/freescale/fman/fman.c
+++ b/drivers/net/ethernet/freescale/fman/fman.c
@@ -2747,6 +2747,7 @@ static struct fman *read_dts_node(struct
}
clk_rate = clk_get_rate(clk);
+ clk_put(clk);
if (!clk_rate) {
err = -EINVAL;
dev_err(&of_dev->dev, "%s: Failed to determine FM%d clock rate\n",
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 933/982] ipv6: do not let ipv6_find_hdr() return an offset past the packet end
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (931 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 932/982] fsl/fman: Fix clk reference leak in read_dts_node() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 934/982] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST Greg Kroah-Hartman
` (55 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Eric Dumazet,
Norbert Szetei, Ido Schimmel, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
commit ee319bd3a0e976af5087cbe59ebc50a66f31d202 upstream.
ipv6_find_hdr() walks the extension header chain, skipping each header by
the length that header itself declares. ipv6_optlen() returns up to 2048,
and the skip is never checked against skb->len, so the offset stored in
*offset can point past the end of the packet.
openvswitch installs that offset as the transport header, and
update_ipv6_checksum() then reads and writes the transport checksum field
out of bounds:
BUG: KASAN: slab-use-after-free in inet_proto_csum_replace16+0x445/0x470
Read of size 2 at addr ffff88810b754b06 by task ovs_ipv6_oob/629
CPU: 4 UID: 1000 PID: 629 Comm: ovs_ipv6_oob Tainted: G N 7.3.0-rc3+ #348
Call Trace:
inet_proto_csum_replace16+0x445/0x470
set_ipv6_addr+0x3dd/0x460
do_execute_actions+0x6a3d/0x7c40
ovs_execute_actions+0xfd/0x480
ovs_packet_cmd_execute+0xc38/0xf20
genl_rcv_msg+0x59e/0x870
netlink_rcv_skb+0x18b/0x450
genl_rcv+0x2d/0x40
netlink_unicast+0x6bc/0xa20
The buggy address belongs to the object at ffff88810b754980
which belongs to the cache skbuff_small_head of size 704
The buggy address is located 390 bytes inside of
freed 704-byte region [ffff88810b754980, ffff88810b754c40)
Other callers use that offset too, so bound it here rather than in one
caller.
Reject a header whose declared length does not fit in the packet.
ipv6_find_hdr() already fails with -EBADMSG on a malformed chain, so this
adds no new failure mode.
Fixes: f8f626754ebe ("ipv6: Move ipv6_find_hdr() out of Netfilter code.")
Suggested-by: Ilya Maximets <i.maximets@ovn.org>
Suggested-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Link: https://patch.msgid.link/8F80BA1A-DDFD-432D-9075-242A3435FEB5@doyensec.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/exthdrs_core.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/ipv6/exthdrs_core.c
+++ b/net/ipv6/exthdrs_core.c
@@ -271,6 +271,9 @@ int ipv6_find_hdr(const struct sk_buff *
hdrlen = ipv6_optlen(hp);
if (!found) {
+ if (skb->len - start < hdrlen)
+ return -EBADMSG;
+
nexthdr = hp->nexthdr;
start += hdrlen;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 934/982] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (932 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 933/982] ipv6: do not let ipv6_find_hdr() return an offset past the packet end Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 935/982] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out() Greg Kroah-Hartman
` (54 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng, Hangbin Liu, Justin Iurman,
Andrea Mayer, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit 2d959c75c27f90e9ec489d18ce5ee6b852ad4741 upstream.
In seg6_genl_policy, SEG6_ATTR_DST is defined with .type = NLA_BINARY and
.len = sizeof(struct in6_addr). For NLA_BINARY, .len only enforces the
maximum payload length and permits shorter payloads (e.g., 0 bytes).
When seg6_genl_set_tunsrc() copies sizeof(struct in6_addr) bytes via
kmemdup(val, sizeof(*val), GFP_KERNEL), a short SEG6_ATTR_DST attribute
triggers a 16-byte out-of-bounds read past skb->tail into uninitialized
skb->head memory, which is stored in sdata->tun_src and leaked back to
userspace via SEG6_CMD_GET_TUNSRC.
Switch SEG6_ATTR_DST in seg6_genl_policy to
NLA_POLICY_EXACT_LEN(sizeof(struct in6_addr)) so that generic netlink
validation rejects any attribute whose length is not exactly
sizeof(struct in6_addr) with -ERANGE.
Tested in QEMU against Linux 7.3.0-rc3 by sending a SEG6_CMD_SET_TUNSRC
Generic Netlink message with a 0-byte SEG6_ATTR_DST attribute followed
by SEG6_CMD_GET_TUNSRC. On the unfixed kernel, SEG6_CMD_SET_TUNSRC
succeeds (err = 0) and SEG6_CMD_GET_TUNSRC leaks 16 bytes of
uninitialized kernel heap memory (tun_src =
836a61ecc4d25a1042a8d60411cfb378); with this patch applied,
SEG6_CMD_SET_TUNSRC is rejected by netlink policy validation with
-ERANGE (-34) and tun_src remains zeroed.
Fixes: 915d7e5e5930 ("ipv6: sr: add code base for control plane support of SR-IPv6")
Cc: stable@vger.kernel.org
Signed-off-by: Hui Peng <benquike@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Reviewed-by: Justin Iurman <justin.iurman@gmail.com>
Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Link: https://patch.msgid.link/20260921044025.1535982-1-benquike@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/seg6.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/ipv6/seg6.c
+++ b/net/ipv6/seg6.c
@@ -140,8 +140,8 @@ out:
static struct genl_family seg6_genl_family;
static const struct nla_policy seg6_genl_policy[SEG6_ATTR_MAX + 1] = {
- [SEG6_ATTR_DST] = { .type = NLA_BINARY,
- .len = sizeof(struct in6_addr) },
+ [SEG6_ATTR_DST] =
+ NLA_POLICY_EXACT_LEN(sizeof(struct in6_addr)),
[SEG6_ATTR_DSTLEN] = { .type = NLA_S32, },
[SEG6_ATTR_HMACKEYID] = { .type = NLA_U32, },
[SEG6_ATTR_SECRET] = { .type = NLA_BINARY, },
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 935/982] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (933 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 934/982] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 936/982] gpio: zynq: fix runtime PM leak on request error path Greg Kroah-Hartman
` (53 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Charles Keepax,
Bartosz Golaszewski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit e9d810279f84b30738f7790c0ed15f8dd5b9024a upstream.
Switching a persistent GPIO line from input to output acquires a
runtime PM reference on the parent device, but if the subsequent
regmap_update_bits() fails the reference is never dropped and no later
direction_in() can balance it since the direction was never changed.
Drop the reference on the update failure path.
Fixes: 27a49ed17e22 ("gpio: arizona: Add support for GPIOs that need to be maintained")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20260916094701.2007509-1-vulab@iscas.ac.cn
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-arizona.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpio/gpio-arizona.c
+++ b/drivers/gpio/gpio-arizona.c
@@ -118,8 +118,12 @@ static int arizona_gpio_direction_out(st
if (value)
value = ARIZONA_GPN_LVL;
- return regmap_update_bits(arizona->regmap, ARIZONA_GPIO1_CTRL + offset,
- ARIZONA_GPN_DIR | ARIZONA_GPN_LVL, value);
+ ret = regmap_update_bits(arizona->regmap, ARIZONA_GPIO1_CTRL + offset,
+ ARIZONA_GPN_DIR | ARIZONA_GPN_LVL, value);
+ if (ret < 0 && (val & ARIZONA_GPN_DIR) && persistent)
+ pm_runtime_put_autosuspend(chip->parent);
+
+ return ret;
}
static void arizona_gpio_set(struct gpio_chip *chip, unsigned offset, int value)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 936/982] gpio: zynq: fix runtime PM leak on request error path
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (934 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 935/982] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 937/982] llc: reserve device headroom for allocated frames Greg Kroah-Hartman
` (52 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ridham Khurana, Bartosz Golaszewski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ridham Khurana <khurana.ridham222@gmail.com>
commit e9438ab5328a177c9c0e5df87eb92a7162841e98 upstream.
pm_runtime_get_sync() leaves the usage counter incremented even when it
fails, and zynq_gpio_request() returns the error without dropping it.
gpiolib does not call ->free() when ->request() fails, so zynq_gpio_free(),
which holds the only matching pm_runtime_put(), never runs. The reference
is leaked and the controller can no longer runtime-suspend, so its clock
stays enabled.
Switch to pm_runtime_resume_and_get(), which only increments the usage
counter on success.
Fixes: 3242ba117e9b ("gpio: Add driver for Zynq GPIO controller")
Cc: stable@vger.kernel.org
Signed-off-by: Ridham Khurana <khurana.ridham222@gmail.com>
Link: https://patch.msgid.link/20260922092102.1053513-1-khurana.ridham222@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-zynq.c | 10 +---------
1 file changed, 1 insertion(+), 9 deletions(-)
--- a/drivers/gpio/gpio-zynq.c
+++ b/drivers/gpio/gpio-zynq.c
@@ -789,15 +789,7 @@ static int __maybe_unused zynq_gpio_runt
static int zynq_gpio_request(struct gpio_chip *chip, unsigned int offset)
{
- int ret;
-
- ret = pm_runtime_get_sync(chip->parent);
-
- /*
- * If the device is already active pm_runtime_get() will return 1 on
- * success, but gpio_request still needs to return 0.
- */
- return ret < 0 ? ret : 0;
+ return pm_runtime_resume_and_get(chip->parent);
}
static void zynq_gpio_free(struct gpio_chip *chip, unsigned int offset)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 937/982] llc: reserve device headroom for allocated frames
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (935 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 936/982] gpio: zynq: fix runtime PM leak on request error path Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 938/982] rds: ib: Clear the sg list when mapping an MR fails Greg Kroah-Hartman
` (51 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, VEGA, Zixuan Chai, Ren Wei,
Eric Dumazet, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zixuan Chai <petalzu987@gmail.com>
commit 72b5b9a28b996e09b8b5b944370c79851bb68f52 upstream.
llc_alloc_frame() reserves link-layer headroom using the device type.
This is insufficient for stacked Ethernet devices such as VLAN devices,
where vlan_dev_hard_header() pushes a VLAN header before the lower
device's Ethernet header. An LLC response on such a device can
therefore underflow skb headroom in eth_header().
Use LL_RESERVED_SPACE() to account for the device's actual required
headroom while preserving the existing LLC device-type check.
Fixes: bf9ae5386bca ("llc: use dev_hard_header")
Cc: stable@vger.kernel.org
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Zixuan Chai <petalzu987@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924012613.2533934-1-weir@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/llc/llc_sap.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/net/llc/llc_sap.c
+++ b/net/llc/llc_sap.c
@@ -25,12 +25,12 @@
#include <linux/llc.h>
#include <linux/slab.h>
-static int llc_mac_header_len(unsigned short devtype)
+static int llc_mac_header_len(struct net_device *dev)
{
- switch (devtype) {
+ switch (dev->type) {
case ARPHRD_ETHER:
case ARPHRD_LOOPBACK:
- return sizeof(struct ethhdr);
+ return LL_RESERVED_SPACE(dev);
}
return 0;
}
@@ -51,7 +51,7 @@ struct sk_buff *llc_alloc_frame(struct s
int hlen = type == LLC_PDU_TYPE_U ? 3 : 4;
struct sk_buff *skb;
- hlen += llc_mac_header_len(dev->type);
+ hlen += llc_mac_header_len(dev);
skb = alloc_skb(hlen + data_size, GFP_ATOMIC);
if (skb) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 938/982] rds: ib: Clear the sg list when mapping an MR fails
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (936 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 937/982] llc: reserve device headroom for allocated frames Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 939/982] drm/i915: fix incorrect RCU teardown order Greg Kroah-Hartman
` (50 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dongliang Qin, Allison Henderson,
Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dongliang Qin <cccccccccccc777777@gmail.com>
commit 58eb1b3325edac42dc6df72c80962bd53a3c8ca7 upstream.
rds_ib_map_frmr() stores the caller's scatterlist in the MR before DMA
mapping and registration can fail. On failure, __rds_rdma_map() unpins
the pages and frees the scatterlist, but rds_ib_free_frmr() can still
return the MR to the pool with the stale pointer set.
This leaves the pool with a dangling scatterlist and can lead to local
privilege escalation. KASAN detects the resulting use-after-free when the
MR is later torn down:
BUG: KASAN: slab-use-after-free in __rds_ib_teardown_mr
Read of size 8
Call Trace:
__rds_ib_teardown_mr
rds_ib_unreg_frmr
rds_ib_flush_mr_pool
rds_ib_flush_mrs
rds_free_mr
rds_setsockopt
Store the scatterlist in the MR only after DMA mapping succeeds. If DMA
mapping fails, return directly while the MR fields remain clear; the caller
keeps ownership of the scatterlist and its pinned pages. If a later
registration step fails, unmap the scatterlist and clear the MR fields
before returning.
Fixes: 1659185fb4d0 ("RDS: IB: Support Fastreg MR (FRMR) memory registration mode")
Cc: stable@vger.kernel.org
Signed-off-by: Dongliang Qin <cccccccccccc777777@gmail.com>
Reviewed-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260922031546.3874605-1-cccccccccccc777777@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/rds/ib_frmr.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
--- a/net/rds/ib_frmr.c
+++ b/net/rds/ib_frmr.c
@@ -204,19 +204,16 @@ static int rds_ib_map_frmr(struct rds_ib
*/
rds_ib_teardown_mr(ibmr);
- ibmr->sg = sg;
- ibmr->sg_len = sg_len;
- ibmr->sg_dma_len = 0;
frmr->sg_byte_len = 0;
- WARN_ON(ibmr->sg_dma_len);
- ibmr->sg_dma_len = ib_dma_map_sg(dev, ibmr->sg, ibmr->sg_len,
+ ibmr->sg_dma_len = ib_dma_map_sg(dev, sg, sg_len,
DMA_BIDIRECTIONAL);
if (unlikely(!ibmr->sg_dma_len)) {
pr_warn("RDS/IB: %s failed!\n", __func__);
return -EBUSY;
}
- frmr->sg_byte_len = 0;
+ ibmr->sg = sg;
+ ibmr->sg_len = sg_len;
frmr->dma_npages = 0;
len = 0;
@@ -264,6 +261,8 @@ out_unmap:
ib_dma_unmap_sg(rds_ibdev->dev, ibmr->sg, ibmr->sg_len,
DMA_BIDIRECTIONAL);
ibmr->sg_dma_len = 0;
+ ibmr->sg = NULL;
+ ibmr->sg_len = 0;
return ret;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 939/982] drm/i915: fix incorrect RCU teardown order
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (937 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 938/982] rds: ib: Clear the sg list when mapping an MR fails Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 940/982] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() Greg Kroah-Hartman
` (49 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian König, Tvrtko Ursulin,
Tvrtko Ursulin, Jani Nikula
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian König <ckoenig.leichtzumerken@gmail.com>
commit d2da6696e0c4e60414706e607029d0bb0330c67e upstream.
i915_gem_busy_ioctl uses dma_resv_for_each_fence_unlocked() to iterate
over the fences in an GEM object without holding a reference but only
the RCU read side lock.
What can happen here is that the GEM object is destroyed concurrently
while i915_gem_busy_ioctl is still running. This won't free the GEM
objects memory, but still drops all the dma_fence references.
Now when dma_resv_for_each_fence_unlocked() sees a destroyed dma_fence it
assumes that a new fence list was installed and re-starts the loop.
But in the case of a destroyed GEM object a new fence list is never
installed, only the old one freed and therefore the iteration never
finishes resulting in an endless loop.
The solution is to drop the fence references only after the RCU grace
period.
The fixes tag is not necessary the patch introducing the problem, but the
one making it so worse that we need to address it.
This problem was pointed out by Sashiko-bot.
Signed-off-by: Christian König <christian.koenig@amd.com>
Fixes: 912ff2ebd695 ("drm/i915: use the new iterator in i915_gem_busy_ioctl v2")
CC: stable@vger.kernel.org
Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Signed-off-by: Tvrtko Ursulin <tursulin@ursulin.net>
Link: https://lore.kernel.org/r/20260903113621.54660-1-christian.koenig@amd.com
(cherry picked from commit 5113479556025093bf8133bb2dcaa33be2d50921)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/gem/i915_gem_object.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/i915/gem/i915_gem_object.c
+++ b/drivers/gpu/drm/i915/gem/i915_gem_object.c
@@ -59,6 +59,7 @@ struct drm_i915_gem_object *i915_gem_obj
void i915_gem_object_free(struct drm_i915_gem_object *obj)
{
+ dma_resv_fini(&obj->base._resv);
return kmem_cache_free(slab_objects, obj);
}
@@ -110,7 +111,6 @@ void __i915_gem_object_fini(struct drm_i
{
mutex_destroy(&obj->mm.get_page.lock);
mutex_destroy(&obj->mm.get_dma_page.lock);
- dma_resv_fini(&obj->base._resv);
}
/**
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 940/982] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (938 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 939/982] drm/i915: fix incorrect RCU teardown order Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 941/982] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() Greg Kroah-Hartman
` (48 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit b4f7b4459b1b155e4c4977a6482b5df2cf08758c upstream.
amdgpu_vm_init() initializes vm->last_update, vm->last_unlocked and
vm->last_tlb_flush with references to the stub fence taken via
dma_fence_get_stub(). The error label at the end of the function
releases the last_unlocked and last_tlb_flush references with
dma_fence_put(), but the reference stored in vm->last_update is never
dropped, so whenever the page table root creation, the reservation of
the root BO or the PASID registration fails, the stub fence reference
leaks.
Drop the vm->last_update reference together with the other stub fence
references on the error path.
Fixes: 187916e6ed9d ("drm/amdgpu: install stub fence into potential unused fence pointers")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit e7979c84fc05a176bdf855ee664871b1648404c9)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -2135,6 +2135,7 @@ error_free_root:
vm->root.bo = NULL;
error_free_delayed:
+ dma_fence_put(vm->last_update);
dma_fence_put(vm->last_tlb_flush);
dma_fence_put(vm->last_unlocked);
drm_sched_entity_destroy(&vm->delayed);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 941/982] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (939 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 940/982] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 942/982] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() Greg Kroah-Hartman
` (47 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 2b86ab1bd6673c525adda88819d7658ba9e784ec upstream.
amdgpu_debugfs_test_ib_show() resumes the device with
pm_runtime_get_sync() before taking the reset domain semaphore with
down_write_killable(). If the write lock acquisition is interrupted,
the function returns without calling pm_runtime_put_autosuspend(),
leaking the runtime PM reference acquired for the device and keeping
the GPU awake.
Drop the runtime PM reference on the interrupted down_write_killable()
error path before returning.
Fixes: 6049db43d6dd ("drm/amdgpu: change reset lock from mutex to rw_semaphore")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit ec30a576c2d4c0364549e6c04218f50704ef56c8)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
@@ -1494,8 +1494,10 @@ static int amdgpu_debugfs_test_ib_show(s
/* Avoid accidently unparking the sched thread during GPU reset */
r = down_write_killable(&adev->reset_domain->sem);
- if (r)
+ if (r) {
+ pm_runtime_put_autosuspend(dev->dev);
return r;
+ }
/* hold on the scheduler */
for (i = 0; i < AMDGPU_MAX_RINGS; i++) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 942/982] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (940 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 941/982] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.1 943/982] drm/nouveau: fix autosuspend cleanup during teardown Greg Kroah-Hartman
` (46 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit aea841bc62a76242396610d22d8ff40c13065f64 upstream.
amdgpu_ring_init() initializes ring->vmid_wait with a reference to the
stub fence taken via dma_fence_get_stub(). When a later step of the
initialization fails, e.g. amdgpu_fence_driver_init_ring(), a writeback
slot allocation or the ring buffer allocation, the function returns an
error without releasing the stub fence reference and the reference is
leaked if the ring is torn down without amdgpu_ring_fini().
Move the stub fence assignment to the end of the initialization, right
before the ring is registered with the GPU scheduler, where no further
failure is possible. The stub fence is only consumed by command
submission handling in amdgpu_ids.c once the ring is up and running, so
nothing reads it during the error-prone part of the initialization.
Fixes: 48e9fbd1a284 ("drm/amdgpu: initialize the vmid_wait with the stub fence")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f2b96986851203e9c50ca0d13aaa3581ca3e8ebd)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c
@@ -201,7 +201,6 @@ int amdgpu_ring_init(struct amdgpu_devic
ring->adev = adev;
ring->num_hw_submission = sched_hw_submission;
ring->sched_score = sched_score;
- ring->vmid_wait = dma_fence_get_stub();
if (!ring->is_mes_queue) {
ring->idx = adev->num_rings++;
@@ -323,6 +322,7 @@ int amdgpu_ring_init(struct amdgpu_devic
ring->max_dw = max_dw;
ring->hw_prio = hw_prio;
+ ring->vmid_wait = dma_fence_get_stub();
if (!ring->no_scheduler && ring->funcs->type < AMDGPU_HW_IP_NUM) {
hw_ip = ring->funcs->type;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 943/982] drm/nouveau: fix autosuspend cleanup during teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (941 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 942/982] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 944/982] drm/nouveau: Fix bridge reference leak in nv1a_ram_new() Greg Kroah-Hartman
` (45 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Lyude Paul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit fefd9480ec361969f1a836df46326a1801062c26 upstream.
nouveau_drm_device_init() calls pm_runtime_use_autosuspend(), but
nouveau_drm_device_fini() does not call the matching
pm_runtime_dont_use_autosuspend().
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped and usage_count remains
unbalanced.
The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().
Add the missing pm_runtime_dont_use_autosuspend() call to the common
device teardown path.
This issue was found by manual code inspection.
Fixes: 5addcf0a5f0f ("nouveau: add runtime PM support (v0.9)")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260808134137.2864847-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_drm.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -658,6 +658,7 @@ nouveau_drm_device_fini(struct drm_devic
if (nouveau_pmops_runtime()) {
pm_runtime_get_sync(dev->dev);
pm_runtime_forbid(dev->dev);
+ pm_runtime_dont_use_autosuspend(dev->dev);
}
nouveau_led_fini(dev);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 944/982] drm/nouveau: Fix bridge reference leak in nv1a_ram_new()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (942 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 6.1 943/982] drm/nouveau: fix autosuspend cleanup during teardown Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 945/982] drm/nouveau: fix double-free in nvif_vmm_dtor Greg Kroah-Hartman
` (44 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Lyude Paul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 67b4411538c8341692548429d43256f25be99f7a upstream.
pci_get_domain_bus_and_slot() takes a reference to the PCI device,
which is never released once the memory size has been read from its
config space. Drop the reference before returning.
Fixes: 2fa6d6cdaf283c05 ("drm/nouveau: deprecate pci_get_bus_and_slot()")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260916180036.2090118-1-vulab@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c
@@ -51,6 +51,8 @@ nv1a_ram_new(struct nvkm_fb *fb, struct
mib = ((mem >> 4) & 127) + 1;
}
+ pci_dev_put(bridge);
+
return nvkm_ram_new_(&nv04_ram_func, fb, NVKM_RAM_TYPE_STOLEN,
mib * 1024 * 1024, pram);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 945/982] drm/nouveau: fix double-free in nvif_vmm_dtor
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (943 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 944/982] drm/nouveau: Fix bridge reference leak in nv1a_ram_new() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 946/982] drm/nouveau: Fix gem reference leak in validate_init() Greg Kroah-Hartman
` (43 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Lyude Paul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 97077ac87afe9e91ec074ef0be64454e7ccbf344 upstream.
On failure, nouveau_cli_init() calls nouveau_cli_fini() to tear
the client down. Then, nouveau_drm_open() also enters into its
cleanup path and calls nouveau_cli_fini() AGAIN. nouveau_cli_fini()
calls nouveau_vmm_fini():
void
nouveau_vmm_fini(struct nouveau_vmm *vmm)
{
nouveau_svmm_fini(&vmm->svmm);
nvif_vmm_dtor(&vmm->vmm);
vmm->cli = NULL;
}
Inside nvif_vmm_dtor(), vmm->page is freed unconditionally:
void
nvif_vmm_dtor(struct nvif_vmm *vmm)
{
kfree(vmm->page);
nvif_object_dtor(&vmm->object);
}
vmm->page is never cleared after being freed, so the second call of
nvif_vmm_dtor() will cause a double-free.
Found by fuzzing the nouveau driver with a modified Syzkaller:
BUG: KASAN: double-free in nvif_vmm_dtor+0x31/0x50 drivers/gpu/drm/nouveau/nvif/vmm.c:194
Free of addr ffff888010fcdc30 by task syz.0.173/2567
CPU: 1 UID: 0 PID: 2567 Comm: syz.0.173 Not tainted 7.2.0 #24 PREEMPT(lazy)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x95/0xe0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xcb/0x5a0 mm/kasan/report.c:482
kasan_report_invalid_free+0xaa/0xd0 mm/kasan/report.c:557
check_slab_allocation+0xe4/0x110 mm/kasan/common.c:235
kasan_slab_pre_free include/linux/kasan.h:199 [inline]
slab_free_hook mm/slub.c:2622 [inline]
slab_free mm/slub.c:6377 [inline]
kfree+0x192/0x590 mm/slub.c:6692
nvif_vmm_dtor+0x31/0x50 drivers/gpu/drm/nouveau/nvif/vmm.c:194
nouveau_vmm_fini+0x16/0x50 drivers/gpu/drm/nouveau/nouveau_vmm.c:127
nouveau_cli_fini+0x10e/0x210 drivers/gpu/drm/nouveau/nouveau_drm.c:225
nouveau_drm_open+0x24e/0x740 drivers/gpu/drm/nouveau/nouveau_drm.c:1255
drm_file_alloc+0x5f2/0xad0 drivers/gpu/drm/drm_file.c:176
drm_open_helper+0x1d7/0x4a0 drivers/gpu/drm/drm_file.c:335
drm_open+0x190/0x3d0 drivers/gpu/drm/drm_file.c:388
drm_stub_open+0x1f2/0x460 drivers/gpu/drm/drm_drv.c:1211
chrdev_open+0x21c/0x660 fs/char_dev.c:411
do_dentry_open+0x59d/0x12b0 fs/open.c:947
vfs_open+0x82/0x390 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2345/0x3420 fs/namei.c:4863
do_file_open+0x207/0x460 fs/namei.c:4892
do_sys_openat2+0xd1/0x1d0 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_sys_openat fs/open.c:1390 [inline]
__se_sys_openat fs/open.c:1385 [inline]
__x64_sys_openat+0x144/0x200 fs/open.c:1385
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fc6d687594d
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc6d5295008 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 00007fc6d6b06180 RCX: 00007fc6d687594d
RDX: 0000000000022501 RSI: 0000200000000000 RDI: ffffffffffffff9c
RBP: 00007fc6d691c303 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fc6d6b06218 R14: 00007fc6d6b06180 R15: 00007ffd9451d760
</TASK>
Allocated by task 2567 on cpu 1 at 163.593900s:
kasan_save_stack+0x24/0x50 mm/kasan/common.c:57
kasan_save_track+0x17/0x60 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__do_kmalloc_node mm/slub.c:5334 [inline]
__kmalloc_noprof+0x304/0x7c0 mm/slub.c:5359
_kmalloc_noprof include/linux/slab.h:992 [inline]
nvif_vmm_ctor+0x3c0/0x7e0 drivers/gpu/drm/nouveau/nvif/vmm.c:237
nouveau_vmm_init+0x40/0x90 drivers/gpu/drm/nouveau/nouveau_vmm.c:134
nouveau_cli_init+0x7b9/0xe10 drivers/gpu/drm/nouveau/nouveau_drm.c:293
nouveau_drm_open+0x236/0x740 drivers/gpu/drm/nouveau/nouveau_drm.c:1243
drm_file_alloc+0x5f2/0xad0 drivers/gpu/drm/drm_file.c:176
drm_open_helper+0x1d7/0x4a0 drivers/gpu/drm/drm_file.c:335
drm_open+0x190/0x3d0 drivers/gpu/drm/drm_file.c:388
drm_stub_open+0x1f2/0x460 drivers/gpu/drm/drm_drv.c:1211
chrdev_open+0x21c/0x660 fs/char_dev.c:411
do_dentry_open+0x59d/0x12b0 fs/open.c:947
vfs_open+0x82/0x390 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2345/0x3420 fs/namei.c:4863
do_file_open+0x207/0x460 fs/namei.c:4892
do_sys_openat2+0xd1/0x1d0 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_sys_openat fs/open.c:1390 [inline]
__se_sys_openat fs/open.c:1385 [inline]
__x64_sys_openat+0x144/0x200 fs/open.c:1385
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 2567 on cpu 1 at 163.601355s:
kasan_save_stack+0x24/0x50 mm/kasan/common.c:57
kasan_save_track+0x17/0x60 mm/kasan/common.c:78
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253 [inline]
__kasan_slab_free+0x61/0x80 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235 [inline]
slab_free_hook mm/slub.c:2677 [inline]
slab_free mm/slub.c:6377 [inline]
kfree+0x383/0x590 mm/slub.c:6692
nvif_vmm_dtor+0x31/0x50 drivers/gpu/drm/nouveau/nvif/vmm.c:194
nouveau_vmm_fini+0x16/0x50 drivers/gpu/drm/nouveau/nouveau_vmm.c:127
nouveau_cli_fini+0x10e/0x210 drivers/gpu/drm/nouveau/nouveau_drm.c:225
nouveau_cli_init+0x593/0xe10 drivers/gpu/drm/nouveau/nouveau_drm.c:324
nouveau_drm_open+0x236/0x740 drivers/gpu/drm/nouveau/nouveau_drm.c:1243
drm_file_alloc+0x5f2/0xad0 drivers/gpu/drm/drm_file.c:176
drm_open_helper+0x1d7/0x4a0 drivers/gpu/drm/drm_file.c:335
drm_open+0x190/0x3d0 drivers/gpu/drm/drm_file.c:388
drm_stub_open+0x1f2/0x460 drivers/gpu/drm/drm_drv.c:1211
chrdev_open+0x21c/0x660 fs/char_dev.c:411
do_dentry_open+0x59d/0x12b0 fs/open.c:947
vfs_open+0x82/0x390 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2345/0x3420 fs/namei.c:4863
do_file_open+0x207/0x460 fs/namei.c:4892
do_sys_openat2+0xd1/0x1d0 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_sys_openat fs/open.c:1390 [inline]
__se_sys_openat fs/open.c:1385 [inline]
__x64_sys_openat+0x144/0x200 fs/open.c:1385
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
The buggy address belongs to the object at ffff888010fcdc30
which belongs to the cache kmalloc-16 of size 16
The buggy address is located 0 bytes inside of
16-byte region [ffff888010fcdc30, ffff888010fcdc40)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10fcd
flags: 0x100000000000000(node=0|zone=1)
page_type: f5(slab)
raw: 0100000000000000 ffff88800d441640 dead000000000100 dead000000000122
raw: 0000000000000000 0000000000550055 00000000f5000000 0000000000000000
page dumped because: kasan: bad access detected
Memory state around the buggy address:
ffff888010fcdb00: fc fc 00 04 fc fc fc fc fa fb fc fc fc fc fa fb
ffff888010fcdb80: fc fc fc fc fa fb fc fc fc fc 00 07 fc fc fc fc
>ffff888010fcdc00: fa fb fc fc fc fc fa fb fc fc fc fc fa fb fc fc
^
ffff888010fcdc80: fc fc fa fb fc fc fc fc 00 04 fc fc fc fc fa fb
ffff888010fcdd00: fc fc fc fc 00 00 fc fc fc fc fa fb fc fc fc fc
Fix by removing the redundant teardown in nouveau_drm_open(),
since nouveau_cli_init() already does the cleanup work.
Also clear vmm->page after its freeing.
Cc: stable@vger.kernel.org
Fixes: 20d8a88e557a ("drm/nouveau: tidy up the client init/fini interfaces")
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: LLM
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/03BA723D9E5FF725+20260916103138.2651605-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_drm.c | 4 +---
drivers/gpu/drm/nouveau/nvif/vmm.c | 1 +
2 files changed, 2 insertions(+), 3 deletions(-)
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -1136,10 +1136,8 @@ nouveau_drm_open(struct drm_device *dev,
mutex_unlock(&drm->clients_lock);
done:
- if (ret && cli) {
- nouveau_cli_fini(cli);
+ if (ret && cli)
kfree(cli);
- }
pm_runtime_mark_last_busy(dev->dev);
pm_runtime_put_autosuspend(dev->dev);
--- a/drivers/gpu/drm/nouveau/nvif/vmm.c
+++ b/drivers/gpu/drm/nouveau/nvif/vmm.c
@@ -108,6 +108,7 @@ void
nvif_vmm_dtor(struct nvif_vmm *vmm)
{
kfree(vmm->page);
+ vmm->page = NULL;
nvif_object_dtor(&vmm->object);
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 946/982] drm/nouveau: Fix gem reference leak in validate_init()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (944 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 945/982] drm/nouveau: fix double-free in nvif_vmm_dtor Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 947/982] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked() Greg Kroah-Hartman
` (42 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Lyude Paul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 5ea72f7b7139b123713a7983448f910bc4514d9e upstream.
On the ttm_bo_reserve() failure and "vma not found" error paths, the
loop breaks without adding the looked-up object to any validate list,
so the reference taken by drm_gem_object_lookup() is never released;
validate_fini() only walks the spliced lists. Drop the reference
before breaking out on both paths.
Fixes: 19ca10d82e33bcfe ("drm/nouveau/gem: lookup VMAs for buffers referenced by pushbuf ioctl")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260916180202.2090231-1-vulab@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_gem.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/nouveau/nouveau_gem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_gem.c
@@ -471,6 +471,7 @@ retry:
if (unlikely(ret)) {
if (ret != -ERESTARTSYS)
NV_PRINTK(err, cli, "fail reserve\n");
+ drm_gem_object_put(gem);
break;
}
}
@@ -480,6 +481,7 @@ retry:
struct nouveau_vma *vma = nouveau_vma_find(nvbo, vmm);
if (!vma) {
NV_PRINTK(err, cli, "vma not found!\n");
+ drm_gem_object_put(gem);
ret = -EINVAL;
break;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 947/982] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (945 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 946/982] drm/nouveau: Fix gem reference leak in validate_init() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 948/982] HID: alps: fix use-after-free on input2 registration failure Greg Kroah-Hartman
` (41 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Lyude Paul
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 6a6870d3077faa501ca97760057ddca22b68418d upstream.
nouveau_bo_pin_locked() checks whether an already pinned BO is in a
memory domain compatible with a new pin request. When the domains are
incompatible, it sets -EBUSY but still calls ttm_bo_pin() before
returning.
Callers treat a failed nouveau_bo_pin() as not having acquired a new pin,
so the extra pin count is never decreased by a matching unpin.
This triggers the warning in ttm_bo_release():
WARN_ON_ONCE(bo->pin_count);
Found when fuzzing the nouveau driver with a modified Syzkaller:
WARNING: drivers/gpu/drm/ttm/ttm_bo.c:256 at ttm_bo_release+0x827/0x9e0 drivers/gpu/drm/ttm/ttm_bo.c:256, CPU#1: syz.3.24/2212
Modules linked in:
CPU: 1 UID: 0 PID: 2212 Comm: syz.3.24 Not tainted 7.2.0 #24 PREEMPT(lazy)
nouveau 0000:01:00.0: gsp:msg fn:103 len:0x40/0x20 res:0x19 resp:0x19
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:ttm_bo_release+0x827/0x9e0 drivers/gpu/drm/ttm/ttm_bo.c:256
Code: 02 00 0f 85 51 01 00 00 48 8b 7b 08 e8 d2 20 01 00 e9 80 fd ff ff e8 d8 15 c0 fe 90 0f 0b 90 e9 e1 f8 ff ff e8 ca 15 c0 fe 90 <0f> 0b 90 e9 a4 f8 ff ff e8 bc 15 c0 fe be 03 00 00 00 4c 89 e7 e8
msg: 00000000: 05 00 d0 c1 04 00 f0 f1 01 30 00 00 2d 90 00 00 .........0..-...
RSP: 0018:ffffc9000f5cf710 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff888018e5d2a8 RCX: ffffffff82bb1b36
RDX: ffff888017b68000 RSI: 0000000000000004 RDI: ffff888018e5d2a8
msg: 00000010: 19 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
RBP: ffff88801261c720 R08: 0000000000000001 R09: ffffed10031cba55
R10: ffff888018e5d2ab R11: 00000000000000f3 R12: ffff888018e5d290
R13: ffff888018e5d2d4 R14: ffff88801b219c18 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880e0f6f000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b31223ffc CR3: 0000000028e00005 CR4: 0000000000770ef0
PKRU: 80000000
Call Trace:
<TASK>
kref_put include/linux/kref.h:65 [inline]
ttm_bo_put drivers/gpu/drm/ttm/ttm_bo.c:325 [inline]
ttm_bo_fini+0x55/0x80 drivers/gpu/drm/ttm/ttm_bo.c:330
nouveau_gem_object_del+0xb2/0x1b0 drivers/gpu/drm/nouveau/nouveau_gem.c:90
drm_gem_object_free+0x5f/0x90 drivers/gpu/drm/drm_gem.c:1165
kref_put include/linux/kref.h:65 [inline]
__drm_gem_object_put include/drm/drm_gem.h:562 [inline]
drm_gem_object_put include/drm/drm_gem.h:575 [inline]
nouveau_abi16_chan_fini.constprop.0+0x44f/0x5a0 drivers/gpu/drm/nouveau/nouveau_abi16.c:195
nouveau 0000:01:00.0: syz.2.23[2209]: Unknown handle 0x00000000
nouveau_abi16_fini+0x1d0/0x340 drivers/gpu/drm/nouveau/nouveau_abi16.c:225
nouveau_drm_postclose+0x18b/0x3e0 drivers/gpu/drm/nouveau/nouveau_drm.c:1284
nouveau 0000:01:00.0: syz.2.23[2209]: validate_init
drm_file_free.part.0+0x6d6/0xb60 drivers/gpu/drm/drm_file.c:267
drm_file_free drivers/gpu/drm/drm_file.c:237 [inline]
drm_close_helper.isra.0+0x11a/0x160 drivers/gpu/drm/drm_file.c:290
drm_release+0x1ab/0x330 drivers/gpu/drm/drm_file.c:438
__fput+0x39c/0xa60 fs/file_table.c:512
nouveau 0000:01:00.0: syz.2.23[2209]: validate: -2
task_work_run+0x15a/0x230 kernel/task_work.c:233
exit_task_work include/linux/task_work.h:40 [inline]
do_exit+0x82b/0x25a0 kernel/exit.c:1009
do_group_exit+0xc2/0x280 kernel/exit.c:1152
get_signal+0x1d6e/0x1f30 kernel/signal.c:3046
arch_do_signal_or_restart+0x7d/0x6e0 arch/x86/kernel/signal.c:337
__exit_to_user_mode_loop kernel/entry/common.c:66 [inline]
exit_to_user_mode_loop+0xdf/0x440 kernel/entry/common.c:101
__exit_to_user_mode_prepare include/linux/irq-entry-common.h:207 [inline]
syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:230 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:318 [inline]
do_syscall_64+0x4f8/0x690 arch/x86/entry/syscall_64.c:100
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f12bac8594d
Code: Unable to access opcode bytes at 0x7f12bac85923.
RSP: 002b:00007f12b96e70d8 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
RAX: 0000000000000001 RBX: 00007f12baf15fa8 RCX: 00007f12bac8594d
RDX: 00000000000f4240 RSI: 0000000000000081 RDI: 00007f12baf15fac
RBP: 00007f12baf15fa0 R08: 00007f12baee8000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f12baf16038 R14: 0000000000000006 R15: 00007ffe2ed394b0
</TASK>
irq event stamp: 47867
hardirqs last enabled at (47883): [<ffffffff815cafc6>] __up_console_sem+0x66/0x70 kernel/printk/printk.c:347
hardirqs last disabled at (47892): [<ffffffff815cafab>] __up_console_sem+0x4b/0x70 kernel/printk/printk.c:345
softirqs last enabled at (47880): [<ffffffff81434277>] __do_softirq kernel/softirq.c:656 [inline]
softirqs last enabled at (47880): [<ffffffff81434277>] invoke_softirq kernel/softirq.c:496 [inline]
softirqs last enabled at (47880): [<ffffffff81434277>] __irq_exit_rcu+0x137/0x1c0 kernel/softirq.c:735
softirqs last disabled at (47875): [<ffffffff81434277>] __do_softirq kernel/softirq.c:656 [inline]
softirqs last disabled at (47875): [<ffffffff81434277>] invoke_softirq kernel/softirq.c:496 [inline]
softirqs last disabled at (47875): [<ffffffff81434277>] __irq_exit_rcu+0x137/0x1c0 kernel/softirq.c:735
Fix by calling ttm_bo_pin() only when the existing placement is compatible
with the new pin request. This matches the correct behavior in other DRM
drivers such as amdgpu_bo_pin() in amdgpu.
Cc: stable@vger.kernel.org
Fixes: ad76b3f7c7a0 ("drm/nouveau: teach nouveau_bo_pin() how to force a contig vram allocation")
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: LLM
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/EACEF2F4E098413F+20260918025312.2814889-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_bo.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nouveau_bo.c
+++ b/drivers/gpu/drm/nouveau/nouveau_bo.c
@@ -460,8 +460,9 @@ nouveau_bo_pin(struct nouveau_bo *nvbo,
"0x%08x vs 0x%08x\n", bo,
bo->resource->mem_type, domain);
ret = -EBUSY;
+ } else {
+ ttm_bo_pin(&nvbo->bo);
}
- ttm_bo_pin(&nvbo->bo);
goto out;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 948/982] HID: alps: fix use-after-free on input2 registration failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (946 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 947/982] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 949/982] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard Greg Kroah-Hartman
` (40 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Changcheng, Jiri Kosina
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Changcheng <chenchangcheng@kylinos.cn>
commit d3aba3442798ce4a4c8ce3104d7b286d61e605f9 upstream.
alps_input_configured() stores data->input2 before calling
input_register_device(). If registration fails, input_free_device()
frees the input device but data->input2 still points to the freed memory.
alps_input_configured() calls hid_hw_open() before allocating input2, so
URBs are already active and raw_event can fire during the failure window.
A U1_SP_ABSOLUTE_REPORT_ID report arriving then causes u1_raw_event()
to dereference the freed data->input2 -> use-after-free.
Fix by only storing input2 into drvdata after successful registration
and adding a NULL guard in the raw_event path.
Fixes: 2562756dde55 ("HID: add Alps I2C HID Touchpad-Stick support")
Cc: stable@vger.kernel.org
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-alps.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/hid/hid-alps.c
+++ b/drivers/hid/hid-alps.c
@@ -407,6 +407,8 @@ static int u1_raw_event(struct alps_dev
return 1;
case U1_SP_ABSOLUTE_REPORT_ID:
+ if (!hdata->input2)
+ return 0;
sp_x = get_unaligned_le16(data+2);
sp_y = get_unaligned_le16(data+4);
@@ -738,7 +740,6 @@ static int alps_input_configured(struct
goto exit;
}
- data->input2 = input2;
input2->phys = input->phys;
input2->name = "DualPoint Stick";
input2->id.bustype = BUS_I2C;
@@ -762,11 +763,12 @@ static int alps_input_configured(struct
__set_bit(INPUT_PROP_POINTER, input2->propbit);
__set_bit(INPUT_PROP_POINTING_STICK, input2->propbit);
- if (input_register_device(data->input2)) {
+ if (input_register_device(input2)) {
input_free_device(input2);
ret = -ENOENT;
goto exit;
}
+ data->input2 = input2;
}
exit:
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 949/982] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (947 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 948/982] HID: alps: fix use-after-free on input2 registration failure Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 950/982] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Greg Kroah-Hartman
` (39 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marco Carvalho, Junjie Cao,
Benjamin Tissoires
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junjie Cao <junjie.cao@intel.com>
commit cdb669a3b8f844aca71fc3224990157d61562165 upstream.
The SDINNOVATION gaming keyboard (USB ID 36ae:feab) stops reporting
input events after its RGB lighting mode is switched about twice.
Disabling USB autosuspend and unbinding the other HID interfaces make
no difference; the issue does not occur on Windows.
HID_QUIRK_ALWAYS_POLL alone resolves it, verified on 7.1.8 via
usbhid.quirks=0x36ae:0xfeab:0x400.
Reported-by: Marco Carvalho <marcocarvalho.web@gmail.com>
Link: https://bugzilla.redhat.com/show_bug.cgi?id=2514627
Cc: stable@vger.kernel.org
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-ids.h | 3 +++
drivers/hid/hid-quirks.c | 1 +
2 files changed, 4 insertions(+)
--- a/drivers/hid/hid-ids.h
+++ b/drivers/hid/hid-ids.h
@@ -1155,6 +1155,9 @@
#define USB_DEVICE_ID_SAMSUNG_IR_REMOTE 0x0001
#define USB_DEVICE_ID_SAMSUNG_WIRELESS_KBD_MOUSE 0x0600
+#define USB_VENDOR_ID_SDINNOVATION 0x36ae
+#define USB_DEVICE_ID_SDINNOVATION_GAMING_KBD 0xfeab
+
#define USB_VENDOR_ID_SEMICO 0x1a2c
#define USB_DEVICE_ID_SEMICO_USB_KEYKOARD 0x0023
#define USB_DEVICE_ID_SEMICO_USB_KEYKOARD2 0x0027
--- a/drivers/hid/hid-quirks.c
+++ b/drivers/hid/hid-quirks.c
@@ -171,6 +171,7 @@ static const struct hid_device_id hid_qu
{ HID_USB_DEVICE(USB_VENDOR_ID_SAITEK, USB_DEVICE_ID_SAITEK_X52_2), HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE },
{ HID_USB_DEVICE(USB_VENDOR_ID_SAITEK, USB_DEVICE_ID_SAITEK_X52_PRO), HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE },
{ HID_USB_DEVICE(USB_VENDOR_ID_SAITEK, USB_DEVICE_ID_SAITEK_X65), HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE },
+ { HID_USB_DEVICE(USB_VENDOR_ID_SDINNOVATION, USB_DEVICE_ID_SDINNOVATION_GAMING_KBD), HID_QUIRK_ALWAYS_POLL },
{ HID_USB_DEVICE(USB_VENDOR_ID_SEMICO, USB_DEVICE_ID_SEMICO_USB_KEYKOARD2), HID_QUIRK_NO_INIT_REPORTS },
{ HID_USB_DEVICE(USB_VENDOR_ID_SEMICO, USB_DEVICE_ID_SEMICO_USB_KEYKOARD), HID_QUIRK_NO_INIT_REPORTS },
{ HID_USB_DEVICE(USB_VENDOR_ID_SENNHEISER, USB_DEVICE_ID_SENNHEISER_BTD500USB), HID_QUIRK_NOGET },
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 950/982] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (948 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 949/982] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 951/982] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get() Greg Kroah-Hartman
` (38 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Gerecke, Wei Jie Law,
Jason Gerecke, Jiri Kosina
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Jie LAW <98lawweijie@gmail.com>
commit 9aa237cf66495b2426ddde8532e9b08a0ed83aaa upstream.
The 'wacom_wac_pen_serial_enforce()' function may calculate and pass an
invalid offset to hid_field_extract(), resulting in memory reads at
incorrect addresses -- possibly beyond the end of the report. If a
field in the HID descriptor lists more usages than its Report Count
actually reserves space for, the function's inner 'j' will walk past
the end of the field:
for (i = 0; i < report->maxfield; i++) {
for (j = 0; j < report->field[i]->maxusage; j++) {
...
value = hid_field_extract(hdev, raw_data + 1,
offset + j * size, size);
A descriptor listing 12288 usages against Report Count 1 has the loop
extract the usage at index 12287 from bit offset 98296 -- about 12 KB
past a 2-byte received report. The value is stored in
wacom_wac->serial[0] and can reach userspace as an MSC_SERIAL event,
making this an information disclosure.
Clamp the loop to field->report_count, the number of value slots the
report holds. Value slots past the last declared usage are still
scanned; they reuse that usage (HID 1.11, 6.2.2.8).
Verified on v6.12.105 with a UHID reproducer: a 2-byte report from
such a descriptor trips KASAN before the patch and not after it.
Fixes: 83417206427b ("HID: wacom: Queue events with missing type/serial data for later processing")
Suggested-by: Jason Gerecke <killertofu@gmail.com>
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Assisted-by: GLM:glm-5.3
Signed-off-by: Wei Jie Law <98lawweijie@gmail.com>
Reviewed-by: Jason Gerecke <jason.gerecke@wacom.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/wacom_sys.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/hid/wacom_sys.c
+++ b/drivers/hid/wacom_sys.c
@@ -97,8 +97,9 @@ static int wacom_wac_pen_serial_enforce(
/* Queue events which have invalid tool type or serial number */
for (i = 0; i < report->maxfield; i++) {
- for (j = 0; j < report->field[i]->maxusage; j++) {
- struct hid_field *field = report->field[i];
+ struct hid_field *field = report->field[i];
+
+ for (j = 0; j < field->report_count; j++) {
struct hid_usage *usage = &field->usage[j];
unsigned int equivalent_usage = wacom_equivalent_usage(usage->hid);
unsigned int offset;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 951/982] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (949 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 950/982] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 952/982] net/sched: reject IDR error pointers when deleting actions Greg Kroah-Hartman
` (37 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Tariq Toukan,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 0bf6bb567f0edaa771e7dd208ef98da50e6a4485 upstream.
When the reverse entry is found but its counter is already being
released, refcount_inc_not_zero() fails and the reference taken by
mlx5_tc_ct_entry_get() is never dropped before falling through to
create_counter. Drop it so the reverse entry is not kept alive forever
by a shared counter lookup that did not use it.
Fixes: 1edae2335adf ("net/mlx5e: CT: Use the same counter for both directions")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260917113131.2149024-1-vulab@iscas.ac.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c
@@ -1016,6 +1016,9 @@ mlx5_tc_ct_shared_counter_get(struct mlx
spin_unlock_bh(&ct_priv->ht_lock);
+ if (rev_entry)
+ mlx5_tc_ct_entry_put(rev_entry);
+
create_counter:
shared_counter = mlx5_tc_ct_counter_create(ct_priv);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 952/982] net/sched: reject IDR error pointers when deleting actions
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (950 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 951/982] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 953/982] net: arp: terminate device name before lookup Greg Kroah-Hartman
` (36 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit c82b797abe668d0b668601a93ba2c0b071a63574 upstream.
tcf_action_delete() drops the reference held by its lookup before calling
tcf_idr_delete_index() with the saved action index. An unlocked
classifier can remove that action and reserve the same IDR slot with
ERR_PTR(-EBUSY) in between.
tcf_idr_delete_index() only checks the lookup result for NULL. It
therefore treats the reservation as a tc_action and dereferences
tcfa_bindcnt. A hardware execution breakpoint was used to schedule the
interleaving without changing the kernel source. KASAN reported this
decoded trace:
BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010
Read of size 4 at addr 0000000000000010 by task poc/150
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002
RIP: tca_action_gd+0x5c0/0x1010:
arch_atomic_read at arch/x86/include/asm/atomic.h:23
raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457
atomic_read at include/linux/atomic/atomic-instrumented.h:33
tcf_idr_delete_index at net/sched/act_api.c:766
tcf_action_delete at net/sched/act_api.c:1859
tcf_del_notify at net/sched/act_api.c:2014
tca_action_gd at net/sched/act_api.c:2064
R13: 0000000000000010 R15: fffffffffffffff0
Kernel panic - not syncing: Fatal exception
R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces
the address in R13. With the guard applied, the same reproducer returned
-ENOENT without a KASAN report or panic. Treat error pointers as absent
and return -ENOENT.
Fixes: 0190c1d452a9 ("net: sched: atomically check-allocate action")
Cc: stable@vger.kernel.org
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/20260914065123.4109709-2-bestswngs@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/act_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -712,7 +712,7 @@ static int tcf_idr_delete_index(struct t
mutex_lock(&idrinfo->lock);
p = idr_find(&idrinfo->action_idr, index);
- if (!p) {
+ if (IS_ERR_OR_NULL(p)) {
mutex_unlock(&idrinfo->lock);
return -ENOENT;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 953/982] net: arp: terminate device name before lookup
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (951 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 952/982] net/sched: reject IDR error pointers when deleting actions Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 954/982] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read Greg Kroah-Hartman
` (35 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zijie Huang, Ren Wei,
Ido Schimmel, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijie Huang <milkory@outlook.com>
commit d8b6529e80bcb4fb8177121404cbb3377acaebd2 upstream.
The ARP ioctl copies a user-provided struct arpreq into a stack object. Its
arp_dev field may contain IFNAMSIZ bytes without a NUL terminator.
Such input is passed to dev_get_by_name_rcu() or __dev_get_by_name(), where
strcmp() can read past the end of the stack object when a matching
alternative interface name exists.
Terminate the field before the lookup to prevent the out-of-bounds read.
Fixes: 36fbf1e52bd3 ("net: rtnetlink: add linkprop commands to add and delete alternative ifnames")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zijie Huang <milkory@outlook.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/fabf02a70787d17299e4b3153eadffaf20d154b3.1789910973.git.milkory@outlook.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/arp.c | 1 +
1 file changed, 1 insertion(+)
--- a/net/ipv4/arp.c
+++ b/net/ipv4/arp.c
@@ -1222,6 +1222,7 @@ int arp_ioctl(struct net *net, unsigned
err = copy_from_user(&r, arg, sizeof(struct arpreq));
if (err)
return -EFAULT;
+ r.arp_dev[IFNAMSIZ - 1] = '\0';
break;
default:
return -EINVAL;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 954/982] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (952 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 953/982] net: arp: terminate device name before lookup Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 955/982] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy() Greg Kroah-Hartman
` (34 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gajdos Tamás, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gajdos Tamás <tamas@rimpianto.com>
commit 43e746821f5f5afbbf68e388bf9fbe221e03bfca upstream.
Same issue as atl1c (see the first commit in this series, "net:
atl1c: fix soft lockup on out-of-range tpd_cons read"): the hardware
can report an out-of-range cmb_tpd_next_to_clean (seen as 0xffff)
while the PCIe link/MAC is resetting. An out-of-range value can
never be reached and the loop below would spin forever. Treat it as
"nothing new to clean" instead.
Fixes: f3cc28c797604f ("Add Attansic L1 ethernet driver.")
Cc: stable@vger.kernel.org
Signed-off-by: Gajdos Tamás <tamas@rimpianto.com>
Link: https://patch.msgid.link/20260921091334.3571525-4-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/atheros/atlx/atl1.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/atheros/atlx/atl1.c
+++ b/drivers/net/ethernet/atheros/atlx/atl1.c
@@ -2066,6 +2066,9 @@ static int atl1_intr_tx(struct atl1_adap
sw_tpd_next_to_clean = atomic_read(&tpd_ring->next_to_clean);
cmb_tpd_next_to_clean = le16_to_cpu(adapter->cmb.cmb->tpd_cons_idx);
+ if (unlikely(cmb_tpd_next_to_clean >= tpd_ring->count))
+ cmb_tpd_next_to_clean = sw_tpd_next_to_clean;
+
while (cmb_tpd_next_to_clean != sw_tpd_next_to_clean) {
buffer_info = &tpd_ring->buffer_info[sw_tpd_next_to_clean];
if (buffer_info->dma) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 955/982] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (953 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 954/982] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 956/982] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
` (33 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Simon Horman,
Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 999e8295bc41d6ce45b8e54f88150efa96f3f01e upstream.
hns_dsaf_find_platform_device() returns the mdio platform device with its
reference count incremented. hns_mac_register_phy() never drops that
reference, so the mdio device can not be released.
Release the reference on both the deferred probe and the normal path.
Fixes: 1d1afa2ebf82 ("net: hns: register phy device in each mac initial sequence")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260917110828.2148390-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c
+++ b/drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c
@@ -793,6 +793,7 @@ static int hns_mac_register_phy(struct h
dev_err(mac_cb->dev,
"mac%d mdio is NULL, dsaf will probe again later\n",
mac_cb->mac_id);
+ put_device(&pdev->dev);
return -EPROBE_DEFER;
}
@@ -801,6 +802,8 @@ static int hns_mac_register_phy(struct h
dev_dbg(mac_cb->dev, "mac%d register phy addr:%d\n",
mac_cb->mac_id, addr);
+ put_device(&pdev->dev);
+
return rc;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 956/982] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (954 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 955/982] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 957/982] net: atl1c: fix soft lockup on out-of-range tpd_cons read Greg Kroah-Hartman
` (32 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Axel Mierczuk, Ilya Maximets,
Aaron Conole, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit 26b2bd70d22457556e2fa01cbf1192cb1a94d619 upstream.
In a case where skb with an unconfirmed ct entry gets cloned, we may
end up committing both but with different sets of extensions.
The series of events:
1. The first clone wants to commit and runs the helpers wiring up
the extension pointer into the expectation list.
2. Then it looses the confirmation keeping the entry unconfirmed.
3. Second clone now wants to commit labels and adds the new extension
for that breaking the pointer in the expectation list causing
UAF on the destruction path later.
While this is possible to trigger, there should be no practical
network pipeline where committing both clones without modifications
into the same zone is needed. So, let's just reset the entry in case
for some reason we got an skb with a shared one during commit. This
doesn't affect any known use cases, but avoids any potential problems
with sharing and modification of the unconfirmed ct entry.
The fixes tag points to the introduction of helpers, since that's the
main UAF trigger for the sharing.
Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action")
Cc: stable@vger.kernel.org
Reported-by: Axel Mierczuk <axel.mierczuk@1password.com>
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260921145655.3167436-2-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/net/netfilter/nf_conntrack.h | 5 +++++
net/openvswitch/conntrack.c | 12 ++++++++++++
2 files changed, 17 insertions(+)
--- a/include/net/netfilter/nf_conntrack.h
+++ b/include/net/netfilter/nf_conntrack.h
@@ -194,6 +194,11 @@ static inline void nf_ct_put(struct nf_c
int nf_ct_l3proto_try_module_get(unsigned short l3proto);
void nf_ct_l3proto_module_put(unsigned short l3proto);
+static inline bool nf_ct_shared(const struct nf_conn *ct)
+{
+ return refcount_read(&ct->ct_general.use) > 1;
+}
+
/* load module; enable/disable conntrack in this namespace */
int nf_ct_netns_get(struct net *net, u8 nfproto);
void nf_ct_netns_put(struct net *net, u8 nfproto);
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -970,6 +970,18 @@ static int __ovs_ct_lookup(struct net *n
enum ip_conntrack_info ctinfo;
struct nf_conn *ct;
+ /* If the ct entry is not confirmed and shared with some other skb,
+ * e.g., a cloned one, we can't just modify it with the commit as we
+ * must not modify the extension set. Reset.
+ */
+ if (cached && info->commit) {
+ ct = nf_ct_get(skb, &ctinfo);
+ if (ct && !nf_ct_is_confirmed(ct) && nf_ct_shared(ct)) {
+ nf_reset_ct(skb);
+ cached = false;
+ }
+ }
+
if (!cached) {
struct nf_hook_state state = {
.hook = NF_INET_PRE_ROUTING,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 957/982] net: atl1c: fix soft lockup on out-of-range tpd_cons read
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (955 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 956/982] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 958/982] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read Greg Kroah-Hartman
` (31 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gajdos Tamás, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gajdos Tamás <tamas@rimpianto.com>
commit 36c2009d90f2210ef92e6f4f2850e8b57b09e754 upstream.
The hardware can report an out-of-range tpd_cons (seen as 0xffff)
while the PCIe link/MAC is resetting. An out-of-range value can
never be reached and the loop below would spin forever. To avoid
a soft lockup treat it as "nothing new to clean" instead.
Reproduced on two machines, same NIC (Qualcomm Atheros AR8151 v2.0,
4-port), triggered by rebooting a Mikrotik CCR2004 PCIe card that
the ports are directly linked to:
- Ubuntu 26.04.1 LTS, kernel 7.0.0-31-generic. The link-flap
precursor, before the lockup was captured with a full trace
elsewhere:
atl1c 0000:05:00.0 enp5s0f0: NETDEV WATCHDOG: CPU: 4: transmit queue 2 timed out 489984 ms
atl1c 0000:05:00.0: MAC state machine can't be idle since disabled for 10ms second
atl1c 0000:05:00.0: atl1c: enp5s0f0 NIC Link is Up<65535 Mbps Full Duplex>
65535 (0xffff) here is the same value tpd_cons reads back once the
loop below gets stuck.
- Proxmox VE, kernel 7.0.14-11-pve. Same NIC/trigger, this time
caught by the soft lockup watchdog with a full stack trace:
watchdog: BUG: soft lockup - CPU#12 stuck for 354s! [napi/eth%d-0:329]
CPU: 12 UID: 0 PID: 329 Comm: napi/eth%d-0 Tainted: P O L 7.0.14-11-pve #1 PREEMPT(lazy)
RIP: 0010:atl1c_clean_tx+0x142/0x2d0 [atl1c]
Call Trace:
<TASK>
__napi_poll+0x32/0x1e0
napi_threaded_poll_loop+0x286/0x2e0
napi_threaded_poll+0xfd/0x140
kthread+0xf7/0x130
ret_from_fork+0x2da/0x3a0
ret_from_fork_asm+0x1a/0x30
</TASK>
Fixes: 43250ddd75a35d ("atl1c: Atheros L1C Gigabit Ethernet driver")
Cc: stable@vger.kernel.org
Signed-off-by: Gajdos Tamás <tamas@rimpianto.com>
Link: https://patch.msgid.link/20260921091334.3571525-2-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/atheros/atl1c/atl1c_main.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/atheros/atl1c/atl1c_main.c
+++ b/drivers/net/ethernet/atheros/atl1c/atl1c_main.c
@@ -1611,6 +1611,9 @@ static int atl1c_clean_tx(struct napi_st
AT_READ_REGW(&adapter->hw, atl1c_qregs[tpd_ring->num].tpd_cons,
&hw_next_to_clean);
+ if (unlikely(hw_next_to_clean >= tpd_ring->count))
+ hw_next_to_clean = next_to_clean;
+
while (next_to_clean != hw_next_to_clean) {
buffer_info = &tpd_ring->buffer_info[next_to_clean];
if (buffer_info->skb) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 958/982] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (956 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 957/982] net: atl1c: fix soft lockup on out-of-range tpd_cons read Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 959/982] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist Greg Kroah-Hartman
` (30 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gajdos Tamás, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gajdos Tamás <tamas@rimpianto.com>
commit 374bf9e4b90f979e052332c4faca2d745c491a12 upstream.
Same issue as atl1c (see the first commit in this series, "net:
atl1c: fix soft lockup on out-of-range tpd_cons read"): the hardware
can report an out-of-range hw_next_to_clean (seen as 0xffff) while
the PCIe link/MAC is resetting. An out-of-range value can never be
reached and the loop below would spin forever. Treat it as "nothing
new to clean" instead.
Fixes: a6a5325239c202 ("atl1e: Atheros L1E Gigabit Ethernet driver")
Cc: stable@vger.kernel.org
Signed-off-by: Gajdos Tamás <tamas@rimpianto.com>
Link: https://patch.msgid.link/20260921091334.3571525-3-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/atheros/atl1e/atl1e_main.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/atheros/atl1e/atl1e_main.c
+++ b/drivers/net/ethernet/atheros/atl1e/atl1e_main.c
@@ -1234,6 +1234,9 @@ static bool atl1e_clean_tx_irq(struct at
u16 hw_next_to_clean = AT_READ_REGW(&adapter->hw, REG_TPD_CONS_IDX);
u16 next_to_clean = atomic_read(&tx_ring->next_to_clean);
+ if (unlikely(hw_next_to_clean >= tx_ring->count))
+ hw_next_to_clean = next_to_clean;
+
while (next_to_clean != hw_next_to_clean) {
tx_buffer = &tx_ring->tx_buffer[next_to_clean];
if (tx_buffer->dma) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 959/982] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (957 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 958/982] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 960/982] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Greg Kroah-Hartman
` (29 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ming Wang, Jakub Kicinski
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ming Wang <wangming01@loongson.cn>
commit f75f21ef36285e5f56ee0c428bd2909ee81165b9 upstream.
The MeiG Smart SRM821 5G module (0x2dee:0x4d53) crashes and drops off
the USB bus when it receives a Zero Length Packet (ZLP) after sending
or receiving an NTB of exactly 16384 bytes (tx_max).
According to the MBIM specification, devices do not require a ZLP
if the NTB size is exactly dwNtbOutMaxSize. However, the cdc_mbim
driver defaults to sending ZLPs for devices not explicitly whitelisted
to accommodate non-conformant hardware. This default behavior breaks
the strictly conformant MeiG SRM821 module.
Add this device to the ZLP conformance whitelist (cdc_mbim_info) so
the driver will pad the NTB to avoid sending ZLPs, preventing the
device firmware from crashing.
Cc: stable@vger.kernel.org
Signed-off-by: Ming Wang <wangming01@loongson.cn>
Link: https://patch.msgid.link/20260920074500.826121-1-wangming01@loongson.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/cdc_mbim.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/net/usb/cdc_mbim.c
+++ b/drivers/net/usb/cdc_mbim.c
@@ -634,6 +634,11 @@ static const struct usb_device_id mbim_d
.driver_info = (unsigned long)&cdc_mbim_info,
},
+ /* MeiG Smart SRM821 ZLP conformance */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x2dee, 0x4d53, USB_CLASS_COMM, USB_CDC_SUBCLASS_MBIM, USB_CDC_PROTO_NONE),
+ .driver_info = (unsigned long)&cdc_mbim_info,
+ },
+
/* Some Huawei devices, ME906s-158 (12d1:15c1) and E3372
* (12d1:157d), are known to fail unless the NDP is placed
* after the IP packets. Applying the quirk to all Huawei
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 960/982] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (958 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 959/982] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 961/982] netfilter: ip6t_rpfilter: reject routes without inet6_dev Greg Kroah-Hartman
` (28 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Paolo Abeni
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 17741334d00bf5ebd37f8c1c36bc9c146a351deb upstream.
usb_get_from_anchor() hands over a reference to the URB, which the caller
must release. lan78xx_submit_deferred_urbs() never does, so every deferred
Tx URB keeps an extra reference: the counter grows on each suspend/resume
cycle and the URBs are never freed when the buffers are released. Drop
the reference after submitting, and on the path that drops the packet
instead of submitting it.
Fixes: 5f4cc6e25148 ("lan78xx: Fix race conditions in suspend/resume handling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260917115811.2150119-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/lan78xx.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/net/usb/lan78xx.c
+++ b/drivers/net/usb/lan78xx.c
@@ -4935,10 +4935,12 @@ static bool lan78xx_submit_deferred_urbs
!netif_carrier_ok(dev->net) ||
pipe_halted) {
lan78xx_release_tx_buf(dev, skb);
+ usb_put_urb(urb);
continue;
}
ret = usb_submit_urb(urb, GFP_ATOMIC);
+ usb_put_urb(urb);
if (ret == 0) {
netif_trans_update(dev->net);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 961/982] netfilter: ip6t_rpfilter: reject routes without inet6_dev
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (959 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 960/982] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 962/982] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read Greg Kroah-Hartman
` (27 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+459f67f4d8af8ce6,
Florian Westphal, Weiming Shi, Pablo Neira Ayuso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit 1b9b5323725e458906c7620a3bc10398b51ad954 upstream.
ip6_route_lookup() can return an error-free route whose rt6i_idev is
NULL. Lowering an external nexthop device's MTU below IPV6_MIN_MTU tears
down its inet6_dev while fib6_ifdown() leaves routes using nexthop objects
in the FIB. An unprivileged user can construct this state with rtnetlink
in a private user and network namespace, then trigger a NULL dereference
through an IPv6 rpfilter lookup:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: rpfilter_mt (net/ipv6/netfilter/ip6t_rpfilter.c:75)
Call Trace:
ip6t_do_table (net/ipv6/netfilter/ip6_tables.c:316)
nf_hook_slow (net/netfilter/core.c:619)
ipv6_rcv (net/ipv6/ip6_input.c:351)
__netif_receive_skb_one_core (net/core/dev.c:6216)
process_backlog (net/core/dev.c:6680)
__napi_poll (net/core/dev.c:7739)
net_rx_action (net/core/dev.c:7959)
handle_softirqs (kernel/softirq.c:622)
do_softirq.part.0 (kernel/softirq.c:523)
__local_bh_enable_ip (kernel/softirq.c:450)
__dev_queue_xmit (net/core/dev.c:4913)
packet_sendmsg (net/packet/af_packet.c:3139)
__sys_sendto (net/socket.c:2252)
__x64_sys_sendto (net/socket.c:2259)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Reject routes without an inet6_dev immediately after lookup. Such routes
are not eligible for reverse-path filtering, and the check protects all
later rt6i_idev dereferences.
Fixes: e26f9a480fb6 ("netfilter: add ipv6 reverse path filter match")
Reported-by: co+459f67f4d8af8ce6@bugs.sh
Closes: https://lore.kernel.org/all/VtWUkE8QzJt5CroTj2V2v3ZQ0gwbXZ7nq7I3@bugs.sh/
Suggested-by: Florian Westphal <fw@strlen.de>
Assisted-by: Claude:gpt-5
Cc: stable@vger.kernel.org
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/netfilter/ip6t_rpfilter.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/ipv6/netfilter/ip6t_rpfilter.c
+++ b/net/ipv6/netfilter/ip6t_rpfilter.c
@@ -61,7 +61,7 @@ static bool rpfilter_lookup_reverse6(str
fl6.flowi6_oif = dev->ifindex;
rt = (void *)ip6_route_lookup(net, &fl6, skb, lookup_flags);
- if (rt->dst.error)
+ if (rt->dst.error || !rt->rt6i_idev)
goto out;
if (rt->rt6i_flags & (RTF_REJECT|RTF_ANYCAST))
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 962/982] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (960 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 961/982] netfilter: ip6t_rpfilter: reject routes without inet6_dev Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 963/982] nfc: fix use-after-free in nfc_get_local_general_bytes Greg Kroah-Hartman
` (26 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Florian Westphal, Luxiao Xu,
Ren Wei, Pablo Neira Ayuso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luxiao Xu <rakukuip@gmail.com>
commit 82313c169eddc02b1bf5ba6b427803e272d3ec42 upstream.
rt_mt6_check() permits rules to be configured with rtinfo->addrnr == 0
even when address matching (IP6T_RT_FST_MASK) is requested.
In the IP6T_RT_FST_NSTRICT path, rt_mt6() evaluates packet routing
addresses against rtinfo->addrs[i] and terminates backwards at the bottom
of the loop:
if (ipv6_addr_equal(ap, &rtinfo->addrs[i])) {
i++;
}
if (i == rtinfo->addrnr)
break;
When addrnr is 0, if the first packet address matches rtinfo->addrs[0],
i is incremented to 1. Because i is now strictly greater than addrnr (0),
the loop termination condition (i == rtinfo->addrnr) is bypassed and will
never be satisfied.
If a crafted IPv6 packet contains matching routing addresses, i will
advance past IP6T_RT_HOPS (16). The subsequent call to ipv6_addr_equal()
reads beyond struct ip6t_rt, triggering UBSAN/KASAN out-of-bounds warnings
or kernel panics.
Fix this by:
1. Rejecting rules in rt_mt6_check() where IP6T_RT_FST_MASK is set but
rtinfo->addrnr is zero.
2. In rt_mt6(), moving the termination condition (i < rtinfo->addrnr)
into the for-loop header condition and removing the backwards break
at the end of the loop body.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Suggested-by: Florian Westphal <fw@strlen.de>
Assisted-by: LLM
Signed-off-by: Luxiao Xu <rakukuip@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/netfilter/ip6t_rt.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/net/ipv6/netfilter/ip6t_rt.c
+++ b/net/ipv6/netfilter/ip6t_rt.c
@@ -96,7 +96,8 @@ static bool rt_mt6(const struct sk_buff
unsigned int i = 0;
for (temp = 0;
- temp < (unsigned int)((hdrlen - 8) / 16);
+ temp < (unsigned int)((hdrlen - 8) / 16) &&
+ i < rtinfo->addrnr;
temp++) {
ap = skb_header_pointer(skb,
ptr
@@ -112,8 +113,6 @@ static bool rt_mt6(const struct sk_buff
if (ipv6_addr_equal(ap, &rtinfo->addrs[i]))
i++;
- if (i == rtinfo->addrnr)
- break;
}
if (i == rtinfo->addrnr)
return ret;
@@ -162,6 +161,12 @@ static int rt_mt6_check(const struct xt_
pr_debug("too many addresses specified\n");
return -EINVAL;
}
+
+ if ((rtinfo->flags & IP6T_RT_FST_MASK) && !rtinfo->addrnr) {
+ pr_info_ratelimited("address list match requested but addrnr is 0\n");
+ return -EINVAL;
+ }
+
if ((rtinfo->flags & (IP6T_RT_RES | IP6T_RT_FST_MASK)) &&
(!(rtinfo->flags & IP6T_RT_TYP) ||
(rtinfo->rt_type != 0) ||
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 963/982] nfc: fix use-after-free in nfc_get_local_general_bytes
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (961 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 962/982] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 964/982] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc() Greg Kroah-Hartman
` (25 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxiao Xu, Ren Wei,
Simon Horman, David Heidelberg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luxiao Xu <rakukuip@gmail.com>
commit dcab71a7011918f6fdba7adcec02d217dcb84b8d upstream.
Commit 6709d4b7bc2e ("net: nfc: Fix use-after-free caused by
nfc_llcp_find_local") attempted to fix a use-after-free (UAF) issue by
invoking nfc_llcp_local_put(local) after accessing local->gb. However,
if the reference count drops to zero, local is freed immediately,
leading to a use-after-free when callers access the returned pointer.
Alternative approaches using dynamic allocation (e.g. kmemdup) introduced
memory leaks because callers consistently treat the returned pointer as
borrowed memory.
Fix this properly by refactoring nfc_llcp_general_bytes() and
nfc_get_local_general_bytes() to accept a caller-provided output buffer
(out_gb) and its maximum length (gb_max_len). The general bytes are
safely copied into out_gb before calling nfc_llcp_local_put(local),
ensuring safe lifetime management without ownership transfer complications.
Update all callers across drivers (microread, pn533, pn544, st21nfca,
digital_dep, and nci) to provide their own destination buffers and pass
them to nfc_get_local_general_bytes().
Fixes: 6709d4b7bc2e ("net: nfc: Fix use-after-free caused by nfc_llcp_find_local")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Signed-off-by: Luxiao Xu <rakukuip@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/3cbaac3bee23f8ff3a3284ed32d347696eb1d208.1788841683.git.rakukuip@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nfc/microread/microread.c | 6 +++---
drivers/nfc/pn533/pn533.c | 14 ++++++++------
drivers/nfc/pn533/pn533.h | 4 +++-
drivers/nfc/pn544/pn544.c | 7 +++----
drivers/nfc/st21nfca/core.c | 8 ++++----
include/net/nfc/hci.h | 2 +-
include/net/nfc/nfc.h | 3 ++-
net/nfc/core.c | 15 +++++++--------
net/nfc/digital_dep.c | 8 ++++----
net/nfc/llcp_core.c | 17 +++++++++++++----
net/nfc/nci/core.c | 10 +++++-----
net/nfc/nfc.h | 3 ++-
12 files changed, 55 insertions(+), 42 deletions(-)
--- a/drivers/nfc/microread/microread.c
+++ b/drivers/nfc/microread/microread.c
@@ -251,9 +251,9 @@ static int microread_start_poll(struct n
param[1] |= (1 << 1);
if ((im_protocols | tm_protocols) & NFC_PROTO_NFC_DEP_MASK) {
- hdev->gb = nfc_get_local_general_bytes(hdev->ndev,
- &hdev->gb_len);
- if (hdev->gb == NULL || hdev->gb_len == 0) {
+ nfc_get_local_general_bytes(hdev->ndev, hdev->gb,
+ sizeof(hdev->gb), &hdev->gb_len);
+ if (hdev->gb_len == 0) {
im_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
tm_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
}
--- a/drivers/nfc/pn533/pn533.c
+++ b/drivers/nfc/pn533/pn533.c
@@ -1355,10 +1355,11 @@ static int pn533_poll_dep(struct nfc_dev
u8 *next, nfcid3[NFC_NFCID3_MAXSIZE];
u8 passive_data[PASSIVE_DATA_LEN] = {0x00, 0xff, 0xff, 0x00, 0x3};
- if (!dev->gb) {
- dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
-
- if (!dev->gb || !dev->gb_len) {
+ if (!dev->gb_len) {
+ nfc_get_local_general_bytes(nfc_dev, dev->gb,
+ sizeof(dev->gb),
+ &dev->gb_len);
+ if (!dev->gb_len) {
dev->poll_dep = 0;
queue_work(dev->wq, &dev->rf_work);
}
@@ -1660,8 +1661,9 @@ static int pn533_start_poll(struct nfc_d
}
if (tm_protocols) {
- dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
- if (dev->gb == NULL)
+ nfc_get_local_general_bytes(nfc_dev, dev->gb,
+ sizeof(dev->gb), &dev->gb_len);
+ if (dev->gb_len == 0)
tm_protocols = 0;
}
--- a/drivers/nfc/pn533/pn533.h
+++ b/drivers/nfc/pn533/pn533.h
@@ -6,6 +6,8 @@
* Copyright (C) 2012-2013 Tieto Poland
*/
+#include <net/nfc/nfc.h>
+
#define PN533_DEVICE_STD 0x1
#define PN533_DEVICE_PASORI 0x2
#define PN533_DEVICE_ACR122U 0x3
@@ -166,7 +168,7 @@ struct pn533 {
struct timer_list listen_timer;
int cancel_listen;
- u8 *gb;
+ u8 gb[NFC_MAX_GT_LEN];
size_t gb_len;
u8 tgt_available_prots;
--- a/drivers/nfc/pn544/pn544.c
+++ b/drivers/nfc/pn544/pn544.c
@@ -377,10 +377,9 @@ static int pn544_hci_start_poll(struct n
return r;
if ((im_protocols | tm_protocols) & NFC_PROTO_NFC_DEP_MASK) {
- hdev->gb = nfc_get_local_general_bytes(hdev->ndev,
- &hdev->gb_len);
- pr_debug("generate local bytes %p\n", hdev->gb);
- if (hdev->gb == NULL || hdev->gb_len == 0) {
+ nfc_get_local_general_bytes(hdev->ndev, hdev->gb,
+ sizeof(hdev->gb), &hdev->gb_len);
+ if (hdev->gb_len == 0) {
im_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
tm_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
}
--- a/drivers/nfc/st21nfca/core.c
+++ b/drivers/nfc/st21nfca/core.c
@@ -351,10 +351,10 @@ static int st21nfca_hci_start_poll(struc
if (r < 0)
return r;
} else {
- hdev->gb = nfc_get_local_general_bytes(hdev->ndev,
- &hdev->gb_len);
-
- if (hdev->gb == NULL || hdev->gb_len == 0) {
+ nfc_get_local_general_bytes(hdev->ndev, hdev->gb,
+ sizeof(hdev->gb),
+ &hdev->gb_len);
+ if (hdev->gb_len == 0) {
im_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
tm_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
}
--- a/include/net/nfc/hci.h
+++ b/include/net/nfc/hci.h
@@ -144,7 +144,7 @@ struct nfc_hci_dev {
data_exchange_cb_t async_cb;
void *async_cb_context;
- u8 *gb;
+ u8 gb[NFC_MAX_GT_LEN];
size_t gb_len;
unsigned long quirks;
--- a/include/net/nfc/nfc.h
+++ b/include/net/nfc/nfc.h
@@ -269,7 +269,8 @@ struct sk_buff *nfc_alloc_recv_skb(unsig
int nfc_set_remote_general_bytes(struct nfc_dev *dev,
const u8 *gt, u8 gt_len);
-u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, size_t *gb_len);
+u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, u8 *out_gb,
+ size_t gb_max_len, size_t *gb_len);
int nfc_fw_download_done(struct nfc_dev *dev, const char *firmware_name,
u32 result);
--- a/net/nfc/core.c
+++ b/net/nfc/core.c
@@ -279,10 +279,10 @@ static struct nfc_target *nfc_find_targe
int nfc_dep_link_up(struct nfc_dev *dev, int target_index, u8 comm_mode)
{
- int rc = 0;
- u8 *gb;
- size_t gb_len;
struct nfc_target *target;
+ u8 gb[NFC_MAX_GT_LEN];
+ size_t gb_len = 0;
+ int rc = 0;
pr_debug("dev_name=%s comm %d\n", dev_name(&dev->dev), comm_mode);
@@ -301,7 +301,7 @@ int nfc_dep_link_up(struct nfc_dev *dev,
goto error;
}
- gb = nfc_llcp_general_bytes(dev, &gb_len);
+ nfc_get_local_general_bytes(dev, gb, sizeof(gb), &gb_len);
if (gb_len > NFC_MAX_GT_LEN) {
rc = -EINVAL;
goto error;
@@ -644,11 +644,10 @@ int nfc_set_remote_general_bytes(struct
}
EXPORT_SYMBOL(nfc_set_remote_general_bytes);
-u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, size_t *gb_len)
+u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, u8 *out_gb,
+ size_t gb_max_len, size_t *gb_len)
{
- pr_debug("dev_name=%s\n", dev_name(&dev->dev));
-
- return nfc_llcp_general_bytes(dev, gb_len);
+ return nfc_llcp_general_bytes(dev, out_gb, gb_max_len, gb_len);
}
EXPORT_SYMBOL(nfc_get_local_general_bytes);
--- a/net/nfc/digital_dep.c
+++ b/net/nfc/digital_dep.c
@@ -1490,14 +1490,14 @@ static int digital_tg_send_atr_res(struc
struct digital_atr_req *atr_req)
{
struct digital_atr_res *atr_res;
+ u8 gb[NFC_MAX_GT_LEN];
struct sk_buff *skb;
- u8 *gb, payload_bits;
+ u8 payload_bits;
size_t gb_len;
int rc;
- gb = nfc_get_local_general_bytes(ddev->nfc_dev, &gb_len);
- if (!gb)
- gb_len = 0;
+ nfc_get_local_general_bytes(ddev->nfc_dev, gb, sizeof(gb),
+ &gb_len);
skb = digital_skb_alloc(ddev, sizeof(struct digital_atr_res) + gb_len);
if (!skb)
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -651,23 +651,32 @@ out:
return ret;
}
-u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len)
+u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, u8 *out_gb, size_t gb_max_len,
+ size_t *general_bytes_len)
{
struct nfc_llcp_local *local;
+ if (!out_gb || !general_bytes_len)
+ return NULL;
+
local = nfc_llcp_find_local(dev);
- if (local == NULL) {
+ if (!local) {
*general_bytes_len = 0;
return NULL;
}
nfc_llcp_build_gb(local);
- *general_bytes_len = local->gb_len;
+ if (local->gb_len) {
+ *general_bytes_len = min_t(size_t, local->gb_len, gb_max_len);
+ memcpy(out_gb, local->gb, *general_bytes_len);
+ } else {
+ *general_bytes_len = 0;
+ }
nfc_llcp_local_put(local);
- return local->gb;
+ return out_gb;
}
int nfc_llcp_set_remote_gb(struct nfc_dev *dev, const u8 *gb, u8 gb_len)
--- a/net/nfc/nci/core.c
+++ b/net/nfc/nci/core.c
@@ -762,15 +762,15 @@ static int nci_set_local_general_bytes(s
{
struct nci_dev *ndev = nfc_get_drvdata(nfc_dev);
struct nci_set_config_param param;
+ u8 gb[NFC_MAX_GT_LEN];
int rc;
- param.val = nfc_get_local_general_bytes(nfc_dev, ¶m.len);
- if ((param.val == NULL) || (param.len == 0))
+ nfc_get_local_general_bytes(nfc_dev, gb, sizeof(gb),
+ ¶m.len);
+ if (param.len == 0)
return 0;
- if (param.len > NFC_MAX_GT_LEN)
- return -EINVAL;
-
+ param.val = gb;
param.id = NCI_PN_ATR_REQ_GEN_BYTES;
rc = nci_request(ndev, nci_set_config_req, ¶m,
--- a/net/nfc/nfc.h
+++ b/net/nfc/nfc.h
@@ -49,7 +49,8 @@ void nfc_llcp_mac_is_up(struct nfc_dev *
int nfc_llcp_register_device(struct nfc_dev *dev);
void nfc_llcp_unregister_device(struct nfc_dev *dev);
int nfc_llcp_set_remote_gb(struct nfc_dev *dev, const u8 *gb, u8 gb_len);
-u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len);
+u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, u8 *out_gb, size_t gb_max_len,
+ size_t *general_bytes_len);
int nfc_llcp_data_received(struct nfc_dev *dev, struct sk_buff *skb);
struct nfc_llcp_local *nfc_llcp_find_local(struct nfc_dev *dev);
int nfc_llcp_local_put(struct nfc_llcp_local *local);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 964/982] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (962 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 963/982] nfc: fix use-after-free in nfc_get_local_general_bytes Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 965/982] nfc: port100: reject frames whose declared length exceeds the received data Greg Kroah-Hartman
` (24 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Simon Horman,
David Heidelberg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
commit 273f9d667cde649f8de9d72b1303cc2f4b658c50 upstream.
nfc_llcp_recv_hdlc() reads the sequence byte skb->data[2], via
nfc_llcp_ns()/nfc_llcp_nr(), before any length check. The receive path
only guarantees the two-byte LLCP header -- __nfc_llcp_recv() checks it
with pskb_may_pull() and nfc_llcp_recv_agf() admits two-byte inner PDUs
-- so a two-byte I, RR or RNR PDU reads one byte of uninitialised skb
tailroom. The byte becomes N(R)/N(S); a peer can already set those with
a well-formed PDU, so this is acting on uninitialised memory, not new
peer control.
Guard the read with pskb_may_pull(), as commit 95674f506c63 ("nfc: llcp:
reject PDUs shorter than the LLCP header") did for the two-byte header,
so the sequence byte is present and linear before it is read. RR and RNR
PDUs are LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE bytes and an I PDU is
longer, so no valid frame is rejected; a truncated PDU is malformed, so
return without a DM reply.
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/AS8P251MB0001789BBF04B72745C7D96BC8BA2@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/nfc/llcp_core.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1099,6 +1099,9 @@ static void nfc_llcp_recv_hdlc(struct nf
struct sock *sk;
u8 dsap, ssap, ptype, ns, nr;
+ if (!pskb_may_pull(skb, LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE))
+ return;
+
ptype = nfc_llcp_ptype(skb);
dsap = nfc_llcp_dsap(skb);
ssap = nfc_llcp_ssap(skb);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 965/982] nfc: port100: reject frames whose declared length exceeds the received data
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (963 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 964/982] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 966/982] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU Greg Kroah-Hartman
` (23 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Doruk Tan Ozturk, Simon Horman,
David Heidelberg
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doruk Tan Ozturk <doruk@0sec.ai>
commit 092c6a605cbd6414ef499834c2e0da69c2c3388e upstream.
port100_recv_response() passes the URB transfer buffer to
port100_rx_frame_is_valid(), which checksums le16_to_cpu(frame->datalen)
bytes of frame->data. datalen is a 16-bit field supplied by the device
and is never checked against the number of bytes actually received
(urb->actual_length), so a device reporting a datalen larger than the
received frame makes port100_data_checksum() read out of bounds past the
transfer buffer.
Reject a response whose declared frame size does not fit the received
length before validating it.
Found by 0sec (https://0sec.ai) using automated source analysis; the
missing bound is evident from source. Compile-tested.
Fixes: 562d4d59b8a1 ("NFC: Sony Port-100 Series driver")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:claude-opus-4-8
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260711123651.32595-1-doruk@0sec.ai
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nfc/port100.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/nfc/port100.c
+++ b/drivers/nfc/port100.c
@@ -636,6 +636,13 @@ static void port100_recv_response(struct
in_frame = dev->in_urb->transfer_buffer;
+ if (urb->actual_length < PORT100_FRAME_HEADER_LEN ||
+ urb->actual_length < port100_rx_frame_size(in_frame)) {
+ nfc_err(&dev->interface->dev, "Received a truncated frame\n");
+ cmd->status = -EIO;
+ goto sched_wq;
+ }
+
if (!port100_rx_frame_is_valid(in_frame)) {
nfc_err(&dev->interface->dev, "Received an invalid frame\n");
cmd->status = -EIO;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 966/982] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (964 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 965/982] nfc: port100: reject frames whose declared length exceeds the received data Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 967/982] pinctrl: single: free the IRQ on domain creation failure Greg Kroah-Hartman
` (22 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Mike Christie,
Martin K. Petersen (Oracle)
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
commit bce07e2f37b5e4a427d36fd6b1c14067b27591db upstream.
The Data-In branch of iscsi_tcp_hdr_dissect() resolves the ITT to a task
and copies the PDU's data segment into that command's scatterlist without
asking whether the command was reading. iscsi_tcp_r2t_rsp() in the same
file does ask, and rejects an R2T for a command that is not DMA_TO_DEVICE.
A target that answers a WRITE command's ITT with a Data-In therefore has
the initiator write target-supplied bytes into the pages that write was
about to send. Those are the caller's own pinned pages for an O_DIRECT
write, and page cache pages for a buffered one.
Observed against a test target that emits one 512-byte Data-In naming a 128
KB write's ITT, after the R2T for that write. With O_DIRECT the caller's
buffer ends up holding 512 bytes of the target's data while pwrite()
returns 131072. Buffered is quieter: pwrite() and fsync() both succeed,
nothing is logged, and reading those blocks back returns the target's bytes
out of the page cache without a command going on the wire.
Check the direction before using the scatterlist, the way the R2T path
already does.
Cc: stable@vger.kernel.org
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Reviewed-by: Mike Christie <michael.christie@oracle.com>
Link: https://patch.msgid.link/20260801133635.1986706-1-yhlee@isslab.korea.ac.kr
Fixes: a081c13e39b5 ("[SCSI] iscsi_tcp: split module into lib and lld")
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/libiscsi_tcp.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/scsi/libiscsi_tcp.c
+++ b/drivers/scsi/libiscsi_tcp.c
@@ -491,6 +491,9 @@ static int iscsi_tcp_data_in(struct iscs
int datasn = be32_to_cpu(rhdr->datasn);
unsigned total_in_length = task->sc->sdb.length;
+ if (task->sc->sc_data_direction != DMA_FROM_DEVICE)
+ return ISCSI_ERR_PROTO;
+
/*
* lib iscsi will update this in the completion handling if there
* is status.
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 967/982] pinctrl: single: free the IRQ on domain creation failure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (965 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 966/982] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 968/982] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() Greg Kroah-Hartman
` (21 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Linus Walleij
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 1d9bb9c870632adea249cfdec49ac37e6f069164 upstream.
pcs_irq_init_chained_handler() requests a shared IRQ on affected SoCs, but
its domain creation failure path only removes a chained handler. That does
not release the action installed by request_irq(). The probe can continue
without interrupt support while leaving the shared IRQ action registered.
Use pcs_irq_free() to undo the appropriate type of handler registration.
At this point pcs->domain is NULL, so the helper only releases the parent
IRQ handler. Then mark the IRQ invalid, as the other initialization error
paths already do, to prevent another release from a later probe unwind or
remove.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: 3e6cee1786a1 ("pinctrl: single: Add support for wake-up interrupts")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/pinctrl-single.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/pinctrl/pinctrl-single.c
+++ b/drivers/pinctrl/pinctrl-single.c
@@ -1631,7 +1631,8 @@ static int pcs_irq_init_chained_handler(
&pcs_irqdomain_ops,
pcs_soc);
if (!pcs->domain) {
- irq_set_chained_handler(pcs_soc->irq, NULL);
+ pcs_irq_free(pcs);
+ pcs_soc->irq = -1;
return -EINVAL;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 968/982] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (966 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 967/982] pinctrl: single: free the IRQ on domain creation failure Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 969/982] RISC-V: KVM: Synchronize hrtimer callback during teardown Greg Kroah-Hartman
` (20 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vineeth Vijayan, Peter Oberparleiter,
Heiko Carstens
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
commit 5b76268dac968612f7283d59b539036de955b7d9 upstream.
The channel path registry entry associated with a CHPID may be removed
while the subchannel's PMCW still references that CHPID. In this case,
chpid_to_chp() can return NULL, leading to a NULL pointer dereference.
Add the missing NULL check before dereferencing the returned pointer.
Fixes: 199652309a4d ("s390/cio: add helper to query utility strings per given ccw device")
Cc: stable@vger.kernel.org
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/cio/device_ops.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/s390/cio/device_ops.c
+++ b/drivers/s390/cio/device_ops.c
@@ -509,6 +509,8 @@ u8 *ccw_device_get_util_str(struct ccw_d
chp_id_init(&chpid);
chpid.id = sch->schib.pmcw.chpid[chp_idx];
chp = chpid_to_chp(chpid);
+ if (!chp)
+ return NULL;
util_str = kmalloc(sizeof(chp->desc_fmt3.util_str), GFP_KERNEL);
if (!util_str)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 969/982] RISC-V: KVM: Synchronize hrtimer callback during teardown
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (967 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 968/982] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 970/982] Bluetooth: hci_sock: validate event length before filtering Greg Kroah-Hartman
` (19 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Myeonghun Pak, Anup Patel
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit aaad136d56d91252517272b68cd533e5714698d5 upstream.
The non-Sstc hrtimer callback clears next_set before its final uses of
the enclosing vCPU. If teardown observes next_set as false while the
callback is still running, kvm_riscv_vcpu_timer_cancel() skips
hrtimer_cancel() and kvm_destroy_vcpus() can free the vCPU before the
callback enters kvm_riscv_vcpu_set_interrupt().
A guest can arm the timer with SBI TIME and request shutdown with SBI
legacy shutdown or SRST. A VMM that honors KVM_EXIT_SYSTEM_EVENT and
destroys the VM supplies the teardown side of the race; no post-launch
host ioctl is needed to arm or request teardown.
On upstream master 62cc90241548, generic KASAN reported:
BUG: KASAN: slab-use-after-free in do_raw_spin_lock
Write of size 4 at addr ff60000005e58898
kvm_riscv_vcpu_set_interrupt
kvm_riscv_vcpu_hrtimer_expired
__hrtimer_run_queues
hrtimer_interrupt
The object was allocated by KVM_CREATE_VCPU and freed concurrently by:
kvm_destroy_vcpus
kvm_arch_destroy_vm
kvm_destroy_vm
__fput
For deterministic validation, I added mdelay(1000) immediately after
the existing next_set = false assignment. This only widens the
existing post-clear callback window. A no-delay trace build naturally
reached the callback-after-teardown-start/before-deinit ordering in 12
of 200 runs, but 1,500 stock-kernel stress iterations did not produce a
KASAN report, so natural reproduction is timing-sensitive.
Always invoke hrtimer_cancel() for an initialized timer. Preserve the
existing -EINVAL result when the timer is no longer set, but only after
synchronizing with a running callback.
With this patch, hrtimer_cancel() blocked for the full widened callback
window before vCPU destruction. KASAN reported no error in 100
fixed-and-widened runs or 200 fix-only timing-sweep runs.
Fixes: 3a9f66cb25e1 ("RISC-V: KVM: Add timer functionality")
Cc: stable@vger.kernel.org
Assisted-by: OpenAI:GPT-5.6
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260731163550.46991-1-mhun512@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/kvm/vcpu_timer.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/arch/riscv/kvm/vcpu_timer.c
+++ b/arch/riscv/kvm/vcpu_timer.c
@@ -60,10 +60,13 @@ static enum hrtimer_restart kvm_riscv_vc
static int kvm_riscv_vcpu_timer_cancel(struct kvm_vcpu_timer *t)
{
- if (!t->init_done || !t->next_set)
+ if (!t->init_done)
return -EINVAL;
hrtimer_cancel(&t->hrt);
+
+ if (!t->next_set)
+ return -EINVAL;
t->next_set = false;
return 0;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 970/982] Bluetooth: hci_sock: validate event length before filtering
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (968 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 969/982] RISC-V: KVM: Synchronize hrtimer callback during teardown Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 971/982] Bluetooth: hci_sock: reject out-of-range OCF values Greg Kroah-Hartman
` (18 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit b0a6cf99afd57a39598b1beca0e86ef5004980de upstream.
is_filtered_packet() reads the event code from skb->data[0] without first
checking that the skb is nonempty. When an opcode filter is configured,
it also reads the command opcode at offsets 3 or 4 without checking that
a Command Complete or Command Status event is long enough.
hci_send_to_sock() invokes the filter before hci_event_packet() validates
the event header. A malformed event supplied by a controller or a vhci
device can therefore cause an out-of-bounds read.
Keep the unmasked event code for the opcode checks. The masked value is
needed for the 64-bit event bitmap, but using it to identify command events
aliases event codes above 0x3f. In particular, Synchronous Train Complete
(0x4f) was treated as Command Status (0x0f) even though its payload has no
opcode.
Reject actual command events that are too short for the field being
inspected. A truncated command event cannot match a configured opcode.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sock.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
--- a/net/bluetooth/hci_sock.c
+++ b/net/bluetooth/hci_sock.c
@@ -166,6 +166,7 @@ static bool is_filtered_packet(struct so
{
struct hci_filter *flt;
int flt_type, flt_event;
+ u8 event;
/* Apply filter */
flt = &hci_pi(sk)->filter;
@@ -179,7 +180,11 @@ static bool is_filtered_packet(struct so
if (hci_skb_pkt_type(skb) != HCI_EVENT_PKT)
return false;
- flt_event = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
+ if (skb->len < 1)
+ return true;
+
+ event = *(__u8 *)skb->data;
+ flt_event = event & HCI_FLT_EVENT_BITS;
if (!hci_test_bit(flt_event, &flt->event_mask))
return true;
@@ -188,11 +193,17 @@ static bool is_filtered_packet(struct so
if (!flt->opcode)
return false;
- if (flt_event == HCI_EV_CMD_COMPLETE &&
+ if (event == HCI_EV_CMD_COMPLETE && skb->len < 5)
+ return true;
+
+ if (event == HCI_EV_CMD_COMPLETE &&
flt->opcode != get_unaligned((__le16 *)(skb->data + 3)))
return true;
- if (flt_event == HCI_EV_CMD_STATUS &&
+ if (event == HCI_EV_CMD_STATUS && skb->len < 6)
+ return true;
+
+ if (event == HCI_EV_CMD_STATUS &&
flt->opcode != get_unaligned((__le16 *)(skb->data + 4)))
return true;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 971/982] Bluetooth: hci_sock: reject out-of-range OCF values
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (969 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 970/982] Bluetooth: hci_sock: validate event length before filtering Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 972/982] Bluetooth: L2CAP: validate frame length before control and FCS access Greg Kroah-Hartman
` (17 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit e93fad891c72deb84cae49430163b384ebcc92b1 upstream.
The raw HCI socket security filter has 128 OCF bits per supported OGF,
but masks the 10-bit OCF with 127 before looking up the command. An
unprivileged socket can therefore submit a reserved OCF that aliases an
allowlisted command modulo 128.
A conforming controller should reject reserved opcodes. Nevertheless,
the security decision must apply to the opcode that will actually be
sent, especially since controller-specific behavior is outside the host
stack's control.
Reject OCF values that cannot be represented by the security filter
instead of aliasing them onto an unrelated command.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sock.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/bluetooth/hci_sock.c
+++ b/net/bluetooth/hci_sock.c
@@ -1823,7 +1823,8 @@ static int hci_sock_sendmsg(struct socke
u16 ocf = hci_opcode_ocf(opcode);
if (((ogf > HCI_SFLT_MAX_OGF) ||
- !hci_test_bit(ocf & HCI_FLT_OCF_BITS,
+ (ocf > HCI_FLT_OCF_BITS) ||
+ !hci_test_bit(ocf,
&hci_sec_filter.ocf_mask[ogf])) &&
!capable(CAP_NET_RAW)) {
err = -EPERM;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 972/982] Bluetooth: L2CAP: validate frame length before control and FCS access
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (970 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 971/982] Bluetooth: hci_sock: reject out-of-range OCF values Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 973/982] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO Greg Kroah-Hartman
` (16 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit 6c78a213d9070b610c7f418af2c25b66180b7e37 upstream.
l2cap_data_rcv() unpacks either a two-byte or four-byte control field
without first ensuring that it is present. A short ERTM or streaming-mode
frame can therefore cause an out-of-bounds read.
There is a second short-frame case when CRC16 is enabled. After the
control field is pulled, l2cap_check_fcs() subtracts two from skb->len
without checking it. If fewer than two bytes remain, the subtraction
wraps; skb_trim() leaves the buffer unchanged and the subsequent FCS
load reads past the logical end of the frame.
Validate that the frame contains both its control field and, when
enabled, its FCS before either field is accessed.
Fixes: 1c2acffb76d4 ("Bluetooth: Add initial support for ERTM packets transfers")
Fixes: fcc203c30d72 ("Bluetooth: Add support for FCS option to L2CAP")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/l2cap_core.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -6725,9 +6725,17 @@ static int l2cap_stream_rx(struct l2cap_
static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
{
struct l2cap_ctrl *control = &bt_cb(skb)->l2cap;
- u16 len;
+ u16 len, min_len;
u8 event;
+ min_len = test_bit(FLAG_EXT_CTRL, &chan->flags) ?
+ L2CAP_EXT_CTRL_SIZE : L2CAP_ENH_CTRL_SIZE;
+ if (chan->fcs == L2CAP_FCS_CRC16)
+ min_len += L2CAP_FCS_SIZE;
+
+ if (skb->len < min_len)
+ goto drop;
+
__unpack_control(chan, skb);
len = skb->len;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 973/982] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (971 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 972/982] Bluetooth: L2CAP: validate frame length before control and FCS access Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 974/982] smb: client: validate POSIX create context length Greg Kroah-Hartman
` (15 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Peng, Luiz Augusto von Dentz
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit 46f8ffd0a1f1eb6cbc94946a92c11ef601e228a1 upstream.
The RFCOMM_CONNINFO getsockopt handler accepts a socket that is not
connected as long as deferred setup is enabled:
if (sk->sk_state != BT_CONNECTED &&
!rfcomm_pi(sk)->dlc->defer_setup) {
err = -ENOTCONN;
break;
}
l2cap_sk = rfcomm_pi(sk)->dlc->session->sock->sk;
dlc->defer_setup is set in rfcomm_sock_init() when rfcomm_connect_ind()
creates a child socket for an incoming connection on a listening socket
that has BT_DEFER_SETUP enabled. It is never cleared afterwards. The
session, however, can go away underneath it.
rfcomm_recv_disc() forces the dlc state before tearing it down:
d->state = BT_CLOSED;
__rfcomm_dlc_close(d, err);
The RFCOMM_DEFER_SETUP early return in __rfcomm_dlc_close() only covers
BT_CONNECT, BT_CONFIG, BT_OPEN and BT_CONNECT2, so with the state
already BT_CLOSED that switch does not match and the function falls
through to rfcomm_dlc_unlink(), which sets d->session = NULL, while
d->defer_setup stays 1.
A getsockopt(SOL_RFCOMM, RFCOMM_CONNINFO) on the accepted socket after
that point therefore skips the -ENOTCONN path -- sk->sk_state is
BT_CLOSED, but dlc->defer_setup is still set -- and dereferences the
NULL session. No race is needed: once the DISC has been processed, the
dereference is unconditional.
Reproduced on a KASAN kernel under QEMU with a BR/EDR peer emulated over
/dev/vhci: the peer brings up an ACL link, opens L2CAP on the RFCOMM
PSM, starts a session and sends SABM for a channel bound with
BT_DEFER_SETUP, and sends DISC for that dlci after the socket has been
accepted. getsockopt(SOL_RFCOMM, RFCOMM_CONNINFO) on the accepted
socket then hits:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000002: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
CPU: 1 UID: 0 PID: 150 Comm: init Tainted: G B 7.3.0-rc3-g5dd1818b15d9
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)
RIP: 0010:rfcomm_sock_getsockopt+0x529/0x780
Call Trace:
<TASK>
do_sock_getsockopt+0x3ad/0x7d0
__sys_getsockopt+0x10e/0x1b0
__x64_sys_getsockopt+0xc2/0x160
do_syscall_64+0xda/0x4b0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
0x10 is the offset of sock in struct rfcomm_session;
rfcomm_sock_getsockopt_old() is inlined into rfcomm_sock_getsockopt().
Commit 43a556b2fd43 ("Bluetooth: RFCOMM: take rfcomm_mutex for the
deferred setup accept") fixed the same "a remote DISC clears the session
while deferred setup is still flagged" problem in rfcomm_dlc_accept();
this is the remaining instance of it, in the getsockopt path.
Deferred setup only leaves a socket usable here once it has reached
BT_CONNECT2, so restrict the exception to that state and check that a
session is actually present before following it.
Fixes: bb23c0ab8246 ("Bluetooth: Add support for deferring RFCOMM connection setup")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/rfcomm/sock.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/net/bluetooth/rfcomm/sock.c
+++ b/net/bluetooth/rfcomm/sock.c
@@ -786,8 +786,10 @@ static int rfcomm_sock_getsockopt_old(st
break;
case RFCOMM_CONNINFO:
- if (sk->sk_state != BT_CONNECTED &&
- !rfcomm_pi(sk)->dlc->defer_setup) {
+ if ((sk->sk_state != BT_CONNECTED &&
+ !(sk->sk_state == BT_CONNECT2 &&
+ rfcomm_pi(sk)->dlc->defer_setup)) ||
+ !rfcomm_pi(sk)->dlc->session) {
err = -ENOTCONN;
break;
}
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 974/982] smb: client: validate POSIX create context length
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (972 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 973/982] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 975/982] xfs: fix blockgc group quota scanning when usrquota isnt enforced Greg Kroah-Hartman
` (14 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit fa2e9900dd2a3f5a1e7ef5a8c5e8d435feedbfcc upstream.
parse_posix_ctxt() reads the fixed nlink, reparse_tag, and mode fields
before checking that the POSIX create context contains them. A short
context can pass the generic checks and still make these fixed-width
reads run past its declared data.
The current in-tree smb2_open_file() path passes a NULL posix pointer,
so this handler is not reached on the ordinary open path. Still require
the POSIX data to cover all three fields before reading them because the
helper performs those unguarded reads. Keep the existing soft-failure
behavior so malformed optional metadata does not fail the open.
Fixes: 69dda3059e7a ("cifs: add SMB2_open() arg to return POSIX data")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2pdu.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -2190,12 +2190,15 @@ static void
parse_posix_ctxt(struct create_context *cc, struct smb2_file_all_info *info,
struct create_posix_rsp *posix)
{
- int sid_len;
u8 *beg = (u8 *)cc + le16_to_cpu(cc->DataOffset);
- u8 *end = beg + le32_to_cpu(cc->DataLength);
+ u32 dlen = le32_to_cpu(cc->DataLength);
+ u8 *end = beg + dlen;
+ int sid_len;
u8 *sid;
memset(posix, 0, sizeof(*posix));
+ if (dlen < 3 * sizeof(__le32))
+ return;
posix->nlink = get_unaligned_le32(beg);
posix->reparse_tag = get_unaligned_le32(beg + 4);
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 975/982] xfs: fix blockgc group quota scanning when usrquota isnt enforced
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (973 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 974/982] smb: client: validate POSIX create context length Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 976/982] net: tls: fix silent data drop under pipe back-pressure Greg Kroah-Hartman
` (13 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit f8f6382ff13109e19d0fc1d0224ff7d29641e56a upstream.
LOLLM noticed the copy-paste error here -- if user quotas aren't
enforced but we're near the group quota limit, we fail to set FLAG_GID
and hence we might not actually free any preallocations, causing
unnecessary EDQUOT. Fix that.
Cc: stable@vger.kernel.org # v5.12
Fixes: c237dd7c709432 ("xfs: flush eof/cowblocks if we can't reserve quota for inode creation")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_icache.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/xfs_icache.c
+++ b/fs/xfs/xfs_icache.c
@@ -1578,7 +1578,7 @@ xfs_blockgc_free_dquots(
do_work = true;
}
- if (XFS_IS_UQUOTA_ENFORCED(mp) && gdqp && xfs_dquot_lowsp(gdqp)) {
+ if (XFS_IS_GQUOTA_ENFORCED(mp) && gdqp && xfs_dquot_lowsp(gdqp)) {
icw.icw_gid = make_kgid(mp->m_super->s_user_ns, gdqp->q_id);
icw.icw_flags |= XFS_ICWALK_FLAG_GID;
do_work = true;
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 976/982] net: tls: fix silent data drop under pipe back-pressure
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (974 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 975/982] xfs: fix blockgc group quota scanning when usrquota isnt enforced Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 977/982] perf test: Change all remaining #!/bin/sh to #!/bin/bash Greg Kroah-Hartman
` (12 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, Sasha Levin
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 7e7be31bfdb066c1c780dcd6b1224078fc54063f ]
tls_sw_splice_read() uses len when advancing rxm->offset / rxm->full_len
after skb_splice_bits(), rather than copied (the actual number of bytes
successfully spliced into the pipe). When the destination pipe cannot
accept all the requested bytes, splice_to_pipe() returns fewer bytes
than len, and 'len - copied' of data is effectively skipped over.
Fixes: e062fe99cccd ("tls: splice_read: fix accessing pre-processed records")
Link: https://patch.msgid.link/20260429222944.2139041-2-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/tls/tls_sw.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/tls/tls_sw.c b/net/tls/tls_sw.c
index 242f96f799084..68b8a59684e30 100644
--- a/net/tls/tls_sw.c
+++ b/net/tls/tls_sw.c
@@ -2392,9 +2392,9 @@ ssize_t tls_sw_splice_read(struct socket *sock, loff_t *ppos,
if (copied < 0)
goto splice_requeue;
- if (chunk < rxm->full_len) {
- rxm->offset += len;
- rxm->full_len -= len;
+ if (copied < rxm->full_len) {
+ rxm->offset += copied;
+ rxm->full_len -= copied;
goto splice_requeue;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 990+ messages in thread* [PATCH 6.1 977/982] perf test: Change all remaining #!/bin/sh to #!/bin/bash
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (975 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 976/982] net: tls: fix silent data drop under pipe back-pressure Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 978/982] tools/thermal/tmon: Fix compilation warning for wrong format Greg Kroah-Hartman
` (11 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Clark, Collin Funk,
Arnaldo Carvalho de Melo, Namhyung Kim, Salvatore Bonaccorso
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <james.clark@linaro.org>
commit 2f5d370dec3f800b44bbf7b68875d521e0af43cd upstream.
There are 43 instances of posix shell tests and 35 instances of bash. To
give us a single consistent language for testing in, replace
all #!/bin/sh to #!/bin/bash. Common sources that are included in both
different shells will now work as expected. And we no longer have to fix
up bashisms that appear to work when someone's system has sh symlinked
to bash, but don't work on other systems that have both shells
installed.
Although we could have chosen sh, it's not backwards compatible so it
wouldn't be possible to bulk convert without re-writing the existing
bash tests.
Choosing bash also gives us some nicer features including 'local'
variable definitions and regexes in if statements that are already
widely used in the tests.
It's not expected that there are any users with only sh available due to
the large number of bash tests that exist.
Discussed in relation to running shellcheck here:
https://lore.kernel.org/linux-perf-users/e3751a74be34bbf3781c4644f518702a7270220b.1749785642.git.collin.funk1@gmail.com/
Signed-off-by: James Clark <james.clark@linaro.org>
Reviewed-by: Collin Funk <collin.funk1@gmail.com>
Acked-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Link: https://lore.kernel.org/r/20250623-james-perf-bash-tests-v1-1-f572f54d4559@linaro.org
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
When commit b02027776ac5 ("perf tests: Fix flakiness in BPF counters
test on hybrid systems") was backported to several stable series
(v5.15.221, v6.1.188, v6.6.157, v6.12.110, v6.18.52, v7.2.6) it
introduced specific bash syntax. For versions after 2f5d370dec3f ("perf
test: Change all remaining #!/bin/sh to #!/bin/bash") in v6.17-rc1 this
is not a problem as the shebang was already hanged to #!/bin/bash. For
the older stable series this introduced invalid syntax if #!/bin/sh is
not bash:
$ sh -n tools/perf/tests/shell/stat_bpf_counters.sh
tools/perf/tests/shell/stat_bpf_counters.sh: 12: Syntax error: "(" unexpected
$ checkbashism tools/perf/tests/shell/stat_bpf_counters.sh
possible bashism in tools/perf/tests/shell/stat_bpf_counters.sh line 52 (bash arrays, ${name[0|*|@]}):
base_instructions=$(perf stat --no-big-num -e instructions:u -- "${workload[@]}" 2>&1 | \
awk -v i=0 -v c=0 '/instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
} END { if (i > 0) printf "%.0f", c; else print "<not" }')
possible bashism in tools/perf/tests/shell/stat_bpf_counters.sh line 57 (bash arrays, ${name[0|*|@]}):
bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions:u \
-- "${workload[@]}" 2>&1 | \
awk -v i=0 -v c=0 '/instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
} END { if (i > 0) printf "%.0f", c; else print "<not" }')
possible bashism in tools/perf/tests/shell/stat_bpf_counters.sh line 68 (bash arrays, ${name[0|*|@]}):
stat_output=$(perf stat --no-big-num \
-e instructions/name=base_instructions/u,instructions/name=bpf_instructions/bu \
-- "${workload[@]}" 2>&1)
Change shebang for the stat_bpf_counters.sh script.
No upstream commit exists for this change as for versions post 6.17-rc1
the scripts were converted to #!/bin/bash already.
Signed-off-by: Salvatore Bonaccorso <carnil@debian.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/perf/tests/shell/stat_bpf_counters.sh | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/perf/tests/shell/stat_bpf_counters.sh
+++ b/tools/perf/tests/shell/stat_bpf_counters.sh
@@ -1,4 +1,4 @@
-#!/bin/sh
+#!/bin/bash
# perf stat --bpf-counters test
# SPDX-License-Identifier: GPL-2.0
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 978/982] tools/thermal/tmon: Fix compilation warning for wrong format
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (976 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 977/982] perf test: Change all remaining #!/bin/sh to #!/bin/bash Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 979/982] lan78xx: Enable 125 MHz CLK configuration for LAN7801 if NO EEPROM is detected Greg Kroah-Hartman
` (10 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Eckert, Daniel Lezcano,
Florian Fainelli
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Eckert <fe@dev.tdt.de>
commit 9da39ef332c417ce52732564c1c682a6e1209302 upstream.
The following warnings are shown during compilation:
tui.c: In function 'show_cooling_device':
tui.c:216:40: warning: format '%d' expects argument of type 'int', but
argument 7 has type 'long unsigned int' [-Wformat=]
216 | "%02d %12.12s%6d %6d",
| ~~^
| |
| int
| %6ld
......
219 | ptdata.cdi[j].cur_state,
| ~~~~~~~~~~~~~~~~~~~~~~~
| |
| long unsigned int
tui.c:216:44: warning: format '%d' expects argument of type 'int', but
argument 8 has type 'long unsigned int' [-Wformat=]
216 | "%02d %12.12s%6d %6d",
| ~~^
| |
| int
| %6ld
......
220 | ptdata.cdi[j].max_state);
| ~~~~~~~~~~~~~~~~~~~~~~~
| |
| long unsigned int
To fix this, the correct string format must be used for printing.
Signed-off-by: Florian Eckert <fe@dev.tdt.de>
Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://lore.kernel.org/r/20231204141335.2798194-1-fe@dev.tdt.de
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/thermal/tmon/tui.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/thermal/tmon/tui.c
+++ b/tools/thermal/tmon/tui.c
@@ -213,7 +213,7 @@ void show_cooling_device(void)
* cooling device instances. skip unused idr.
*/
mvwprintw(cooling_device_window, j + 2, 1,
- "%02d %12.12s%6d %6d",
+ "%02d %12.12s%6lu %6lu",
ptdata.cdi[j].instance,
ptdata.cdi[j].type,
ptdata.cdi[j].cur_state,
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 979/982] lan78xx: Enable 125 MHz CLK configuration for LAN7801 if NO EEPROM is detected
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (977 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 978/982] tools/thermal/tmon: Fix compilation warning for wrong format Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 980/982] lan78xx: Enable Auto Speed and Auto Duplex " Greg Kroah-Hartman
` (9 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Simon Horman, Rengarajan S,
Jakub Kicinski, Minh Tiến Nguyễn
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rengarajan S <rengarajan.s@microchip.com>
commit 5160b129f65fc6e1a4aa282d44f824e12aa800ee upstream.
The 125MHz and 25MHz clock configurations are enabled in the initialization
regardless of EEPROM (125MHz is needed for RGMII 1000Mbps operation). After
a lite reset (lan78xx_reset), these contents go back to defaults(all 0, so
no 125MHz or 25MHz clock).
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Rengarajan S <rengarajan.s@microchip.com>
Link: https://lore.kernel.org/r/20240529140256.1849764-2-rengarajan.s@microchip.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Cc: Minh Tiến Nguyễn <zizuzacker@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/lan78xx.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/net/usb/lan78xx.c
+++ b/drivers/net/usb/lan78xx.c
@@ -2979,6 +2979,8 @@ static int lan78xx_reset(struct lan78xx_
return ret;
buf |= HW_CFG_MEF_;
+ buf |= HW_CFG_CLK125_EN_;
+ buf |= HW_CFG_REFCLK25_EN_;
ret = lan78xx_write_reg(dev, HW_CFG, buf);
if (ret < 0)
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 980/982] lan78xx: Enable Auto Speed and Auto Duplex configuration for LAN7801 if NO EEPROM is detected
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (978 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 979/982] lan78xx: Enable 125 MHz CLK configuration for LAN7801 if NO EEPROM is detected Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 981/982] drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() Greg Kroah-Hartman
` (8 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Simon Horman, Rengarajan S,
Jakub Kicinski, Minh Tiến Nguyễn
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rengarajan S <rengarajan.s@microchip.com>
commit 799f532de13601f91ecb9cc6169d45d6e6933b0f upstream.
Enabled ASD/ADD configuration for LAN7801 in the absence of EEPROM.
After the lite reset these contents go back to defaults where ASD/
ADD is disabled. The check is already available for LAN7800.
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Rengarajan S <rengarajan.s@microchip.com>
Link: https://lore.kernel.org/r/20240529140256.1849764-3-rengarajan.s@microchip.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Cc: Minh Tiến Nguyễn <zizuzacker@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/lan78xx.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/net/usb/lan78xx.c
+++ b/drivers/net/usb/lan78xx.c
@@ -3069,8 +3069,11 @@ static int lan78xx_reset(struct lan78xx_
return ret;
/* LAN7801 only has RGMII mode */
- if (dev->chipid == ID_REV_CHIP_ID_7801_)
+ if (dev->chipid == ID_REV_CHIP_ID_7801_) {
buf &= ~MAC_CR_GMII_EN_;
+ /* Enable Auto Duplex and Auto speed */
+ buf |= MAC_CR_AUTO_DUPLEX_ | MAC_CR_AUTO_SPEED_;
+ }
if (dev->chipid == ID_REV_CHIP_ID_7800_ ||
dev->chipid == ID_REV_CHIP_ID_7850_) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 981/982] drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (979 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 980/982] lan78xx: Enable Auto Speed and Auto Duplex " Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.1 982/982] ALSA: hda: Fix missing pointer check in hda_component_manager_init function Greg Kroah-Hartman
` (7 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Alex Deucher,
Roman Demidov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit cc9a8e238e42c1f43b98c097995137d644b69245 upstream.
kcalloc() may fail. When WS is non-zero and allocation fails, ectx.ws
remains NULL while ectx.ws_size is set, leading to a potential NULL
pointer dereference in atom_get_src_int() when accessing WS entries.
Return -ENOMEM on allocation failure to avoid the NULL dereference.
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
[ Roman: added parentheses to the 'if' statement, matching the upstream commit. ]
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/atom.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/atom.c
+++ b/drivers/gpu/drm/amd/amdgpu/atom.c
@@ -1228,10 +1228,15 @@ static int amdgpu_atom_execute_table_loc
ectx.ps = params;
ectx.abort = false;
ectx.last_jump = 0;
- if (ws)
+ if (ws) {
ectx.ws = kcalloc(4, ws, GFP_KERNEL);
- else
+ if (!ectx.ws) {
+ ret = -ENOMEM;
+ goto free;
+ }
+ } else {
ectx.ws = NULL;
+ }
debug_depth++;
while (1) {
^ permalink raw reply [flat|nested] 990+ messages in thread* [PATCH 6.1 982/982] ALSA: hda: Fix missing pointer check in hda_component_manager_init function
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (980 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 981/982] drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 18:46 ` [PATCH 6.1 000/982] 6.1.189-rc1 review Florian Fainelli
` (6 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Denis Arefev, Takashi Iwai,
Roman Demidov
6.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Denis Arefev <arefev@swemel.ru>
commit 1cf11d80db5df805b538c942269e05a65bcaf5bc upstream.
The __component_match_add function may assign the 'matchptr' pointer
the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced.
The call stack leading to the error looks like this:
hda_component_manager_init
|-> component_match_add
|-> component_match_add_release
|-> __component_match_add ( ... ,**matchptr, ... )
|-> *matchptr = ERR_PTR(-ENOMEM); // assign
|-> component_master_add_with_match( ... match)
|-> component_match_realloc(match, match->num); // dereference
Add IS_ERR() check to prevent the crash.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: ae7abe36e352 ("ALSA: hda/realtek: Add CS35L41 support for Thinkpad laptops")
Cc: stable@vger.kernel.org
Signed-off-by: Denis Arefev <arefev@swemel.ru>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[Roman: Instead of modifying hda_component_manager_init() (which does not
yet exist in version 6.1), a check needs to be added to the
cs35l41_generic_fixup() function—the very function introduced by the
offending commit, which calls component_match_add() without verifying its
successful completion.]
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/pci/hda/patch_realtek.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -7021,6 +7021,11 @@ static void cs35l41_generic_fixup(struct
spec->comps[i].codec = cdc;
component_match_add(dev, &spec->match,
comp_match_cs35l41_dev_name, rec);
+ if (IS_ERR(spec->match)) {
+ codec_err(cdc, "Fail to add component %ld\n",
+ PTR_ERR(spec->match));
+ return;
+ }
}
ret = component_master_add_with_match(dev, &comp_master_ops, spec->match);
if (ret)
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (981 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 6.1 982/982] ALSA: hda: Fix missing pointer check in hda_component_manager_init function Greg Kroah-Hartman
@ 2026-09-30 18:46 ` Florian Fainelli
2026-09-30 21:40 ` Peter Schneider
` (5 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Florian Fainelli @ 2026-09-30 18:46 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, sudipm.mukherjee, rwarsow, conor,
hargar, broonie, achill, sr
On 9/30/2026 8:12 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 6.1.189 release.
> There are 982 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.1.189-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
On ARCH_BRCMSTB using 32-bit and 64-bit ARM kernels, build tested on
BMIPS_GENERIC:
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
--
Florian
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (982 preceding siblings ...)
2026-09-30 18:46 ` [PATCH 6.1 000/982] 6.1.189-rc1 review Florian Fainelli
@ 2026-09-30 21:40 ` Peter Schneider
2026-10-01 9:16 ` Pavel Machek
` (4 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Peter Schneider @ 2026-09-30 21:40 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
Am 30.09.2026 um 17:12 schrieb Greg Kroah-Hartman:
> This is the start of the stable review cycle for the 6.1.189 release.
> There are 982 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
Builds, boots and works on my 2-socket Ivy Bridge Xeon E5-2697v2 server. No dmesg oddities or regressions found.
Tested-by: Peter Schneider <pschneider1968@googlemail.com>
Beste Grüße,
Peter Schneider
--
Climb the mountain not to plant your flag, but to embrace the challenge,
enjoy the air and behold the view. Climb it so you can see the world,
not so the world can see you. -- David McCullough Jr.
OpenPGP: 0xA3828BD796CCE11A8CADE8866E3A92C92C3FF244
Download: https://www.peters-netzplatz.de/download/pschneider1968_pub.asc
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@googlemail.com
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@gmail.com
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (983 preceding siblings ...)
2026-09-30 21:40 ` Peter Schneider
@ 2026-10-01 9:16 ` Pavel Machek
2026-10-01 10:22 ` Ron Economos
` (3 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Pavel Machek @ 2026-10-01 9:16 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
[-- Attachment #1: Type: text/plain, Size: 503 bytes --]
Hi!
> This is the start of the stable review cycle for the 6.1.189 release.
> There are 982 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
CIP testing did not find any problems here:
https://gitlab.com/cip-project/cip-testing/linux-stable-rc-ci/-/tree/linux-6.1.y
Tested-by: Pavel Machek (CIP) <pavel@nabladev.com>
Best regards,
Pavel
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (984 preceding siblings ...)
2026-10-01 9:16 ` Pavel Machek
@ 2026-10-01 10:22 ` Ron Economos
2026-10-01 11:09 ` Miguel Ojeda
` (2 subsequent siblings)
988 siblings, 0 replies; 990+ messages in thread
From: Ron Economos @ 2026-10-01 10:22 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/30/26 08:12, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 6.1.189 release.
> There are 982 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.1.189-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Built and booted successfully on RISC-V RV64 (HiFive Unmatched).
Tested-by: Ron Economos <re@w6rz.net>
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (985 preceding siblings ...)
2026-10-01 10:22 ` Ron Economos
@ 2026-10-01 11:09 ` Miguel Ojeda
2026-10-01 16:44 ` Brett A C Sheffield
2026-10-02 1:41 ` Barry K. Nathan
988 siblings, 0 replies; 990+ messages in thread
From: Miguel Ojeda @ 2026-10-01 11:09 UTC (permalink / raw)
To: gregkh
Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
linux-kernel, linux, lkft-triage, patches, patches, pavel,
rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
Miguel Ojeda
On Wed, 30 Sep 2026 17:12:16 +0200 Greg Kroah-Hartman <gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 6.1.189 release.
> There are 982 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
Boot-tested under QEMU for Rust x86_64:
Tested-by: Miguel Ojeda <ojeda@kernel.org>
Thanks!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (986 preceding siblings ...)
2026-10-01 11:09 ` Miguel Ojeda
@ 2026-10-01 16:44 ` Brett A C Sheffield
2026-10-02 1:41 ` Barry K. Nathan
988 siblings, 0 replies; 990+ messages in thread
From: Brett A C Sheffield @ 2026-10-01 16:44 UTC (permalink / raw)
To: gregkh
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr,
Brett A C Sheffield
# Librecast Test Results
044/044 [ OK ] liblcrq
010/010 [ OK ] libmld
120/120 [ OK ] liblibrecast
CPU/kernel: Linux auntie 6.1.189-rc1-00983-gae9e011542b0 #1 SMP PREEMPT_DYNAMIC Thu Oct 1 15:02:46 -00 2026 x86_64 AMD Ryzen 9 9950X 16-Core Processor AuthenticAMD GNU/Linux
Tested-by: Brett A C Sheffield <bacs@librecast.net>
^ permalink raw reply [flat|nested] 990+ messages in thread* Re: [PATCH 6.1 000/982] 6.1.189-rc1 review
2026-09-30 15:12 [PATCH 6.1 000/982] 6.1.189-rc1 review Greg Kroah-Hartman
` (987 preceding siblings ...)
2026-10-01 16:44 ` Brett A C Sheffield
@ 2026-10-02 1:41 ` Barry K. Nathan
988 siblings, 0 replies; 990+ messages in thread
From: Barry K. Nathan @ 2026-10-02 1:41 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/30/26 8:12 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 6.1.189 release.
> There are 982 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.1.189-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.1.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Tested on an amd64 laptop (Lenovo ThinkPad T14 Gen 1). Working well,
no regressions observed.
Tested-by: Barry K. Nathan <barryn@pobox.com>
--
-Barry K. Nathan <barryn@pobox.com>
^ permalink raw reply [flat|nested] 990+ messages in thread